CSSD logo
Focused certification exam prep
Start practice

What Is CSSD Certification?

TL;DR
  • CSSD here means Cyber Secure Software Developer, issued by CertNexus; the current exam is CSD-110, launched May 11, 2026.
  • The exam has 25 multiple-choice/multiple-response questions delivered online through CHOICE, and the passing score is 80% (20 of 25).
  • Develop Secure Code is the largest domain at 33%, followed by the secure software development lifecycle at 22%.
  • There are no formal registration prerequisites, and one complimentary retake is included.

What the Cyber Secure Software Developer Credential Is

Cyber Secure Software Developer, abbreviated CSSD, is a vendor-neutral certification aimed at people who write, review, test, and ship software and want to prove they can do it securely. It is not a general security-analyst credential, and it is not a network-defense certification. Its center of gravity is the work developers actually do: designing features, writing code, handling data, wiring up build pipelines, and deciding what to trust.

The acronym is shared by several unrelated credentials in other industries, so it is worth being precise. This article, and this site, cover only the Cyber Secure Software Developer certification. If you have seen other uses of the letters CSSD elsewhere, none of those details apply here. For shorter explainers on the naming question, see What Does CSSD Stand For? and CSSD Meaning.

Why the identity matters: Fees, exam formats, domain structures, and renewal rules differ completely between credentials that share an acronym. Everything below applies to the CertNexus Cyber Secure Software Developer exam CSD-110 and nothing else.

Who Issues It and Which Exam Is Current

The credential is issued by CertNexus. The current exam is CSD-110, which launched on May 11, 2026. The exam objectives come from the official CertNexus blueprint, version 1.12, issued December 15, 2024 and modified June 1, 2026. That blueprint is the authoritative statement of what can appear on the test, and it is the document every study plan should be anchored to.

One point of potential confusion: the publisher identifies the CSD-110 courseware as replacing the earlier Cyber Secure Coder CSC-210 courseware. Those are distinct exams with distinct blueprints. If you find older study material labeled for CSC-210, treat it as a different product rather than a drop-in resource. Likewise, some product descriptions mention a "CSD-210" designation that conflicts with the issuer's own CSD-110 title and blueprint; the issuer's naming is what counts.

For a broader overview of the credential and its positioning, the site also has What Is CSSD Certification? companion pages such as CSSD Certification, which approach the same topic from slightly different angles.

Exam Format and Question Style

The CSD-110 assessment is compact by certification standards. Here is the structure at a glance:

AttributeCSD-110 Detail
IssuerCertNexus
DeliveryOnline through CHOICE
Number of questions25
Question typesMultiple-choice and multiple-response
Passing score80% (20 of 25)
Estimated completion time30 to 60 minutes (an estimate, not a verified fixed timer)
RetakeOne complimentary retake

What "multiple-response" means for you

Some questions ask you to select more than one correct answer. That changes how you should study. It is not enough to recognize one good practice among four options; you need to understand a topic well enough to identify every valid statement and reject plausible-sounding distractors. A question about input handling, for example, might present several defensive measures and expect you to choose all that genuinely apply.

Why 80% is a demanding bar

With only 25 questions and an 80% threshold, you can miss at most five. There is little room to gamble on a weak domain. Because Develop Secure Code carries 33% of the blueprint, a candidate who is shaky on code-level defenses will feel it quickly. For a deeper breakdown of the scoring threshold, read CSSD Passing Score 2026: Exactly What You Need to Pass, and for a realistic sense of difficulty, see How Hard Is the CSSD Exam?

A note on timing: The 30 to 60 minute figure is an estimated completion time, not a confirmed fixed exam clock. Plan to answer thoughtfully rather than racing, and check the current CertNexus assessment page for the latest delivery details before you sit the exam.

The Five Exam Domains in Detail

The blueprint divides the exam into five weighted domains. The weights tell you where the points are, so they should shape where your hours go.

DomainWeight
1. Understand the Fundamentals of Secure Software Development15%
2. Explain the Secure Software Development Lifecycle22%
3. Develop Secure Code33%
4. Defending Against Cyberattacks15%
5. Engage in Governance, Risk Management, and Compliance15%

Domain 1: Understand the Fundamentals of Secure Software Development (15%)

This domain sets the vocabulary and mental models the rest of the exam builds on. Expect foundational security principles applied to software work.

  • The CIA triad: confidentiality, integrity, availability
  • AAA: authentication, authorization, accounting
  • Least privilege as a design default rather than an afterthought

Domain 2: Explain the Secure Software Development Lifecycle (22%)

The second-largest domain asks you to place security activities at the right stage of the lifecycle instead of bolting them on at the end.

  • Threat modeling during design
  • Abuse cases alongside use cases
  • Security testing and review across requirements, design, build, test, and deployment

Domain 3: Develop Secure Code (33%)

The heaviest domain, and the one most directly tied to day-to-day developer work. It is where hands-on fluency pays off.

  • Input validation and output encoding
  • Authentication and authorization implementation
  • Secrets management
  • Reviewing AI-generated code for security flaws

Domain 4: Defending Against Cyberattacks (15%)

This domain connects coding decisions to the attacks they are meant to resist, including how testing tools and dependency hygiene reduce exposure.

  • SAST, DAST, IAST, and SCA tooling and what each finds
  • Dependency security
  • Secure CI/CD and software supply chain security

Domain 5: Engage in Governance, Risk Management, and Compliance (15%)

Developers rarely work in a vacuum. This domain covers how security obligations, risk decisions, and compliance expectations shape engineering practice.

  • Governance responsibilities that touch the development process
  • Risk management as a basis for prioritizing fixes
  • Compliance considerations relevant to software delivery

For a domain-by-domain walkthrough with additional context, see CSSD Exam Domains 2026: Complete Guide to All 5 Content Areas.

Concrete Topics You Must Master

The blueprint lists many specific topics, and it notes that its detailed examples are not an exhaustive list of everything that may be tested. Treat the list below as a floor, not a ceiling. Several clusters deserve focused attention.

Design-time thinking: threat modeling and abuse cases

Threat modeling asks "what could go wrong with this design, and who would cause it?" Abuse cases flip the usual requirements exercise: instead of describing how a legitimate user completes a task, you describe how a malicious actor misuses the same feature. A candidate should be able to explain why these activities are cheaper and more effective early in the lifecycle than after code ships.

Code-level defenses: validation, encoding, and identity

Input validation and output encoding are a matched pair. Validation controls what enters your system; encoding controls how data is rendered or interpreted when it leaves. Confusing the two is a classic exam trap. Authentication confirms who someone is, while authorization decides what that identity may do. Secrets management covers how credentials, keys, and tokens are stored and supplied so they never end up hardcoded in source or leaked through logs and repositories.

AI-generated code review

A distinctive feature of this blueprint is its attention to reviewing AI-generated code. The core idea is that code produced by an assistant deserves the same scrutiny as code written by a person, and sometimes more, because it can look polished while carrying insecure patterns, outdated dependencies, or missing validation. Be ready to reason about what a careful reviewer checks before accepting generated output.

Testing and pipeline security

Know the four testing acronyms and how they differ in what they inspect and when they run: SAST analyzes source without running it, DAST probes a running application from the outside, IAST observes behavior from within an instrumented application, and SCA inventories open-source components and flags known-vulnerable dependencies. Pair that with secure CI/CD practices and software supply chain security, where the concern is that the build and delivery path itself can be attacked.

Key Takeaway

Do not memorize tools as a list of acronyms. For each of SAST, DAST, IAST, and SCA, be able to say what it examines, at what stage it fits, and what kind of defect it is likely to miss. Scenario questions reward that comparison skill.

Access, Registration, and Cost Mechanics

The registration picture is refreshingly simple. There are no formal registration prerequisites, no application fee, no supporting documentation to assemble, and no eligibility verification step. CertNexus does recommend foundational security knowledge plus experience in software development, design, testing, and deployment, but it does not prescribe a particular programming language. You can approach the material from whatever language background you have.

The course access key includes the CHOICE credential process, so the learning and the credentialing path are bundled together. One complimentary retake is included if you do not pass the first time.

What the published prices actually represent

Two student digital course bundles are published through a courseware retailer:

  • USD 514.50 for the bundle without lab (SKU CNX0022SEBU2, revision 1.0)
  • USD 561.75 for the bundle with lab (SKU CNX0022SEBU, revision 1.0)

These are courseware-bundle prices. They have not been separately verified as exam-only fees, so do not read them as a standalone exam price. A small quirk worth knowing: the first listing is titled "Student Digital Course Bundle" even though its web address uses "instructor" wording. Confirm details on the product page at checkout. For a fuller treatment of budgeting, see CSSD Certification Cost 2026: Complete Pricing Breakdown, and for entry conditions see CSSD Requirements 2026: Eligibility, Prerequisites & How to Qualify.

With lab or without? The lab edition costs more, but a developer-focused credential benefits from hands-on practice with the kinds of controls and tools the blueprint names. If you already work daily in secure development tooling, the no-lab bundle may suffice; if your experience is thinner, the lab is worth weighing.

Who Should Pursue It and Who Hires for These Skills

The credential suits several overlapping groups:

  • Software developers who want to formalize secure-coding habits and demonstrate them to employers.
  • Application and product engineers responsible for design and testing decisions with security consequences.
  • DevOps and platform engineers who own build pipelines and need to harden CI/CD and the software supply chain.
  • Security-minded QA and test engineers who want to broaden into security testing methodologies.
  • Early-career developers looking for a structured, vendor-neutral way to show security literacy.

Employers who value these skills tend to be organizations that build and ship their own software: product companies, software vendors, financial and healthcare technology firms, and teams in regulated industries where compliance pressure makes secure development a hiring criterion. Roles where the credential is relevant include secure software developer, application security engineer, DevSecOps engineer, and software engineer on security-conscious teams. Because no verified salary or hiring-volume figures are tied to this specific credential here, treat any dollar claims you encounter elsewhere with caution; the site's CSSD Salary Guide and CSSD Jobs pages discuss the career picture qualitatively, and Is the CSSD Certification Worth It? weighs the return on investment.

Validity and Renewal

CertNexus's general maintenance policy states that certifications are valid for three years and can be renewed by passing the current exam. Continuing education is available to eligible holders under the CertNexus Continuing Education Program. An important caveat: that program page does not establish CSSD-specific continuing-education eligibility or requirements. So the safe summary is the general policy, three-year validity and renewal by passing the current exam, and you should verify directly with CertNexus whether continuing education applies to your situation rather than assuming rules from any other credential.

Sequencing Your Preparation by Domain

Because the exam is short and the passing bar is high, the order in which you tackle domains matters more than the total number of hours. A sensible approach front-loads the foundations, then spends the most time where the blueprint pays the most.

Week 1

Fundamentals and vocabulary (Domain 1)

  • Lock in CIA, AAA, and least privilege so later scenarios make sense
  • Read the full CSD-110 blueprint once, end to end
Week 2

Lifecycle placement (Domain 2)

  • Practice threat modeling and write abuse cases for a sample feature
  • Map each security activity to a lifecycle stage
Weeks 3 to 4

Secure coding depth (Domain 3)

  • Spend the most time here given its 33% weight
  • Drill validation versus encoding, authentication versus authorization, and secrets handling
  • Practice spotting flaws in AI-generated code samples
Week 5

Defense and governance (Domains 4 and 5)

  • Compare SAST, DAST, IAST, and SCA by scope and timing
  • Review secure CI/CD, supply chain risks, and governance and compliance basics

Finish with timed practice on multiple-response questions, since that format punishes partial knowledge. Our CSSD Study Guide 2026 expands this into a fuller plan, and the CSSD Cheat Sheet is useful for a last-pass review. When you are ready to test yourself under realistic conditions, the CSSD practice tests on the main site let you check your readiness domain by domain.

Frequently Asked Questions

What does CSSD stand for in this context?

It stands for Cyber Secure Software Developer, a CertNexus certification. The current exam is CSD-110. The acronym is used by other unrelated credentials, but none of their details apply to this one.

How many questions are on the exam and what is the passing score?

The exam has 25 multiple-choice and multiple-response questions, and the passing score is 80%, meaning 20 of 25 correct. One complimentary retake is included.

Are there prerequisites to take the exam?

There are no formal registration prerequisites, application fee, supporting documentation, or eligibility verification. CertNexus recommends foundational security knowledge and experience in software development, design, testing, and deployment, with no required programming language.

Which domain should I prioritize?

Develop Secure Code is the largest at 33%, followed by the secure software development lifecycle at 22%. Together they account for more than half of the blueprint, so they deserve the largest share of your study time.

How long does the certification last?

CertNexus's general maintenance policy gives three-year validity with renewal by passing the current exam. Continuing education may be available to eligible holders, but the program page does not confirm CSSD-specific requirements, so verify with CertNexus.

Ready to pass your CSSD exam?

Put this into practice with free CSSD questions across every exam domain.