- What the Cyber Secure Software Developer Credential Is
- Who Issues It and Which Exam Is Current
- Exam Format and Question Style
- The Five Exam Domains in Detail
- Concrete Topics You Must Master
- Access, Registration, and Cost Mechanics
- Who Should Pursue It and Who Hires for These Skills
- Validity and Renewal
- Sequencing Your Preparation by Domain
- Frequently Asked Questions
- CSSD here means Cyber Secure Software Developer, issued by CertNexus; the current exam is CSD-110, launched May 11, 2026.
- The exam has 25 multiple-choice/multiple-response questions delivered online through CHOICE, and the passing score is 80% (20 of 25).
- Develop Secure Code is the largest domain at 33%, followed by the secure software development lifecycle at 22%.
- There are no formal registration prerequisites, and one complimentary retake is included.
What the Cyber Secure Software Developer Credential Is
Cyber Secure Software Developer, abbreviated CSSD, is a vendor-neutral certification aimed at people who write, review, test, and ship software and want to prove they can do it securely. It is not a general security-analyst credential, and it is not a network-defense certification. Its center of gravity is the work developers actually do: designing features, writing code, handling data, wiring up build pipelines, and deciding what to trust.
The acronym is shared by several unrelated credentials in other industries, so it is worth being precise. This article, and this site, cover only the Cyber Secure Software Developer certification. If you have seen other uses of the letters CSSD elsewhere, none of those details apply here. For shorter explainers on the naming question, see What Does CSSD Stand For? and CSSD Meaning.
Who Issues It and Which Exam Is Current
The credential is issued by CertNexus. The current exam is CSD-110, which launched on May 11, 2026. The exam objectives come from the official CertNexus blueprint, version 1.12, issued December 15, 2024 and modified June 1, 2026. That blueprint is the authoritative statement of what can appear on the test, and it is the document every study plan should be anchored to.
One point of potential confusion: the publisher identifies the CSD-110 courseware as replacing the earlier Cyber Secure Coder CSC-210 courseware. Those are distinct exams with distinct blueprints. If you find older study material labeled for CSC-210, treat it as a different product rather than a drop-in resource. Likewise, some product descriptions mention a "CSD-210" designation that conflicts with the issuer's own CSD-110 title and blueprint; the issuer's naming is what counts.
For a broader overview of the credential and its positioning, the site also has What Is CSSD Certification? companion pages such as CSSD Certification, which approach the same topic from slightly different angles.
Exam Format and Question Style
The CSD-110 assessment is compact by certification standards. Here is the structure at a glance:
| Attribute | CSD-110 Detail |
|---|---|
| Issuer | CertNexus |
| Delivery | Online through CHOICE |
| Number of questions | 25 |
| Question types | Multiple-choice and multiple-response |
| Passing score | 80% (20 of 25) |
| Estimated completion time | 30 to 60 minutes (an estimate, not a verified fixed timer) |
| Retake | One complimentary retake |
What "multiple-response" means for you
Some questions ask you to select more than one correct answer. That changes how you should study. It is not enough to recognize one good practice among four options; you need to understand a topic well enough to identify every valid statement and reject plausible-sounding distractors. A question about input handling, for example, might present several defensive measures and expect you to choose all that genuinely apply.
Why 80% is a demanding bar
With only 25 questions and an 80% threshold, you can miss at most five. There is little room to gamble on a weak domain. Because Develop Secure Code carries 33% of the blueprint, a candidate who is shaky on code-level defenses will feel it quickly. For a deeper breakdown of the scoring threshold, read CSSD Passing Score 2026: Exactly What You Need to Pass, and for a realistic sense of difficulty, see How Hard Is the CSSD Exam?
The Five Exam Domains in Detail
The blueprint divides the exam into five weighted domains. The weights tell you where the points are, so they should shape where your hours go.
| Domain | Weight |
|---|---|
| 1. Understand the Fundamentals of Secure Software Development | 15% |
| 2. Explain the Secure Software Development Lifecycle | 22% |
| 3. Develop Secure Code | 33% |
| 4. Defending Against Cyberattacks | 15% |
| 5. Engage in Governance, Risk Management, and Compliance | 15% |
Domain 1: Understand the Fundamentals of Secure Software Development (15%)
This domain sets the vocabulary and mental models the rest of the exam builds on. Expect foundational security principles applied to software work.
- The CIA triad: confidentiality, integrity, availability
- AAA: authentication, authorization, accounting
- Least privilege as a design default rather than an afterthought
Domain 2: Explain the Secure Software Development Lifecycle (22%)
The second-largest domain asks you to place security activities at the right stage of the lifecycle instead of bolting them on at the end.
- Threat modeling during design
- Abuse cases alongside use cases
- Security testing and review across requirements, design, build, test, and deployment
Domain 3: Develop Secure Code (33%)
The heaviest domain, and the one most directly tied to day-to-day developer work. It is where hands-on fluency pays off.
- Input validation and output encoding
- Authentication and authorization implementation
- Secrets management
- Reviewing AI-generated code for security flaws
Domain 4: Defending Against Cyberattacks (15%)
This domain connects coding decisions to the attacks they are meant to resist, including how testing tools and dependency hygiene reduce exposure.
- SAST, DAST, IAST, and SCA tooling and what each finds
- Dependency security
- Secure CI/CD and software supply chain security
Domain 5: Engage in Governance, Risk Management, and Compliance (15%)
Developers rarely work in a vacuum. This domain covers how security obligations, risk decisions, and compliance expectations shape engineering practice.
- Governance responsibilities that touch the development process
- Risk management as a basis for prioritizing fixes
- Compliance considerations relevant to software delivery
For a domain-by-domain walkthrough with additional context, see CSSD Exam Domains 2026: Complete Guide to All 5 Content Areas.
Concrete Topics You Must Master
The blueprint lists many specific topics, and it notes that its detailed examples are not an exhaustive list of everything that may be tested. Treat the list below as a floor, not a ceiling. Several clusters deserve focused attention.
Design-time thinking: threat modeling and abuse cases
Threat modeling asks "what could go wrong with this design, and who would cause it?" Abuse cases flip the usual requirements exercise: instead of describing how a legitimate user completes a task, you describe how a malicious actor misuses the same feature. A candidate should be able to explain why these activities are cheaper and more effective early in the lifecycle than after code ships.
Code-level defenses: validation, encoding, and identity
Input validation and output encoding are a matched pair. Validation controls what enters your system; encoding controls how data is rendered or interpreted when it leaves. Confusing the two is a classic exam trap. Authentication confirms who someone is, while authorization decides what that identity may do. Secrets management covers how credentials, keys, and tokens are stored and supplied so they never end up hardcoded in source or leaked through logs and repositories.
AI-generated code review
A distinctive feature of this blueprint is its attention to reviewing AI-generated code. The core idea is that code produced by an assistant deserves the same scrutiny as code written by a person, and sometimes more, because it can look polished while carrying insecure patterns, outdated dependencies, or missing validation. Be ready to reason about what a careful reviewer checks before accepting generated output.
Testing and pipeline security
Know the four testing acronyms and how they differ in what they inspect and when they run: SAST analyzes source without running it, DAST probes a running application from the outside, IAST observes behavior from within an instrumented application, and SCA inventories open-source components and flags known-vulnerable dependencies. Pair that with secure CI/CD practices and software supply chain security, where the concern is that the build and delivery path itself can be attacked.
Key Takeaway
Do not memorize tools as a list of acronyms. For each of SAST, DAST, IAST, and SCA, be able to say what it examines, at what stage it fits, and what kind of defect it is likely to miss. Scenario questions reward that comparison skill.
Access, Registration, and Cost Mechanics
The registration picture is refreshingly simple. There are no formal registration prerequisites, no application fee, no supporting documentation to assemble, and no eligibility verification step. CertNexus does recommend foundational security knowledge plus experience in software development, design, testing, and deployment, but it does not prescribe a particular programming language. You can approach the material from whatever language background you have.
The course access key includes the CHOICE credential process, so the learning and the credentialing path are bundled together. One complimentary retake is included if you do not pass the first time.
What the published prices actually represent
Two student digital course bundles are published through a courseware retailer:
- USD 514.50 for the bundle without lab (SKU CNX0022SEBU2, revision 1.0)
- USD 561.75 for the bundle with lab (SKU CNX0022SEBU, revision 1.0)
These are courseware-bundle prices. They have not been separately verified as exam-only fees, so do not read them as a standalone exam price. A small quirk worth knowing: the first listing is titled "Student Digital Course Bundle" even though its web address uses "instructor" wording. Confirm details on the product page at checkout. For a fuller treatment of budgeting, see CSSD Certification Cost 2026: Complete Pricing Breakdown, and for entry conditions see CSSD Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Who Should Pursue It and Who Hires for These Skills
The credential suits several overlapping groups:
- Software developers who want to formalize secure-coding habits and demonstrate them to employers.
- Application and product engineers responsible for design and testing decisions with security consequences.
- DevOps and platform engineers who own build pipelines and need to harden CI/CD and the software supply chain.
- Security-minded QA and test engineers who want to broaden into security testing methodologies.
- Early-career developers looking for a structured, vendor-neutral way to show security literacy.
Employers who value these skills tend to be organizations that build and ship their own software: product companies, software vendors, financial and healthcare technology firms, and teams in regulated industries where compliance pressure makes secure development a hiring criterion. Roles where the credential is relevant include secure software developer, application security engineer, DevSecOps engineer, and software engineer on security-conscious teams. Because no verified salary or hiring-volume figures are tied to this specific credential here, treat any dollar claims you encounter elsewhere with caution; the site's CSSD Salary Guide and CSSD Jobs pages discuss the career picture qualitatively, and Is the CSSD Certification Worth It? weighs the return on investment.
Validity and Renewal
CertNexus's general maintenance policy states that certifications are valid for three years and can be renewed by passing the current exam. Continuing education is available to eligible holders under the CertNexus Continuing Education Program. An important caveat: that program page does not establish CSSD-specific continuing-education eligibility or requirements. So the safe summary is the general policy, three-year validity and renewal by passing the current exam, and you should verify directly with CertNexus whether continuing education applies to your situation rather than assuming rules from any other credential.
Sequencing Your Preparation by Domain
Because the exam is short and the passing bar is high, the order in which you tackle domains matters more than the total number of hours. A sensible approach front-loads the foundations, then spends the most time where the blueprint pays the most.
Fundamentals and vocabulary (Domain 1)
- Lock in CIA, AAA, and least privilege so later scenarios make sense
- Read the full CSD-110 blueprint once, end to end
Lifecycle placement (Domain 2)
- Practice threat modeling and write abuse cases for a sample feature
- Map each security activity to a lifecycle stage
Secure coding depth (Domain 3)
- Spend the most time here given its 33% weight
- Drill validation versus encoding, authentication versus authorization, and secrets handling
- Practice spotting flaws in AI-generated code samples
Defense and governance (Domains 4 and 5)
- Compare SAST, DAST, IAST, and SCA by scope and timing
- Review secure CI/CD, supply chain risks, and governance and compliance basics
Finish with timed practice on multiple-response questions, since that format punishes partial knowledge. Our CSSD Study Guide 2026 expands this into a fuller plan, and the CSSD Cheat Sheet is useful for a last-pass review. When you are ready to test yourself under realistic conditions, the CSSD practice tests on the main site let you check your readiness domain by domain.
Frequently Asked Questions
It stands for Cyber Secure Software Developer, a CertNexus certification. The current exam is CSD-110. The acronym is used by other unrelated credentials, but none of their details apply to this one.
The exam has 25 multiple-choice and multiple-response questions, and the passing score is 80%, meaning 20 of 25 correct. One complimentary retake is included.
There are no formal registration prerequisites, application fee, supporting documentation, or eligibility verification. CertNexus recommends foundational security knowledge and experience in software development, design, testing, and deployment, with no required programming language.
Develop Secure Code is the largest at 33%, followed by the secure software development lifecycle at 22%. Together they account for more than half of the blueprint, so they deserve the largest share of your study time.
CertNexus's general maintenance policy gives three-year validity with renewal by passing the current exam. Continuing education may be available to eligible holders, but the program page does not confirm CSSD-specific requirements, so verify with CertNexus.