Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about the ISC2 credential for secure software development as of 2026, covering the eight domains, the exam format, the four-year experience requirement, career paths, DoD 8140 status, and how CSSLP compares to CISSP and CompTIA PenTest+. A reference for developers, architects and application security engineers weighing the certification.
CSSLP is the ISC2 certification for people who build software, not for people who run a security program.
Its eight domains follow the software development lifecycle in order: concepts, lifecycle management, requirements, architecture and design, implementation, testing, deployment and operations, and the supply chain. That is a deliberate structure. The credential is built on the idea that security is a property of how software gets specified, designed, written, tested and shipped, so the exam walks that path rather than surveying the security field.
The credential is ANAB-accredited under ISO/IEC 17024, listed by ISC2 as approved by the Department of Defense under DoDM 8140.03, and gated behind four years of software lifecycle experience. CSSLP is issued and maintained by ISC2, the same body behind CISSP and CCSP.
Core security principles applied to software. 12% of the exam.
Security inside agile or waterfall, with metrics and checkpoints. 11%.
Data classification, privacy, misuse cases, traceability. 13% of the exam.
Design patterns, threat modeling, architectural risk. The heaviest domain at 15%.
Secure coding, validation, crypto, code review, anti-tampering. 14%.
Test strategy, DAST, penetration testing, fuzzing, results analysis. 14%.
CI/CD, secrets, monitoring, incident response, patching. 11% of the exam.
Third-party components, SBOM, provenance, supplier terms. 10%.
Four reasons the credential keeps its place on job descriptions for software and application security work.
Most security certifications organize themselves around security functions. CSSLP organizes itself around how software actually gets made: requirements, then design, then code, then tests, then release, then everything you inherited from a package registry. That structure is why it maps so cleanly onto the work of a development team.
Software bills of materials, component provenance and supplier security terms get a full domain worth 10 percent of the exam. Few credentials treat third-party code as a first-class subject, and it is now where a large share of software risk sits.
ISC2 lists CSSLP as approved by the Department of Defense under DoD Manual 8140.03. That approval matters for federal and contractor software work, where an unqualified person cannot be assigned to a cyber work role.
Which DoD Cyber Workforce Framework work roles CSSLP satisfies, and at what proficiency level, is decided by the qualification matrix rather than by ISC2. We are not listing individual work roles here because the matrix is revised periodically. Check the current version at the DoD Cyber Exchange before you rely on it for a specific billet.
The certification, the exam structure, and what it takes to keep CSSLP current, as ISC2 publishes them in 2026.
CSSLP proves you can build software securely. From there people usually widen out into enterprise security, move deeper into architecture, or pick up the offensive skills that make design reviews sharper.
The ISC2 flagship covers all eight security domains, from governance to operations. It is the usual move for a CSSLP holder who starts owning security decisions beyond the codebase. It asks five years of experience in two or more of its domains.
ISC2's standalone architecture certification goes deeper on designing systems and their controls, and a CISSP is one of the two ways to qualify for it. A natural continuation for anyone whose CSSLP work centered on Domain 4.
Hands-on penetration testing from CompTIA. Useful for CSSLP holders who want to see how their designs fail in practice rather than only reason about it. Read the full PenTest+ guide.
CSSLP is the specialist credential for the build side of security. It sits above general security fundamentals and leads either into broad security leadership or into deeper architecture and offensive work.
Build the baseline
The specialty
Two questions to settle before you commit: can you certify, and should you pick CSSLP over the alternatives. Here is a straight answer to both.
You can certify in full.
You have four years of cumulative, full-time experience in one or more of the eight CSSLP domains. Note the wording: one or more, so four years spent entirely in secure coding or entirely in software testing counts. A post-secondary degree in computer science, information technology or a related field covers one of those four years. Part-time work and internships count on a pro-rated basis. Pass the exam, get endorsed, and you hold the full CSSLP.
You can still pass now.
Sit the exam without the experience and you become an Associate of ISC2 once you pass. From there you have five years to accumulate the four years of experience and convert to full CSSLP. Associates pay a $50 annual maintenance fee, earn 15 CPE credits a year, and pay an $85 upgrade fee at conversion, so the exam never has to wait on your resume.
ISC2 aims CSSLP at software architects, engineers, developers, application security specialists, program managers, QA testers, penetration testers, procurement analysts and IT managers. These six are where it shows up most.
Reviews code, runs the SAST and DAST tooling, triages what comes back and works with developers on the fix. CSSLP tracks that work closely, because requirements, implementation and testing are three separate domains on the exam.
Picks the patterns, trust boundaries and controls a system is built on. Domain 4 is the heaviest on the exam at 15 percent and covers exactly this: threat modeling, secure design patterns and architectural risk assessment.
Puts the gates in the pipeline: dependency scanning, secrets handling, signed builds, policy as code. Domain 7 covers CI/CD release practices, secrets and keys, monitoring and patch management directly.
Writes the code the controls live in. CSSLP is one of the few security credentials aimed at developers rather than analysts, and Domain 5 is about validation, session handling, crypto use, access control and code review.
Owns security for a product line from requirements through release and patching. The eight domains run in that same order, which is why the credential reads clearly for this kind of role.
Runs the secure development program across teams: standards, tooling, metrics, training and supplier requirements. Domain 2 covers lifecycle management and Domain 8 covers the supply chain, both central to the job.
Three credentials, three relationships to software. CSSLP builds it, CISSP governs it, PenTest+ attacks it. Here is how they line up.
| CSSLP | CISSP | PenTest+ | |
|---|---|---|---|
| Issuer | ISC2 | ISC2 | CompTIA |
| Focus | Building software securely | Running a security program | Testing systems by attacking them |
| Audience | Developers, architects, AppSec, DevSecOps | Security managers and senior generalists | Penetration testers and red teamers |
| Domains | 8, following the SDLC | 8, spanning all of security | 5, following an engagement |
| Exam Format | Linear, 125 items, 3 hrs | Adaptive, 100 to 150 items, 3 hrs | 90 items max, 165 min, MC plus PBQ |
| Experience | 4 yrs in 1+ CSSLP domain | 5 yrs in 2+ CISSP domains | None required, 3 to 4 yrs suggested |
| Passing Score | 700 / 1000 | 700 / 1000 | 750 of 900 |
| Exam Cost | ~$599 USD | ~$749 USD | ~$439 USD |
| Renewal | 90 CPEs over 3 years | 120 CPEs over 3 years | 60 CEUs over 3 years |
| DoD 8140 Approved | Yes | Yes | Yes |
| Best For | People who ship code | People who own the security function | People who test what others shipped |
Prices and renewal terms vary by region and membership status. The audience split is the thing to weigh: CSSLP is a build-side credential, CISSP is a program-side credential, and holding both is common for people who moved from engineering into security leadership.
Our official ISC2 CSSLP boot camp covers all eight domains over five days, with authorized ISC2 courseware, your exam voucher and a free retake guarantee included, so practitioners leave exam-ready.
The Associate route, how CSSLP relates to the rest of the ISC2 family, DoD 8140, and where these roles sit on pay.
The route most people take when they can pass the CSSLP exam before they have four years of lifecycle experience. How the Associate designation works, what it costs, and how you convert it.
For CISSP holders whose work sits close to engineering teams, CSSLP is one of the specializations that follows. A look at where each of the usual next steps leads.
A full walkthrough of the ISC2 flagship credential. Useful context for deciding whether you want the broad security credential, the software one, or both.
How commercial certifications line up against DoD Cyber Workforce Framework work roles, and where the software engineering element sits in the qualification matrix.
Where application security and secure development roles land against the rest of the field, with the figures and their sources laid out.
What shows up in real contract language rather than in marketing copy, and why an approved credential matters when the work is federal.
A survey of the credentials employers name most often, useful for placing CSSLP against the broader security certification landscape before you commit.
The CSSLP Common Body of Knowledge is organized into eight domains that run in lifecycle order, each carrying its own weight on the exam. Click any domain for what it covers.
The security fundamentals a developer is expected to apply without being told: confidentiality, integrity, availability, authentication, authorization and accountability, plus design principles such as least privilege, separation of duties, defense in depth, economy of mechanism and complete mediation.
Fitting security into whichever methodology the team already uses, agile or waterfall. Security milestones and checkpoints, documentation, metrics such as average remediation time, decommissioning and end-of-life policy, and risk management across the whole lifecycle.
Turning security into something written down and testable. Functional and non-functional security requirements, data classification, privacy and regulatory obligations, misuse and abuse cases, and a security requirements traceability matrix.
The heaviest domain. Secure design patterns, distributed and service-oriented architectures, cloud service models, mobile, embedded and IoT considerations, secure interface design, threat modeling with methods such as STRIDE and PASTA, and architectural risk assessment.
The code itself. Secure coding standards, input validation and output sanitization, session management, error handling, cryptography, access control and trust zones, static analysis and manual code review, and anti-tampering work such as code signing and obfuscation.
Proving the controls actually hold. Test strategy and security test cases, functional and non-functional security testing, DAST and other automated vulnerability testing, penetration testing, fuzzing, cryptographic validation, and reading the results for real risk.
Shipping it and keeping it safe. Secure configuration and version control, CI/CD and DevSecOps release practices, handling credentials, secrets and keys, continuous monitoring, incident response, patch and vulnerability management, runtime protection such as RASP and WAF, and continuity planning.
The code nobody on your team wrote. Supply chain risk management, component selection and assessment, maintaining a software bill of materials, verifying pedigree and provenance, supplier security requirements in acquisition, and the contractual side of third-party software.
Domains and weights reflect the ISC2 CSSLP Exam Outline effective September 15, 2023, the version ISC2 administers today.
The questions candidates ask most often when researching the Certified Secure Software Lifecycle Professional certification.
CSSLP is the ISC2 credential for building software securely. It covers eight domains that follow the software development lifecycle, from concepts and requirements through architecture, coding, testing, deployment and the supply chain. It is aimed at the people who design and write software rather than at the people who run a security program.
CSSLP fits developers, application security engineers, software architects, DevSecOps engineers, QA and product security staff, and the program managers who own secure development. ISC2 also names software procurement analysts, project managers and IT managers among its audience. It is not an entry-level credential and it assumes you already work on software.
The CSSLP exam costs approximately $599 USD as of 2026, set by ISC2 and varying slightly by region. The fee covers the exam itself, not training or study materials. Many boot camps fold the exam voucher into the course price, so check what is included before you pay separately.
The CSSLP is a linear, fixed-form exam of 125 items over three hours, delivered at Pearson VUE test centers in English. It mixes standard multiple choice with advanced item types, and you need a scaled score of 700 out of 1000 to pass. Unlike CISSP and CCSP it is not adaptive, so the length does not change based on how you are answering.
CSSLP requires four years of cumulative, full-time work experience in one or more of the eight CSSLP domains. A post-secondary degree in computer science, information technology or a related field satisfies one year of that requirement. Part-time work and paid or unpaid internships count on a pro-rated basis.
Yes. Pass the exam without the four years and you can become an Associate of ISC2. From there you have five years to earn the four years of experience and convert to full CSSLP status. Associates pay a $50 annual maintenance fee, earn 15 CPE credits a year, and pay an $85 upgrade fee on conversion.
The eight domains are Secure Software Concepts at 12 percent, Secure Software Lifecycle Management at 11 percent, Secure Software Requirements at 13 percent, Secure Software Architecture and Design at 15 percent, Secure Software Implementation at 14 percent, Secure Software Testing at 14 percent, Secure Software Deployment, Operations, Maintenance at 11 percent, and Secure Software Supply Chain at 10 percent. Architecture and Design carries the most weight.
CSSLP runs on a three-year cycle. You earn 90 Continuing Professional Education credits across the cycle, at least 60 of which must be Group A credits tied to the CSSLP domains, and you pay the ISC2 annual maintenance fee of $135. ISC2 suggests 30 credits a year but sets no hard annual minimum for certified members.
Yes. ISC2 lists CSSLP as approved by the Department of Defense under DoDM 8140.03. Which DCWF work roles it covers, and at which proficiency level, is set by the DoD 8140 qualification matrix rather than by ISC2, so check the current matrix at the DoD Cyber Exchange before relying on it for a specific role.
Both are ISC2 credentials, but they answer different questions. CISSP is about running security across an organization, spanning eight broad domains from risk management to security operations. CSSLP is about building software securely, spanning eight domains that follow the development lifecycle. CISSP asks for five years of experience in two or more of its domains; CSSLP asks for four years of software lifecycle work. If you design, write or ship code, CSSLP is the closer fit.
The outline in force took effect September 15, 2023. It renamed several domains and rebalanced the weights, and it is the version ISC2 administers today. ISC2 has announced no replacement outline and has not moved CSSLP to adaptive testing. Check that any study material you buy matches this outline rather than an older one.
If your work is building software rather than running a security program, CSSLP is one of the few credentials that says so on its face. It is approved under DoD 8140, ANAB-accredited under ISO/IEC 17024, and its domains line up with real application security and DevSecOps work. It is a poor fit if you do not touch software, where CISSP or a specialist security track will serve you better.
Whether you are weighing the certification, working out funding, or planning training for a development team, tell us where you are and we will help you map out the right path.