Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Certification Guide

The Certified Secure Software Lifecycle Professional (CSSLP)
Certification Explained.

Everything you need to know about the ISC2 credential for secure software development as of 2026, covering the eight domains, the exam format, the four-year experience requirement, career paths, DoD 8140 status, and how CSSLP compares to CISSP and CompTIA PenTest+. A reference for developers, architects and application security engineers weighing the certification.

CSSLP_FAST_FACTS
Issuer: ISC2
Exam: 125 questions, 3 hours
Passing Score: 700 / 1000
Experience: 4 years in the domains
DoD 8140 Approved
8 CSSLP Domains 4 YRS Experience Required 125 Exam Questions 3-HOUR Linear Exam SEPT 2023 Current Outline
UPDATED 2026
Overview

What Is the Certified Secure Software Lifecycle Professional (CSSLP)?

CSSLP is the ISC2 certification for people who build software, not for people who run a security program.

Its eight domains follow the software development lifecycle in order: concepts, lifecycle management, requirements, architecture and design, implementation, testing, deployment and operations, and the supply chain. That is a deliberate structure. The credential is built on the idea that security is a property of how software gets specified, designed, written, tested and shipped, so the exam walks that path rather than surveying the security field.

The credential is ANAB-accredited under ISO/IEC 17024, listed by ISC2 as approved by the Department of Defense under DoDM 8140.03, and gated behind four years of software lifecycle experience. CSSLP is issued and maintained by ISC2, the same body behind CISSP and CCSP.

8 Domains
125 Exam Items
4 Yr Experience
The CSSLP Domains

Eight Domains, One Lifecycle

01

Secure Software Concepts

Core security principles applied to software. 12% of the exam.

02

Lifecycle Management

Security inside agile or waterfall, with metrics and checkpoints. 11%.

03

Secure Software Requirements

Data classification, privacy, misuse cases, traceability. 13% of the exam.

04

Architecture and Design

Design patterns, threat modeling, architectural risk. The heaviest domain at 15%.

05

Secure Implementation

Secure coding, validation, crypto, code review, anti-tampering. 14%.

06

Secure Software Testing

Test strategy, DAST, penetration testing, fuzzing, results analysis. 14%.

07

Deployment and Operations

CI/CD, secrets, monitoring, incident response, patching. 11% of the exam.

08

Secure Software Supply Chain

Third-party components, SBOM, provenance, supplier terms. 10%.

Why CSSLP Matters

Why Is CSSLP So Widely Recognized?

Four reasons the credential keeps its place on job descriptions for software and application security work.

Built Around the Lifecycle, Not the Job Title

Most security certifications organize themselves around security functions. CSSLP organizes itself around how software actually gets made: requirements, then design, then code, then tests, then release, then everything you inherited from a package registry. That structure is why it maps so cleanly onto the work of a development team.

Carries the ISC2 Name

CSSLP comes from the body behind CISSP and CCSP. Hiring managers who already recognize those two do not need the acronym explained, which matters for a specialty credential that fewer people hold.

Supply Chain Is Its Own Domain

Software bills of materials, component provenance and supplier security terms get a full domain worth 10 percent of the exam. Few credentials treat third-party code as a first-class subject, and it is now where a large share of software risk sits.

Approved Under DoD 8140

ISC2 lists CSSLP as approved by the Department of Defense under DoD Manual 8140.03. That approval matters for federal and contractor software work, where an unqualified person cannot be assigned to a cyber work role.

Which DoD Cyber Workforce Framework work roles CSSLP satisfies, and at what proficiency level, is decided by the qualification matrix rather than by ISC2. We are not listing individual work roles here because the matrix is revised periodically. Check the current version at the DoD Cyber Exchange before you rely on it for a specific billet.

DoDM 8140.03 Approved ISO/IEC 17024 Accredited ANAB Listed
Fast Facts

What Are the Key Facts About CSSLP?

The certification, the exam structure, and what it takes to keep CSSLP current, as ISC2 publishes them in 2026.

01

The Certification

Certification Name
Certified Secure Software Lifecycle Professional (CSSLP)
Issued By
ISC2
Exam Outline
Effective September 15, 2023
Domains
8, following the development lifecycle
Prerequisites
4 yrs in one or more CSSLP domains
Experience Waiver
1 year for a relevant degree
No-Experience Path
Pass and hold Associate of ISC2
Accreditation
ANAB-accredited (ISO/IEC 17024)
DoD 8140 Status
Approved under DoDM 8140.03
02

Exam & Maintenance

Exam Format
Linear, fixed form (not adaptive)
Number of Items
125 questions
Item Types
Multiple choice plus advanced items
Exam Duration
3 hours
Passing Score
700 out of 1000
Delivery
Pearson VUE test center, English
Exam Cost
~$599 USD
Validity
3 years
CPE Requirement
90 CPEs over 3 years, 60 in Group A
Maintenance Fee
$135 annual maintenance fee to ISC2
Going Deeper

What Comes After the CSSLP?

CSSLP proves you can build software securely. From there people usually widen out into enterprise security, move deeper into architecture, or pick up the offensive skills that make design reviews sharper.

CISSP (Breadth)

The ISC2 flagship covers all eight security domains, from governance to operations. It is the usual move for a CSSLP holder who starts owning security decisions beyond the codebase. It asks five years of experience in two or more of its domains.

ISSAP (Architecture)

ISC2's standalone architecture certification goes deeper on designing systems and their controls, and a CISSP is one of the two ways to qualify for it. A natural continuation for anyone whose CSSLP work centered on Domain 4.

PenTest+ (Offense)

Hands-on penetration testing from CompTIA. Useful for CSSLP holders who want to see how their designs fail in practice rather than only reason about it. Read the full PenTest+ guide.

Certification Roadmap

Where Does CSSLP Fit in Your Career?

CSSLP is the specialist credential for the build side of security. It sits above general security fundamentals and leads either into broad security leadership or into deeper architecture and offensive work.

STAGE 02 You Are Here

Software Credential

The specialty

PRIMARY
CSSLP
ISC2 ยท Certified Secure Software Lifecycle Professional
Associate of ISC2
ISC2 ยท Pass first, earn experience after
STAGE 03

Specialize

Pick your path

Broad Security
Build and Break
Decision Point

Is CSSLP Right For You?

Two questions to settle before you commit: can you certify, and should you pick CSSLP over the alternatives. Here is a straight answer to both.

Q1

Do You Qualify for CSSLP?

Path A

4+ Years in the Software Lifecycle

You can certify in full.

You have four years of cumulative, full-time experience in one or more of the eight CSSLP domains. Note the wording: one or more, so four years spent entirely in secure coding or entirely in software testing counts. A post-secondary degree in computer science, information technology or a related field covers one of those four years. Part-time work and internships count on a pro-rated basis. Pass the exam, get endorsed, and you hold the full CSSLP.

Path B

Fewer Than 4 Years So Far

You can still pass now.

Sit the exam without the experience and you become an Associate of ISC2 once you pass. From there you have five years to accumulate the four years of experience and convert to full CSSLP. Associates pay a $50 annual maintenance fee, earn 15 CPE credits a year, and pay an $85 upgrade fee at conversion, so the exam never has to wait on your resume.

Q2

Is CSSLP the Right Certification for Your Goals?

CSSLP Is a Strong Fit If...

  • You write, review, design or test software, and security is part of that job rather than a separate one
  • You run or want to run an application security program, a secure SDLC, or the security gates in a CI/CD pipeline
  • You are an architect who does threat modeling and design review and wants a credential that names that work
  • You handle third-party and open source risk, software bills of materials, or supplier security terms
  • You need a DoD 8140 approved credential for software work in a federal or contractor setting
  • You hold CISSP already and want to show depth on the build side rather than the program side

Consider Alternatives If...

  • You want to run a security program rather than build software, where CISSP is the broader and better known credential
  • You are early in your career with no security fundamentals yet, where Security+ is the sensible first step
  • Your interest is breaking applications rather than building them, where PenTest+ is hands-on and closer to the work
  • Your work is cloud infrastructure rather than application code, where CCSP fits better
  • You need a credential recruiters screen for by keyword volume, since CSSLP appears on fewer job postings than CISSP does
  • You do not work on or near software, in which case most of the eight domains will stay abstract
Career Paths

What Jobs Can You Get With CSSLP?

ISC2 aims CSSLP at software architects, engineers, developers, application security specialists, program managers, QA testers, penetration testers, procurement analysts and IT managers. These six are where it shows up most.

Application Security

Application Security Engineer

Reviews code, runs the SAST and DAST tooling, triages what comes back and works with developers on the fix. CSSLP tracks that work closely, because requirements, implementation and testing are three separate domains on the exam.

Architecture

Secure Software Architect

Picks the patterns, trust boundaries and controls a system is built on. Domain 4 is the heaviest on the exam at 15 percent and covers exactly this: threat modeling, secure design patterns and architectural risk assessment.

Engineering

DevSecOps Engineer

Puts the gates in the pipeline: dependency scanning, secrets handling, signed builds, policy as code. Domain 7 covers CI/CD release practices, secrets and keys, monitoring and patch management directly.

Development

Software Developer

Writes the code the controls live in. CSSLP is one of the few security credentials aimed at developers rather than analysts, and Domain 5 is about validation, session handling, crypto use, access control and code review.

Product Security

Product Security Engineer

Owns security for a product line from requirements through release and patching. The eight domains run in that same order, which is why the credential reads clearly for this kind of role.

Program Management

Software Program Manager

Runs the secure development program across teams: standards, tooling, metrics, training and supplier requirements. Domain 2 covers lifecycle management and Domain 8 covers the supply chain, both central to the job.

Comparison

How Does CSSLP Compare to CISSP and PenTest+?

Three credentials, three relationships to software. CSSLP builds it, CISSP governs it, PenTest+ attacks it. Here is how they line up.

  CSSLP CISSP PenTest+
Issuer ISC2 ISC2 CompTIA
Focus Building software securely Running a security program Testing systems by attacking them
Audience Developers, architects, AppSec, DevSecOps Security managers and senior generalists Penetration testers and red teamers
Domains 8, following the SDLC 8, spanning all of security 5, following an engagement
Exam Format Linear, 125 items, 3 hrs Adaptive, 100 to 150 items, 3 hrs 90 items max, 165 min, MC plus PBQ
Experience 4 yrs in 1+ CSSLP domain 5 yrs in 2+ CISSP domains None required, 3 to 4 yrs suggested
Passing Score 700 / 1000 700 / 1000 750 of 900
Exam Cost ~$599 USD ~$749 USD ~$439 USD
Renewal 90 CPEs over 3 years 120 CPEs over 3 years 60 CEUs over 3 years
DoD 8140 Approved Yes Yes Yes
Best For People who ship code People who own the security function People who test what others shipped

Prices and renewal terms vary by region and membership status. The audience split is the thing to weigh: CSSLP is a build-side credential, CISSP is a program-side credential, and holding both is common for people who moved from engineering into security leadership.

Ready to Get Certified?

Train for CSSLP with Training Camp.

Our official ISC2 CSSLP boot camp covers all eight domains over five days, with authorized ISC2 courseware, your exam voucher and a free retake guarantee included, so practitioners leave exam-ready.

View Boot Camp
Dive Deeper

CSSLP Articles and Guides.

The Associate route, how CSSLP relates to the rest of the ISC2 family, DoD 8140, and where these roles sit on pay.

Featured Certification Path

Becoming an Associate of ISC2: A Comprehensive Guide

The route most people take when they can pass the CSSLP exam before they have four years of lifecycle experience. How the Associate designation works, what it costs, and how you convert it.

Read Article โ†’
Career Path

What Comes After CISSP? Top Certifications to Advance Your Career

For CISSP holders whose work sits close to engineering teams, CSSLP is one of the specializations that follows. A look at where each of the usual next steps leads.

Read Article โ†’
ISC2 Foundation

Complete CISSP Guide

A full walkthrough of the ISC2 flagship credential. Useful context for deciding whether you want the broad security credential, the software one, or both.

Read Article โ†’
DoD 8140

Which Certifications Qualify for DoD 8140 Work Roles? A DCWF Map

How commercial certifications line up against DoD Cyber Workforce Framework work roles, and where the software engineering element sits in the qualification matrix.

Read Article โ†’
Salary and Demand

Highest Paid Cybersecurity Jobs: Careers with Top Earning Potential

Where application security and secure development roles land against the rest of the field, with the figures and their sources laid out.

Read Article โ†’
Federal Work

What Cybersecurity Certifications Do Government Contractors Actually Require?

What shows up in real contract language rather than in marketing copy, and why an approved credential matters when the work is federal.

Read Article โ†’
Landscape

Top 15 Cyber Security Certifications

A survey of the credentials employers name most often, useful for placing CSSLP against the broader security certification landscape before you commit.

Read Article โ†’
Curriculum

Inside the Eight CSSLP Domains.

The CSSLP Common Body of Knowledge is organized into eight domains that run in lifecycle order, each carrying its own weight on the exam. Click any domain for what it covers.

Domains 01-04

Concepts to Design
01 Secure Software Concepts 12%

The security fundamentals a developer is expected to apply without being told: confidentiality, integrity, availability, authentication, authorization and accountability, plus design principles such as least privilege, separation of duties, defense in depth, economy of mechanism and complete mediation.

02 Secure Software Lifecycle Management 11%

Fitting security into whichever methodology the team already uses, agile or waterfall. Security milestones and checkpoints, documentation, metrics such as average remediation time, decommissioning and end-of-life policy, and risk management across the whole lifecycle.

03 Secure Software Requirements 13%

Turning security into something written down and testable. Functional and non-functional security requirements, data classification, privacy and regulatory obligations, misuse and abuse cases, and a security requirements traceability matrix.

04 Secure Software Architecture and Design 15%

The heaviest domain. Secure design patterns, distributed and service-oriented architectures, cloud service models, mobile, embedded and IoT considerations, secure interface design, threat modeling with methods such as STRIDE and PASTA, and architectural risk assessment.

Domains 05-08

Code to Supply Chain
05 Secure Software Implementation 14%

The code itself. Secure coding standards, input validation and output sanitization, session management, error handling, cryptography, access control and trust zones, static analysis and manual code review, and anti-tampering work such as code signing and obfuscation.

06 Secure Software Testing 14%

Proving the controls actually hold. Test strategy and security test cases, functional and non-functional security testing, DAST and other automated vulnerability testing, penetration testing, fuzzing, cryptographic validation, and reading the results for real risk.

07 Secure Software Deployment, Operations, Maintenance 11%

Shipping it and keeping it safe. Secure configuration and version control, CI/CD and DevSecOps release practices, handling credentials, secrets and keys, continuous monitoring, incident response, patch and vulnerability management, runtime protection such as RASP and WAF, and continuity planning.

08 Secure Software Supply Chain 10%

The code nobody on your team wrote. Supply chain risk management, component selection and assessment, maintaining a software bill of materials, verifying pedigree and provenance, supplier security requirements in acquisition, and the contractual side of third-party software.

Domains and weights reflect the ISC2 CSSLP Exam Outline effective September 15, 2023, the version ISC2 administers today.

Frequently Asked Questions

Common Questions About CSSLP.

The questions candidates ask most often when researching the Certified Secure Software Lifecycle Professional certification.

What is the CSSLP certification?

CSSLP is the ISC2 credential for building software securely. It covers eight domains that follow the software development lifecycle, from concepts and requirements through architecture, coding, testing, deployment and the supply chain. It is aimed at the people who design and write software rather than at the people who run a security program.

Who should get the CSSLP?

CSSLP fits developers, application security engineers, software architects, DevSecOps engineers, QA and product security staff, and the program managers who own secure development. ISC2 also names software procurement analysts, project managers and IT managers among its audience. It is not an entry-level credential and it assumes you already work on software.

How much does the CSSLP exam cost in 2026?

The CSSLP exam costs approximately $599 USD as of 2026, set by ISC2 and varying slightly by region. The fee covers the exam itself, not training or study materials. Many boot camps fold the exam voucher into the course price, so check what is included before you pay separately.

What is the CSSLP exam like?

The CSSLP is a linear, fixed-form exam of 125 items over three hours, delivered at Pearson VUE test centers in English. It mixes standard multiple choice with advanced item types, and you need a scaled score of 700 out of 1000 to pass. Unlike CISSP and CCSP it is not adaptive, so the length does not change based on how you are answering.

What experience do you need for the CSSLP?

CSSLP requires four years of cumulative, full-time work experience in one or more of the eight CSSLP domains. A post-secondary degree in computer science, information technology or a related field satisfies one year of that requirement. Part-time work and paid or unpaid internships count on a pro-rated basis.

Can you take the CSSLP exam without experience?

Yes. Pass the exam without the four years and you can become an Associate of ISC2. From there you have five years to earn the four years of experience and convert to full CSSLP status. Associates pay a $50 annual maintenance fee, earn 15 CPE credits a year, and pay an $85 upgrade fee on conversion.

What are the eight CSSLP domains?

The eight domains are Secure Software Concepts at 12 percent, Secure Software Lifecycle Management at 11 percent, Secure Software Requirements at 13 percent, Secure Software Architecture and Design at 15 percent, Secure Software Implementation at 14 percent, Secure Software Testing at 14 percent, Secure Software Deployment, Operations, Maintenance at 11 percent, and Secure Software Supply Chain at 10 percent. Architecture and Design carries the most weight.

How do I maintain my CSSLP certification?

CSSLP runs on a three-year cycle. You earn 90 Continuing Professional Education credits across the cycle, at least 60 of which must be Group A credits tied to the CSSLP domains, and you pay the ISC2 annual maintenance fee of $135. ISC2 suggests 30 credits a year but sets no hard annual minimum for certified members.

Is CSSLP approved for DoD 8140?

Yes. ISC2 lists CSSLP as approved by the Department of Defense under DoDM 8140.03. Which DCWF work roles it covers, and at which proficiency level, is set by the DoD 8140 qualification matrix rather than by ISC2, so check the current matrix at the DoD Cyber Exchange before relying on it for a specific role.

What is the difference between CSSLP and CISSP?

Both are ISC2 credentials, but they answer different questions. CISSP is about running security across an organization, spanning eight broad domains from risk management to security operations. CSSLP is about building software securely, spanning eight domains that follow the development lifecycle. CISSP asks for five years of experience in two or more of its domains; CSSLP asks for four years of software lifecycle work. If you design, write or ship code, CSSLP is the closer fit.

Which CSSLP exam outline is current?

The outline in force took effect September 15, 2023. It renamed several domains and rebalanced the weights, and it is the version ISC2 administers today. ISC2 has announced no replacement outline and has not moved CSSLP to adaptive testing. Check that any study material you buy matches this outline rather than an older one.

Is CSSLP worth it in 2026?

If your work is building software rather than running a security program, CSSLP is one of the few credentials that says so on its face. It is approved under DoD 8140, ANAB-accredited under ISO/IEC 17024, and its domains line up with real application security and DevSecOps work. It is a poor fit if you do not touch software, where CISSP or a specialist security track will serve you better.

Get In Touch

Have Questions About CSSLP?

Whether you are weighing the certification, working out funding, or planning training for a development team, tell us where you are and we will help you map out the right path.

+1
    100% Secure. NDA Compliant.
    ISC2 CSSLP Boot Camp 5-Day Boot Camp ยท Exam Voucher Included
    View Boot Camp