CSSLP · ● Active · Professional · ISC2
Exam facts
| Field | Value |
|---|---|
| Cost | $599 USD (GBP 479, EUR 555 in select regions) |
| Duration | 3 hours |
| Questions | 125 multiple choice |
| Passing | 700/1000 scaled |
| Format | Multiple choice |
| Delivery | Pearson VUE (testing center) |
| Languages | English |
| Valid | 3 years |
| Renewal | CPE credits (continuing professional education) |
| Prerequisites | 4 years experience in 1+ of 8 CSSLP domains (or 3 years + 4-year degree) |
| Released | ~2002 (current format ongoing) |
| Retiring | N/A |
Vendor source — ISC2 CSSLP ↗ Official exam outline — CSSLP Certification Exam Outline ↗ Experience requirements — CSSLP Experience Requirements ↗
About
The Certified Secure Software Lifecycle Professional (CSSLP) is an ISC2 professional-level credential validating expertise in secure software development, secure coding practices, threat modeling, security testing, and secure deployment. Designed for software developers, security architects, and DevSecOps engineers, the CSSLP tests mastery across eight domains of the Software Development Lifecycle (SDLC) from design through operations. Unlike foundational certifications like Security+, CSSLP focuses exclusively on application security and secure development practices, making it the specialized credential for engineers building security into software rather than managing infrastructure. The certification requires 4 years of SDLC experience (or 3 years + relevant degree) and is maintained through CPE credits over a 3-year validity period.
Domain context — Security
Application Security is the discipline of designing, building, and operating software that is resistant to attack, free of vulnerabilities, and secure-by-default. This spans threat modeling, secure design patterns, secure coding, code review and static analysis (SAST), dynamic testing (DAST), penetration testing, vulnerability management, and secure deployment practices. CSSLP validators demonstrate hands-on competency across the full SDLC, bridging development teams and security teams.
Read full deep dive — ISC2 Ecosystem →
Topics covered
The CSSLP exam is structured around eight domains of the ISC2 Certified Software Lifecycle Professional Common Body of Knowledge (CBK):
- Domain 1: Secure Software Concepts (10%) — Core concepts, security design principles, secure architecture models, threat classification, security standards and frameworks
- Domain 2: Secure Software Lifecycle Management (11%) — Security in SDLC governance, risk management, security requirements gathering, process integration
- Domain 3: Secure Software Requirements (12%) — Requirements definition and analysis, misuse and abuse cases, privacy requirements, security requirements traceability
- Domain 4: Secure Software Architecture and Design (16%) — Threat modeling, secure design patterns, secure API design, cryptographic design, authentication and authorization design
- Domain 5: Secure Software Implementation (16%) — Secure coding practices, code review, static analysis (SAST), security testing in development, secure build practices
- Domain 6: Secure Software Testing (14%) — Dynamic analysis (DAST), penetration testing, fuzzing, security test planning, vulnerability assessment
- Domain 7: Software Acceptance (7%) — Pre-release security assessment, acceptance criteria, deployment approval, sign-off
- Domain 8: Software Deployment, Operations, and Maintenance (14%) — Incident response for software, patching and updates, vulnerability management, secure configuration, logging and monitoring
Source: ISC2 CSSLP Certification Exam Outline ↗
Common skills at Security · Professional
Shared competencies for information security professionals at the Professional level.
- Designing and implementing threat models for software systems
- Identifying and remediating OWASP Top 10 and CWE vulnerabilities
- Evaluating secure design patterns and architecture decisions
- Conducting code review for security defects
- Planning and executing security testing (SAST, DAST, penetration testing)
- Advising development teams on secure coding practices and compliance requirements
- Managing vulnerability disclosure and patching workflows
Recommended courses at Security · Professional
| Provider | Title | Cost | URL |
|---|---|---|---|
| ISC2 Official | CSSLP Exam Preparation Course (Self-paced) | $399–$499 | ↗ |
| Udemy | CSSLP Secure Software Lifecycle Practice Exam Preparation | ~$15–$80 | ↗ |
| Udemy | ISC2 CSSLP Secure Software Lifecycle Mock Exams 2026 | ~$15–$80 | ↗ |
| Infosec Institute | ISC2 CSSLP Certification Training | $399–$799 | ↗ |
| LinkedIn Learning | ISC2 CSSLP Certification Training | Included with subscription | ↗ |
| QA | ISC2 Certified Secure Software Lifecycle Professional (QACSSLP) | Contact for pricing | ↗ |
Course-selection rule: Each course must be specifically for CSSLP (not generic ISC2 or general software security). Prefer ISC2-sanctioned or exam-focused prep courses over broad software security overviews.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| Boson Exsim | ISC2 CSSLP Practice Exam | $99–$149 | ↗ |
| Whizlabs | ISC2 CSSLP Practice Tests | $99 | ↗ |
| MeasureUp | ISC2 CSSLP Exam Practice Test | $129–$159 | ↗ |
| Tutorials Dojo | CSSLP Practice Exam Bundle | $49–$99 | ↗ |
| Infosec Institute | ISC2 CSSLP Practice Test | Included with course | ↗ |
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| The CSSLP Prep Guide | Budi Beltran | Sybex | 2024 | 978-1-119-82145-7 | ↗ |
| CSSLP Certification All-in-One Exam Guide, 2nd Edition | James Michael Stewart | McGraw-Hill | 2023 | 978-1-264-27234-5 | ↗ |
| The Software Security Handbook | Mikael Olsson | Independently Published | 2023 | N/A | ↗ |
| Secure Coding Handbook: 101 Best Practices and Lessons Learned | Graff & van Wyk | Sybex | 2023 | 978-1-119-99099-2 | ↗ |
| Threat Modeling: Designing for Security | Adam Shostack | Wiley | 2014 | 978-1118809990 | ↗ |
Typical job titles at Security · Professional
Application Security Engineer · Secure SDLC Architect · DevSecOps Engineer · Software Security Analyst · Security Engineer (AppSec) · Product Security Engineer · Security Architect (Software) · Code Security Reviewer
(Job titles drawn from current job-board postings that list CSSLP as required or preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $120K–$175K | Glassdoor ↗ · Robert Half ↗ · Levels.fyi ↗ |
| ZAR | R480K–R850K | Pnet ↗ · PayScale ZA ↗ · CareerJunction ↗ |
| GBP | £72K–£105K | IT Jobs Watch ↗ · Hays ↗ |
| EUR | €82K–€118K | StepStone DE/FR/NL ↗ · Michael Page ↗ |
| AUD | A$155K–A$215K | Seek ↗ · Hays Australia ↗ |
Salary rule: Ranges reflect application security and secure SDLC specialist roles. ZAR conversion uses approximate 1 USD = 18 ZAR rate (verify current exchange for accuracy).
Skills validated
Cert-specific — what the CSSLP exam actually tests.
- Threat modeling and attack surface analysis
- Secure design pattern implementation
- Cryptographic design principles and practices
- OWASP Top 10 vulnerability remediation
- Static Application Security Testing (SAST) tools and techniques
- Dynamic Application Security Testing (DAST) and penetration testing
- Secure code review methodologies
- Secure development lifecycle governance
- Security requirement definition and traceability
- API security design
- Vulnerability management and patching workflows
- Secure deployment and configuration management
- Security incident response for software systems
Related certifications
- Stacks with: CompTIA Security+ ↗ (foundational security knowledge)
- Prerequisite for: Advanced ISC2 certifications at Expert level (e.g., CISSP after gaining additional management experience)
- Equivalent at this level: GIAC GCES (GIAC Certified Enterprise Software Security Specialist) ↗
- Vendor overview: ISC2 Overview ↗
Sources
- ISC2 CSSLP Certification: https://www.isc2.org/certifications/csslp
- CSSLP Certification Exam Outline: https://www.isc2.org/certifications/csslp/csslp-certification-exam-outline
- CSSLP Experience Requirements: https://www.isc2.org/certifications/csslp/csslp-experience-requirements
- Infosec Institute CSSLP Overview: https://www.infosecinstitute.com/resources/csslp/
- Infosec Institute CSSLP Exam Details: https://www.infosecinstitute.com/resources/csslp/isc2-csslp-exam-details-and-process/
- TechTarget CSSLP Definition: https://www.techtarget.com/searchsecurity/definition/CSSLP-certified-secure-software-lifecycle-professional
- NICCS Training Catalog (CSSLP): https://niccs.cisa.gov/training/catalog/tpai/isc2-certified-secure-software-lifecycle-professional-csslp
Last verified: 2026-05-02 Parent ecosystem: ISC2 Ecosystem Parent domain: Security Domain Vendor overview: ISC2 Overview