CSSLP (Certified Secure Software Lifecycle Professional)
The CSSLP is about building security practices such as authentication, authorization and auditing into each phase of the software development lifecycle, including requirements, design, testing, deployment and the software supply chain. Its audience is software and application security professionals.
Exam Details
Fixed-length English exam with multiple choice and advanced item types at Pearson VUE test centers.
Standard registration in the Americas, Asia Pacific, Middle East and Africa. ISC2 also lists EUR 575.04 for EMEA and GBP 485.19 for the UK. Currency and taxes depend on the exam location.
Requirements and Renewal
Prerequisites
Four years of cumulative, full-time experience in one or more of the eight CSSLP domains. A relevant degree can count for one year. Candidates who pass without the experience can become an Associate of ISC2 for up to five years.
Renewal
90 CPE credits per three-year cycle (60 Group A, 30 Group A or B) and a U.S. $135 annual maintenance fee.
Current Version
CSSLP Exam Outline effective September 15, 2023, in effect since Sep 15, 2023.
Exam Domains
8 domains| Domain | Weight |
|---|---|
| Secure Software Concepts | 12% |
| Secure Software Lifecycle Management | 11% |
| Secure Software Requirements | 13% |
| Secure Software Architecture and Design | 15% |
| Secure Software Implementation | 14% |
| Secure Software Testing | 14% |
| Secure Software Deployment, Operations, Maintenance | 11% |
| Secure Software Supply Chain | 10% |
DoD 8140 Work Roles
4 work rolesThe DoD 8140 Qualification Matrix V2.1 lists CSSLP as a foundational qualification option for these DoD Cyber Workforce Framework work roles, up to the proficiency level shown. Lower levels of the same work role are also covered.
Related Tool Categories
Frequently Asked Questions
What does CSSLP stand for?→
CSSLP stands for Certified Secure Software Lifecycle Professional, an ISC2 certification focused on security across the software development lifecycle.
What experience is required for the CSSLP?→
Four years of full-time experience in at least one CSSLP domain. A bachelor's or master's degree in computer science, IT or a related field can satisfy one of those years.
Does the CSSLP cover software supply chain security?→
Yes. Secure Software Supply Chain is the eighth domain of the current outline and carries 10% of the exam weight.
How long is the CSSLP exam?→
It has 125 items, a 3-hour limit and a passing grade of 700 out of 1000 points.
Sources
Exam details are checked against official ISC2 pages. Fees, exam versions, and renewal rules change; confirm with ISC2 before registering. CSSLP is a trademark of its owner. This site is not affiliated with or endorsed by ISC2.