If you build, test, or secure software for a living, the Certified Secure Software Lifecycle Professional (CSSLP)® from ISC2 is the credential that proves you can bake security into every phase of development, not bolt it on at the end. The exam covers a lot of ground, from threat modeling to supplier contracts, so it’s normal to feel a little overwhelmed at first. The good news is that ISC2 publishes exactly what it tests, and a study plan built around that blueprint gives you a clear path to passing on your first try.
In this guide, we’ll walk you through the exam format, all eight domains and their weights, the official resources worth using, and answers to the questions candidates ask most.
What Is the ISC2 CSSLP Exam?
The CSSLP is ISC2’s credential for professionals who are responsible for application security across the entire software development lifecycle (SDLC). ANAB accredits it to ISO/IEC 17024, and it’s approved under U.S. Department of Defense Manual 8140.03, making it a recognized credential for many government and contractor roles.
The exam isn’t a coding test, and it isn’t tied to any one programming language. Instead, it asks you to apply secure development principles to realistic situations: which requirement is missing, which design control best reduces a threat, which test would catch a flaw, or what should happen before a release goes to production. Think like a security-minded architect or lead who must balance risk, cost, and business needs.
What Is the ISC2 CSSLP Exam Format?
Here’s the exam at a glance, based on the ISC2 CSSLP Certification Exam Outline and the ISC2 CSSLP Ultimate Guide:
- Questions: 125 items.
- Time: Up to 3 hours (180 minutes).
- Question types: Multiple choice plus advanced item types, including formats such as drag-and-drop and hot spot.
- Passing score: 700 out of 1,000 scaled points.
- Delivery: Computer-based at Pearson VUE testing centers, scheduled year-round.
- Language: English.
- Results: You’ll see a provisional pass/fail result at the test center as soon as you finish.
- Fee: U.S. $599 for standard registration in the Americas, per the ISC2 exam pricing page. Rescheduling costs $50 and canceling costs $100.
With 180 minutes for 125 items, you have about 86 seconds per question. That’s comfortable for most items, but scenario questions with long stems can eat time, so practice reading for the key qualifier (first, best, most effective) rather than rereading every detail.
What Content Outline Does the CSSLP Exam Use?
The current exam is based on the ISC2 CSSLP Certification Exam Outline, effective September 15, 2023. That version reorganized the exam into eight domains and added a dedicated software supply chain domain. Here are the domains and their weights:
- Domain 1, Secure Software Concepts: 12%
- Domain 2, Secure Software Lifecycle Management: 11%
- Domain 3, Secure Software Requirements: 13%
- Domain 4, Secure Software Architecture and Design: 15%
- Domain 5, Secure Software Implementation: 14%
- Domain 6, Secure Software Testing: 14%
- Domain 7, Secure Software Deployment, Operations, Maintenance: 11%
- Domain 8, Secure Software Supply Chain: 10%
Domain 1: Secure Software Concepts (12%)
This is the vocabulary and principles domain. It covers the core security concepts and the classic design principles that every other domain builds on.
- Confidentiality, integrity, availability, authentication, authorization, accountability, and nonrepudiation.
- Governance, risk, and compliance (GRC) standards.
- Design principles such as least privilege, segregation of duties, defense in depth, economy of mechanism, complete mediation, open design, least common mechanism, and psychological acceptability.
What questions look like: A scenario describes a control, such as re-checking authorization on every request instead of caching a decision, and asks which principle it demonstrates (complete mediation).
Domain 2: Secure Software Lifecycle Management (11%)
This domain is about running security as a program across the SDLC rather than as a one-time activity.
- Managing security within Agile, waterfall, and other development methodologies.
- Security milestones and checkpoints, documentation, and security metrics such as criticality level, average remediation time, and key performance indicators (KPIs).
- Decommissioning applications, including end-of-life (EOL) policies and data disposition.
- Integrated risk management and secure operation practices such as change management, incident response planning, and the assessment and authorization (A&A) process.
Domain 3: Secure Software Requirements (13%)
Security starts with requirements. This domain tests whether you can capture what the software must do, and must not do, before design begins.
- Functional and non-functional security requirements.
- Compliance, data classification, and privacy requirements (data collection scope, anonymization, retention, user rights, and cross-border rules).
- Data access provisioning, including service accounts and reapproval processes.
- Misuse and abuse cases, the security requirements traceability matrix (SRTM), and third-party vendor security requirements.
Study tip: Be able to turn a misuse case (“an attacker replays a captured session token”) into a testable requirement and mitigating control.
Domain 4: Secure Software Architecture and Design (15%)
The heaviest domain covers how you design systems that resist attack. It spans architecture for cloud, mobile, embedded, and Industrial Internet of Things (IIoT) systems; secure interface design; threat modeling; architectural risk assessment; and secure operational architecture, including continuous integration and continuous delivery (CI/CD).
- Define the security architecture and select secure design patterns.
- Perform secure interface design, including management and log interfaces.
- Evaluate reusable technologies such as credential management, virtualization, and trusted computing.
- Perform threat modeling and attack surface evaluation.
Domain 5: Secure Software Implementation (14%)
This domain covers secure coding and code analysis without testing any specific language.
- Input validation, output sanitization, error and exception handling, session management, secure logging, and cryptography.
- Declarative versus imperative (programmatic) security.
- Static application security testing (SAST), manual code review, and vulnerability databases.
- Integrating third-party and open-source components, and security during the build (anti-tampering, compiler switches, addressing compiler warnings).
Domain 6: Secure Software Testing (14%)
Here you plan and interpret security testing.
- Security test strategy, plans, and test cases, including misuse and abuse test cases.
- Techniques such as penetration testing, fuzzing, attack surface validation, regression, and continuous testing.
- Identifying undocumented functionality, classifying and tracking security bugs with risk scoring, and securing test data (including the risks of reusing production data).
What questions look like: A team wants to copy production records into a test environment. The best answer usually involves masking or generating synthetic data rather than simply restricting access.
Domain 7: Secure Software Deployment, Operations, Maintenance (11%)
This domain follows software into production.
- Operational risk analysis, secure configuration and version control, and secure release through a hardened CI/CD pipeline with build artifact verification.
- Managing secrets, keys, and certificates; secure installation and provisioning; obtaining approval to operate.
- Continuous monitoring, incident response, patch and vulnerability management, and runtime protections such as runtime application self-protection (RASP), web application firewalls (WAF), and address space layout randomization (ASLR).
- Continuity of operations and service level agreements (SLAs).
Domain 8: Secure Software Supply Chain (10%)
This domain covers risk from code you didn’t write.
- Software supply chain risk management, including maintaining a list of third-party components and monitoring them for vulnerabilities.
- Verifying pedigree and provenance through code repository and build-environment security and cryptographically hashed, digitally signed components.
- Supplier security requirements and contractual terms such as intellectual property ownership, code escrow, liability, warranty, end-user license agreements (EULAs), and right to audit.
How Should You Use the CSSLP Blueprint to Build a Study Plan?
Treat the outline as your master checklist. Each numbered objective (for example, 4.4 Perform threat modeling) should become something you can explain and apply without notes.
- Take a mixed baseline. Answer a set of questions from all eight domains before deep review so you know where you actually stand.
- Weight your time. Domains 4, 5, and 6 together make up 43% of the exam. Weak spots there deserve attention first.
- Map every miss. Tag each missed question to an outline objective. Patterns (say, repeated misses on data classification) tell you what to reread.
- Fill experience gaps. Developers often need extra time on Domains 2 and 8 (program management and contracts). Security analysts often need more time on Domains 5 and 6.
- Finish with mixed, timed practice. The real exam blends domains, so your final weeks should too.
What Official CSSLP Resources Should You Use?
- CSSLP Certification Exam Outline: The definitive list of domains, weights, and objectives.
- CSSLP Ultimate Guide: ISC2’s overview of exam facts, eligibility, and certification steps.
- ISC2 CSSLP certification page: Official training options, including self-paced and instructor-led courses, plus the official eTextbook and study questions.
Commonly used references:
- CSSLP Certification All-in-One Exam Guide, 3rd Edition
- Official (ISC)² Guide to the CSSLP CBK, 2nd Edition
Frequently Asked Questions About the ISC2 CSSLP Exam
What score do I need to pass the CSSLP?
You need a scaled score of 700 out of 1,000. Because the score is scaled, it doesn’t translate to a fixed percentage of correct answers.
Can I take the exam before I have four years of experience?
Yes. If you pass without the required experience, you can become an Associate of ISC2 and then have five years to earn the experience needed for full certification.
How soon do I get my results?
You’ll receive a provisional result at the test center right after you finish. If you pass, you must complete the endorsement process within nine months of your exam date.
What happens if I don’t pass?
You can retest after a waiting period that starts at 30 days after a first attempt and gets longer with each subsequent attempt. Check ISC2’s after-your-exam page for the current retake rules.
How do I keep the CSSLP active?
You’ll earn 90 continuing professional education (CPE) credits over each three-year cycle (at least 30 per year) and pay a $135 annual maintenance fee (AMF).
Start Preparing for the ISC2 CSSLP Exam With Pocket Prep
Pocket Prep’s ISC2 CSSLP practice questions give you 500 exam-style questions across the outline, each with a detailed explanation of why the best answer is correct. Use Weakest Subject to find your gaps and Timed Quiz to build exam-day pacing. With a clear map of the blueprint and steady practice, you’re well on your way to earning your CSSLP.