CertGrid
Security Study Guide

(ISC)² CSSLP Study Guide

The (ISC)² Certified Secure Software Lifecycle Professional (CSSLP) validates the ability to build security into every phase of software development rather than testing for it at the end. It is aimed at developers, architects, testers, engineers and programme managers who own software security decisions, and the credential requires four years of experience in one or more of the eight domains. The exam is 125 multiple-choice items in a maximum of 180 minutes (3 hours), scored 0-1000 with 700 required to pass. The domain weighting follows the outline effective 15 September 2023.

Objective-mapped study guide, aligned to current exam objectives · Reviewed Sep 2026 · Independent practice platform.

Real exam: 180 min

Domain 1: Secure Software Concepts

Key concepts you must know · 84 practice questions

Domain 2: Secure Software Lifecycle Management

Key concepts you must know · 78 practice questions

Domain 3: Secure Software Requirements

Key concepts you must know · 90 practice questions

Domain 4: Secure Software Architecture and Design

Key concepts you must know · 105 practice questions

Domain 5: Secure Software Implementation

Key concepts you must know · 98 practice questions

Domain 6: Secure Software Testing

Key concepts you must know · 99 practice questions

Domain 7: Secure Software Deployment, Operations and Maintenance

Key concepts you must know · 77 practice questions

Domain 8: Secure Software Supply Chain

Key concepts you must know · 69 practice questions

(ISC)² CSSLP exam tips

Study guide FAQ

How is the CSSLP exam structured and scored?

The CSSLP is 125 multiple-choice questions in a maximum of 180 minutes (3 hours). It is scored on a 1000-point scaled score with 700 required to pass, so the pass mark is not a raw percentage of questions answered correctly. Items are distributed across the eight domains per the (ISC)² outline effective 15 September 2023: Secure Software Concepts 12%, Secure Software Lifecycle Management 11%, Secure Software Requirements 13%, Secure Software Architecture and Design 15%, Secure Software Implementation 14%, Secure Software Testing 14%, Secure Software Deployment/Operations/Maintenance 11%, and Secure Software Supply Chain 10%.

What experience do I need before taking the CSSLP?

(ISC)² requires four years of cumulative paid full-time work experience in the software development lifecycle in one or more of the eight CSSLP domains, or three years with a relevant four-year degree or an approved credential. If you pass the exam without the experience, you become an Associate of (ISC)² and have five years to earn it. The experience requirement is why the exam rewards judgement about trade-offs rather than recall of definitions.

How does the CSSLP differ from the CISSP and from developer-focused certifications?

The CISSP covers information security management broadly across eight domains, of which software development security is one. The CSSLP goes deep on that one area, covering requirements, architecture, coding, testing, deployment, operations and the software supply chain in detail. It is also vendor-neutral and role-neutral: it does not test a specific language or framework, so questions concern principles, patterns and lifecycle decisions rather than syntax.

Do I need to be a working developer to pass the CSSLP?

No. The exam is written for everyone who influences software security decisions, including architects, testers, security engineers, project managers and procurement staff, and a substantial share of the content concerns requirements, testing strategy, operations and supplier risk rather than code. You do need to recognise the major implementation defect classes - injection, memory safety errors, deserialisation, cross-site scripting and race conditions - and understand why each fix works, without needing to write the code yourself.

Related Security resources

What CertGrid is (and is not)

CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.

Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by Security. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.