ISC2 · CSSLP
The CSSLP validates that software professionals have the expertise to incorporate security practices—authentication, authorization, and auditing—into each phase of the software development lifecycle (SDLC). It is designed for software developers, engineers, architects, and security professionals with at least four years of SDLC experience.
Practice Questions
841
≈ 6 practice exams
Duration
180 minutes
Passing Score
700/1000
Difficulty
ProfessionalLast Updated
Oct 2026
CSSLP tests whether you can build security into every phase of the software lifecycle. The current outline, effective September 15, 2023, has eight domains: Secure Software Concepts (12%), Lifecycle Management (11%), Requirements (13%), Architecture and Design (15%), Implementation (14%), Testing (14%), Deployment, Operations, and Maintenance (11%), and Supply Chain (10%). ISC2's live outline page now also explains how AI security is folded into these domains, but it has not published a new effective date or different weights.
The exam has 125 items in three hours, mixes multiple-choice and advanced item types, is delivered in English only, and needs 700 out of 1000 to pass. Standard registration is $599 in the US, Asia Pacific, Middle East, and Africa, EUR 575.04 in EMEA, and GBP 485.19 in the UK. The 175-question, four-hour figure you will see in older guides is the pre-2020 format. Certification also needs four years of full-time experience in one or more domains (a degree can waive up to one), or you can pass first and become an Associate of ISC2 with five years to earn the experience.
Use these 841 questions to practise the secure-lifecycle owner's reasoning: which phase a control belongs in, how a requirement becomes a design decision, what a test should prove, and where third-party and open-source risk enters. Once certified, you keep CSSLP with 90 CPE credits per three-year cycle and a $135 annual maintenance fee.
ISC2 CSSLP validates the ability to build security into every phase of the software lifecycle. The current outline, effective September 15, 2023, has eight domains: Secure Software Concepts, Lifecycle Management, Requirements, Architecture and Design, Implementation, Testing, Deployment, Operations and Maintenance, and Supply Chain. ISC2's live outline page also explains how AI security is incorporated into the domains.
The credential suits software architects, developers, testers, and security professionals who are responsible for secure delivery, and it is accredited under ISO/IEC 17024.
The CSSLP is intended for experienced software and security professionals who bear responsibility for security outcomes across the development lifecycle. Primary candidates include software architects, software engineers, application security specialists, security engineers, and software program managers who work directly in development organizations. Secondary audiences include quality assurance testers, penetration testers, software procurement analysts, project managers, security managers, and IT directors who oversee software delivery or vendor relationships.
Candidates typically have four or more years of hands-on SDLC experience and are already working in roles where they make or influence security design decisions. The certification is particularly well-suited for professionals transitioning from pure development into security-focused engineering roles, or for AppSec practitioners who want a globally recognized credential to formalize their expertise.
ISC2 requires a minimum of four years of cumulative, paid, full-time professional work experience in one or more of the eight CSSLP CBK domains. Candidates who hold a four-year degree in Computer Science, Information Technology, or a related field may substitute one year of that experience requirement, reducing the minimum to three years. There are no formal prerequisites requiring other certifications before sitting the exam.
Beyond the experience requirement, candidates are expected to have working familiarity with secure coding practices, threat modeling methodologies such as STRIDE or PASTA, cryptographic concepts, access control models, and at least one SDLC methodology (e.g., Agile, DevSecOps, waterfall). Professionals without the required experience at exam time can pass the exam and become an Associate of ISC2, with five years to accumulate the qualifying work experience before converting to full CSSLP status. All certified members must adhere to the ISC2 Code of Ethics.
The exam has 125 items in three hours, mixes multiple-choice and advanced item types, and is delivered in English only. A scaled score of 700 out of 1000 is required. ISC2 lists standard registration at $599 in the US, Asia Pacific, Middle East, and Africa, with regional prices in EMEA and the UK. The older 175-question, four-hour format predates 2020.
Certification requires four years of cumulative full-time experience in one or more domains, and a relevant degree can waive up to one year. Candidates who pass without the experience become an Associate of ISC2 and have five years to earn it. Maintenance takes 90 CPE credits per three-year cycle and a $135 annual maintenance fee.
CSSLP shows that you can apply security throughout design, development, testing, deployment, and supply-chain decisions rather than only at the end of a project. It is most useful for secure-software, application-security, and architecture roles where lifecycle accountability matters. The credential is DoDM 8140.03 approved according to ISC2.
5 sample questions with answers and explanations. The full bank has 841 questions, enough for 6 full-length practice exams.
Preview — answers shown1. A global pharmaceutical company classifies research data as Top Secret at the government level. What is the equivalent commercial classification level for this data? (Select one!)
Explanation
Government Top Secret classification maps to commercial Confidential level. The standard mapping is Top Secret maps to Confidential, Secret maps to Private, Confidential maps to Sensitive, and Unclassified maps to Public. This mapping is important for organizations handling both government and commercial data. Public is the least sensitive level. Sensitive maps to government Confidential. Private maps to government Secret.
2. A risk assessment calculates that an asset valued at $500,000 faces a threat with an Exposure Factor of 40% and an Annual Rate of Occurrence of 0.25. What is the Annualized Loss Expectancy (ALE)? (Select one!)
Explanation
ALE is calculated as SLE × ARO. First calculate Single Loss Expectancy: SLE = Asset Value × Exposure Factor = $500,000 × 0.40 = $200,000. Then calculate Annualized Loss Expectancy: ALE = SLE × ARO = $200,000 × 0.25 = $50,000. This represents the expected annual loss from this specific risk scenario. The ALE calculation is fundamental to quantitative risk analysis and cost-benefit analysis for security controls, helping determine if countermeasure costs are justified by risk reduction.
3. A software development organization assesses its security maturity using BSIMM. The organization has established a Software Security Group (SSG) and deployed Security Champions across development teams. These roles represent which BSIMM domain? (Select one!)
Explanation
BSIMM's Governance domain encompasses organizational structure including the Software Security Group (SSG) as the centralized team driving software security initiatives and Security Champions as distributed advocates embedded in development teams. The Governance domain covers Strategy & Metrics, Compliance & Policy, and Training. Intelligence domain focuses on attack models and security features. SSDL Touchpoints covers technical activities like code review and architecture analysis. Deployment addresses penetration testing and configuration management.
4. A retail company calculates risk for their e-commerce platform. Their payment processing server is valued at 500000 USD. A DDoS vulnerability has an exposure factor of 40 percent and occurs twice per year on average. What is the Annualized Loss Expectancy? (Select one!)
Explanation
ALE equals SLE multiplied by ARO. First calculate SLE: Asset Value times Exposure Factor equals 500000 times 0.40 equals 200000 USD. Then calculate ALE: SLE times ARO equals 200000 times 2 equals 400000 USD annualized loss expectancy. This represents the expected yearly loss from this specific risk. 200000 is the SLE, not the ALE. 1000000 incorrectly doubles the asset value. 800000 uses incorrect multiplication factors.
5. A software development organization adopts BSIMM to benchmark its security practices. The organization establishes a dedicated Software Security Group and identifies Security Champions in each development team. Which BSIMM domain does this activity primarily address? (Select one!)
Explanation
BSIMM Governance domain covers Strategy and Metrics, Compliance and Policy, and Training including establishing the Software Security Group and Security Champions network. The SSG is the internal team driving software security initiatives while Security Champions are distributed advocates. Intelligence domain covers Attack Models, Security Features and Design, and Standards and Requirements. SSDL Touchpoints includes Architecture Analysis, Code Review, and Security Testing. Deployment covers Penetration Testing, Software Environment, and Configuration Management.
ISC2's current outline lists 125 items, mixing multiple-choice and advanced item types. The 175-question format in older guides predates 2020.
Three hours (180 minutes) under the current outline, delivered in English only.
You need 700 out of 1000 on a scaled score. ISC2 does not publish a raw-score cut.
ISC2 lists $599 in the US, Asia Pacific, Middle East, and Africa, EUR 575.04 in EMEA, and GBP 485.19 in the UK. Taxes vary by location.
Four years of cumulative full-time experience in one or more of the eight domains; a relevant degree can waive up to one year. If you pass without it, you become an Associate of ISC2 and have five years to earn the experience.
Earn 90 CPE credits per three-year cycle (60 in Group A and 30 in Group A or B) and pay the $135 annual maintenance fee.
Certified Information Systems Security Professional (CISSP)
CISSP · 850 questions
Certified Cloud Security Professional (CCSP)
CCSP · 850 questions
Information Systems Security Architecture Professional (ISSAP)
ISSAP · 850 questions
Systems Security Certified Practitioner (SSCP)
SSCP · 849 questions
Certified in Cybersecurity (CC)
CC · 838 questions
Certified in Governance, Risk and Compliance (CGRC)
CGRC · 850 questions
$17.99
One-time access to this exam