You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The Certified Secure Software Lifecycle Professional (CSSLP) certification validates your ability to integrate security practices—authentication, authorization, and auditing—into every phase of the software development lifecycle (SDLC). It is designed for software and security professionals who build, test, and deploy secure applications. Earning the CSSLP demonstrates advanced application security skills and a commitment to best practices established by ISC2, helping you advance your career and gain recognition from employers and peers.
Content last reviewed 30 July 2026 · Up to date
What this certification covers, who it is written for, and what the exam itself looks like on the day.
What it validates, who it is written for, and the experience it assumes.
The Certified Secure Software Lifecycle Professional (CSSLP) certification from ISC2 validates that software professionals have the expertise to incorporate security practices—authentication, authorization, and auditing—into each phase of the software development lifecycle (SDLC), from design and implementation to testing and deployment. This vendor-neutral credential is built around eight domains that cover the full spectrum of secure software development, ensuring relevancy across all disciplines in the field of information security.
Earning the CSSLP demonstrates that you possess the advanced technical skills and knowledge necessary to apply best practices, policies, and procedures established by ISC2's cybersecurity experts. It shows employers and peers that you are committed to building security into software from the ground up, reducing risk and enhancing the overall security posture of your organization. As a globally recognized certification, the CSSLP opens doors to career advancement and connects you with a community of cybersecurity leaders dedicated to professional growth.
The CSSLP is ideal for software development and security professionals responsible for applying best practices to each phase of the SDLC—from software design and implementation to testing and deployment. This includes roles such as software architect, software engineer, software developer, application security specialist, software program manager, quality assurance tester, penetration tester, software procurement analyst, project manager, security manager, and IT director/manager. If you are involved in developing, deploying, or managing software and want to demonstrate your ability to integrate security throughout the lifecycle, the CSSLP is designed for you. It is particularly valuable for those seeking to formalize their expertise in secure software development and stand out in a competitive job market.
A minimum of four years of cumulative, full-time experience in one or more of the eight domains of the CSSLP exam outline is required for certification. A post-secondary degree in computer science, IT, or a related field may satisfy up to one year of this experience requirement. Experience in secure software concepts, lifecycle management, requirements, architecture and design, implementation, testing, deployment, operations, maintenance, or supply chain; Part-time work and internships may count toward the experience requirement; Candidates without the required experience can become an Associate of ISC2 by passing the exam and have five years to earn the required experience
Every domain and objective ISC2 measures, with the weight they carry on the exam.
The official ISC2 exam outline · checked 30 July 2026 · See the source
Everything ISC2 publishes about sitting it, and nothing we inferred.
Minimum of four years cumulative, full-time experience in one or more of the eight domains of the CSSLP exam outline.
The path ISC2 lays out, how the credential is kept, and where to book.
Step-by-step path to Certified Secure Software Lifecycle Professional
ISC2 certifications are time-limited and must be renewed on a regular three-year cycle. Certification holders maintain their credentials by earning continuing professional education (CPE) credits and complying with ISC2 policies and ethical standards. An annual maintenance fee (AMF) is also required. Stay current with the latest technologies and maintain your certification.
Learn more about renewal requirementsThis certification is currently active and available. ISC2 maintains this certification to validate current skills and industry relevance.
Register for the exam through Pearson VUE, ISC2’s authorized testing partner.
Schedule your examVisit the official ISC2 certification page for exam policies and requirements.
View the official pageYour coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.
See how the coach worksAccording to the official exam outline, the CSSLP exam is available in English only.
Yes. If you don't have the required experience, you can become an Associate of ISC2 by passing the CSSLP exam. You will then have five years to earn the four years of required experience.
Peace of Mind Protection is an exam-only purchase that includes two exam attempts at a lower cost than two single exams. Candidates have 180 days from purchase to sit both attempts, with a 30-day waiting period between attempts.
Exam codes must be scheduled and administered within 365 days of purchase.
The CSSLP is ideal for software architects, software engineers, software developers, application security specialists, software program managers, quality assurance testers, penetration testers, software procurement analysts, project managers, security managers, and IT directors/managers.
Yes, the CSSLP is accredited by the ANSI National Accreditation Board (ANAB) to the ISO/IEC 17024 standard and is approved by the U.S. Department of Defense (DoD) under DoDM 8140.03.
ISC2 certifications are renewed through continuing professional education (CPE) credits and compliance with ISC2 policies. Passing a different exam may contribute to CPE credits, but the renewal process is based on earning CPEs, not automatically by passing another exam.
Every domain, every objective, and every concept ISC2 measures — each one written out.





Every objective below is a page you can open and practise now, without an account.
The official ISC2 exam outline · checked 30 July 2026 · See the source
In front of every objective the practice pages are already there, free and without an account. This is one objective, opened.
27 questions on this objective, five to a page. Every range above is a real page, open now, with no account.
The curriculum tells you what is on the exam. Proving you know it is a different job — and it is the one the closed-book run does.
The whole bank is open. 5 questions to a page, every answer explained, and a discussion thread on each one.
Every objective, and every page range, is a link — so you can pick up exactly where you left off.
Short enough to finish, long enough to matter.
Not only which one is right — why the others are wrong.
Ask, answer, and vote. Every question has its own thread.
These are not trivia. Each one is written against a concept in the book, so when you get one wrong there is somewhere to go and find out why.

The pages shown here come from our AI-900 book — an example of how each concept is written in plain language and, where the idea needs one, drawn as a full page you can take in at a glance.





Three reasons, and each one is a real finding rather than a slogan.
You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The whole idea at onceWhere it starts, what happens in the middle, what comes out, and the mistake to avoid.
Multimedia principle · Mayer
The look-alikes sit togetherThe pairs the exam tests are drawn side by side, so the difference is seen, not told.
Dual coding · PaivioYou are never asked to read a poster here — only to see how one is built. After that, every other page is legible at a glance.

The idea as a sequence, followed with a finger before a word is read.
What it is, how the machine learns it, when it is the right tool.
The distinction the exam tests, given its own box instead of buried in prose.
The sentence to carry into the exam room.
This is the part that teaches. The illustration and the written explanation stay where they are while you work, so a scenario stops being a memory test and becomes something you can simply look at.
A smartphone uses AI to unlock when the owner looks at the camera. Which AI capability is being used?

The same questions come back with the book closed — that run is the one that counts. After it, your coach picks one thing for tonight, sized to the time you have, and brings pages back before you lose them.
Testing effect · Roediger & Karpicke 2006 · spacing effect · Cepeda et al. 2006
Where the exam is defined, scheduled and scored.
We link to them rather than repeat them, so nothing here goes stale behind them.
We build from the official skills outline, not from a summary of it — 58 objectives, 447 concepts written under them, and free questions against every one. When ISC2 changes the outline, this page changes with it.
That is the only question worth answering the night before, and no link answers it. You answer it by taking the questions with the book closed, and seeing what comes back.