Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB

Certified Tester Security Tester

The ISTQB® Certified Tester Security Tester (CT-SEC) certification validates your ability to plan, perform, and evaluate security tests from multiple perspectives—risk, requirements, vulnerability, and human factors. It is designed for testers with some security testing experience who want to deepen their expertise. Earning it demonstrates that you can align security testing with the software lifecycle, apply security mechanisms, and use the right tools and standards to protect your organization.

Exam formatMultiple choice
Duration120 minutes
DeliveryISTQB Member Boards
Passing score52 out of 80
Free questions1239

Content last reviewed 30 July 2026 · Up to date

The certification

What Certified Tester Security Tester proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

9domains
49objectives
278concepts
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The ISTQB® Certified Tester Security Tester (CT-SEC) certification focuses on planning, performing, and evaluating security tests from multiple perspectives including risk, requirements, vulnerability, and human factors. It also covers security testing tools and standards, giving you a comprehensive framework to identify and mitigate security risks throughout the software development lifecycle.

By earning CT-SEC, you demonstrate the ability to analyze security policies and procedures, evaluate the effectiveness of security mechanisms, and adopt an attacker mentality to uncover vulnerabilities in a protected environment. You will also learn to select and apply appropriate security testing tools, understand industry standards, and contribute to building information security awareness within your organization.

Who it’s for

The Security Tester certification is aimed at people who have some experience in security testing and wish to further develop their expertise in security testing. It is ideal for testers, security analysts, and quality assurance professionals who are responsible for ensuring the security of software systems. Candidates should be comfortable with fundamental testing concepts and have practical experience in security testing. The certification is designed to help you advance your career by validating your specialized skills in security testing.

Recommended experience

Candidates should have some experience in security testing and a solid understanding of software testing fundamentals. ISTQB recommends at least three years of relevant academic, practical, or consulting experience. Experience in planning and executing security tests; Knowledge of security risks, vulnerabilities, and attack vectors; Familiarity with security testing tools and standards; Understanding of the software development lifecycle and testing processes

The syllabus

What you’ll learn

Every domain and objective ISTQB measures, with the weight they carry on the exam.

The official ISTQB exam outline · checked 30 July 2026 · See the source

The Basis of Security Testing
  • The Role of Risk Assessment in Security Testing
  • Asset Identification
  • Analysis of Risk Assessment Techniques
  • Understanding Security Policies and Procedures
  • Analysis of Security Policies and Procedures
  • Purpose of a Security Audit
  • Risk Identification, Assessment and Mitigation
  • People, Process and Technology
8 objectives · 230 free questions · 49 pages
Security Testing Purposes, Goals and Strategies
  • Foundations of Security Testing
  • Setting Security Testing Goals and Objectives
  • Security Testing Approaches and Stakeholders
  • Improving Security Testing Practices
4 objectives · 83 free questions · 18 pages
Security Testing Processes
  • Security Testing Process Overview
  • Security Test Planning
  • Security Test Design
  • Security Test Execution and Evaluation
  • Security Test Maintenance
5 objectives · 114 free questions · 25 pages
Security Testing Throughout the Software Lifecycle
  • Lifecycle Overview
  • Requirements and Design
  • Component and Integration Testing
  • System, Acceptance, and Maintenance
4 objectives · 101 free questions · 22 pages
Testing Security Mechanisms
  • System Hardening
  • Authentication and Authorization
  • Encryption
  • Firewalls
  • Intrusion Detection
  • Malware Scanning
  • Data Obfuscation
  • Security Training
8 objectives · 213 free questions · 46 pages
Human Factors in Security Testing
  • The Impact of Human Behavior on Security Risks
  • Understanding the Attacker Mentality
  • Common Motivations and Sources of Computer System Attacks
  • Understanding Attack Scenarios and Motivations
  • Social Engineering
  • The Importance Of Security Awareness
  • Increasing Security Awareness
7 objectives · 175 free questions · 37 pages
Security Test Evaluation and Reporting
  • Security Test Evaluation
  • Confidentiality of Security Test Results
  • Analyzing Interim Security Test Status Reports
3 objectives · 70 free questions · 15 pages
Security Testing Tools
  • Types and Purposes of Security Testing Tools
  • Analyzing and Documenting Security Testing Needs
  • Issues with Open Source Tools
  • Evaluating a Tool Vendor's Capabilities
4 objectives · 119 free questions · 25 pages
Standards and Industry Trends
  • The Benefits of Using Security Testing Standards
  • Applicability of Standards in Regulatory Versus Contractual Situations
  • Selection of Security Standards
  • Applying Security Standards
  • Where to Learn of Industry Trends in Information Security
  • Evaluating Security Testing Practices for Improvements
6 objectives · 134 free questions · 29 pages
On the day

The exam itself

Everything ISTQB publishes about sitting it, and nothing we inferred.

Prerequisites

Must hold the Certified Tester Foundation Level (CTFL) certificate.

CertificationCertified Tester Security Tester
Exam formatMultiple choice
Duration120 minutes
Questions45 questions
Passing score52 out of 80
DeliveryISTQB Member Boards
LanguagesEnglish, Non-native language support (+25% time)
After you pass

Where this credential goes next

The path ISTQB lays out, how the credential is kept, and where to book.

Step-by-step path to Certified Tester Security Tester

PrerequisiteMust hold the Certified Tester Foundation Level (CTFL) certificate.
Certified Tester Security Tester badgeCredential earnedCertified Tester Security Tester Certification
Renewal and maintenance

ISTQB certifications do not require renewal except for Expert Level. The CT-SEC certification does not require renewal. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. ISTQB maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by ISTQB

Exam registration

Register for the exam through ISTQB Member Boards, ISTQB’s authorized testing partner.

Schedule your exam

Visit the official ISTQB certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does CT-SEC relate to the newer Certified Tester Security Test Engineer (CT-STE) certification?

CT-SEC focuses on planning, performing, and evaluating security tests from multiple perspectives, while CT-STE equips professionals with essential skills to address evolving security testing challenges such as asset protection, audits, and adapting to new threats. Both are Specialist-level certifications, but CT-STE is a distinct, newer certification.

Is the CTFL prerequisite mandatory for CT-SEC?

Yes, you must hold the Certified Tester Foundation Level (CTFL) certificate to be eligible for the CT-SEC exam. This is a mandatory prerequisite.

Can I take the CT-SEC exam without attending accredited training?

Yes, self-study using the official syllabus and recommended reading material is an option. However, ISTQB highly recommends attending accredited training to ensure the materials are relevant and consistent with the syllabus.

What is the exam format for CT-SEC?

The CT-SEC exam consists of 45 multiple-choice questions. You have 120 minutes to complete it, with an additional 25% time if you are taking the exam in a non-native language.

Are there any hands-on or lab components in the CT-SEC exam?

No, the CT-SEC exam is a multiple-choice exam. There are no hands-on or lab components.

What job roles does the CT-SEC certification map to?

The CT-SEC certification is relevant for security testers, security analysts, and quality assurance professionals who are responsible for planning, performing, and evaluating security tests.

Can I proceed to other ISTQB certifications after earning CT-SEC?

Yes, holders of the CT-SEC certification may choose to proceed to other Core, Agile, or Specialist stream certifications.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 1239 questions, free, no account needed.