Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB

Certified Tester Security Test Engineer

The ISTQB® Certified Tester Security Test Engineer (CT-STE) certification equips testing professionals with the engineering-focused skills to plan, perform, and evaluate security tests across the software development lifecycle. It covers security methodologies, standards, techniques, processes, and tools, enabling you to identify vulnerabilities and protect systems against evolving cyber threats. This certification is for anyone involved in testing IT-based systems for security, from testers and analysts to developers and managers.

Exam formatMultiple Choice
Duration75 minutes
DeliveryISTQB Member Boards
Passing score28 out of 43 points
Free questions1355

Content last reviewed 30 July 2026 · Up to date

The certification

What Certified Tester Security Test Engineer proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

9domains
49objectives
331concepts
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The ISTQB® Certified Tester Security Test Engineer (CT-STE) certification focuses on how security testing should be done, presenting security methodologies, standards, techniques, processes, and tools. As cyberattacks grow in frequency and sophistication, a robust engineering-focused approach to testing security is more critical than ever. Without security testing aligned to an IT system's specific risk levels, vulnerabilities may be exploited—potentially during production—with devastating consequences.

The CT-STE certification aims to bridge this gap, ensuring professionals can proactively create maximum transparency about effective security risk exposure to secure systems against emerging threats. It provides a comprehensive understanding of security paradigms, test techniques, standards, and best practices, and how to apply them within different organizational contexts and software development lifecycles.

Who it’s for

The Certified Tester Security Test Engineer is aimed at anyone involved in testing IT-based systems for security. This includes people in roles such as testers, test analysts, test managers, and even software developers, as everyone in a team should care about security. This certification is also appropriate for anyone who wants a basic understanding of executing security testing activities, such as project managers, quality managers, software development managers, business analysts, operations team members, IT directors, and management consultants.

Recommended experience

While not mandatory, ISTQB recommends attending accredited training to ensure materials are assessed for relevance and consistency against the syllabus. Self-study using the syllabus and recommended reading is also an option. A foundational understanding of software testing concepts, typically gained through the ISTQB Foundation Level certification.; Familiarity with basic security concepts and the software development lifecycle.

The syllabus

What you’ll learn

Every domain and objective ISTQB measures, with the weight they carry on the exam.

The official ISTQB exam outline · checked 30 July 2026 · See the source

Security Paradigms
  • Assets and Their Corresponding Protection Level
  • Information Sensitivity and Security Testing
  • Security Audits and Security Testing
  • What is Zero Trust?
  • Zero Trust concept in Security Testing
  • The concept of OSS and its impacts on security testing
6 objectives · 163 free questions · 34 pages
Security Test Techniques
  • Black-Box, White-Box and Grey-Box Security Testing
  • Static and Dynamic Security Testing
  • Addressing Security Risks in Test Design
  • Recertification testing and reconciliation testing
  • Testing Identification, Authentication and Authorization
  • Encryption
  • Testing protective technologies
7 objectives · 206 free questions · 44 pages
The Security Test Process
  • ISTQB Security Test Process
  • The Security Test Environment
  • Security Test Design at Component Test Level
  • Security Test Design at Component Integration Level
  • System Testing and Acceptance Testing
5 objectives · 163 free questions · 34 pages
Standards and Best Practices
  • Standards
  • Industry Standards for Security Testing
  • Mandatory Application
  • Voluntary Application
  • Test Oracles Extracted from Standards and Best Practices
  • Pros and Cons of Leveraging Standards and Best Practices
6 objectives · 140 free questions · 30 pages
Adjusting To the Organizational Context
  • The Impact of Organizational Structures in the Context of Security Testing
  • The impact of regulations on security regulations
  • Common Attack Scenarios
  • Common Approach of a Hacker
  • Incident response and post incident analysis
5 objectives · 138 free questions · 30 pages
Adjusting to Software Development Lifecycle Models
  • Sequential Development Models
  • Agile Development Lifecycle Models
  • The DevOps Approach
  • Security Regression Testing and Confirmation Testing
4 objectives · 125 free questions · 26 pages
Security Testing as Part of an Information Security Management System
  • Acceptance Criteria for Security Testing
  • Input for an Information Security Management System (ISMS)
  • Improving Holistic View of an ISMS
  • Improving Measurability Within an ISMS
4 objectives · 112 free questions · 24 pages
Reporting Test Results
  • Security Test Reporting
  • Identifying and Analyzing Vulnerabilities
  • Hide Vulnerability
  • Avoid Vulnerability
4 objectives · 104 free questions · 22 pages
Security Test Tools
  • White-box Security Test Tools
  • Black-box Security Test Tools
  • Grey-box Security Test Tools
  • Static Security Test Tools
  • Dynamic Security Test Tools
  • Considerations for Selecting Tools
  • Understand the Usage and Concepts of Static Security Test Tools
  • Understand the Usage and Concepts of Dynamic Test Tools
8 objectives · 204 free questions · 45 pages
On the day

The exam itself

Everything ISTQB publishes about sitting it, and nothing we inferred.

Prerequisites

Must hold the ISTQB Certified Tester Foundation Level (CTFL) certification.

CertificationCertified Tester Security Test Engineer
Exam formatMultiple Choice
Duration75 minutes
Questions40 questions
Passing score28 out of 43 points
DeliveryISTQB Member Boards
LanguagesEnglish, Non-Native Language (with +25% time)
After you pass

Where this credential goes next

The path ISTQB lays out, how the credential is kept, and where to book.

Step-by-step path to Certified Tester Security Test Engineer

PrerequisiteMust hold the ISTQB Certified Tester Foundation Level (CTFL) certification.
Certified Tester Security Test Engineer badgeCredential earnedCertified Tester Security Test Engineer Certification
Renewal and maintenance

ISTQB certifications do not require renewal except for Expert Level. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. ISTQB maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by ISTQB

Exam registration

Register for the exam through ISTQB Member Boards, ISTQB’s authorized testing partner.

Schedule your exam

Visit the official ISTQB certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

What is the difference between the CT-STE and the CT-SEC (Security Tester) certification?

The CT-STE certification focuses on an engineering-focused approach to security testing, covering methodologies, standards, techniques, processes, and tools. The CT-SEC certification focuses on planning, performing, and evaluating security tests from multiple perspectives including risk, requirements, vulnerability, and human factors.

Is the CTFL certification required before taking the CT-STE exam?

Yes, the ISTQB Certified Tester Foundation Level (CTFL) certification is a prerequisite for all non-Foundation exams, including the CT-STE.

Can I take the CT-STE exam through remote proctoring?

Yes, ISTQB exams are available both at test centres and through remote proctoring, depending on the Member Board and exam provider.

What job roles does the CT-STE certification map to?

The CT-STE certification is aimed at anyone involved in testing IT-based systems for security, including testers, test analysts, test managers, software developers, project managers, quality managers, and IT directors.

Can I proceed to other ISTQB certifications after earning the CT-STE?

Yes, holders of this certification may choose to proceed to other Core, Agile, or Specialist stream certifications.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 1355 questions, free, no account needed.