Home/ Courses/ ISC2/ CSSLP
ISC2 Authorised Advanced · AppSec 2026 ECO DevSecOps Cert

CSSLP
Secure Software Lifecycle Professional

ISC2's secure-software credential. The cert for senior application-security engineers, AppSec architects and DevSecOps leads building and shipping secure software at MY banks, fintechs, telcos and SaaS companies.

Duration: 5 days / 40 hrs
💻Format: Instructor-Led + Code Labs
🌐Delivery: On-site · Virtual · Hybrid
Pass rate: 91%
📅Next intake: 23 May 2026
CSSLP training session at Nexperts Academy
🔍

Secure SDLC

Threat modelling, secure design, secure coding across full lifecycle

🛡️

DevSecOps

SAST, DAST, IAST, SCA, IaC scanning, secret management in pipelines

📚

OWASP

OWASP Top 10, ASVS, MASVS, SAMM, Cloud-Native Top 10

📊

Supply-chain security

SBOM, dependency scanning, signed artefacts, SLSA

What this course is

Where AppSec stops
being a scanner alert.

CSSLP is ISC2's secure-software lifecycle credential. It is the cert for senior application-security engineers, AppSec architects and DevSecOps leads building and shipping secure software at MY banks, fintechs, telcos, GLCs and SaaS companies. CSSLP is the cert that validates security across the full development lifecycle — not just at scanner-alert time.

At Nexperts, CSSLP is delivered as a 5-day intensive that walks the eight exam domains with hands-on coding, threat-modelling and pipeline labs. By day 5 you've threat-modelled a real MY-style application, embedded SAST + DAST + SCA in a CI/CD pipeline and defended a secure-architecture review.

CSSLP sits between CISSP (security breadth) and the engineering-deep certs like OSWE. It is the credential that signals you can lead AppSec from architecture to production — not just patch findings after a pentest.

The 2024+ CSSLP update aligned with modern DevSecOps practice, supply-chain security (SBOM, SLSA, SSDF), and cloud-native software (containers, serverless, K8s). We map every lab to current OWASP, NIST SSDF and BNM RMiT app-security expectations.

Who should take this course
👨‍💻

Senior AppSec engineers

Owning secure-coding standards and SAST / DAST programmes.

🛡️

AppSec architects

Designing AppSec controls at enterprise scale. CSSLP is the recognised architect cert.

🔐

DevSecOps leads

Building security into CI/CD pipelines.

📚

Senior software engineers

Pivoting into AppSec or security-engineering roles.

📊

Security architects

CISSP holders adding the AppSec / lifecycle depth.

💼

Tech leads

Owning secure-coding standards across squads.

Prerequisites
4 years of paid experience in 1 or more of the 8 CSSLP domains
OR 3 years experience plus a 4-year IT-security degree
Hands-on experience in software development required
ISC2 endorsement required after exam pass
Don't yet meet experience? Pass the exam to become an ISC2 Associate; full cert grants when experience is met within 5 years.