Image Alt
  /  ISC2 Courses   /  CSSLP   /  CSSLP Domain Refresh FAQ

CSSLP Domain Refresh FAQ

CSSLP learning imageOn September 15, 2023, the CSSLP credential exam will see some updates and changes as was previously announced on January 18, 2023. As with all ISC2 certifications, this exam update is based on a Job Task Analysis (JTA) process which ensures the exam accurately reflects the industry.


Effective September 15, 2023

An exam that is up to date ensures that those who hold the CSSLP, such as software development and security professionals, are applying best practices during each phase of the Software Development Life Cycle (SDLC)– from software design and implementation to testing and deployment.

Q: Why are changes being made to the CSSLP exam?

ISC2 has an obligation to its membership to maintain the relevancy of its credentials. These enhancements are the result of a rigorous, methodical process that ISC2: follows to routinely update its credential exams. This process ensures that the examinations and subsequent continuing professional education requirements encompass the topic areas relevant to the roles and responsibilities of today’s practicing software development professional.

Q: How is the CSSLP exam changing?

While the weights of many of the domains of the CSSLP exam are changing it still requires at least four years of work experience in one or more of the eight domains. If you are taking the CSSLP after September 15, 2023, and have the necessary work experience, you will still be equally prepared to take the updated CSSLP exam. Only five of the eight domain weights were minimally impacted, and the list was merely re-ordered. While these changes are minor, we still recommend that all exam candidates be familiar with the current domains. As a result of the content refresh, the domain names have been updated to describe the topics accurately.


The weights for the domains are also changing.


Q: Why do domains for ISC2 credential exams change?

Domains change because it is a reflection of a change in the knowledge, skills and abilities, as indicated by experts through the Job Task Analysis process.

Q: When will these changes go into effect?

The changes will begin on September 15, 2023.

Q: In what language will the refreshed CSSLP exam be available?

The refreshed CSSLP exam will be available in English only.

Q: Will this change the number of questions or the time required to take the CSSLP exam?

The CSSLP exam will still have 125 items, and the exam time is still three hours. A passing grade remains 700 out of 1,000.

Q: If I have been studying for the CSSLP exam with material that focuses on the current domains, will I be sufficiently prepared to take the new exam without additional study?

ISC2 exams are experience-based that include experience-based questions that cannot be learned by studying alone. If you already have the experience in the domains covered in CSSLP and believe that you have sufficiently studied those domains, you should feel confident that you are qualified to take the new exam and pass it. ISC2 cannot guarantee you will pass the exam.

Q: Do these updates affect the experience requirement for the CSSLP?

No. For the CSSLP, a candidate is required to have a minimum of four years cumulative work experience in one or more of the eight domains of the CSSLP CBK.

Q: When will the training course for CSSLP be updated to reflect these changes?

The Official ISC2 CSSLP training course will be updated on September 15, 2023 to reflect the changes to the exam outline.


The CSSLP Domain Refresh FAQ content was originally posted on the ISC2 website

Cycubix is an ISC2 Official Training Partner and offers CISSPCCSPCSSLPSSCP trainings.

In addition, we offer custom cybersecurity trainingsecurity awareness trainingcorporate cybersecurity trainingcybersecurity consultancy to ensure we adapt to your company’s specific needs. Discover all our cyber security trainings and online cyber security trainings available at Cycubix.