ISC2 Certified Secure Software Lifecycle Professional (CSSLP) focuses on integrating security throughout the software development lifecycle rather than treating it as a final testing activity. It is designed for software development and security professionals who are responsible for building, assessing, deploying, or maintaining applications, along with organizations seeking to reduce software risk through more consistent development practices.
The curriculum addresses secure software concepts, lifecycle management, requirements, architecture and design, implementation, testing, deployment, operations, maintenance, and software supply chain security. Participants examine how security requirements are established, translated into design decisions, applied during development, and verified through testing. The training also covers secure deployment, vulnerability management, third-party components, supply chain risk, and the governance processes needed to maintain software security after release.
Software architects, developers, application security engineers, DevSecOps professionals, testers, and technical leaders with substantial software security responsibilities are the primary audience. ISC2 requires four years of relevant professional experience for certification, with qualifying education able to satisfy up to one year of that requirement. Organizations can use CSSLP training to improve coordination between development and security teams, strengthen secure development practices, and embed security into software delivery from initial planning through production operations.