IBACTP® — International Board of AI, Cybersecurity & Technology Professionals
CDevSOP®

Certified DevSecOps Professional

It is also useful for cybersecurity professionals who need stronger understanding of modern software engineering and delivery pipelines.

Credential
Certified DevSecOps Professional
Certification Designation
CDevSOP®
Certification Level
Professional
Certification Body
International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)
Program Category
DevSecOps, Secure Software Delivery, Cloud-Native Engineering & Cybersecurity
Delivery Format
Instructor-Led, Virtual Instructor-Led, Self-Paced, or Blended Learning
Recommended Training Duration
40–60 Hours
Certification Examination
Proctored, competency-based examination with multiple-choice and scenario-based questions
Alternative Assessment Pathway
Applied DevSecOps Capstone for eligible candidates in approved instructor-led pathways
Credential Renewal Cycle
3 Years
Program code on a dark screen
DevSecOps
CDevSOP® Certified DevSecOps Professional badge

Automate Delivery. Secure the Pipeline.

Professional Level For practitioners, specialists, analysts and engineers
Vendor-Neutral Skills and knowledge that apply across platforms and tools
Global Recognition Recognized internationally across industries and regions
Digital Credential Shareable, verifiable credential and certificate
Certification Overview

What You Will Learn

Develop the knowledge and practical skills to build, automate and secure modern software delivery pipelines.

View Full Syllabus
1

Apply DevSecOps and Secure SDLC Principles

Integrate security requirements, threat modeling, shared responsibility, risk awareness, and security control…

2

Apply Secure Coding and Source-Control Practices

Evaluate code security, repository controls, secrets, dependencies, development workflows, and source-code ri…

3

Build and Secure CI/CD Pipelines

Apply automated security testing, pipeline controls, artifact management, deployment gates, and secure releas…

4

Secure Cloud Infrastructure and Infrastructure as Code

Evaluate cloud configurations, IaC templates, identity, access, network controls, automated infrastructure, a…

5

Secure Containers, APIs, and Cloud-Native Applications

Evaluate container images, registries, orchestration, APIs, microservices, runtime environments, and cloud-na…

6

Manage Software Supply-Chain and Vulnerability Risk

Identify vulnerable dependencies, assess software components, interpret SBOM information, prioritize remediat…

7

Apply DevSecOps Monitoring and Operational Feedback

Use telemetry, logs, alerts, runtime findings, incidents, and operational data to improve applications and de…

8

Evaluate AI-Assisted and Emerging DevSecOps Technologies

Use and assess AI-assisted development, testing, remediation, automation, and emerging tools responsibly.

Certified DevSecOps Professional
BuildSecureDeliverRepeat
Designed for you

Built for Modern DevSecOps Professionals

Whether you build, deploy, secure or manage modern applications, CDevSOP® helps you advance your skills and career.

  • DevSecOps Engineer
  • DevOps Engineer
  • Software Developer
  • Application Developer
  • Software Engineer
  • Cloud Engineer
  • Platform Engineer
  • Site Reliability Engineer
  • Application Security Analyst
  • Application Security Engineer
CDevSOP® Body of Knowledge

Eight Modules. Real-World Impact.

Explore Detailed Syllabus
01

DevSecOps Foundations and Secure Software Lifecycle

DevSecOps Principles and Shared Responsibility · Secure SDLC, Agile, and Continuous Delivery · Security Requirements and Risk Integration

02

Secure Coding, Source Control, and Application Security

Secure Coding Principles and Common Weaknesses · Source-Control Security and Repository Governance · Secrets, Credentials, and Developer Access

03

CI/CD Pipeline Security and Automation

CI/CD Architecture and Pipeline Workflows · Pipeline Identity, Permissions, and Secrets · Automated Security Testing and Security Gates

04

Cloud, Infrastructure as Code, and Configuration Security

Cloud Security and Shared Responsibility · Infrastructure as Code and Secure Templates · Identity, Network, and Resource Configuration

05

Containers, APIs, and Cloud-Native Security

Container Images, Registries, and Image Security · Kubernetes and Orchestration Security Concepts · API Authentication, Authorization, and Security Testing

06

Software Supply Chain, Dependencies, and Vulnerabilities

Open-Source Dependencies and Package Security · Software Composition Analysis and Vulnerability Detection · SBOMs and Software Component Transparency

07

Observability, Operations, Resilience, and Continuous Improvement

Logging, Metrics, Tracing, and Application Observability · Runtime Security and Production Monitoring · Incident Detection, Response, and Development Feedback

08

AI-Assisted DevSecOps and Emerging Technologies

AI-Assisted Coding and Developer Productivity · AI-Enabled Security Testing and Vulnerability Analysis · AI-Generated Code Risk and Validation

Learning outcomes

From Development to a More Secure Tomorrow

Apply security across the entire software delivery lifecycle.

  1. PlanDesign with security in mind
  2. CodeWrite and review secure code
  3. BuildAutomate with security controls
  4. TestValidate and assess risks
  5. DeployRelease with confidence
  6. MonitorDetect and respond to threats
  7. ImproveLearn and strengthen
Assessment pathways

Two Pathways. One Recognized Credential.

Choose the pathway that suits your learning journey.

CDevSOP® Certification Examination

  • 100 questions
  • Multiple-choice and scenario-based questions
  • 90 minutes
  • Closed book
  • Secure online proctoring or approved testing center

Applied DevSecOps Capstone

  • Eligible candidates in approved instructor-led pathways may complete a structured Applied DevSecOps Capstone.
  • Requirements → Threat Model → Code → Pipeline → Security Testing → Deployment → Monitoring → Remediation

See the Four Ways to Enroll

Why CDevSOP®?

Advance Your Career. Strengthen Your Impact.

From Security Review to Security Integration

From Manual Security to Automated Security

From Vulnerability Counts to Risk Prioritization

From Application Security to Supply-Chain Security

From Deployment to Continuous Feedback

Career opportunitiesDevSecOps EngineerDevOps EngineerApplication Security EngineerCloud Security EngineerPlatform EngineerSite Reliability Engineer
Your credential

Shareable. Verifiable. Professional.

Earn a digital credential and certificate to showcase your achievement.

  • Official IBACTP® Certificate
  • Digital Badge (Shareable)
  • Verifiable Credential
  • Showcase on LinkedIn and professional profiles
CDevSOP® digital badge
CDevSOP®Certified DevSecOps Professional
About the credential

Become a DevSecOps professional the market trusts.

Certification Designation: CDevSOP®

Certification Level: Professional

Certification Body: International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)

Program Category: DevSecOps, Secure Software Delivery, Cloud-Native Engineering & Cybersecurity

Delivery Format: Instructor-Led, Virtual Instructor-Led, Self-Paced, or Blended Learning

Program code on a dark screen

Professional level — Three-year certification cycle with continuing professional education

Recommended Training Duration: 40–60 Hours

Certification Examination: Proctored, competency-based examination with multiple-choice and scenario-based questions

Alternative Assessment Pathway: Applied DevSecOps Capstone for eligible candidates in approved instructor-led pathways

Credential Renewal Cycle: 3 Years

Program code on a dark screen
CDevSOP®

Full Syllabus and Program Details

Open any topic to read the complete program information.

Who Should Earn CDevSOP®?
CDevSOP®

Who Should Earn CDevSOP®?

CDevSOP® is designed for professionals and aspiring professionals such as:

It is also useful for cybersecurity professionals who need stronger understanding of modern software engineering and delivery pipelines.

  • DevSecOps Engineer
  • DevOps Engineer
  • Software Developer
  • Application Developer
  • Software Engineer
  • Cloud Engineer
  • Platform Engineer
  • Site Reliability Engineer
  • Application Security Analyst
  • Application Security Engineer
  • Security Engineer
  • Cloud Security Engineer
  • Infrastructure Engineer
  • CI/CD Engineer
  • Build and Release Engineer
  • Automation Engineer
  • Systems Engineer
  • Security Operations Professional
  • Technical Consultant
  • Professionals transitioning into secure software delivery
CDevSOP® Body of Knowledge — Eight Modules
Curriculum

CDevSOP® Body of Knowledge — Eight Modules

CDevSOP® Course Learning Outcomes
Learning outcomes

CDevSOP® Course Learning Outcomes

Upon successful completion, participants will be able to:

1. Apply DevSecOps and Secure SDLC Principles

Integrate security requirements, threat modeling, shared responsibility, risk awareness, and security controls throughout modern software-delivery lifecycles.

2. Apply Secure Coding and Source-Control Practices

Evaluate code security, repository controls, secrets, dependencies, development workflows, and source-code risks.

3. Build and Secure CI/CD Pipelines

Apply automated security testing, pipeline controls, artifact management, deployment gates, and secure release practices.

4. Secure Cloud Infrastructure and Infrastructure as Code

Evaluate cloud configurations, IaC templates, identity, access, network controls, automated infrastructure, and configuration risk.

5. Secure Containers, APIs, and Cloud-Native Applications

Evaluate container images, registries, orchestration, APIs, microservices, runtime environments, and cloud-native attack surfaces.

6. Manage Software Supply-Chain and Vulnerability Risk

Identify vulnerable dependencies, assess software components, interpret SBOM information, prioritize remediation, and strengthen artifact integrity.

7. Apply DevSecOps Monitoring and Operational Feedback

Use telemetry, logs, alerts, runtime findings, incidents, and operational data to improve applications and delivery pipelines.

8. Evaluate AI-Assisted and Emerging DevSecOps Technologies

Use and assess AI-assisted development, testing, remediation, automation, and emerging tools responsibly.

CDevSOP® Certification Testing Outcomes — Skills & Competencies Tested
What is assessed

CDevSOP® Certification Testing Outcomes — Skills & Competencies Tested

The CDevSOP® assessment evaluates whether candidates can apply DevSecOps knowledge to realistic development, security, cloud, and delivery scenarios.

CDevSOP®–IBACTP® DevSecOps Competency Model
CDevSOP®

CDevSOP®–IBACTP® DevSecOps Competency Model

The CDevSOP® competency model consists of eight integrated professional dimensions.

1. DevSecOps Foundations and Secure Software Lifecycle

Understand DevSecOps principles, Agile and DevOps delivery, secure SDLC, shared responsibility, security requirements, threat modeling, and integrated development practices.

2. Secure Coding, Source Control, and Application Security

Apply secure coding principles, code review, repository security, branch protection, secrets management, application-security testing, and developer security practices.

3. CI/CD Pipeline Security and Automation

Understand continuous integration, continuous delivery, build pipelines, security gates, automated testing, pipeline permissions, artifact management, and secure deployment workflows.

4. Cloud, Infrastructure as Code, and Configuration Security

Apply security to cloud infrastructure, Infrastructure as Code, configuration templates, identity, network controls, policy enforcement, and automated infrastructure delivery.

5. Containers, APIs, and Cloud-Native Security

Evaluate container images, registries, orchestration, Kubernetes concepts, APIs, microservices, service identities, runtime security, and cloud-native threats.

6. Software Supply Chain, Dependencies, and Vulnerability Management

Identify and manage open-source dependencies, packages, SBOMs, artifact integrity, vulnerabilities, third-party components, patching, and supply-chain exposure.

7. Observability, Operations, Incident Feedback, and Resilience

Apply logging, monitoring, telemetry, runtime analysis, incident feedback, reliability, recovery, post-incident learning, and continuous operational improvement.

8. AI-Assisted DevSecOps and Emerging Secure-Delivery Technologies

Evaluate AI-assisted coding, automated security testing, intelligent remediation, AI-generated code risk, agentic development tools, and emerging software-delivery technologies.

  • CDevSOP® Professional Progression
What Is CDevSOP®?
What it validates

What Is CDevSOP®?

The Certified DevSecOps Professional (CDevSOP®) validates professional competency in applying security, automation, software quality, reliability, observability, and continuous improvement across modern software development and technology delivery environments.

CDevSOP® prepares professionals to integrate security controls into workflows rather than apply them as isolated technical activities.

The certification connects:

  • Code
  • Pipeline
  • Artifact
  • Infrastructure
  • Deployment
  • Runtime
  • Feedback

This creates an integrated view of secure software delivery.

What Does CDevSOP® Cover?
CDevSOP®

What Does CDevSOP® Cover?

DevSecOps Foundations

Candidates develop an understanding of:

  • DevSecOps principles
  • DevOps culture
  • Development and operations collaboration
  • Shared security responsibility
  • Continuous delivery
  • Feedback loops
  • Automation
  • Security integration
  • Continuous improvement
Recommended Prerequisites and Eligibility
CDevSOP®

Recommended Prerequisites and Eligibility

CDevSOP® is positioned at the professional level.

Candidates benefit from familiarity with:

Prior professional DevSecOps experience is beneficial but advanced experience is not required to begin training.

Knowledge of Python, Bash, PowerShell, JavaScript, Java, .NET, Git, Docker, Kubernetes, Terraform, cloud platforms, or security testing tools may be beneficial but is not required to enter the certification learning pathway.

  • Software-development concepts
  • Operating systems
  • Cloud computing
  • Networking
  • Cybersecurity fundamentals
  • Git or version-control concepts
  • APIs
  • Scripting
  • Containers
  • CI/CD concepts
  • Application architecture
Standards and International Framework Alignment — CDevSOP®
DevSecOps

Standards and International Framework Alignment — CDevSOP®

The CDevSOP® Body of Knowledge incorporates relevant principles and practices associated with:

  • ISO/IEC 27001
  • ISO/IEC 27002
  • ISO/IEC 27005
  • ISO/IEC 27017
  • ISO/IEC 27034 application-security concepts
  • ISO/IEC 27701
  • ISO 31000
  • ISO/IEC 42001
  • ISO/IEC 23894
  • NIST Cybersecurity Framework
  • NIST Secure Software Development Framework (SSDF)
  • NIST NICE Workforce Framework
  • NIST AI Risk Management Framework
  • Relevant NIST application-security, cloud, software-supply-chain, and cybersecurity guidance
  • CISA secure-by-design and software-security guidance
  • OWASP application-security practices
  • OWASP API-security practices
  • Recognized DevOps, DevSecOps, cloud-native, secure-development, CI/CD, and software-supply-chain practices

CDevSOP® Framework Application Progression

Understand → Build → Integrate → Secure → Validate → Deploy → Monitor → Improve

Framework alignment does not constitute accreditation, recognition, approval, affiliation, or endorsement by any referenced organization.

Global and Vendor-Neutral Design — CDevSOP®
DevSecOps

Global and Vendor-Neutral Design — CDevSOP®

CDevSOP® is designed around transferable secure-delivery competencies rather than dependence on a specific:

Programming Language • Cloud Provider • CI/CD Platform • Source-Control Vendor • Container Platform • Security Scanner • IaC Tool • Monitoring Product

This allows competency to transfer across diverse development environments.

CDevSOP® Vendor-Neutral Principle

Understand the Security Principle → Integrate the Control → Automate Where Appropriate → Validate the Result

Certification Overview
CDevSOP®

Certification Overview

Build Securely. Automate Continuously. Detect Earlier. Deliver with Confidence.

The Certified DevSecOps Professional (CDevSOP®) is a comprehensive, vendor-neutral professional certification designed to validate practical competency in integrating security, automation, reliability, and continuous improvement throughout the software development and technology delivery lifecycle.

CDevSOP® prepares professionals to work effectively across modern environments where development, cybersecurity, cloud, infrastructure, platform engineering, operations, and automation increasingly converge.

The certification is designed for professionals and organizations that need to release software rapidly while maintaining appropriate standards for:

CDevSOP® recognizes that modern software delivery is no longer a simple progression from coding to deployment. Applications are built through interconnected pipelines involving source repositories, open-source dependencies, cloud infrastructure, containers, APIs, automated testing, deployment platforms, identity systems, secrets, and monitoring technologies.

As a result, DevSecOps professionals must understand how security should be integrated across the entire delivery ecosystem, not attached as a final checkpoint.

The certification integrates:

  • Security
  • Quality
  • Reliability
  • Traceability
  • Compliance
  • Resilience
  • Operational visibility
  • Continuous improvement

Secure Development + DevOps + CI/CD + Application Security + Infrastructure as Code + Cloud Security + Container Security + Software Supply Chain + Vulnerability Management + Secrets Management + Observability + Automation + AI-Assisted DevSecOps

CDevSOP® therefore focuses on a practical competency question:

“Can you build, test, secure, deploy, monitor, and continuously improve software through an integrated, automated, and risk-aware delivery lifecycle?”

CDevSOP® Professional Objective

Plan Securely → Build Securely → Test Continuously → Automate Controls → Deploy Safely → Monitor Continuously → Remediate Rapidly → Improve Continuously

Why CDevSOP®?
CDevSOP®

Why CDevSOP®?

01 / 03

Security Can No Longer Wait Until the End of Development

Traditional software-development approaches often treated security as a separate activity performed near the end of the development lifecycle.

The typical sequence was:

Design → Develop → Test → Security Review → Deploy

In that model, security teams frequently received applications only after most design and development decisions had already been made.

That creates several problems.

The longer these issues remain undiscovered, the more difficult and expensive they can become to correct.

Modern software delivery therefore requires security to be integrated much earlier—and much more continuously.

  • A weakness discovered late may require significant redesign.
  • A critical vulnerability may delay release.
  • A developer may receive security feedback long after writing the affected code.
  • A cloud environment may already contain insecure configurations.
  • Credentials or secrets may already exist in repositories.
  • Third-party libraries may introduce vulnerabilities that were never reviewed.
  • Container images may include outdated or insecure packages.
  • Build pipelines may contain excessive privileges.
  • APIs may expose functions without appropriate authorization.
02 / 03

The Cost of Late Security

Security discovered at the end of development often becomes:

CDevSOP® promotes a more integrated model where security feedback is provided as close as possible to the point where a weakness is introduced.

The goal is:

  • More expensive to remediate
  • More disruptive to delivery schedules
  • More difficult to redesign
  • More likely to create conflict between development and security teams
  • More likely to result in temporary exceptions
  • More difficult to test thoroughly before release
03 / 03

Find Earlier → Fix Faster → Reduce Rework → Improve Security

DevSecOps Changes the Delivery Model

DevSecOps connects:

Development + Security + Operations

rather than treating them as independent organizational silos.

The professional lifecycle becomes:

Plan → Code → Build → Test → Secure → Release → Deploy → Operate → Monitor → Learn

Security is incorporated throughout this lifecycle through activities such as:

The objective is not simply to perform security earlier.

It is to make security an integrated, repeatable, automated, measurable, and shared responsibility.

  • Security requirements
  • Secure architecture
  • Threat modeling
  • Secure coding
  • Peer review
  • Static application security testing
  • Software-composition analysis
  • Dependency scanning
  • Secrets detection
  • Infrastructure scanning
  • Container scanning
  • Dynamic application testing
  • API security testing
  • Policy enforcement
  • CI/CD security gates
  • Artifact validation
  • Deployment controls
  • Runtime monitoring
  • Vulnerability management
  • Incident feedback
  • Continuous remediation

Swipe or scroll sideways to see each part →

Beyond “Shift Left”
CDevSOP®

Beyond “Shift Left”

The phrase shift left is often used to describe moving security activities earlier in development.

That is important—but incomplete.

Security cannot exist only at the beginning of the lifecycle.

Some risks become visible only:

CDevSOP® therefore promotes a broader principle:

  • During build
  • During integration
  • During deployment
  • In production
  • Through runtime behavior
  • Through changing vulnerabilities
  • Through new threat intelligence
  • Through operational incidents
Security Everywhere It Adds Value Across the Delivery Lifecycle
CDevSOP®

Security Everywhere It Adds Value Across the Delivery Lifecycle

This includes both:

Shift Left

Identify design, coding, dependency, and configuration weaknesses earlier.

and

Shift Right

Use runtime telemetry, production monitoring, incident findings, and operational feedback to improve software continuously.

The result is a complete feedback loop:

Design → Build → Test → Deploy → Observe → Learn → Improve

Shared Responsibility Is Central to DevSecOps
CDevSOP®

Shared Responsibility Is Central to DevSecOps

DevSecOps does not mean turning developers into security analysts.

It does not mean forcing security teams to manage every pipeline.

It means assigning security responsibilities intelligently across the delivery lifecycle.

For example:

Developers

Apply secure coding practices and remediate code-level findings.

Security Teams

Define security requirements, provide expertise, validate risk, and establish assurance practices.

Platform and DevOps Teams

Secure pipelines, automation, infrastructure, secrets, and deployment environments.

Operations Teams

Monitor runtime environments and provide operational feedback.

Product Teams

Prioritize security alongside features, reliability, and customer needs.

Management

Establish governance, accountability, investment, metrics, and risk-acceptance authority.

CDevSOP® prepares professionals to operate effectively within this collaborative model.

The Modern Application Is a Software Supply Chain
CDevSOP®

The Modern Application Is a Software Supply Chain

Modern software is rarely written entirely by one development team.

Applications may depend upon:

This creates a complex software supply chain.

A compromise in one component can affect many downstream systems.

For example:

Compromised Dependency → Build Pipeline → Application Artifact → Container Image → Production Environment

Another scenario could be:

Stolen Pipeline Credential → Unauthorized Build → Modified Artifact → Deployment → Production Compromise

Or:

Compromised Package Repository → Malicious Dependency → Application Build → Customer Environment

CDevSOP® therefore prepares professionals to think beyond application code and evaluate the complete chain of trust associated with software delivery.

  • Proprietary source code
  • Open-source libraries
  • Third-party packages
  • Frameworks
  • Package repositories
  • Build systems
  • CI/CD pipelines
  • Development tools
  • Secrets
  • APIs
  • Containers
  • Base images
  • Cloud infrastructure
  • Infrastructure as Code
  • Artifact repositories
  • Registries
  • Third-party SaaS services
  • Identity providers
  • Deployment platforms
  • Monitoring systems
Software Supply-Chain Security Requires Visibility
CDevSOP®

Software Supply-Chain Security Requires Visibility

Effective software-supply-chain security requires professionals to understand questions such as:

This is where concepts such as:

SBOM • Signing • Provenance • Artifact Integrity • Dependency Governance • Trusted Repositories

become increasingly important.

  • What components are included in the application?
  • Where did they originate?
  • Are the package sources trusted?
  • Are dependencies vulnerable?
  • Have build artifacts been modified?
  • Can artifacts be verified?
  • Are container images trustworthy?
  • Are pipeline identities properly protected?
  • Are secrets exposed?
  • Can the organization identify affected applications quickly when a new vulnerability is disclosed?
  • Is software provenance available?
Automation Is Essential—but Must Be Governed
CDevSOP®

Automation Is Essential—but Must Be Governed

DevSecOps depends heavily on automation.

Automation can improve:

However, badly designed automation can also create significant risk.

An automated pipeline with excessive privileges can deploy insecure software at scale.

An incorrectly configured security gate can create false confidence.

Automated remediation may make damaging changes if not properly validated.

CDevSOP® therefore teaches an important principle:

  • Speed
  • Repeatability
  • Consistency
  • Scalability
  • Testing coverage
  • Configuration accuracy
  • Deployment frequency
  • Security feedback
  • Compliance evidence
DevSecOps Must Balance Security and Delivery
CDevSOP®

DevSecOps Must Balance Security and Delivery

Successful DevSecOps is not about creating as many security gates as possible.

Excessive friction can cause teams to bypass controls.

Weak controls can create unacceptable risk.

The goal is to build security processes that are:

The professional challenge becomes:

  • Risk-based
  • Timely
  • Automated where appropriate
  • Actionable
  • Developer-friendly
  • Measurable
  • Repeatable
  • Integrated into existing workflows

Security + Speed + Reliability + Developer Experience

not security at the expense of everything else.

Secure Software Development Lifecycle
CDevSOP®

Secure Software Development Lifecycle

CDevSOP® addresses security throughout the SDLC.

Relevant areas include:

The objective is to ensure that security is considered throughout the lifecycle rather than applied only at release.

  • Planning
  • Security requirements
  • Architecture
  • Threat modeling
  • Development
  • Testing
  • Release
  • Deployment
  • Operations
  • Maintenance
Agile and Continuous Delivery
CDevSOP®

Agile and Continuous Delivery

Candidates develop awareness of how security operates within Agile and rapid-delivery environments.

Coverage includes:

  • Iterative delivery
  • Product teams
  • Backlogs
  • Security stories
  • Acceptance criteria
  • Continuous feedback
  • Sprint integration
  • Automated testing
  • Frequent releases
  • Continuous improvement
Threat Modeling
CDevSOP®

Threat Modeling

Threat modeling enables teams to identify potential security issues before implementation.

CCTP® candidates learn to consider:

The progression is:

  • Assets
  • Trust boundaries
  • Data flows
  • Attack surfaces
  • Threat actors
  • Abuse cases
  • Security controls
  • Risk
  • Mitigation
  • Residual exposure
Secure Coding
CDevSOP®

Secure Coding

Secure coding is fundamental to DevSecOps.

CDevSOP® addresses:

The objective is not certification in one programming language.

It is to develop secure-development principles that transfer across languages and frameworks.

  • Input validation
  • Output handling
  • Authentication
  • Authorization
  • Session security
  • Error handling
  • Logging
  • Secrets
  • Data protection
  • Common software weaknesses
Source-Code and Repository Security
CDevSOP®

Source-Code and Repository Security

Modern repositories are critical parts of the software-delivery environment.

CDevSOP® addresses:

  • Repository access
  • Branch protection
  • Pull requests
  • Code review
  • Commit integrity
  • Secrets exposure
  • Developer permissions
  • Repository governance
  • Version control
  • Secure collaboration
CI/CD Security
CDevSOP®

CI/CD Security

CI/CD pipelines automate the movement from code to production.

Candidates learn to evaluate:

The secure pipeline progression becomes:

Commit → Build → Test → Validate → Approve → Release → Deploy

  • Pipeline stages
  • Build processes
  • Testing
  • Permissions
  • Service accounts
  • Secrets
  • Security gates
  • Artifact management
  • Release approvals
  • Deployment controls
Static Application Security Testing
CDevSOP®

Static Application Security Testing

SAST examines source or compiled code for potential security weaknesses.

Candidates develop understanding of:

The objective is not merely generating findings.

It is:

  • Static analysis
  • Rule sets
  • Findings
  • False positives
  • Severity
  • Developer feedback
  • Remediation
  • Pipeline integration
  • Finding → Validation → Prioritization → Remediation
Dynamic Application Security Testing
CDevSOP®

Dynamic Application Security Testing

DAST evaluates running applications from an external perspective.

Relevant areas include:

  • Runtime testing
  • Web application testing
  • Authentication
  • Input handling
  • Configuration
  • Common vulnerabilities
  • Test environments
  • Findings interpretation
  • Remediation
  • Validation
Software Composition Analysis
CDevSOP®

Software Composition Analysis

Modern applications often contain significant amounts of third-party and open-source code.

SCA helps organizations identify:

This enables more effective software-supply-chain visibility.

  • Libraries
  • Packages
  • Versions
  • Known vulnerabilities
  • Licensing considerations
  • Dependency relationships
  • Transitive dependencies
  • Remediation options
Dependency Management
CDevSOP®

Dependency Management

CDevSOP® addresses professional practices involving:

  • Package sources
  • Approved repositories
  • Version management
  • Updates
  • Vulnerability tracking
  • Dependency pinning concepts
  • Transitive dependencies
  • Package integrity
  • Third-party risk
Secrets Management
CDevSOP®

Secrets Management

Secrets should not be embedded directly in:

Candidates learn relevant concepts involving:

  • Source code
  • Scripts
  • Configuration files
  • Container images
  • Pipeline definitions
  • Public repositories
  • Secret stores
  • Tokens
  • API keys
  • Credentials
  • Rotation
  • Access
  • Detection
  • Revocation
  • Least privilege
Infrastructure as Code
CDevSOP®

Infrastructure as Code

Modern infrastructure is increasingly defined through code.

CDevSOP® addresses:

Infrastructure can therefore be subjected to the same security principles as application code.

  • IaC templates
  • Declarative infrastructure
  • Version control
  • Automated provisioning
  • Configuration validation
  • Security scanning
  • Drift detection
  • Repeatability
  • Change review
  • Rollback concepts
Policy as Code
CDevSOP®

Policy as Code

Policy as Code enables organizations to represent controls programmatically.

Relevant concepts include:

The objective is to convert selected policies from documents into automatable and testable controls.

  • Automated policy evaluation
  • Configuration rules
  • Deployment constraints
  • Compliance checks
  • Security guardrails
  • Pipeline enforcement
Cloud Security
CDevSOP®

Cloud Security

Modern DevSecOps environments frequently depend on cloud platforms.

Candidates develop competency involving:

  • Shared responsibility
  • Identity
  • Permissions
  • Network security
  • Data protection
  • Configuration
  • Logging
  • Cloud resources
  • Secure deployment
  • Cloud monitoring
Container Security
CDevSOP®

Container Security

CDevSOP® addresses security throughout the container lifecycle:

Build

Secure Dockerfiles and base images.

Scan

Identify vulnerable components.

Registry

Protect images and repositories.

Deploy

Apply appropriate configuration.

Runtime

Monitor container behavior.

Candidates develop familiarity with:

  • Images
  • Registries
  • Vulnerabilities
  • Privileges
  • Secrets
  • Networks
  • Runtime protection
  • Image integrity
Kubernetes Security Concepts
CDevSOP®

Kubernetes Security Concepts

CDevSOP® introduces relevant Kubernetes security concepts such as:

The certification remains vendor-neutral and does not require mastery of a particular managed Kubernetes platform.

  • Cluster architecture
  • Workloads
  • Namespaces
  • Service accounts
  • Role-based access
  • Secrets
  • Network policies
  • Admission controls
  • Image security
  • Runtime monitoring
API Security
CDevSOP®

API Security

APIs connect modern applications and services.

Candidates develop competency involving:

API security is particularly important in distributed, microservice, cloud-native, and AI-enabled environments.

  • Authentication
  • Authorization
  • Tokens
  • Input validation
  • Rate limiting
  • Data exposure
  • API discovery
  • Security testing
  • Logging
  • Monitoring
Software Supply-Chain Security
CDevSOP®

Software Supply-Chain Security

CDevSOP® addresses:

The objective is to establish confidence that software is built from expected components through trusted processes.

  • Source-code integrity
  • Dependencies
  • Package repositories
  • Build systems
  • CI/CD
  • Artifacts
  • Signing
  • Provenance
  • Container images
  • Deployment systems
  • Third-party services
Software Bill of Materials
CDevSOP®

Software Bill of Materials

Candidates develop understanding of SBOM concepts.

An SBOM can help organizations understand:

The professional progression is:

  • Which software components exist
  • Which versions are present
  • Which dependencies are included
  • Which applications may be affected by a disclosed vulnerability
  • Which suppliers contribute components
Vulnerability Management
CDevSOP®

Vulnerability Management

DevSecOps integrates vulnerability management into software delivery.

Candidates learn to consider:

The goal is to prioritize intelligently rather than treat every finding identically.

  • Severity
  • Exploitability
  • Reachability
  • Asset criticality
  • Exposure
  • Business impact
  • Compensating controls
  • Remediation
  • Risk acceptance
Security Automation
CDevSOP®

Security Automation

CDevSOP® develops competency in automating activities such as:

The principle is:

Automate Repetitive Security Activities So Humans Can Focus on Higher-Value Decisions

  • Code scanning
  • Dependency scanning
  • Container scanning
  • Secrets detection
  • IaC scanning
  • Compliance checks
  • Security gates
  • Notifications
  • Ticket creation
  • Remediation workflows
Observability and Logging
CDevSOP®

Observability and Logging

DevSecOps does not end at deployment.

Candidates develop understanding of:

Observability enables the organization to understand what is happening once software reaches production.

  • Logs
  • Metrics
  • Traces
  • Application telemetry
  • Infrastructure telemetry
  • Security events
  • Performance
  • Alerts
  • Distributed tracing
  • Runtime monitoring
Incident Feedback
CDevSOP®

Incident Feedback

Security incidents provide valuable development information.

CDevSOP® integrates:

Incident → Root Cause → Development Feedback → Control Improvement → Safer Software

This enables production lessons to improve future architecture, code, testing, deployment, and monitoring.

Reliability and Resilience
CDevSOP®

Reliability and Resilience

Secure software must also be reliable.

Candidates develop awareness of:

Security and reliability should reinforce each other.

  • Availability
  • Fault tolerance
  • Rollback
  • Recovery
  • Deployment safety
  • Health checks
  • Monitoring
  • Resilience
  • Graceful degradation
  • Incident recovery
AI-Assisted Development and Security
CDevSOP®

AI-Assisted Development and Security

Artificial intelligence is increasingly used for:

CDevSOP® evaluates both the opportunities and risks.

Relevant risks include:

  • Code generation
  • Code explanation
  • Security testing
  • Vulnerability analysis
  • Test generation
  • Documentation
  • Remediation suggestions
  • Pipeline analysis
  • Operational troubleshooting
  • Insecure generated code
  • Hallucinated recommendations
  • Exposed proprietary code
  • Sensitive-data leakage
  • Vulnerable dependencies
  • Overreliance on automation
  • Poor validation
  • CDevSOP® AI Principle
Emerging DevSecOps Technologies
CDevSOP®

Emerging DevSecOps Technologies

The DevSecOps environment continues to evolve.

CCTP® introduces candidates to relevant developments involving:

  • Platform engineering
  • Developer portals
  • Internal developer platforms
  • GitOps
  • Policy as Code
  • Supply-chain attestations
  • AI coding assistants
  • Security copilots
  • Agentic workflows
  • Automated remediation
  • Cloud-native security
  • Runtime application protection
CDevSOP® Professional Delivery Lifecycle
CDevSOP®

CDevSOP® Professional Delivery Lifecycle

CDevSOP® connects the entire professional workflow:

Requirements → Design → Code → Build → Test → Secure → Package → Deploy → Observe → Remediate → Improve

This reinforces the point that secure software delivery is not a single security activity.

It is a continuous engineering discipline.

What Makes CDevSOP® Different?
CDevSOP®

What Makes CDevSOP® Different?

CDevSOP® develops competency across several important professional transitions.

From Security Review to Security Integration

“Security will test the application before release.”

becomes:

“Security requirements and controls are integrated throughout delivery.”

From Manual Security to Automated Security

“Someone will scan the application.”

becomes:

“Appropriate security controls execute automatically within the pipeline.”

From Vulnerability Counts to Risk Prioritization

“The scanner found 500 issues.”

becomes:

“These issues create the greatest risk and require priority remediation.”

From Application Security to Supply-Chain Security

“Is our code secure?”

becomes:

“Can we trust the code, dependencies, build process, artifacts, containers, and deployment chain?”

From Deployment to Continuous Feedback

“The application is in production.”

becomes:

“Production telemetry continuously informs development, security, and reliability improvements.”

CDevSOP® Professional Value Proposition
CDevSOP®

CDevSOP® Professional Value Proposition

CDevSOP® integrates:

Secure Development + CI/CD + Application Security + Cloud + Infrastructure as Code + Containers + APIs + Software Supply Chain + Observability + Automation + AI

Its central professional objective is:

Build Securely → Test Continuously → Automate Intelligently → Deploy Safely → Monitor Effectively → Remediate Rapidly → Improve Continuously

CDevSOP® Professional Identity
CDevSOP®

CDevSOP® Professional Identity

A CDevSOP® professional should be capable of asking:

That is the professional competency CDevSOP® is designed to develop and validate.

CDevSOP® — Build Securely. Automate Continuously. Deliver with Confidence. Improve Without Stopping.

  • What security requirements apply?
  • What threats should we consider during design?
  • Is the code following secure-development practices?
  • Are repositories properly protected?
  • Are secrets exposed?
  • Are dependencies trustworthy?
  • Which security tests belong in the pipeline?
  • Should this finding block the release?
  • Is the infrastructure configuration secure?
  • Are container images trusted?
  • Are APIs appropriately protected?
  • Can artifacts be verified?
  • What components are included in the software?
  • Are we monitoring production effectively?
  • What did the last incident teach us?
  • Can this control be automated safely?
  • Is AI-generated code properly reviewed?
  • Are we delivering software both quickly and securely?
Tools, Technologies, and DevSecOps Applications
CDevSOP®

Tools, Technologies, and DevSecOps Applications

CDevSOP® remains vendor-neutral but addresses representative technologies used across secure software delivery.

Source Control and Collaboration

Git • GitHub • GitLab • Bitbucket • Pull Requests • Branch Protection

CI/CD

GitHub Actions • GitLab CI/CD • Jenkins • Azure DevOps • CircleCI • Equivalent Pipeline Platforms

Application Security Testing

SAST • DAST • SCA • Secrets Scanning • Dependency Scanning • API Security Testing

Representative technologies may include:

SonarQube • Semgrep • OWASP ZAP • Trivy • Dependency-Check • Snyk Concepts • Equivalent Platforms

Containers and Cloud Native

Docker • Kubernetes • Container Registries • Helm Concepts • Runtime Security

Infrastructure as Code

Terraform/OpenTofu Concepts • Ansible • Cloud Templates • Policy as Code

Cloud

AWS • Microsoft Azure • Google Cloud • Private/Hybrid Cloud

Observability

Prometheus • Grafana • OpenTelemetry • Logging Platforms • Cloud-Native Monitoring

Software Supply Chain

SBOM Tools • Artifact Repositories • Signing • Provenance • Package Repositories

Automation and AI

APIs • Python • Bash • PowerShell • AI Coding Assistants • Automated Analysis • Intelligent Remediation

The professional focus is:

Code → Pipeline → Artifact → Infrastructure → Deployment → Runtime → Feedback

Flexible CDevSOP® Certification Assessment
CDevSOP®

Flexible CDevSOP® Certification Assessment

Option 1 — CDevSOP® Certification Examination

Recommended structure:

Assessment emphasis:

Secure Development • CI/CD • Application Security • Cloud • IaC • Containers • Supply Chain • Monitoring • Automation

  • 100 questions
  • Multiple-choice and scenario-based questions
  • 90 minutes
  • Closed book
  • Secure online proctoring or approved testing center
  • Recommended passing score: 70%

Option 2 — Applied DevSecOps Capstone

Eligible candidates in approved instructor-led pathways may complete a structured Applied DevSecOps Capstone.

The Capstone may integrate:

Requirements → Threat Model → Code → Pipeline → Security Testing → Deployment → Monitoring → Remediation

Employment Outlook — CDevSOP®
CDevSOP®

Employment Outlook — CDevSOP®

Strong Demand at the Intersection of Software, Cloud, Cybersecurity, and Automation

The employment outlook for professionals with DevSecOps-related skills remains favorable because DevSecOps sits at the intersection of several high-growth technology disciplines:

Software Development • Cybersecurity • Cloud Computing • DevOps • Application Security • Platform Engineering • Automation • Software Supply-Chain Security • AI-Assisted Engineering

There is no single U.S. Bureau of Labor Statistics occupation titled “DevSecOps Professional” or “DevSecOps Manager.” DevSecOps responsibilities are distributed across occupations such as software developers, information security analysts, cloud and infrastructure engineers, security engineers, DevOps engineers, software engineering managers, and computer and information systems managers.

For that reason, the strongest employment outlook is obtained by examining the occupations that most closely align with CDevSOP® and CDevSOM® competencies.

CDevSOP® Employment Outlook
CDevSOP®

CDevSOP® Employment Outlook

  • Certified DevSecOps Professional (CDevSOP®)

Build Securely. Automate Continuously. Deliver with Confidence.

CDevSOP® prepares professionals for a labor market in which organizations increasingly need workers who understand both software delivery and cybersecurity.

Modern employers need professionals who can combine:

Development + Cloud + Security + Automation + CI/CD + Application Security + Software Supply Chain

The U.S. Bureau of Labor Statistics projects strong growth in several occupations directly related to this competency profile.

U.S. Employment Growth Indicators
CDevSOP®

U.S. Employment Growth Indicators

Software Developers

Software development is one of the largest occupational foundations for DevSecOps careers.

The U.S. Bureau of Labor Statistics reports approximately 1.69 million software developer jobs in 2024 and projects employment to reach approximately 1.96 million by 2034.

That represents approximately:

267,700 Additional Software Developer Jobs
CDevSOP®

267,700 Additional Software Developer Jobs

and a projected growth rate of:

15.8% from 2024–2034
CDevSOP®

15.8% from 2024–2034

This is more than five times the approximately 3.1% projected growth for all U.S. occupations. BLS also identifies software developers as having one of the largest projected increases in employment of any occupation. (Bureau of Labor Statistics)

Approximately 115,200 software developer openings per year, on average, are projected over the 2024–2034 period. (Bureau of Labor Statistics)

Information Security Analysts
CDevSOP®

Information Security Analysts

DevSecOps professionals also operate within the rapidly expanding cybersecurity workforce.

According to BLS, employment of Information Security Analysts is projected to increase from approximately:

182,800 jobs in 2024

to:

234,900 jobs in 2034

representing approximately:

52,100 New Positions
CDevSOP®

52,100 New Positions

and projected growth of:

28.5%–29%
CDevSOP®

28.5%–29%

between 2024 and 2034. (Bureau of Labor Statistics)

Approximately 16,000 information-security analyst openings per year are projected over the decade. (Bureau of Labor Statistics)

This growth rate is substantially above the projected 3.1% growth for all occupations and makes information security analysts one of the fastest-growing computer occupations in the United States. (Bureau of Labor Statistics)

Programme Facts
CDevSOP®

Software Development, QA, and Testing · 15% between 2024 and 2034

Software Development, QA, and Testing

The broader occupational group covering software developers, software quality-assurance analysts, and testers is projected by BLS to grow approximately:

15% between 2024 and 2034

with approximately:

129,200 openings annually
CDevSOP®

129,200 openings annually

on average. (Bureau of Labor Statistics)

This is highly relevant to CDevSOP® because DevSecOps integrates software engineering with:

  • Automated testing
  • Security testing
  • Quality assurance
  • CI/CD
  • Secure release
  • Runtime monitoring
Why Demand Is Expected to Continue
CDevSOP®

Why Demand Is Expected to Continue

BLS specifically identifies continued expansion of software for:

as contributors to software-development demand.

BLS also expects organizations to increase investment in software protecting electronic networks and infrastructure because of cybersecurity concerns. (Bureau of Labor Statistics)

That combination is particularly significant for DevSecOps because the discipline brings together software development, automation, cybersecurity, and secure infrastructure.

  • Artificial intelligence
  • Internet of Things
  • Robotics
  • Automation
Cybersecurity Skills Demand Supports DevSecOps
CDevSOP®

Cybersecurity Skills Demand Supports DevSecOps

The 2025 ISC2 Cybersecurity Workforce Study, based on responses from 16,029 cybersecurity professionals and decision-makers globally, found that organizations increasingly face a skills shortage rather than merely a headcount shortage. (ISC2)

Among respondents:

Several skills particularly relevant to DevSecOps ranked among the most needed:

This is particularly relevant to CDevSOP® because its Body of Knowledge combines application security, cloud security, secure engineering, automation, AI-assisted development, and risk-based remediation.

Skill AreaOrganizations Reporting Need
AI 41%
Cloud Security 36%
Risk Assessment 29%
Application Security 28%
Security Engineering 27%
Governance, Risk & Compliance 27%
  • 95% reported at least one cybersecurity skills need.
  • 59% reported critical or significant skills needs.
  • 23% reported one or more critical skills needs.
  • 36% reported significant skills shortages. (ISC2)
Hiring Managers Are Prioritizing Related Skills
CDevSOP®

Hiring Managers Are Prioritizing Related Skills

ISC2 found that cybersecurity hiring managers identified:

Cloud Security — 29%

AI — 27%

Security Engineering — 24%

Security Analysis — 23%

Risk Assessment — 23%

among technical skills they were prioritizing in hiring. (ISC2)

A separate ISC2 hiring study reported that nearly 90% of surveyed hiring managers had open cybersecurity positions, while 75% planned to hire additional cybersecurity professionals in 2025. (ISC2). These data support the growing value of professionals capable of combining software engineering with cloud and security competencies.

CDevSOP® Salary Outlook
CDevSOP®

CDevSOP® Salary Outlook

DevSecOps Engineer — U.S. Market Benchmark

Because BLS does not publish a separate wage category for “DevSecOps Engineer,” current market salary benchmarks provide useful supplementary guidance.

As of July 1, 2026, Salary.com reported an average U.S. salary for a DevSecOps Engineer of approximately:

$137,495 per year
CDevSOP®

$137,495 per year

or approximately:

$66 per hour
CDevSOP®

$66 per hour

The reported compensation distribution was approximately:

(Salary)

Salary.com's experience-based estimates showed considerable progression:

(Salary)

These are market estimates rather than BLS occupational medians and can vary significantly by employer, location, clearance requirements, technical specialization, and experience.

PercentileAnnual Salary
10th percentile $115,731
25th percentile $126,103
Average $137,495
75th percentile $145,943
90th percentile $153,634
Experience LevelEstimated Annual Salary
Entry / <1 year $83,443
Early Career / 1–2 years $101,283
Mid-Level / 2–4 years $135,735
Senior / 5–8 years $151,829
Expert / 8+ years $167,756
Related Official U.S. Salary Benchmarks
CDevSOP®

Related Official U.S. Salary Benchmarks

BLS provides useful compensation benchmarks for occupations closely related to DevSecOps.

Software Developers

The BLS median annual wage for software developers was:

$133,080 in May 2024
CDevSOP®

$133,080 in May 2024

(Bureau of Labor Statistics)

More recent BLS Occupational Employment and Wage Statistics for May 2025 reported approximately:

(Bureau of Labor Statistics)

  • 1,687,890 employed software developers
  • $148,100 mean annual wage
  • $71.20 mean hourly wage

Information Security Analysts

The BLS median annual wage for information security analysts was:

$124,910 in May 2024
CDevSOP®

$124,910 in May 2024

(Bureau of Labor Statistics)

These figures demonstrate that both of the major occupational foundations underlying DevSecOps—software engineering and cybersecurity—are relatively highly compensated compared with the $49,500 median annual wage for all U.S. workers in 2024. (Bureau of Labor Statistics)

Current DevSecOps Job-Posting Examples
CDevSOP®

Current DevSecOps Job-Posting Examples

Actual compensation may be considerably higher for positions requiring specialized cloud, security, clearance, platform, or senior engineering capabilities.

Recent 2026 U.S. postings included:

These examples are individual job postings—not national salary averages—but demonstrate the potential compensation range for professionals with specialized DevSecOps capabilities.

  • A CACI DevSecOps Engineer position listing a national salary range of approximately $98,500–$206,800. (Indeed)
  • A Boeing Senior Software Engineer–DevSecOps posting listing approximately $136,850–$185,150. (Indeed)
  • A DevSecOps contract role listed at approximately $60–$65 per hour. (Indeed)
Potential Careers for CDevSOP® Professionals
CDevSOP®

Potential Careers for CDevSOP® Professionals

CDevSOP® competencies may support career development toward roles such as:

  • DevSecOps Engineer
  • DevOps Engineer
  • Application Security Engineer
  • Cloud Security Engineer
  • Platform Engineer
  • Site Reliability Engineer
  • Secure Software Engineer
  • Security Automation Engineer
  • CI/CD Engineer
  • Software Security Engineer
  • Product Security Engineer
  • Infrastructure Automation Engineer
  • Cloud Engineer
  • Container Security Engineer
  • Kubernetes Security Engineer
  • Application Security Analyst
  • Software Supply-Chain Security Specialist
  • Security Engineer
  • Build and Release Engineer
High-Value Skill Combinations
CDevSOP®

High-Value Skill Combinations

Professionals may strengthen their employment potential by combining DevSecOps competency with expertise in:

Cloud + Cybersecurity + Software Engineering + Containers + Infrastructure as Code + CI/CD + Application Security + Automation + AI

Particularly valuable combinations include:

DevSecOps + Cloud Security

Cloud security remains one of the most significant cybersecurity skills needs. ISC2 reported it as the top technical skill prioritized by hiring managers at 29% in its 2025 research. (ISC2)

DevSecOps + Application Security

Application security was identified as a significant skills need by 28% of cybersecurity respondents. (ISC2)

DevSecOps + AI

AI was the most frequently cited cybersecurity skills need in the ISC2 study at 41%. (ISC2)

DevSecOps + Security Engineering

Security engineering was identified as an important skills need by 27% of respondents. (ISC2)

CDevSOP® Employment Outlook Summary
CDevSOP®

CDevSOP® Employment Outlook Summary

15.8%

Projected U.S. software-developer employment growth, 2024–2034. (Bureau of Labor Statistics)

267,700

Projected additional U.S. software-developer jobs by 2034. (Bureau of Labor Statistics)

28.5%

Projected U.S. information-security analyst growth, 2024–2034. (Bureau of Labor Statistics)

52,100

Projected additional information-security analyst jobs by 2034. (Bureau of Labor Statistics)

$137,495

July 2026 market-average salary estimate for U.S. DevSecOps Engineers. (Salary)

$148,100

May 2025 BLS mean annual wage for U.S. software developers. (Bureau of Labor Statistics)

$124,910

2024 BLS median annual wage for information security analysts. (Bureau of Labor Statistics)

95%

Cybersecurity respondents reporting at least one skills need in ISC2's 2025 global study. (ISC2)

The examination

Exam & Certification Details

Everything you need to plan your sitting.

CDevSOP-100

Exam code for the Professional-level DevSecOps credential.

100 questions (maximum)

Multiple choice, completed in 120 minutes.

700 out of 1000

Passing score. Delivered in English.

Recommended experience

A minimum of two years of experience in devsecops or a closely related technology discipline.

Where you sit it

IBACTP® approved testing centers and online proctored delivery

Staying certified

Three-year certification cycle with continuing professional education

Choose your route

Four ways to enroll. One credential.

Every route leads to the same CDevSOP® examination and the same designation.

Option 1

Self-Paced Learning

Self-study
$400 USD
  • Exam fee only
  • Complimentary course materials provided
Option 2

Virtual Instructor-Led Training

4 days
$1,200 USD
  • 4 days, 2 hours daily online
  • Includes all course materials + Exam
Select a Date and Purchase
Option 3

Bootcamps & Intensives

10 days
$1,800 USD
  • 10 days, 2 hours daily
  • Includes all course materials + Exam
Select a Date and Purchase
Option 4

Corporate Training

Your schedule
Fees negotiable
  • Certify a whole team on a schedule that suits your organization
  • Fees depend on the team's size / number
Request a Team Quote
Progression

Your Certification Pathway

Start as a Professional. Advance as a Leader.

28+ Certifications
14 Technology Disciplines
Global Recognition
Industry Validated
Your Career Our Mission