If you have been searching for the ISTQB Certified Tester Security Tester, the CT-SEC exam, there is something you need to know before you book anything: ISTQB split it. The 2016 CT-SEC syllabus became two separate credentials, and the one that exists today for hands-on work is the Certified Tester Security Test Engineer, exam code CT-STE, released in January 2025. A second credential, Security Test Analyst or CT-STA, is due to follow. Nothing carries over automatically between them. This matters because a good deal of the material still circulating online describes the old syllabus as current. This article sets out what CT-STE actually contains, what the exam costs and how it is scored, what its nine syllabus areas ask, why two of them are noticeably harder than the rest, and what you need in place before you can sit it.
What Is the ISTQB Security Test Engineer Certification?
CT-STE is ISTQB’s specialist credential for people who carry out security testing as part of a software testing practice. It sits above ISTQB Foundation Level and covers the practical execution of security testing: choosing techniques, running a security test process, applying industry standards, and reporting what you find in a way an organisation can act on.
The framing is deliberately different from a penetration testing certification. ISTQB is explicit about this.
“Penetration testing is just one aspect of security testing. ISTQB’s security testing syllabus takes a broader approach, emphasizing shift-left testing – integrating security testing from the earliest stages of software development.”
That single sentence explains most of the syllabus. If you expect an exam about exploiting a vulnerable web application, you will be surprised by how much of CT-STE is about process, lifecycle, organisational context and reporting. The exam is aimed at making security testing a normal part of how software is built, not a specialist raid conducted at the end.
Who it is written for
Test engineers and QA leads adding a security specialism are the core audience. Security professionals sometimes take it too, usually when they need to work credibly alongside a test team and want the shared vocabulary. What it is not is an entry-level security credential, because ISTQB Foundation Level is a hard requirement before you can sit it.
Why Did CT-SEC Become CT-STE and CT-STA?
Because the 2016 syllabus tried to serve two different jobs at once. ISTQB’s own account is that the old CT-SEC combined multiple roles and activities, which made it complex and hard to navigate. The replacement separates execution from strategy: CT-STE covers carrying out security testing, and CT-STA will cover analysing business security risk and defining testing strategy.
Two consequences follow, and both catch people out. First, CT-STE was released in January 2025, so any study material describing a 2015 or 2016 syllabus is describing something else. Second, there is no grandfathering. Holding CT-SEC does not convert into either new credential; you sit the new exam or you do not hold it.
| Credential | Status | Focus |
|---|---|---|
| CT-SEC, Security Tester | Replaced, 2016 syllabus | Combined execution and analysis in one paper |
| CT-STE, Security Test Engineer | Current, released January 2025 | Practical execution of security testing |
| CT-STA, Security Test Analyst | Announced for 2026 | Business security risk and test strategy |
If you were part way through preparing for CT-SEC, the honest position is that some of your knowledge transfers and some of it does not. The Human Factors chapter that features heavily in old CT-SEC study notes has no counterpart in CT-STE. In its place you get zero trust, open-source reuse, and a full area on information security management systems. Details of the split are set out on the official CT-STE page.
What Is on the CT-STE Exam, and What Does It Cost?
CT-STE is 40 multiple choice questions in 75 minutes, costing USD $249 and delivered through Pearson VUE. The scoring is worth understanding: the 40 questions are worth 43 points in total, and the pass mark is 28 of those 43, which works out at roughly 65%. Some questions therefore carry more weight than others.
| Exam detail | Value |
|---|---|
| Certification | ISTQB Certified Tester Security Test Engineer |
| Exam code | CT-STE |
| Questions | 40 |
| Total points | 43 |
| Passing score | 28 of 43, about 65% |
| Duration | 75 minutes |
| Fee | USD $249 |
| Format | Multiple choice |
| Delivery | Pearson VUE |
| Prerequisite | ISTQB Foundation Level |
Forty questions in 75 minutes gives you close to two minutes each, which is comfortable by certification standards. The pressure in this exam is not the clock. It is that a third of the points come from areas asking you to analyse a situation rather than recall a definition, and analysis questions have long stems.
The mismatch between 40 questions and 43 points is worth a second thought. It means at least three questions are weighted more heavily, so a wrong answer on one of those costs more than a wrong answer elsewhere. There is no way to identify them during the exam, which is another argument for even coverage.
What Do the Nine Syllabus Areas Cover?
CT-STE publishes no percentage weightings, but it does something more useful: it publishes a teaching-time allocation in minutes and a cognitive K-level for every area. Nine areas total 1,290 minutes of teaching time, and the split tells you exactly where the syllabus thinks the difficulty lies.
| Syllabus area | Time | Level |
|---|---|---|
| Security Paradigms | 135 minutes | K3 |
| Security Test Techniques | 150 minutes | K3 |
| The Security Test Process | 120 minutes | K3 |
| Security Testing Standards and Best Practices | 195 minutes | K3 |
| Adjusting Security Testing to the Organizational Context | 195 minutes | K4 |
| Adjusting Security Testing to Software Development Lifecycle Models | 165 minutes | K4 |
| Security Testing as Part of an Information Security Management System | 105 minutes | K3 |
| Reporting Security Test Results | 135 minutes | K3 |
| Security Testing Tools | 90 minutes | K3 |
What the shape tells you
Standards and Best Practices and Organizational Context tie for the largest allocation at 195 minutes each. Security Testing Tools is the smallest at 90, which is a useful corrective for anyone assuming a security testing exam will be tool-heavy. It is not: tools are the shortest area on the syllabus and are pitched at understanding categories and selection criteria rather than operating any specific product.
Security Paradigms opens the syllabus with concepts that were not in the old exam at all, including asset security levels, the role of security testing in audits, zero trust, and the security implications of reusing open-source software. Security Test Techniques then gets specific: black-box, white-box and greybox contexts, static against dynamic testing, and testing identity and access controls, data protection controls and protective technologies.
Why Are the Two K4 Areas the Hard Part?
ISTQB grades objectives by cognitive level. K3 means apply, which is what most of this syllabus asks. K4 means analyse, and only two areas reach it: Adjusting Security Testing to the Organizational Context, and Adjusting Security Testing to Software Development Lifecycle Models. Together they carry 360 of the 1,290 minutes, well over a quarter of the syllabus.
The difference is not academic. A K3 objective asks you to apply a technique you have learned. A K4 objective hands you a situation and asks you to work out which considerations apply and why, with no single obvious mapping. Those questions have longer stems, more plausible distractors, and no shortcut.
Organizational context
You are asked to analyse an organisational context and determine which aspects matter for security testing, to analyse how regulation shapes security policy and how to test that policy, and to analyse an attack scenario to identify the likely source and motivation. That last one is unusual for a testing exam and rewards people who have read incident writeups rather than only test plans.
Lifecycle models
Here you analyse how security testing activities change across different development lifecycle models, and you define and perform security regression and confirmation testing off the back of a system change. Anyone who has only worked in one delivery model will find this the thinnest ground, because the question is precisely about the differences between models.
Practical advice: give these two areas more than a proportional share of your preparation. Twenty-eight per cent of teaching time at the harder cognitive level plausibly means rather more than 28% of the difficulty.
Which Standards Does the Exam Expect You to Apply?
Four are named directly in the syllabus objectives, and the wording is “apply the concept of”, not “be aware of”. You need to know what OWASP, CWE, CVE and CVSS are, what each is for, and how a security tester would actually use them. Standards and Best Practices is one of the two largest areas at 195 minutes.

- OWASP for the testing methodology and the common web application weakness categories
- CWE, the Common Weakness Enumeration, for classifying the type of a weakness
- CVE, the Common Vulnerabilities and Exposures list, for identifying specific known vulnerabilities
- CVSS and the Common Weakness Scoring System for expressing severity in a comparable way
The distinction between CWE and CVE trips people up and is exactly the kind of thing a multiple choice exam tests. A CWE describes a class of weakness, such as improper input validation. A CVE identifies one concrete instance of a weakness in a specific product. Scoring then sits on top: the CVSS scoring framework gives a severity number you can compare across findings, which is what makes a report actionable.
For methodology, the OWASP Web Security Testing Guide is the closest thing to a practical companion to this part of the syllabus, and the weakness taxonomy itself is maintained as the Common Weakness Enumeration. The syllabus also asks about the advantages and disadvantages of test oracles in security testing, which is a subtler point: for a security test, knowing what the correct outcome should look like is often the hardest part of the design.
Do You Need Programming or Foundation Level First?
Foundation Level is mandatory. ISTQB requires a valid Certified Tester Foundation Level certificate before you can sit CT-STE, and there is no route around it. Programming is a different matter: ISTQB states that a technical background helps but is not required, and that the syllabus is written to be accessible regardless of programming experience.

That is a genuine design decision rather than a marketing line. Read the objectives and you find “describe how to test”, “analyze”, “evaluate” and “explain” far more often than anything requiring you to write code. Where technical depth appears, such as static and dynamic analysis tools, the objective is to understand the concepts and use cases rather than to operate a scanner.
What actually helps
- Having sat in a real security test planning conversation, so organisational context is not hypothetical
- Having read vulnerability reports, which makes the reporting and severity material concrete
- Familiarity with more than one development lifecycle model, which directly serves a K4 area
- Working knowledge of identity and access controls, since testing them is an explicit objective
If Foundation Level is the piece you are missing, that is where to start rather than here. The ISTQB Foundation Level route sets out what that exam covers, and the wider ISTQB certification catalogue shows how the specialist tracks branch off it. ISTQB’s own current listing of every active exam is kept on its certification catalogue page, which is the place to confirm a syllabus version before you buy any study material.
How Should You Prepare for CT-STE?
Use the published teaching times as your budget and the K-levels as your difficulty multiplier. Nine areas over 1,290 minutes means the syllabus itself has told you where the weight sits, and the two K4 areas deserve more than their share because analysis questions cannot be revised by memorisation.
- Confirm your ISTQB Foundation Level certificate is valid before anything else, because it is a hard prerequisite and there is no route around it.
- Discard any study material built on the 2015 or 2016 CT-SEC syllabus, since the Human Factors chapter and much else in it has no counterpart in CT-STE.
- Read the current syllabus end to end once without taking notes, so the shape of the nine areas is familiar before you start studying any of them in depth.
- Spend your largest blocks on the two K4 areas, organisational context and lifecycle models, because analysis-level questions carry long stems and plausible distractors.
- Learn the four named standards properly, drilling the difference between a CWE class and a CVE instance until it is automatic, then layering CVSS severity on top.
- Practise writing up a finding as a report, since a whole area covers reporting, confidentiality of results, and evaluating techniques for closing a vulnerability.
- Finish with timed practice at under two minutes a question, tracking wrong answers by syllabus area so you can see which of the nine still needs work.
The full area list with every objective is published on the CT-STE syllabus breakdown, which is the reference to check your coverage against before booking.
Frequently Asked Questions
Is the ISTQB CT-SEC Security Tester exam still available?
It has been replaced. ISTQB split the 2016 CT-SEC syllabus into CT-STE, released in January 2025, and CT-STA, scheduled for 2026. If you are choosing an ISTQB security credential today, CT-STE is the one covering practical security testing.
Does CT-SEC convert into CT-STE?
No. ISTQB states there is no automatic transfer or grandfathering between the old and new credentials. A CT-SEC holder who wants CT-STE or CT-STA has to pass that exam in the usual way.
How many questions are on the CT-STE exam?
Forty multiple choice questions in 75 minutes. They are worth 43 points in total, so a few carry extra weight, and the pass mark is 28 points, which comes out at roughly 65%.
What are the prerequisites for the CT-STE exam?
A valid ISTQB Certified Tester Foundation Level certificate is required before you can sit it. There is no experience requirement written into the entry criteria, though the syllabus assumes working familiarity with testing practice.
Do you need programming skills for this certification?
No. ISTQB says a technical background such as knowledge of network protocols and firewalls is beneficial but not mandatory, and the syllabus is written to be accessible regardless of programming experience.
How much does the CT-STE exam cost?
USD $249, booked through Pearson VUE. Prices are set regionally by ISTQB member boards, so the figure you see at checkout can differ depending on where you sit the exam.
Which syllabus area is hardest?
The two graded at K4: adjusting security testing to the organisational context, and to different lifecycle models. Together they take 360 of the syllabus’s 1,290 teaching minutes and ask you to analyse rather than apply.
Is CT-STE a penetration testing certification?
No. ISTQB positions penetration testing as one part of security testing and builds the syllabus around shift-left practice, process, standards and reporting instead. Expect far more about test design and lifecycle than about exploitation.
Does the exam cover specific security tools?
Only lightly. Security Testing Tools is the smallest area at 90 minutes and asks you to categorise tools and understand static and dynamic testing concepts, not to operate any named product.
Is the syllabus useful outside regulated industries?
Yes. ISTQB states the syllabus is not limited to any industry and explicitly addresses different regulatory contexts, including how standards apply differently in regulatory as against contractual situations.
Conclusion
The single most valuable thing to take away is that the exam most people are searching for no longer exists in the form they expect. CT-SEC was split, CT-STE is the current execution-focused credential, and nothing transfers automatically. Once you are aiming at the right target, the syllabus is unusually generous with planning information: nine areas, a published teaching time for each, and a K-level that tells you which two will hurt. Budget accordingly, get Foundation Level in place first, and learn the four named standards properly rather than in outline. Check your coverage against the current syllabus areas before you book, and let timed practice tell you which of the nine still needs work.
