Skip to content

ISTQB Certified Tester
Security Test Engineer (CT-STE)

ISTQB Certified Tester Security Test Engineer (CT-STE) certification logo.

Cybersecurity threats continue to grow in frequency, complexity and impact. Organisations therefore need testing professionals who can identify security weaknesses, evaluate risk exposure and provide clear evidence about whether systems are adequately protected.

The ISTQB® Certified Tester – Security Test Engineer (CT-STE) certification equips professionals with the knowledge and practical approaches needed to plan, design, execute and report security testing activities.

CT-STE focuses on the engineering side of security testing. It covers security paradigms, risk-based test approaches, security test techniques, standards, regulations, organisational context, software development lifecycle models, vulnerability analysis, security reporting and security testing tools.

The certification also explains how security test results contribute to an Information Security Management System (ISMS) and ongoing security risk management.

Whether you work in software testing, development, operations, quality assurance or information security, CT-STE provides internationally recognised guidance for conducting structured, evidence-based security testing.

ISTQB® Certified Tester – Security Test Engineer (CT-STE)
Security paradigm
Asset Security Levels
Security Audits
The Concept of Zero Trust
Open-Source Software (OSS)
Security Test Techniques
Applying Security Test Types According to a Test Context
Applying Security Testing
The Security Test Process
The Security Test Process
Designing Security Tests
Standards and Best Practices
Introduction to Standards and Best Practices
Apply Important Standards and Best Practices for Security Testing
Leveraging Standards and Best Practices
Adjusting to the Organizational Context
The Impact of Organizational Structures in the Context of Security Testing
The Impact of Regulations on Security Policies and How to Test Them
Analyzing an Attack Scenario
Adjusting to Software Development Lifecycle Models
The Effects from Different Software Development Models on Security Testing
Security Testing During Operations and Maintenance
Security Testing as Part of an Information Security Management System
Acceptance Criteria for Security Testing
Input for an Information Security Management System (ISMS)
Improving an ISMS by Adjusted Security Testing
Reporting Test Results
Security Test Reporting
Identifying and Analyzing Vulnerabilities
Close Identified Vulnerabilities
Security Test Tools
Categorization of Security Test Tools
Applying Security Test Tools

Exam Structure

Candidates qualify for extra time if they are not writing the exam in their native language. Extra time needs to be applied for upon completing the exam registration form. 

No. of Questions: 40
Duration: 75 Min
Pass Mark: 65%
Extra Time (Non-Native Language): 19 Min
Lifetime Validity
Prerequisite: ISTQB Foundation (CTFL)

Exam Price

R 2 900

Why Get ISTQB CT-STE Certified?

Security testing helps organisations understand their actual exposure to threats before vulnerabilities are exploited in production.

By earning the ISTQB Certified Tester – Security Test Engineer certification, you will be able to:

Understand fundamental security paradigms and their effect on testing
Assess asset security levels and security risks
Apply appropriate security test techniques
Select security test types based on the system and risk context
Plan, design and execute structured security tests
Apply recognised standards and security best practices
Adapt security testing to organisational structures and regulations
Analyse attack scenarios and possible vulnerabilities
Adjust security testing to different development lifecycle models
Support security testing during operations and maintenance
Feed testing results into an Information Security Management System
Collect, evaluate and report security test evidence
Support vulnerability remediation
Identify requirements for security testing tools
Demonstrate internationally recognised security testing expertise

The certification is vendor-neutral and focuses on transferable security testing principles rather than a particular product, platform or security tool.

Who Is the ISTQB CT-STE Certification For?

The ISTQB CT-STE certification is designed for professionals involved in testing IT systems for security.

This certification is ideal for:

Software Testers
Security Testers
Test Analysts
Technical Test Analysts
Test Engineers
Test Managers
QA Engineers
Quality Engineers
Software Developers
Security Engineers
Information Security Professionals
DevOps and DevSecOps Professionals
Operations Team Members
Business Analysts
Project Managers
Quality Managers
Software Development Managers
IT Directors
Management Consultants

Understand how security testing should be planned, performed, evaluated and reported within modern software environments.

Download Documents

Download the documents below for more information about the syllabus, exam structure, and sample exam questions for the ISTQB Certified Tester – Security Test Engineer (CT-STE) certification.

Please note that these documents are intended for informational purposes only and should not be considered official study material. For effective exam preparation, SASTQB recommends using accredited training course material and attending an accredited training course.

ISTQB Certified Tester Security Test Engineer (CT-STE) certification logo.

FAQ’s About ISTQB Security Test Engineer (CT-STE)

Q: What is the ISTQB Security Test Engineer certification?

The ISTQB CT-STE certification is a specialist qualification focused on planning, designing, executing, evaluating and reporting security tests. It covers security test techniques, standards, vulnerabilities, organisational context, lifecycle integration, ISMS support and security testing tools.

Q: Who should take the CT-STE certification?

CT-STE is suitable for software testers, security testers, test analysts, test engineers, developers, QA professionals, security engineers, DevSecOps professionals and anyone involved in testing IT systems for security.

Q: How is CT-STE different from CT-SEC?

CT-STE focuses on the practical engineering and execution of security testing, including test techniques, test processes, vulnerability analysis, reporting, standards, ISMS integration and tool selection.

CT-SEC is an Advanced Level Specialist certification that covers broader and more advanced security testing responsibilities, including policies, strategy, risk, security mechanisms, human factors and security test management.

The two certifications cover related areas but serve different levels and professional needs.

Q: Does CT-STE cover penetration testing?

CT-STE includes security test techniques, attack scenario analysis and vulnerability identification. However, it is broader than a penetration testing course and focuses on structured security testing throughout the software lifecycle.

Q: What is Zero Trust?

Zero Trust is a security approach based on the principle that no user, device, service or connection should automatically be trusted. Access should be continuously verified based on identity, context and risk.

Q: Does CT-STE cover open-source software security?

Yes. The syllabus includes security considerations relating to open-source software and the risks that external components and dependencies may introduce.

Q: Does CT-STE cover security standards?

Yes. The certification covers how security testing standards and recognised best practices can be applied and adapted to a specific organisational and technical context.

Q: Does CT-STE cover security testing in Agile and DevOps environments?

Yes. The syllabus addresses the effect of different software development lifecycle models on security testing, including how security testing should be adapted for modern delivery approaches.

Q: What is an Information Security Management System?

An Information Security Management System, or ISMS, is a structured framework for managing information security risks, policies, controls and improvement activities. CT-STE covers how security test results can support and improve an ISMS.

Q: Does CT-STE cover security testing tools?

Yes. The syllabus covers security testing tool categories, tool requirements, tool selection and the effective application of tools within a security testing approach.

Q: Is CT-STE tool-specific?

No. CT-STE is vendor-neutral. It teaches principles, methods and selection criteria that can be applied across different security testing tools and platforms.

Q: Is the CT-STE certification internationally recognised?

Yes. CT-STE is an internationally recognised ISTQB Specialist certification focused on security test engineering.

Q: Can I prepare through self-study?

Yes. Candidates may prepare through self-study using the official syllabus and recommended references. However, SASTQB recommends attending training through an ISTQB Accredited Training Provider for comprehensive, syllabus-aligned preparation.

Q: What certification should I take after CT-STE?

After completing CT-STE, candidates may consider the ISTQB Security Tester certification, other Specialist certifications or Advanced Level modules aligned with their security, technical testing or test management goals.