Draft:Certified DevSecOps Professional
Where to get help
How to improve a draft
You can also browse Wikipedia:Featured articles and Wikipedia:Good articles to find examples of Wikipedia's best writing on topics similar to your proposed article. Improving your odds of a speedy review To improve your odds of a faster review, tag your draft with relevant WikiProject tags using the button below. This will let reviewers know a new draft has been submitted in their area of interest. For instance, if you wrote about a female astronomer, you would want to add the Biography, Astronomy, and Women scientists tags. Editor resources
|
The Certified DevSecOps Professional (CDP) is a practitioner-level certification in DevSecOps issued by Practical DevSecOps, a subsidiary of HYSN Technologies Inc. The certification evaluates competency in integrating security practices into continuous integration and continuous delivery (CI/CD) pipelines and is listed in the CISA national training catalog.
Issuing organization
[edit]Practical DevSecOps is operated by HYSN Technologies Inc., incorporated in Delaware with offices in Newark, New Jersey, and Singapore. The company was founded by Mohammed A. Imran, a security professional who delivered training at Black Hat USA 2018 titled "Practical DevSecOps: Continuous Security in the Age of Cloud."[1] Practical DevSecOps instructors have also delivered training at Hack In The Box (HITB) international security conferences, including HITBSecConf Singapore and HITB CyberWeek.[2][3]
Certification
[edit]The CDP is included in the Cybersecurity and Infrastructure Security Agency (CISA) National Initiative for Cybersecurity Careers and Studies (NICCS) training catalog.[4] TechTarget's SearchSecurity listed the CDP among recommended DevSecOps certifications for cybersecurity professionals, alongside offerings from DevOps Institute, EXIN, and EC-Council.[5]
Exam format
[edit]The CDP exam consists of five scenario-based challenges administered within a 12-hour hands-on window, followed by a 24-hour period for report submission. Candidates must achieve a minimum score of 80% to pass. The examination contains no multiple-choice questions; performance is assessed entirely within a live lab environment.[6]
Course curriculum
[edit]The preparatory course covers nine modules including CI/CD pipeline security, static application security testing (SAST), dynamic application security testing (DAST), infrastructure as code (IaC), compliance as code (CaC), software composition analysis (SCA), and vulnerability management.[6] The certification carries no expiration date and does not require periodic recertification.[6]
See also
[edit]References
[edit]- ^ "Practical DevSecOps – Continuous Security in the Age of Cloud". Black Hat. Retrieved 2026-06-18.
- ^ "Mohammed A. Imran – HITBSecTrain". Hack In The Box. Retrieved 2026-06-18.
- ^ "Secure Coding and DevSecOps – HITB CyberWeek 2020". HITBSecTrain. Retrieved 2026-06-18.
- ^ "Certified DevSecOps Professional (CDP) – NICCS Training Catalog". National Initiative for Cybersecurity Careers and Studies, Cybersecurity and Infrastructure Security Agency. Retrieved 2026-06-18.
- ^ "Top DevSecOps certifications and trainings". SearchSecurity. TechTarget. Retrieved 2026-06-18.
- ^ a b c "Certified DevSecOps Professional (CDP)". Practical DevSecOps. Retrieved 2026-06-18.
Category:Computer security certifications Category:DevOps Category:Professional certifications in computing

- provide significant coverage: discuss the subject in detail, not just brief mentions or routine announcements;
- are reliable: from reputable outlets with editorial oversight;
- are independent: not connected to the subject, such as interviews, press releases, the subject's own website, or sponsored content.
Please add references that meet all three of these criteria. If none exist, the subject is not yet suitable for Wikipedia.