The EC-Council DevSecOps Essentials (D|SE) exam, code 112-55, is a two-hour, 75-question proctored test with a 70% passing score and no eligibility prerequisites. Its blueprint defines ten domains, from application development concepts (16%) through implementing security into the CI/CD pipeline and testing (12%) to monitoring and feedback (8%). This guide gives you those weights, the registration and renewal facts, and a study sequence that prioritizes the heaviest domains — plus what EC-Council says about preparing from the blueprint rather than from courseware alone.
What the DSE credential covers
DevSecOps Essentials (D|SE) is EC-Council's entry-level program in secure application development. It teaches you to identify application development risks and to secure and test applications across on-premises, cloud, and hybrid infrastructures, and it requires no prior IT or cybersecurity experience.
EC-Council positions D|SE for fresh graduates, career starters and switchers, professionals, and IT or cybersecurity teams with little or no work experience. The associated course includes 12 modules, 12 hours of self-paced video training, and 9 practical labs, with a capstone project to apply the material.
If you already have experience and want a deeper credential, EC-Council points to the Certified DevSecOps Engineer (E|CDE) as the advanced option. D|SE is the essentials-level step; the two programs have different scope, so choose your study material for the one you intend to test.
Official sources: DevSecOps Essentials (D|SE) — EC-Council certification page — Program description, Exam Details, and FAQ sections
Exam format and key facts
The D|SE exam (prefix 112-55) has 75 questions, lasts 2 hours, and requires a 70% score to pass. It is delivered proctored through the ECC Exam Center.
Every EC-Council exam is proctored: a trained representative authorized by EC-Council administers the session and must be able to view you and the exam throughout. If the proctor cannot see you while you test, the result is not valid and the test must be rescheduled — so plan a quiet, compliant setup before exam day.
EC-Council reserves the right to revoke certification if you do not comply with its examination policies, so it is worth reading those policies before you sit the exam, not after.
- Questions: 75
- Duration: 2 hours
- Passing score: 70%
- Delivery: proctored, within the ECC Exam Center
Official sources: DevSecOps Essentials (D|SE) — EC-Council certification page — Program description, Exam Details, and FAQ sections; EC-Council certification FAQ — Exam Preparation section
The ten exam domains and their weights
The official 112-55 blueprint defines ten domains. Application Security Fundamentals carries the largest weight at 20%, followed by Application Development Concepts at 16% and Implementing Security into the CI/CD Pipeline and Testing at 12%. The remaining domains are each weighted 8%, except Introduction to DevOps at 4%.
The blueprint is your scope authority. Its sub-topics tell you what each domain measures: for example, Application Security Fundamentals includes the OWASP Top 10, secure design principles, threat modeling, secure coding and code review, and SAST and DAST testing. The testing domains cover integrating threat modeling in the plan stage, SAST, DAST and IAST in the build and test stages, and RASP and VAPT in release and deploy; the monitoring domain adds infrastructure as code, compliance as code, and logging, monitoring, and alerting.
These sub-topic names are preparation priorities, not instructions in themselves. Use the blueprint to decide what to study and in what depth, and download the full document for its complete sub-domain lists.
| Domain | Weight |
|---|---|
| 1. Application Development Concepts | 16% |
| 2. Application Security Fundamentals | 20% |
| 3. Introduction to DevOps | 4% |
| 4. Introduction to DevSecOps | 8% |
| 5. Introduction to DevSecOps Management Tools | 8% |
| 6. Introduction to DevSecOps Continuous Integration Tools | 8% |
| 7. Introduction to DevSecOps Pipelines | 8% |
| 8. Implementing Security into the CI/CD Pipeline and Testing | 12% |
| 9. Implementing Security into DevSecOps Testing | 8% |
| 10. Implementing Security into DevSecOps Monitoring | 8% |
Official sources: DevSecOps Essentials Exam 112-55 Exam Blueprint (EC-Council Official Curricula) — Domain and weight table, pages 1–2
Eligibility and registration
There are no eligibility criteria for the D|SE program. To register, you need a valid and active exam voucher; the registration guide is sent to you along with the voucher.
Because there are no prerequisites, the practical gatekeepers are administrative: buy your voucher, follow the registration guide, and arrange a compliant proctored environment. Current voucher pricing was not stated on the pages reviewed for this guide, so check the ECC Exam Center or contact EC-Council for fees before you book.
Official sources: DevSecOps Essentials (D|SE) — EC-Council certification page — Program description, Exam Details, and FAQ sections; EC-Council certification FAQ — Exam Preparation section
Validity, renewal, and ongoing fees
The D|SE credential is valid for three years from the date of your successful exam attempt. After that, you recertify by passing the D|SE exam again — there are no continuing education fees or ECE credits required during the term.
D|SE is not part of EC-Council's Continuing Education (ECE) scheme, which removes the usual annual paperwork and fees. The only renewal action is retaking the same exam once your three-year term ends.
When you plan a job search or a study timeline around this credential, note that the three-year clock starts on your successful attempt date, not on the day you enroll in training.
Official sources: DevSecOps Essentials (D|SE) — EC-Council certification page — Program description, Exam Details, and FAQ sections
How to structure your preparation
Study in blueprint order and weight your effort by domain percentages: Application Security Fundamentals, Application Development Concepts, and CI/CD pipeline security together account for 48% of the exam. Rely on the blueprint and objectives as your coverage check, because EC-Council states that exam content can include material not covered in official training.
EC-Council's FAQ is explicit on this point: official courseware is developed independently of exam content, official training is recommended but not mandatory, and completing it does not guarantee a pass. The exam material can include content not covered in the training. Candidates are directed to check the exam blueprint and objectives before registering — so treat the blueprint table above as your checklist, and confirm every topic you study against it.
A practical sequence follows the blueprint's own progression: application development concepts first, then application security fundamentals, then the short DevOps and DevSecOps foundations, then the tools and pipeline domains, and finally the three implementation domains covering testing, pipeline security, and monitoring. The implementation domains reuse vocabulary from the earlier ones, so studying in order reduces rework.
EC-Council also notes that minor exam updates may happen without announcement, with a new blueprint released only for significant objective changes. Check the exam details page shortly before you book to confirm you are studying against the current blueprint.
Practice exercise
Using the blueprint table, identify the three highest-weighted domains and compute their combined share. Does that percentage alone tell you which topic you personally need to study first?
Show answer
Application Security Fundamentals (20%), Application Development Concepts (16%) and Implementing Security into the CI/CD Pipeline and Testing (12%) total 48%. The weights alone do not identify your personal knowledge gaps.
20 + 16 + 12 = 48. The blueprint describes assessment coverage. Compare that coverage with the concepts you can already explain and apply before choosing your next study task. A high-weight domain deserves attention, but a prerequisite you have not learned may be the useful starting point.
- Download the 112-55 blueprint and use its sub-domain lists as your coverage checklist
- Allocate study time roughly in proportion to domain weights, front-loading the 20% and 16% domains
- Treat official courseware as one input, not a guarantee or a boundary of exam scope
- Re-check the exam details page for updates before scheduling
Official sources: DevSecOps Essentials Exam 112-55 Exam Blueprint (EC-Council Official Curricula) — Domain and weight table, pages 1–2; EC-Council certification FAQ — Exam Preparation section
Official sources
Facts checked against EC-Council sources:
