CT-SEC vs CT-STE vs CT-STA: Which ISTQB Security Certification Should You Take?
ISTQB has three names in its security track and only two exams you can book. The entry rule, not the syllabus, decides which one is yours.
ISTQB has three names in its security track and only two exams you can actually book. CT-SEC has been on the catalogue since 2016. CT-STE took over the engineering half of it in January 2025. CT-STA, the analyst half, was announced for 2026 and, checked on 5 October 2026, still is not on the certifications list. Here is the decision, with the exam numbers behind it rather than the marketing copy.
The short answer
For most people the syllabus never gets a vote, because the entry rule decides first:
Fewer than three years of security-relevant experience? CT-STE is your only option. CT-SEC will not let you sit it.
Three years or more, and you want the broader syllabus? CT-SEC is still bookable and still carries no retirement date.
Waiting for CT-STA? Keep waiting, and do not build a 2026 plan around it.
Three names, two exams you can book
ISTQB's own explanation is that the 2016 CT-SEC syllabus mixed several roles into one qualification and became hard to navigate. The replacement is a split: CT-STE, the Security Test Engineer, covers the practical execution of security testing, and CT-STA, the Security Test Analyst, is meant to cover business security risk and security testing strategy. Only the first half has shipped.
That leaves an odd situation. The certification being replaced is still live, the replacement is only half built, and nothing on the ISTQB site tells a candidate which to choose. The official CT-STE FAQ describes the split and the absence of grandfathering, but stops short of a recommendation.
The entry requirement is the real decision
CT-SEC has the hardest entry rule of any ISTQB security qualification. The syllabus requires a Foundation Level certificate plus enough practical experience to satisfy the exam board, and it puts a number on it: not less than three years of relevant academic, practical or consulting experience. That is a gate, not a suggestion, and it is enforced at registration.
CT-STE asks for one thing: a valid ISTQB Foundation Level certificate. No years of service, no prior security qualification, and explicitly no CT-SEC. If you are a tester moving into security rather than a security specialist moving into testing, that difference settles the question on its own. If you do not hold CTFL yet, start with the CTFL exam format and pass mark, because every route here goes through it.
The two exams side by side
CT-SEC: 45 questions, 80 points, 52 points to pass, 120 minutes, 150 minutes with the non-native language extension. Syllabus dated 18 March 2016, 86 pages.
CT-STE: 40 questions, 43 points, 28 points to pass, 75 minutes, 94 minutes with the extension. Syllabus v1.0.1 dated 31 January 2025, 103 pages.
Both land on the standard ISTQB threshold of at least 65% of the available points, rounded up. The interesting part is not the totals, it is how those points are built.
Where the points come from

Neither exam gives every question the same weight. In CT-SEC a K2 question is worth 1 point, a K3 question 2 and a K4 question 3, so 20 K2 plus 15 K3 plus 10 K4 produces exactly 80 points. In CT-STE the weights are flatter: K2 and K3 are both worth 1 point and K4 is worth 2, so 24 plus 13 plus 6 gives 43. If the K-level scale is new to you, our breakdown of why a K3 question is worth two points explains the mechanism across the whole ISTQB portfolio.
The practical consequence is sharp. On CT-SEC, 10 questions out of 45 carry 30 of the 80 points, which is 37% of the exam riding on analysis-level work: attack scenarios, failed testing approaches, intermediate reports, tool needs. Drop all ten and you top out at 50 points against a pass mark of 52. On CT-STE the three K4 questions are worth 6 points of 43, so no single band can sink you. CT-STE rewards breadth; CT-SEC punishes anyone who prepared by memorising.
What CT-STE asks, chapter by chapter

CT-STE is unusually flat. Nine chapters share 40 questions, and the largest, Security Test Techniques, is 7 of them. Only two chapters are worth more points than questions: Adjusting Security Testing to the Organizational Context and Adjusting Security Testing to Software Development Lifecycle Models, which is where all three K4 questions sit. Both are the chapters that ask you to analyse an attack scenario or reason about what a given lifecycle model does to your testing, and both carry 195 and 165 minutes of recommended study respectively. They are the ones to over-prepare.
What CT-SEC covers that CT-STE leaves out
CT-SEC devotes an entire chapter to testing security mechanisms, and it is the heaviest in the syllabus at 240 minutes. Eight mechanisms are treated in pairs: understand the mechanism, then test whether it actually works. System hardening, authentication and authorization, encryption, firewalls and network zones, intrusion detection, malware scanning, data obfuscation and security training. Nothing in CT-STE replaces that chapter mechanism by mechanism.
CT-SEC also has a standalone human factors chapter covering attacker motivation, reconnaissance, social engineering and security awareness programmes, plus a chapter on standards as a consensus-based framework and the difference between regulatory and contractual enforcement. If your job is evaluating whether an organisation's defences hold rather than running the tests, that content is the reason CT-SEC still has an audience.
What CT-STE adds that CT-SEC never had
The nine years between the syllabi show. CT-STE builds zero trust in as a paradigm with its own K3 learning objective, walks the weakness-to-vulnerability-to-attack chain through CWE, CVE and CAPEC, separates CWSS from CVSS for prioritisation, teaches STRIDE for threat modelling, and categorises tooling as SAST, DAST, IAST and software composition analysis. It covers DevSecOps and shift-left explicitly, treats GDPR as something you have to test against, and asks you to feed results into an ISMS under ISO/IEC 27001.
One warning for anyone preparing from blog posts rather than the syllabus: the software bill of materials does not appear in CT-STE at all. Neither do red teaming, honeypots, SIEM or Common Criteria. Open-source software is covered, but as component reuse and its consequences for testing, not as SBOM tooling. Study the syllabus, not the industry conversation around it.
CT-STA: announced for 2026, still not here
Checked on 5 October 2026: CT-STA does not appear on the ISTQB certifications page, and the security FAQ still describes it in the future tense as scheduled for release in 2026. There is no syllabus, no sample exam and no exam structure table. With under three months of the year left, a candidate who needs a security certification this year has two choices, not three. This is not the first ISTQB syllabus to sit still for a long time, and the CT-PT syllabus from 2018 is the comparison worth keeping in mind before you plan around a date.
A CT-SEC certificate does not convert
ISTQB is unambiguous: there is no automatic transfer and no grandfathering. A CT-SEC holder who wants CT-STE or, eventually, CT-STA has to sit and pass that exam like anyone else. This cuts both ways. If you already hold CT-SEC, it does not expire and it does not convert, so adding CT-STE is a deliberate second investment rather than a renewal. If you are choosing now, you are choosing one exam, not a step on a ladder.
How to prepare once you have picked
For CT-STE, work from the 2025 syllabus and practise against the point structure rather than the question count, because the two chapters that carry K4 questions are the ones that decide borderline results. Our CT-STE mock exams follow the official chapter distribution and give a written rationale on every answer option, including the wrong ones. Start with CT-STE mock exam 1 and read the CT-STE preparation guide for the chapter-by-chapter plan. For CT-SEC, the certification page on istqb.org carries the 2016 syllabus and sample exam, and the ISTQB glossary is the terminology reference both exams are written against. If you still need Foundation Level first, our complete CTFL guide is the place to start.
Frequently asked
CT-SEC is still listed on istqb.org and carries no [Retiring] tag and no published sunset date, unlike CTAL-TA v3.1, CT-AI v1.0, CTFL-AT and CT-ATT. It is a 2016 syllabus, but it is still bookable.
No. CT-STE requires only a valid ISTQB Foundation Level certificate. No security certification and no work experience are required.
No. ISTQB states there is no automatic transfer and no grandfathering. You have to sit and pass each exam separately.
Not as of 5 October 2026. The ISTQB FAQ still describes it as scheduled for release in 2026, and it does not appear on the ISTQB certifications list.
CT-SEC. It is 45 questions in 120 minutes against CT-STE's 40 in 75, and 30 of its 80 points sit on 10 analysis-level K4 questions, against 6 of 43 points on CT-STE.
CT-SEC needs 52 of 80 points, CT-STE needs 28 of 43. Both are the standard ISTQB 65% threshold, rounded up.
Part of the ExamCaliber editorial team. Every ExamCaliber question and rationale is written and reviewed by hand against the current syllabus — never scraped from exam dumps.