CASE
EC Council Certified Application Security Engineer (.NET or Java)
EC Council Certified Application Security Engineer (.NET or Java)
› Quality score
Four-axis SecProve rubric, each 0–10. SecProve editorial assessment — each axis carries a written justification so you can push back on any single call without dismissing the whole score.
› Exam format
50 multiple-choice questions, 2 hours, proctored. Pass mark: 70%. Available for Java and .NET.
First retake immediate; 14 days between attempts 2-3, 1 month between 3-4, 3 months between 4-5. Max 5 attempts/year.
› Recertification
Valid for 3 years. 120 ECE credits over 3 years + annual AMF (80 USD).
› 3-year cost of ownership
Excludes study materials, training, retake risk, and lost-wage opportunity. Use as a floor estimate.
› NICE Framework work roles
The NIST NICE work-role IDs this cert maps to. NICCS lookup.
› Core domains covered
The 1 domain this cert is centrally about. Passing the exam demonstrates working knowledge of each.
› Prerequisites
2 years development experience OR official EC-Council training course.
› Careers that commonly pursue this cert
Embed security into the software development lifecycle. Shift left to catch vulnerabilities before they reach production.
Embedded in a product team — owns threat modelling, secure design, libraries, dependency risk, and increasingly the AI-specific hardening of LLM features the product ships.
See this cert’s domains highlighted on the interactive map, or compare it against the rest of the catalog.