ProfessionalVendor-neutralEC-Council· issued from US

CASE

EC Council Certified Application Security Engineer (.NET or Java)

EC Council Certified Application Security Engineer (.NET or Java)

Exam fee
$450
Ongoing
$80/yr AMF · 40 CPE/yr
Study time
80–160 hrs
Delivery
Hybrid
Validity
3 yrs (renewal cycle)

› Quality score

23.5 / 40

Four-axis SecProve rubric, each 0–10. SecProve editorial assessment — each axis carries a written justification so you can push back on any single call without dismissing the whole score.

Blueprint rigor
How well-defined and rigorous the exam blueprint is.
EC-Council Application Security Engineer — separate Java / .NET tracks.
6.5/10
Practical evidence
Hands-on labs / written reports vs pure MCQ.
Includes scenario-based items but no live coding artefact.
5.0/10
Currency & upkeep
How aggressively content is kept current with the field.
Refresh trails the broader AppSec landscape.
6.5/10
Market recognition
How often this signal actually moves a hiring decision.
Recognised in EC-Council-trained dev orgs; CSSLP / OSWE more practitioner-respected.
5.5/10

› Exam format

50 multiple-choice questions, 2 hours, proctored. Pass mark: 70%. Available for Java and .NET.

Retake policy
Fee: $499 per attempt
Wait: 0d between attempts

First retake immediate; 14 days between attempts 2-3, 1 month between 3-4, 3 months between 4-5. Max 5 attempts/year.

› Recertification

Valid for 3 years. 120 ECE credits over 3 years + annual AMF (80 USD).

› 3-year cost of ownership

Exam (1×)
$450
AMF (3×)
$240@$80/yr
Total
$690

Excludes study materials, training, retake risk, and lost-wage opportunity. Use as a floor estimate.

› NICE Framework work roles

The NIST NICE work-role IDs this cert maps to. NICCS lookup.

DD-WRL-005DD-WRL-003
Recognition
Global
Exam languages
en

› Core domains covered

The 1 domain this cert is centrally about. Passing the exam demonstrates working knowledge of each.

› Prerequisites

Experience

2 years development experience OR official EC-Council training course.

› Careers that commonly pursue this cert

AppSec / DevSecOps Engineer

Embed security into the software development lifecycle. Shift left to catch vulnerabilities before they reach production.

Product Security Engineer

Embedded in a product team — owns threat modelling, secure design, libraries, dependency risk, and increasingly the AI-specific hardening of LLM features the product ships.

See this cert’s domains highlighted on the interactive map, or compare it against the rest of the catalog.