Other Certifications · Practical DevSecOps · CDE

CDE — Certified DevSecOps Expert

This course teaches toward the Certified DevSecOps Professional (CDP) — the credential profiled on the certifications hub and prepared for in depth across the CDP exam guide, the CDP study plan, and four mock exams. The Certified DevSecOps Expert (CDE) is the same vendor's next rung up — Practical DevSecOps' own advanced credential, built for people who already have CDP-level pipeline security in hand and are ready to take it deeper into Kubernetes clusters and cloud-native environments. This page isn't a study guide for the CDE. It's the honest answer to the question this course's own material eventually raises: I've finished this, I've got the CDP-level material down cold — what's actually next, and what does it assume I already know?

☺ Explain it like I'm 10

Passing a regular driving test proves you can steer, brake, and park on an ordinary road. A rally-driving certificate doesn't re-ask whether you know where the brake pedal is — it assumes that's settled, and tests you on gravel, mud, and blind corners instead. The CDE is the rally-driving version of the CDP: the same vehicle-handling basics are assumed, not re-taught, and the terrain gets a lot rougher.

🦉🤖Your hosts for this topic: Professor Owl & Recon the Robot — Owl already laid out the secure SDLC this whole course builds on, so he's the one who can tell you honestly where that map stops. Recon owns everything past that point — the reconciling instinct that already secured the cluster and the cloud account underneath it, which is exactly the territory this credential adds.

What the CDE is, and why this page treats it as "after," not "instead of"

☺ Like you're 10: It's not a rival to the CDP — it's the next chapter in the same book, from the same author.

Practical DevSecOps runs its own certification ladder rather than sitting inside the CNCF's or a cloud provider's catalog, and the CDP is only the first rung of it. The Certified DevSecOps Expert sits above the CDP within that same vendor's lineup — positioned, in Practical DevSecOps' own marketing, as the credential for practitioners who've already proven they can find, exploit, and remediate a vulnerability across a real pipeline and now want that same practical bar raised against harder, more distributed infrastructure: multi-service Kubernetes clusters and the cloud accounts they run inside of.

The relationship to the CDP is additive, not competitive. Nothing about the CDE contradicts or replaces what the CDP exam guide already prepares you for — SAST, DAST, SCA, secrets scanning, and CI/CD pipeline hardening stay exactly as load-bearing as they were. What changes is the environment those skills get exercised against, and how much is assumed rather than walked through from zero.

◆ Key idea

The honest way to read "CDE" is scope extension, not harder retest. It doesn't ask you to prove SAST and secrets-scanning competence again at a higher difficulty — it assumes that competence is already settled, and spends its own time entirely on what a single-pipeline credential like the CDP was never built to cover: cluster-level and cloud-account-level security.

What the CDE adds over the CDP — Kubernetes and cloud-native security depth

☺ Like you're 10: The CDP tests one workshop with one machine in it. The CDE tests the whole factory floor — dozens of machines, the building's own locks, and who's allowed to walk in the front door.

Practical DevSecOps doesn't publish the two curricula side by side on one page the way the CNCF publishes CKA and CKS domain weights — so treat the comparison below as this page's own synthesis of what's publicly described about each credential's positioning, not a transcription of an official chart. The direction of the comparison is solid even where an exact figure isn't published.

CDPCDE
Core questionCan you find, exploit, and fix a vulnerability in a pipeline?Can you do the same across a cluster and the cloud account underneath it?
EnvironmentA single application pipelineMulti-service Kubernetes workloads plus cloud infrastructure
KubernetesContainer basics — image hygiene, not cluster internalsCluster hardening, admission control, RBAC audited for least privilege, not just written correctly
CloudNot a dedicated focusCloud-native posture across identity, network exposure, and workload configuration
Pipeline fundamentals (SAST/DAST/SCA/secrets)Directly testedAssumed already solid — not re-tested from zero
Format100% practical, live environment, no multiple choiceSame house style — practical and task-based (verify current specifics before booking)

Concretely, the additions land in territory this course covers in its deep-dive material rather than its foundations: Kubernetes Security Deep Dive covers Pod Security Standards, admission control, and the structured RBAC review that separates "wrote a Role" from "audited a binding for privilege creep" — exactly the gap between the CDP's container basics and the CDE's cluster-hardening expectations. CNAPP & the Unified Cloud Security Stack covers the CSPM, CWPP, and CIEM disciplines that make up "cloud-native posture" as a combined practice rather than three separate tools. Container Runtime Security covers the behavioral, after-the-gate detection a live cluster environment can actually exercise in a way a single pipeline never could. And Workload Identity & Pipeline IAM covers the identity-not-a-shared-secret pattern — SPIFFE/SPIRE, keyless auth — that a distributed, multi-service environment makes unavoidable in a way a single pipeline's secrets management doesn't.

Two different kinds of "comes after" — worth telling apart CDP SAST · DAST · SCA Secrets scanning CI/CD pipeline gates Container basics one pipeline, one application assumed baseline — not a booking gate CDE Cluster hardening & admission control Workload identity Cloud-native posture multi-service cluster + a cloud account For comparison — elsewhere on this site CKA hard gate, CDP → CDE is one vendor's own recommended sequencing — nothing stops you from booking the CDE directly. CKA → CKS (see the CKS profile on this site) is enforced at registration — you cannot book it without the prerequisite. Same-sounding phrase, structurally different promise. Don't assume one behaves like the other.

Format, cost, and prerequisites — verify before you book

☺ Like you're 10: A vendor's own certification catalog changes shape more often than a big standards body's does — read the current page before you commit anything.

Practical DevSecOps updates its certification catalog — names, challenge counts, durations, and prices — more often and with less advance notice than a body like the CNCF or AWS. Rather than print specific numbers this page can't keep current, the table below states what's structurally known about how the CDE relates to the CDP and flags exactly what to verify directly with the vendor before you register.

ItemWhat to know
FormatPractical and task-based, in keeping with the CDP's own house style — not a multiple-choice exam. Confirm the current challenge structure on the vendor's page; it isn't reproduced here to avoid stating a number that may already be stale.
EnvironmentA live, more complex environment than the CDP's single pipeline — Kubernetes workloads and at least one cloud account, based on the credential's stated scope
PrerequisitesNo formal prerequisite enforced at registration, as far as this course can confirm — unlike the CNCF's CKA → CKS gate. The CDP is a recommended starting point, not a checked one, which makes it easier to attempt underprepared than a hard-gated exam would allow
Passing scoreNot published
ValidityNot published
PriceNot reproduced here — Practical DevSecOps prices its credentials individually and has run bundle pricing with its own training courses; check the current listing
⚠ Verify this before you book

Every figure a vendor publishes for its own certification catalog is subject to change without the kind of public changelog a standards body maintains. This site is independent and unofficial, and has no relationship with Practical DevSecOps. Before registering, confirm current format, price, and prerequisites on Practical DevSecOps' own certification pages directly — the CDP's official page is linked from the certifications hub, and the CDE listing should sit alongside it in the vendor's current catalog. If a specific URL you find has moved, search the vendor's site directly rather than trusting a stale link, including the one on this page.

The baseline it assumes — and what to shore up first if it's shaky

☺ Like you're 10: If you show up to the rally course still unsure where the brake pedal is, a harder track doesn't teach you that — it just costs more to find out.

This is the part worth taking seriously before spending money on a harder exam: the CDE assumes CDP-level pipeline security is already solid, and its own preparation material won't re-teach it. If any of the following still feels shaky, the honest move is to close that gap here first, not during a more expensive attempt.

If all four of those already feel routine rather than effortful, that's the actual signal the CDP-level baseline is in place — a passed exam is one proxy for that, but it isn't the only one, and the CDE doesn't check for the certificate itself, only for the competence it's supposed to represent.

How the CDE's scope maps onto this course's deeper material

☺ Like you're 10: Here's the map from what the CDE actually tests to the exact pages on this site that go deep enough to prepare for it.

Because the CDE isn't re-testing pipeline fundamentals, the useful preparation from here forward lives almost entirely in this course's deep-dive material rather than its foundations. Kubernetes Security Deep Dive and Container Runtime Security together cover the cluster-hardening and behavioral-detection half of the CDE's added scope. CNAPP & the Unified Cloud Security Stack and cloud security posture cover the cloud-account half. Workload Identity & Pipeline IAM and Zero Trust for Pipelines cover the identity model a genuinely distributed environment forces on you in a way a single pipeline doesn't. And for practice against something closer to a live, multi-part environment than a single lesson can offer, the capstone lab track — particularly hardening and signing a container and scanning IaC and enforcing policy — and the container escape investigation drill are the closest hands-on equivalents this course has to what a CDE-style challenge actually demands.

Who should consider it, and who should wait

☺ Like you're 10: If you're already the person people call when the cluster's on fire, this is worth a look. If you've never been handed the keys to one, that's the gap to close first.

Consider the CDE if the CDP-level material in this course already feels solved rather than aspirational, and your actual work — or the work you're aiming at — already touches Kubernetes clusters or multi-account cloud infrastructure, not just a single application's pipeline. It's a reasonable next step for someone who's finished this course's Kubernetes Security Deep Dive and CNAPP material and wants external, practical proof of it — the same reason the CDP itself appeals to people who want proof over a vocabulary quiz.

Wait if any of the baseline items in the section above still feel effortful rather than routine — the CDE won't teach them to you, and a harder live environment is an expensive place to discover a pipeline-fundamentals gap. Wait too if Kubernetes and multi-cloud infrastructure aren't part of your actual work yet; in that case, the certifications hub's comparison of the CDP, CKS, and AWS Security Specialty is the better next stop, since at least one of those three tracks a narrower, more platform-specific scope that might match your day job more closely than a broad cluster-plus-cloud credential would.

🎬 At the Shift-Left Squad
🦊

Foxy: I just wrapped the CDP study plan. Do I need the CDE next, or is that a completely different animal?

🦉

Professor Owl: Different question, same vendor. CDP proved you can find and fix a vulnerability across a pipeline. CDE assumes that's already true and asks whether you can do the same thing inside a cluster and a cloud account.

🤖

Recon the Robot: Which is my territory. Admission control, RBAC that's actually audited instead of just written correctly, a cloud posture that doesn't drift the moment nobody's watching it.

🦊

Foxy: So it re-teaches the pipeline stuff, just at a harder difficulty?

🦉

Professor Owl: No — and that's the part people get wrong. It doesn't re-teach SAST or secrets scanning at all. It assumes you already have that, and spends its own time entirely on what's past it.

🐢

Timmy the Turtle: Which means don't book it on a guess. If the CDP material's still shaky, that gap doesn't close by paying for a harder exam stacked on top of it.

🦥

Sol the Sloth: And whatever the current price and format actually are — go read the vendor's own page slowly, before committing to anything. That part changes without much warning.

✓ Checkpoint

1. What is the CDE's relationship to the CDP, and how is that relationship different from the CKA-to-CKS relationship covered elsewhere on this site? 2. Name two things the CDE adds in scope that the CDP does not test. 3. Does the CDE re-test SAST, DAST, SCA, and secrets-scanning competence? What does it do instead? 4. Name two specific things a candidate should already have solid before attempting the CDE, and where on this site each is covered. 5. Why does this page avoid printing an exact price or challenge count for the CDE?

Check your answers
  1. The CDE is Practical DevSecOps' own next credential above the CDP within the same vendor's catalog — a recommended sequencing, not an enforced one. That's structurally different from CKA → CKS, which is a hard prerequisite checked at the moment CKS is booked; nothing stops a candidate from attempting the CDE without ever having sat the CDP.
  2. Any two of: Kubernetes cluster hardening and admission control; RBAC audited for least privilege rather than just written correctly; cloud-native posture across identity, network exposure, and workload configuration; workload identity in a distributed, multi-service environment.
  3. No. It assumes CDP-level pipeline fundamentals — SAST, DAST, SCA, secrets scanning, CI/CD gates — are already solid, and spends its own scope entirely on Kubernetes cluster and cloud-account security instead of re-testing what the CDP already covers.
  4. Any two of: static/dynamic analysis fundamentals (SAST, DAST & SCA); secrets hygiene (secrets management); CI/CD pipeline hardening (security in CI/CD); container fundamentals (container & supply-chain security).
  5. Because a vendor's own certification catalog — price, challenge structure, duration — changes more often and with less public notice than a standards body's published curriculum, so a specific figure printed here risks going stale quickly; the page instead flags what to verify directly on the vendor's current page before registering.