SJD-100: Secure Java Development Essentials - on the way to OSCC-SJD.
SJD-100 covers secure Java development from a developer's perspective: ten modules and roughly 41 hours on input validation, output encoding, cookie and session security, logging and error handling, misconfiguration and secure database access, each with hands-on labs. Not an attack course.

- Certification
- OSCC-SJD - OffSec CyberCore Certified - Secure Java Development
- Level
- Foundational
- Discipline
- Build
- Audience
- For security teams
Who this course is for
Java development teams and security champions expected to avoid vulnerabilities rather than pay for them later in a pentest.
Not the right course yet if
- -Your stack is not Java
- -You want to attack rather than build securely - go to WEB-200
- →Spot and replace insecure patterns in your own code
- →Apply safe defaults for validation, auth and crypto
- →Understand and fix pentest findings on their merits
- ·Practical Java development experience
Not sure whether you meet them? We run a short placement conversation before you buy.
What SJD-100 covers.
- Injection and input validation
- Output encoding against XSS
- Cookie and web session security
Course content, labs and the OSCC-SJD exam are provided by OffSec. Precedence always sits with the official course description. This page reviewed: 2026-08-12.
Labs and format
Course modules with code exercises and guided fixes on vulnerable Java applications.
Exam and credential
Six-hour proctored practical exam: find and fix five vulnerabilities without breaking core functionality, roughly one hour each. No report, results immediately after submission. Passing awards the OSCC-SJD certification, valid for three years.
The packages that include SJD-100.
Prices in EUR, net, plus statutory VAT. Invoiced through a German entity. Your course is pre-selected at checkout.
Entry route without prior experience.
- ▸ 365 days of access to the 100-level courses
- ▸ 2 exam attempts
- ▸ Proving Grounds Play
Several people in a team, with evidenced progression.
- ▸ The full OffSec catalogue
- ▸ Learning paths and reporting
- ▸ Reassignable from 5 seats
- +A code review session on your own repository
- +A link back to the findings from your last application pentest
For security teams
Multiple people, role paths, reporting and procurement run through OffSec Learn Enterprise.
See Learn EnterpriseTeam capability development
Badges, learning paths and evidence across attack, defend, build and govern.
See the capability mapOther hackers also bought ... ;)
No. SJD-100 is a secure coding course for development teams.
Individually through CyberCore (one year of access to one 100-level course including labs and two exam attempts), or through Learn Enterprise so several developers get parallel access.
Yes, OSCC-SJD is valid for three years. You renew through an equivalent exam, the recertification exam or OffSec's CPE programme.
Not sure whether SJD-100 is the right course?
We run a short placement conversation: background, study time, goal. Then we recommend a course and package - even when it is the cheaper one.