CSQA logo
Focused certification exam prep
Start practice

CSQA Exam Domains 2026: Complete Guide to All 10 Content Areas

TL;DR
  • The legacy PeopleCert CSQA exam covered exactly 10 CBOK domains, from Quality Principles to Outsourcing/COTS.
  • Voucher sales ended August 1, 2025, and the final sitting (including Take2 resits) was February 1, 2026.
  • Existing CSQA holders keep the credential and can still use PeopleCert renewal routes.
  • GAQM's active CSQA is a separate, unrelated certification - don't confuse the two bodies of knowledge.

Important Status Note for 2026

Before digging into the content areas, a clarification matters more than any study tactic: PeopleCert retired the CSQA exam. Voucher sales stopped on August 1, 2025, and the final exam date - including Take2 resit attempts - was February 1, 2026. If you already hold the credential, you are unaffected; PeopleCert's existing renewal routes remain open to you. If you were planning to sit the exam for the first time, this domain guide is now a historical and study-reference resource rather than a registration roadmap.

There is also a naming collision worth resolving. GAQM operates its own active CSQA program with a different exam structure and body of knowledge. That GAQM credential is not the same as the legacy PeopleCert/Software Certifications exam described here. If you're comparing options, read What Is CSQA? and CSQA Meaning for a breakdown of how the two lineages diverge, and check CSQA Requirements 2026: Eligibility, Prerequisites & How to Qualify before assuming either path applies to you.

Why This Guide Still Matters: Even with the exam retired, the 10 CBOK domains remain the reference framework many QA teams use to structure internal training, job descriptions, and interview questions. Understanding them helps you evaluate legacy-certified candidates or refresh your own knowledge for renewal.

The 10 CBOK Domains at a Glance

The legacy CSQA body of knowledge organized software quality competency into ten distinct domains. Each domain represented a scored section on the exam, and each mapped to a real job function a quality analyst was expected to perform, not just recall.

  1. Quality Principles and Concepts
  2. Quality Leadership
  3. Quality Baselines (Assessments and Audits)
  4. Quality Assurance
  5. Quality Planning
  6. Define, Build, Implement, and Improve Work Processes
  7. Quality Control Practices
  8. Metrics and Measurement
  9. Internal Control and Security
  10. Outsourcing, COTS, and Contracting Quality

Unlike many technical certifications that lean heavily on tools or coding syntax, this exam tested conceptual fluency and applied judgment: candidates faced scenario-style multiple-choice items asking them to select the *best* next step for a QA manager, not just define a term. That format is a core reason people search for How Hard Is the CSQA Exam? Complete Difficulty Guide 2026 - the difficulty isn't memorization, it's interpretation.

Domains 1-3: Foundations, Leadership, and Baselines

Domain 1: Quality Principles and Concepts

This domain establishes the vocabulary and philosophy underpinning everything else in the CBOK. Candidates needed to distinguish quality assurance from quality control, understand cost-of-quality models, and recognize how quality maturity evolves across an organization.

  • Difference between prevention-based and detection-based quality activities
  • Cost of quality: prevention, appraisal, internal failure, external failure
  • How quality principles connect to customer satisfaction and business risk

Domain 2: Quality Leadership

This domain tested whether candidates could think like a QA manager responsible for culture, not just process. Expect scenario questions about building buy-in, managing resistance to quality initiatives, and aligning QA goals with executive priorities.

  • Building a quality-focused organizational culture
  • Roles and responsibilities of quality leaders versus quality practitioners
  • Change management techniques for introducing new QA practices

Domain 3: Quality Baselines (Assessments and Audits)

This domain covers how organizations measure where they currently stand before improving. Candidates needed familiarity with maturity models, audit types, and how baseline assessments feed into improvement roadmaps.

  • Difference between an assessment and a formal audit
  • Using maturity models to benchmark current process capability
  • Documenting findings in a way that supports later improvement plans

Domains 4-6: Assurance, Planning, and Process Work

These three domains formed the operational backbone of the exam and, in most candidate experiences, required the deepest study time.

Domain 4: Quality Assurance

Quality Assurance is the largest conceptual pillar of the CBOK. It covers the proactive, process-oriented activities designed to prevent defects rather than catch them after the fact.

  • QA program structure and governance
  • Standards, policies, and procedures that support consistent quality
  • Difference between QA activities and QC activities in practice

Domain 5: Quality Planning

This domain tests whether a candidate can build a quality plan from scratch: defining objectives, selecting standards, and setting acceptance criteria before a project begins.

  • Elements of a formal quality plan
  • Setting measurable quality objectives tied to business requirements
  • Risk-based planning for testing and review activities

Domain 6: Define, Build, Implement, and Improve Work Processes

This domain focuses on process engineering itself - how organizations design, document, roll out, and continuously refine their software development and QA workflows.

  • Process definition and documentation standards
  • Rollout strategies for new or revised work processes
  • Continuous improvement loops (plan-do-check-act style thinking)
Study Priority: Domains 4-6 together account for a large share of scenario-based questions because they describe what a working quality analyst actually does day to day. If your study time is limited, weight these three domains heavily before moving to narrower topics.

Domains 7-8: Control Practices and Metrics

Domain 7: Quality Control Practices

Where Domain 4 is about prevention, this domain is about detection and correction - the hands-on techniques used to find defects before release.

  • Review types: walkthroughs, inspections, technical reviews
  • Testing techniques and their appropriate use cases
  • Defect tracking and root-cause analysis workflows

Domain 8: Metrics and Measurement

This domain requires comfort with quantitative thinking - not advanced statistics, but the ability to select, interpret, and act on quality metrics.

  • Common software quality metrics (defect density, test coverage, etc.)
  • Interpreting trend data to support process decisions
  • Avoiding metric misuse (measuring the wrong thing or gaming numbers)

Candidates who struggled with these two domains often did so because they tried to memorize formulas instead of understanding when a given control or metric applies. That's a recurring theme across the CBOK, and it's discussed further in CSQA Study Guide 2026: How to Pass on Your First Attempt.

Domains 9-10: Security and Outsourcing

Domain 9: Internal Control and Security

This domain extends quality thinking into governance and risk territory - how internal controls protect data integrity and how security considerations intersect with QA responsibilities.

  • Internal control frameworks and their relevance to software quality
  • Security review touchpoints within the SDLC
  • Segregation of duties and audit trail requirements

Domain 10: Outsourcing, COTS, and Contracting Quality

The final domain addresses quality management when work is not fully in-house - vendor-supplied components, commercial off-the-shelf (COTS) software, and outsourced development contracts.

  • Vendor evaluation and acceptance criteria for COTS products
  • Contract clauses that protect quality expectations
  • Managing quality risk across outsourced or distributed teams

Key Takeaway

Domains 9 and 10 are often under-studied because they feel peripheral, but they generate distinct scenario questions about vendor contracts and access controls that don't overlap with earlier domains - skipping them is a common scoring mistake.

How the Domains Compare in Depth and Difficulty

Not every domain demands equal study time. The table below reflects how candidates typically allocated effort based on conceptual breadth and question density, drawn from the structure of the CBOK itself rather than any official percentage breakdown.

DomainCore FocusRelative Study Load
1. Quality Principles and ConceptsFoundational vocabulary and philosophyLight
2. Quality LeadershipCulture, change management, rolesModerate
3. Quality BaselinesAssessments, audits, maturity modelsModerate
4. Quality AssuranceProcess governance and preventionHeavy
5. Quality PlanningQuality plans and acceptance criteriaHeavy
6. Work Process DesignDefining, building, improving processesHeavy
7. Quality Control PracticesReviews, testing, defect trackingHeavy
8. Metrics and MeasurementQuantitative quality analysisModerate
9. Internal Control and SecurityGovernance and SDLC securityLight-Moderate
10. Outsourcing, COTS, ContractingVendor and contract quality riskLight-Moderate

For a fact-check on exactly what score threshold each domain contributed toward, see CSQA Passing Score 2026: Exactly What You Need to Pass, and for how these domains historically influenced results, see CSQA Pass Rate 2026: What the Data Shows.

Mapping Study Weeks to Domains

If you're revisiting this material for renewal purposes or internal training rather than a live registration, sequencing still matters. A domain-aligned schedule works better than reading the CBOK linearly, because it lets you cluster related concepts (assurance, planning, and process design) before moving to more isolated topics like outsourcing.

Week 1

Foundations

  • Domain 1: Quality Principles and Concepts
  • Domain 2: Quality Leadership
Week 2

Core Operations

  • Domain 4: Quality Assurance
  • Domain 5: Quality Planning
Week 3

Process and Control

  • Domain 6: Work Process Design
  • Domain 7: Quality Control Practices
Week 4

Measurement and Risk

  • Domain 8: Metrics and Measurement
  • Domain 3: Quality Baselines
Week 5

Specialized Topics and Review

  • Domain 9: Internal Control and Security
  • Domain 10: Outsourcing, COTS, and Contracting
  • Full-length practice review

Note this schedule intentionally puts the generic technique - spaced weekly review blocks - in service of domain sequencing rather than as a standalone method. For a broader walkthrough of preparation logistics, see CSQA Study Guide 2026: How to Pass on Your First Attempt, and run timed domain drills using practice questions on the main practice test platform to see which domains need another pass.

Who Actually Tests on This Material

The CBOK domains weren't written for developers or testers alone - they target quality analysts, QA managers, audit specialists, and process improvement leads across industries like finance, healthcare IT, government contracting, and enterprise software vendors. Employers hiring for these roles frequently listed the CSQA credential in job postings as a signal that a candidate understood governance-level quality thinking, not just test execution.

If you're weighing whether this background is worth pursuing given the exam's retirement, two resources are directly relevant: Is the CSQA Certification Worth It? Complete ROI Analysis 2026 covers the credential's career value, and CSQA Salary Guide 2026: Complete Earnings Analysis looks at how the certification has correlated with compensation in QA leadership roles. For open positions that reference this background, browse CSQA Jobs.

Organizations still building internal quality-training curricula sometimes use these same ten domains as a checklist, independent of any live exam. If your team is doing that, CSQA Training outlines how the domain structure translates into internal enablement programs, and CSQA Certification gives the broader credential context. For quick terminology lookups while studying, What Does CSQA Stand For?, What Is A CSQA?, and What Does CSQA Mean? are useful references.

Renewal Reminder: If you hold the legacy CSQA and need to maintain it, PeopleCert's renewal routes remain active even though new exam registrations have ended. Confirm your specific renewal path directly with PeopleCert rather than assuming exam-based recertification is still available.

FAQ

Can I still register for the CSQA exam in 2026?

No. PeopleCert ended voucher sales on August 1, 2025, and the final exam date, including Take2 resits, was February 1, 2026. New registrations are no longer available for this legacy credential.

If I already passed the CSQA exam, do I lose my certification?

No. Existing CSQA holders keep their credential and can continue using PeopleCert's established renewal routes to maintain it.

Is the GAQM CSQA the same exam described in this domain guide?

No. GAQM's CSQA is a separate, currently active credential with its own body of knowledge. This guide covers the ten CBOK domains from the legacy PeopleCert and Software Certifications exam, so don't assume the two overlap.

Which of the 10 domains carried the most weight on the exam?

Quality Assurance, Quality Planning, and Work Process Design (Domains 4-6) generally required the deepest preparation because they covered the broadest range of applied, scenario-based questions.

Are these domains still useful to study if the exam is retired?

Yes, for reference purposes. Many QA teams still use the CBOK domain structure to organize internal training, interview criteria, and process documentation, even without a live certification exam attached.

Ready to pass your CSQA exam?

Put this into practice with free CSQA questions across every exam domain.