Awarded for completing Account Takeover and Credential Stuffing Defense and passing its exam, demonstrating the ability to distinguish credential stuffing from password spraying, apply detection signals for account takeover attempts, design layered defenses combining rate limiting and multi-factor authentication, use breach monitoring as an early warning capability, and run a post-takeover response playbook covering containment and scoped review.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.