Awarded for completing Running a Coordinated Vulnerability Disclosure and Bug Bounty Programme and passing its exam, demonstrating the ability to stand up a disclosure policy with a real safe harbor commitment, triage and score inbound reports, decide readiness for a paid bounty, and run the researcher relationship through a full disclosure timeline.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.