Awarded for completing CSRF and Clickjacking: Session Riding Defenses and passing its exam, demonstrating the ability to distinguish cross-site request forgery and clickjacking from cross-site scripting and from each other, apply the synchronizer token pattern and the SameSite cookie attribute correctly, apply framing policy headers correctly, recognize the combined risk when both techniques are chained, and design and review state-changing endpoints against both attack classes.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.