Awarded for completing The CWE Top 25: Authentication, Authorisation and Session Weaknesses and passing its exam, demonstrating the ability to distinguish, detect, fix and systemically prevent the access control weaknesses that recur most often across disclosed vulnerabilities and testing programmes.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.