Certifies the ability to detect a package compromise already running in production using inventory, intelligence and runtime telemetry, scope its exposure, contain it through the Package Firewall, pinning and rollback, preserve forensic evidence, and run the communication and playbook steps that close the incident.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.