Awarded for completing Reading Vulnerability Intelligence Without Being Misled and passing its exam, demonstrating the ability to read a severity score for what it does and does not measure, treat an exploit prediction score as a probability rather than a verdict, use a known exploited catalogue as a distinct binary signal alongside severity rather than a substitute for it, apply a weakness taxonomy for triage and pattern spotting rather than ranking, recognise the absence of evidence fallacy, and check what any security metric measures, how it was collected, and how current it is before acting on it.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.