Awarded for completing HTTP Security Headers and passing its exam, demonstrating the ability to explain how a security header's protection depends on browser enforcement, configure HTTP Strict Transport Security and X-Content-Type-Options correctly, apply framing defenses alongside Content-Security-Policy as part of a coherent header family, choose a Referrer-Policy appropriate to an application's own sensitive addresses, build and tune a practical baseline header set, verify that headers actually reach production responses rather than only a staging environment, recognize recurring misconfiguration patterns, and describe these headers accurately as a defense-in-depth layer rather than a substitute for the underlying fix.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.