Awarded for completing Reviewing Infrastructure as Code Like an Attacker and passing its exam, demonstrating the ability to review identity, trust relationships, exposure paths, data stores, key ownership and logging in infrastructure definitions, to recognise state file and module supply chain exposure, to read a plan for consequences a diff hides, and to run a review practice that converts findings into rules and defaults.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.