Awarded for completing Input Validation Fundamentals and passing its exam, demonstrating the ability to explain input validation as the shared principle behind several vulnerability classes, choose allowlisting over denylisting where practical, apply canonicalization before validation, place validation at the correct trust boundary, apply baseline type, length, range and format checks alongside context-specific handling at each destination, recognize the limits of client-side validation, and configure a validation library correctly rather than trusting its defaults.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.