Awarded for completing Insecure Deserialization Vulnerabilities and passing its exam, demonstrating the ability to recognize insecure deserialization call sites across languages and carriers, apply the elimination, safe-format and allow-listing mitigation hierarchy in the correct order, explain why generic network-level filters are unreliable against this class, and build and verify a remediation program across an existing codebase using safe, non-exploit methods.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.