Awarded for completing Proving Security Actually Improved and passing its exam, demonstrating the ability to explain why an incident count cannot support an improvement claim, state the counterfactual problem and the level of claim it permits, apply an admission test to any proposed measure, compute and present coverage against an independently derived population, compare remediation and exposure data as distributions rather than averages, use escape rate and recurrence as evidence that something structural changed, meet the five conditions of a before and after comparison and pre commit to it, correct for instrumentation, population, organisational and calendar confounds, build an internal baseline that survives a definitional change, produce the evidence that serves an auditor and a customer reviewer at once, and answer a board's question about whether the organisation is more secure in four honest sentences.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.