Awarded for completing Reading Vendor SOC 2 Reports and Penetration Test Reports and passing its exam, demonstrating the ability to read these two document types with practical scepticism, distinguish strong evidence from weak or incomplete evidence, recognise recurring red flags, and integrate the findings proportionately into a broader vendor risk scoring process.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.