Awarded for completing Safeguard for Open Source Maintainers and passing its exam, demonstrating the ability to keep a maintained project's supply chain clean on a volunteer's time budget, publish verifiable trust artefacts for every release, run a responsible vulnerability disclosure process, and read a vendor's published maintainer programme terms precisely and honestly.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.