Awarded for completing Security Architecture and Design Review and passing its exam, demonstrating the ability to map trust boundaries and data flows, run a structured design review covering authentication, authorization, data protection and failure modes, document accepted risk explicitly, set proportionate triggering criteria, and track design review findings through the same lifecycle used for any other security finding.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.