An auditor's method for testing SBOMs and VEX statements as management assertions rather than accepting them as documents. You will reconcile SPDX and CycloneDX inventories to builds, lockfiles and registries, test the justification behind every not_affected claim, and trace SBOM, VEX and vulnerability findings to each other and to the audit trail. The course closes with red flags, common audit failures and how to write the finding.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.