A practical guide to reading a vendor's System and Organization Controls 2 (SOC 2) report and penetration test report as received evidence, distinct from the broader vendor risk programme covered in tprm-essentials-onboarding-vendors and vendor-risk-scoring-methodology. You will learn to distinguish Type I from Type II reports, read an auditor's opinion and scope statement carefully, understand complementary user entity controls, apply the same practical scepticism to a penetration test report's scope and date, recognise the specific red flags that recur across both document types, and use these documents as one input into a broader risk score rather than a pass or fail gate. Every scenario in this course is a clearly labelled hypothetical; no real vendor, auditor, or report is described.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.