Vulnerability Exploitability eXchange (VEX) treated as a channel you are speaking through rather than a compliance artefact you are filing. The course covers the four parties who open a statement and what each does next, the evidence bar each status should require before you are entitled to publish it, the craft of a justification a customer's security team will accept and the six ways one fails review, the asymmetric cost of a wrong not affected and the retraction protocol for the day it happens, scope and versioning so nobody reads more into a statement than you meant, why statements decay because your product moved rather than because the vulnerability changed, the register that makes the practice operable, what can be automated safely and where a person must still decide, and how to measure what it does to your support load.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.