Learn to tell the world, precisely and verifiably, which vulnerabilities in your SBOM actually matter. This course covers CISA's minimum requirements for VEX, the CSAF, OpenVEX and CycloneDX formats with complete worked documents and crosswalks, how to author defensible not_affected justifications from reachability evidence, and how to consume, verify and share VEX using Safeguard's Upload CSAF/VEX integration, Vulnerabilities and Mitigations tabs, VEX Readiness policy, Portal Sharing and TPRM.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.