top of page
Graduation Certificates

Security by Design — Certified Professional License (CSbDP)

Evidence-based licensing that validates principles, models, and methods of Security by Design—no multiple-choice exams.

What Is the CSbDP CPL?

Your CSbDP Professional Certification License

What the license represents
 

The CSbDP CPL recognizes security engineers, architects, and technical leaders who embed proactive security engineering, threat modeling, and secure-by-default principles directly into system architectures, product development lifecycles, and software engineering workflows across enterprise, cloud, and embedded environments.

A professional who earns this certification can conduct comprehensive threat modeling and attack surface reduction; design secure software development lifecycles (SSDLC); enforce secure design patterns, cryptographic controls, and software supply chain security (SBOM); automate continuous security verification within DevSecOps pipelines; and systematically eliminate vulnerability classes during the design phase.

The certification demonstrates the ability to make sound security engineering decisions, document design trade-offs and residual risk, establish secure-by-default baselines, and align engineering, product, and executive stakeholders around resilient systems design.

What Will I Receive?

Your CSbDP Professional Licensing Certification

What the license represents

Your certificate is the official record that you have satisfied the qualification and assessment requirements for the CPL. It displays your name, professional designation, issue date, and unique Credential ID.

The certification is valid for three years and can be independently verified through the public credential registry.

CPL_SbD_image1.png

Your CSbDP Professional Stamp

The personalized CPL Stamp is a professional mark issued to each certificate holder. It identifies the holder by name and signifies demonstrated capability to evaluate, design, threat model, validate, and build secure systems.

Authorized use of the CPCA Stamp

The CPL Stamp may be applied to threat models, security architecture specs, software design review records, security decision records, technical reports, and system design documents prepared or approved by the credential holder.

Use of the stamp signifies professional accountability for the security design work and adherence to professional certification requirements and the credential holder's Code of Ethics. It does not represent organizational approval, regulatory compliance, or acceptance of risk unless the credential holder has specific authority.

SbD_CPL_stamp_wht__transp_pic.png

Who Is This CPL For?

Designed for Experienced Practitioners

The CSbDP is intended for software, systems, and security professionals who build, architect, or lead secure system design. Candidates do not need to already hold the title of Security Architect, but should have a solid technical foundation and hands-on experience with secure coding, threat modeling, design reviews, secure-by-default principles, risk analysis, and DevSecOps workflows.

NOTE: The CSbDP is a professional-level credential and is not intended as an entry-level cybersecurity certification.

Cybersecurity and Security Architects

Architect Drafting Plans

Technical Project & Program Managers

Image by Jo Szczepanska

Enterprise and Solution Architects

Discussing Design Plans

Startup & Product Teams
 

Image by Jason Goodman

Cloud & DevOps Engineers & Architects

Image by Desola Lanre-Ologun

GRC Professionals
 

Filling Checklist Form

Technical Executives & Management

Office employee

Instructors & Trainers
 

Teacher

Why Should I Earn It?

Demonstrate Applied Security Engineering Capabilities

The CSbDP lets experienced professionals demonstrate they can perform security engineering and threat modeling in a realistic scenario. It recognizes applied design judgment—how you analyze attack surfaces, model threats, enforce secure-by-default controls, address design trade-offs, and automate secure lifecycles—not just knowledge recall.

Demonstrate Applied Capability

Show that you can evaluate, design, threat model, and implement secure-by-default systems through professional work products.

Strengthen Your Professional Credibility

Use the CSbDP designation and professional stamp to identify your demonstrated security design capability and accountability.

Make Your Achievement Verifiable

Provide employers, clients, and professional peers with a unique Credential ID that you can confirm through the public credential registry.

Support Your Career Development

Document your readiness for secure system design, DevSecOps engineering, application security leadership, consulting, and technical design roles.

How Can I Earn It?

Two ways to earn your license.

How Earn SbD CPL

Path 1 — Attend ISAU Academy (recommended)

Learn the method, then earn the license:

  1. Enroll in the Pro Bundle (course + ebook + one evaluation)

  2. Complete the self-paced modules (knowledge checks; non-heavy)

  3. Submit your capstone portfolio (principles, models, methods in use)

  4. Panel review & decision (up to 14 days for course completion)

NOTE: 20 CPEs awarded automatically for course completion.

Path 2 — Direct Evaluation

(for experienced practitioners)

Already fluent in the concepts and methods? Bypass the course and go straight to the cyber capstone portfolio:

  • Brief eligibility check (experience + example artifacts)

  • Capstone portfolio submission and panel review

  • Same license, same stamp, same public verification

NOTE: 0 (zero) CPEs will be awarded for not completing the course.

What Is the CPL Assessment?

A Cyber Capstone Completed Through FlexCert 30

The certification exam is not a traditional multiple-choice, memorization-based exam. Instead, you complete a real-world, scenario-based Cyber Capstone that reflects the work cybersecurity practitioners do.

You will analyze a realistic organization and technical environment, identify security requirements and design risks, develop a secure architecture, recommend risk remediation, explain your design decisions and trade-offs, and define how to validate the architecture.

What You Will Submit

Your Cyber Capstone includes five connected professional work artifacts:

  1. Architecture Context and Requirements Brief

  2. Threat Model and Design Risk Analysis

  3. Target Security Architecture Package

  4. Security Design Rationale and Implementation Guidance

  5. Architecture Validation and Executive Decision Brief

 

Complete It Through FlexCert 30

FlexCert 30 is the remote, independent format for completing your Cyber Capstone. You receive a controlled professional scenario, instructions, and submission templates, then have 30 days to develop and submit your work.

 

Complete the assessment on your own schedule without traveling to a testing center, scheduling a fixed examination appointment, or participating in live remote proctoring.

Thirty days. Independent completion. Your schedule.

How Will I Be Evaluated?

Your Cyber Capstone Artifacts Work Is the Evidence

Trained cyber evaluators review your five Cyber Capstone work artifacts as one connected architecture submission. The evaluation considers whether your requirements, threat analysis, architecture models, security controls, design decisions, validation approach, and professional communication are clear, technically sound, and consistent.

Part 1 — Technical Artifact Evaluation

This section determines whether you have passed the technical requirements of the Cyber Capstone.

 

Evaluators assess:

  • Architecture context and security requirements

  • Architecture models, data flows, and trust boundaries

  • Threat modeling and design risk analysis

  • Security patterns and control placement

  • Design decisions, trade-offs, and risk remediation

  • Technical feasibility and implementation guidance

  • Validation criteria and professional communication

Part 2 — Professional Capability Profile

We also use your submission to develop a separate Skills, Knowledge, and Abilities Capability Profile. This evidence-based profile evaluates your professional reasoning, technical judgment, disciplined practice, problem-solving, and communication across seven capability dimensions.

 

The profile shows how you performed, where you demonstrated strength, and where continued professional development may be beneficial.

 

 

Your Evaluation Outcome

After the review is completed, you receive a Defensible Capability Score Report containing your technical results, professional capability profile, evaluator findings, and licensing decision. Candidates who meet the technical and professional requirements receive the Certification License and are added to the public credential registry.

Image by Bench Accounting

Ready to Demonstrate Your Security by Design Capability?

bottom of page