CDAISP exists because of one number: 22%. That's how many organisations test the AI they've deployed against an attacker (IBM Cost of a Data Breach 2025). The other 78% are running assistants that can be prompt-injected, models that can be poisoned and agents holding real credentials, and hoping. Someone has to be able to secure the pipeline and the model, and prove it. This is the certification for that person.
What it certifies
That the holder can secure code, cloud, pipelines and AI systems to a professional standard and evidence it — the merged role employers now call the DevSecOps & AI Security Engineer.
The blueprint (six domains)
| Domain | Weight | Mapped to |
|---|---|---|
| 1. Foundations & Threat Modelling | 15% | OWASP Threat Modelling, NIST CSF 2.0, ISO 27001:2022 |
| 2. Cloud & Infrastructure Security | 20% | CIS AWS Foundations, NIST SSDF |
| 3. Application & API Security | 15% | OWASP Top 10 2025, OWASP API Top 10, ASVS |
| 4. Pipeline Security & Supply Chain | 20% | NIST SSDF, SLSA v1, OWASP DSOMM |
| 5. AI Security | 20% | OWASP LLM Top 10 2026, OWASP Agentic Top 10, MITRE ATLAS |
| 6. Assurance, Detection & Response | 10% | NIST SP 800-61r3, NIST AI RMF, ISO/IEC 42001, EU AI Act Art. 50 |
How you're assessed
Session entry checks 10% · four portfolio projects marked to published rubrics 30% (each ≥ 60%) · 48-hour practical exam 50% (≥ 65% overall and ≥ 50% in every domain) · 15-minute viva 10% (pass/fail). Overall pass mark 70% with every threshold met.
The exam
Your own seeded copy of FinTrust Bank with problems nobody has seen. Six tasks, one per domain: threat-model a new feature; fix the infrastructure; find and fix the vulnerabilities; gate and harden the pipeline; red-team the AI assistant and evidence the mitigations; write the detection, the incident note and the assurance evidence. You submit a pull request and a findings report written to a commercial template, then defend it in a viva. Blind-marked to the published rubric by an examiner who did not lead your room; 20% second-marked. AI-assisted work is allowed and must be disclosed.
The AI Security Engineer endorsement
Awarded on the same credential with ≥ 65% in Domain 5 and a pass on the AI-assurance items of Domain 6.
Verification
Every holder has a public page at cyberagoge.com/verify/{id}: name, credential ID, version, date, domain scores, endorsement — and, if the holder chooses, a link to the exam artefacts. That's what "a hiring manager can read your exam" means.
Validity and renewal
Three years. Stay current with CDAISP Active (£39/year, 30 CPD hours per cycle and the annual "what changed" module) or re-sit the current exam (£149).
Policies
One free retake within 90 days, then £99. Appeals within 14 days to the exam committee. Reasonable adjustments (extra time, text-based viva) on request. Integrity: unique seeds per candidate, commit-history analysis, similarity checks, AI-use disclosure, viva.
Governance
Exam committee of three owns the item bank, rubrics, marking and appeals. A Certification Advisory Board (names to be published) reviews the blueprint every August; pass rates are published annually in aggregate.
Dates and prices
First exam window 16–27 November 2026. Included in the bootcamp. Exam-only £249 from December (eligibility check). Alumni upgrade £149.
Roadmap — what we will and won't claim
CPD accreditation: application autumn 2026. UK Cyber Security Council syllabus mapping: planned Q1 2027. We will update this page when each is granted and will not claim it before.