Build a credential
For any organisation issuing a credential against the framework. Eight steps, one published standard for the specification document, and a conformance checklist you can run against your own draft before we see it.
Coverage map fieldsDecide what the credential is for
Name the person it is for, the work they do, and the decision an employer would make on the strength of it.
A scope statement of two to three sentences.
Select the statement set
Choose statements from the framework at the level you intend to certify, plus any overlay or extension statements.
A list of statement identifiers, pinned to a framework version.
Verify prerequisites the framework does not publish
Some statements presume competence defined elsewhere. D8 presumes general information security competence.
A prerequisite section naming each prerequisite and the verification method.
Design assessment per statement type
Knowledge, Skill, Judgement and Practice statements need different instruments.
An assessment plan mapping instruments to statements and indicators.
Set and document the pass mark
Choose a standard-setting method, run a panel, record the judgements and the date.
A standard-setting record: method, panel, date, judgements, adjustments.
Write the coverage map
Fill in the template: coverage values, weightings summing to 100, assessment method per group, exclusions with rationale.
A complete coverage map, published at a stable public address.
Write the specification against the published standard
The credential specification is a document with a defined structure.
A specification document plus a completed checklist.
Publish, then apply if you want it listed
You may issue the credential without ever contacting us; the licence permits it.
A published credential, and optionally a conformance application.
The four types are not assessable by the same method
| Type | Reaches it | Cannot reach it |
|---|---|---|
| Knowledge | Selected-response items, short written answers, structured oral questions. | Over-assessed Knowledge is the usual way a credential looks rigorous while testing little. |
| Skill | Practical tasks with an observable product; simulation with a marked artefact. | Multiple choice about how the task would be done. |
| Judgement | Scenario with competing constraints, requiring a decision and a defended justification. | Any item with one correct answer. |
| Practice | Portfolio of real work with provenance; workplace observation with attestation. | Examination of any kind. A two-hour exam cannot see habit. |
D8 requires general information security competence
The framework covers AI-specific security competence. It does not restate general information security competence, because that competence is already defined by other standards bodies. Verify the prerequisite at entry, by an external credential or by documented assessment, and record how you verified it in the specification.
External security credential at entry, or documented assessment covering access control, secrets handling, logging and incident response.
Entry assessment or prior qualification.
Not certifiable by us or by you as competence in law; state the jurisdiction assumed.
Stated experience requirement, or a practical entry task.
A defensible pass mark, and the record that makes it defensible
60% is not a standard. What makes a pass mark defensible is a documented method, a panel who applied it, and a date.
A panel judges, item by item, the proportion of minimally competent candidates who would answer correctly.
Panellists order items by difficulty and place a cut where the minimally competent candidate stops.
Define the borderline performance in writing, then set the mark that performance would earn.
Decide whether components compensate — for Practice and Judgement statements a conjunctive rule is usually right.
The technology moves faster than your validity period
A five-year certificate in this field is a claim about years ahead made today. Some competences decay because the systems change, and some do not decay at all.
Run this against your draft before submitting
Every item is checkable by you, in advance. An application that fails an item is returned rather than reviewed.