Coming Q3 2026

CVEasy University

The industry's first certification program built entirely for vulnerability management professionals. Six courses, 39 modules, three certification tiers, 100% hands-on exams. Written by practitioners who run VM programs daily.

500K+
Unfilled cyber roles in the US
40%
YoY growth in VM job postings
0
Existing VM-focused certifications
Courses in development · sign up for early notification
01 · The syllabus

Six courses, numbered in the order you read them.

The numbers are the sequence, not decoration. Course 01 assumes nothing. Each course after it uses what the one before it built: the program sets the SLAs, EPSS and KEV feed the scoring model, the model gates the AI triage, BASzy validates the fixes, and the reporting course turns the whole chain into a board narrative. Every module runs on real CVEs and real scan data.

Building a VM program from scratch

Foundation · 10 modules

From zero to a functioning vulnerability management program. Policy creation, tool selection, scanning cadence, remediation SLAs, executive reporting, and continuous improvement. The complete playbook.

PolicySLAsReporting
Start hereAssumes nothing

EPSS and KEV prioritization that works

Advanced · 6 modules

Deep dive into FIRST's EPSS model and CISA's KEV catalog. Learn the statistics behind exploitation prediction, build automated prioritization pipelines, and stop wasting cycles on CVEs that will never be exploited.

FIRST.orgCISAAutomation
After 01Uses your program's SLAs

TRIS™ scoring masterclass

Deep dive · 6 modules

Go beyond CVSS. Build a risk scoring model that factors in EPSS probability, CISA KEV status, industry context, and compliance requirements. Calibrate it for your organization and defend it to leadership.

CVSSEPSSKEV
After 02EPSS and KEV feed the model

AI-powered vulnerability triage

Practical · 8 modules

Learn to use local AI models to triage CVEs at scale. Build custom prompts, evaluate remediation quality, and integrate AI into your existing patching workflow. Hands-on labs using real NVD data.

CVEasy AI™NVDPrompt engineering
After 03The model gates the triage

Attack simulation for VM teams

Offensive · 4 modules

Use Breach & Attack Simulation to validate that your remediations actually work. Run BASzy™ attack modules against test environments, map results to MITRE ATT&CK, and prove exploitability before and after patching.

BASzyMITRE ATT&CKValidation
After 04Validates what triage shipped

Executive reporting and board narratives

Leadership · 5 modules

Translate technical risk into business impact. Build board-ready dashboards, craft risk narratives that drive funding, and present VM metrics that CISOs and executives actually care about.

MetricsDashboardsRisk comms
After 05Reports what validation proved

Read 01 → 06 and you have run one full exposure cycle: program → prioritization → scoring → triage → validation → report.

02 · Certification

Three tiers, zero multiple choice.

Each certification builds on the last, and every exam runs inside a live CVEasy AI instance: real findings, real scoring, real remediation work. Pricing is announced at launch.

Entry level

CVU-VMF

Vulnerability Management Foundations

Contact sales →

For SOC analysts, IT admins, junior VM staff, and career changers. Covers the full vulnerability lifecycle from scanning through remediation. No prior security experience required.

  • CVE lifecycle, NVD, CVSS scoring
  • Scan ingestion and triage workflows
  • Remediation, SLAs, and verification
  • Stakeholder reporting basics
Exam8-hour practical
PrerequisitesNone
Validity3 years
Intermediate

CVU-VMA

Vulnerability Management Analyst

Contact sales →

For working VM analysts and engineers. Advanced risk scoring, multi-source triage, compliance mapping, AI-assisted analysis, and remediation orchestration at scale.

  • Multi-factor risk scoring (TRIS methodology)
  • AI-assisted triage and prompt engineering
  • Multi-scanner ingestion (Nessus, Qualys, OpenVAS)
  • Compliance mapping and threat intelligence
Exam24-hour practical
PrerequisitesCVU-VMF or 2 years exp.
Validity3 years
Advanced

CVU-VMP

Vulnerability Management Professional

Contact sales →

For VM program leads, security managers, and architects. Design complete VM programs, build metrics frameworks, present to boards, and drive strategic risk management across the enterprise.

  • VM program design and maturity models
  • Board-level reporting and risk narratives
  • Compliance governance (SOC 2, HIPAA, PCI, FedRAMP)
  • 72-hour capstone: build a complete VM program
Exam72-hour practical
PrerequisitesCVU-VMA or 5 years exp.
Validity3 years
03 · Learning paths

Six paths feed three exams.

Every path is a module sequence pointed at one certification. Path 1 preps CVU-VMF. Paths 2, 3, and 6 prep CVU-VMA. Paths 4 and 5 prep CVU-VMP. Finish a column and you are exam-ready.

CVU-VMFEntry level · 1 path
Path 1 VM foundations 8 modules · CVE lifecycle, scanning, triage, remediation basics
CVU-VMAIntermediate · 3 paths
Path 2 Risk scoring and prioritization 6 modules · EPSS, KEV, asset context, TRIS methodology
Path 3 AI-powered security ops 5 modules · prompt engineering, AI triage, knowledge bases
Path 6 Attack surface and threat exposure 4 modules · CTEM framework, BAS, attack path analysis
CVU-VMPAdvanced · 2 paths
Path 4 Compliance and governance 5 modules · SOC 2, HIPAA, PCI-DSS, SLA design, audits
Path 5 Program design and leadership 6 modules · metrics, exec comms, continuous improvement, capstone
04 · Method

Every exam runs on a live CVEasy instance.

The testing environment is the product: the same scoring engine, the same ingest pipeline, the same remediation workflow you would run at work. The exam checks whether the environment ends up fixed.

Exam format
100% hands-on. Every exam is performed in a live CVEasy AI instance, and no tier uses multiple choice.
Lab data
Live NVD data, real scan imports, and production-grade tooling. No sanitized examples or toy datasets.
Faculty
Written by security engineers who run VM programs daily. Every module reflects the workflows they use on shift.
Scope
Vulnerability management only. CVEasy University is the only certification body focused exclusively on VM operations.
05 · The gap

Every enterprise runs a VM program, and no certification covers it

Existing training platforms teach penetration testing, CTF challenges, and SOC analysis. Every enterprise still runs a vulnerability management program, and until CVEasy University nobody certified the people who run them.

Other platforms

Teach penetration testing, CTF challenges, and SOC analysis. Zero coverage of VM program operations.

Broad certifications

Cover security breadth-first, with one VM question out of 90. They do not prepare anyone to run a VM program.

CVEasy University

100% vulnerability management: scanning, triage, scoring, remediation, compliance, reporting. The complete skill set, certified.

06 · Accreditation

The road from launch to recognized standard.

Certification bodies earn trust in a fixed order: verifiable badges first, government catalog listing second, ISO accreditation third, defense baseline last. The dates below are the plan of record.

Year 12026-2027

Credly digital badges

All six courses and the CVU-VMF certification launch. Verifiable digital badges issue through Credly, the same platform CompTIA, AWS, and Google use, and they are shareable on LinkedIn from day one.

Year 22027-2028

CISA NICCS recognition

CVU-VMF is submitted to CISA's National Initiative for Cybersecurity Careers and Studies catalog. The CVU-VMA and CVU-VMP exams launch, and CPE credit partnerships with ISC2 and ISACA begin.

Years 3-42028-2030

ISO/IEC 17024 accreditation

Accreditation through ANAB: the international standard for personnel certification bodies, and the same accreditation CompTIA, ISC2, and ISACA hold. It requires psychometric analysis, job task analysis, and independent governance.

Year 52030-2031

DoD 8140 baseline

CVU-VMF recognized on the DoD 8140 approved baseline for DCWF Work Role 541, Vulnerability Assessment Analyst. Recognition there makes CVU certifications count toward a hiring requirement for defense contractors.

Start your vulnerability management career today.

Explore the platform that powers CVEasy University.

Request a Demo Quick Start Guide →