Building a VM program from scratch
From zero to a functioning vulnerability management program. Policy creation, tool selection, scanning cadence, remediation SLAs, executive reporting, and continuous improvement. The complete playbook.
The industry's first certification program built entirely for vulnerability management professionals. Six courses, 39 modules, three certification tiers, 100% hands-on exams. Written by practitioners who run VM programs daily.
Courses in development · sign up for early notificationThe numbers are the sequence, not decoration. Course 01 assumes nothing. Each course after it uses what the one before it built: the program sets the SLAs, EPSS and KEV feed the scoring model, the model gates the AI triage, BASzy validates the fixes, and the reporting course turns the whole chain into a board narrative. Every module runs on real CVEs and real scan data.
From zero to a functioning vulnerability management program. Policy creation, tool selection, scanning cadence, remediation SLAs, executive reporting, and continuous improvement. The complete playbook.
Deep dive into FIRST's EPSS model and CISA's KEV catalog. Learn the statistics behind exploitation prediction, build automated prioritization pipelines, and stop wasting cycles on CVEs that will never be exploited.
Go beyond CVSS. Build a risk scoring model that factors in EPSS probability, CISA KEV status, industry context, and compliance requirements. Calibrate it for your organization and defend it to leadership.
Learn to use local AI models to triage CVEs at scale. Build custom prompts, evaluate remediation quality, and integrate AI into your existing patching workflow. Hands-on labs using real NVD data.
Use Breach & Attack Simulation to validate that your remediations actually work. Run BASzy™ attack modules against test environments, map results to MITRE ATT&CK, and prove exploitability before and after patching.
Translate technical risk into business impact. Build board-ready dashboards, craft risk narratives that drive funding, and present VM metrics that CISOs and executives actually care about.
Read 01 → 06 and you have run one full exposure cycle: program → prioritization → scoring → triage → validation → report.
Each certification builds on the last, and every exam runs inside a live CVEasy AI instance: real findings, real scoring, real remediation work. Pricing is announced at launch.
Vulnerability Management Foundations
Contact sales →For SOC analysts, IT admins, junior VM staff, and career changers. Covers the full vulnerability lifecycle from scanning through remediation. No prior security experience required.
Vulnerability Management Analyst
Contact sales →For working VM analysts and engineers. Advanced risk scoring, multi-source triage, compliance mapping, AI-assisted analysis, and remediation orchestration at scale.
Vulnerability Management Professional
Contact sales →For VM program leads, security managers, and architects. Design complete VM programs, build metrics frameworks, present to boards, and drive strategic risk management across the enterprise.
Every path is a module sequence pointed at one certification. Path 1 preps CVU-VMF. Paths 2, 3, and 6 prep CVU-VMA. Paths 4 and 5 prep CVU-VMP. Finish a column and you are exam-ready.
The testing environment is the product: the same scoring engine, the same ingest pipeline, the same remediation workflow you would run at work. The exam checks whether the environment ends up fixed.
Existing training platforms teach penetration testing, CTF challenges, and SOC analysis. Every enterprise still runs a vulnerability management program, and until CVEasy University nobody certified the people who run them.
Teach penetration testing, CTF challenges, and SOC analysis. Zero coverage of VM program operations.
Cover security breadth-first, with one VM question out of 90. They do not prepare anyone to run a VM program.
100% vulnerability management: scanning, triage, scoring, remediation, compliance, reporting. The complete skill set, certified.
Certification bodies earn trust in a fixed order: verifiable badges first, government catalog listing second, ISO accreditation third, defense baseline last. The dates below are the plan of record.
All six courses and the CVU-VMF certification launch. Verifiable digital badges issue through Credly, the same platform CompTIA, AWS, and Google use, and they are shareable on LinkedIn from day one.
CVU-VMF is submitted to CISA's National Initiative for Cybersecurity Careers and Studies catalog. The CVU-VMA and CVU-VMP exams launch, and CPE credit partnerships with ISC2 and ISACA begin.
Accreditation through ANAB: the international standard for personnel certification bodies, and the same accreditation CompTIA, ISC2, and ISACA hold. It requires psychometric analysis, job task analysis, and independent governance.
CVU-VMF recognized on the DoD 8140 approved baseline for DCWF Work Role 541, Vulnerability Assessment Analyst. Recognition there makes CVU certifications count toward a hiring requirement for defense contractors.
Be the first to enroll. Early subscribers get priority access and launch-day pricing.
No spam. Unsubscribe anytime. Read our privacy policy.
Explore the platform that powers CVEasy University.