Coming Q3 2026

CVEasy University

The industry's first certification program built entirely for vulnerability management professionals. 30 modules. 3 certifications. 100% hands-on exams. Built by practitioners, not academics.

500K+
Unfilled cyber roles in the US
40%
YoY growth in VM job postings
0
Existing VM-focused certifications
Courses in development · sign up for early notification

Course Catalog

Courses that close the skills gap

Every course built around real CVEs, real tools, and real workflows. 6 courses, 30 modules, all hands-on.

Practical 8 modules

AI-Powered Vulnerability Triage

Learn to use local AI models to triage CVEs at scale. Build custom prompts, evaluate remediation quality, and integrate AI into your existing patching workflow. Hands-on labs using real NVD data.

Ollama NVD Prompt Engineering
Deep Dive 6 modules

TRIS™ Scoring Masterclass

Go beyond CVSS. Build a risk scoring model that factors in EPSS probability, CISA KEV status, industry context, and compliance requirements. Calibrate it for your organization and defend it to leadership.

CVSS EPSS KEV
Foundation 10 modules

Building a VM Program from Scratch

From zero to a functioning vulnerability management program. Policy creation, tool selection, scanning cadence, remediation SLAs, executive reporting, and continuous improvement. The complete playbook.

Policy SLAs Reporting
Advanced 6 modules

EPSS & KEV: Prioritization That Actually Works

Deep dive into FIRST's EPSS model and CISA's KEV catalog. Learn the statistics behind exploitation prediction, build automated prioritization pipelines, and stop wasting cycles on CVEs that will never be exploited.

FIRST.org CISA Automation
Leadership 5 modules

Executive Reporting & Board Narratives

Translate technical risk into business impact. Build board-ready dashboards, craft risk narratives that drive funding, and present VM metrics that CISOs and executives actually care about. Stop being ignored.

Metrics Dashboards Risk Comms
Offensive 4 modules

Attack Simulation for VM Teams

Use Breach & Attack Simulation to validate that your remediations actually work. Run BASzy attack modules against test environments, map results to MITRE ATT&CK, and prove exploitability before and after patching.

BASzy MITRE ATT&CK Validation

Certification Tiers

Three levels. All practical. No multiple choice.

Each certification builds on the last. Every exam uses a live CVEasy AI instance as the testing environment. Prove you can do the work, not just answer questions about it.

Entry Level

CVU-VMF

Vulnerability Management Foundations

$199 exam fee

For SOC analysts, IT admins, junior VM staff, and career changers. Covers the full vulnerability lifecycle from scanning through remediation. No prior security experience required.

  • CVE lifecycle, NVD, CVSS scoring
  • Scan ingestion and triage workflows
  • Remediation, SLAs, and verification
  • Stakeholder reporting basics
Duration8-hour practical exam
PrerequisitesNone
Validity3 years
Intermediate

CVU-VMA

Vulnerability Management Analyst

$349 exam fee

For working VM analysts and engineers. Advanced risk scoring, multi-source triage, compliance mapping, AI-assisted analysis, and remediation orchestration at scale.

  • Multi-factor risk scoring (TRIS methodology)
  • AI-assisted triage and prompt engineering
  • Multi-scanner ingestion (Nessus, Qualys, OpenVAS)
  • Compliance mapping and threat intelligence
Duration24-hour practical exam
PrerequisitesCVU-VMF or 2 years exp.
Validity3 years
Advanced

CVU-VMP

Vulnerability Management Professional

$499 exam fee

For VM program leads, security managers, and architects. Design complete VM programs, build metrics frameworks, present to boards, and drive strategic risk management across the enterprise.

  • VM program design and maturity models
  • Board-level reporting and risk narratives
  • Compliance governance (SOC 2, HIPAA, PCI, FedRAMP)
  • 72-hour capstone: build a complete VM program
Duration72-hour practical exam
PrerequisitesCVU-VMA or 5 years exp.
Validity3 years

Learning Paths

6 paths. 30 modules. One clear progression.

Each path maps directly to a certification tier. Start at foundations and advance through to program leadership.

1
VMF Prep

VM Foundations

8 modules · CVE lifecycle, scanning, triage, remediation basics

2
VMA Prep

Risk Scoring & Prioritization

6 modules · EPSS, KEV, asset context, TRIS methodology

3
VMA Prep

AI-Powered Security Ops

5 modules · Prompt engineering, AI triage, knowledge bases

4
VMP Prep

Compliance & Governance

5 modules · SOC 2, HIPAA, PCI-DSS, SLA design, audits

5
VMP Prep

Program Design & Leadership

6 modules · Metrics, exec comms, continuous improvement, capstone

6
VMA Prep

Attack Surface & Threat Exposure

4 modules · CTEM framework, BAS, attack path analysis

CVU-VMF
Path 1
CVU-VMA
Paths 2, 3 & 6
CVU-VMP
Paths 4 & 5

Why CVEasy University

What makes this different

Not another video course platform. A certification program designed around how VM work actually happens.

100% Practical

No multiple choice. Every exam is hands-on using a live CVEasy AI instance. Prove you can do the work, not memorize answers.

Real CVEs, Real Data

Labs use live NVD data, real scan imports, and production-grade tooling. No sanitized examples or toy datasets.

Built by Practitioners

Created by security engineers who run VM programs daily. Every module reflects real-world workflows, not textbook theory.

Industry-First Focus

The only certification body focused exclusively on vulnerability management operations. Not pentesting. Not SOC. VM.

The Gap in Cybersecurity Training

Other platforms teach you to hack.
We teach you to defend.

Existing training platforms focus on offensive security and SOC operations. But every enterprise runs a vulnerability management program, and nobody certifies the people who run them.

Other platforms

Teach penetration testing, CTF challenges, and SOC analysis. Zero coverage of VM program operations.

Broad certifications

Cover security breadth-first. One VM question out of 90. Doesn't prepare you to run a VM program.

CVEasy University

100% focused on vulnerability management. Scanning, triage, scoring, remediation, compliance, reporting. The complete skill set.

Nobody certifies vulnerability management operations. Until now.

Accreditation Roadmap

From launch to industry standard

A clear path to recognized, accredited certifications that employers trust and governments require.

Y1

Credly Digital Badges

2026-2027

Launch all courses and the CVU-VMF certification. Issue verifiable digital badges via Credly -- the same platform used by CompTIA, AWS, and Google. Shareable on LinkedIn from day one.

Y2

CISA NICCS Recognition

2027-2028

Submit CVU-VMF to CISA's National Initiative for Cybersecurity Careers and Studies catalog. Launch CVU-VMA and CVU-VMP exams. Begin CPE credit partnerships with ISC2 and ISACA.

Y3-4

ISO 17024 Accreditation

2028-2030

Achieve ISO/IEC 17024 accreditation through ANAB -- the international standard for personnel certification bodies. This is the same accreditation held by CompTIA, ISC2, and ISACA. Includes psychometric analysis, job task analysis, and independent governance.

Y5

DoD 8140 Compliance

2030-2031

CVU-VMF recognized on the DoD 8140 approved baseline for DCWF Work Role 541 (Vulnerability Assessment Analyst). This makes CVU certifications a requirement for defense contractors -- the gold standard for industry recognition.

Start your vulnerability management career today.

Explore the platform that powers CVEasy University.

Get Started Free Quick Start Guide →