Can't make it to Vegas? Bring Hacker Summer Camp home with 50% OFF using HACKERCAMP50.

Certification

AppSecEngineer™ Certified Secure AI Agent Developer (CSAAD)

Your team is shipping AI agents into production. This certifies they can be trusted to touch it.
Agents don't just answer questions anymore — they hold identities, remember context across sessions, call MCP servers, retrieve from your knowledge base, and take action on your behalf. CSAAD certifies that a developer or engineer can build AI agents, MCP servers, RAG systems, and skills that are secure by default: attacking and defending every layer — identity, memory, retrieval, tooling, secrets, runtime — and shipping an agent safe enough to touch production.
Format: Instructor-Led  ·  Capstone: Required  ·  Certify: Capstone + Exam, both required

Why enterprises need this certification now

Agents are already in production, and incidents are following them

Agentic AI moved from pilot to production faster than any prior enterprise software category, and the incident data is already catching up to that speed. Two-thirds of organizations report having experienced at least one cybersecurity incident tied to an AI agent operating on their network in the past year, and a separate 2026 enterprise survey put confirmed-or-suspected agent security incidents as high as 88%. 

Excessive agency and over-permissioned identities are the default, not the exception

Agents don't behave like the service accounts security teams already know how to govern — they acquire credentials at runtime, spawn sub-agents, and reason about what their access allows, which turns a single compromised identity into an open-ended exploitation problem instead of a bounded one. The numbers reflect it:

  • Non-human identities now outnumber human identities in the typical enterprise by somewhere between 45:1 and over 80:1, and only around a fifth of enterprises treat AI agents as independent identities with their own governance.
  • In one industry survey, 80% of organizations reported their AI agents had already performed actions beyond their intended scope — including accessing unauthorized systems and revealing access credentials.
  • A large share of secrets held by non-human identities carry excessive permissions, and over 90% of organizations say their current IAM tooling simply cannot manage AI agent identities at all.
  • OWASP's own Top 10 for Agentic Applications (2026) put Identity and Privilege Abuse (ASI03) in its top three risks — alongside agent goal hijack and tool misuse — for exactly this reason.

Excessive agency isn't a hypothetical CSAAD teaches around; it's the modal way agents fail in production today, and it's the OWASP Agentic Top 10 attack class CSAAD candidates learn to exploit and then close.

MCP has become the fastest-growing, least-secured part of the agent supply chain

Every agent's usefulness depends on the tools and servers it connects to through MCP — and that layer has grown far faster than anyone has secured it. Independent research on deployed MCP servers found that over 80% use file operations prone to path traversal, roughly two-thirds use APIs related to code injection, and only a small single-digit percentage implement OAuth at all. A study of nearly 8,000 live MCP servers found 40% running with zero authentication whatsoever, and every OAuth-enabled server tested still carried at least one flaw. 

This is precisely the terrain CSAAD's MCP domain is built around: tool poisoning, shadow-server impersonation, and the scanning, allowlisting, and gateway controls that actually close the gap — skills that essentially no existing security certification currently teaches.

Memory and retrieval poisoning let an attack outlive the moment it happened

Unlike a single bad prompt, a poisoned memory or a poisoned knowledge source keeps steering an agent's behavior long after the original injection — which is exactly why OWASP classifies memory and context poisoning (ASI06) as its own top-tier risk. An agent that trusts what it retrieves, retrieves what an attacker planted. Developers who have never been trained to test for this have no reason to suspect their RAG pipeline is the entry point — which is why CSAAD has candidates poison their own memory layer and knowledge source before they're shown how to defend it.

Governance and accountability haven't caught up, and regulators are starting to ask

Fewer than one in ten organizations have a single named individual with formal accountability for AI agent behavior — most describe ownership as unclear, shared, or simply undiscussed. Around three-quarters of enterprises have no documented policy for creating or removing AI agent identities in the first place. At the same time, regulatory pressure is closing in: the EU AI Act's requirements for audit trails and attribution of autonomous systems reach full enforcement in 2026, and Gartner projects that by 2028, a quarter of enterprise breaches will trace back to AI agent abuse specifically.

Certification is how an enterprise puts a floor under this before a regulator, an auditor, or an incident does it for them — by verifying, developer by developer, that the people building agents actually know how to build them safely.

Who CSAAD certifies

A developer or engineer who builds AI agents, MCP servers, RAG systems, and skills, and can make them secure by default — attacking and defending each layer (identity, memory, retrieval, tooling, secrets, runtime) and shipping an agent safe enough to touch production.
Ideal for
AI Engineer
Developer
Security Engineer

3-4 days

of training

6-8 hrs

per day

X

number of lab exercises

52 weeks

access to platform

How certification works

Step 1

Attend live, instructor-led sessions
cohort-based, run by a practicing AppSec engineer, not pre-recorded video.

Step2

Complete a hands-on capstone project
a hardened, secure-by-default agent, built by applying every domain to a real, working deliverable. Graded, and required before the exam counts.

Step 3

Pass the certification exam
required in addition to the capstone, not instead of it.
Delivery: Live  ·  Capstone: Required  ·  Exam Attempts: 2 included
Instructors were well prepared, thorough and passionate. They covered the material well and were very helpful when needed
Security Architect,
Black Hat 2026 Attendee
Highly technical and thorough proof of concept labs that showed real-world applicability and I can immediately get a sense of how I can apply these techniques in my own AppSec program.Loved the course and very glad it was so technical, detailed, and very well prepared. The coverage of various frameworks is impressive.
Senior Developer,
Black Hat 2026 Attendee
Excellent course, I’ve been to several courses at Black Hat and this is for sure in the top 3. Keep doing what you’re doing!
DevSecOps Lead,
BlackHat USA 2026 Attendee

What the certification covers

Six domains. Weights reflect each domain's share of the total assessment score.

The capstone project

Every candidate closes CSAAD by shipping a single hardened, secure-by-default agent that survives everything the six domains taught them to throw at it: identity scoped to least privilege, memory and retrieval defended against poisoning, MCP tooling scanned and allowlisted behind a gateway, secrets held nowhere in the agent itself, and execution sandboxed so a compromise stays contained. The capstone is graded and required — it, and the exam, must both be passed to earn the certification.
Format: Instructor-Led  ·  Capstone: Required  ·  Certify: Capstone + Exam, both required

The best AppSec training in the biz

Hackevent Logo
4.6

Koushik M.

"Exceptional Hands-On Security Learning Platform"

Varunsainadh K.

"Practical Security Training with Real-World Labs"

Gaël Z.

"A new generation platform showing both attacks and remediations"

Nanak S.

"Best resource to learn for appsec and product security"

Ready to Elevate Your Security Training?

Empower your teams with the skills they need to secure your applications and stay ahead of the curve.
Get Started Now
Copyright AppSecEngineer © 2026
X

Not ready for a demo?

Join us for a live product tour - available every Thursday at 8am PT/11 am ET

Schedule a demo

No, I will lose this chance & potential revenue

x
x