Back to index
OtherSelf paced with 60 days of browser based lab access and 30 plus guided exercises, then a hands on exam of five challenges in six hours with a further 24 hours to write the report·$1,099 at the standing discount from a $1,199 list, with one exam attempt included and 36 CPE points on completion

CAISP (Certified AI Security Professional)

4.1

The practical exam is the reason to consider this over the better known AI security certifications. You attack things and then write up what you found, which is a much harder thing to fake than a question bank.

What We Liked

  • The exam is five hands on challenges plus a written report, not multiple choice, so passing means something specific
  • Built on frameworks people actually use, with OWASP LLM Top 10 and MITRE ATLAS as the spine rather than a bespoke taxonomy
  • 60 days of browser based labs with 30 plus guided exercises removes all environment setup friction
  • The supply chain chapter covers where most real AI exposure sits, which is other people's models and plugins
  • Genuinely low prerequisites, needing only basic Linux and some scripting familiarity

What Could Be Better

  • Around $1,100 is a lot for a credential from a provider most hiring managers have never heard of
  • The discount from $1,199 appears to be permanent, which is a marketing habit that undermines trust
  • 60 days of lab access is a hard clock that will not suit anyone with an unpredictable job
  • Lifetime validity with no recertification sounds generous and is faintly worrying in a field moving this quickly
  • Brand recognition sits well below ISACA or ISC2, so the credential travels less far than the knowledge does

Detailed review

There are now enough AI security certifications that the interesting question is not whether to hold one but which failure mode you are avoiding. The dominant failure mode is the policy exam, where a hundred multiple choice questions establish that you can recognise the phrase prompt injection without establishing that you could find one. CAISP is built to avoid that specific failure, and the mechanism is the exam. You get five challenges and six hours to complete them, then a further 24 hours to write and submit a report.

That format is borrowed from the offensive security world and it is the right borrowing. Writing the report is not an administrative afterthought, it is half the skill, because a finding nobody can act on is not a finding. The curriculum runs across seven chapters and it is sensibly built. It opens with AI security fundamentals, moves into understanding and attacking large language models, then the OWASP LLM Top 10, then AI attacks and defences in a DevOps context, then threat modelling AI systems with STRIDE, then supply chain attacks, and closes on emerging threats and governance under NIST RMF, ISO 42001 and the EU AI Act.

Two things stand out. The first is that the frameworks are ones the industry has converged on rather than a taxonomy the provider invented to make their material feel proprietary, which matters because you can carry OWASP and MITRE ATLAS vocabulary into a room with people who have never heard of Practical DevSecOps. The second is that the governance chapter is last and is one chapter of seven. On a technical certification that is the correct weighting, and it is the opposite of how most AI security material is balanced.

The supply chain chapter deserves specific credit. Most organisations' genuine AI exposure is not a model they trained. It is a vendor component that quietly started calling a language model, a plugin with read access to a document store, a fine tune of somebody else's weights of uncertain provenance, or a model pulled from a public hub without anybody checking what was in it. Those are third party risk problems that happen to involve models, and a course that treats them as central is describing the real threat surface.

The labs are 60 days of browser based access with 30 plus guided exercises, which means no environment setup, no dependency hell and no arguing with your laptop before you can start. For a course that lives or dies on hands on work, that is the correct investment. Twenty four seven instructor support over a dedicated channel is offered and is the kind of thing that is either excellent or nominal depending on who is staffing it, and I would not weight it heavily either way in your decision. Now the problems.

The price is roughly $1,100 and the brand is not one that opens doors. That is the central tension in this review. The knowledge is real and the assessment is honest, but a credential is partly a signal, and this one signals to a smaller audience than its price implies. If your motivation is a line on a CV that a non technical hiring manager will recognise, ISACA's AAISM is better known despite being, in my view, the less demanding qualification.

If your motivation is being able to do the work, CAISP is the better spend. Be clear with yourself about which one you are buying. The permanent discount irritates me more than it probably should. A list price of $1,199 and a current price of $1,099 that never seems to expire is a small dishonesty, and I have seen the same course quoted higher elsewhere with a matching fake saving.

It has nothing to do with the quality of the material and everything to do with how much benefit of the doubt I extend to the rest of the marketing. The 60 day lab window is a real constraint that people underestimate at purchase. Self paced sounds relaxed until you have a hard expiry, and 30 plus exercises plus exam preparation inside two months while holding a demanding job is tighter than it reads. Buy it when you have a quiet quarter, not when you are optimistic.

Lifetime validity with no recertification is the item I keep circling back to. On a certification covering attack techniques against systems that did not exist three years ago, a credential that never expires is telling you something uncomfortable about what it will mean in 2030. It is a genuine cost saving and a genuine signalling weakness, and the honest framing is that your CAISP will always be evidence of what you could do in the year you sat it. My 4.1 is for a technically serious certification that is assessed properly, priced high, and carried by a brand that has not yet earned the price.

If you are the person who will actually be asked to threat model a retrieval pipeline or explain why an agent with tool access is a different exposure than an API, this will make you better at that, and the exam will prove you are. If you need the badge to do the talking, buy a different badge.

[ final ]

The verdict.

Worth it if you are a working security or platform engineer who needs to actually attack and defend model backed systems, and if you can clear the 60 day window. If you want a credential a board will recognise, ISACA's AAISM is the better badge and the worse course.