Verified learning
Professional credentials
This page collects verifiable badges and learning paths that document ongoing work on technology, standards and requirements relevant to connected products.
The Linux Foundation Education · Credly
Understanding the EU Cyber Resilience Act
LFEL1001 is a learning path focused on the Cyber Resilience Act: terminology, roles and responsibilities, essential cybersecurity requirements, user information and required markings.
The badge is issued by The Linux Foundation Education and can be publicly verified through Credly.
This credential confirms completion of the learning path; it is not a CRA conformity certification or a declaration about a specific product.
The Linux Foundation Education · Credly
Automating Supply Chain Security: SBOMs and Signatures
LFEL1007 covers the use of open-source tools to sign and secure software packages and artifacts, verify their integrity, and assess supply-chain security information.
The learning path also addresses the verification of release artifacts. The badge is issued by The Linux Foundation Education and can be publicly verified through Credly.
This credential confirms completion of the learning path; it does not replace a supply-chain assessment or certify the security of a specific piece of software or product.
The Linux Foundation · Credly
Secure AI/ML-Driven Software Development
LFEL1012 covers the secure use of AI code assistants, secure-coding practices in AI-assisted development, and effective review of generated changes.
The learning path also addresses the mitigation of risks associated with the “lethal trifecta,” secure MCP server development, slopsquatting and the management of low-quality AI-generated contributions.
This credential confirms completion of the learning path; it does not replace a secure code review, threat model or software security assessment.
The Linux Foundation · Credly
Authentication & Authorization for Web/API
LFEL1004 confirms knowledge of designing, configuring and managing secure identity and access controls for web applications and APIs.
The learning path covers OAuth 2.0 and OpenID Connect, Single Sign-On, Role-Based Access Control, multi-factor authentication and token-based security, applying the principle of least privilege.
This credential confirms completion of the learning path; it does not replace an architecture review, penetration test or security assessment of applications and APIs.
How this learning is applied
Credentials do not replace a technical assessment. They strengthen work on requirements, evidence, exposed surface, updates, roles and documentation when a connected product falls within the CRA scope.