An overview of free as well as commercial training and certifications related to secure software development in no particular order.
Last verified: 2026-08-09. Every link in this file was checked on that date and resolves. A few publisher and vendor sites (O'Reilly, Packt, Security Compass) block automated checkers, so those were confirmed in a real browser instead. Prices are the figures published on the vendor's own page at that time, in the currency the vendor quotes. Where a vendor no longer publishes a price, the cost column says 🤷 rather than repeating a stale number.
Legend: ✨free · ✅ certificate issued · ❌ no certificate · 🤷 not published
The fastest-moving category, and the one most likely to be out of date. Treat prices here as especially perishable.
| Org/Platform | Course/Cert | Cost | Certificate? |
|---|---|---|---|
| SANS | SEC545: GenAI and LLM Application Security | $8,260 | ✅ (GAIPS, $999) |
| Practical DevSecOps | Certified AI Security Professional (CAISP) | $1,099 | ✅ (included) |
| Certified MCP Security Expert (CMCPSE) | $699 | ✅ (included) |
|
| The Linux Foundation | Secure AI/ML-Driven Software Development (LFEL1012) | ✨free | ✅ (badge) |
| Learn Prompting | AI Red Teaming Professional (AIRTP+) | $299 exam $1,199 w/ course |
✅ (included) |
| HiddenLayer | AI Security Academy | 🤷 | ✅ |
| DeepLearning.AI | Red Teaming LLM Applications | ✨free | ✅ (Pro only) |
| Snyk Learn | OWASP Top 10 for LLM, GenAI and Agentic Applications | ✨free | ✅ |
| Org/Platform | Course/Cert | Cost | Certificate? |
|---|---|---|---|
| ThreatModeler Academy (formerly IriusRisk) | Threat Modeling Foundations | ✨free | ✅ (included) |
| + more like Champion, AI/ML Systems, Agentic AI, Embedded Devices | ✨free | ✅ (included) |
|
| Shostack + Associates | Threat Modeling Essentials (201) | $899 | 🤷 |
| Practical DevSecOps | Certified Threat Modeling Professional (CTMP) | $899 | ✅ (included) |
Labs and deliberately vulnerable applications for building the skill rather than collecting a credential.
| Org/Platform | Resource | Cost | Certificate? |
|---|---|---|---|
| OWASP | WebGoat | ✨free | ❌ |
| Secure Coding Dojo | ✨free (self-hosted) |
❌ | |
| Hacksplaining | Interactive secure coding lessons | ✨free | ❌ |
| APIsec University | Certified API Security Analyst (CASA) | ✨free | ✅ |
| PentesterLab | PRO: web exploitation and code review labs | $19.99/mo. $199.99/yr. |
✅ |
| Cybrary | Secure Coding | ✨free (cert needs sub.) |
✅ |
- OWASP Application Security Verification Standard (ASVS): control requirements to test against and to write into your own specs.
- OWASP Cheat Sheet Series: concise, practitioner-written secure coding guidance per topic.
- OWASP AI Exchange: open, continuously updated reference on AI and LLM threats and controls.
- NIST Secure Software Development Framework (SSDF, SP 800-218): vendor-neutral SDLC practices, increasingly referenced in procurement and supply-chain requirements.
- Hsu, T. (2018) Hands-on security in DevOps. Birmingham, UK: Packt Publishing.
- Janca, T. (2021) Alice & Bob Learn Application Security. Indianapolis, IN: John Wiley & Sons, Inc.
- Shostack, A. (2014) Threat Modeling: Designing for Security. Indianapolis, IN: John Wiley & Sons, Inc.
- Tarandach, I. and Coles, M. J. (2020) Threat Modeling: Risk Identification and Avoidance in Secure Design. Sebastopol, CA: O'Reilly Media.
- Adkins, H., Beyer, B., Blankinship, P., Lewandowski, P., Oprea, A. and Stubblefield, A. (2020) Building Secure and Reliable Systems. Sebastopol, CA: O'Reilly Media. (free to read online)
- Johnsson, D. B., Deogun, D. and Sawano, D. (2019) Secure by Design. Shelter Island, NY: Manning Publications.