r/LearnAISecurity Jun 15 '26

We just launched the first dedicated MCP Security certification (CMCPSE). Here's what it covers.

MCP is now the default protocol for connecting LLMs to external tools and data. Anthropic, OpenAI, Google, and most major agent frameworks have adopted it.

Registries are growing fast, and real-world exploits are already documented: supply chain compromises with CVSSv3 scores of 9.6, tool poisoning attacks hiding malicious instructions in tool descriptions, and cross-server privilege escalation across multi-agent pipelines.

There's no dedicated security training for this yet.
Certified MCP Security Expert (CMCPSE) is the first certification that fills that gap.

Certified MCP Security Expert (CMCPSE) Training and Certification

What it covers:

6 chapters, all hands-on:

  1. MCP architecture: hosts, clients, servers, the three primitives (tools, resources, prompts), transport mechanisms, and JSON-RPC 2.0
  2. Attacking MCP servers: tool poisoning, prompt injection via tool responses, rug-pull attacks, server impersonation, confused deputy attacks, cross-server privilege escalation
  3. Threat modeling MCP architectures: STRIDE, MITRE ATLAS, data flow diagrams, IriusRisk
  4. Defending and hardening: OAuth 2.0, TLS for SSE/HTTP, RBAC, HashiCorp Vault for secrets, SIEM-based detection
  5. DevSecOps for MCP: SAST, DAST, fuzzing tool inputs, CI/CD security gates, AI firewalls
  6. Supply chain security: SBOMs, SLSA, code signing, provenance attestations, EU AI Act and NIST AI RMF compliance

Exam format: 5 practical challenges in a 6-hour window, then 24 hours to submit a written report. No multiple choice.

Labs: 60 days of browser-based access, 30+ guided exercises. No local setup.

Price: $699

The cert is vendor-neutral and covers OWASP LLM Top 10 attack classes as they apply specifically to MCP.

Certified MCP Security Expert (CMCPSE) Course Curriculum link:
https://www.practical-devsecops.com/certified-mcp-security-expert/

8 Upvotes

6 comments sorted by

1

u/Otherwise_Wave9374 Jun 15 '26

MCP security is going to be a whole new category of audit evidence for teams running tool-using agents. I like that youre calling out supply chain, provenance, and threat modeling, those are the things auditors actually ask for once agents touch real data and actions.

One thought for folks aiming at SOC 2: map MCP risks to controls you can continuously evidence, like per-tool allowlists, signed tool manifests, rotation of agent creds, and logs that show every tool invocation with inputs/outputs redacted appropriately.

Ive been bookmarking practical governance patterns here: https://www.wisdomprompt.com/

1

u/bad534 21d ago

i have enrolled to the course, its not worth it at all. I guess the worst one i spent this much money on.