CTTPSpecialization
Certified Third-Party Trust Practitioner
The third-party risk specialization. It shows you can tier vendors, read SOC reports properly, own the controls they hand back to you, and keep watching between reviews.
6 required courses 18 ALCs Proctored scenario exam
Valid 3 years
What it shows you can do
- Build and run a tiered third-party risk program
- Read a SOC 2 report for scope, exceptions and carve-outs
- Turn complementary user entity controls into owned internal controls
- Monitor vendors and software supply chain risk between reviews
Who it's for
Vendor risk and TPRM analysts and managers, and procurement or security staff who assess suppliers.
Your path to CTTP
Your dashboard tracks each step against your record, so you always know what's done and what's left.
- 1Complete the required courses6 courses, 18 ALCs. Each ends with a deliverable you keep.
- TPR-201Building a Third-Party Risk Program: From Zero and At Scale4 ALCs
- TPR-210Reading a SOC 2 Report: Opinion, Scope, Exceptions, CUECs and Subservice Organisations3 ALCs
- TPR-215Handling CUECs: Turning Complementary User Entity Controls Into Your Own Obligations2 ALCs
- TPR-220Vendor Due Diligence Questionnaires: SIG, CAIQ, Custom and Scoring3 ALCs
- TPR-240Continuous Vendor Monitoring: Breach Intelligence, Attestation Expiry and Recertification3 ALCs
- CYB-201Software Supply Chain: SBOMs, VEX and Component Monitoring in Practice3 ALCs
- 2Pass the assessmentA proctored scenario exam, plus a graded SOC report review and CUEC register.
- 3Affirm the code of ethicsA short annual affirmation of the ADTP code of ethics.
Keeping it current
The credential is valid for 3 years. You renew it with continuing education and the annual ethics affirmation, so it keeps saying something true about you.
Anyone can check it
Your credential has a public verification page and an Open Badges assertion you can add to LinkedIn. Employers and clients can confirm it in seconds.