CTEM Program Leader Certification

Design a CTEM program a board would fund. Operating model, metrics, toolchain, and roadmap that hold up under scrutiny.
The CTEM Program Leader certification is the leadership-level, free credential from LearnCTEM. It is a capstone submission, not a multiple-choice exam. You are given a fictional company (industry, size, regulatory context) and you produce a complete CTEM program design: operating model with RACI, governance and cadence, toolchain architecture, metrics and board reporting, a maturity assessment, a 90-day roadmap, and explicit regulatory alignment with DORA, NIS2, and the SEC Cybersecurity Disclosure Rule. Submissions are scored against a public rubric. Free and unlimited resubmissions.
This certification is not open yet
The CTEM Program Leader Certification is in final review. Enrolment, the capstone brief, and the sample material will open here soon. In the meantime, complete the Beginner and Practitioner certifications, they are the recommended preparation path.
Who this certification is for
CISOs and security directors
Show the board a CTEM program that connects security work to business risk in language leadership actually understands.
Exposure management program owners
Prove you can stand up or mature a CTEM program with defensible operating and governance choices.
Senior consultants and advisors
Ship a reference-quality CTEM design you can adapt for any client engagement.
Exam blueprint
| Domain | Weight | What you must prove |
|---|---|---|
| Operating Model and RACI | 20 percent | Clear ownership for every stage across security, IT, cloud, identity, app, and business units. |
| Governance and Cadence | 15 percent | Steering committee, decision rights, cycle cadence, exception process, and escalation paths. |
| Toolchain Architecture | 15 percent | Vendor-neutral tool categories, integration model, data flow, and gap analysis. |
| Metrics and Board Reporting | 20 percent | Metrics that reflect risk reduction, plus a reporting pack a board can act on. |
| Maturity and 90-day Roadmap | 20 percent | Honest current-state maturity, target state, and a feasible 90-day plan that ships value. |
| Regulatory Alignment (DORA, NIS2, SEC Cyber Rule) | 10 percent | Explicit mapping to relevant obligations without turning the program into a compliance checklist. |
Question style
Strategic capstone submission scored against a public rubric
You will receive a fictional company brief: sector (for example EU-regulated fintech, US healthcare payer, or global manufacturer), size, footprint, regulatory obligations, current tooling, and known incidents. You produce a written CTEM program design that any competent security leader could implement. There are no trick constraints and no vendor requirements. The rubric rewards clarity, business alignment, and honesty about maturity. Programs designed to look impressive but that no team could actually run score lower than modest programs that ship value in 90 days.
Preparation path
The pillar for operating model and governance.
Grounds your current-state and target-state assessment.
Board-appropriate metric templates.
RACI, governance charter, roadmap, and board report templates.
Grading and retake policy
- Reviewed by a LearnCTEM CTEM Program Leader panel within 10 business days.
- Scored 0 to 4 on each of six rubric criteria. Weighted total of 3.0 or higher passes.
- Rubric is public and shipped inside the capstone brief. No surprises.
- Unlimited free revise and resubmit. Reviewers flag specific gaps.
- Certificate issued with a unique ID and public verification URL.
What the certificate proves
Every certificate carries a unique ID and a public verification URL at learnctem.com/verify.
Frequently asked questions
Who should take the CTEM Program Leader certification?
Security managers, CISOs, exposure management program owners, and senior consultants who design or mature CTEM programs. Practitioner-level knowledge is expected.
What is the format?
There is no multiple-choice exam. You submit a capstone: a full CTEM program design for a fictional company (industry, size, regulation). It covers scope, operating model, governance, toolchain, metrics, reporting, and a 90-day roadmap. It is scored against a public rubric.
How is the capstone graded?
Against a published rubric with six criteria: operating model, governance and cadence, toolchain architecture, metrics and board reporting, maturity and roadmap, and regulatory alignment. Each criterion is scored 0 to 4. A weighted total of 3.0 or higher passes.
Do you cover 2026 regulations?
Yes. The capstone requires you to show how the program aligns with DORA, NIS2, and the SEC Cybersecurity Disclosure Rule at a minimum, plus any industry-specific overlay in your fictional company brief.
How long does the capstone take?
Self-paced. Most candidates complete it in 15 to 25 hours of work spread across one to three weeks. Reviews are returned within 10 business days.
Can I revise and resubmit?
Yes. Reviewers return the rubric with specific gaps flagged. You may revise and resubmit as many times as needed. There is no cost.
