GSCP overview
Find out exactly what the GSCP credential tests, how a sitting gets scored, and what to do before you book one.
The GenAI Security Certified Professional (GSCP) is GenAI Security Lab's flagship credential. It proves you can find a real flaw in a live AI application, exploit it, and explain the fix — not that you can recognize the right answer in a list.
What GSCP proves
GSCP is a practical exam. There's no multiple choice anywhere in it.
Every objective is graded on the evidence you capture against a live target, exactly like a lab. Picture the VIP-coupon objective from the ShopBot lab: you're handed a goal, not a script, and you prove you met it with a real extracted value, not a description of your approach.
The exam adds one thing training labs don't ask for. For every objective you land, you write up the impact, the root cause, and the remediation — the same shape as a report you'd hand a client. That write-up is graded against a rubric, not skimmed for keywords.
A private exam bankYour live targets come from a bank you won't have trained on. Every target is seeded uniquely for your sitting.
Exam shape
GSCP is remotely proctored and time-boxed. A proctor verifies your identity at the start and supervises the session until you submit or the clock runs out.
Inside that window, you work a set of objective-based tasks against live targets — the same format as the labs, under exam conditions. Your set is randomized and locked in the moment you begin: no regenerating it, and no hints if you get stuck.
See Sitting the exam for the full mechanics of booking, proctoring, and submitting.
How it's scored
Each objective is graded the same way as any lab — your evidence is checked against the target and scored. GSCP then rolls every objective's result into one overall proficiency rating for your sitting — a different scale from the labs' three bands.
| Rating | What it means |
|---|---|
| Insufficient | Well short of the bar — most objectives unmet. |
| Developing | Real progress, but not yet consistent across categories. |
| Job-ready | Clears the passing threshold with solid coverage. |
| Strong | Consistently high performance across almost every category. |
Passing takes two things at once. Your overall score has to clear the passing threshold shown before you start, and every required category has to be solved outright — a high score elsewhere doesn't cover for a required category you skipped.
Prepare before you book
Book once you can already land exploits unaided, not before. GSCP has no hints and no walkthroughs, so exam day is the wrong place to learn the format for the first time.
- Work the lab catalogue until the OWASP LLM Top 10 categories feel routine.
- Reach Advanced or Expert on the difficulty ladder — GSCP is scoped to the same OWASP LLM, MCP, and agentic categories your labs already cover.
- Run a lab end to end, evidence and all, so exam-day mechanics aren't new to you.
After you pass
A credential is issued the moment you pass, carrying its own serial number. Your certificate is ready to view immediately from your certifications area.
That serial resolves to a public page anyone can check, no account or login required. See Verifying a credential for what it shows and how to share it.
Evidence, not a line on a resume.