We compared 3 threat modeling trainings & certifications to find out what’s the best threat modeling. Threat modeling moved from a nice-to-have to a hiring requirement. 94% of organizations now expect security-by-design practices in their SDLC, and most security teams have never been formally trained to run the sessions. That gap is why threat modeling credentials carry a real salary premium in 2026.
Three names come up most when people search for training: the Certified Threat Modeling Professional (CTMP) from Practical DevSecOps, the free IriusRisk Academy, and the instructor-led courses from Shostack + Associates. They solve different problems. Here’s how they compare and which one fits your goals.
3 Threat Modeling Certifications Compared
| Course Providers | Certified Threat Modeling Professional (CTMP) course – Practical DevSecOps | IriusRisk | Shostack |
| Price | $899 | Free | $4,400+ |
| Format | Self-paced, 40+ labs | Self-paced, short courses | 2-day in-person |
| Exam | 6-hour practical | None | None |
| Credential | Lifetime cert | Digital badge | None |
| Vendor-neutral | Yes | No (tool-tied) | Yes |
Certified Threat Modeling Professional (CTMP)
The CTMP from Practical DevSecOps is what experienced security professionals pick when they want a credential that proves they can do the work, not just talk about it.
It’s vendor-neutral, self-paced, and built around 40+ browser-based labs. You learn STRIDE, PASTA, VAST, RTMP, LINDDUN, and attack trees, then apply them to cloud-native systems, AI/ML pipelines, and CI/CD workflows. The course also teaches threat-modeling-as-code, which is the part most hiring managers ask about.
Price is $899. You get 3 years of video access, 60 days of lab time, 24 CPE points, and 24/7 instructor support. The credential is lifetime.
The exam sets it apart. You solve 5 real challenges in a 6-hour practical window, then submit a report within 24 hours. No multiple-choice. You either can threat model or you can’t, and the certificate says which.
That rigor is why the Certified Threat Modeling Professional (CTMP) course pays off. Roles asking for documented threat modeling skills tend to pay 15% to 20% more than equivalent AppSec positions, and Practical DevSecOps reports certified threat modelers earning $140,000 to $180,000 against a market baseline near $90,000. The skill stays niche, so supply stays tight.
Practical DevSecOps is a cybersecurity training and certifications company specializing in hands-on DevSecOps, AI security, and Application Security. It has trained over 12,500+ security professionals and is trusted by organizations including Roche, Accenture, IBM, PWC, and Booz Allen Hamilton.
Best for: security engineers, architects, and DevSecOps practitioners who want a hands-on, resume-grade certification.
IriusRisk Academy
IriusRisk Academy is free. You pick from short courses running 35 minutes to 4 hours, covering threat modeling fundamentals, AI/ML systems, embedded devices, and secure-by-design principles. Each one gives you a digital badge and a certificate you can post on LinkedIn.
The catch is scope. Most of the catalog teaches you how to use the IriusRisk platform, so the training is tied to one vendor’s tool. Levels run beginner to advanced, but there’s no proctored exam and no independent credential. It builds knowledge without validating skill through an exam.
Best for: beginners testing the water, or teams already running IriusRisk who want product fluency at zero cost.
Shostack + Associates
Adam Shostack wrote the book on threat modeling and created the Four Question Framework, so the pedigree here is hard to beat. The courses are principles-based, taught live by industry practitioners, and aimed at teams that want deep, facilitated learning.
The trade-off is cost and format. The Threat Modeling AI Systems course runs $4,400 per seat, lasts 2 days, and is in-person only (recently in Washington D.C.). There’s no certification exam at the end. You leave with skills and a sharper way of thinking, but no badge to verify them.
Best for: Enterprise teams with a budget who want expert-led, in-room instruction and don’t need a portable credential.
Which one should you pick?
If you want a credential that gets you hired or promoted, get the Certified Threat Modeling Professional (CTMP) course. It’s the only one of the three with a hands-on exam and a portable, lifetime certification, and it costs a fraction of Shostack’s fee.
Use IriusRisk Academy as a free warm-up, or if your team already runs that tool. Book Shostack when you have a budget for premium in-person coaching and don’t need a certificate at the end.
Conclusion
Threat modeling skills are scarce, and the pay reflects it. All three teach the fundamentals well, but only one gives you proof you can perform under exam conditions. For most working security professionals in 2026, the Certified Threat Modeling Professional (CTMP) course is the sharpest return on time and money. IriusRisk covers the free entry point, and Shostack covers high-touch enterprise training.
Pick based on what you actually need: a credential, free knowledge, or in-room expertise.
FAQs
Yes, if you work in AppSec, DevSecOps, or security architecture. 94% of organizations now require security-by-design, and few professionals are formally trained. A credential like the CTMP separates you in hiring and can lift pay by 15 to 20%.
The CTMP is a paid, vendor-neutral certification with a 6-hour practical exam and a lifetime credential. IriusRisk Academy is free, tied to the IriusRisk tool, and awards a badge with no proctored exam. The Certified Threat Modeling Professional (CTMP) validates skill. IriusRisk builds product knowledge.
The CTMP is $899. It’s self-paced with 3 years of video access and 60 days of lab time, so you can finish in a few weeks or spread it out. Most learners complete it inside 60 days.
No. You need basic security fundamentals: confidentiality, integrity, and availability. Application development knowledge helps but isn’t required.
Start with STRIDE, then PASTA and LINDDUN. STRIDE is the most widely used in software development. The CTMP covers all three, plus VAST, RTMP, and attack trees, in one program.




