Free cybersecurity certificates, signed to last
You can now earn a free certificate on CyberLearner. Finish 90% of the labs in a discipline and you get a Certificate of Completion with your name on it, the number of labs you solved, and the skills they cover. You can add it to LinkedIn in one click, print it as a PDF, or send the link to an employer.
I wanted these certificates to mean something. Plenty of online certificates are a nice PDF that anyone can make in five minutes. So I built ours the way security people would want it: signed, checkable by anyone, and very hard to fake.
What you can earn
There is one certificate per discipline, and a bigger one for doing three of them:
- Binary Exploitation (22 labs): memory, buffer overflows, format strings, ROP chains.
- Reverse Engineering (27 labs): disassembly, anti-debugging, unpacking, custom VMs.
- Cryptography (17 labs): RSA attacks, lattices, LWE and NTRU, MAC forgery.
- Forensics (20 labs): disk, memory and network forensics, log analysis.
- CyberLearner Practitioner: earn three of the certificates above.
The bar is 90% of a discipline's labs. That is the same as the Gold badge, so one stubborn lab will not block you, but you cannot get there by skimming either. New disciplines get their own certificate automatically once they have eight or more labs.
Already solved a lot of labs?
Then you may have earned one already. Certificates count every lab you have solved so far, not only new ones. Open your profile, look at the Certificates section, and press Claim. The first time, you type your real name as it appears on your CV. It is then locked, so a certificate cannot be passed to someone else.
Why "post-quantum signed" matters
When you claim a certificate, our server signs its contents twice. Once with Ed25519, a modern signature used across the internet today, and once with ML-DSA-65, the post-quantum signature standard that NIST published in 2024 as FIPS 204. Post-quantum means it is designed to stay secure even against a large quantum computer, which could one day break most signatures in use now.
A certificate is only valid when both signatures check out. Change one letter of the name or one number of the score, and both break. The signing keys never sit in the website's database, so even someone with access to the database cannot mint a certificate that passes.
Anyone can check it
Every certificate has its own page, for example cyberlearner.org/verify/CL-XXXX-XXXX-XXXX.
When an employer opens it, three checks run in front of them:
- our server checks the Ed25519 signature;
- our server checks the ML-DSA-65 signature;
- their own browser checks both again, with separate open-source code, so they do not have to trust our server.
You can also download the signed file and check it offline against our published keys. If a certificate is ever revoked, its page says so in red.
One honest limit: no online certificate can prove who was sitting at the keyboard. What we can promise is that a CyberLearner certificate cannot be forged, edited or bought, and that every lab on it was solved with a flag made only for that student, so answers cannot be copied between accounts.
Share your badges too
Not there yet? You can still show your progress. Switch on Share your badges on your profile and you get a public page with the badges and certificates you hold now, ready for LinkedIn or X. It updates as you earn more, never shows your email, and switching it off kills the link.
CyberLearner.org is a free cybersecurity training platform, built on the curriculum of the International Cybersecurity Olympiad (ICO). Every lab is hands-on and runs in your browser. It is open to everyone, regardless of skill level.