Practical DevSecOps launches first hands-on MCP security certification
Practical DevSecOps on June 14 launched Certified MCP Security Expert, a new hands-on certification for security professionals who need to attack and defend Model Context Protocol infrastructure. The program arrives as MCP adoption and related security incidents rise across enterprise AI systems.
Why it matters: - Practical DevSecOps is targeting a fast-growing security gap around Model Context Protocol infrastructure, which now connects AI agents to tools, databases, APIs and production systems. - The new certification is meant for security teams that need hands-on skills for attacking, auditing and defending MCP deployments, not just shipping them. - The launch comes after more than 30 CVEs were filed against MCP servers, clients and tooling between January and February 2026. - The timing also follows a confirmed malicious MCP package that stayed undetected for two weeks in September 2025 while exfiltrating email data, and an NSA advisory on MCP security design considerations in May 2026.
What happened: - Practical DevSecOps launched Certified MCP Security Expert (CMCPSE) on June 14, 2026. - The company described CMCPSE as the first dedicated hands-on MCP security certification built for security professionals attacking and defending MCP infrastructure. - CMCPSE is the 10th certification in the Practical DevSecOps portfolio and extends the company’s AI security training track into MCP threat management. - The certification becomes available June 15, 2026, at $599. - The course is self-paced and available with on-demand access.
The details: - The program is built for security engineers, AppSec leads, red teamers and platform engineers deploying or evaluating AI agent infrastructure. - The curriculum covers MCP threat modeling and attack surface analysis, OWASP MCP Top 10, tool poisoning detection, prompt injection defense, OAuth 2.1 authentication and authorization patterns, gateway architecture and sandboxing, supply chain security, secure server build practices and adversarial labs. - Practical DevSecOps says the certification includes 60 days of lab access, 30-plus hands-on exercises and a 6-hour practical exam. - All labs run in-browser against live MCP server environments, with no local setup required. - MCP was introduced by Anthropic in late 2024 and later adopted by OpenAI, Google, Microsoft and Block. - Existing AI governance frameworks such as NIST AI RMF and ISO/IEC 42001 do not yet cover MCP-specific threats in detail.
Between the lines: - Developer-focused MCP courses already exist, but the launch positions CMCPSE as a security-first alternative focused on break-fix skills rather than implementation speed. - Practical DevSecOps is betting that MCP will become a standard enterprise attack surface, and that security teams will need specialized credentials to keep up. - The certification also signals that traditional signature-based detection is not enough for semantic-layer threats like prompt injection and tool poisoning.
What's next: - Learners can enroll now and start on their own schedule. - The certification rollout could give Practical DevSecOps a foothold in the emerging MCP security training market as enterprise adoption expands. - More organizations may look for MCP-specific guidance as tooling, standards and formal security practices continue to catch up with deployment.
The bottom line: - Practical DevSecOps is turning MCP security into a formal hands-on credential at a moment when enterprise AI systems are adopting the protocol faster than security training and governance frameworks are adapting.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Smart's Business Wire
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.