The certification proves you know it. We prove you can do it.

Employers screen on certifications the Association does not own. We teach the practice behind them, then examine whether you can actually do the work, and put our name on the answer.

Privacy, security, risk, compliance, third-party oversight and AI governance arrive on one desk now. We call that practice trust governance, and our purpose is to make it learnable, applicable and demonstrable, independently of any one employer, vendor or framework.

DTF-101Course3 ALCs+ 5 moreCredits30 ALCsEthicsCDTPCredential
PrivacySecurityRiskComplianceThird-partyAI governanceTrust & assurance

You passed the exam. Now do the work.

The certifications employers ask for test what you know. Few teach you how to put it into practice. The Association closes that gap: implementation guidance for the work those certifications describe.

THE EXAM · THE ROLEISO/IEC 27001 Lead Implementer
What the exam asks

Which clause requires the organisation to determine the scope of the ISMS?

What the role requires

Write a scope statement your auditor accepts, and defend every boundary in it.

You leave with: an ISMS scope statement, ready to adapt.

The work has changed faster than the profession around it.

Responsibilities converge long before job titles do.

A security leader inherits privacy obligations

Attached to systems they already run, arriving with a regulation rather than a design brief.

A privacy practitioner is pulled into AI governance

A new obligation with no settled practice, assigned to whoever sits closest to data.

A risk professional must read third-party assurance

Reports whose exclusions matter more than their conclusions, and nobody taught the difference.

An IT leader owns evidence, policy and audit readiness

Usually announced by a customer who will not sign the contract without it.

Capability that exists inside one organisation is bounded by what that organisation happens to need.

When the role changes, or the employer does, the professional standing does not travel with it. The Association exists to give this work a home of its own, not by collapsing these disciplines into one, but by establishing the common practice that makes them work together.

ONE EMPLOYER what the role needs possible, unbuilt

The gap every practitioner recognises.

Strategic certifications earn their place. They set a shared vocabulary and a recognised bar. What they rarely cover is how to implement what they describe.

01

The exam tests recall

Knowing the framework is necessary. It is not the same as knowing where to start on a Monday morning.

02

The role tests judgement

Employers need people who can scope, build, evidence and defend the work, in a startup and in an enterprise.

03

The evidence tests both

Auditors and customers ask to see the control working. A certificate on the wall does not answer that question.

Every pathway is paired with the practice behind it.

Opening in waves, beginning with the certifications most requested in hiring. Preparation lives on its own home; the practice lives here.

Visit Exam Pathways
PREPARE FORCISSP · CISM
PRACTISE WITH ADTPRunning a security programme leadership will fund
PREPARE FORCISA · CRISC
PRACTISE WITH ADTPTesting controls and building risk registers that drive decisions
PREPARE FORCIPP/E · CIPM
PRACTISE WITH ADTPOperating a privacy programme, from records of processing to DPIAs
PREPARE FORAIGP · ISO/IEC 42001
PRACTISE WITH ADTPGoverning AI systems from intake and inventory to impact assessment
PREPARE FORISO/IEC 27001
PRACTISE WITH ADTPBuilding an ISMS that holds up at certification audit
PREPARE FORCCSP · CCAK
PRACTISE WITH ADTPAssessing cloud and third-party assurance with evidence you can defend

Exam Pathways are independently authored by the Association and are not endorsed by the certification owners. They are never built from recalled or leaked exam content. Certification names are marks of their respective owners.

Trust governance is a practice.

Frameworks matter. Knowing what they say is a different skill from putting them into operation.

01

Decide

What the obligation actually requires here, at this size, in this business.

02

Translate

Into controls and operating practice that someone owns and runs on a cadence.

03

Evidence

Produce proof that it is working, in a form that survives being tested.

04

Defend

Explain the decision to someone whose job is to doubt it, and be right.

Seven strands. One professional practice.

PrivacySecurityRiskComplianceThird-party oversightAI governanceTrust & assurance

Learn. Apply. Prove.

What the Association does, and the order it does it in.

Learn

Courses organised around the responsibilities practitioners are asked to carry, written for both early-stage and enterprise realities.

Apply

Standards, templates, registers, playbooks and the Digital Trust Common Framework, so learning produces work you can use.

Prove

Verifiable completion and a visible record of professional development. Credentials require separate examination.

Belong

A definition of the work, a standard of practice, and a community that recognises what it involves.

Membership provides the professional home. Credentials must be earned.

Prepare for the certificate. Practise for the role.

External certifications have a place alongside the Association's own work. Each stage builds on the one before, and every stage ends in something you can use.

The ADTP Academy

Learn

Courses organised around the responsibilities practitioners carry, written for early-stage and enterprise realities.

Prepare

Exam Pathways: preparation for the strategic certifications employers name, kept on its own home.

Apply

Standards, templates, registers and the DTCF, so learning produces work you can use.

Prove

Designations earned by separate examination, verifiable by anyone.

DTFC badge CDTP badge CPTP badge CTTP badge CATP badge

Nothing is granted silently.

One ADTP Learning Credit is about an hour of assessed effort. Credits fill a credential map by domain. A credential always requires a separate examination, for every member, at every tier.

Explore ADTP credentials

Step 1

Take a course

A certificate with a verification ID and its credit value, issued on completion.

Step 2

Accumulate credits

Your credential map fills by competency domain, showing exactly what remains.

Step 3

Sit the examination

Meet the published eligibility, pass the examination, hold a publicly verifiable credential.

Recognition should mean something.

Four things that are routinely confused, kept deliberately separate.

Participation

Reading the framework, the glossary or the intelligence feed. Open to anyone.

Nothing required
Membership

Belonging to the Association and holding access to its curriculum and resources.

Join
Course certificate

A record that specific learning was completed, with a verification ID and credit value.

Complete the course
Professional credential

A demonstration of capability against published requirements, verifiable by anyone.

Pass the examination

You can tell them apart without reading them. The shape is the category.

Charter Practitioner membership plate, a shield
A shield is membershipBelonging to the Association, at any tier
Course certificate stamp, a hexagon
A hexagon is completed learningOne course finished, with its credit value
Professional credential medallion, a circle
A circle is an examined credentialEarned by assessment, and only by assessment

A common foundation for digital trust.

Explore the DTCF
ISO 27001 SOC 2 NIST CSF GDPR EU AI Act Digital Trust Common Framework Where they converge Where they differ What it means in practice

The Digital Trust Common Framework gives one control language across the standards and obligations practitioners meet in their work. It is published by the Association as an open professional resource.

The purpose is not another framework to memorise. It is to make it easier to see where established frameworks agree, where they part company, and what either fact means on a Tuesday afternoon.

Resources for the profession.

A good deal of it is free, and stays free. A common professional vocabulary should not depend on the ability to pay for it, and neither should finding out whether this work is for you.

All resources
Policy templates

Forty-five documents, written to be adopted rather than admired.

Policy and standard templates for your organization, mapped to the frameworks you are actually assessed against, with the gaps marked rather than papered over. Previews are open to everyone; the editable set comes with membership.

Open the library
DeepDive · free

One subject, worked through properly.

Written for the decision rather than the headline: what a finding actually means, and what you do about it on Monday. No account, no paywall, no email required to read it.

Read the latest
Flashcards · partly free

Spaced repetition across every certification we cover.

The first five cards of every domain are free on every pathway, so any exam can be tried without paying for it. Membership opens the full deck and the scheduling, which is the part that makes them work.

Pick a pathway
Templates and registers

Blank artefacts you can use on Monday.

Access reviews, vendor tiering, risk acceptances, evidence calendars. The same artefacts our courses ask you to produce, without the course.

Browse templates
DTCF · free

One objective, many frameworks, honest gaps.

The Digital Trust Control Framework maps a single control objective across SOC 2, ISO, NIST, PCI, HIPAA, GDPR and the AI Act, and says where they genuinely do not line up. Download the whole thing under CC BY 4.0.

Explore the DTCF
Practitioner intelligence

Current developments, read for their implications rather than their headlines.

Advisories and briefings written for risk decisions. Members set their own topics and severity thresholds.

Open the feed

Membership in the Association.

Open to people already carrying trust governance responsibilities, and to professionals deliberately moving toward them from security, privacy, audit, risk, legal, compliance, IT and operations. Membership begins with an open entry tier; Practitioner memberships broaden access to the curriculum and professional resources.

Explore membership
Founding period

Charter Practitioner

The Association is establishing its founding practitioner community. Those who join during this period may be invited to become Charter Practitioners, marking their membership during the founding. It is a membership designation, separate from the credentials earned by examination.

Read more
Organisations

Team membership

Seats, assignments and completion evidence for teams carrying these responsibilities together, including awareness training available only through an organisation.

For organisations
Verification

Anyone can check a credential

Every certificate and credential carries an ID that resolves to a public verification page. No need to ask the holder, and no need to ask us. A record nobody can check is worth what it costs to print.

Verify a credential

A profession should travel with you.

Employers change. Roles change. Technologies change. Frameworks change. Professional capability should remain yours.

Verify a certificate or credential