Anyone can download TTR-2026 and work through it. A TTR Certified Auditor is someone whose application of it has been examined and recorded - a named individual with a registry ID, permitted to sign an assessment that can be entered in the public register.
Certification is a credential for the individual, not for their employer. It travels with you.
You already sell technical due diligence or engineering assessments. Certification replaces “trust my judgement” with a published methodology and a registry ID a client can look up.
You are a CTO or VP Engineering who wants to run the assessment in-house and have the result stand up in a board pack or a data room rather than read as self-marking.
Your firm is applying for Authorized Partner status, which requires at least two certified auditors on staff. You are one of them.
Self-paced, roughly 20 hours of material. Every module closes with a graded exercise on a real anonymized case. You sit the exam when the five exercises are passed.
The four qualification criteria, the diagnostic questions, and the decision tree behind Enterprise, Rescue, Growth and Launch. Where profile assignment goes wrong and what it does to the score.
What each Control Point is actually testing, what compliance looks like in practice, and the Readiness Blocker protocol - the points that act as a binary veto and force Level F regardless of the rest.
Evidence types per Control Point, the verification method for each, how to run the interviews, and how to record a finding so a reviewer can follow it without you in the room.
Domain scoring, weighting by profile, the global score, the A-F mapping, and the 29 Business Impact Indicators with their formulas and their input assumptions.
The four mandatory report components, the remediation roadmap, and the conduct rules: conflict of interest, scope pressure from the client, and what to do when a sponsor asks you to move a score.
The written part checks that you know the standard. The practical part checks that you can apply it to a case that does not fit neatly - which is every real case.
Sixty questions across the nine domains, the scoring logic, profile selection and the Readiness Blocker protocol. Closed book on the scoring rules, open book on the Control Point catalogue.
You receive an anonymized evidence pack from a real assessment - repository metrics, pipeline configuration, incident history, interview notes, gaps and all. You return a scored assessment and a full report.
A missed Readiness Blocker is an automatic fail on Part B. A blocker is a binary veto in the methodology. An auditor who scores around one has not misjudged a detail - they have produced a materially wrong Level, and the register cannot carry that.
Renewal requires either two assessments registered in the period, or a short recertification exercise covering the changes since your last cycle. The standard moves; a credential that never revalidates stops meaning anything.
Certification lapses if neither condition is met. Lapsed entries stay visible in the register marked rather than being deleted.
Covers the five training modules, both exam parts, one retake, the 24-month term and your Audit Studio seat. Renewal is $300 per year after that.
Apply for the next cohort →Tell us what you have audited and we will tell you whether the exam is worth your time. That conversation takes 20 minutes and costs nothing.