Third Party Risk Association's
Third Party Cyber Risk Assessor (TPCRA) Certification
The TPCRA Certification is a specialized qualification that validates expertise in assessing third-party cybersecurity controls, managing cyber risk assessments, and evidencing proficiency in cybersecurity assessment techniques, as well as establishing credibility for third-party risk management professionals.

What is the TPCRA?
The TPCRA Certification is a specialized qualification designation which will:
-
Confirm your understanding & skill in the assessment of third party cyber security controls and processes.
-
Validate your competency in the creation, execution, & management of third party cyber risk assessments.
-
Authenticate & add credibility to your expertise as a third party cyber risk assessor.
Evidence your proficiency with various cyber security & information technology assessment terms & techniques.
Who is the TPCRA for?
The TPCRA is the standard of achievement for those who assess, monitor, and review third party cyber security and information technology controls, as well as identify and mitigate risk related to said controls. Such roles may include, but not be limited to:
-
Third Party Risk Management Practitioners
-
Procurement Specialist
-
Vendor Managers
-
Auditors
-
Information Security Professionals
-
Privacy or Compliance Specialists
-
Legal Professionals


"The TPCRA Certification is foundational to achieving success as a third party risk management professional."
Domains
Building Core Competencies for Lasting Professional Excellence
Cybersecurity & Third Party Risk Management Basics
Pre-Contract Due Diligence
Continuous Monitoring
Physical Validation
Disengagement Due Diligence
Cloud Due Diligence
Reporting & Analytics
Practitioner Ethics
Examination Overview
Examination Outline
The examination is a 150-question, multiple-choice assessment. Questions will include a variety of formats, such as scenario-based, true or false, and choose the best response.
-
The time limit is 3 hours for the examination process, broken out into the following:
-
5 minutes to read and sign the NDA
-
10 minutes to complete the optional tutorial
-
160 minutes to complete the examination
-
5 minutes to complete the post-exam survey
-
The examination is a closed-book assessment that will be monitored via an assigned proctor.
Passing Score
You must receive a score of 80% or higher to pass the TPCRA examination.
Exam Scheduling
-
The examination will be taken in person at a Pearson VUE testing facility.
-
Examinations may be scheduled at a day/time that suits you via a Pearson VUE location.
-
Pearson VUE offers over 5,000 test facilities worldwide and is ADA-compliant.
Training Schedule
DATE | TIME | LOCATION | INSTRUCTOR | REGISTER |
|---|---|---|---|---|
February 9 - 12, 2026 | 5 PM - 8 PM CT | Zoom | Greg Rasner | Author of "Cybersecurity & Third-Party Risk", SVP of Cyber Third Party Risk at Truist, Educator, and Frequent Keynote Speaker | View Training Options |
May 14 - 15, 2026 | 9 AM - 4 PM CT | Zoom | Greg Rasner | Author of "Cybersecurity & Third-Party Risk", SVP of Cyber Third Party Risk at Truist, Educator, and Frequent Keynote Speaker | View Training Options |