1337

Do you need a certification to tell you how to threat model?

No (with caveats). Here's my review of the courses claiming to teach threat modelling.

Caveat 1 - If you have been pentesting for 5+ years and have never "written" a threat model, you dont need to spend money on a certification to tell you how to threat model - you have been mentally threat modelling before each and every pentest you complete.

I thought there would be more caveats, but thats my main point. Any penetration tester should be able to look at a solution and point out flaws in the design, a threat model is taking the next step and writing down why you pointed out said flaws. Now there is a magic to actually making this process of pointing out flaws useful to the business and the ever beholden shareholders, but a course will not teach you this. Businesses are complex machines and there is no one size fits all for threat modelling.

Unless your manager tells you to do a threat modelling certification, in which case you should tell them that it will be useless, dont bother not be spending time on a threat modelling certification. Read docs on DFDs, STRIDE/PASTA and starting asking yourself in what way can you present the risks that you have pointed out.