Skip to main content
Career PathsOutcome → ISSO / RMF Analyst

Federal & Defense Path

Those targeting U.S. government and defense-contractor roles handling controlled information.

5 stepsHands-on labsCapstone + portfolioA named role

Save $297 vs. courses separately

By the end, you can

What this path makes you able to do.

  • Protect CUI and prepare for CMMC L1 & L2 against NIST 800-171
  • Run the NIST RMF end to end (SP 800-37)
  • Perform ISSO duties: SSPs, POA&Ms, continuous monitoring
A guided journey, not a pile of courses

The 5-step path.

  1. 1

    Cybersecurity Foundations

    The core concepts & landscape

    View course
  2. 2

    CMMC Level 1 & 2 Practitioner

    CUI & NIST 800-171

    View course
  3. 3

    ISSO Training

    The day-to-day ISSO role

    View course
  4. 4

    NIST RMF Implementation

    Categorize → authorize → monitor

    View course
  5. Capstone: RMF authorization package

    SSP, POA&M and authorization artifacts

Practice, not just reading

Hands-on lab work.

Every step above is backed by real practice in Atlas, our simulated workbench. You do the work an employer would hand you, and you keep the artifacts as portfolio evidence.

RMF / ISSO

RMF Authorization: Meridian

Step into the ISSO seat. Take Meridian through the full Risk Management Framework lifecycle and the continuous-monitoring grind: assess controls, gather evidence, work the POA&M, and keep the authorization honest.

CMMC Audit

CMMC Level 2 Assessment

Sit on the assessment team. Scope the enclave, review the SSP, assess all 110 requirements with Examine/Interview/Test, score MET / NOT MET with the SPRS score, and build the findings and limited POA&M, the way a C3PAO actually runs it.

Every path is backed by

Hands-on labs. A final exam & capstone. A real role.

You finish with a portfolio you can show, a cumulative exam, and the skills to land the ISSO / RMF Analyst role.

Not sure this is the one? Take the free fit and aptitude check first: twelve short questions, instant answer.