Training government since 1921

Cybersecurity training built around how your agency defends its systems and earns its authorizations

Taught by federal security practitioners and RMF assessors, and delivered your way: onsite, live online, or self-paced.

Graduate School USA instructors and federal staff working together

Trusted across the federal government

Since 1921
training the federal workforce
500,000+
government employees trained
125+
federal agencies served
200+
federally experienced instructors
400+
courses and certificates
All levels
across the federal cybersecurity curriculum
U.S. Department of AgricultureU.S. Department of the TreasuryU.S. Department of CommerceU.S. Department of EnergyU.S. Department of Veterans AffairsU.S. Department of DefenseU.S. Department of Homeland SecurityU.S. Department of Health and Human ServicesU.S. Department of JusticeU.S. Department of the InteriorU.S. Department of LaborU.S. Department of TransportationU.S. Office of Personnel ManagementU.S. General Services AdministrationU.S. Department of StateNASA

Agency seals reflect organizations Graduate School USA has trained. They do not imply endorsement by, or affiliation with, any federal agency.

Delivered your way

Every format draws on the same practitioner-built cybersecurity curriculum and instructors who have done the work. Choose what fits your headcount, timeline, and budget, or combine them.

A Graduate School USA instructor teaching a live online session

Live online

Send one or two people to scheduled classes such as NIST 800-53: Control Selection, Implementation, and Security Planning, live online or in Washington, DC

  • Ask questions and work real cases live
  • Cohort dates published for every program
  • One free retake within a year
A federal employee working through a self-paced Graduate School USA course

Self-paced eLearning

FedRAMP, CMMC 2.0, and NIST 800-53 courses your staff complete around on-call and audit schedules

  • No cohort to wait for
  • Same CEUs and credential at the end
  • Attend the live class free within a year
Federal staff working together in a training room

Onsite for your team

We bring NIST 800-53, zero trust, or incident response to your team, scoped to the systems they defend

  • Delivered on your schedule
  • Tailored to your policies and real cases
  • One agreement covers the cohort
A Graduate School USA advisor meeting one-on-one with an agency client

Private group training

Onsite delivery lets a security team work on its own material: the NIST SP 800-53 controls it is tailoring, the cloud package it is reviewing before authorization, the incident it handled last quarter. Sessions are shaped around the systems your agency has to get authorized and keep authorized.

  • Any course or certificate in our cybersecurity catalog, delivered onsite, live online, or blended
  • A new course built to your specification when nothing off-the-shelf fits
  • Scheduled around your calendar, for a cohort of any size
  • Rostering, progress, and completion reporting for the whole group

Open enrollment

When one analyst is sitting for the CISSP, or a single staff member has just inherited responsibility for a security plan, a scheduled public class is the practical option. Live sessions run through the year across the Risk Management Framework, cloud and FedRAMP, security operations, and AI security tracks.

  • A published schedule across the federal cybersecurity curriculum, entry to advanced
  • Live online, or in person at 1050 Connecticut Ave NW in Washington, DC
  • No minimum headcount and no setup: register and go
  • The same instructors and materials as our private cohorts
A Graduate School USA instructor leading a federal class

A cybersecurity curriculum mapped to federal frameworks

Thirty-seven courses across ten areas of federal security practice, from workforce awareness and the Risk Management Framework to FedRAMP, security operations, digital forensics, and AI security. Every course below runs both live and self-paced except the three marked self-paced only.

Zero trust and identity

Move from zero trust as a mandate to a staged implementation, built on phishing-resistant identity, credential, and access management.

Security operations and threat detection

Work inside a federal SOC: triage and monitoring, threat hunting and detection engineering, and the web applications attackers reach first.

Incident response and digital forensics

Run a federal incident response program end to end, investigate defensibly under NIST SP 800-86, and analyze the malware behind the incident.

Cyber governance, risk, and compliance

Run security and privacy as one program: quantify risk, manage the supply chain, and meet the mandates that reach your contractors.

Information protection, privacy, and records

Handle CUI, PII, and federal records correctly, and recognize the insider threat indicators that precede a loss.

Professional certification prep

Exam preparation across the eight CISSP domains, for staff pursuing the credential the rest of this catalog supports in daily practice.

Certificates and credentials, from one system to a whole security program

A three-level certificate ladder takes a practitioner from carrying one system through the Risk Management Framework to assessing systems independently and authorizing cloud services. Two credentials stack the RMF core with a specialization end to end. Seven focused certificates cover the tracks a team builds around instead: GRC, SOC and cyber defense, forensics and incident response, AI security, zero trust, and cloud. Each one has a live and a self-paced edition.

Level I

Federal RMF Practitioner Certificate Program

Everything it takes to carry a federal system through the Risk Management Framework, from categorization to an authorization to operate.

28 hours
View the certificate
Level II

Security Control Assessor Certificate Program

Grow into the independent assessor an authorizing official can lean on, from assessment plan through to a Security Assessment Report that holds up.

40 hours
View the certificate
Level III

Cloud & FedRAMP Authorization Certificate Program

Assess, authorize, and sustain secure federal cloud services, and stay ahead of FedRAMP's move to the 20x model.

48 hours
View the certificate
Credential

Federal Cybersecurity Authorization Professional: Security Control Assessor

The RMF core first, then the assessor specialization, in one continuous program for staff who will make the independent judgment an authorizing official leans on.

60 hours
View the certificate
Credential

Federal Cybersecurity Authorization Professional: Cloud & FedRAMP Authorization

The RMF core first, then the cloud specialization, for staff who will authorize and sustain secure federal cloud services end to end.

76 hours
View the certificate
Focus track

Cyber GRC Certificate Program

Risk assessment and quantification, cybersecurity supply chain risk management, security and privacy program management, and CMMC 2.0 readiness.

4 courses, 39 hours
View the certificate
Focus track

Cyber Defense & SOC Analyst Certificate Program

SOC foundations, then federal incident response, then threat hunting and detection engineering, in the order a federal SOC analyst grows into the work.

3 courses, 38 hours
View the certificate
Focus track

Digital Forensics & Incident Response Certificate Program

Federal incident response, then digital forensics and incident investigation, then malware analysis: respond, substantiate, then establish what actually happened.

3 courses, 36 hours
View the certificate
Focus track

Applied AI Security Certificate Program

An engineering path through AI security: securing AI/ML systems, monitoring and incident response, then red teaming and assurance.

3 courses, 32 hours
View the certificate
Focus track

Zero Trust & Modern Access Certificate Program

Identity and phishing-resistant MFA, zero trust architecture implementation, and the FedRAMP transition from Rev5 to 20x and CR26.

3 courses, 28.5 hours
View the certificate
Focus track

AI Security Foundations Certificate Program

Secure and govern AI inside a federal environment, from the threat landscape through to a working agency AI security and governance program.

20 hours
View the certificate
Focus track

Cloud Security Certificate Program

Federal cloud security in two steps: fundamentals and FedRAMP context first, then architecture and hardening taught against real recent cloud breaches.

2 courses, 16 hours
View the certificate

Vetted procurement, right from the GSA Schedule

Graduate School USA is a GSA Multiple Award Schedule contract holder, allowing federal agencies and other qualifying organizations to confidently purchase our services.

  • GSA MAS contract 47QRAA24D004K, SINs 611430 (professional training) and 541611 (management/administrative consulting)
  • Held as American Public Training LLC d/b/a Graduate School USA; UEI LA83MCFN1ST3; CAGE 99AA0
  • We work with your training office on the paperwork, whether a Schedule order, purchase order, or an SF-182.
Graduate School USA staff welcoming agency colleagues
A historical Graduate School USA faculty and leadership gathering, reflecting the institution's roots as the USDA Graduate School since 1921

An established federal training institution

Graduate School USA's federal cybersecurity curriculum is designed and taught in-house by practitioners who have defended federal systems and networks, not licensed from a generic library.

  • Founded 1921 as the USDA Graduate School; 500,000+ government employees trained across 125+ agencies
  • ACCET-accredited (ACCET is a U.S. Department of Education-recognized accreditor)
  • Center for Leadership and Management runs ECQ-aligned executive development, including the Executive Potential Program since 1995
  • 200+ federally experienced subject-matter experts across 400+ courses and certificates
  • Available on an active GSA MAS Schedule (SINs 611430 and 541611)

Questions agencies ask

The answers training officers and program directors ask for most, in one place.

How does my agency buy training from Graduate School USA?
Graduate School USA holds GSA Multiple Award Schedule contract 47QRAA24D004K (SINs 611430 and 541611), so you can place a pre-priced order directly under FAR Subpart 8.4 without running an open-market procurement. We accept the SF-182, Schedule orders, government purchase orders, and purchase cards for micro-purchases.
Can we pay with an SF-182?
Yes. We accept the SF-182, purchase orders, and GSA Schedule orders under contract 47QRAA24D004K, and our group training team works with your training office on the paperwork.
What is the difference between private group training and open enrollment?
Open enrollment classes are scheduled public sessions anyone can register for, taken live online or at our Washington, DC campus at 1050 Connecticut Ave NW. Private group training delivers a course for your agency's own cohort, tailored to your mission and delivered onsite, live online, or blended.
Can employees train self-paced, and still take the live class later?
Yes. Our self-paced online courses let a learner start anytime and work at their own pace, and when you buy the self-paced course the learner may also attend the live instructor-led course for free within one year.
Can courses be tailored to our agency?
Yes. We tailor existing courses to reflect your agency's mission, policies, and real cases, and we can develop new courses for unique requirements, all delivered under GSA contract 47QRAA24D004K.
Can training be delivered virtually or in person?
Both. Courses are offered as live virtual instruction or in-person onsite at your facility or at our Washington, DC location, and some programs blend live sessions with self-paced work.
What if an employee needs to repeat a class?
We offer one free retake of a class within one year, so a first attempt is never wasted if someone is reassigned, deployed, or needs a refresher before applying the material.
What's new in your federal cybersecurity training?
Our curriculum is refreshed to current federal law, policy, and practice; the catalog now runs to thirty-seven courses, ten certificates, and two stacked credentials, with new coverage of AI security, FedRAMP's move to 20x and CR26, and federal security operations; courses run in a modern learning portal, and self-paced courses add an always-available AI coach; and self-paced online options let a learner start anytime and still take the live class for free within a year.
Will this help our system owners actually earn and keep an ATO, or is it general security awareness?
Yes. RMF Foundations: From Risk to Authorization walks a system from categorization to authorization, and the two NIST 800-53 courses cover control selection, implementation, and security planning, then advanced assessment, tailoring, and enterprise program management. Security Control Assessor (SCA) Practitioner develops the independent assessment an authorizing official relies on, and FISMA and Continuous Monitoring Fundamentals covers keeping the authorization once you have it. The Federal RMF Practitioner certificate stacks that work into one program. Instructors include federal security practitioners and RMF assessors.
We buy cloud services rather than build them. Is there anything for the acquisition and oversight side?
Both FedRAMP for Agency Buyers courses are written for the buying side: the intermediate one covers the authorization process and cloud service selection, the advanced one covers package due diligence and cloud security program management. FedRAMP Modernization: Transitioning from Rev5 to 20x & CR26 covers what changes ahead of the January 1, 2027 deadline, and if your contractors fall under CMMC, Understanding CMMC 2.0 for Federal Contractors covers those requirements. Each runs live and self-paced, so contracting and program staff can start without waiting for a scheduled date.

Plan your agency's cybersecurity training

Tell us your topics, headcount, and timeline, and we'll propose the right mix for your team.

Group training team
onsite@graduateschool.edu
Main line: (888) 744-4723