Cybersecurity training built around how your agency defends its systems and earns its authorizations
Taught by federal security practitioners and RMF assessors, and delivered your way: onsite, live online, or self-paced.

Trusted across the federal government
















Agency seals reflect organizations Graduate School USA has trained. They do not imply endorsement by, or affiliation with, any federal agency.
Delivered your way
Every format draws on the same practitioner-built cybersecurity curriculum and instructors who have done the work. Choose what fits your headcount, timeline, and budget, or combine them.

Live online
Send one or two people to scheduled classes such as NIST 800-53: Control Selection, Implementation, and Security Planning, live online or in Washington, DC
- Ask questions and work real cases live
- Cohort dates published for every program
- One free retake within a year

Self-paced eLearning
FedRAMP, CMMC 2.0, and NIST 800-53 courses your staff complete around on-call and audit schedules
- No cohort to wait for
- Same CEUs and credential at the end
- Attend the live class free within a year

Onsite for your team
We bring NIST 800-53, zero trust, or incident response to your team, scoped to the systems they defend
- Delivered on your schedule
- Tailored to your policies and real cases
- One agreement covers the cohort

Private group training
Onsite delivery lets a security team work on its own material: the NIST SP 800-53 controls it is tailoring, the cloud package it is reviewing before authorization, the incident it handled last quarter. Sessions are shaped around the systems your agency has to get authorized and keep authorized.
- Any course or certificate in our cybersecurity catalog, delivered onsite, live online, or blended
- A new course built to your specification when nothing off-the-shelf fits
- Scheduled around your calendar, for a cohort of any size
- Rostering, progress, and completion reporting for the whole group
Open enrollment
When one analyst is sitting for the CISSP, or a single staff member has just inherited responsibility for a security plan, a scheduled public class is the practical option. Live sessions run through the year across the Risk Management Framework, cloud and FedRAMP, security operations, and AI security tracks.
- A published schedule across the federal cybersecurity curriculum, entry to advanced
- Live online, or in person at 1050 Connecticut Ave NW in Washington, DC
- No minimum headcount and no setup: register and go
- The same instructors and materials as our private cohorts

A cybersecurity curriculum mapped to federal frameworks
Thirty-seven courses across ten areas of federal security practice, from workforce awareness and the Risk Management Framework to FedRAMP, security operations, digital forensics, and AI security. Every course below runs both live and self-paced except the three marked self-paced only.
Risk Management Framework and system authorization
Cloud security and FedRAMP
Zero trust and identity
Security operations and threat detection
Incident response and digital forensics
Cyber governance, risk, and compliance
AI security and governance
Information protection, privacy, and records
Workforce security awareness
Professional certification prep
Certificates and credentials, from one system to a whole security program
A three-level certificate ladder takes a practitioner from carrying one system through the Risk Management Framework to assessing systems independently and authorizing cloud services. Two credentials stack the RMF core with a specialization end to end. Seven focused certificates cover the tracks a team builds around instead: GRC, SOC and cyber defense, forensics and incident response, AI security, zero trust, and cloud. Each one has a live and a self-paced edition.
Federal RMF Practitioner Certificate Program
Everything it takes to carry a federal system through the Risk Management Framework, from categorization to an authorization to operate.
View the certificateSecurity Control Assessor Certificate Program
Grow into the independent assessor an authorizing official can lean on, from assessment plan through to a Security Assessment Report that holds up.
View the certificateCloud & FedRAMP Authorization Certificate Program
Assess, authorize, and sustain secure federal cloud services, and stay ahead of FedRAMP's move to the 20x model.
View the certificateFederal Cybersecurity Authorization Professional: Security Control Assessor
The RMF core first, then the assessor specialization, in one continuous program for staff who will make the independent judgment an authorizing official leans on.
View the certificateFederal Cybersecurity Authorization Professional: Cloud & FedRAMP Authorization
The RMF core first, then the cloud specialization, for staff who will authorize and sustain secure federal cloud services end to end.
View the certificateCyber GRC Certificate Program
Risk assessment and quantification, cybersecurity supply chain risk management, security and privacy program management, and CMMC 2.0 readiness.
View the certificateCyber Defense & SOC Analyst Certificate Program
SOC foundations, then federal incident response, then threat hunting and detection engineering, in the order a federal SOC analyst grows into the work.
View the certificateDigital Forensics & Incident Response Certificate Program
Federal incident response, then digital forensics and incident investigation, then malware analysis: respond, substantiate, then establish what actually happened.
View the certificateApplied AI Security Certificate Program
An engineering path through AI security: securing AI/ML systems, monitoring and incident response, then red teaming and assurance.
View the certificateZero Trust & Modern Access Certificate Program
Identity and phishing-resistant MFA, zero trust architecture implementation, and the FedRAMP transition from Rev5 to 20x and CR26.
View the certificateAI Security Foundations Certificate Program
Secure and govern AI inside a federal environment, from the threat landscape through to a working agency AI security and governance program.
View the certificateCloud Security Certificate Program
Federal cloud security in two steps: fundamentals and FedRAMP context first, then architecture and hardening taught against real recent cloud breaches.
View the certificateVetted procurement, right from the GSA Schedule
Graduate School USA is a GSA Multiple Award Schedule contract holder, allowing federal agencies and other qualifying organizations to confidently purchase our services.
- GSA MAS contract 47QRAA24D004K, SINs 611430 (professional training) and 541611 (management/administrative consulting)
- Held as American Public Training LLC d/b/a Graduate School USA; UEI LA83MCFN1ST3; CAGE 99AA0
- We work with your training office on the paperwork, whether a Schedule order, purchase order, or an SF-182.


An established federal training institution
Graduate School USA's federal cybersecurity curriculum is designed and taught in-house by practitioners who have defended federal systems and networks, not licensed from a generic library.
- Founded 1921 as the USDA Graduate School; 500,000+ government employees trained across 125+ agencies
- ACCET-accredited (ACCET is a U.S. Department of Education-recognized accreditor)
- Center for Leadership and Management runs ECQ-aligned executive development, including the Executive Potential Program since 1995
- 200+ federally experienced subject-matter experts across 400+ courses and certificates
- Available on an active GSA MAS Schedule (SINs 611430 and 541611)
Questions agencies ask
The answers training officers and program directors ask for most, in one place.
How does my agency buy training from Graduate School USA?
Can we pay with an SF-182?
What is the difference between private group training and open enrollment?
Can employees train self-paced, and still take the live class later?
Can courses be tailored to our agency?
Can training be delivered virtually or in person?
What if an employee needs to repeat a class?
What's new in your federal cybersecurity training?
Will this help our system owners actually earn and keep an ATO, or is it general security awareness?
We buy cloud services rather than build them. Is there anything for the acquisition and oversight side?
Plan your agency's cybersecurity training
Tell us your topics, headcount, and timeline, and we'll propose the right mix for your team.