This certificate traces the modern access problem from the credential through to the authorization boundary. It opens at the identity layer and runs the chain in order — identity, proofing, authentication and MFA, authorization, federation, and the access decision itself — weighted toward multifactor authentication, since most federal compromises begin with a credential rather than an exploit. Multifactor is pulled apart rather than treated as a checkbox: authenticator types separated, assurance levels explained, and the attacks aimed directly at MFA covered in detail, so participants can articulate why a push notification and a PIV card are not equivalent controls.
The path then turns architectural, and finally operational. Zero trust moves from principle to plan through a current-state maturity assessment using the CISA Zero Trust Maturity Model, then the pillars in sequence — identity and access modernization, device, network and workload trust enforcement, and application, data and policy enforcement — followed by the visibility, analytics and automation that make zero trust operational, and a staged implementation roadmap carrying governance and metrics. It closes on federal cloud authorization and how it is changing, working through the transition from FedRAMP Rev5 to the 20x model and CR26, so the access architecture is understood together with the authorization regime it has to satisfy.