Cyber GRC Certificate Program
Four courses covering the whole governance, risk and compliance arc — assessing and quantifying cyber risk, managing it through the supply chain, running it as a program, and knowing where you stand against CMMC.
Four courses covering the whole governance, risk and compliance arc — assessing and quantifying cyber risk, managing it through the supply chain, running it as a program, and knowing where you stand against CMMC.
This certificate teaches you to turn technical findings into decisions leadership can act on. It runs the full governance, risk and compliance arc — defining accountability, assessing and prioritizing risk, choosing a response, recording it in a register, mapping it to controls, and reporting it upward — with the federal stack taught alongside its commercial and international parallels.
What sets it apart is depth in two places. Risk quantification goes past qualitative red, amber and green to the FAIR model and a materiality determination under SEC disclosure criteria, the question boards are asking now. Supply chain goes past naming SBOM to the artifacts you will actually be handed and asked to judge, and to the skill of checking whether a federal rule you are about to cite still applies. The path closes on program-level work and CMMC 2.0, so you finish knowing where an organization stands before an assessment rather than after.
Foundational cybersecurity knowledge. The program management course additionally assumes working familiarity with security and privacy fundamentals.
This is the recommended order, but some courses may be taken in a different order.
Unit 1 1 Day
A plain-language overview of CMMC 2.0 for federal contractors - what it is, who must comply, the maturity levels, and the rollout timeline you need to plan around.
Unit 2 12 Hours
An intermediate pass through cyber governance, risk and compliance, from governance and assessment through quantification, registers, controls, assurance, third-party risk, and board-level reporting.
Unit 3 12 Hours
Intermediate cybersecurity supply chain risk management on the NIST SP 800-161r1 structure, from criticality and supplier assessment through acquisition, controls, software supply chain and lifecycle monitoring.
Unit 4 12 Hours
An organization-wide course on running security and privacy as a single program: governance and accountability, strategy, risk, controls, assurance, monitoring, and leadership reporting.
Receive instruction from subject‑matter experts who bring proven government experience.
Courses that are regularly updated based on feedback and industry developments, ensuring versions are mapped to federal competencies.
The instructor was wonderful and so knowledgeable. The course materials were extremely relevant to what my job is. I feel like I can be better because of this class.
— 2025 student
Directly addressing the day-to-day challenges of federal employees.
Your trusted training partner, equipping public service professionals with the skills and knowledge to excel in their roles and drive meaningful impact.
Attend this certificate program live online or as self-paced training. Engage with expert instructors, ask questions, and get feedback on your exercises and projects.
Get the same interactivity and access to the instructor as in-person students. There are no extra fees and we’ll work with you to ensure your remote setup is perfect.
Learn at your own pace with pre-recorded video lessons and hands-on exercises. Work through the material on your schedule with access to course content and resources.
Upon completion of this course, you’ll receive an official certificate testifying to your mastery of the curriculum. We’ll send you a link where you can download your certificate, share it online with your friends, post it to your professional network on LinkedIn, and view all your earned certificates. Congratulations on your achievement!
Shareable on
We offer a single free retake of any module or the whole program within a year.
You can also access recordings of each session in your student portal within one business day of the session’s end. Recordings are available for one month after the session.
Since 1921, Graduate School USA has partnered with over 125 federal agencies and trained more than one million federal employees. Led by instructors with deep, real-world knowledge of federal regulations, policies, and practices, our private group programs are practical, mission-driven, and tailored to your agency’s objectives. We offer expertise across key federal domains—including human resources, financial management, acquisition and contracting, leadership, and more—to deliver training where and how your team needs it.
Complete this form and we’ll get back to you within 1 business hour.
Each installment is charged to your card on file one week before the start of the associated course. The payment schedule may vary if the courses are taken in a different order.
| Installments | List Price | |
|---|---|---|
| $299.90 | 10% non-refundable deposit | -- |
| $795.00 | Understanding CMMC 2.0 for Federal Contractors | $795 |
| $1,049.00 | Cyber Risk Management & GRC: From Risk to Assurance Course | $1,049 |
| $855.10 | Cybersecurity Supply Chain Risk Management (C-SCRM) Course | $1,049 |
| ▴ Your 10% deposit has been applied, as well as the certificate discount of $943 | ||
| Free | Security & Privacy Program Management: From Governance to Assurance Course | $1,049 |
| $2,999.00 | Total You Pay | |
See the Installment plan FAQ for more information.