Learn RMF by doing the actual job
An 8-week live cohort that takes you through all seven steps of the Risk Management Framework (RMF).
You'll leave ready to interview for ISSO, Security Control Assessor, and RMF Analyst roles at federal agencies and the contractors that support them.
Next cohort runs August 8 through September 26.
What is the RMF?
The Risk Management Framework (RMF) is how the federal government decides whether a system is secure enough to be used.
Every federal and DoD system runs through its seven steps before it can go live, and the monitoring never stops for as long as the system is online. It's written into federal law, which is why the work never dries up.
This program trains you for the roles that keep it running: ISSO, Security Control Assessor, RMF analyst.
What you'll learn:
Every RMF job posting wants experience. This is where you get it.
You'll take one system through the full framework and finish holding the package to prove it: a categorized system, tailored 800-53 controls, STIG checks you ran yourself, documented assessment findings, a POA&M you built from them, and an authorization package an Authorizing official could act on. You'll also see how eMASS works, the system DoD uses to manage all of it, so nothing is unfamiliar on day one.
What you'll gain:
Nobody gets hired for knowing what RMF stands for. They get hired for walking a hiring manager through a system they categorized, controls they selected, findings they assessed, and a POA&M they wrote.
That's what you leave with, plus the interview answers to back it up, and a real shot at ISSO, Security Control Assessor, RMF analyst, and GRC roles across federal agencies, DoD, and the contractors that support them.
Your instructor
I'm Ade, a Federal Cybersecurity Engineer and Air Force reservist. I broke into RMF the same way you're about to: no federal cyber background at the start, a bootcamp, and real reps. Along the way I earned my CISSP, CompTIA Security+, and AWS certifications. Today I do the same RMF work I teach, and I built this program to be the one I wish I'd had, focused on the work that gets you hired, not slides. You might know me as cyberwithade.
How it works
Live on Zoom every Saturday, 10 AM to 12 PM CST. Every session is recorded and posted inside the course, so if you miss a Saturday you catch the replay.
Between sessions you get the private student community for questions, and you keep every template and artifact you build.
The Curriculum
What you'll do
We don't do theory for eight weeks. You take one system, the Unit Readiness Tracker, from nothing to authorized, doing the same work an RMF practitioner does on the job.
-
01Week 1
RMF foundations
Learn how federal authorization works under NIST SP 800-37, and get introduced to the system you'll carry all the way through.
-
02Week 2
Categorize the system
Set impact levels, define the boundary, and document what the system actually does.
-
03Week 3
Select security controls
Tailor the NIST SP 800-53 baseline to your system instead of copying it wholesale.
-
04Week 4
Implement and document
Hands-on with STIGs and the DISA STIG Viewer, writing implementation statements that hold up.
-
05Week 5
Assess controls
Gather evidence, test against the assessment procedures, and write findings the way an assessor would.
-
06Week 6
POA&Ms and communicating risk
Turn open findings into a defensible plan, and learn to brief risk to people who don't speak in control numbers.
-
07Week 7
Build the authorization package
Assemble the full package that earns the ATO, the single deliverable your next employer wants to see.
-
08Week 8
Continuous monitoring
Keep the authorization alive after the ATO, then turn all of this into interviews.
One week mid-program is delivered async with recorded lessons, so the pace never breaks.
Enrollment
One price. Everything included.
- All 8 live sessions
- Replays of every session
- Every template and document you build
- Access to the student community
- ADELV Academy certificate of completion
The price is the price. No upsells waiting on the other side.
Frequently Asked Questions
-
No. This is built for people breaking in.
-
Not to take this program. For the jobs, most cleared roles require citizenship, and public trust roles vary by agency, some are open to permanent residents. If you're a green card holder, week 8 covers how to find the openings that fit.
-
Not for this program, and not for every RMF job. Public trust roles exist, and many employers sponsor clearances. We cover how to target both in week 8.
-
It depends on your location and experience. Entry-level RMF roles generally post in the $70,000 to $95,000 range, and roles near DC run higher. The six-figure averages you'll see online reflect people with years in the field, not a first job. Search ISSO and Security Control Assessor on the job boards and look at what's actually posted in your area. That's the real number.
-
Replays are posted inside the course after every session.
-
No. We'll cover which ones actually matter and when.
-
Yes. You finish with an ADELV Academy certificate of completion for your LinkedIn, backed by real work product you can walk through in interviews. It's a completion certificate, not an industry certification like Security+, and inside the program we cover which of those are worth pursuing and when.
-
Nobody can promise you a job, and you should be skeptical of anyone who does. You'll finish with real work product and the ability to walk an interviewer through the full RMF process like someone who's done it.
-
Yes, Affirm and Klarna offer payment plan options at checkout.
-
Seats are limited, so enrollment is final once the cohort starts. If something comes up before the first session, email me.
The cohort starts Saturday, August 8. Seats are limited so every student gets attention.
Not ready to enroll?
Start with the free RMF Career Roadmap.
The path from where you are to your first RMF role: the certs that matter, the process
you'll be hired to help run, and the steps in order. Free, straight to your inbox.