The Cybersecurity Trade Project
An open-source, vendor-neutral framework to restructure cybersecurity into a recognized skilled trade through paid apprenticeships, standardized wage floors, progressive rotations, professional licensure, guild protections, and underwriter-driven accountability.
The Core Thesis
Cybersecurity is an applied engineering and operational trade, not an academic abstraction. Critical digital infrastructure, connected medical devices, industrial grids, and cloud data backbones carry the same societal risk as civil bridges, municipal water systems, and electrical grids.
To eliminate the artificial entry-level talent shortage, eradicate predatory training bootcamps, and restore engineering accountability, cybersecurity must adopt the proven architecture of the skilled trades: institutional pre-apprenticeships, paid earn-while-you-learn pipelines, progressive domain rotations, personal professional licensure, craft guild protections, and insurance-underwritten standards.
Foundational Principle: The National Cybersecurity Trade Board licenses the practitioner and protects public safety; the Craft Guild trains, protects, and represents the workforce.
The Model at a Glance
- The Economic Lever: Cyber liability insurance underwriters tie policy rates, deductibles, and exclusions to verified labor standards, offering preferred premium credits for certified Journeyman staffing ratios and active Master of Record sign-offs.
- The Enterprise ROI: Sponsoring apprenticeship seats becomes cost-neutral or net-positive through insurance premium discounts, federal/state registered apprenticeship tax credits, and zero recruiter placement fees.
- The Regulatory Authority: The National Cybersecurity Trade Board owns the credential standards, practical challenge exams, and malpractice inquiries. Academic institutions and JATC trusts serve as contracted training providers to open trade standards (NIST NICE), eliminating commercial vendor lock-in.
Fast-Start: How to Engage in 5 Minutes
The Cyber Trade Project is in its open-source formative stage. You do not need to read the entire repository to contribute:
- Test Your Career Placement: Run your numbers in the open-source Trade Tier & Grandfathering Estimator to see where your verified runtime, certifications, or challenge pathways place you.
- Inspect the Tooling: Review the offline-first Universal Digital Logbook Progressive Web App for cryptographic runtime attestation and decentralized supervisor verification.
- Review Active RFCs: Read, stress-test, and critique active Request for Comments proposals:
- RFC 0001: vMoR Statutory Scope & Liability (#7): Fractional Master of Record engagement scopes and SMB safe harbors.
- RFC 0002: DFIR Surge Capacity & Rest Cycles (#8): Crisis incident response surge compensation, rest cycles, and forensic trauma respite.
- RFC 0003: Mandatory Mentorship Quotas (#12): Defining apprentice line-of-sight supervision requirements and ratio audits.
- Join GitHub Discussions: Share your thoughts, edge cases, and critiques on GitHub Discussions.
- Jurisdictional Adaptation: While baseline specifications anchor in United States labor statutes (29 CFR Part 29, Taft-Hartley Section 302(c), ERISA), the modular framework adapts directly for international apprenticeship systems (such as Canada’s Red Seal Program, Skilled Trades Ontario, or UK Modern Apprenticeships).
Strategic Roadmap & 10-Year Phased Horizon
| Phase | Horizon | Primary Driver | Governance Milestone | Key Deliverable |
|---|---|---|---|---|
| Phase 1: Market Adoption & JATC Pilots | Years 0-2 | Insurers + Guild + Employers | National Board & Guild Chartered | Cohort 0 launch, DOL-registered JATC trusts, underwriting warranty credits, & 24-mo portfolio bridge. |
| Phase 2: Critical Infrastructure & Procurement | Years 3-5 | Enterprise & Federal Procurement | FAR/DFARS Procurement Scoring | Defense contractor clauses, high-reliability adoption (ICS/MedTech), & Model Compact drafting. |
| Phase 3: Interstate Compacts & Safe Harbors | Years 5-10 | Multi-State Legislatures | National Licensure Compact (NCTLC) | Statutory interstate reciprocity, mandatory MoR critical infrastructure sign-off, & legal safe harbors. |
The Systemic Problem
The modern cybersecurity employment model is broken across every tier:
- The Experience Paradox: “Entry-level” postings demand 3-5 years of experience or four-year degrees, locking out qualified foundational talent.
- Predatory Bootcamps & Debt: Unregulated vendors charge five-figure tuitions on empty placement promises with minimal enterprise curriculum alignment.
- The Multiple-Choice Treadmill: Commercial vendors push dozens of overlapping multiple-choice tests and recurring annual fees that fail to measure hands-on execution.
- Alert-Silo Burnout: Junior analysts remain trapped in monotonous SOC Tier 1 queues for years without structured rotation into senior competencies.
- Diffused Corporate Liability: When breaches occur due to executive cost-cutting or ignored warnings, frontline engineers carry the stress while corporations treat catastrophic breaches as cost-of-doing-business risks.
The Seven Core Pillars
- Pillar I: Standardized Pre-Apprenticeship & Vocational Screening: High-volume, non-debt vocational talent screening embedded into community colleges.
- Pillar II: Paid Apprenticeships & Graduated Wage Escalation: Zero-tuition direct W-2 employment with graduated living wages and paid classroom time.
- Pillar III: Progressive Rotations & Enforced Ratios: Mandatory 8,000-hour cross-domain rotations and line-of-sight supervisory ratios.
- Pillar IV: Professional Licensure & The Journeyman Standard: Unified Journeyman milestones, credential evaluation clearinghouse, and malpractice accountability.
- Pillar V: Personal Liability & The Right of Technical Refusal: Dual-layer insurance, statutory safe harbor, and formal liability transfer via the Notice of Safety Non-Concurrence.
- Pillar VI: Craft Guilds, Labor Trusts & Collective Defense: Taft-Hartley JATC training funds, legal defense shields, and portable multi-employer benefits.
- Pillar VII: Cyber Underwriting & Actuarial Risk Stratification: Market enforcement through actuarial risk tiering, prima facie due care, and insurance premium incentives.
Operational Frameworks & Governance
Foundational Architecture & Primers
- Skilled Trades for Tech Workers: Foundational Primer: Plain-English explanation of DOL registration, Taft-Hartley trusts, ERISA benefit portability, and insurance warranty economics.
- Systemic Edge Cases & Institutional Defenses: Technical, statutory, and economic failure mode analyses across constitutional police powers, clearance doctrines (Egan), signals intelligence (SIGINT) metadata, and NLRA labor law.
- International Adaptation Guide: Crosswalks and mapping guides for Canadian (Red Seal, STO), UK (IfATE), and European (ENISA) apprenticeship systems.
- 10-Year Industry Transition Plan: Phased statutory compact horizon, 24-month portfolio bridge, and National Registry rollout.
- Glossary of Terms & Acronyms: Canonical definitions across skilled trade, technical operations, and regulatory frameworks.
- Frequently Asked Questions (FAQ): Addressing developer velocity, small business models, cloud providers, and personal liability.
- Contributing Guide: Issue templates, proposal workflows, quality gates, and release cadence policies.
Operational Framework Specifications
- Apprenticeship Standards & Operational On-Ramps: Core 8,000-hour rotational breakdown, RTI classroom mandates, and Prior Learning Assessment (PLA) challenge rules.
- Licensure Standards & Progression Milestones: Progression tiers from Apprentice Tier 1 through Master Practitioner and Master of Record.
- Standards, Regulatory Baselines & Compliance: The technical governance model (NICE workforce taxonomy, consensus technical baselines, and legal sign-offs).
- Wage Scales & Compensation Floors: Milestone progression tiers, COLI standards, hazard differentials, and on-call surge pay.
- Specialty Endorsements & Domain Architecture: The Three-Layer Architecture, Master Endorsement Ledger, and all 9 specialized track specifications (
SE-MED,SE-ICS,SE-DFIR,SE-CLD,SE-OFF,SE-AIML,SE-APP,SE-ICAM,SE-PKI). - Contractors, Consulting & The Trade LLC Model: 1099/W-2 contractor rules, fractional Master of Record (vMoR) guidelines, and entity licensing.
- Executive Leadership & The CISO Role: Separating corporate business management from statutory Master of Record technical sign-off.
- Velocity, Cloud & Safe Harbor: Certified CI/CD pipeline automation, SLSA Level 4 supply-chain provenance, Dead-Man’s Switch freeze protocols, Cloud Shared Responsibility boundaries, and shadow IT protections.
- Universal Logbook Schema & Telemetry Standard: Dual-layer verification, hardware cryptographic pulse, cryptographic commit hashes, AI/ML artifact ingestion, and actuarial feed schemas.
- Supervisory Ratios: On-shift headcount caps, virtual line-of-sight SLAs, and counter-cyclical Cyber Civil Defense Reserve (CCDR) allocations.
- Code of Ethics, Civil Rights & Conduct: Canons of ethics, protected classes, violation classes, mandatory reporting, 72-hour remediation cure period, and disciplinary sanction matrix.
- Technical Refusal & Liability Shield: Exception flags, formal Notice of Safety Non-Concurrence workflow, Master of Record liability transfer, and statutory malpractice liability caps.
- Business & Operational Benefits: The enterprise value model (linear benefit costs, zero agency fees, 25% to 35% insurance discounts, and statutory due care).
- National DOL Apprenticeship Standards (29 CFR Part 29): Official National Guidelines for Apprenticeship Standards (NGAS), Appendix A 8,000-hour work process schedule, Appendix B 576-hour RTI community college curriculum, and Appendix C affirmative action plans.
- Refusal & Institutional Templates: Standardized procedural forms including Form FORM-001 (Notice of Safety Non-Concurrence), Form FORM-002 (Executive Override & Risk Acceptance), Form FORM-003 (Operational Exception Flag), Form FORM-004 (Ethics Incident Report), Form FORM-005 (Targeted OSS Security Fork Exemption), Form FORM-006 (JATC Multi-Employer Trust Agreement), and Form FORM-007 (Employer Participation Agreement).
Institutional Governance & Trust Accords
- National Governance Board Structure: 11-member board composition, practical challenge exams, and the 18-month JATC curriculum rule.
- Board Bylaws & Democratic Elections: Founding steering committee sunset, secret-ballot elections, staggered 3-year terms, and member recall protocols.
- Guild Formation & Labor Charter: Bilateral governance accord, Taft-Hartley JATC trusts, legal defense shields, portable benefits, Tier-I No-Disruption Covenant, and Final-Offer Interest Arbitration.
- Model State Legislation & Interstate Compact (ICPC): Draft statutory bill language and interstate practice reciprocity compact for state legislative sponsors.
- Regional Chapters & Local Governance: Three-tier federation, local chapter chartering, COLI wage negotiations, and convention delegate apportionment.
- Dues Structure & Labor Trusts: Two-part worker dues model, employer training trust contributions, and pre-tax policy advocacy.
- Operational Field Roles & Stewards: Shop Stewards, JATC Training Directors, Board Practical Challenge Examiners, and Dispatch Officers.
- Participating Employer Council (PEC): Multi-employer association charter, Large Enterprise vs. SMB/Contractor divisions, and management trustee elections.
- Underwriter & Actuarial Consortium (CUAAC): Risk capital consortium charter, 25% to 35% premium warranty schedules, and insurer trustee selection.
Ecosystem Tooling
- Cybersecurity Trade Tier & Grandfathering Estimator: An open-source, privacy-first client-side web application and mathematical engine enabling practitioners to estimate their provisional trade placement, PLA hour credits, and milestone path (Repository).
- Universal Digital Logbook & Competency Ledger: A mobile-first, privacy-preserving Progressive Web Application (PWA) and cryptographic verification engine for logging operational runtime, SCIF shift transcriptions, Merkle hash chaining, and supervisor attestation (Repository).
- Cybersecurity Trade Clearinghouse: Central ingestion, Merkle hash traversal, practitioner registry, and interactive FIFO Dispatch Simulator (Repository).
- Insurance Telemetry Gateway: Zero-knowledge supervisory ratio attestation, Master of Record verification feed, and CUAAC actuarial warranty scoring engine (Repository).
Priority Areas for Community Contribution
We welcome contributions and pull requests on these active focus areas:
- Specialty Track Specifications: Proposing normative curricula and 2,000-hour ledgers for remaining tracks (ICS/SCADA, Cloud Architecture, DFIR, AI/ML Assurance, OffSec) using our New Specialty Track Template and Medical Device Specification exemplar.
- Community College Pre-Apprenticeship Syllabi: Mapping hands-on lab modules and practical screening rubrics to the 4 prerequisite technical domains.
- Regional JATC Pilot Programs: Establishing local employer consortia and community college training trust partnerships across metropolitan chapters.
- Statutory Model Legislation: Drafting language for state and interstate licensing compacts modeled after the IMLC and NCEES.
- Actuarial Risk Modeling: Partnering with cyber-insurance underwriters to refine empirical loss-prevention credits for certified trade labor.
How to Get Involved
- Practitioners & Engineers: Review the Specialty Endorsements and open an Issue or PR to refine practical competencies for your domain.
- CISOs & Engineering Leaders: Review Executive Leadership & The CISO Role to evaluate organizational governance and risk transfer models.
- Educators & Vocational Providers: Help expand the open pre-apprenticeship curriculum specifications in Pillar I.
- Join the Initiative: Open an Issue using our structured Proposal Templates or submit a pull request following the Contributing Guidelines.
License
This project is licensed under the Creative Commons Attribution-ShareAlike 4.0 International Public License (CC BY-SA 4.0).