Skip to main content

The Cybersecurity Trade Project

An open-source, vendor-neutral framework to restructure cybersecurity into a recognized skilled trade through paid apprenticeships, standardized wage floors, progressive rotations, professional licensure, guild protections, and underwriter-driven accountability.


The Core Thesis

Cybersecurity is an applied engineering and operational trade, not an academic abstraction. Critical digital infrastructure, connected medical devices, industrial grids, and cloud data backbones carry the same societal risk as civil bridges, municipal water systems, and electrical grids.

To eliminate the artificial entry-level talent shortage, eradicate predatory training bootcamps, and restore engineering accountability, cybersecurity must adopt the proven architecture of the skilled trades: institutional pre-apprenticeships, paid earn-while-you-learn pipelines, progressive domain rotations, personal professional licensure, craft guild protections, and insurance-underwritten standards.

Foundational Principle: The National Cybersecurity Trade Board licenses the practitioner and protects public safety; the Craft Guild trains, protects, and represents the workforce.


The Model at a Glance

  • The Economic Lever: Cyber liability insurance underwriters tie policy rates, deductibles, and exclusions to verified labor standards, offering preferred premium credits for certified Journeyman staffing ratios and active Master of Record sign-offs.
  • The Enterprise ROI: Sponsoring apprenticeship seats becomes cost-neutral or net-positive through insurance premium discounts, federal/state registered apprenticeship tax credits, and zero recruiter placement fees.
  • The Regulatory Authority: The National Cybersecurity Trade Board owns the credential standards, practical challenge exams, and malpractice inquiries. Academic institutions and JATC trusts serve as contracted training providers to open trade standards (NIST NICE), eliminating commercial vendor lock-in.

Fast-Start: How to Engage in 5 Minutes

The Cyber Trade Project is in its open-source formative stage. You do not need to read the entire repository to contribute:

  • Test Your Career Placement: Run your numbers in the open-source Trade Tier & Grandfathering Estimator to see where your verified runtime, certifications, or challenge pathways place you.
  • Inspect the Tooling: Review the offline-first Universal Digital Logbook Progressive Web App for cryptographic runtime attestation and decentralized supervisor verification.
  • Review Active RFCs: Read, stress-test, and critique active Request for Comments proposals:
  • Join GitHub Discussions: Share your thoughts, edge cases, and critiques on GitHub Discussions.
  • Jurisdictional Adaptation: While baseline specifications anchor in United States labor statutes (29 CFR Part 29, Taft-Hartley Section 302(c), ERISA), the modular framework adapts directly for international apprenticeship systems (such as Canada’s Red Seal Program, Skilled Trades Ontario, or UK Modern Apprenticeships).

Strategic Roadmap & 10-Year Phased Horizon

Phase Horizon Primary Driver Governance Milestone Key Deliverable
Phase 1: Market Adoption & JATC Pilots Years 0-2 Insurers + Guild + Employers National Board & Guild Chartered Cohort 0 launch, DOL-registered JATC trusts, underwriting warranty credits, & 24-mo portfolio bridge.
Phase 2: Critical Infrastructure & Procurement Years 3-5 Enterprise & Federal Procurement FAR/DFARS Procurement Scoring Defense contractor clauses, high-reliability adoption (ICS/MedTech), & Model Compact drafting.
Phase 3: Interstate Compacts & Safe Harbors Years 5-10 Multi-State Legislatures National Licensure Compact (NCTLC) Statutory interstate reciprocity, mandatory MoR critical infrastructure sign-off, & legal safe harbors.

The Systemic Problem

The modern cybersecurity employment model is broken across every tier:

  • The Experience Paradox: “Entry-level” postings demand 3-5 years of experience or four-year degrees, locking out qualified foundational talent.
  • Predatory Bootcamps & Debt: Unregulated vendors charge five-figure tuitions on empty placement promises with minimal enterprise curriculum alignment.
  • The Multiple-Choice Treadmill: Commercial vendors push dozens of overlapping multiple-choice tests and recurring annual fees that fail to measure hands-on execution.
  • Alert-Silo Burnout: Junior analysts remain trapped in monotonous SOC Tier 1 queues for years without structured rotation into senior competencies.
  • Diffused Corporate Liability: When breaches occur due to executive cost-cutting or ignored warnings, frontline engineers carry the stress while corporations treat catastrophic breaches as cost-of-doing-business risks.

The Seven Core Pillars

  1. Pillar I: Standardized Pre-Apprenticeship & Vocational Screening: High-volume, non-debt vocational talent screening embedded into community colleges.
  2. Pillar II: Paid Apprenticeships & Graduated Wage Escalation: Zero-tuition direct W-2 employment with graduated living wages and paid classroom time.
  3. Pillar III: Progressive Rotations & Enforced Ratios: Mandatory 8,000-hour cross-domain rotations and line-of-sight supervisory ratios.
  4. Pillar IV: Professional Licensure & The Journeyman Standard: Unified Journeyman milestones, credential evaluation clearinghouse, and malpractice accountability.
  5. Pillar V: Personal Liability & The Right of Technical Refusal: Dual-layer insurance, statutory safe harbor, and formal liability transfer via the Notice of Safety Non-Concurrence.
  6. Pillar VI: Craft Guilds, Labor Trusts & Collective Defense: Taft-Hartley JATC training funds, legal defense shields, and portable multi-employer benefits.
  7. Pillar VII: Cyber Underwriting & Actuarial Risk Stratification: Market enforcement through actuarial risk tiering, prima facie due care, and insurance premium incentives.

Operational Frameworks & Governance

Foundational Architecture & Primers

Operational Framework Specifications

Institutional Governance & Trust Accords

Ecosystem Tooling


Priority Areas for Community Contribution

We welcome contributions and pull requests on these active focus areas:

  1. Specialty Track Specifications: Proposing normative curricula and 2,000-hour ledgers for remaining tracks (ICS/SCADA, Cloud Architecture, DFIR, AI/ML Assurance, OffSec) using our New Specialty Track Template and Medical Device Specification exemplar.
  2. Community College Pre-Apprenticeship Syllabi: Mapping hands-on lab modules and practical screening rubrics to the 4 prerequisite technical domains.
  3. Regional JATC Pilot Programs: Establishing local employer consortia and community college training trust partnerships across metropolitan chapters.
  4. Statutory Model Legislation: Drafting language for state and interstate licensing compacts modeled after the IMLC and NCEES.
  5. Actuarial Risk Modeling: Partnering with cyber-insurance underwriters to refine empirical loss-prevention credits for certified trade labor.

How to Get Involved


License

This project is licensed under the Creative Commons Attribution-ShareAlike 4.0 International Public License (CC BY-SA 4.0).