Skip to content

Tier II Specialization · PKI Career Pathway Cohort

Develop the capability to understand, operate, troubleshoot, and design enterprise PKI.

A six-month, practitioner-led program that moves from digital-trust foundations to enterprise PKI operations and architectural thinking. Across three phases — Foundations, Operations, Engineering & Architecture — participants work in prebuilt enterprise Azure PKI environments and document their work in a professional GitHub portfolio.

Successful completion of Cyber Foundations is the required Tier I prerequisite for this program.

Applications are currently closed.

Enterprise PKI trust architecture: a central digital trust core connected to users, devices, applications, APIs, servers, and cloud, above a Build, Operate, Engineer progression

Program snapshot

24

Weeks

Six months of progressive development

3

Phases

Foundations → Operations → Engineering & Architecture

Weekly

Live + async

Live sessions with coursework between them

Azure

Enterprise PKI labs

Prebuilt enterprise operations environments

GitHub

Portfolio + capstones

Documented work across the full program

Why the program exists

PKI is not a certificate topic. It is an operational trust system.

Digital trust underpins identities, systems, applications, devices, and secure communication. When it fails, the consequence is rarely a single bad certificate file — it is an outage, a broken authentication path, or an organizational process that no one owns.

Enterprise PKI has to be designed, operated, monitored, recovered, governed, and modernized. That is a different skill set from recognizing what a certificate is, and it is not developed by reading about certificates.

Professionals need the ability to explain why trust works, diagnose why it fails, and improve how it is managed. The twenty-four weeks are organized around those three capabilities.

Who it is for

Built for professionals ready to specialize, not to start.

Successful completion of Cyber Foundations is required to apply. Admission remains subject to cohort availability and any program-specific requirements.

  • Cyber Foundations graduates ready for Tier II specialization
  • Security, identity, and access management professionals
  • Systems, cloud, and platform administrators
  • Professionals preparing for greater PKI operational responsibility

Come prepared to work in these ways

  • Work in Windows Server and command-line environments
  • Read and produce technical documentation
  • Submit and document work through GitHub
  • Participate in live sessions and complete asynchronous labs

Three-phase learning journey

Your 24-Week Journey

Every phase builds on the one before it. Learners first build the mental models behind digital trust, then operate enterprise PKI environments, and finally develop the architectural thinking required to modernize trust systems.

  1. Phase 1 · Weeks 1–8

    Build

    PKI Foundations

    Build the technical foundation needed to explain digital trust, cryptography, certificates, lifecycle management, TLS, and common trust failures.

    Foundations Milestone

    Foundations work, labs, and the Phase 1 Reflection Project

  2. Phase 2 · Weeks 9–16

    Operate

    PKI Operations

    Apply foundational knowledge in enterprise Azure PKI environments through issuance, templates, autoenrollment, revocation, monitoring, troubleshooting, backup, and recovery.

    Operations Milestone

    Operational labs, documented troubleshooting, and the Phase 2 mini capstone

  3. Phase 3 · Weeks 17–24

    Engineer

    PKI Engineering & Architecture

    Develop architectural judgment across key protection, lifecycle automation, machine identity, Zero Trust, cryptographic modernization, and future trust planning.

    Engineering & Architecture Milestone

    Architecture and modernization capstone

Curriculum detail by phase

Expand a phase for its themes and detailed curriculum areas.

Applied enterprise practice

Enterprise PKI practice — not simulated screenshots.

Learners perform PKI operations in browser-accessible Azure environments and preserve the resulting work in structured GitHub portfolios.

Enterprise Azure PKI operations labs

During the PKI Operations phase, learners work in prebuilt enterprise Azure environments accessed through the browser, so program time is spent on operations rather than on assembling lab infrastructure.

  • Prebuilt enterprise-style Windows PKI environments in Azure
  • Browser-based access to a two-tier certificate authority
  • Active Directory and AD CS operational work
  • Certificate templates, issuance, and profiles
  • Revocation, monitoring, and progressive troubleshooting
  • Backup, recovery, and failure scenarios with instructor support

GitHub portfolio

Work is submitted and preserved in structured GitHub repositories, accumulating into a professional PKI portfolio that shows how someone thinks and works.

  • Lab documentation
  • Troubleshooting records
  • Operational summaries
  • Architecture work
  • Reflections
  • Capstone materials

The infrastructure is configured for learning and practice, and is not a production enterprise system.

Labs are available only to authorized enrolled participants, and access follows cohort policies.

Portfolio work must exclude private keys, credentials, confidential infrastructure details, and other sensitive material.

Evidence of capability

Explain it, diagnose it, document it.

The goal is not memorization. It is the ability to explain PKI as a connected system and describe why it matters to secure communication, identity, and digital trust.

Explain

The Phase 1 Reflection Project asks learners to explain PKI as a connected system in their own words.

  • Connect cryptography, certificates, lifecycle, TLS, and trust
  • Reference specific lab exercises
  • Submit a written or short video explanation
  • Include a visual model of a handshake, lifecycle, or trust hierarchy

Diagnose

Troubleshooting runs through the program as a method rather than a list of fixes.

  • Identify the symptom and inspect the environment
  • Test assumptions and determine the root cause
  • Apply a controlled resolution
  • Verify and document the result

Document

Documented work accumulates in the GitHub portfolio throughout the program.

  • Lab documentation and troubleshooting records
  • Certificate-profile comparisons and operational summaries
  • Architecture diagrams and recovery planning artifacts
  • Capstone materials

The exact Phase 3 artifact set continues to be finalized, and specific deliverables may vary by cohort. Full assignment instructions are provided to enrolled participants.

Capabilities developed

What you should be able to do as you progress.

  • Explain digital trust and enterprise PKI architecture
  • Analyze certificates, trust chains, lifecycle states, and trust boundaries
  • Operate AD CS certificate services and issuance workflows
  • Diagnose common PKI, TLS, and trust failures
  • Manage revocation, monitoring, backup, recovery, and lifecycle operations
  • Evaluate automation, machine identity, key protection, Zero Trust, cryptographic agility, and modernization

These are capabilities developed through the program, not guarantees of employment, title, or external certification.

Credentials

Each phase carries its own completion credential.

  • Phase 1

    PKI Foundations Certificate of Completion

  • Phase 2

    PKI Operations Practitioner

  • Phase 3

    PKI Engineering Fellow

Credentials require satisfactory completion of the applicable phase requirements, including participation, lab submissions, and reflection or capstone work.

CVI program credentials document completion of CVI requirements. They are not vendor certifications and do not guarantee employment or advancement.

Program details

How the program runs.

Format

  • 24 weeks across six months
  • Weekly live sessions
  • Asynchronous coursework
  • Enterprise Azure PKI labs
  • GitHub documentation and submissions
  • Reflection and capstone work

Weekly time commitment

The weekly commitment includes live instruction, asynchronous study, hands-on lab work, documentation, and portfolio development. A specific weekly estimate will be published with the next cohort schedule.

Tuition and enrollment

Program Tuition

Program Tuition

4,000 US dollars

Tuition covers the complete 24-week PKI Career Pathway Cohort.

Tuition includes

  • All instructor-led sessions
  • Asynchronous learning materials
  • Enterprise Azure PKI operations labs
  • GitHub portfolio development
  • Capstone activities
  • Eligibility for applicable CVI credentials upon successful completion

Enrollment Deposit

500 US dollars

Accepted applicants submit a $500 enrollment deposit to reserve their seat. The deposit is applied toward the total tuition.

Payment Plans

Flexible payment plans are available for accepted applicants. Specific installment schedules are discussed during the enrollment process.

Enrollment Policies

Institute-wide enrollment, tuition, refund, and conduct policies apply to every CVI cohort. Applications for this cohort are not currently open, and no seat can be reserved at this time.

Review Institute policies
  • Practitioner-led instruction
  • Enterprise Azure PKI labs
  • GitHub portfolio development
  • Cohort-based learning
  • Payment plans available

PKI Admissions

Applications

Applications are currently closed.

Applications for the next PKI Career Pathway Cohort will open after the next cohort schedule is announced.

When applications reopen, the application will be completed directly on this page.

Successful completion of Cyber Foundations is required to apply.

Frequently asked questions

Trust is engineered. So is the capability to run it.

Six months of progressive, documented practice — from explaining why trust works to diagnosing why it fails and improving how it is managed.

We don’t sell dreams. We help create visions.

#DisruptTheIndustry