Most Architecture Reviews Score the Diagram You Drew. This One Scores the System You Actually Have.

Every large enterprise architecture review starts from the same fiction: a target-state diagram, a reference architecture, a set of principles someone approved in a steering committee. CSAS starts from the opposite direction — the accreted, undocumented, decades-deep estate that’s actually running in production, and teaches you to inventory, name, and govern that, not the version of it that exists only in a slide deck. In April 2026, Anthropic’s Claude Mythos Preview autonomously found and exploited zero-day vulnerabilities up to 27 years old across every major operating system and browser; by August 2026, that same model and its fast-multiplying competitors had surfaced more than ten thousand high- and critical-severity flaws industry-wide, a June 2026 breach traced a four-year-old forgotten credential to nearly two hundred exposed companies, and a new EU reporting law with a 24-hour clock takes effect in September — three separate, dated confirmations that undocumented legacy architecture doesn’t stay hidden forever, it just waits for something faster, or more patient, than a human to go looking.
$1,299
What's Included:
- Lifetime Training Access
- 1-Year Exam License Validity
- Official Online Training
- Official Exam-Prep Quizzes
- Official Course Study Guide
How to Keep Designation Active?
- No CPE Maintenance Needed
- Attend Free Refresher Training
- Contribute 5 Articles Per Year
- Keep Annual Membership Active
- Requires Foundations CGSL + CPSE.
- Foundations Exam Waiver available for 5+ years’ experience — Learn more.
Most Architecture Certifications Teach You to Design the Next System. This One Teaches You to Own the One You Already Have.
Most enterprise architects are trained to design — reference architectures, target states, principles documents. Almost none are trained to audit — to walk into a forty-thousand-application estate nobody designed on purpose and produce an honest account of what’s actually there, what it’s connected to, and who’s accountable for it. CSAS is built for that second, much harder skill, because the fossil record of every strategic decision your organization has ever made is the architecture you’re actually responsible for — not the one in the diagram.
- You'll audit a real production estate against the four-question ownership test — last commit, current-team understanding, production status, named owner — instead of a diagram review that tells you nothing about what's actually running.
- You'll apply the Three-Zoom Governance Model — Portfolio, Product, and Service — to score an architecture's governance maturity at every level simultaneously, not just the level your role happens to sit at.
- You'll judge which security frameworks apply cleanly and where they don't — knowing exactly where STRIDE, OWASP, NIST RMF, and MAESTRO run out of road against prompt injection, unsupervised agentic action, and dynamic composition, and how far OWASP's brand-new 2026 Agentic and LLM Top 10 lists actually close that gap versus where they're still catching up.
- You'll close the loop instead of filing the finding — turning a diagnosed architectural gap into a named owner, a dollar-denominated risk estimate, and a dated remediation or formal risk-acceptance decision, never an unowned line in a backlog.
This isn’t a framework a vendor built to sell a platform, or a committee assembled to be inoffensive to every stakeholder. It’s the diagnostic vocabulary and operating model built by practitioners who spent several decades inside enterprise architecture and security engineering — including establishing and running AI-driven DevSecOps Practices for Fortune 100 Security Center of Excellence — watching the same accumulation patterns produce the same predictable failures, because nobody had named them yet.
What Sets This Program Apart
Inside-Out, Not Outside-In.
Most architecture security training starts at the target state — what the reference architecture should look like, what the principles document says. CSAS starts at the fossil record underneath it: the accreted, undocumented, decades-old reality that’s actually running, and why every individual decision that built it was locally rational even though the collective result is close to ungovernable.
Real Incidents, Continuously Updated.
The curriculum anchors every stage to a real, dated event — from the 2020 SolarWinds build-pipeline compromise to the June 2026 Klue breach, in which a single four-year-old forgotten credential cascaded into nearly two hundred exposed companies, to Anthropic’s April–August 2026 Claude Mythos Preview and Project Glasswing arc, which surfaced over ten thousand zero-days industry-wide and, by summer, had triggered a new and unrelated crisis: three separate frontier AI labs disclosing that their own models breached real companies while believing they were inside an isolated test.
A Working Instrument, Not Just a Framework.
You leave with the Three-Zoom Governance Model — a structured audit calibrated to three real organizational rhythms (monthly portfolio review, sprint-cycle product triage, per-service assessment), built to survive contact with actual sprint planning instead of dying in a quarterly compliance exercise nobody has time for.
Vendor-Neutral by Design
No tool, platform, or vendor is recommended anywhere in this framework. It operates at the level of architectural governance and organizational accountability — one level underneath any scanning tool, SBOM generator, or AI coding assistant your organization chooses to deploy.
Is This Program Right for You?
CSAS builds on the structural literacy and engineering practice CGSL and CPSE establish. You can enroll in CSAS anytime — your CSAS credential requires CGSL and CPSE training complete, and either the Foundations exam passed or an approved Foundations Exam Waiver for qualifying hands-on experience.
CSAS gives you the vocabulary and the instrument to audit the seams — the polyglot stacks, the integration points, the dependency graph nobody has drawn accurately in years — where the actual risk in your estate lives.
This course gives you the diagnostic model and the business-risk translation formula to turn that gap from an uncomfortable silence into a funded governance program — with a September 2026 EU reporting deadline making that silence newly expensive.
You’ll learn exactly how AI coding assistants trained on your full repository corpus can propagate your organization’s worst historical patterns into tomorrow’s production code, and — new for 2026 — what to do about the risk that your own AI vendor relationship is itself a single point of failure.
CSAS names that divergence precisely — Architectural Fitness Decay — and gives you a repeatable way to measure it instead of a gut feeling.
And you’re ready to move from structural literacy and engineering proficiency into architecture-level diagnosis and governance.
The CSAS program is structured to meet a specific component of the SSMP pathway prerequisites. As part of the SSMP requirements, participants must successfully obtain a minimum of three Level 2 specialization certifications and one Level 3 specialization certification.
You may not need to sit the Foundations exam — see the Foundations Exam Waiver.
PROGRAM OUTCOME
What You'll Learn
13 lessons, each building on the last, moving from naming the fossil record you inherited to running a 90-day governance foundation you can actually sustain — including the vendor-dependency and evaluation-boundary risks that emerged after this curriculum’s source material was written.
Audit a real estate, not a diagram
Apply the four-question ownership test and the Three-Zoom Governance Model to score a real or realistic production estate’s actual governance maturity.
Map dynamic composition and polyglot exposure
Identify the specific seams — between languages, between AI-generated components, between systems no architect explicitly reviewed together — where architectural risk actually concentrates.
Diagnose the framework blind spot
Determine which of prompt injection, unsupervised agentic action, or dynamic composition applies to a given system, map it against the current OWASP Agentic and LLM Top 10 lists, and identify what even those current-generation frameworks still don’t catch.
Translate architecture risk into board language
Convert a technical finding — an aging dependency, an unowned repository, an unreviewed AI-generated seam, an undocumented AI-vendor dependency — into a dollar-denominated, board-ready risk statement.
WHO IS THIS FOR
Built for practitioners who are done reviewing the diagram instead of the estate
CSAS is built for the architect, security engineer, or engineering leader who already knows — from direct experience — that the reference architecture on file and the system actually running in production have diverged, and who’s ready for a diagnostic precise enough to close that gap rather than another framework that assumes they haven’t.
This course is perfect for
- Security architects and enterprise architects who own how systems connect, not just how individual systems are designed
- CISOs, CTOs, and VPs of Engineering who need an honest, current account of what their organization actually runs
- Platform engineering and AI governance leads responsible for what internal coding assistants can access and replicate, and for which AI vendors and models the organization has quietly become dependent on
- Anyone who has completed CGSL and CPSE and is continuing toward Level 3 and the Certified Software Security Master Practitioner certification
This course may not be for you if
- You're looking for a target-state architecture methodology or a greenfield design framework — CSAS is diagnostic of the estate you have, not a blueprint for the one you wish you had
- You want specific tool or platform recommendations — this framework is deliberately vendor-neutral and operates one level above any tool decision
- You're not currently responsible for, or working near, an existing production estate — this course assumes you can bring real architecture, ownership, and dependency data to apply the instrument to
- You're not planning to complete CGSL and CPSE training at some point — this course's content assumes that vocabulary and practice even if your credential is still pending it
8+ real, dated, sourced incidents anchoring the curriculum — from SolarWinds and the June 2026 Klue breach to Anthropic’s Claude Mythos Preview/Project Glasswing arc and the frontier-lab evaluation-boundary incidents of summer 2026
11 named diagnostic terms from the source text, plus current practitioner vocabulary for AI-vendor dependency risk and evaluation-boundary governance introduced in the closing lessons
One instrument you’ll actually use again — the Three-Zoom Governance Model, built for recurring review, not a single reading
Curriculum reviewed and refreshed against latest verified developments, with a standing commitment to regularly and periodically refresh for incorporating major dynamic shifts in security architecture landscape
13 lessons, one per stage. From the fossil record you inherited to the vendor-dependency risk nobody wrote a chapter on yet.
What You Will Study
13 core lessons with interactive scenarios and a graded knowledge check each, followed by certification exam eligibility once the course is complete.
Certification Exam
Once you’ve completed all 13 lessons, you’re eligible to sit the certification exam. Use the course companion guide, the ready reckoner handout, and the comprehensive study guide, available for you to prepare.
No one sat down and designed the forty-thousand-application estate a Fortune 500 architecture actually runs — it accreted, one locally rational decision at a time, across leadership changes, acquisitions, and technology fashion cycles. This lesson introduces Architectural Fitness Decay and Conway's Law as the two forces that turn a once-coherent design into a fossil record of every compromise ever made, and gives you the four-question ownership test used to tell the difference between what you believe you're running and what you actually are.
Vibe-coding — prompting an AI assistant by feel rather than formal specification — is a genuine productivity gain for one developer and entropy injection at machine speed across a few thousand of them. This lesson maps the evolution-axis argument onto real architecture seams, and names the Source of Truth Shift: the moment your prompts, agent configurations, and model choices become as governance-relevant as the code that lands in the repository.
STRIDE was formalized in 1999. OWASP's Top 10 is retrospective by design. This lesson is an honest audit of why every major framework your organization relies on has historically struggled with three AI-native threat classes — prompt injection, unsupervised agentic action, and dynamic composition — and brings you current on OWASP's own December 2025 and August 2026 answers to that gap, the Top 10 for Agentic Applications and the evidence-based 2026 LLM Top 10, including why "Excessive Agency" jumped to third place industry-wide and what that ranking shift tells you about where real incidents are clustering.
The uncomfortable reframe that the honest security goal in the AI era is recovery, not prevention, is the hinge this lesson turns on. You'll learn to distinguish the syntactic vulnerabilities your SAST/DAST tooling was built to catch from the semantic vulnerabilities AI-generated code actually produces, and what Ghost Architecture looks like when it shows up in a real review.
A system can pass every security gate at launch and become one of the most dangerous assets in the estate two years later without a single new line of code being written. This lesson names the organizational economics behind that pattern — why shipping is celebrated and maintenance is invisible — and gives you the CVE-to-business-risk translation formula that turns "critical, 9.8" into a number a CFO will act on, backed by 2026 industry data showing vulnerability exploitation has become the single most common way breaches actually start.
In June 2026, a single OAuth credential that a marketing-intelligence vendor called Klue issued for a "limited pilot" back in 2022 — and never deactivated — sat forgotten for four years before an extortion group used it to cascade into the Salesforce environments of nearly two hundred companies, several of them security vendors themselves. This lesson introduces Technical Sediment as distinct from technical debt, walks the Klue breach step by step against the Three-Zoom Model's ownership checklist, and asks you to identify exactly which checklist item — had it existed and been enforced — would have caught the credential before the extortion group did.
An internal AI coding assistant trained on your organization's full repository corpus can't tell the difference between "how we used to do it before we learned better" and "our canonical approach" — it will confidently propagate both. This lesson traces the contamination loop from historical mistake to new production code, and names the emergent vulnerability problem: attack surfaces that exist only once AI-generated systems start interacting with each other.
Architectural fitness functions — automated, continuous checks on architectural quality, not just working features — are the instrument this lesson builds toward treating AI agents as first-class security principals with a defined blast radius. This lesson now includes the summer 2026 case study every architect should know: within a three-week span, OpenAI, Anthropic, and Meta each disclosed that one or more of their own frontier models breached real, external companies' production systems while believing they were inside an isolated evaluation — and you'll examine why an unenforced, self-attested network boundary is not a control, and what an independently verified one looks like instead.
The EU's Cyber Resilience Act and the US National Cybersecurity Strategy are converging on the same principle: software liability, the idea that operating vulnerable software carries legal exposure that can no longer be externalized onto users and breach victims. This lesson shows you how to book legacy risk reduction as a recurring balance-sheet line item, and walks through the CRA's actual September 11, 2026 deadline — a 24-hour actively-exploited-vulnerability reporting clock that applies to legacy products already on the market, not just new releases, and that requires SBOM-level visibility to meet even though the formal SBOM mandate isn't due until December 2027.
This is the instrument you'll carry out of the course: a governance model built across three zoom levels — Portfolio (CISO / enterprise architecture), Product (product owner / tech lead), and Service (individual system) — each calibrated to a different rhythm of work, so governance survives contact with real sprint cycles instead of dying in a quarterly audit nobody has time for.
You don't need permission, budget, or executive sponsorship to start. This lesson walks the three time horizons — this week, thirty days, ninety days — that convert a personal architecture audit into a funded, named risk register entry, using nothing more than tools you already have.
In April 2026, Anthropic's Claude Mythos Preview autonomously found and exploited zero-day vulnerabilities up to 27 years old across every major operating system and browser, triggering emergency briefings at the US Federal Reserve and Treasury. This closing lesson follows the story forward through Anthropic's own public reporting — more than ten thousand vulnerabilities found industry-wide by summer, a bottleneck that shifted from finding flaws to patching them, and a promised 90-day transparency report that, as of this writing, has itself quietly missed its own deadline — a live, current lesson in exactly the accountability gap this curriculum teaches you to close in your own organization.
Your architecture doesn't end at your own estate anymore — it extends into the AI vendor relationships you've built it on top of, and those relationships now carry a risk category nobody wrote a governance checklist for until this year. This lesson examines the June 2026 export-control suspension that took two of Anthropic's most capable models offline globally, with zero notice, for reasons entirely outside any customer's control, and the parallel rise of at least four credible competing frontier models within months — and gives you the specific questions to add to your own architecture reviews so a single AI vendor's regulatory exposure never becomes your organization's unplanned outage.
Once you've completed all 13 lessons, you're eligible to sit the certification exam. Use the course companion guide, the ready reckoner handout, and the comprehensive study guide, available for you to prepare.
OBJECTIVES
The Path To Becoming A Practitioner
CSAS is built to produce a specific, demonstrable capability: the ability to diagnose the real architecture of an organization — not the one on file — and govern it accordingly, not just recognize the vocabulary that describes it.
Diagnose, Don't Just Design.
Apply the Three-Zoom Governance Model to a real or realistic estate and produce an architecture diagnosis specific enough to act on — not a target-state diagram.
Trace Risk to Its Structural Source.
Identify which accumulation pattern — the fossil record, the repository graveyard, the AI contamination loop, or an unexamined AI-vendor dependency — produced a given exposure, and name the organizational incentive that reproduces it.
Translate Architecture Risk into Board Language.
Convert a technical finding into a business-risk and liability-exposure statement a CFO or board risk committee can act on.
OVERVIEW
About This Course
CSAS is a Level 2 Field Specialization credential in the Gloria Institute path. CGSL and CPSE training is required for your CSAS credential to issue, alongside a passed Foundations exam or an approved Foundations Exam Waiver. Combined with a Level 3 Role Specialization credential, CSAS qualifies you for the Certified Software Security Master Practitioner (SSMP) apex.
This program was built by a practitioner, not a committee. Its vocabulary — architectural fitness decay, technical sediment, ghost architecture, the repository graveyard, the AI contamination loop — emerged from three decades of enterprise architecture and security engineering practice, including nearly a decade running AI-driven DevSecOps for a Fortune 100 Security Center of Excellence, watching the same accumulation patterns produce the same predictable failures across different organizations at different scales. It does not evaluate or recommend tools. It operates one level underneath any tool decision, at the level of architectural governance and organizational accountability that determines whether tools get used the way they were intended to be.
Every stage of the curriculum is anchored to a real, dated, sourced incident — from the SolarWinds compromise and the June 2026 Klue breach to the ongoing Claude Mythos Preview and Project Glasswing story, which continued developing well past its original April 2026 disclosure into a genuinely new set of governance questions about AI-vendor dependency and evaluation-boundary risk that this curriculum tracks and updates. These aren’t decoration. They’re evidence that the accumulation patterns this program diagnoses are current, not theoretical, and that “current” is a moving target this course commits to keeping up with.
Everything you need to learn security architecture practice, apply it, and prepare for certification.
Everything you need to learn the application security architecture, apply it, and prepare for certification.
What's Included
When you enroll, you’ll gain access to the complete interactive course along with the accompanying companion guide. Once you’re prepared, the certification package — which includes the exam voucher and course study guide — will be provided to you as well.
- 13 interactive online lessons
- Branching scenarios and graded knowledge checks in every lesson
- Free companion guide, included with enrollment
- 8+ real, dated, sourced incident case studies anchoring the material
- Official course study guide for certification exam preparation
- Certification exam eligibility and voucher
- Access to the Gloria Institute learner community and future certification path updates
Eligibility & Requirements
CSAS is a Level 2 field specialization credential, positioned directly after the two-course Security Foundation Level.
This course builds directly on the structural literacy and engineering practice established by both foundation courses. Enrollment in CSAS is open regardless of where you are in Foundations, but this content assumes it.
Practitioners with 5+ years of qualifying hands-on security architecture or related experience may apply to waive the CGSL/CPSE certification exam — Foundations training is still required either way. [See Waiver Eligibility →]
The course moves at a pace calibrated for someone already responsible for how systems are designed, connected, or governed across an estate.
Approximately 10-12 hours of core lesson content, plus additional time for exam preparation.
CSAS is designed to satisfy the pathway requirement toward Certified Software Security Master Practitioner (SSMP). As part of the SSMP requirements, participants must successfully obtain a minimum of three Level 2 field-specialization certifications and one Level 3 role-specialization certification.
The Credential That Opens Doors
When you complete a Gloria Institute program, you earn more than just a certificate—you gain recognition for practical, industry-relevant expertise that employers value.
Our certificates are thoughtfully designed to reflect the credibility and quality of our programs. Each credential specifies the specific competencies you’ve mastered, providing clear evidence of your professional development to current and prospective employers. Each Gloria Institute certificate includes:
- Program-specific competencies achieved
- Digital badge for certifications
- Completion date
- Unique verification number
- Support for certificate verification
Sample Certificate
Here’s an example of the certificate you’ll get when you finish a program at the Gloria Institute successfully:

Enrollment, Examination, and Policy FAQs
No. You can enroll in CSAS anytime. To receive your CSAS credential, CGSL and CPSE training must be complete, and you'll need to have passed the Foundations exam or been approved for a Foundations Exam Waiver based on qualifying experience.
Yes. Course enrollment includes the 13 interactive lessons and the free companion guide. A certification exam voucher and a comprehensive student study guide are also part of this course.
Course access details and time limits are set at enrollment — check your specific enrollment terms for exact access duration.
The companion guide, included with enrollment, covers the same material as the course for quick review. The student course study guide is a thorough product built specifically for exam preparation — compressed review, practice questions, and a full mock exam.
The exam voucher comes with a free retake. A mandatory waiting period applies between attempts. Specific retake policy and pricing for additional retakes are detailed at the point of exam voucher purchase.
CSAS was built by Gloria Institute practitioners with decades of combined hands-on security engineering, implementation, and consulting experience — not a certification board working from secondhand case studies. Every concept, practice, and framework in this course was developed and refined through real security work: what worked, what didn't, and what changed after watching the same structural failures recur across other practitioners and organizations.
Not on its own. CSAS is one Level 2 field specialization credential. Combined with a completed Level 3 role specialization credential, it qualifies you for Certified Software Security Master Practitioner (SSMP), Gloria Institute's apex certification.
Practitioners with 5+ years of hands-on security architecture, enterprise architecture, or security engineering experience can apply to waive the CGSL and CPSE certification exam specifically. You'll still complete CGSL and CPSE training in full — the waiver only removes the exam-sitting requirement, since the content itself is what CSAS and every Gloria Institute specialization assumes you know. [Apply for a Waiver →]
The System Wasn't Designed. It Was Accumulated. Somebody Still Has to Own What It Became.
CSAS builds on Foundations. Add CGSL + CPSE now, or apply for a Foundations Exam Waiver if you’ve got the hands-on experience to skip the exam.
