Certified As Security Sustainability Specialist (CSSS)

Most Security Programs Are Built to Survive the Next Audit. This One Is Built to Stop Needing One.

Engraved illustration of a fortification wall with a fresh crack breaking through an old repaired patch — Gloria Institute CSSS structural sustainability diagnostic

Every large enterprise is running the same unspoken bargain: security teams work harder every year, and the ground underneath them keeps moving anyway. CSSS names the structural reason that bargain never pays off — and teaches you to redesign the conditions that produce it, instead of running the treadmill faster. In April 2026, Anthropic’s Claude Mythos Preview surfaced thousands of zero-day flaws across every major operating system and browser, including bugs 17 and 27 years old — triggering emergency briefings at the U.S. Federal Reserve and Treasury. Latest releases by Anthropic and OpenAI have raised the bar even higher. It confirmed, at the highest institutional level, exactly what this certification was built to diagnose and fix.

Self-paced Online Training
Board-issued Credential
Lifetime Course Access
1-Year Exam Validity
Certified Security Sustainability Specialist (CSSS)
SPECIALIZATION — LEVEL 2
Founding Cohort Price
$999
/
$1,249
Pre-Enroll Before 10/25/26
Save $250

What's Included:

How to Keep Designation Active?

Founding Cohort Begins

28 October, 2026

  • Requires Foundations CGSL + CPSE.
  • Foundations Exam Waiver available for 5+ years’ experience — Learn more.

Most Security Programs Measure Effort. This One Measures Whether the Ground Is Still Moving Under You.

Every large enterprise security function is optimized to run harder — more scans, more audits, more emergency response — without ever asking whether harder effort is closing the gap or just keeping pace with it. It almost never is. Software estates decay in hundreds of directions at once, at different speeds, in ecosystems no single centralized team can see fully. CSSS teaches the diagnostic vocabulary and the structural playbook to tell the difference between a security program that’s holding its ground and one that’s spending everything it has just to look like it is.

This isn’t a framework a vendor built to sell a platform, or a committee assembled to be inoffensive to every stakeholder. It’s the diagnostic language and operating model built by practitioners who spent decades into building and running many Fortune 500 Security Center of Excellence, watching the same structural failure produce the same predictable outcomes across every organization they touched — because nobody had named it yet.

What Sets This Program Apart

Inside-Out, Not Outside-In.

Most security training starts at the control layer — what to implement, what to scan for, what to check. CSSS starts at the structural layer underneath the controls: why rational people, following their own incentives exactly as designed, produce an unsustainable security posture. You learn to redesign the conditions, not just add another control on top of the ones already failing to hold.

Real Incidents, Real Institutional Confirmation.

The curriculum anchors every stage to real, dated events — from Equifax’s unpatched Struts vulnerability to the SolarWinds supply-chain compromise to Anthropic’s April 2026 Claude Mythos Preview disclosure (followed by its subsequent new releases), which surfaced decades-old vulnerabilities at a scale that moved the conversation into Federal Reserve emergency briefings.

A Working Instrument, Not Just a Framework.

You leave with the Tier Inventories — structured, revisit-quarterly self-assessments that convert the diagnostic vocabulary into a live accountability system for your own organization, not a binder that gets read once and shelved.

Vendor-Neutral by Design

No tool, platform, or vendor is recommended anywhere in this framework. It operates at the organizational design and behavioral level — the layer no procurement decision can fix.

Is This Program Right for You?

CSSS builds on the structural literacy and engineering practice CGSL and CPSE establish. You can enroll in CSSS anytime — your CSSS credential requires CGSL and CPSE training complete, and either the Foundations exam passed or an approved Foundations Exam Waiver for qualifying hands-on experience.

You're the one absorbing everything nobody else will own.

Security architects, AppSec engineers, DevSecOps engineers, and Security COE leads carry the accountability for systems they didn’t build, on infrastructure they don’t fully control — CSSS gives you the vocabulary to make that visible and the playbook to change it.

You're a CISO, CTO, or VP running a function that feels like it's always one incident behind.

You know the current model can’t hold. CSSS gives you the structural diagnosis and the tier-specific playbook to build something that can.

You own architecture, governance, or security engineering decisions across a large, multi-language estate.

You’ve felt the specific exhaustion of a unified security process trying to cover an estate that isn’t unified. This names why that never works and what to build instead.

You've completed, or are working through, CGSL and CPSE.

And you’re ready to move from structural literacy and engineering proficiency into the diagnostic and organizational-design layer above them.

You're building toward Certified Software Security Master Practitioner (SSMP).

CSSS combined with a Level 3 Role Specialization credential qualifies you for the SSMP apex.

You've got 5+ years of hands-on security engineering or governance experience already.

You may not need to sit the Foundations exam — see the Foundations Exam Waiver.

PROGRAM OUTCOME

What You'll Learn

14 lessons, each building on the last, moving from naming a structural failure nobody has language for, to running a tier-specific playbook that closes it.

Diagnose structural unsustainability

Apply the 3-condition sustainability test to a real security program and identify exactly which condition is missing.

Map a Polytrophic Decay profile

Score a real, multi-ecosystem estate across its decay velocity, carrying capacity, and integration-point risk, not as a single aggregate number.

Trace an Accountability Vacuum to its source

follow a specific security gap back through the handoffs that laundered its ownership, and identify where a durable accountability model needs to be built.

Run the tier-appropriate playbook

Apply the specific operating-model changes available to your own tier (strategic, operational, practitioner, or engineering), not a generic best-practice checklist.

WHO IS THIS FOR

Built for practitioners who are done running the treadmill faster

CSSS is built for the practitioner who already knows, from direct experience, that the current model produces the same outcome every year regardless of how hard the team runs it — and who’s ready for a structural diagnosis precise enough to actually change that, not another framework that adds one more control to check.

This course is perfect for
This course may not be for you if
  • 6+ real, dated, sourced incidents anchoring the curriculum — from Equifax and SolarWinds to Anthropic’s Claude Mythos Preview disclosure and its subsequent Mythos releases

  • 16 named diagnostic terms forming a precise, testable vocabulary for structural conditions most organizations currently have no language for

  • One instrument you’ll actually use again — the Tier Inventories, built for quarterly return, not a single reading

  • Built from decades of hands-on practitioner experiences — not a framework assembled by committee

14 core lessons with interactive scenarios and a graded knowledge check in each, moving from naming structural failure to running the tier-specific sustainability playbook in your own organization.

What You Will Study

14 core lessons with interactive scenarios and a graded knowledge check each, followed by certification exam eligibility once the course is complete.

Certification Exam

Once you’ve completed all 14 lessons, you’re eligible to sit the certification exam. Use the course companion guide, the ready reckoner handout and the comprehensive study guide, which is available for you to prepare.

Every enterprise security function is running a cycle that was never designed to finish: discover, prioritize, remediate, repeat — without ever reducing the underlying rate of exposure. This lesson names that structural failure precisely, and establishes why more effort inside the current model cannot close the gap.

Sustainable security" gets used constantly and defined rarely. This lesson builds a working, structural definition — a system's ability to keep performing its core function without escalating effort — and applies the 3-condition test that tells you, with precision, how far your organization is from meeting it.

The discover-prioritize-remediate cycle feels productive and produces no ground gained. This lesson maps the physics of why — and why applying a single unified remediation model to a genuinely multi-language estate multiplies the problem instead of solving it.

The 2020 SolarWinds compromise moved through a supply chain where every individual handoff looked defensible. This lesson introduces the Accountability Horizon and traces how legitimate-looking handoffs launder responsibility until it arrives with no identifiable owner.

When the developer who wrote it leaves, the security reasoning behind the code leaves with them. This lesson names the three layers of knowledge — individual, institutional, threat-model — that permanently disappear at that moment, and why documentation rarely recovers it.

In April 2026, Anthropic's Claude Mythos Preview surfaced zero-day vulnerabilities up to 27 years old, sitting undetected through decades of audits and scans. This lesson builds the Decay Velocity model that explains exactly how code like that accumulates unnoticed, and the Decay Hygiene practice that manages it before discovery becomes necessary.

The 2017 Equifax breach exploited a known, unpatched vulnerability inside an organization with a real compliance program and real audits on file. This lesson distinguishes compliance activity that improves actual posture from Security Laundering — genuine-looking activity with no durable connection to the systems that matter.

No single tier created the current dysfunction alone, and no single tier can fix it alone. This lesson maps exactly what each of the four organizational tiers controls, what they can't see from their position, and what changes when the full map is understood.

The institutional confirmation is in: Polytrophic Decay is accumulating, and the window to address it deliberately is measured in months, not years. This lesson makes the case for urgency without relying on fear — grounded in what's structurally true about carrying capacity and compounding exposure.

What organizational design decisions has your organization been treating as someone else's problem that are actually yours to make? This lesson gives CISOs, CTOs, and CIOs the specific measurement-architecture and incentive changes only Tier 1 can authorize.

Strategic intent from the top routinely arrives at engineering as a compliance requirement with the reasoning stripped out. This lesson gives VPs of Engineering and Security, and heads of DevSecOps, the operating-model changes that convert adrenaline response into metabolic, continuous security practice.

Security architects and AppSec engineers absorb everything the rest of the organization won't own. This lesson gives Tier 3 practitioners the path from enforcement posture to genuine partnership with the engineering community — and why that shift determines whether Tier 4 engagement is real or performative.

Every line of code, every dependency, every shortcut under delivery pressure — Tier 4 controls more of the actual security posture than any tier above it, using measurement systems that don't reward it. This lesson gives developers, tech leads, and platform engineers the specific behaviors that make security contribution visible and professionally rational.

Individual tiers acting alone hit a ceiling. This closing lesson shows what changes when all four tiers act on the same diagnostic map at once — and how to sequence that change realistically, given the specific resistance each tier will generate.

Once all 14 lessons and knowledge checks are complete, you're eligible to sit the CSSS certification exam. The exam tests diagnostic application — identifying structural conditions in a realistic scenario and selecting the tier-appropriate response — not framework recall.

OBJECTIVES

The Path To Becoming A Practitioner

CSSS is built to produce a specific, demonstrable capability: the ability to diagnose structural security dysfunction in a real organization and design the tier-appropriate response, not just recognize the vocabulary that describes it.

Diagnose, Don't Just Describe.

Apply the 3-condition sustainability test and the Polytrophic Decay model to a real or realistic estate, and produce a structural diagnosis specific enough to act on.

Map Accountability to Its Actual Source.

Trace a security gap back through the handoffs that dissolved its ownership, and identify the durable accountability structure that would have caught it.

Design the Tier-Appropriate Response.

Select and apply the specific operating-model change available at your own tier — not a generic best-practice recommendation borrowed from a different organizational position.

OVERVIEW

About This Course

CSSS is a Level 2 Field Specialization credential in the Gloria Institute path. CGSL and CPSE training is required for your CSSS credential to issue, alongside a passed Foundations exam or an approved Foundations Exam Waiver. Combined with a Level 3 Role Specialization credential, CSSS qualifies you for the Certified Software Security Master Practitioner (SSMP) apex.

This program was built by a practitioner, not a committee. Its vocabulary — Security Sustainability, the Security Treadmill, Polytrophic Decay, Accountability Laundering, Context Severance — emerged from nearly a decade running a Fortune 100 Security Center of Excellence, watching the same structural conditions produce the same outcomes across different organizations at different scales. It does not evaluate or recommend tools. It operates one level underneath any tool decision, at the level of organizational design and incentive structure that determines whether tools get used the way they were intended to be.

Every stage of the curriculum is anchored to a real, dated, sourced incident — from the Equifax and SolarWinds breaches to the April 2026 Claude Mythos Preview disclosure that moved this framework’s core argument into Federal Reserve emergency briefings. These aren’t decoration. They’re evidence that the structural conditions this program diagnoses are current, not theoretical.

Everything you need to learn security sustainability practice, apply it, and prepare for certification.

Everything you need to learn the application security pipeline, apply it, and prepare for certification.

What's Included

When you enroll, you’ll gain access to the complete interactive course along with the accompanying companion guide. Once you’re prepared, the certification package — which includes the exam voucher and course study guide — will be provided to you as well.

Eligibility & Requirements

CSSS is a Level 2 field specialization credential, positioned directly after the two-course Security Foundation Level.

This course builds directly on the structural literacy and engineering practice established by both foundation courses. Enrollment in CSSS is open regardless of where you are in Foundations, but this content assumes it.

Practitioners with 5+ years of qualifying hands-on security engineering experience may apply to waive the CGSL/CPSE certification exam — Foundations training is still required either way. [See Waiver Eligibility →]

Security engineering, architecture, or governance experience recommended not required, but the course moves at a pace calibrated for someone already working in or near application development, platform engineering, or product security.

Approximately 11-13 hours of core lesson content, plus additional time for exam preparation.

CSSS is designed to satisfy the pathway requirement toward Certified Software Security Master Practitioner (SSMP). As part of the SSMP requirements, participants must successfully obtain a minimum of three Level 2 field-specialization certifications and one Level 3 role-specialization certification.

The Credential That Opens Doors

When you complete a Gloria Institute program, you earn more than just a certificate—you gain recognition for practical, industry-relevant expertise that employers value.

Our certificates are thoughtfully designed to reflect the credibility and quality of our programs. Each credential specifies the specific competencies you’ve mastered, providing clear evidence of your professional development to current and prospective employers. Each Gloria Institute certificate includes:

Sample Certificate

Here’s an example of the certificate you’ll get when you finish a program at the Gloria Institute successfully:

Enrollment, Examination, and Policy FAQs

No. You can enroll in CSSS anytime. To receive your CSSS credential, CGSL and CPSE training must be complete, and you'll need to have passed the Foundations exam or been approved for a Foundations Exam Waiver based on qualifying experience.

Yes. Course enrollment includes the 14 interactive lessons and the free companion guide. A certification exam voucher and a comprehensive student study guide are also part of this course.

Course access details and time limits are set at enrollment — check your specific enrollment terms for exact access duration.

The companion guide, included with enrollment, covers the same material as the course for quick review. The student course study guide is a thorough product built specifically for exam preparation — compressed review, practice questions, and a full mock exam.

The exam voucher comes with a free retake. A mandatory waiting period applies between attempts. Specific retake policy and pricing for additional retakes are detailed at the point of exam voucher purchase.

CSSS was built by Gloria Institute practitioners with decades of combined hands-on security engineering, implementation, and consulting experience — not a certification board working from secondhand case studies. Every concept, practice, and framework in this course was developed and refined through real security work: what worked, what didn't, and what changed after watching the same structural failures recur across other practitioners and organizations.

Not on its own. CSSS is one Level 2 field specialization credential. Combined with a completed Level 3 role specialization credential, it qualifies you for Certified Software Security Master Practitioner (SSPM), Gloria Institute's apex certification.

Practitioners with 5+ years of hands-on secure coding, DevSecOps, or penetration testing experience can apply to waive the CGSL and CPSE certification exam specifically. You'll still complete CGSL and CPSE training in full — the waiver only removes the exam-sitting requirement, since the content itself is what CSSS and every Gloria Institute specialization assumes you know. [Apply for a Waiver →]

The Ground Doesn't Get More Stable Because You Ran Harder This Year. It Gets More Stable Because You Built It to Hold.

CSSS builds on Foundations. Add CGSL + CPSE now, or apply for a Foundations Exam Waiver if you’ve got the hands-on experience to skip the exam.

Early-bird Enrollment Pricing
Scroll to Top