top of page
Stamping Documents

Cybersecurity Architect — Certified Professional License (CPCA)

A professional license for architects who design defensible, measurable, and reviewable cybersecurity architecture and infrastructure.

What Is the CPCA CPL?

The Certified Professional Cybersecurity Architect (CPCA) License

What the license represents

The CPCA CPL recognizes cybersecurity architects who can translate business objectives, technical requirements, cybersecurity risk, and credible threats into secure architecture models, reference patterns, solution designs, and improvement roadmaps across enterprise, cloud, and hybrid environments.

A professional who earns this license can model systems, data flows, identity flows, trust boundaries, interfaces, and dependencies; conduct threat modeling and design risk analysis; select and position appropriate security controls and services; review proposed and existing architectures; recommend risk remediation; and guide implementation teams.

The license represents the demonstrated ability to make and explain sound design decisions, document trade-offs and residual risk, define validation criteria, and communicate architecture clearly to technical and business stakeholders.

What Will I Receive?

Your CPCA Professional Licensing Certification

Your certification is the official record that you have satisfied the qualification and assessment requirements for the CPCA. It displays your name, professional designation, issue date, and unique License ID.

The license is valid for three years and can be independently verified through the ISAUnited public credential registry.

CPL-ARCH_sample1.png

Your CPCA Professional Stamp

The personalized CPCA Stamp is a professional mark issued to each license holder. It identifies the holder by name and signifies demonstrated capability to analyze, design, review, validate, and communicate cybersecurity architecture.

Authorized use of the CPCA Stamp

The CPCA Stamp may be applied to architecture diagrams and packages, design-review records, architecture decision records, technical reports, and other cybersecurity architecture documents prepared or approved by the license holder.

Use of the stamp signifies professional accountability for the architecture work and adherence to ISAUnited licensing requirements and its Code of Ethics. It does not represent organizational approval, regulatory certification, or acceptance of risk unless the license holder has been separately granted that authority.

AE Stamp Sample BLKbkg.png

Who Is This CPL For?

Designed for Experienced Practitioners

The CPCA is intended for cybersecurity and technology professionals who design, review, or guide the security of enterprise systems. Candidates do not need to already hold the title of Cybersecurity Architect, but should have a strong technical foundation and experience working with architecture diagrams, security requirements, threat modeling, design risk, security controls, and technical design decisions.

NOTE: The CPCA is a professional-level credential and is not intended as an entry-level cybersecurity certification.

Cybersecurity and Security Architects

Professionals responsible for enterprise-wide or solution-level cybersecurity architecture.

Architect Drafting Plans

Enterprise and Solution Architects

Architects whose responsibilities include translating cybersecurity requirements and risk into secure technical designs.

Architects Reviewing Plans

Specialized Security Architects

Cloud, application, product, identity, data, network, platform, and infrastructure architects seeking broader cross-domain architecture capability.

Image by Desola Lanre-Ologun

Senior Security Engineers and Technical Leaders

Experienced practitioners transitioning into architecture or directly responsible for security design, architecture reviews, and implementation guidance.

Office employee

Why Should I Earn It?

Demonstrate Applied Security Architecture Capabilities

The CPCA gives experienced professionals a way to demonstrate that they can perform cybersecurity architecture work in a realistic scenario. It recognizes applied design judgment—how you interpret requirements, analyze threats and design risk, make architecture decisions, position security controls, explain trade-offs, and define validation—not just knowledge recall.

Demonstrate Applied Capability

Show that you can analyze, design, review, and communicate cybersecurity architecture through professional work products.

 

Strengthen Your Professional Credibility

Use the CPCA designation and professional stamp to identify your demonstrated architecture capability and accountability.

 

Make Your Achievement Verifiable

Provide employers, clients, and professional peers with a unique License ID that you can confirm through the public credential registry.

 

Support Your Career Development

Document your readiness for cybersecurity architecture, security architecture, principal-level, consulting, and technical design leadership opportunities.

How Can I Earn It?

Two ways to earn your license.

Earn CPL

Path 1 — Attend ISAU Academy (recommended)

Learn the method, then earn the license:

  1. Enroll in the Pro Bundle (course + ebook + one evaluation)

  2. Complete the self-paced modules (knowledge checks; non-heavy)

  3. Submit your capstone portfolio (principles, models, methods in use)

  4. Panel review & decision (up to 14 days for course completion)

NOTE: 20 CPEs awarded automatically for course completion.

Path 2 — Direct Evaluation (for experienced practitioners)

Already fluent in the concepts and methods? Bypass the course and go straight to the cyber capstone portfolio:

  • Brief eligibility check (experience + example artifacts)

  • Cyber Capstone portfolio submission and panel review

  • Same license, same stamp, same public verification

NOTE: 0 (zero) CPEs will be awarded for not completing the course.

What Is the CPL Assessment?

A Cyber Capstone Completed Through FlexCert 30

The certification exam isn't a traditional multiple-choice, memorization-based test. Instead, you complete a real-world, scenario-based Cyber Capstone that reflects the work cybersecurity practitioners do.

You will analyze a realistic organization and technical environment, identify security requirements and design risks, develop a secure architecture, recommend risk remediation, explain your design decisions and trade-offs, and define how to validate the architecture.

What You Will Submit

Your Cyber Capstone includes five connected professional work artifacts:

  1. Architecture Context and Requirements Brief

  2. Threat Model and Design Risk Analysis

  3. Target Security Architecture Package

  4. Security Design Rationale and Implementation Guidance

  5. Architecture Validation and Executive Decision Brief

 

Complete It Through FlexCert 30

FlexCert 30 is the remote, independent format for completing your Cyber Capstone. You receive a controlled professional scenario, instructions, and submission templates, then have 30 days to develop and submit your work.

 

Complete the assessment on your own schedule without traveling to a testing center, scheduling a fixed examination appointment, or participating in live remote proctoring.

Thirty days. Independent completion. Your schedule.

How Will I Be Evaluated?

Your Cyber Capstone Artifacts Work Is the Evidence

Trained evaluators review your five Cyber Capstone artifacts as one connected architecture submission. The evaluation considers whether your requirements, threat analysis, architecture models, security controls, design decisions, validation approach, and professional communication are clear, technically sound, and consistent.

Part 1 — Technical Artifact Evaluation

This section determines whether you have passed the technical requirements of the Cyber Capstone.

 

Evaluators assess:

  • Architecture context and security requirements

  • Architecture models, data flows, and trust boundaries

  • Threat modeling and design risk analysis

  • Security patterns and control placement

  • Design decisions, trade-offs, and risk remediation

  • Technical feasibility and implementation guidance

  • Validation criteria and professional communication

Part 2 — Professional Capability Profile

We also use your submission to develop a separate Skills, Knowledge, and Abilities Capability Profile. This evidence-based profile evaluates your professional reasoning, technical judgment, disciplined practice, problem-solving, and communication across seven capability dimensions.

 

The profile shows how you performed, where you demonstrated strength, and where continued professional development may be beneficial.

 

 

Your Evaluation Outcome

After the review is completed, you receive a Defensible Capability Score Report containing your technical results, professional capability profile, evaluator findings, and licensing decision.

Candidates who successfully satisfy the technical and professional requirements are awarded the CPCA License and entered into the public credential registry.

Image by Bench Accounting

Ready to Demonstrate Your Architecture Capability?

bottom of page