← All 186 courses
SEC-306 Security

Cryptographic Agility Engineering

Build systems that can change cryptographic algorithms without a redesign. Learners abstract primitives behind versioned envelopes, automate certificate and key lifecycles, deploy hybrid key exchange through TLS and PKI, and confront the HSM, KMS and payload-size realities that break naive migrations. Every design decision is tested against a rollback scenario where the new suite has to be withdrawn in production.

B4Professional
6modules
42skill atoms
3role journeys
Curriculum

What this course covers.

6 modules, 42 named skill atoms. Expand any module to see them.

1Agility By Design7 skill atoms
crypto abstraction layersalgorithm identifiers carried in protocols and formatsversioned message envelopesnegotiation vs pinned configurationno hardcoded key, digest or nonce sizesfeature-flagged algorithm rollouta rollback path when a suite fails
2Certificate & Key Lifecycle Automation7 skill atoms
ACME issuance at fleet scaleshort-lived certificate strategyrotation without downtimedual-chain and dual-certificate servinginventory-driven expiry alertingCA agility and trust store updatesrotation runbooks with blast-radius limits
3Hybrid Key Exchange7 skill atoms
hybrid groups such as X25519MLKEM768TLS 1.3 key share negotiationdowngrade and fallback handlingmiddlebox intolerance to large ClientHellopost-quantum options in SSH and IKEv2migration order across VPN and mesh transportan interoperability test matrix
4PKI Migration Mechanics7 skill atoms
parallel PQC hierarchycomposite vs pure certificateschain size and path-building limitsOCSP and CRL impact of larger signaturescode signing and firmware trust anchorstrust store rollout across fleets and appliancesstaged cutover with a tested rollback
5HSM, KMS & Key Custody7 skill atoms
firmware support for ML-KEM and ML-DSAkey wrapping and export constraintsFIPS 140-3 validation lagcloud KMS algorithm availabilitykey ceremony and custody changesthroughput and capacity planningvendor roadmap dependency risk
6Performance & Payload Reality7 skill atoms
handshake size growthextra round trips and initial congestion window effectslatency on mobile and satellite linksCPU cost on constrained devicesrecord and datagram fragmentation limitshonest benchmark methodologybudgeting the regression with stakeholders
Where it fits

SEC-306 in the role journeys.

This course appears in 3 of our 45 role journeys. Here is what a learner takes immediately before and after it in each.

Security Engineer

Professional stage
SEC-404SEC-306SEC-405

AppSec Engineer

Professional stage
SEC-404SEC-306SEC-501

Cryptography / PQC Engineer

Professional stage
SEC-104SEC-306SEC-207

Roles this course serves

The capability ladder

This course is authored to band B4.

Every course we run is written to one rung of the CASI ladder, so a plan can be assembled to take a team from where they are to where they need to be.

What do B1–B6 mean?The CASI Capability Ladder — click to expand

Every course targets a band on the CASI Capability Ladder — our six-band proficiency scale, anchored to open standards (O*NET, ESCO, NICE, NIST AI RMF, Bloom's). A band tells you how deep a course goes, and what evidence proves it.

What the learner can doTypical evidence
B1
AwareUnderstands concepts and vocabulary; uses tools with guidance
Knowledge checks
B2
FoundationPerforms standard tasks correctly in familiar contexts
Guided labs, autograded exercises
B3
PractitionerDelivers complete pieces of work independently
Scenario labs, proctored hands-on exams
B4
ProfessionalHandles production-grade complexity, trade-offs and failure modes
Break-fix drills, design defenses
B5
AdvancedEngineers systems end-to-end under constraints; leads others
Rubric-scored capstones, vivas
B6
ExpertSets direction; recognised authority across teams
Portfolio + panel evaluation

A note on B6. Courses in this catalog target B1–B5. B6 is not taught — it is recognised, through a portfolio and a panel, once someone is setting direction for others. Every journey here is built to land a learner at B5.

Next step

Run SEC-306 for your team.

This course runs at several lengths depending on how deep you need to go and how much of it your people already have. Tell us who is being trained and we will scope it.

Add it to a training plan Talk to our team Check your team’s level free