I’m planning my 40 CPEs for 2026 and want them to map directly to NIST CSF 2.0 outcomes and CMMC 2.0 practices, ideally with material I can turn into policy updates and audit-ready evidence. Has anyone found providers or specific courses that explicitly tie learning objectives to regulatory requirements (e.g., SEC cyber disclosures, ISO/IEC 27001:2022 control changes) rather than just general awareness?
SANS SEC566 mapped CSF 2.0/CMMC and ISO 27001:2022 — produced policy/audit artifacts; costly but solid. https://www.sans.org/cyber-security-courses/implementing-and-auditing-cis-controls/.
ISACA’s Implementing NIST CSF using COBIT 2019 paired with CSA’s CCSK gave me CPEs plus mapping matrices I turned into policy updates and ‘audit-ready evidence’ for CSF 2.0 and ISO/IEC 27001:2022… For CMMC 2.0, a Cyber AB LTP workshop (Edwards Performance Solutions) bundled SSP/POA&M templates — better value than SANS, but you’ll still have to map SEC disclosure items yourself, @tpeterson71.
Quick example: I used the NCSP (NIST Cybersecurity Professional) Practitioner from DVMS Institute/APMG (https://apmg-international.com/product/nist-cyber-security-professional), which includes a workbook mapping objectives to the latest NIST CSF outcomes and CMMC practices and lets you export policy drafts and evidence checklists; it covered 24 CPEs, and I filled the rest with a short SEC disclosure update webinar. The “policy-to-control” sheets were plug-and-play enough that audit dropped them straight into workpapers. Caveat: provider quality varies and it’s pricier than webinars, but it’s a two-birds-one-spreadsheet move.
I had good results with the HITRUST Implementer course plus MyCSF mappings — gave me control-to-requirement traceability I dropped straight into “turn into policy updates” and audit evidence for the latest NIST framework, CMMC 2.0, ISO 27001, and even SEC disclosure prep, like a policy kit in a box. Link: https://hitrustalliance.net/training; caveat: the best mapping/export features require a MyCSF subscription, so if that’s a blocker the BSI ISO 27001 Lead Implementer worksheets are a decent fallback.