Aligning CPEs with NIST CSF 2.0 and CMMC

I’m planning my 40 CPEs for 2026 and want them to map directly to NIST CSF 2.0 outcomes and CMMC 2.0 practices, ideally with material I can turn into policy updates and audit-ready evidence. Has anyone found providers or specific courses that explicitly tie learning objectives to regulatory requirements (e.g., SEC cyber disclosures, ISO/IEC 27001:2022 control changes) rather than just general awareness?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‌​⁠‌‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍​⁠​⁠‌​‍​‌​​⁠‌‍​‍‌‍⁠⁠‌‍‍⁠‌⁠‌⁠‌​⁠‌​⁠​‍​⁠‍‌‌​⁠‌‌​‍⁠‌​​‌​⁠​⁠‌‌‍‌‌‌​‌​‍​‍‌⁠⁠‌​

SANS SEC566 mapped CSF 2.0/CMMC and ISO 27001:2022 — produced policy/audit artifacts; costly but solid. https://www.sans.org/cyber-security-courses/implementing-and-auditing-cis-controls/.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‍‌​⁠​‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‌​⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍​⁠​‍‌​​‌‌​‌​‌‌‍​‌‍⁠‌‌⁠‍‌‌‌​‌‌‍‍‍‌⁠​‍​⁠​‍‌‌‌⁠​⁠​⁠​‍⁠‌‌​⁠⁠‌⁠‌‍​⁠​‌​‍​‍‌⁠⁠‌​

ISACA’s Implementing NIST CSF using COBIT 2019 paired with CSA’s CCSK gave me CPEs plus mapping matrices I turned into policy updates and ‘audit-ready evidence’ for CSF 2.0 and ISO/IEC 27001:2022… For CMMC 2.0, a Cyber AB LTP workshop (Edwards Performance Solutions) bundled SSP/POA&M templates — better value than SANS, but you’ll still have to map SEC disclosure items yourself, @tpeterson71.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‍‌​⁠​‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‌​⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍⁠⁠‌‍‌⁠‌⁠​​‌​‌‍‌‌⁠⁠‌⁠‍‌‌‍⁠⁠‌​⁠‌‌‌⁠⁠‌‍‍⁠‌⁠‌​‌‌‌‍‌​‌⁠‌⁠​⁠‌‍​‌‌⁠‍‌​‍​‍‌⁠⁠‌​

Quick example: I used the NCSP (NIST Cybersecurity Professional) Practitioner from DVMS Institute/APMG (https://apmg-international.com/product/nist-cyber-security-professional), which includes a workbook mapping objectives to the latest NIST CSF outcomes and CMMC practices and lets you export policy drafts and evidence checklists; it covered 24 CPEs, and I filled the rest with a short SEC disclosure update webinar. The “policy-to-control” sheets were plug-and-play enough that audit dropped them straight into workpapers. Caveat: provider quality varies and it’s pricier than webinars, but it’s a two-birds-one-spreadsheet move.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‍‌​⁠​‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‍​⁠​‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​​‍‌⁠‌⁠‌​​‌​‍⁠‌‌​⁠‌‌‍‍​‌​‌‌‌​⁠‍​⁠​​‌⁠‌​‌​‍‍‌⁠‌​‌⁠‍‍‌‍⁠‍‌‍​‌‌​‌​​‍​‍‌⁠⁠‌​

I had good results with the HITRUST Implementer course plus MyCSF mappings — gave me control-to-requirement traceability I dropped straight into “turn into policy updates” and audit evidence for the latest NIST framework, CMMC 2.0, ISO 27001, and even SEC disclosure prep, like a policy kit in a box. Link: https://hitrustalliance.net/training; caveat: the best mapping/export features require a MyCSF subscription, so if that’s a blocker the BSI ISO 27001 Lead Implementer worksheets are a decent fallback.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‍‌​⁠​‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‍​⁠‌​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​​‍‌‍‍​‌​‌‍​⁠‌‍‌⁠‌‌‌‌‌⁠‌​‌‌‌‍​‌‌⁠‌⁠‌​‌‌‌⁠‍‍‌⁠‌‌‌​‌‌​⁠​​‌⁠‌​‌⁠​‌​‍​‍‌⁠⁠‌​