Learning roadmap

From free training to credentials people can trust

The training library is only the first stage. This page shows what comes next, what has to be true before each stage ships, and where independent reviewers can challenge the work.

Current truth

The training library is live. Course mode, completion certificates, skills credentials, independent recognition, and accreditation are not.

What ships next

The roadmap, in dependency order

Each stage depends on the one before it. Dates will be added when the underlying work is scoped well enough to make them meaningful.

  1. 01

    Training library

    Interactive command-line and security labs are live and free to use. They do not currently award a certificate or credential.

    Complete
  2. 02

    Structured course paths

    Define versioned outcomes, lesson sequences, practice requirements, and claim limits for CLIP, CLIO, and CLIA.

    In progress
  3. 03

    Completion records

    Add course mode and verifiable completion certificates once the course contracts and completion rules are frozen.

    Not started
  4. 04

    Independent skills assessment

    Build separate assessment forms, frozen rubrics, blinded evidence, trained raters, and an appeals process before issuing skills credentials.

    Not started
  5. 05

    External recognition

    Pursue independent recognition or accreditation only after the programs have operating evidence and qualified outside review.

    Not started

Review & assurance

Help verify the program

Inspect what each program intends to teach, the evidence behind it, the limits on each claim, and the work still open to qualified reviewers. A stage moves only when its evidence exists. Automated validation can support a human review, but it cannot impersonate one.

Public

Claims, outcomes, versions, review state, approved summaries, limitations, and change history.

Protected

Answer keys, seeds, source artifacts, private findings, learner transcripts, ratings, appeals, and deliberation.

Never inferred

Solvable does not mean pedagogically sound. Complete does not mean competent. Mapped does not mean endorsed.

Program register

Proposed course families

CLIP supplies one shared command-line foundation; learners can then continue toward offensive work through CLIO or defensive analysis through CLIA. Many certifications survey a broad domain. This program is intentionally narrower: CLI-first practice, deterministic labs that can be reproduced and audited, and a clear claim boundary for each path.

clip-course-v0.1.0

Command Line Practitioner (CLIP)

In progress
Intended claim

Performs foundational command-line work in a controlled Linux security lab.

Draft completion claim

Completed the required learning activities for the named version of Command Line Practitioner.

Course contract
review ready
Assessment blueprint
clip-assessment-v0.1
Completion certificate
not shipped
Skills credential
not shipped
Evidence reviewed
2026-07-26
Content review
0 of 51 targets fully approved
Stale review targets
0
Outcomes and present coverage
clip-01 · supported

Navigate an unfamiliar Linux filesystem and locate relevant files without a worked command path.

clip-02 · partial

Inspect users, permissions, processes, services, and system state and cite the evidence supporting a conclusion.

Current tasks emphasize discovery more than permission changes, signals, or service operations.
clip-03 · partial

Compose shell text-processing steps and independently discover appropriate command options.

Quoting, redirection, structured data, and independent man-page use need deeper coverage.
clip-04 · supported

Complete and debug a small program that transforms unfamiliar input data and handles failure explicitly.

clip-05 · partial

Enumerate network services, establish authorized remote access, and distinguish credential and encoding risks.

Current labs do not yet collect enough professional explanation or remediation evidence.
In progressAuthored

The training library and draft outcome blueprint exist; learner-facing course mode is not yet frozen.

Not startedTechnical review

Automated validation is not a named human technical approval.

Not startedPedagogical review

A qualified instructional-design reviewer has not approved the course.

Not startedAssessment-design review

The outcome blueprint and any independent forms still require specialist review.

Not startedPiloted

No operational learner pilot or standard-setting evidence exists.

Not startedApproved L0

No completion certificate is issued.

Not startedApproved L1

No skills credential is issued.

Not startedIndependently accepted

No outside organization has yet documented reliance on the credential.

Not startedAccredited

CLI-Games does not claim accreditation.

Human review

Linux and security technical reviewOpen
Instructional-design and pedagogy reviewOpen
Assessment-design reviewOpen

Independent assessment forms

clip-form-aprototype; automated validation passing

Human review not started. No cut score. Not credential eligible.

Claim limits

  • The current library is training, not a certification exam.
  • Framework mappings are drafts and do not imply NICE, employer, government, or accreditor approval.
  • Automated scenario and solver checks establish consistency and solvability, not teaching quality or occupational competence.
  • CLIP Form A is a design prototype with no cut score, pass/fail result, or credential authority.

clio-course-v0.1.0

Command Line Operator (CLIO)

In progress
Intended claim

Performs scoped introductory offensive-security testing in a controlled lab.

Draft completion claim

Completed the required learning activities for the named version of Command Line Operator.

Course contract
draft
Assessment blueprint
clio-assessment-v0.1
Completion certificate
not shipped
Skills credential
not shipped
Evidence reviewed
2026-07-26
Content review
0 of 165 targets fully approved
Stale review targets
0
Outcomes and present coverage
clio-01 · gap

Translate an authorization statement into test scope, stop conditions, and a minimally destructive plan.

Course-context rules of engagement are prototyped, but scope decisions are not yet practiced, captured, or assessed.
clio-02 · partial

Enumerate an unfamiliar target and validate representative server-side, client-side, and access-control flaws.

Breadth is strong, but current checks largely preserve teaching topology and answer locations.
clio-03 · partial

Chain authorized access, credential recovery, privilege escalation, and lateral movement while preserving reproducible evidence.

Cleanup, false-positive control, and evidence minimization are not consistently required.
clio-04 · partial

Use static and dynamic evidence to explain a small program behavior relevant to the engagement.

The lab exercises the tooling, but no CLIO scenario collects the evidence-citation or reasoning this outcome requires — clip-capstone-a is currently the only scenario with an assessment form.
clio-05 · gap

Write a concise finding that separates evidence, impact, exploit preconditions, primary remediation, and defense in depth.

Debriefs model parts of a finding, but learners do not yet author or revise one.
In progressAuthored

The training library and draft outcome blueprint exist; learner-facing course mode is not yet frozen.

Not startedTechnical review

Automated validation is not a named human technical approval.

Not startedPedagogical review

A qualified instructional-design reviewer has not approved the course.

Not startedAssessment-design review

The outcome blueprint and any independent forms still require specialist review.

Not startedPiloted

No operational learner pilot or standard-setting evidence exists.

Not startedApproved L0

No completion certificate is issued.

Not startedApproved L1

No skills credential is issued.

Not startedIndependently accepted

No outside organization has yet documented reliance on the credential.

Not startedAccredited

CLI-Games does not claim accreditation.

Human review

Linux and security technical reviewOpen
Instructional-design and pedagogy reviewOpen
Assessment-design reviewOpen

Claim limits

  • The current library is training, not a certification exam.
  • Framework mappings are drafts and do not imply NICE, employer, government, or accreditor approval.
  • Automated scenario and solver checks establish consistency and solvability, not teaching quality or occupational competence.
  • No independent assessment form has been authored for this program.
  • The professional course overlay is specified, but learner-facing course mode and artifact capture are not built.

clia-assessment-v0.1

Command Line Analyst (CLIA)

In progress
Intended claim

Performs introductory Linux-centric defensive analysis and network forensics in a controlled lab.

Course contract
not defined
Assessment blueprint
clia-assessment-v0.1
Completion certificate
not shipped
Skills credential
not shipped
Evidence reviewed
2026-07-26
Content review
not defined
Stale review targets
0
Outcomes and present coverage
clia-01 · partial

Identify evidence provenance, acquisition limits, integrity considerations, time basis, and material gaps before analysis.

The corrected timeline package models provenance, but the discipline is not yet course-wide.
clia-02 · partial

Correlate host, authentication, application, and network evidence into a defensible incident timeline.

Correlation is genuinely exercised, but the objectives are answer flags: no CLIA scenario collects the evidence-citation or reasoning this outcome requires.
clia-03 · partial

Recover and interpret representative filesystem, packet, hidden-data, deleted-file, and program artifacts.

Recovery is well covered; interpretation is not assessed — no CLIA scenario collects the evidence-citation or reasoning this outcome requires.
clia-04 · partial

Triage observed activity, distinguish fact from inference, state confidence, and recommend proportionate response actions.

Containment, eradication, recovery, and escalation decisions need explicit scenarios.
clia-05 · gap

Produce reproducible case notes and a concise technical handoff with limitations and next steps.

Current objectives are primarily answer flags rather than authored case notes.
In progressAuthored

The training library and draft outcome blueprint exist; learner-facing course mode is not yet frozen.

Not startedTechnical review

Automated validation is not a named human technical approval.

Not startedPedagogical review

A qualified instructional-design reviewer has not approved the course.

Not startedAssessment-design review

The outcome blueprint and any independent forms still require specialist review.

Not startedPiloted

No operational learner pilot or standard-setting evidence exists.

Not startedApproved L0

No completion certificate is issued.

Not startedApproved L1

No skills credential is issued.

Not startedIndependently accepted

No outside organization has yet documented reliance on the credential.

Not startedAccredited

CLI-Games does not claim accreditation.

Human review

Linux and security technical reviewOpen
Instructional-design and pedagogy reviewOpen
Assessment-design reviewOpen

Claim limits

  • The current library is training, not a certification exam.
  • Framework mappings are drafts and do not imply NICE, employer, government, or accreditor approval.
  • Automated scenario and solver checks establish consistency and solvability, not teaching quality or occupational competence.
  • No independent assessment form has been authored for this program.

Open review roles

Auditors wanted

Course auditors review the program itself. Attempt raters, when operational assessment eventually exists, will judge blinded candidate evidence against a frozen rubric.

Linux & security

Are the commands, systems, vulnerabilities, explanations, and remediations technically right?

See the opportunity

Instructional design

Do the sequence, practice, feedback, accessibility, and transfer demands help people learn?

See the opportunity

Assessment design

Do the tasks and rubric support the claim without rewarding memorization or answer-sheet access?

See the opportunity
The workbenches exist, but are not public archives.

Invited course auditors receive program-version-specific access to protected evidence and a findings ledger. Attempt raters receive separate, revocable grants and only their blinded assignments. Neither role receives general site administration.