Skip to main content
CYB-0346ExpertCurrent Intake
XCASP

XCASP: Xcademia Advanced Security Practitioner

5-Day Instructor-Led Programme

The XCASP Certification Programme is the practitioner standard for senior security professionals who design enterprise security architectures, govern risk in complex multi-framework environments, lead security operations at programme level, and influence engineering and business decisions as the technical security authority. Assessed on Day 5 through a supervised enterprise security architecture and risk governance scenario. No performance-based exam questions.

Duration

5 Days

Price

$4,994

XCASP: Xcademia Advanced Security Practitioner
Duration
5 Days
Complete in 5 days
Learning Style
Mentor-led, practical and scenario-based
Guided walkthroughs, real-world examples, and applied skills for the workplace.

Course Overview

CompTIA CASP+ (rebranded as SecurityX) is positioned as the advanced practitioner certification for experienced security professionals who are not moving into management. It is a $480 exam including performance-based questions in a timed environment. Even performance-based exam questions cannot replicate the quality of a supervised practitioner scenario assessed by a senior colleague with real enterprise experience. XCASP is built for experienced security professionals who want to demonstrate advanced practitioner capability through actual architecture and governance work.

Across five instructor-led days, XCASP covers enterprise security architecture and engineering, zero trust implementation at enterprise scale, post-quantum cryptography migration planning, AI security architecture and governance, advanced security operations at programme level, enterprise vulnerability management, supply chain security at enterprise scale, multi-framework GRC programme management, and senior practitioner leadership. Coverage extends SecurityX exam objectives to reflect 2026 enterprise security realities.

On Day 5, participants design an enterprise security architecture for a complex simulated organisation and navigate a multi-framework governance scenario requiring applied knowledge across all domains simultaneously. A senior practitioner assesses architectural quality, risk judgement, and governance decisions. XCASP certificate and Practitioner Assessment Report issued. Aligned with CompTIA SecurityX/CASP+ objectives, SABSA enterprise security architecture, NIST SP 800-207 Zero Trust, NIST PQC FIPS 203/204/205, NIST AI RMF, NIST CSF 2.0, and DoD 8140.

Hands-On Learning

Applied enterprise architecture design exercises, zero trust implementation planning, post-quantum migration roadmap, AI security governance design, supply chain security programme design, multi-framework GRC compliance planning, and a full architecture scenario on Day 5.

Mentor-Led Sessions

Mentor-led sessions from senior security architects examining real enterprise security architecture decisions, zero trust implementation trade-offs, supply chain security programme governance, and regulatory complexity at enterprise scale in UK, EU, and US contexts.

Career-Ready Skills

Design and govern enterprise security architectures at senior practitioner level, applying advanced risk management, zero trust principles, AI security governance, post-quantum planning, and multi-framework regulatory compliance across complex environments.

Learning Outcomes

Design enterprise security architectures using SABSA methodology, NIST CSF 2.0, and NIST SP 800-207 Zero Trust at scale for complex multi-environment organisations

Plan post-quantum cryptography migration using NIST FIPS 203, 204, and 205 published August 2024 and design cryptographic inventory for enterprise migration readiness

Govern enterprise vulnerability management, attack surface management, and supply chain security programmes at programme director level

Manage multi-framework regulatory compliance across ISO 27001, SOC 2, PCI DSS, DORA, NIS2, and UK GDPR simultaneously in complex enterprise environments

Design and govern AI security architecture including LLM deployment, RAG pipeline, and agentic AI governance aligned to NIST AI RMF and EU AI Act Article 9

Exercise technical authority as the senior security practitioner: architectural decision governance, cross-functional influence, and executive risk communication

Prerequisites

1

Minimum 5 years of technical security experience in security architecture, security engineering, or senior security practitioner roles

2

Working knowledge of at least three major security frameworks: NIST CSF 2.0, ISO 27001, NIST SP 800-53, or enterprise security architecture frameworks

3

Demonstrated experience with enterprise security architecture, advanced risk management, or complex GRC programme delivery

Detailed Syllabus

Organized by professional domains with comprehensive coverage

Topics Covered:
  • SABSA enterprise security architecture: Security Control Framework application and architecture traceability
  • TOGAF for security architects: security in enterprise architecture governance and ADR (Architecture Decision Records)
  • Security architecture patterns: hub-and-spoke, distributed, and federated for different organisational models
  • Security architecture review board design: governance, membership, escalation rights, and decision authority
  • Security architecture for M&A: integration security assessment, Day 1 security controls, and architecture harmonisation
Stage 5Final Capstone

XCASP: Xcademia Advanced Security Practitioner — Capstone Project

On Day 5, participants design a comprehensive enterprise security architecture for a complex simulated organisation undergoing cloud migration, AI system deployment, and multi-jurisdictional regulatory compliance simultaneously. They must produce an architecture decision record covering zero trust implementation, cryptographic modernisation roadmap, AI security controls, and supply chain security policy. The senior practitioner assesses architectural quality, technical authority, and cross-domain integration throughout.

Assessed by a senior Xcademia practitioner

Framework Alignment

This course is mapped directly onto the standards your organisation already answers to. No invented frameworks, no proprietary jargon.

  • CompTIA SecurityX/CASP+

    Global

    All CASP+ domain content in depth with SecurityX rebranding reflected and content extended beyond exam scope

  • SABSA

    Global

    Sherwood Applied Business Security Architecture: enterprise architecture methodology throughout Days 1 and 2

  • NIST SP 800-207

    Global

    Zero Trust Architecture: ZTA implementation at enterprise scale throughout

  • NIST PQC FIPS 203/204/205

    Global

    Post-quantum standards published August 2024: migration planning in emerging technology module

  • NIST AI RMF

    Global

    AI Risk Management Framework: all four functions applied to enterprise AI security architecture

  • NIST CSF 2.0

    Global

    All six functions at programme-level governance perspective across all domains

  • DORA Articles 28 to 44

    Global

    ICT third-party and supply chain risk management: supply chain security module alignment

  • DoD 8140

    Global

    US defence workforce framework: senior technical cybersecurity role categories referenced throughout

Skills You'll Gain

Master these in-demand skills through hands-on practice

Enterprise security architecture (SABSA)Zero trust at scale (NIST 800-207)Post-quantum cryptography planning (FIPS 203/204/205)AI security architecture (NIST AI RMF)Advanced GRC programme managementSupply chain security programmeRisk-based vulnerability managementSOC programme governanceStrategic threat intelligenceMulti-framework regulatory complianceDORA Articles 28 to 44Technical leadership and authority

Career Progression

A clear view of the roles this programme supports, what typically comes next, and where learners progress over time

Senior Security ArchitectEnterprise Security EngineerLead Security ConsultantSecurity Technical ArchitectPrincipal Security AnalystSecurity Programme Technical Lead
Flexible Delivery Options

Ways to Learn

Choose the learning format that works best for you and your team

Book Now

Live Online

Instructor-Led Training

Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.

5 Days
Small cohorts
  • Live instructor interaction (real-time)
  • Trainer-led walkthroughs and real examples
  • Guided resources and session notes provided
  • Structured Q&A and practical discussion

Price per person

$4,994+ VAT

Group enrolments and early planning options available.

All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.

Premium Training Option

Prefer a Faster, Personalised Route into IT?

Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.

Personalised XCASP: Xcademia Advanced Security Practitioner learning plan
Tailored to your pace and goals
Live 1-to-1 sessions
With an experienced mentor
Real-world troubleshooting
Practice, not just exam theory
Flexible scheduling
To fit around work, study, or family

"Many learners choose 1-to-1 when they want understanding, not memorisation."

Exam & Certification Information

Everything you need to know about the certification exams

Xcademia Certification Programme

Xcademia Certification Programme

On successful completion of XCASP: Xcademia Advanced Security Practitioner, learners are assessed on the final day through a supervised practitioner scenario. Three outcomes are possible, Certificate Awarded, Certificate Deferred, or Not Awarded. The Practitioner Assessment Report and certificate are issued together. Verified at xcademia.com/verify.

Certificate Awarded

Assessed competent on the final day.

Certificate Deferred

Resit available on a future cohort.

Not Awarded

Attendance record issued. Reassessment possible.

Frequently Asked Questions

Everything you need to know about this course

SecurityX is a $480 exam including performance-based questions in a timed environment. XCASP is 5 instructor-led days with a senior practitioner present throughout, assessed on Day 5 through a real enterprise architecture and governance scenario. The Practitioner Assessment Report documents what was designed and decided, not a timed exam performance score. XCASP content is also significantly broader than the SecurityX exam objectives.

Share:

Ready to Start Your Learning Journey?

Take the next step in your professional development

Digital certificate upon completion
Comprehensive course materials
Expert instructor support
Flexible learning options