ServicesSSSC Platform
For Defense & Regulated Organizations · NIST 800-171 · DFARS · CMMC-ready

Prove Your Team's Security Competence, Continuously

SSSC turns daily 60-second micro-learning into an audit-ready record of ongoing competency: the security awareness training and evidence you're required to keep for protecting CUI under NIST 800-171 (DFARS 252.204-7012), and ready whichever way CMMC reform lands.

Requirements change. Your evidence shouldn't have to be rebuilt.

19
Certificate Programs
Daily
Audit-ready evidence
12
Awareness Domains
60s
a day
CUI Handling · Evidence log
NIST 800-171

Which marking applies to Controlled Unclassified Information?

Progress68%
85%
72%
68%
55%

How It Works

Daily reinforcement that builds real competence and captures the evidence automatically.

Assess

60 seconds

Daily micro-assessments personalized to your role and knowledge level.

Learn

Instant feedback

AI-powered explanations and contextual learning tailored to your answers.

Track & Certify

Audit-ready evidence

Certificates, live dashboards, and audit-ready reports that prove ongoing competency.

The Science

Built on how memory actually works

Security knowledge doesn't fail because people don't care. It fails because memory fades. SSSC is built on three of the most reproduced findings in learning research.

Spacing

The same lesson spread over time is remembered far better than one long session, confirmed across a meta-analysis of 300+ experiments.

Cepeda et al., Psychological Bulletin (2006)

Retrieval practice

Answering a question beats re-reading. Learners who recalled material kept 61% after a week vs. 40% who re-studied.

Roediger & Karpicke, Psychological Science (2006)

Microlearning

Short daily lessons fit real schedules and move knowledge into long-term memory, with measurable gains in on-the-job behavior.

Microlearning meta-analysis (industry research, 2025)
The security proof

It isn't just general learning theory. A field study of 409 employees found anti-phishing training faded within four to six months without reinforcement (Reinheimer et al., SOUPS 2020), and a 2025 UChicago / UC San Diego study found annual awareness training showed no measurable reduction in phishing failures (Ho et al., IEEE S&P 2025). Continuous, interactive training is what actually reduces risk, which is how SSSC is designed.

One platform, three tracks

Awareness, compliance, and deep technical skill

Two tracks live today; a third for security professionals on the way. All built on the same daily, evidence-generating engine.

Live
Primary track

Compliance Training Certificates

Mandate-specific training certificates for regulated and defense organizations, with audit-ready evidence.

19 certificate programs
Live
Reinforcement track

Daily Awareness

60-second daily micro-learning that builds everyday security instincts across the whole workforce.

12 categories · 52 topics
Coming soon
For technical teams

Specialized Technical / Expert Track

Deep, role-targeted training for developers, engineers, and security professionals: expert-level scenarios, secure coding, and sequenced learning paths.

7 technical domains · in development
Primary track · Live

19 training certificate programs for regulated organizations

Certificates are earned by demonstrating knowledge over time, not by clicking through slides. After a year, a user's history is a verifiable record of genuine ongoing competency.

Defense & Classified Information

Controlled Unclassified Information (CUI)

CMMC L2NIST 800-171

Operations Security (OPSEC)

NIST

ITAR / EAR Export Control

DFARS

Counterintelligence Awareness

DoD

Derivative Classification

EO 13526

Foreign Travel Security

DoD

Insider Threat Awareness

NIST
Cyber Threats & Incident Response

Phishing Awareness

Social Engineering Awareness

Business Email Compromise (BEC)

Ransomware Awareness

Incident Response Awareness

Privacy & Data Handling

PII & Privacy Handling

Physical Security Awareness

Remote / Telework Security

Workplace & Conduct

Active Shooter / Workplace Violence

Sexual Harassment Prevention

Ethics & Standards of Conduct

Annual Security Awareness

PCI 12.6NIST
Compliance

Mapped to the standards you're actually held to

Every assessment and certificate maps to the awareness & training controls your auditors look for, across the frameworks that govern your contracts.

Backed today
NIST SP 800-171
3.2.1–3.2.3 Awareness & Training · the DIB/CUI baseline
DFARS 252.204-7012
Safeguarding CUI · the contract obligation
NIST 800-53 Rev 5
AT-2 · AT-3 · AT-4
NIST CSF 2.0
PR.AT-01 · PR.AT-02 · GV
ISO/IEC 27001:2022
A.6.3 Awareness & Training
CMMC 2.0
L1–L3 · AT.L2-3.2.1 / 3.2.2 · aligned to 800-171
Expanding
PCI DSS v4.0
Req 12.6.1–12.6.3
HIPAA
§164.308(a)(5)
FERPA
34 CFR §99
CIPA
Internet-safety education
Built for regulatory change. CMMC is being reformed, but the underlying obligation to train and prove it (NIST 800-171 / DFARS) isn't going anywhere. SSSC's continuous-evidence record holds up whichever way the rules land.

Supports your NIST RMF process via NIST 800-53. SOC 2 and GLBA Safeguards Rule are expanding alongside the frameworks above.

Live capability

Daily threat intelligence, tailored to each role

SSSC pulls live CISA KEV and NVD feeds every day and turns them into persona-tailored security recommendations on each user's dashboard, so training reflects the threats that are active right now, not last year's course.

Live feeds

CISA Known Exploited Vulnerabilities + NVD CVE data, refreshed daily.

Persona-tailored

Recommendations matched to each user's role and profile, priority-ranked.

Sourced & timely

Every item links its source and shows an expiry, so there's no stale advice.

Reinforcement track · Live

12 categories, 52 topics of everyday security awareness

The daily micro-learning layer that keeps every employee sharp. It's the reinforcement beneath the certificates.

01

Passwords & Authentication

4 topics
Strong passwords
Password managers
MFA
Reuse risks
02

Phishing & Social Engineering

4 topics
Phishing emails
Social engineering
Safe attachments
Tech support scams
03

Safe Internet Habits

5 topics
Safe shopping
Fake websites
Tracking & cookies
Oversharing
Deepfakes
04

Device Security

4 topics
PIN & biometrics
Malware signs
App permissions
Data backups
05

Wi-Fi & Home Networks

4 topics
Public Wi-Fi
VPN use
Home Wi-Fi
IoT & router security
06

Identity & Financial Safety

4 topics
Identity theft
Credit monitoring
Card protection
Romance scams
07

Online Fraud & Scams

4 topics
Crypto scams
Investment fraud
Tax scams
Benefits fraud
08

Data Protection

4 topics
Device encryption
Cloud storage
Document shredding
Device disposal
09

Workplace & Remote Work

4 topics
Home office security
Video conferencing
Insider threats
Travel security
10

Physical & Everyday Awareness

4 topics
Tailgating
Shoulder surfing
Device security in public
Reporting threats
11

Family & Children

4 topics
Children's privacy
Cyberbullying
Harmful apps
Family digital safety
12

Big Picture Security

7 topics
Ransomware
USB safety
Disinformation
Secure browsing
Security mindset
Travel tips
Year in review
Platform

Built for teams. Designed for people.

AI-Adaptive Scoring

Machine learning adjusts question difficulty based on individual performance

Compliance Mapping

Automatic alignment with NIST, ISO, and CMMC requirements

Admin Dashboard

Real-time team progress, export reports, role-based access

Capability

Personalized to every role

Assessments adapt to each person's job function, helping satisfy role-based training requirements (NIST AT-3), with risk scoring and role-based gap analytics for the compliance owner.

General UserManagerExecutiveDeveloper / EngineerSystem AdminCloud AdminHelp DeskSecurity TeamFinanceHRData Owner / DPOIncident Response
Coming soon · for technical teams

Specialized Technical / Expert Track

Deep, role-targeted training for the people who build and defend your systems: SOC analysts, pen testers, cloud security engineers, incident responders. Expert-level scenarios, secure coding, sequenced learning paths, and completion certificates.

Authentication

NIST IA-5

Data Privacy

NIST SI-12

Network Security

NIST SC-7

Access Control

NIST AC-6

Secure Coding

NIST SA-11

Email & Phishing

NIST AT-2

Social Engineering

NIST PS-3

Be first in line →

Join the waitlist for early access to the Expert Track.

Pricing

Plans for every organization

Transparent pricing with no hidden fees. All plans include a 14-day free trial.

Government

Federal agencies and defense contractors

Contact
for pricing · agencies & contractors
Contact Sales
  • Contractors: NIST 800-171 · CMMC 2.0 · DFARS
  • Agencies: FISMA · NIST RMF · NIST 800-53
  • Audit reports & evidence export
  • SAML SSO (coming soon)
  • Admin dashboard

Education

Schools, districts, and universities

Contact
for pricing · K-12 & higher ed
Contact Sales
  • K-12: FERPA · CIPA · COPPA
  • Higher ed: FERPA · GLBA Safeguards Rule
  • Staff & faculty training + evidence
  • LMS integration
  • District / campus admin controls
Most Popular

SMB

Most Popular for fast-growing companies

Contact
for pricing
Contact Sales
  • One program → many frameworks: SOC 2 · PCI · HIPAA · ISO 27001 · NIST CSF
  • Documented, audit-ready evidence: proof you trained, not just a claim
  • AI-personalized assessments
  • Slack & Teams integration

Enterprise

Custom solutions for complex organizations

Contact
for pricing
Contact Sales
  • Custom training programs
  • Custom question libraries
  • HRIS / SIEM integration
  • White-label platform
  • SLA & dedicated support
Enterprise Training

Security training built around
your organization

Every organization has unique roles, risks, and compliance obligations. Our custom training programs are designed from the ground up around your specific environment, not off-the-shelf content retrofitted to fit your team.

Talk to Us About Custom Training

Role-Based Tracks

Separate learning paths for executives, IT staff, general employees, and privileged users.

Industry-Specific Content

Scenarios and examples drawn from your sector: government, finance, healthcare, education.

Custom Question Libraries

Upload your own policies and procedures. SSSC generates assessments directly from your documentation.

Compliance-Mapped Curriculum

Training objectives mapped to your active frameworks: NIST 800-171, CMMC 2.0, NIST 800-53, ISO 27001, or HIPAA.

Need a custom plan? Let's talk about your organization's unique needs.

Contact Sales

Common questions

Can't find the answer you're looking for? Reach out to our support team.

SSSC + Awareness Programs = Maximum Impact

SSSC is powerful on its own, but it's even more effective as the reinforcement engine inside a managed awareness program. Pair the platform with Tiamat's program design and management services for a complete, audit-ready solution.

See Awareness Program Services →
Get Started

Build your security culture starting tomorrow

14-day free trial · No credit card required · Cancel anytime