H2-CCEE · Specialist path
Compliance Engineering
H2 Certified Compliance Engineer
Turn frameworks into running code. SOC 2, ISO 27001 and CIS as controls-as-code on the platform you built, evidence collected automatically, continuous compliance instead of an annual scramble, and an audit you walk into ready.
5 courses · 15 lessons · ~26 h of guided work
Assumes Foundation + T-Shaped core; CSDE recommended
What you leave with
A platform whose controls are enforced as code, whose evidence is collected automatically, and that is continuously audit-ready across SOC 2, ISO 27001 and CIS.
- Frameworks
- SOC 2 / ISO 27001 / CIS
- Policy
- OPA / Kyverno
- Evidence
- Automated collection
- Monitoring
- Continuous checks
Syllabus
5 courses · every lesson graded · minutes are guided work
Course 01
Frameworks as controls, not documents
Read SOC 2, ISO 27001 and CIS as sets of technical controls you can implement and test, not binders you write once and forget.
3 lessons · ~6 h
Tools The frameworks, the platform, a control matrix
- 01The frameworks decodedSOC 2, ISO 27001 and CIS; what each actually asks for in engineering terms.120 min
- 02From requirement to controlTurning a clause into a technical control you can test.120 min
- 03The shared control setOne control satisfying several frameworks; mapping once, not thrice.90 min
Course checkMap a set of framework requirements to concrete, testable technical controls on a real platform.
You leave withA control map from SOC 2, ISO 27001 and CIS to concrete, testable controls on the platform you built.
Course 02
Controls as code
Implement the controls as policy and configuration that enforce themselves, so compliance is the system's default state.
3 lessons · ~6 h
Tools OPA, Kyverno, the platform
- 01Access controls as codeLeast privilege and separation of duties, enforced by policy.120 min
- 02Configuration controlsCIS benchmarks as admission policy; drift that cannot happen.120 min
- 03Change and release controlsReview, approval and traceability enforced in the pipeline.90 min
Course checkImplement a set of controls as enforced policy; prove a non-compliant change is rejected automatically.
You leave withControls enforced as OPA and Kyverno policy on the platform, where a non-compliant change simply cannot ship.
Course 03
Evidence automation
The audit's real cost is evidence collection. Automate it, so producing proof for a control is a query, not a fire drill.
3 lessons · ~5 h
Tools Evidence collectors, the SIEM, the anchored trail
- 01What auditors wantThe evidence each control needs, and the form it must take.90 min
- 02Collecting it automaticallyPulling evidence from the platform on a schedule; the auditor package assembled by code.120 min
- 03Tamper-evident evidenceAn anchored trail so the evidence itself cannot be quietly altered.90 min
Course checkAutomate evidence collection for a set of controls and produce an auditor-ready package on demand.
You leave withAutomated evidence collection that produces an auditor-ready package for each control at any time.
Course 04
Continuous compliance
Stop treating compliance as an annual event. Monitor controls continuously, catch drift the moment it happens, and know your posture at all times.
3 lessons · ~5 h
Tools Continuous checks, alerting, dashboards
- 01Compliance as monitoringControls checked continuously, not annually; drift as an alert.120 min
- 02The posture dashboardCurrent compliance state at a glance; the gaps ranked by risk.90 min
- 03Drift and remediationCatch a control slipping and remediate before it matters.90 min
Course checkDetect a control drifting out of compliance in real time and prove the alert reached the owner within the SLA.
You leave withContinuous monitoring of every control, with real-time drift detection and a live compliance posture.
Course 05
The audit itself
Walk into the audit ready. How auditors work, what they ask, how to present evidence, and how to find your own gaps before they do.
3 lessons · ~5 h
Tools Mock audit, evidence packages
- 01How auditors workWhat they test, how they sample, and what a finding actually means.90 min
- 02Presenting evidenceMaking the auditor's job easy; the package that answers before they ask.90 min
- 03Finding your own gapsA self-audit that closes the gaps before the auditor names them.120 min
Course checkRun a mock audit: field the questions, present the evidence, and close a gap you found before the auditor reached it.
You leave withA rehearsed audit: the questions answered, the evidence presented, and a gap-closing pass you ran before the real thing.
Certification course
H2 Certified Compliance Engineer
$799 · one price · courses + 90-day labs + exam
A simulated audit across SOC 2, ISO 27001 and CIS on the platform you built. Graded on controls enforced as code, evidence produced on demand, and gaps found and closed before the auditor does.
Opens when Foundation is complete and the 5 course checks are passed. One proctored attempt, plus a free retake if you fail by a margin. The credential is an Open Badges 3.0 credential, signed and verifiable.
Create an account to enrol