Development and Delivery of a Cybersecurity Risk Management Training Program

September 25, 2026

The Information Systems Agency of Armenia (ISAA) invites organizations providing educational services in Armenia to apply to develop and deliver a Cybersecurity Risk Management Specialist training program (the Program) in the area of Governance, Risk and Compliance (CGRC), with the support of Carnegie Mellon University in the United States.

1. Background

The Law on Cybersecurity entered into force on January 4, 2025. Its purpose is to ensure a secure cyber environment for information systems in vital sectors and for critical information infrastructure in the Republic of Armenia. 

To build and develop a digital society in Armenia and fully implement the Law, critical information infrastructure and other high-risk organizations need additional professional capacity. 

According to the World Economic Forum's Global Cybersecurity Outlook 2025: 

  • the global cybersecurity workforce shortage is estimated at 2.8–4.8 million professionals; 
  • only 14% of organizations are confident they have the people and skills needed to achieve their cybersecurity objectives; 
  • the shortage is unevenly distributed and concentrated in security operations and cloud security, both essential to protecting vital systems; 
  • and the skills gap grew by 8% in 2024–2025, with the issue particularly pronounced in the public sector. 

The Program aims to develop risk management professionals in Armenia to international standards, strengthen the capacity of local educational institutions, and build long-term partnerships with recognized international academic institutions. 

Up to two organizations are expected to be selected to develop, pilot, deliver, and subsequently institutionalize the training program with support from Carnegie Mellon University.

2. Eligibility Criteria

Organizations with the required professional capacity may apply if they are: 

  • public higher education institutions established by or with the participation of the Government of Armenia; 
  • higher education institutions operating in Armenia and established under an interstate agreement; 
  • private higher education institutions with accreditation recognized by the Republic of Armenia; or 
  • professional organizations providing educational services in Armenia. 

3. Contributions of Program Partners

  • Carnegie Mellon University, United States: Support in defining learner personas and entry prerequisites; developing the curriculum, assessment criteria and approaches; and training trainers (ToT). 
  • Participating organization: Develop and teach the program (at least 160 hours in total for curriculum development, involving three to four specialists; an initial total workload of 35–45 hours for delivery), recruit participants, and transfer knowledge and experience. 
  • ISAA: Coordinate the partnership and support the participating institution in organizing the work. 

4. Application Requirements

Applicants must provide the following information: 

  • the organization's operating license and, where applicable and available, its accreditation certificate; 
  • details of the administrative, technical, and professional personnel who will participate in the Program, as required; 
  • CVs of the specialists who will develop and deliver the training program, including education, professional experience, current employment, and any professional certificates; 
  • a description of the technical and physical resources available for delivery; and 
  • the proposed approach to curriculum development, delivery, improvement after the pilot, and subsequent sustainability and institutionalization. 

Minimum Requirements for Participating Trainers and Curriculum Developers 

The applicant must propose a multidisciplinary team of three to four people to develop and teach the Program, indicating each person's proposed role or roles, subject areas, and form of participation. 

Each curriculum developer or trainer must: 

1. Have practical English proficiency, evidenced by at least one example of work, research, teaching, training, or international cooperation conducted in English; 

2. Have five years of professional experience in at least one of the following areas: development or implementation of cybersecurity policies and requirements; implementation or assessment of security controls; audit; risk management; risk and compliance; development of secure infrastructure or systems; or operational cybersecurity management (SOC); and 

3. Have completed training relevant to their role in the Program within the past three years or hold a current professional certification relevant to that role. ISAA will assess the certification's relevance to the Program. A copy of any such certificate must be attached to the application. 

Collectively, the proposed team must include: 

  • At least one specialist with two years of experience auditing, assessing, or implementing cybersecurity controls or programs, including application of NIST SP 800-53, ISO/IEC 27001, CIS Controls, NIST CSF, or NIS 2 requirements; and 
  • At least one specialist with practical professional experience in risk management or governance, risk, and compliance (GRC). 
  • All curriculum developers who will teach must have two years of teaching experience in technical or management subjects relevant to the Program, including risk management; cybersecurity audit and assessment; governance, risk, and compliance (GRC); infrastructure or systems engineering; or security operations management.
  • The same specialist may satisfy more than one team requirement. 

Supporting documents: For each specialist, provide a CV; descriptions of relevant work or projects identifying the organization, dates, individual role, and outcome; a list of courses taught, if applicable; and documents evidencing relevant training or a current certification.

Universities must also submit a summary matrix showing which team member meets each requirement.

5. Evaluation of Applications

Criterion Weight  Description
Relevance 20% Alignment of the Program with the organization’s strategic development goals and priorities. Prior experience developing and delivering similar programs.
Professional capacity 30% English proficiency, experience, and qualifications of the organization and proposed specialists, as well as the ability to develop and teach high-quality IT/cybersecurity learning content.
Required resources 5% Availability of technical and physical resources, including computers, software, a learning management system (LMS), classrooms/laboratories, and similar facilities.
Readiness 20% Willingness and capacity to mobilize professional, administrative, and technical resources; develop, deliver, and improve the Program; and train specialists from other universities or organizations.
Sustainability 25% Commitment to the Program’s outcomes, continued delivery, development, and institutionalization, including an approach to incorporating it into a university’s core degree programs.

Evaluation Process 

Applications will be evaluated by a committee comprising representatives of ISAA's cybersecurity and capacity-building teams and Carnegie Mellon University. 

Scoring Method 

Each evaluation committee member will score each criterion on a scale of 0–100 points as follows: 

  • 90–100, Excellent: The information exceeds the requirements, is clearly substantiated, and presents minimal risks
  • 70–89, Good: The requirements are met, with some minor gaps
  • 50–69, Satisfactory: The requirements are partially met, and the proposal departs substantially from the call's requirements
  • 0–49, Unsatisfactory: The information does not meet the minimum requirements or most information needed to make a decision is missing

The score for each criterion is multiplied by that criterion's percentage weight expressed as a decimal. 

The application's final score is the average of the scores awarded by all evaluators. 

The minimum passing score is 70 points. The applicants or applicants whose scores meet the threshold and are highest overall will be selected.

6. Application Submission

Applicant organizations must submit the complete application package in the requested format by October 16 at 00:00 to capacity.building@isaa.am, with the subject line “Application to Develop the Risk Management Specialist Program.”

Evaluation, consolidation, and publication of the results are planned for October 30, 2026.