A new free, two-year cybersecurity curriculum is giving U.S. high schools another option for building career and technical education pathways into one of the country’s fastest-growing technology fields.
Fortinet announced August 31 that its Training Institute is making a Technical High School Cybersecurity Curriculum available to secondary schools nationwide at no charge. The program consists of two year-long courses designed to move students from introductory cybersecurity concepts toward more advanced technical skills and industry certifications.
But the significance extends beyond another company offering educational materials.
The launch comes as schools face a difficult combination of growing employer demand for cybersecurity skills, new national computer science standards that explicitly recognize cybersecurity as a high-school specialty pathway, the launch of AP Cybersecurity during the 2026–27 school year, and a persistent shortage of educators with the technical expertise needed to teach rigorous cybersecurity courses.
The result is an important question for CTE leaders:
Can ready-to-use industry-developed curriculum help schools expand cybersecurity pathways without sacrificing instructional quality, teacher expertise or long-term program independence?
The answer will depend on much more than whether the curriculum itself is free.
Key Takeaways
- Fortinet launched a free, nationwide two-course high school cybersecurity curriculum on August 31, 2026.
- Each course is designed for approximately 145 instructional hours across a full school year.
- The curriculum covers networking, cryptography, endpoint security, application security, risk management and cyber defense.
- The U.S. Department of Education says many high schools still lack enough educators with the expertise needed to provide rigorous cybersecurity education.
- Employment of information security analysts is projected to grow 21% from 2025 through 2035, according to the Bureau of Labor Statistics.
- Free curriculum can reduce one barrier to starting a program, but districts still need qualified teachers, technical infrastructure, assessments, professional development and sustainable career pathways.
- The launch coincides with the national debut of AP Cybersecurity and new CSTA standards that establish cybersecurity as a high-school specialty area.
What Fortinet Is Offering High Schools
Fortinet’s Technical High School Cybersecurity Curriculum is structured as a two-course sequence.
Cybersecurity 1: Foundations serves as the introductory year. It is intended to build foundational cybersecurity knowledge while exposing students to education and career opportunities.
Cybersecurity 2: Fundamentals advances into more technical cybersecurity concepts and is intended to serve as a bridge toward industry-standard certifications.
Each course is designed for approximately 180 school days, or about 145 instructional hours. Fortinet says lessons can be used as a complete course sequence or incorporated into existing cybersecurity programs.
Topics include:
- Networking
- Cryptography
- Endpoint security
- Application security
- Risk management
- Cyber defense
The company is also providing lesson plans, activities and instructor materials intended to reduce the amount of curriculum development required from individual teachers.
Chicago Public Schools is among the districts exploring an early pilot. According to the announcement, CPS is considering the curriculum as it expands its cybersecurity pathway and AP Cybersecurity offerings.
That connection to AP Cybersecurity is particularly important.
Cybersecurity Education Is Entering a New Phase
For years, cybersecurity education in K–12 schools often depended heavily on individual instructors, extracurricular competitions, specialized academies, summer programs or locally developed courses.
That landscape is becoming more structured.
The 2026 CSTA PK–12 Computer Science Standards now include cybersecurity among six high-school specialty areas alongside artificial intelligence, data science, game development, physical computing and software development.
At the same time, College Board is launching AP Cybersecurity nationally during the 2026–27 school year.
The year-long AP course is aligned with the NIST NICE Workforce Framework and introduces students to areas such as:
- Risk analysis
- Cyber threats
- Network security
- Device security
- Application and data security
- Cryptography
- Attack detection
- Security controls
- Artificial intelligence in cybersecurity
Students can potentially earn college credit as well as an employer-endorsed AP Cybersecurity credential after achieving a qualifying exam score.
Taken together, these developments suggest that cybersecurity is moving from a specialized computer-science elective toward a more recognizable secondary career pathway.
That creates an opportunity for CTE programs—but it also raises expectations.
The Cybersecurity Teacher Problem Has Not Disappeared
Curriculum availability addresses only one part of the challenge.
The U.S. Department of Education’s Office of Career, Technical, and Adult Education identifies a more difficult problem: many high schools do not have enough teachers with the expertise necessary to provide rigorous cybersecurity education.
That distinction matters.
A prepared curriculum can reduce lesson-planning time. It can provide sequence and pacing. It can supply activities, terminology and instructional resources.
It cannot automatically give an instructor deep knowledge of:
- Networking
- Operating systems
- Security architecture
- Vulnerability analysis
- Incident response
- Authentication
- Cryptography
- Secure software
- Threat analysis
- Cyber ethics
- Digital forensics
Nor can a curriculum answer every question students will encounter during hands-on technical work.
This is one reason CISA’s Cybersecurity Education and Training Assistance Program has historically paired curriculum with educator professional development and classroom technology rather than treating instructional materials as a complete solution.
For districts evaluating the new Fortinet materials, teacher support should therefore be considered alongside curriculum quality.
Why This Matters
Ready-to-use cybersecurity curriculum may reduce the barrier to starting a program, but it does not eliminate the need to develop the instructor.
A sustainable cybersecurity pathway requires both.
Fortinet Is Not the Only Free Cybersecurity Option
The availability of free cybersecurity curriculum itself is not new.
CYBER.ORG, supported through CISA’s K–12 cybersecurity efforts, already provides free cybersecurity education resources and professional development for educators.
Its Cybersecurity 701 course, for example, is a full-year high-school program covering topics including Linux, networking, cyber law and policy, risk assessment, cryptography and cybersecurity tools. The course also uses the CYBER.ORG Range for hands-on activities and is designed to help prepare students for CompTIA Security+.
That means districts should not ask simply:
“Is this curriculum free?”
A better question is:
“What does this curriculum provide that best fits our existing pathway?”
Comparing Three Emerging Options
| Program | Structure | Major Strength |
|---|---|---|
| Fortinet Technical High School Cybersecurity Curriculum | Two year-long courses | Ready-to-use two-year pathway with progression toward certifications |
| CYBER.ORG Cybersecurity 701 | Year-long high-school course | Free curriculum, cyber range and established K–12 cybersecurity ecosystem |
| AP Cybersecurity | Year-long AP course | College-level coursework, AP credit opportunity and employer-endorsed credential |
Sources: Fortinet Training Institute, CYBER.ORG and College Board.
These programs do not necessarily compete with one another.
A district could potentially use different resources at different points in a pathway, depending on state course requirements, instructor expertise, available instructional hours and postsecondary partnerships.
The key is designing a coherent sequence rather than accumulating disconnected courses.
Workforce Demand Makes the Question More Urgent
The career opportunity behind these programs is substantial.
The Bureau of Labor Statistics projects employment of information security analysts to grow 21% between 2025 and 2035, compared with 3% for all occupations.
BLS projects about 14,100 openings annually, on average, for information security analysts during that period.
Median annual pay reached $129,180 in May 2025.
CyberSeek provides an even broader view of the cybersecurity labor market. Its most recent available national data identified 514,359 U.S. employer job listings involving cybersecurity positions during the May 2024–April 2025 reporting period. About 10% of cybersecurity job listings specifically referenced artificial intelligence skills.
Those figures should be interpreted carefully.
A high-school cybersecurity course does not automatically prepare a teenager to become an information security analyst immediately after graduation.
BLS reports that information security analysts typically need a bachelor’s degree and related work experience, although employers may also value professional certifications.
Cybersecurity pathways therefore need to show students the entire career ladder, including:
High school coursework
→ industry credentials
→ internships or apprenticeships
→ community college or university programs
→ entry-level IT or networking roles
→ specialized cybersecurity work
That is a more credible career message than suggesting students can complete one high-school course and immediately step into a six-figure security position.
The NICE Framework Can Help Schools Evaluate Curriculum
One of the strongest tools available to educators is the NICE Workforce Framework for Cybersecurity, maintained through the National Institute of Standards and Technology.
The framework provides a common language for describing cybersecurity work through tasks, knowledge and skills.
NIST specifically recommends that K–12 educators use the NICE Framework to:
- Introduce students to cybersecurity careers
- Develop cybersecurity course content
- Connect instruction to workplace skills
- Help students explore different cybersecurity work roles
- Build competency-based learning experiences
The framework is especially valuable because cybersecurity is not one occupation.
NICE describes multiple categories and work roles encompassing areas such as security operations, system administration, investigation, governance, development and defense.
A strong high-school pathway should therefore expose students to the breadth of the field rather than presenting cybersecurity simply as “hacking.”
Free Curriculum Does Not Mean a Free Cybersecurity Program
This may be the most important distinction for administrators.
The instructional materials may cost nothing, but implementation still requires resources.
Districts should consider:
Teacher Preparation
Who will teach the program, and what technical knowledge will that instructor need?
Professional Development
What training is available before and during implementation?
Lab Infrastructure
Will students need virtual machines, cyber ranges, networking hardware, cloud environments or specialized software?
Technical Support
Who assists when classroom systems, networks or lab environments stop working?
Security
How will cybersecurity exercises be isolated from production school networks?
Assessment
How will instructors determine whether students can actually perform technical tasks rather than simply recall terminology?
Credentials
Which industry credentials does the pathway prepare students for, and who pays for examinations?
Postsecondary Articulation
Can students earn dual credit or transition into a community-college or university cybersecurity program?
Employer Connections
Are local employers involved in curriculum review, mentoring, internships, apprenticeships or work-based learning?
Sustainability
Who updates the program when cybersecurity practices, technologies and threats change?
These questions can separate a sustainable CTE pathway from a course that disappears when its founding teacher leaves.
Hands-On Learning Will Be the Real Test
Cybersecurity is particularly poorly suited to instruction based primarily on slides, definitions and multiple-choice assessments.
Students need repeated opportunities to investigate systems, diagnose problems, interpret evidence and make security decisions.
The NICE Framework emphasizes demonstrable tasks, knowledge and skills.
A credible high-school cybersecurity program might ask students to:
- Analyze network traffic
- Interpret system logs
- Configure access controls
- Evaluate password policies
- Detect suspicious behavior
- Identify vulnerabilities
- Compare encryption approaches
- Harden a test system
- Analyze a phishing attempt
- Conduct a risk assessment
- Document an incident
- Recommend security controls
- Explain the consequences of a security decision
That aligns with a broader shift in computer science education toward performance and applied problem-solving.
TechEd Magazine has previously examined the same principle in Coding Projects That Build Real Computer Science Skill, where project quality depends on students being able to explain, test and defend their technical decisions—not simply produce a finished artifact. Coding Projects That Build Real Computer Science Skill
AP Cybersecurity Changes the Strategic Equation
The timing of Fortinet’s announcement is notable because AP Cybersecurity is beginning its first national school year now.
College Board describes AP Cybersecurity as equivalent to an introductory college-level cybersecurity course, with no recommended prerequisite.
Its curriculum is aligned with the NICE Workforce Framework and uses applied scenarios involving networks, devices, physical security, applications and data.
Fortinet specifically presents its high-school curriculum as potentially complementary to AP Cybersecurity, with Chicago Public Schools exploring that relationship.
That creates several possibilities for schools.
One course could provide preparation before AP Cybersecurity.
A two-year CTE program could incorporate AP Cybersecurity as part of a larger program of study.
A district could use individual Fortinet modules to supplement an existing state-approved cybersecurity course.
Or schools could select a different curriculum entirely.
The important development is that secondary cybersecurity education is becoming an ecosystem of pathways, standards, credentials and instructional resources rather than a collection of isolated electives.
Questions to Ask Your Program
Before adopting any cybersecurity curriculum, CTE and district leaders should ask:
- Which state CTE and computer-science standards does the curriculum address?
- Can the provider supply a detailed standards crosswalk?
- How does the curriculum align with the NICE Workforce Framework?
- How much hands-on technical work do students actually perform?
- What professional development will instructors receive?
- What hardware, software, cloud services or cyber-range resources are required?
- Which industry credentials or postsecondary programs does the pathway lead toward?
- Are local cybersecurity employers and colleges involved in reviewing the program?
- How will student technical competency be assessed?
- Who is responsible for updating curriculum as cybersecurity practices change?
What District Leaders Should Do Next
Schools interested in the new curriculum should resist the temptation to adopt it simply because the price is attractive.
Instead, conduct a program-level review.
1. Map the curriculum against existing standards
Compare the courses with state computer-science and CTE requirements, the 2026 CSTA standards and relevant NICE competencies.
2. Evaluate teacher readiness
Determine whether instructors need additional networking, security, Linux, cloud or cyber-defense training.
3. Examine the entire pathway
Identify what students do after completing the first and second courses.
4. Build employer and college partnerships
Ask local cybersecurity employers, IT departments, community colleges and universities to review the technical competencies.
5. Prioritize authentic assessment
Require students to demonstrate skills through secure labs, troubleshooting, analysis and documentation.
6. Measure outcomes
Track enrollment, pathway completion, credential attainment, dual-credit participation, work-based learning and postsecondary continuation.
This approach is consistent with TechEd Magazine’s broader analysis of CTE access. Recent national data shows that simply offering CTE is not enough; the quality of students’ actual career experiences and connections to employers matters as well. CTE Is Nearly Everywhere. The Career Connection Still Has Gaps.
What to Watch Next
Three developments deserve close attention.
Adoption
The first question is how many districts move from evaluating the Fortinet curriculum to actually implementing it.
Chicago Public Schools could provide an important early case study if its exploration results in broader adoption.
Teacher Development
Curriculum providers will increasingly be judged not only by student materials but also by how effectively they prepare teachers.
The stronger programs may ultimately combine curriculum, labs, assessments, educator communities and continuous professional development.
Convergence of CTE, AP and Industry Credentials
AP Cybersecurity represents a potentially important bridge between traditional Advanced Placement coursework and career and technical education.
If districts combine AP credit, industry credentials, work-based learning and technical CTE coursework within coherent programs of study, cybersecurity could become a model for how college and career preparation increasingly overlap.
Frequently Asked Questions
What is Fortinet’s new high-school cybersecurity curriculum?
It is a free two-course cybersecurity pathway announced August 31, 2026, for U.S. secondary schools. Each course is designed for approximately one full school year and about 145 instructional hours.
Is the curriculum really free?
Fortinet says the curriculum and associated instructional materials are available to schools at no cost. Districts should still evaluate potential implementation expenses involving teacher preparation, technology, labs, certifications and technical support.
What does the curriculum teach?
Topics identified by Fortinet include networking, cryptography, endpoint security, application security, risk management and cyber defense.
Does a high-school cybersecurity course qualify students for cybersecurity jobs?
It can provide an important foundation, but cybersecurity careers have widely varying requirements. BLS reports that information security analysts typically require a bachelor’s degree and related experience, while other IT and cybersecurity pathways may begin through certifications, technical education, apprenticeships or entry-level technology positions.
What is the NICE Cybersecurity Workforce Framework?
The NICE Framework is a NIST-developed system for describing cybersecurity work using common work roles, tasks, knowledge and skills. Schools can use it to connect curriculum with actual cybersecurity workforce competencies.
How does this compare with AP Cybersecurity?
AP Cybersecurity is a separate year-long College Board course launching nationally during the 2026–27 school year. Students can potentially earn college credit and an employer-endorsed credential through a qualifying AP exam score. Fortinet describes its curriculum as potentially complementary to AP Cybersecurity.
Are other free cybersecurity curricula available?
Yes. CYBER.ORG provides free K–12 cybersecurity resources, including its year-long Cybersecurity 701 course and access to a cyber range for U.S. K–12 educators.
TechEd Magazine Perspective
Fortinet’s announcement matters, but not because America’s cybersecurity education challenge can be solved by another free curriculum.
The more significant development is that the infrastructure surrounding high-school cybersecurity education is rapidly becoming more mature.
There are now dedicated CSTA cybersecurity standards, a national NICE workforce framework, free federal-supported educational resources, industry-developed courses, professional certifications and an AP Cybersecurity pathway capable of connecting career education with college credit.
Schools therefore have more options than ever.
The next challenge is choosing among them intelligently.
A successful cybersecurity program should not be judged by whether a district can announce that it offers cybersecurity. It should be judged by what students can actually understand, analyze, configure, defend and explain when they finish the pathway—and where those capabilities allow them to go next.
Free curriculum can lower the barrier to entry.
Building the teacher expertise, technical infrastructure, employer connections and instructional quality required for a durable cybersecurity pathway remains the harder—and more important—work.
Recommended Reading
- CTE Is Nearly Everywhere. The Career Connection Still Has Gaps. — Why course availability alone does not guarantee strong career preparation.
- Coding Projects That Build Real Computer Science Skill — Practical guidance for designing authentic computer-science learning.
- How to Build a STEM Curriculum — Framework for aligning standards, instruction, assessments and workforce relevance.
- Assessing STEM Learning: A Practical Guide for Educators — Approaches to assessing applied technical competency.
- Empowering High Schools with STEM Grants — Funding and program-development guidance for high-school STEM initiatives.
Authoritative Sources
- Fortinet — Technical High School Cybersecurity Curriculum Announcement
- U.S. Department of Education — Cybersecurity Education
- Bureau of Labor Statistics — Information Security Analysts
- NIST — NICE Framework K–12 Resources
- CISA — Cybersecurity Education and Career Development
- CyberSeek — Cybersecurity Workforce Data
- CSTA — 2026 PK–12 Computer Science Standards
- College Board — AP Cybersecurity
- CYBER.ORG — Cybersecurity 701




