Daniel followed up on our government versus private sector cyber episode with a question about something we mentioned in passing. The idea that the NSA has its own internal certifications kind of blew his mind. Which makes sense. He's spent his career looking at certifications from the outside, the way most of us do. You pick a cert, buy the study guide, book the exam, put it on LinkedIn. The whole point is that it's portable. It travels with you from employer to employer. So the notion of an organization standing up a private, proprietary, possibly classified certification regime, something you can only earn from the inside, that's a strange thing to sit with. And he asked, do these really exist? What are the best-known examples at the extreme secrecy end, somewhere like the NSA or a big signals intelligence agency? And then in a very different context, what about large multinationals where the certification's existence is public, but the contents are not. You know it's there, but you can't study for it unless you're already inside. So today we're going inside the certification regimes that never show up on LinkedIn.
And the short answer to Daniel's first question is yes, they absolutely exist, and the NSA one is more formal than most people realize. The agency runs something called the National Cryptologic University. It's accredited by the Middle States Commission on Higher Education, which is the same accrediting body that covers places like Princeton and Johns Hopkins. So this isn't a training division with a fancy name. It's an actual internal university that grants credentials, runs courses, and maintains a curriculum for NSA employees and certain external partners. The existence is public. The course catalog is not.
An accredited university inside a spy agency. That's the kind of sentence that sounds made up until you sit with it for a second.
And it's not the only one. The CIA has run its own internal university system since the early two thousands. CIA University. It trains analysts, operations officers, technical staff. Again, the existence is known. The curriculum, the requirements, the specific credentials, those are restricted or classified. So you have two of the most secretive organizations in the American government each running what amounts to an internal higher education system with its own credentialing.
And Daniel's question about whether these are real certification programs or just training, I think that's the key distinction. A training program is a course. You sit through it, you learn something, you go back to your desk. A certification regime has exams, passing criteria, a formal gatekeeping function. It decides who is allowed to do what. That's a different thing entirely.
Right. And we actually got a look at what this looks like from the inside, sort of accidentally. In twenty thirteen, the Office of the Director of National Intelligence released a batch of NSA course materials, and the Electronic Frontier Foundation published them the following year. One of the documents is literally titled Module Six, Tech Personnel. It's part of a structured internal curriculum. You can see the progression. This isn't a one-off seminar. It's a pathway. And the materials show training on technical collection systems, the kind of thing where the course content itself is classified because it describes capabilities.
So the study guide can't leave the building. That's the part I keep coming back to. For a normal certification, the study guide is the product. You buy it on Amazon. For these, the study material is itself a secret. The only way to study is to already be inside the room.
And that's not a bug. That's the entire design. Think about why an intelligence agency needs its own certification regime in the first place. The skills are things like signals intelligence analysis, cryptanalysis, covert operations tradecraft. There is no external body that could possibly validate those skills, because validating them would require access to the classified information they're built on. A civilian certification board can't write an exam about a collection system they're not cleared to know exists. So the agency has to be its own credentialing authority. There's no other option.
Which means the certification itself becomes part of the gatekeeping. It's clearance-adjacent. You can't earn the credential without the clearance, and you can't take the credential with you when you leave, because the credential only means something in the context of the clearance. It's completely non-transferable. The value of it evaporates the moment you walk out the door.
And I think that's the part that blew Daniel's mind, because his professional experience is the opposite. In the tech world, a certification is an asset you accumulate. It belongs to you. It's portable by definition. But in the intelligence world, the certification belongs to the agency. You're borrowing it while you work there. When you leave, it stays behind.
There's something almost feudal about that. The credential is tied to the lord's land. You can't take it with you when you go.
That's not a bad way to put it. And the NSA course materials are a good concrete example. The released documents show a structured internal training progression. Basic to advanced. You can infer that there are checkpoints along the way, assessments, gates you have to pass through. It functions as a certification pathway even if they don't call it a Cisco Certified Network Associate equivalent. The function is the same. It says, this person has demonstrated competence in a specific area, and we, the organization, are the ones vouching for it.
And nobody outside can verify any of it. You can't call the NSA and ask if someone's credential is current. The credential exists entirely inside the walls.
Which is the whole point. The credential is not for the outside world. It's for internal trust. It tells the agency who can be trusted with what. That's a completely different function from a public certification, which exists to signal competence to an external labor market.
So that's the extreme secrecy world. Now Daniel's second question was about the corporate version. Large multinationals where the certification's existence is known, but the contents are not. And that's a different beast, because the logic is different. It's not about national security. It's about something else entirely.
It's about standardization and control. Let's take Microsoft. Everyone knows Microsoft has public certifications. The old MCSE, the Azure certifications, those are public. You can buy study materials, book an exam at a testing center, put the badge on your LinkedIn. But Microsoft also runs internal certifications for its own engineers and support staff. These are not publicly available. The content is proprietary. You can't study for them unless you're already a Microsoft employee.
So the public knows the internal cert exists, but that's it. You know there's a door. You can't see through it.
Amazon does the same thing. AWS has public certifications, the Solutions Architect track, all of that. But Amazon also runs internal technical certifications for its own engineers. Particularly in areas like fulfillment center automation, robotics, internal tooling. These are employee-only. The reason is pretty straightforward. No external body could certify someone on Amazon's internal fulfillment algorithms, because those algorithms are proprietary. The exam would have to describe the thing it's testing, and the thing it's testing is a trade secret.
So the corporate version is protected by trade secret law rather than classification. But the functional effect is the same. The credential only has value inside the organization.
And here's where it gets interesting from a labor economics perspective. The non-portability isn't just a side effect. In the corporate world, it can be a retention mechanism. If you've spent eighteen months earning an internal credential, that credential is worthless the day you leave. So there's a subtle lock-in effect. You've invested in something that only pays off if you stay.
That's the part that feels a little less benign than the intelligence version. In the intelligence world, the non-portability is a security necessity. In the corporate world, the non-portability is at least partly a feature. It keeps you tethered.
I don't think it's usually that calculated. Most companies aren't sitting around thinking, how do we trap our engineers with credentials. It's more that the credential is a natural byproduct of needing to validate skills that only exist inside the company. The lock-in is an emergent property, not a designed one. But the effect is real either way.
And there's a difference in how the two worlds handle the credential itself. In the intelligence world, the credential is tied to the clearance, which is tied to the person. When the person leaves, the clearance goes away, and the credential goes away with it. In the corporate world, the credential is tied to proprietary knowledge, which also doesn't transfer. But the person still knows what they know. The knowledge walks out the door. The credential doesn't.
That's a really important asymmetry. The knowledge is in your head. It leaves with you. But the credential, the formal recognition of that knowledge, stays behind. So you have this strange situation where an ex-NSA analyst might have deep expertise in a specific collection system, but no way to prove it to a future employer. The expertise is real. The proof is gone.
And in the corporate world, it's similar. An ex-Amazon engineer might know everything about how fulfillment automation works, but the internal cert that proved it is meaningless outside Amazon. So they have to fall back on the public credentials, the AWS certs, which are portable but don't capture the proprietary knowledge.
Which creates an interesting incentive. If you're at Amazon and you want to keep your options open, you might prioritize the public AWS certifications over the internal ones, because the public ones travel with you. The internal ones are a bet on staying.
So the employee has to make a strategic choice about where to invest their time. Do I build portable capital or internal capital? One of them pays off if I leave. The other pays off if I stay.
And that's a calculation most people don't even realize they're making. Daniel said he's always looked at certifications from the outside, and I think most people are like that. They assume all certifications are public and portable. The idea that there's a whole category of credentials that are designed not to travel is counterintuitive.
Let's talk about the semi-transparent dynamic Daniel mentioned. The existence is known, the contents are not. In job postings, you'll sometimes see a company mention that candidates should have or be willing to earn an internal certification. So the public gets a glimpse. We know it's there. But the study materials, the exam content, the passing criteria, those are confidential. It's a strange liminal space. You know the door exists. You know you can't open it from outside. But you can see the frame.
And in the intelligence world, sometimes you don't even know the door exists. The NSA's internal certifications weren't widely discussed until the twenty thirteen ODNI release. Before that, it was mostly rumor and inference. The EFF publication of those course materials was the first time a lot of people outside the agency got a concrete look at what the internal training structure actually looked like.
Which is itself an interesting story. The documents were released as part of a broader disclosure, and suddenly there was a PDF floating around that said Module Six, Tech Personnel. You could download it. You could read what the NSA was teaching its technical staff. Not the classified content, but the structure. The skeleton of the curriculum.
The structure is what reveals the certification function. You can see the progression. Basic concepts first, then more advanced material. It's designed to take someone from entry-level to competent in a structured way. That's what a certification pathway does. It's not just a pile of courses. It's a sequence with checkpoints.
What do these regimes reveal about institutional power? I think that's the deeper question Daniel was poking at. The credential is a form of knowledge control. The organization decides what counts as competence, who gets to be recognized as competent, and what happens to that recognition when you leave.
It's sovereignty, in a way. The organization is declaring that it, and only it, has the authority to say who knows what. No external body can second-guess it. In the intelligence world, that's because the external body can't see the material. In the corporate world, it's because the external body doesn't have access to the proprietary systems. Either way, the organization is the sole arbiter.
There's a trust function too. Inside the organization, the credential is a signal. It tells your colleagues and your managers that you've been vetted. You've passed the gates. You can be trusted with the sensitive work. That's valuable internally, even if it's worthless externally.
Which is why these regimes persist despite the non-portability. The organization gets real value from them. Standardization, quality control, trust. The employee gets less value, at least in the long run, but they get access to work they couldn't do otherwise. It's a trade.
The trade is different in the two worlds. In the intelligence world, you're trading portability for access to work that literally doesn't exist anywhere else. There's no private sector equivalent of signals intelligence analysis on classified collection systems. So the non-portable credential is the price of admission to a career that only exists inside the agency.
In the corporate world, the trade is less stark. The work usually does have a private sector equivalent. Fulfillment automation is specific to Amazon, but the underlying robotics skills are transferable. So the internal cert is more of a value-add than a prerequisite. It deepens your expertise, but it doesn't define your career the way an NSA credential might.
Do we know anything about the scale of these corporate internal cert programs? How many internal certifications Microsoft or Amazon actually run?
The honest answer is we don't have public numbers. These programs are not advertised. We know they exist from job postings, from employee discussions, from the occasional mention in earnings calls or internal communications that leak. But the full scope is not public. That's part of the semi-transparent dynamic. We can see the silhouette, not the details.
Even at the corporate level, there's a real information asymmetry. The company knows exactly what its internal certification landscape looks like. The public knows fragments. The employees know more, but even they might not know the full picture. An engineer in one division might not know what internal certs exist in another division.
That's probably true. These things tend to be siloed. The robotics team has its own internal credentials. The cloud team has different ones. The support staff has yet another set. There's probably no single person, or at least very few people, who could map the entire internal certification ecosystem of a company the size of Amazon.
Which is itself a kind of knowledge control. Not just external control, keeping the public out, but internal control, keeping different parts of the organization from seeing each other's credentialing systems.
In the intelligence world, that internal compartmentalization is formalized. You don't just lack access to the certification materials for a different directorate. You might not even know that directorate's certifications exist. The credentialing system is itself compartmented.
The deeper you go into either world, the more the certification regime looks like a map of the organization's internal boundaries. What you're allowed to know about the credentials is a proxy for what you're allowed to know about the work.
That's a sharp way to see it. The credential is a gate, and the visibility of the credential is another gate. You have to be inside the first gate to even see the second one.
Let's talk about what happens when someone leaves. In the intelligence world, we've covered this. The credential stays behind. The clearance goes away. The person walks out with knowledge in their head but no formal proof of it. What about the corporate world? Is there any mechanism for an internal cert to become portable?
Not really. The company could choose to recognize an internal cert from a competitor, but why would they? The internal cert is built on proprietary systems. It doesn't transfer because the subject matter doesn't transfer. An Amazon internal robotics cert doesn't mean much at a different company with different robotics systems.
The non-portability isn't just a policy choice. It's structural. The credential is tied to the specific systems and processes of the organization. It can't travel because the thing it certifies doesn't travel.
That's the key difference from public certifications. A CISSP or a Security Plus certifies general knowledge. It's designed to be portable. The whole point is that the knowledge applies across employers. An internal cert certifies specific knowledge. The whole point is that the knowledge applies only here.
Which brings us back to Daniel's framing. He said he's always looked at certifications from the outside. And I think most of us do. The public certification ecosystem is so dominant that it's easy to forget it's just one part of the credentialing landscape. There's a whole hidden layer underneath, where organizations mint their own credentials for their own purposes, and the public never sees most of it.
That hidden layer is growing, I suspect. As companies build more proprietary systems, more internal tooling, more specialized processes, the need for internal certification grows. You can't rely on public certs to validate skills that only exist inside your walls. So you build your own.
Which raises a question about the future of work. If internal certifications become more common, what does that mean for employees? The portable credential has historically been a form of labor power. It lets you move between employers without losing your accumulated proof of competence. If more of your credentials are non-portable, does that reduce your mobility?
It does, at least at the margin. But I think it's more nuanced than that. The portable credentials don't go away. You still get your AWS cert, your CISSP. Those remain portable. The internal certs are additional. They deepen your expertise in a specific context. The risk is if you over-invest in internal credentials and under-invest in portable ones. Then you're locked in, whether you meant to be or not.
The employee might not even realize they're making that trade. The internal cert is offered, it seems valuable, you take it. It's only later, when you think about leaving, that you realize the credential doesn't come with you.
Which is why transparency matters. Companies should be clear about which credentials are portable and which are internal. But of course, most companies have no incentive to be that clear. The ambiguity works in their favor.
The hidden nature of these regimes isn't just about protecting secrets. It's also about maintaining an information asymmetry between employer and employee. The company knows which credentials are portable and which aren't. The employee has to figure it out.
In the intelligence world, the asymmetry is total. You know the credential isn't portable. It's not a secret. But you also know you can't do the work anywhere else, so the non-portability doesn't matter as much. The career itself is non-portable.
Let's circle back to the NSA for a second. The National Cryptologic University. Do we know anything about how it compares to a normal university? Is it just a rebranding of the training center, or is it something more?
The accreditation is the interesting part. The Middle States Commission on Higher Education is a legitimate accrediting body. The fact that the NSA sought and received accreditation for its internal university suggests they wanted the credentials to carry some weight, at least internally and possibly with external partners. It's not just a training program with a fancy name. It's an accredited institution.
Which means the credentials it grants have a kind of legitimacy that a purely internal training certificate wouldn't have. The accreditation is a signal that the curriculum meets certain standards. But those standards are about educational quality, not about the specific content, which remains classified.
Right. The accreditation says the structure is sound. It doesn't say anything about what's actually taught. So you have this strange hybrid. A legitimate university that teaches things it can't tell you about.
That's the weirdness of this whole topic in one image. An accredited university where the course catalog is a secret.
The CIA University is similar. It's been around since the early two thousands. It's not as publicly documented as the NSA's National Cryptologic University, but the model is the same. Internal training, internal credentials, restricted curriculum. The existence is known. The details are not.
Daniel's question about the best-known examples in the extreme secrecy world, the answer is pretty clear. NSA's National Cryptologic University, CIA University. Those are the two big ones that are publicly acknowledged. There are probably others we don't know about, and that's the point.
The NSA course materials give us a glimpse of what the internal curriculum looks like. The Module Six document on Tech Personnel is a training module for technical staff. It's structured, it's detailed, it's clearly part of a larger sequence. You can see the bones of a certification pathway even if you can't see the whole thing.
The answer to Daniel's first question, do these really exist, is a definitive yes. They exist, they're formal, they're accredited in at least one case, and they function as genuine credentialing regimes with gates and progression.
The answer to his second question, what about the corporate world, is also yes. Microsoft, Amazon, and plenty of other large multinationals run internal certification programs. The existence is sometimes mentioned in job postings or internal communications. The contents are proprietary. You can't study for them from outside.
The underlying logic is different. In the intelligence world, it's about security. The skills are classified, so the credentialing has to be internal. In the corporate world, it's about standardization and control. The skills are proprietary, so the credentialing has to be internal. But the functional effect is the same. A non-portable credential that only has value inside the organization.
The knock-on effect are similar too. Retention, lock-in, information asymmetry. The credential becomes a tether, whether that's the intent or not.
What does this mean for someone like Daniel, who's spent his career on the outside looking in? I think the takeaway is that the certification landscape is bigger and stranger than most people realize. There's the public layer, the one everyone knows about. And then there's the hidden layer, where organizations mint their own credentials for their own purposes. And the hidden layer is probably larger than the public one.
I suspect that's right. For every public certification, there are probably dozens of internal ones that never see the light of day. The public certification ecosystem is just the tip of the iceberg.
The iceberg is mostly invisible, by design. That's the point Daniel was getting at. The existence of these regimes is itself a kind of knowledge control. You can't study for what you don't know exists.
Which brings us to the question of what this means for the future. As AI and automation change the nature of technical work, the skills become more organization-specific. The internal systems get more complex. The proprietary knowledge gets deeper. So the need for internal certification grows. We're probably going to see more of this, not less.
The portable credential, the one you can take with you, becomes less valuable relative to the internal one. Because the work itself is less portable. The skills that matter are the ones tied to specific systems, specific processes, specific internal knowledge. And those are exactly the skills that can't be certified externally.
Which is a strange future to contemplate. A workforce where the most valuable credentials are the ones you can't take with you. Where the proof of competence is locked inside the walls of the organization that granted it.
The employee is left holding a laminated card that says Authorized, with a number on it, and no way to explain to anyone outside what it means.
Hilbert: My cousin's ex-wife had one of those. Laminated card in her wallet. Just said Authorized with a number. No agency name, no system name, nothing. She worked as a technical writer for a defense contractor in the late nineties. Had to get an internal certification just to document one specific signals intelligence system. She couldn't study for it at home because the materials couldn't leave the secure room. So she'd go in early, study for an hour, then take the exam. It was a classified technical writing test. She said the hardest part was you couldn't take notes. Everything had to stay in your head. She passed. Got the card. And then she left for another contractor a few years later, same kind of work, almost identical systems. Had to get a completely different internal cert. The first one didn't transfer at all. She said it was like starting over from zero, even though she'd been doing the job for years. I tried to look up the certification once, just to see. Nothing. Not even a mention. Which I guess is the point. She kept that card in her wallet for years after she left. Wasn't sure if she was supposed to destroy it. Nobody ever told her. So she just carried it around. A little laminated rectangle that said Authorized and a number, and no way to prove what it was for.
The card is the credential in its purest form. No context, no explanation, no portability. It means everything inside the room and nothing outside it.
The fact that she kept it, not sure if she was supposed to destroy it, that's the human side of this. The credential becomes a kind of relic. A proof of something you did that you can't talk about.
Hilbert: She said the weirdest part was that the certification didn't even transfer within the same contractor. Different program, different system, you needed a different cert. It wasn't about competence. It was about access. The cert wasn't saying she knew how to write technical documentation. It was saying she was cleared to write about this specific system. That's all it was.
That's the gatekeeping function in its rawest form. The credential isn't a statement about skill. It's a statement about permission. You are allowed to know this thing, and the card proves it.
The permission is revocable. The card doesn't mean anything once you're outside the system. It's not a badge of honor. It's a key, and the door is gone.
Hilbert: She threw it away eventually. Moved apartments, found it in a drawer, looked at it for a minute, and put it in the trash. Said it felt strange, throwing away something that had been so hard to get. But what else was she going to do with it. Frame it.
The credential that only means something while you're inside, and becomes a curiosity the moment you leave. That's the whole story, really.
It's a story that's going to become more common, not less. As the work gets more specialized, the credentials get more internal. The laminated card with no context becomes the model, not the exception.
The cutting-room floor detail I wanted to mention. The National Cryptologic University's accreditation covers associate, bachelor's, and master's degree programs. So the NSA isn't just running internal certifications. It's running an internal degree-granting institution. You can earn a master's degree from a university that can't tell you what's in the curriculum.
That's a strange thing to sit with. A fully accredited university inside a spy agency, granting degrees that only mean something inside the walls. And the future of work might look more like that than any of us expected.
Thanks to Hilbert Flumingtop for producing. This has been My Weird Prompts. If you enjoyed this one, leave a review. It helps other people find the show.
We'll be back soon.