Skip to main content Scroll Top

Introduction

As cyber threats evolve, the need for robust security measures has become increasingly critical. Penetration testing serves as a proactive strategy for identifying vulnerabilities, making it essential for organizations aiming to safeguard sensitive data and adhere to regulatory standards.

With a multitude of penetration testing companies available, businesses face the challenge of selecting a provider that best meets their specific security requirements. This article examines the strengths and weaknesses of leading firms, providing valuable insights to assist organizations in making informed decisions to enhance their cybersecurity.

Understand Penetration Testing: Purpose and Importance

Penetration testing companies conduct penetration evaluation, commonly known as ‘pen testing,’ to simulate a cyberattack on a company’s systems and identify exploitable weaknesses. This proactive approach is essential for organizations aiming to safeguard sensitive data and adhere to regulatory standards. Notably, 84% of security assessments performed by penetration testing companies reveal at least one exploitable vulnerability, highlighting the critical need for these evaluations.

The significance of vulnerability assessment extends beyond merely identifying flaws; it also evaluates the effectiveness of current protective measures. Regular assessments can lead to enhanced protection protocols, improved staff training, and a fortified overall security posture. For instance, organizations that adopt a systematic approach to security assessments are 4.5 times more likely to resolve critical issues within three days, transforming security from a reactive obligation into a proactive business enabler.

In highly regulated industries such as finance and healthcare, where data breaches can result in substantial financial and reputational damage, security assessments from penetration testing companies are integral to risk management strategies. The Cybersecurity Act of 2023 mandates that federal agencies conduct security assessments on high-value assets, reflecting the increasing recognition of its importance across various sectors. As organizations face evolving threats, the need for regular security evaluations has never been more pressing.

The central node represents penetration testing, with branches showing its purpose, importance, and benefits. Each branch highlights key aspects, making it easy to understand how they connect and contribute to overall security.

Evaluate Key Criteria for Choosing a Penetration Testing Company

When selecting penetration testing companies, organizations should prioritize several key criteria to ensure effective evaluation and security enhancement.

  • Experience and expertise are crucial; therefore, it is essential to seek penetration testing companies with a proven track record in your specific sector. Experienced testers possess the skills necessary to identify complex vulnerabilities that less seasoned professionals might overlook.
  • Methodology: Ensure that the company adheres to a recognized methodology, such as OWASP or NIST. These frameworks provide a structured approach to evaluation, ensuring thoroughness and consistency in the testing process.
  • Reporting Quality: The ability to deliver clear and actionable reports is crucial. Reports should be crafted to be understandable for both technical and non-technical stakeholders, facilitating informed decision-making.
  • Customization: The best penetration testing companies tailor their services to meet the unique requirements of your organization, rather than offering a one-size-fits-all solution. This customization ensures that the testing aligns with your specific security needs.
  • Compliance Knowledge: For organizations operating in regulated sectors, it is vital that the assessment firm understands relevant compliance requirements. Their expertise can assist in ensuring adherence to these regulations, which is critical for maintaining operational integrity.
  • Post-Test Support: Consider whether the company offers support after the testing phase, including guidance on remediation and retesting services. This ongoing support can be invaluable in addressing identified vulnerabilities effectively.

The central node represents the main topic, while the branches show the important criteria to consider. Each branch can be explored to understand what makes a good penetration testing company.

Compare Leading Penetration Testing Companies: Strengths and Weaknesses

Use english for answers

Please return corrected/formatted text for:

  • Company Name: Cobalt.io

    • Strengths: Emphasizes agile methodologies and rapid turnaround, making it ideal for organizations with frequent release cycles and a focus on application security testing.
    • Weaknesses: Limited customization options may not adequately meet the needs of smaller clients.
  • Company Name: Rapid7

  • Company Name: BreachLock

    • Strengths: Combines AI-driven insights with human expertise to deliver thorough vulnerability assessments.
    • Weaknesses: Report generation can be time-consuming, potentially delaying actionable insights.
  • Company Name: Synack

    • Strengths: Utilizes a crowdsourced testing model, offering diverse perspectives and innovative approaches to security challenges.
    • Weaknesses: Availability can be unpredictable, and the onboarding process may be time-consuming, affecting project timelines.
  • Company Name: HackerOne

    • Strengths: Strong community engagement and integration of bug bounty programs foster a proactive security culture.
    • Weaknesses: Primarily focuses on web applications, with less emphasis on infrastructure evaluation.

This summary outlines the strengths and weaknesses of each company, assisting organizations in identifying which provider aligns best with their specific needs.

Each branch represents a different company, with strengths and weaknesses clearly outlined. This layout helps you quickly see what each company offers and where they may fall short.

Make Informed Decisions: Recommendations Based on Your Needs

When selecting penetration testing companies, it is crucial to consider your organization’s specific needs and requirements. The following tailored recommendations can guide your decision:

  • For Small to Medium Enterprises (SMEs): Cobalt is a standout choice, offering agile services that cater to SMEs seeking quick results without the strain of extensive budgets. Their credit-based pricing model provides flexibility, with costs ranging from approximately $8,500 to $25,000 per engagement, ensuring accessibility for smaller entities.
  • For Large Businesses: Rapid7 is well-suited for larger organizations, delivering a comprehensive range of security solutions that include thorough evaluations across various domains. Their services are supported by elite research from the Metasploit team, offering exceptional manual exploit depth and a holistic view of findings integrated with their vulnerability management platform. The cost model for Rapid7 services is premium/custom, typically ranging from $25,000 to $75,000 or more, establishing them as a trusted partner for enterprises requiring in-depth assessments.
  • For Compliance-Focused Organizations: BreachLock is recommended for its hybrid approach, which combines expert human evaluation with AI and automation. This ensures a comprehensive evaluation while efficiently addressing compliance needs, making it ideal for entities in regulated sectors. BreachLock is trusted by over 1,000 organizations across more than 20 countries, reinforcing its reliability in compliance-focused environments.
  • For Innovative Evaluation Methods: Synack and HackerOne are excellent options for organizations looking to leverage crowdsourced assessments. These platforms provide diverse perspectives and creative approaches, enhancing the overall efficiency of security evaluations. Synack’s unique method integrates human expertise with automated resources, while HackerOne focuses on community-driven assessments, allowing organizations to tap into a wide array of researchers in the field.

By aligning your choice with these recommendations, your organization can select penetration testing companies that not only address security needs but also fortify your overall cybersecurity strategy.

The central node represents the main topic, while each branch shows recommendations for different types of organizations. Follow the branches to explore which company might best suit your needs based on your organization's size and focus.

Conclusion

In conclusion, selecting the right penetration testing company is essential for organizations seeking to strengthen their cybersecurity defenses. Understanding the nuances of penetration testing enables businesses to identify vulnerabilities effectively and enhance their security posture. This proactive approach not only protects sensitive data but also ensures compliance with regulatory standards, making it a vital component of contemporary security strategies.

The criteria outlined for choosing a penetration testing provider:

  1. Experience
  2. Adherence to recognized methodologies
  3. Reporting quality
  4. Customization
  5. Compliance knowledge
  6. Post-test support

are crucial in determining the evaluation process’s effectiveness. A comparison of leading companies such as Cobalt.io, Rapid7, BreachLock, Synack, and HackerOne reveals their respective strengths and weaknesses, allowing organizations to make informed decisions tailored to their unique needs.

In a landscape where cyber threats continually evolve, the significance of regular penetration testing cannot be overstated. Organizations must prioritize their security by selecting a provider that aligns with their specific requirements and industry context. By leveraging the insights shared in this article, businesses can enhance their security measures and cultivate a culture of proactive risk management, ultimately transforming security from a mere compliance necessity into a strategic advantage.

Frequently Asked Questions

What is penetration testing?

Penetration testing, or ‘pen testing,’ is a simulated cyberattack conducted by penetration testing companies to identify exploitable weaknesses in a company’s systems.

Why is penetration testing important for organizations?

It is essential for safeguarding sensitive data, adhering to regulatory standards, and improving overall security by identifying vulnerabilities and evaluating the effectiveness of current protective measures.

What percentage of security assessments reveal vulnerabilities?

Notably, 84% of security assessments performed by penetration testing companies reveal at least one exploitable vulnerability.

How can regular penetration testing benefit an organization?

Regular assessments can lead to enhanced protection protocols, improved staff training, and a fortified overall security posture, transforming security from a reactive obligation into a proactive business enabler.

How does penetration testing impact response to critical issues?

Organizations that adopt a systematic approach to security assessments are 4.5 times more likely to resolve critical issues within three days.

In which industries is penetration testing particularly crucial?

It is particularly important in highly regulated industries such as finance and healthcare, where data breaches can cause significant financial and reputational damage.

What recent legislation highlights the importance of security assessments?

The Cybersecurity Act of 2023 mandates that federal agencies conduct security assessments on high-value assets, reflecting the increasing recognition of the importance of these evaluations.

Why is there a pressing need for regular security evaluations?

As organizations face evolving threats, the need for regular security evaluations has become critical to effectively manage risks.

List of Sources

  1. Understand Penetration Testing: Purpose and Importance
    • medium.com (https://medium.com/@markbabcock_79883/where-i-see-cybersecurity-in-2026-through-the-lens-of-appsec-pentesting-430eca6f5c47)
    • cobalt.io (https://cobalt.io/blog/5-key-takeaways-from-the-2026-state-of-pentesting-report)
    • brightdefense.com (https://brightdefense.com/resources/why-penetration-testing-is-important)
    • halock.com (https://halock.com/penetration-testing-requirement-what-u-s-rules-mandate-it-in-2026)
    • thehackernews.com (https://thehackernews.com/expert-insights/2026/01/the-2026-state-of-pentesting-how-modern.html)
  2. Evaluate Key Criteria for Choosing a Penetration Testing Company
    • blazeinfosec.com (https://blazeinfosec.com/post/penetration-testing-companies)
    • capturethebug.xyz (https://capturethebug.xyz/Blogs/Why-Smart-Companies-Rethink-Outsourcing-Penetration-Testing-in-2026)
    • ciso.inc (https://ciso.inc/blog-posts/top-10-considerations-for-choosing-a-penetration-testing-vendor)
    • aerstone.com (https://aerstone.com/our-blog/a-practical-guide-to-choosing-penetration-testing-companies-in-regulated-environments)
    • cobalt.io (https://cobalt.io/blog/how-to-choose-the-best-penetration-testing-service-provider)
  3. Compare Leading Penetration Testing Companies: Strengths and Weaknesses
    • deepstrike.io (https://deepstrike.io/blog/best-penetration-testing-companies)
    • hackernoon.com (https://hackernoon.com/penetration-testing-companies-comparing-the-top-5-vendors)
    • softwaresecured.com (https://softwaresecured.com/post/top-10-penetration-testing-vendors)
    • cybergl.com (https://cybergl.com/blog/top-penetration-testing-companies)
    • deepstrike.io (https://deepstrike.io/blog/top-penetration-testing-companies-2026)
  4. Make Informed Decisions: Recommendations Based on Your Needs
    • cybergl.com (https://cybergl.com/blog/top-penetration-testing-companies)
    • industryarc.com (https://industryarc.com/PressRelease/5065/Penetration-Testing-Market)
    • hackernoon.com (https://hackernoon.com/penetration-testing-companies-comparing-the-top-5-vendors)
    • deepstrike.io (https://deepstrike.io/blog/top-penetration-testing-companies-2026)
    • cybernx.com (https://cybernx.com/penetration-testing-companies-in-usa)

CMMC Compliance Support: Key Practices for Manufacturing Security

Explore essential practices for CMMC compliance support to enhance manufacturing security.

7-1
  • Home
  • General
  • CMMC Compliance Support: Key Practices for Manufacturing Security
7-2

Introduction

Manufacturers in the defense supply chain must urgently adapt to the Cybersecurity Maturity Model Certification (CMMC) requirements. This compliance framework is not merely a regulatory hurdle; it presents a vital opportunity for organizations to enhance their cybersecurity posture and protect sensitive information.

However, manufacturers often struggle to interpret the complex levels of certification and implement effective security practices, which can lead to significant security vulnerabilities. Navigating these complexities is essential not only for compliance but also for safeguarding sensitive information against evolving cyber threats.

Understand CMMC Compliance Requirements

The Cybersecurity Maturity Model Certification (CMMC) serves as a critical framework established by the Department of Defense (DoD) to fortify the cybersecurity posture of entities within the defense supply chain. It consists of three levels, each with unique methods and procedures that organizations must adopt to protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). Manufacturers should focus on the following key aspects:

  1. CMMC Levels: The CMMC framework has shifted to a three-tier model, streamlining adherence while still ensuring robust security measures. Level 1 centers on fundamental cyber hygiene, whereas Level 2 requires compliance with 93 additional methods, underscoring the importance of a more thorough security strategy. Rob McCormick, CEO of Avatara, emphasizes that Level 2 requires not just an evaluation but also compliance with 93 additional methods compared to Level 1.
  2. Assessment Requirements: Organizations face significant challenges in preparing for these assessments, as they must meticulously document their security measures and provide evidence of their implementation. Third-party evaluations carried out by authorized C3PAOs are required to confirm adherence to CMMC standards. The estimated cost for these assessments ranges from $40,000 to $80,000, excluding any additional expenses for third-party services.
  3. Documentation and Reporting: Precise record-keeping of security measures and adherence efforts is essential. Documentation will be rigorously examined during assessments, making it crucial for organizations to maintain detailed and organized records.
  4. Continuous Improvement: This ongoing commitment necessitates that organizations remain vigilant and proactive in enhancing their cybersecurity measures to adapt to evolving threats and ensure adherence to regulations. This includes regular updates to policies and practices in response to changes in technology and regulatory requirements.

Manufacturers must prioritize compliance to remain competitive and secure in an increasingly regulated environment. As of 2026, 81% of DIB organizations surveyed have begun their regulatory adherence process, reflecting the urgency and significance of these measures in the defense industrial base. Additionally, the adherence requirements will be incorporated in almost all DoD solicitations within three years, highlighting the essential nature of prompt adherence for manufacturers.

The central node represents the overall compliance framework, while each branch highlights a key area of focus. Sub-branches provide more detail on specific requirements, helping you understand how each part contributes to overall compliance.

Implement Key Cybersecurity Practices for CMMC

In an era where cyber threats are increasingly sophisticated, manufacturers must prioritize key cybersecurity practices to achieve CMMC compliance:

  1. Access Control: Establish strict access controls to ensure that only authorized personnel can access sensitive information. This includes implementing multi-factor authentication and role-based access controls, which are essential for safeguarding Controlled Unclassified Information (CUI).
  2. Incident Response Plan: Develop and maintain a comprehensive incident response plan that outlines procedures for detecting, responding to, and recovering from cybersecurity incidents. Regular testing and updates of this plan are crucial for ensuring its effectiveness. Many organizations face a daunting reality: a staggering 73% are unprepared for cyber incidents, highlighting the critical need for a robust incident response strategy.
  3. Regular Vulnerability Assessments: Conduct regular vulnerability assessments and penetration testing to identify and remediate potential security weaknesses in your systems. This proactive approach helps bridge the gap between perceived and actual adherence, tackling discrepancies that can result in financial strain. This stark contrast reveals the gap between perceived and actual compliance, urging manufacturers to reassess their cybersecurity measures.
  4. Data Encryption: Encrypt sensitive data both in transit and at rest to protect it from unauthorized access and breaches. This procedure is essential for upholding standards related to regulatory stipulations and guaranteeing the integrity of crucial information.
  5. Patch Management: Implement a robust patch management process to ensure that all software and systems are up to date with the latest security patches. This is particularly important as outdated systems are often targeted by attackers, and timely updates can prevent vulnerabilities from being exploited.

By adopting these practices, manufacturers not only enhance their cybersecurity posture but also benefit from CMMC compliance support, ultimately securing their position in the competitive landscape of defense contracting.

The central node represents the overall goal of achieving CMMC compliance. Each branch shows a key practice that contributes to this goal, and the sub-branches provide additional details or actions related to each practice. Follow the branches to understand how each practice supports cybersecurity efforts.

Establish Continuous Monitoring and Assessment Protocols

Manufacturers face increasing challenges in maintaining security standards amidst evolving threats. Ongoing observation is a proactive approach crucial for manufacturers to uphold standards and enhance their overall security stance. Organizations should implement the following protocols:

  1. Automated Monitoring Tools: Leverage automated tools to continuously track network traffic, system logs, and user activities, identifying signs of suspicious behavior or potential breaches. For instance, Redspin’s experience illustrates that these tools significantly enhance assessment efficiency. Some organizations have reported a 90% increase in effectiveness through automated regulatory processes.
  2. Regular Security Audits: Conduct both internal and external security audits regularly to evaluate the effectiveness of existing controls and pinpoint areas for improvement. Data indicates that manufacturing companies generally perform security assessments at least once a year, which is essential for meeting standards. This practice offers cmmc compliance support to organizations, assisting them in staying aligned with regulatory requirements and adjusting to changing threats.
  3. Incident Reporting Mechanisms: Establish clear protocols for reporting security incidents and vulnerabilities. Encourage employees to report suspicious activities without fear of repercussions, fostering a culture of security awareness.
  4. Compliance Checklists: Develop and maintain compliance checklists that align with CMMC standards. Consistently examine and refresh these checklists to guarantee compliance with optimal methods and regulatory standards.
  5. Feedback Loops: Create feedback mechanisms that facilitate continuous improvement of security practices based on monitoring results and incident reports. This iterative process helps organizations adapt to new threats and enhance their security measures over time.

Failure to adopt these protocols may expose manufacturers to significant risks and financial repercussions.

This flowchart outlines the key protocols for manufacturers to enhance their security. Each box represents a specific action to take, and the arrows show how these actions connect in the overall process of maintaining security standards.

Develop Employee Training and Awareness Programs

To foster a robust cybersecurity culture, manufacturers must prioritize comprehensive employee training and awareness programs that include:

  1. Regular Training Sessions: Conduct regular training sessions covering essential topics related to online security, such as phishing awareness, password security, and data handling best practices. This ensures that all employees are equipped with the knowledge to protect sensitive information.
  2. Role-Specific Training: Customize training programs for specific roles within the organization, ensuring that employees understand the distinct security risks associated with their positions. For example, in 2026, organizations like MSU are introducing staged training in security based on roles, emphasizing the importance of focused education.
  3. Simulated Phishing Exercises: Implement simulated phishing exercises to test employees’ ability to recognize and respond to phishing attempts. Providing feedback and additional training based on their performance can significantly improve their vigilance and response strategies.
  4. Awareness Initiatives: Launch awareness initiatives that promote best practices for digital security and keep safety top-of-mind for employees. Use posters, newsletters, and intranet resources to disseminate information effectively. Every employee plays a vital role in maintaining our digital security.
  5. Feedback and Improvement: Encourage employee feedback on training programs and continuously improve them based on this input to ensure they remain relevant and effective. This iterative process is crucial in addressing the evolving challenges in digital security, especially given the rising frequency and complexity of cyber threats.

Ultimately, a proactive approach to employee training is essential for safeguarding against the evolving landscape of cyber threats.

The center represents the main focus on training programs, while each branch highlights a key component of the training strategy. Follow the branches to explore how each part contributes to building a strong cybersecurity culture.

Conclusion

In the defense supply chain, CMMC compliance is not merely a regulatory checkbox; it is a critical factor for safeguarding sensitive information and maintaining a competitive edge. The Cybersecurity Maturity Model Certification serves as a vital framework that outlines necessary practices and protocols, ensuring that organizations not only meet regulatory standards but also enhance their overall cybersecurity posture.

Key practices for achieving CMMC compliance include:

  1. Understanding the different levels of the framework
  2. Implementing robust cybersecurity measures
  3. Establishing continuous monitoring and assessment protocols

Comprehensive employee training and awareness programs are essential for fostering a culture of security within organizations. By focusing on access control, incident response plans, vulnerability assessments, and data encryption, manufacturers can effectively mitigate risks and prepare for the rigorous assessments required for compliance.

In an environment where cyber threats are constantly evolving, the proactive implementation of these practices is essential. Manufacturers are encouraged to view CMMC compliance not just as a regulatory requirement but as a strategic imperative that enhances their resilience against cyber threats. Ultimately, embracing CMMC compliance as a strategic priority will not only fortify manufacturers against cyber threats but also contribute to the integrity of national security.

Frequently Asked Questions

What is the Cybersecurity Maturity Model Certification (CMMC)?

The CMMC is a framework established by the Department of Defense (DoD) aimed at enhancing the cybersecurity posture of organizations within the defense supply chain. It includes three levels, each with specific methods and procedures for protecting Controlled Unclassified Information (CUI) and Federal Contract Information (FCI).

What are the different levels of CMMC?

The CMMC framework consists of three levels. Level 1 focuses on fundamental cyber hygiene, while Level 2 requires compliance with 93 additional methods, emphasizing a more comprehensive security strategy.

What are the assessment requirements for CMMC compliance?

Organizations must document their security measures and provide evidence of implementation to prepare for assessments. Authorized third-party evaluations by C3PAOs are required to confirm compliance with CMMC standards.

What is the estimated cost for CMMC assessments?

The estimated cost for CMMC assessments ranges from $40,000 to $80,000, not including any additional expenses for third-party services.

Why is documentation important for CMMC compliance?

Precise record-keeping of security measures and adherence efforts is essential, as documentation will be rigorously examined during assessments. Organizations must maintain detailed and organized records.

What does continuous improvement mean in the context of CMMC?

Continuous improvement involves organizations remaining vigilant and proactive in enhancing their cybersecurity measures to adapt to evolving threats and ensure compliance with regulations. This includes regularly updating policies and practices in response to changes in technology and regulatory requirements.

Why must manufacturers prioritize CMMC compliance?

Manufacturers must prioritize compliance to remain competitive and secure in a regulated environment. As of 2026, 81% of defense industrial base (DIB) organizations have started their regulatory adherence process, and compliance will be required in almost all DoD solicitations within three years.

List of Sources

  1. Understand CMMC Compliance Requirements
    • CMMC compliance reckoning for defense contractors arrives | Federal News Network (https://federalnewsnetwork.com/commentary/2025/12/cmmc-compliance-reckoning-for-defense-contractors-arrives)
    • How High a Hurdle is CMMC Compliance for Today’s DoD Suppliers? (https://pivotpointsecurity.com/how-high-a-hurdle-is-cmmc-compliance-for-todays-dod-suppliers)
    • What You Need to Know Heading Into 2026 | Fortra (https://fortra.com/blog/cmmc-compliance-what-you-need-know-heading-2026)
    • Pentagon finalizes CMMC rule, requiring continuous compliance across defense supply chain in three-year rollout – Industrial Cyber (https://industrialcyber.co/regulation-standards-and-compliance/pentagon-finalizes-cmmc-rule-requiring-continuous-compliance-across-defense-supply-chain-in-three-year-rollout)
    • Planning Your 2026 CMMC Compliance Roadmap (https://cybersheath.com/resources/blog/planning-your-2026-cmmc-compliance-roadmap)
  2. Implement Key Cybersecurity Practices for CMMC
    • CMMC: New Era of Cybersecurity Compliance for Defense Contractors | Alston & Bird (https://alston.com/en/insights/publications/2025/11/cmmc-cybersecurity-compliance-defense)
    • The CMMC readiness gap: Why many small manufacturers are unprepared | Federal News Network (https://federalnewsnetwork.com/commentary/2026/04/the-cmmc-readiness-gap-why-many-small-manufacturers-are-unprepared)
    • 112cyber.com (https://112cyber.com/blog/cmmc-compliance-in-2026)
    • CMMC Compliance in 2026: The Stakes Are High, But Success is Within Reach. (https://linkedin.com/pulse/cmmc-compliance-2026-stakes-high-success-eijqe)
    • The Critical Importance of a Robust Incident Response Plan in 2025 | Sygnia (https://sygnia.co/blog/critical-importance-incident-response-plan)
  3. Establish Continuous Monitoring and Assessment Protocols
    • Compliance and Risk Management Case Studies | Cyturus CRT (https://cyturus.com/case-studies)
    • CMMC 2.0 in 2026: What Defense Contractors Must Do Now (https://trustconsultingservices.com/cmmc-2-0-in-2026-defense-compliance-guide)
    • Pentagon finalizes CMMC rule, requiring continuous compliance across defense supply chain in three-year rollout – Industrial Cyber (https://industrialcyber.co/regulation-standards-and-compliance/pentagon-finalizes-cmmc-rule-requiring-continuous-compliance-across-defense-supply-chain-in-three-year-rollout)
    • What is Continuous Cybersecurity Monitoring? – SecurityScorecard (https://securityscorecard.com/blog/what-is-continuous-cybersecurity-monitoring)
  4. Develop Employee Training and Awareness Programs
    • New Cybersecurity Awareness Training for 2026 (https://tech.msu.edu/news/2026/03/new-cybersecurity-awareness-training-for-2026)