Q2 2026 Roadmap
Overview
Unified view of Q2 2026 (April — June) deliverables across all domains. CISSP exam: July 12, 2026 (10-week plan, Week 1 active). RHCSA: Q3 2026 after CISSP.
Q2 2026 Roadmap (April — June)
Certifications
| CISSP is the priority. 10-week plan active. |
| Domain | Item | Target Date | Status | Dependencies |
|---|---|---|---|---|
Certification |
CISSP — ISC2 Certified Information Systems Security Professional |
July 12, 2026 |
ACTIVE — Week 1/10 (Domain 1: Risk) |
Sybex book, Boson exams, Pocket Prep app |
Certification |
RHCSA 9 — Red Hat Certified System Administrator |
Q3 2026 |
Ch 1-2 / 20 (10%) |
After CISSP. Lab environment (KVM) |
Certification |
Claude Code Certification — Anthropic (Nick Saraev course) |
Q2 2026 |
IN PROGRESS (26:49/4hr) |
Course completion, practice projects |
Certification |
LPIC-1 Renewal — Linux Professional Institute |
Q2 2026 |
RENEW — check expiry |
Check expiry date, register for exam |
Language |
SIELE C1 — Instituto Cervantes (computer-based) |
Q2 2026 |
ACTIVE |
Comprension auditiva practice, subjuntivo mastery |
Work Projects (CHLA)
| Domain | Item | Target Date | Status | Dependencies |
|---|---|---|---|---|
Work P0 |
SIEM QRadar → Sentinel Migration — LEAD. 4 collection iterations, Python chart pipeline, migration XLSX, verification pending. |
Q2 2026 |
ACTIVE — collection done, verification pending |
Monad pipeline, Sentinel KQL |
Work P0 |
Linux Research (Xianming Ding) — EAP-TLS completion |
Overdue (02-24) |
BEHIND (59 days) |
nmcli certificate fix |
Work P0 |
iPSK Manager — Pre-shared key automation |
— |
BEHIND |
DB replication (Ben Castillo) |
Work P0 |
MSCHAPv2 Migration — 6,084 devices, 29 types, 5-wave deployment |
Q2 2026 |
ACTIVE — weekly cadence Wed, ownership matrix defined |
netapi DataConnect queries, pandas analytics |
Work P0 |
TCP Clocks deployment — ISE identity group validation |
April 2026 |
ACTIVE — queries run, comms in progress |
Identity group verification, team coordination |
Work P0 |
Murus Portae (WAF) — Phase 0 discovery, FMC cert expired |
Q2 2026 |
INVESTIGATING — d001 has zone map, architecture D2, FMC API ref |
FMC cert fix, ACP investigation |
Work P0 |
Mandiant Remediation — findings status, guest ACL, SIEM posture report |
Q2 2026 |
ACTIVE — d001 comms Apr 23, findings from Apr 16 |
Lab validation, joint CR with NE |
Work P0 |
Research Segmentation — Untrusted VLAN migration |
— |
BLOCKED |
CISO decision |
Work P0 |
Abnormal Security — AI email security, ESA cutover |
Q2 2026 |
ACTIVE — read-only integration live |
Cutover timeline confirmation |
Work P1 |
Sentinel KQL Proficiency — queries, Copilot-assisted, differentiate from team |
April 2026 |
ACTIVE — Azure access acquired |
Azure portal access |
Work P1 |
Monad Pipeline Evaluation — LEAD. Test pipeline creation, input sources |
April 2026 |
TODO (44 days carried) |
Lab environment setup |
Work P1 |
Firewall audit — FMC device & policy inventory done (d001) |
Q2 2026 |
ACTIVE — FMC discovery complete |
EtherChannel, prefilter, policy queries |
Work P1 |
QRadar to Sentinel Migration — SIEM platform transition |
Q2 2026 |
Active — see SIEM P0 entry above |
Monad pipeline evaluation |
Work P1 |
Vocera/Wyse iTrack RCA — RabbitMQ CPU spike |
April 2026 |
OPEN |
Cisco TAC case, endpoint log analysis |
Work P1 |
Strongline Gateway — MAC capture, Identity Group setup |
Q2 2026 |
Active (39 days) |
8 devices reassignment (David Rukiza) |
Work P1 |
Downtime Computers enforcement — ISE AuthZ rule draft |
Q2 2026 |
PENDING — audit delivered, enforcement CR needed |
Separate CR after audit acceptance |
Work P1 |
NebulaONE AI Platform — Azure/Cloudforce |
Q2 2026 |
Active |
C-level direction |
Work P1 |
DMZ Migration — external services audit behind NetScaler |
Q2 2026 |
Active — linked to Murus Portae |
NetScaler reverse proxy audit |
Personal Milestones
| Domain | Item | Target Date | Status | Dependencies |
|---|---|---|---|---|
Personal |
Z Fold 7 Termux — gopass and SSH restoration |
ASAP |
BLOCKER (45 days) |
Termux SSH + gopass configuration |
Personal |
gopass v3 organization — Restructure password store |
April 2026 |
Active (35 days) |
gopass-personal-docs templates |
Personal |
Tax filing 2025 (MFJ) — deadline Apr 23 |
PAST DUE |
CONFIRM STATUS |
Alexandra W-2, 1099-NEC, 1098-E, child info |
Personal |
Housing search — Granada Hills area |
Q2 2026 |
In Progress |
Budget, location research |
Revenue |
netapi Commercialization — Go CLI rewrite, Cobra-style arg discovery |
Q2-Q3 2026 |
P0 ACTIVE |
Go evaluation, CLI framework selection |
Revenue |
Ollama API Service — 17 endpoints, productize config audit + doc tools |
Q2 2026 |
P0 ACTIVE |
Web UI, fine-tuning pipeline |
Personal |
Crypta — educational roguelike in Rust (5,490 lines). Learning Rust via game dev. |
Q2 2026 |
ACTIVE — v0.2, 10-lesson curriculum planned |
Rust lesson progression |
Personal |
ThinkPad P16g Setup — Arch install complete, Phase 12 security pending |
Q2 2026 |
OPERATIONAL — AppArmor SEC-001 remaining |
AppArmor baseline, enforce profiles |
Personal |
System State Arena — competition prep Aug 22-24 |
Aug 2026 |
Phase 0 this week (Apr 21-27) |
Daily practice, man-page-only methodology |
Infrastructure
| Domain | Item | Target Date | Status | Dependencies |
|---|---|---|---|---|
Infra |
k3s NAT verification — NAT rule 170 for pod network |
ASAP (46 days carried) |
P0 BLOCKING |
VyOS NAT rule testing |
Infra |
Wazuh indexer recovery — Restart pod after NAT fix |
After k3s NAT |
P0 Blocked |
k3s NAT verification |
Infra |
ISE Patch 10 upgrade — ISE 3.2 Patch 10 (CVE-2026-20147 CVSS 9.9) |
Q2 2026 |
P0 TODO |
Patch availability, change window |
Infra |
ISE MnT Messaging Service — Enable UDP syslog delivery |
Q2 2026 |
P2 TODO |
ISE maintenance window |
Infra |
Monad Pipeline Evaluation — Test pipeline creation |
April 2026 |
P1 TODO (44 days) |
Lab environment, test data |
Infra |
Borg backup validation — ALL systems |
Q2 2026 |
TODO |
Script path updates, initial archives |
Active Blockers
CRITICAL Blockers
| Domain | Blocker | Impact | Days | Blocked By | Action Required |
|---|---|---|---|---|---|
Work |
k3s NAT verification |
SIEM visibility blocked — Wazuh cannot start without pod networking |
46 |
VyOS NAT rule 170 untested |
Test NAT for 10.42.0.0/16 pod network, verify internet connectivity |
Work |
Wazuh indexer recovery |
No SIEM log ingestion — security blind spot |
46 |
k3s NAT verification |
Restart Wazuh pod after NAT confirmed working |
Work |
SIEM QRadar → Sentinel Migration |
Organization-wide SIEM transition. Monad console error resolved 05-12. Secrets configured. Blocked on DCR creation. |
32 |
DCR not created (Rule ID + Stream Name) + Azure private network policy |
Victor/Mauricio: create DCR. Victor: resolve Azure network policy. |
Work |
MSCHAPv2 Migration Reporting |
Report due. 6,227 devices, 5 waves. 6 batch SQL queries + 3-API profile script built (05-11). Migration window 05-04 to 05-30. |
25 |
Report needs to be turned in |
Turn in report. Batch MAC triage ready for incoming Teams disconnect request. |
Work |
Monad ETL Pipeline |
Console error resolved 05-12. 3/6 values configured. Blocked on DCR creation. |
62 |
DCR not created (Rule ID + Stream Name) |
10am call today. Victor/Mauricio: create DCR. |
Work |
Murus Portae (WAF) |
FMC management cert expired, ACP returns zero rules via API. Phase 0 discovery stalled. |
8 |
FMC cert fix, ACP investigation |
Fix FMC cert, resolve zero-rule API response, complete Q1-Q8 discovery queries |
Work |
Research Segmentation |
Research endpoints remain on trusted network |
— |
CISO decision pending |
Escalate for CISO decision on Untrusted VLAN migration |
Work |
IoT Dr. Kim — recurring incident |
Sleep study devices + watches. 3 incidents across Apr 15, 16, 22. |
9 |
iPSK enrollment validation |
Validate iPSK, check identity group stability, document IoT validation queries |
Personal |
Z Fold 7 Termux |
Cannot access passwords on mobile — no gopass, no SSH |
45 |
Termux SSH and gopass broken |
Debug Termux SSH config, reinstall gopass, test key access |
Personal |
Tax filing 2025 (MFJ) |
Deadline was Apr 23. Status unknown — confirm with user. |
1 |
Need Alexandra W-2, 1099-NEC, 1098-E, child info |
Confirm filed or escalate immediately |
Certification Deadlines
URGENT — Performance Review Certifications
| Certification | Provider | Deadline | Status | Impact |
|---|---|---|---|---|
CISSP |
ISC² — Certified Information Systems Security Professional |
July 12, 2026 |
ACTIVE — Week 2 of 10 (Project) |
Required for performance review. 10-week accelerated plan. |
RHCSA 9 |
Red Hat Certified System Administrator |
Q3 2026 |
ACTIVE — 21-phase curriculum (Project) |
After CISSP. Required for performance review. |
| CISSP: 41 days remaining (exam July 12). Domain 1 study in progress. Schedule exam today (06-01). |
Planned (After Urgent)
| Certification | Provider | Target | Status |
|---|---|---|---|
Claude Code Certification |
Anthropic |
Q2 2026 |
IN PROGRESS |
LPIC-2 |
Linux Professional Institute |
After LPIC-1 renewal |
Blocked |
DevNet Associate |
Cisco Developer Network |
Q3 2026 |
Draft (Project) |
CyberOps Associate |
Cisco Security Operations |
Q4 2026 |
Draft (Project) |
Project Pipeline
Work Projects — Critical (P0)
| ID | Project | Priority | Status | Owner | Target | Blocker |
|---|---|---|---|---|---|---|
PRJ-SEG |
Research Segmentation — Zero-trust VLAN segmentation |
P0 |
BLOCKED |
Evan |
CR due 04/13 (window 04/15) |
CISO decision pending. CR-2026-04-15 |
PRJ-LNX |
Linux Research (Ding/Shahab) — Enterprise EAP-TLS standardization |
P0 |
BEHIND |
Evan |
02-24 (overdue) |
Certificate deployment, CISO priority |
PRJ-MSCHAP |
MSCHAPv2 Migration — Legacy auth deprecation (6,084 endpoints, 29 device types) |
P0 |
BEHIND |
Evan |
— |
Data analysis complete, wave planning needed |
PRJ-IPSK |
iPSK Manager HA — Pre-shared key automation |
P0 |
Active |
Evan / Ben |
— |
Server 1 in production (HTTP/80, insecure SQL). Server 2 VM staged. Security audit needed. |
Work Projects — High Priority (P1)
| ID | Project | Priority | Status | Owner | Target | Blocker |
|---|---|---|---|---|---|---|
PRJ-ABNORMAL |
Abnormal Security — Cisco ESA → API-based email security |
P1 |
Active (newly assigned) |
Evan |
— |
Cisco → Microsoft stack shift |
PRJ-SIEM |
QRadar to Sentinel Migration — Full SIEM platform transition |
P1 |
Active |
Evan |
Q2 2026 |
Monad evaluation complete, SDK integration pending |
PRJ-MONAD |
Monad Pipeline Evaluation — ETL lead role |
P1 |
Active (32 days) |
Evan |
— |
Trial complete, 7 connectors verified |
PRJ-DMZ |
DMZ Migration — External services audit behind NetScaler |
P1 |
Active — audit phase |
Evan |
— |
None |
PRJ-ISE34 |
ISE 3.4 Migration — Upgrade from 3.2p9 |
P1 |
Blocked |
Evan |
Q1 2026 (overdue) |
ISE Patch 9 prerequisite |
PRJ-SW |
Switch Upgrades — IOS-XE fleet update (C9300, 3560CX) |
P1 |
Pending |
Evan |
Q1 2026 (overdue) |
Change window scheduling |
PRJ-SL |
Strongline Gateway — VLAN fix, MAC capture |
P1 |
Active (27 days) |
Evan / David Rukiza |
— |
8 devices in wrong identity group |
PRJ-NEB |
NebulaONE AI Platform — C-level visibility, Azure/Cloudforce |
P1 |
Active |
Evan |
— |
None |
PRJ-VOCERA |
Vocera EAP-TLS Supplicant Fix — ~10 phones failing 802.1X |
P1 |
Active (31 days) |
Evan |
— |
Missing supplicant config |
PRJ-NETDIAG |
Network Diagram Library — L1-L7 enterprise D2 diagrams |
P1 |
Active — scaffolding |
Evan |
— |
New project, team presentation 04/13 |
Personal Projects — Active
| ID | Project | Priority | Status | Owner | Target | Blocker |
|---|---|---|---|---|---|---|
PRJ-CC |
Claude Code — Skills, hooks, MCP servers, agents |
P0 |
Active (v2) |
Evan |
— |
None |
PRJ-CERT |
Certifications — CISSP (July 12), RHCSA (Q3). 17 total planned. |
P0 |
ACTIVE — CISSP Week 1/10 |
Evan |
July 12, 2026 |
70 days remaining (CISSP) |
PRJ-BIB |
PRJ-BIBLIOTHECA — Multi-spoke scripture/literature library |
P1 |
Active — Phase 1 complete |
Evan |
— |
Hub deploy blocked by CF build timeout (SC-001) |
PRJ-DIAG |
Domus Diagrams — Visual knowledge system (8 domains) |
P1 |
Active — scaffolding |
Evan |
— |
New project |
PRJ-DQ |
dots-quantum — Dotfiles framework (35 stow packages) |
P1 |
Active (Primary) |
Evan |
— |
None |
PRJ-NVIM |
domus-nvim — Neovim configuration |
P1 |
Active Development |
Evan |
— |
None |
PRJ-NAPI |
netapi — Network automation library (23 vendors) |
P1 |
Active (Alpha) |
Evan |
— |
None |
PRJ-RADIO |
Amateur Radio — Technician to General, mentor Cliff |
P2 |
Active |
Evan |
— |
None |
PRJ-DD |
Domus Digitalis — Next.js/TypeScript webapp |
P2 |
Active |
Evan |
— |
None |
PRJ-MATH |
domus-math — College Algebra through applied crypto |
P1 |
Active |
Evan |
— |
None |
PRJ-SIEM-R |
SIEM: QRadar to Sentinel — Migration with Monad log filtering |
P1 |
Active |
Evan |
Q2 2026 |
Monad evaluation |
ITSM Summary
ITSM Ticket Counts
| Type | Open | Pending | Total |
|---|---|---|---|
Service Requests (SR) |
2 |
0 |
2 |
Incidents (INC) |
1 |
0 |
1 |
Change Requests — Emergency |
0 |
0 |
0 |
Change Requests — Normal |
0 |
0 |
0 |
Change Requests — Scheduled |
0 |
0 |
0 |
Change Requests — RCA |
1 |
0 |
1 |
TOTAL |
4 |
0 |
4 |