Q2 2026 Roadmap
Overview
Unified view of Q2 2026 (April — June) deliverables across all domains. Hard deadline: June 1, 2026 for CISSP and RHCSA certifications (performance review).
Q2 2026 Roadmap (April — June)
Certifications (HARD DEADLINE: June 1)
| Performance review deadline. These are non-negotiable. |
| Domain | Item | Target Date | Status | Dependencies |
|---|---|---|---|---|
Certification |
CISSP — ISC2 Certified Information Systems Security Professional |
June 1, 2026 |
NOT STARTED |
Study plan needed, exam scheduling |
Certification |
RHCSA 9 — Red Hat Certified System Administrator |
June 1, 2026 |
Ch 1-2 / 20 |
Lab environment (KVM), study schedule |
Certification |
Claude Code Certification — Anthropic (Nick Saraev course) |
Q2 2026 |
IN PROGRESS (26:49/4hr) |
Course completion, practice projects |
Certification |
LPIC-1 Renewal — Linux Professional Institute |
Q2 2026 |
RENEW |
Check expiry date, register for exam |
Language |
SIELE C1 — Instituto Cervantes (computer-based) |
Q2 2026 |
ACTIVE |
Comprension auditiva practice, subjuntivo mastery |
Work Projects (CHLA)
| Domain | Item | Target Date | Status | Dependencies |
|---|---|---|---|---|
Work P0 |
Linux Research (Xianming Ding) — EAP-TLS completion |
Overdue (02-24) |
BEHIND |
nmcli certificate fix |
Work P0 |
iPSK Manager — Pre-shared key automation |
— |
BEHIND |
DB replication (Ben Castillo) |
Work P0 |
MSCHAPv2 Migration — Run netapi reports, pandas graphs, Chromebook+Wyse wave (~2K/8K endpoints) |
Q2 2026 |
URGENT — team meeting |
netapi DataConnect queries, pandas analytics |
Work P0 |
Research Segmentation — Untrusted VLAN migration |
— |
BLOCKED |
CISO decision |
Work P1 |
Sentinel KQL Proficiency — First access, Copilot-assisted queries, differentiate from team |
April 2026 |
NEW — onboarding |
Azure portal access acquired |
Work P1 |
QRadar to Sentinel Migration — SIEM platform transition (leading) |
Q2 2026 |
Active |
Monad pipeline evaluation |
Work P1 |
Vocera/Wyse iTrack RCA — RabbitMQ CPU spike, no definitive root cause |
April 2026 |
OPEN |
Cisco TAC case, endpoint log analysis |
Work P1 |
Spikewell BYOD VPN — dACL SQL, AD group integration |
Q2 2026 |
Active |
None |
Work P1 |
Strongline Gateway — MAC capture, Identity Group setup |
Q2 2026 |
Active |
8 devices reassignment (David Rukiza) |
Work P1 |
NebulaONE AI Platform — Azure/Cloudforce |
Q2 2026 |
Active |
C-level direction |
Personal Milestones
| Domain | Item | Target Date | Status | Dependencies |
|---|---|---|---|---|
Personal |
Z Fold 7 Termux — gopass and SSH restoration |
ASAP |
BLOCKER |
Termux SSH + gopass configuration |
Personal |
gopass v3 organization — Restructure password store |
April 2026 |
Active |
gopass-personal-docs templates |
Personal |
P50 Arch to Ubuntu migration |
April 2026 |
IN PROGRESS |
LUKS encryption, Steam testing |
Personal |
X1 Carbon Ubuntu installs — 2 laptops |
April 2026 |
IN PROGRESS |
LUKS encryption |
Personal |
Housing search — Granada Hills area |
Q2 2026 |
In Progress |
Budget, location research |
Personal |
Tax preparation — 2025 filing |
April 15, 2026 |
Not started |
Gather documents |
Revenue |
netapi Commercialization — Go CLI rewrite, Cobra-style arg discovery, package for distribution |
Q2-Q3 2026 |
P0 ACTIVE |
Go evaluation, CLI framework selection |
Revenue |
Ollama API Service — 17 endpoints, productize config audit + doc tools + runbook gen |
Q2 2026 |
P0 ACTIVE |
Web UI, fine-tuning pipeline |
Personal |
ThinkPad T16g Setup — Arch install, stow, Ollama, netapi dev |
Apr 2-3, 2026 |
PENDING |
Delivery Thursday |
Infrastructure
| Domain | Item | Target Date | Status | Dependencies |
|---|---|---|---|---|
Infra |
k3s NAT verification — NAT rule 170 for pod network |
ASAP (21 days carried) |
P0 BLOCKING |
VyOS NAT rule testing |
Infra |
Wazuh indexer recovery — Restart pod after NAT fix |
After k3s NAT |
P0 Blocked |
k3s NAT verification |
Infra |
ISE Patch 9 upgrade — ISE 3.2 Patch 9 |
Q2 2026 |
P2 TODO |
Change window, TAC guidance |
Infra |
ISE MnT Messaging Service — Enable UDP syslog delivery |
Q2 2026 |
P2 TODO |
ISE maintenance window |
Infra |
Monad Pipeline Evaluation — Test pipeline creation |
April 2026 |
P1 TODO |
Lab environment, test data |
Active Blockers
CRITICAL Blockers
| Domain | Blocker | Impact | Days | Blocked By | Action Required |
|---|---|---|---|---|---|
Work |
k3s NAT verification |
SIEM visibility blocked — Wazuh cannot start without pod networking |
21 |
VyOS NAT rule 170 untested |
Test NAT for 10.42.0.0/16 pod network, verify internet connectivity |
Work |
Wazuh indexer recovery |
No SIEM log ingestion — security blind spot |
21 |
k3s NAT verification |
Restart Wazuh pod after NAT confirmed working |
Work |
MSCHAPv2 Migration Reporting |
Team waiting for endpoint data + auth trend graphs (Chromebook + Wyse wave) |
0 |
Need to run netapi queries |
Execute ise-mschapv2-audit.py → profiler-migration-analytics.py → pandas dashboard |
Work |
Monad ETL Pipeline |
Blocks QRadar → Sentinel log source migration |
21 |
Vendor delivery pending |
Lead evaluation, prepare lab environment |
Work |
Research Segmentation |
Research endpoints remain on trusted network |
— |
CISO decision pending |
Escalate for CISO decision on Untrusted VLAN migration |
Personal |
Z Fold 7 Termux |
Cannot access passwords on mobile — no gopass, no SSH |
20 |
Termux SSH and gopass broken |
Debug Termux SSH config, reinstall gopass, test key access |
Certification Deadlines
URGENT — Performance Review Deadline (June 1, 2026)
| Certification | Provider | Deadline | Status | Impact |
|---|---|---|---|---|
CISSP |
ISC² — Certified Information Systems Security Professional |
June 1, 2026 |
ACTIVE — Phase 0 (Project) |
Required for performance review |
RHCSA 9 |
Red Hat Certified System Administrator |
June 1, 2026 |
ACTIVE — 21-phase curriculum (Project) |
Required for performance review |
| 55 days remaining until June 1st deadline. |
Planned (After Urgent)
| Certification | Provider | Target | Status |
|---|---|---|---|
Claude Code Certification |
Anthropic |
Q2 2026 |
IN PROGRESS |
LPIC-2 |
Linux Professional Institute |
After LPIC-1 renewal |
Blocked |
DevNet Associate |
Cisco Developer Network |
Q3 2026 |
Draft (Project) |
CyberOps Associate |
Cisco Security Operations |
Q4 2026 |
Draft (Project) |
Project Pipeline
Work Projects — Critical (P0)
| ID | Project | Priority | Status | Owner | Target | Blocker |
|---|---|---|---|---|---|---|
PRJ-LNX |
Linux Research (Xianming Ding) — EAP-TLS, dACL, UFW |
P0 |
BEHIND |
Evan |
02-24 (overdue) |
Certificate "password required" — nmcli fix documented |
PRJ-IPSK |
iPSK Manager — Pre-shared key automation |
P0 |
BEHIND |
Ben Castillo |
— |
DB replication issues |
PRJ-MSCHAP |
MSCHAPv2 Migration — Legacy auth deprecation (6,088 devices, 5 waves) |
P0 |
BEHIND |
Evan |
— |
No progress on planning |
PRJ-SEG |
Research Segmentation — All endpoints to Untrusted VLAN |
P0 |
BLOCKED |
Evan |
— |
CISO decision pending |
Work Projects — High Priority (P1)
| ID | Project | Priority | Status | Owner | Target | Blocker |
|---|---|---|---|---|---|---|
PRJ-ISE34 |
ISE 3.4 Migration — Upgrade from 3.2p9 |
P1 |
Blocked |
Evan |
Q1 2026 (overdue) |
ISE Patch 9 prerequisite |
PRJ-SW |
Switch Upgrades — IOS-XE fleet update (C9300, 3560CX) |
P1 |
Pending |
Evan |
Q1 2026 (overdue) |
Change window scheduling |
PRJ-VPN |
Spikewell BYOD VPN — dACL SQL, AD group integration |
P1 |
Active |
Evan |
— |
None |
PRJ-SL |
Strongline Gateway — MAC capture, Identity Group setup |
P1 |
Active |
Evan |
— |
8 devices in wrong identity group |
PRJ-SIEM |
QRadar to Sentinel Migration — Full SIEM platform transition, Monad evaluation |
P1 |
Active |
Evan |
Q2 2026 |
Monad pipeline evaluation pending |
PRJ-NEB |
NebulaONE AI Platform — C-level visibility, Azure/Cloudforce |
P1 |
Active |
Evan |
— |
None |
Personal Projects — Active
| ID | Project | Priority | Status | Owner | Target | Blocker |
|---|---|---|---|---|---|---|
PRJ-CC |
Claude Code Features — Skills, hooks, MCP servers, agents |
P0 |
Planning |
Evan |
Q2 2026 |
None |
PRJ-CERT |
Certifications — CISSP, RHCSA (17 total planned) |
P0 |
In Progress |
Evan |
June 1, 2026 |
63 days remaining |
PRJ-RADIO |
Amateur Radio — Technician to General, mentor Cliff |
P2 |
Active |
Evan |
— |
None |
PRJ-DD |
Domus Digitalis — Next.js/TypeScript project management webapp |
P2 |
Active |
Evan |
— |
None |
PRJ-SIEM-R |
SIEM: QRadar to Sentinel — Migration with Monad log filtering |
P1 |
Active |
Evan |
Q2 2026 |
Monad evaluation |
ITSM Summary
ITSM Ticket Counts
| Type | Open | Pending | Total |
|---|---|---|---|
Service Requests (SR) |
2 |
0 |
2 |
Incidents (INC) |
1 |
0 |
1 |
Change Requests — Emergency |
0 |
0 |
0 |
Change Requests — Normal |
0 |
0 |
0 |
Change Requests — Scheduled |
0 |
0 |
0 |
Change Requests — RCA |
1 |
0 |
1 |
TOTAL |
4 |
0 |
4 |