CyberPatriot is the competition where high school and middle school students stop reading about security and start fixing it. Your team gets a Windows machine and a Linux machine that someone has quietly broken, and you have four hours to find the weak passwords, rogue admins, open services, and hidden malware before the clock runs out. Much of the work comes down to one skill: knowing who should have access to a system and what they should be allowed to do. If you want a head start this week, work through the Linux users, groups, and permissions chapter on HackerDNA. It covers exactly the files and commands you will touch in your first round.
This guide explains how CyberPatriot works, what the 2026-27 season (CyberPatriot 19) looks like, what the images actually test, and how to prepare without breaking the rules. It is written for students and new coaches who have never seen a competition image before.
TL;DR: CyberPatriot is the Air & Space Forces Association's national youth cyber defense competition. Teams of two to six students harden Windows and Linux virtual machines and answer Cisco networking challenges, one four-hour round a month from October to January. CyberPatriot 19 registration was extended to October 8, 2026, Round 1 runs October 22-25, and the best teams travel all-expenses paid to the National Finals in Maryland in March 2027.
What Is CyberPatriot?
CyberPatriot is the National Youth Cyber Education Program, created by the Air & Space Forces Association (AFA) to push K-12 students toward cybersecurity and STEM careers. Its core event is the National Youth Cyber Defense Competition, which the program calls "the nation's largest cyber defense competition."
The scale backs that up. The program started as a proof of concept in 2009, and the CyberPatriot 18 season (2025-26) opened with 4,787 registered teams, according to the official season recap.
The premise is simple. Your team plays newly hired IT staff at a small company. The previous admin left a mess, and your job is to secure the systems while keeping the services the business needs running. That second half matters more than beginners expect, and we will come back to it.
Teams compete in one of three divisions, and they never compete across divisions:
| Division | Who can join | Fee per team (CP19) |
|---|---|---|
| Open | High school students from schools, homeschool programs, scouting units, Boys and Girls Clubs, YMCAs, and other approved youth organizations | $225 |
| All Service | High school students in Army, Navy, Marine Corps, Air Force, Space Force, or Coast Guard JROTC, Civil Air Patrol, or the Naval Sea Cadet Corps | Waived automatically |
| Middle School | Middle school and junior high students from the same kinds of organizations as the Open Division | $175 |
Title I schools can request a fee waiver, and fees are waived on request for all-girl teams. Source: the CyberPatriot schedule and fees page.
How a CyberPatriot Round Works
Every online round follows the same rhythm, and the logistics stop being scary after the first one.
- Download early. On the Monday before a round, your coach receives links to the virtual machine images. They are large files, so download them days ahead and check the MD5 checksum.
- Get the password. On Thursday at 9:00 AM ET, the "StartEx" email arrives with the password that unlocks the images.
- Pick your four hours. Teams choose one continuous four-hour block between Thursday morning and Sunday evening. The clock starts the moment you power on your first image, not when you feel ready.
- Enter your Unique ID. Each image asks for your team's 12-character identifier so the scoring server knows who you are.
- Fix, score, repeat. A scoring report on the desktop updates as you work. Fix a checked vulnerability and points appear. Make the system less secure and points disappear.
Up to six students can be on a roster, but only five compete at once, with one substitution allowed per round. Each round has two parts: the Network Security Challenge (the operating system images) and the Cisco Networking Challenge, which is a quiz plus a Packet Tracer network simulation on Cisco's NetAcad site.
Here is how CyberPatriot 19's Round 1 is scored for Open and All Service teams:
| Challenge | Points |
|---|---|
| Windows 11 image | 100 |
| Linux Mint 21 image | 100 |
| Cisco networking quiz (modules 3-7) | 10 |
| Packet Tracer exercise (modules 1-7) | 20 |
| Total | 230 |
Look at that split. The images are worth 200 of 230 points, which is why most of this guide is about them. Later rounds add Windows Server 2022 and Debian 12, and the Semifinals bring in FreeBSD and a web-based challenge for the top tiers.
Two scoring details catch new teams off guard. First, the official rules say "not all vulnerabilities in an image are scored," so a fix that earns nothing is not proof you did it wrong. Second, you can lose points for any action that "conflicts with the scenario," such as deleting a user the company needs or shutting down a service the scenario says must stay up. The good news: points lost to penalties come back once you undo the mistake.
CyberPatriot 19 Schedule and Registration (2026-27)
If you are reading this in early October 2026, you are not too late. The CyberPatriot homepage says team registration has been "EXTENDED to Oct. 8th" in honor of Cybersecurity Awareness Month. A coach registers the team, and payment is due by November 5, 2026. Here are the dates that matter for this season:
| Event | Dates | Counts toward score? |
|---|---|---|
| Practice Round | October 7-20, 2026 | No, but every team should test an image |
| Round 1 (Open and All Service) | October 22-25, 2026 | Yes |
| Training Round 2 (with answer keys) | Starts October 30, 2026 | No |
| Round 2 / Middle School Introductory Round | November 12-15, 2026 | Yes |
| State Round | December 10-13, 2026 | Yes |
| Semifinals (qualifiers only) | January 21-23, 2027 | Yes |
| National Finals (in person) | March 12-16, 2027 | Yes |
After Round 2, high school teams are split into tiers: Platinum for the top 30%, Gold for the middle 40%, and Silver for the rest. The State Round is a clean slate, and teams compete within their tier for state awards and Semifinal spots. In the Open Division, the top 25% of each tier advance, plus a wildcard for any state with no qualifier.
What you need to compete
Hardware is the hidden blocker for school teams, so check it now rather than on Thursday morning. According to the CyberPatriot technical specifications, each host computer needs:
- A 64-bit Windows 10 (with current security updates) or Windows 11 host. Macs and Linux hosts work "at the team's own risk."
- 8 GB of RAM and 40 GB of free disk space.
- Virtualization (VT-x or AMD-V) enabled in the BIOS. Some images will not open without it.
- VMware Workstation Pro 26H1, which is free, plus 7-Zip and WinMD5.
- Outbound access on ports 80 and 443 to the scoring servers. School firewalls are the most common problem teams hit.
What CyberPatriot Images Actually Test
CyberPatriot does not publish the vulnerabilities in advance, but its Rules Book lists the general categories that results emails use. Read this list as your study plan:
- Users and passwords: User Policy, Password Policy, Login Policy, and Access control and settings.
- Services and network: Insecure services, Firewall, and File sharing and permissions.
- Maintenance: Updates and Antivirus.
- Cleanup: Malware, plus Policy violations for files or services the company does not allow.
- Investigation: Forensics Questions, which ask you to find and report something on the system, plus a Miscellaneous bucket.
Almost all of it is system administration done carefully. The best way to learn it is to build a clean virtual machine and practice on it, which is what the official Linux training page suggests too. Here is what that practice looks like.
Linux: start with who can log in and who is root
Every image comes with a README that describes the scenario: which users are authorized, who should be an administrator, and which services must keep running. In practice, user and group mistakes are the fastest findings on any image, because the README tells you exactly what the right answer looks like. Your first job on Linux is to compare reality against that list.
$ awk -F: '$3 >= 1000 && $3 < 65534 {print $1}' /etc/passwd
alice
bob
mallory
$ getent group sudo
sudo:x:27:alice,mallory
The first command lists human accounts (regular users get IDs from 1000 up on Debian-based systems like Mint). The second shows who has admin rights. If the README says only Alice is an administrator, Mallory should not be in that group:
$ sudo gpasswd -d mallory sudo
Removing user mallory from group sudo
Then check the firewall and look at what is listening on the network:
$ sudo ufw enable
Firewall is active and enabled on system startup
$ sudo ss -tlnp
State Recv-Q Send-Q Local Address:Port Peer Address:Port Process
LISTEN 0 32 0.0.0.0:21 0.0.0.0:* users:(("vsftpd",pid=812,fd=3))
LISTEN 0 128 0.0.0.0:22 0.0.0.0:* users:(("sshd",pid=655,fd=3))
An FTP server on port 21 is a classic finding, but only if the scenario does not need it. If the README says the company runs a file server, harden it instead of removing it.
If /etc/passwd, groups, and permission bits still feel abstract, the HackerDNA Linux hardening chapter goes further with sudoers, auditd, and sysctl settings, and explains which attack each control blocks.
Windows: the same questions, different tools
On Windows 11 and Server 2022, the questions do not change: who are the users, who are the admins, is the firewall on, what is the password policy. PowerShell answers most of them quickly:
PS> Get-LocalGroupMember Administrators
PS> Get-NetFirewallProfile | Select Name, Enabled
Name Enabled
---- -------
Domain True
Private True
Public False
PS> net accounts
Minimum password length: 0
Maximum password age (days): 42
Lockout threshold: Never
A disabled Public firewall profile, no minimum password length, and no lockout are three separate findings on that output alone. You can fix them through the Local Security Policy console (secpol.msc) or from the command line, for example with Set-NetFirewallProfile -Profile Domain,Public,Private -Enabled True. Then check Windows Update, Microsoft Defender, running services, and shared folders.
For a structured way to think about Windows defenses, our Windows hardening lesson maps controls like LAPS and Credential Guard to the attacks they stop. Asking "which attack does this setting block?" is what makes fixes stick.
Build your own checklist. Printed and handwritten checklists are allowed in competition. But the rules forbid using any online resource "specifically created for the CyberPatriot competition" during a round, and they forbid publicly posting resources made for it. Downloaded "CyberPatriot checklists" and shared scripts are exactly what those rules target. Write yours as a team, from general documentation like the CIS Benchmarks and Microsoft's and Ubuntu's own docs.
How to Prepare for CyberPatriot in 4 Weeks
This plan assumes a few hours a week per student. If Round 1 is less than four weeks away, squeeze weeks 1 and 2 together and treat Round 1 as a rehearsal. Round 2 in mid-November is harder, and it decides your tier for the State Round, so that is where the preparation pays off.
- Week 1 - Linux basics on a clean VM. Install Ubuntu or Mint in VMware Workstation Pro. Practice adding and removing users, changing groups, reading
/etc/passwdand/etc/group, setting file permissions, and usingaptandufw. - Week 2 - Windows basics. On a Windows VM, practice Local Users and Groups,
secpol.mscfor password and lockout policy, Windows Firewall, Windows Update, services, and Event Viewer. - Week 3 - Training images with answer keys. The Practice Round (October 7-20) re-releases the training images with answer keys, and Training Round 2 adds harder ones from October 30. Do an image without looking, then read the key and note every finding you missed. Those notes become your checklist.
- Week 4 - Split roles and rehearse. Assign one or two people per image and one person to the Cisco challenge. Do a timed run. Agree on a rule: nobody deletes a user or a service without checking the README first.
One opinionated tip: do not start with scripts. The rules allow scripts your own team wrote during online rounds, at your own risk, but they are banned at the National Finals, which "tests the team's fundamental skills." A script also hides what it changed, so when your score drops, you have no idea why. Learn to do every fix by hand first, keep a written log of each change, and automate later if you still want to.
The Cisco side deserves real time too. It is only 30 points in Round 1, but it grows to 100 points per round in the State Round and Semifinals for high school teams. Make one student its owner early.
CyberPatriot Rules That Trip Up New Teams
Plenty of penalties have nothing to do with security skill. The CyberPatriot 19 Rules Book is long, but these are the rules new teams most need to know:
- No outside help during a round. Coaches and mentors can handle logistics and timekeeping, but they cannot give advice once the round starts. That includes posting questions to forums.
- No AI during rounds. CyberPatriot 19 prohibits AI tools during competition rounds, including chatbots and AI-generated scripts. Paid AI products are banned at any time in connection with the competition. Free AI tools are allowed for training outside rounds.
- One copy of each image at a time. Opening the same image on two computers triggers a multiple instance penalty.
- Four hours means four hours. The clock starts when the first image powers on. Opening an image "just to check" on Wednesday starts your round early.
Is CyberPatriot Worth It?
Yes, especially if you are a high school student who has never touched a real system. Our honest take is that CyberPatriot teaches a skill most beginner CTFs skip: defense under constraints. A CTF asks you to find one flag. CyberPatriot asks you to secure an entire machine without breaking the business that runs on it, which is much closer to an entry-level IT or SOC job.
It also has real rewards. National Finalists travel all-expenses paid, the program says top teams can "earn national recognition and scholarship money," and students who reach the National Finals in all four high school seasons are named Cyber All-Americans. Even a state tier award is a concrete line for a college application.
The limits are worth knowing too:
- You need a coach and an organization. A student cannot register alone. If your school has no team, ask a teacher, a homeschool group, a scouting unit, a Civil Air Patrol squadron, or a Boys and Girls Club to sponsor one.
- It is seasonal. After January, only the finalists keep competing. You need somewhere to practice the rest of the year.
- It is almost entirely defense. You will learn very little about how attacks work, which is half of understanding why a fix matters.
That last point is why we would pair it with offense. If you enjoy CyberPatriot, the National Cyber League is the natural next competition: it runs individual and team games each fall and spring, covers log analysis and password cracking alongside offensive categories, and accepts high school students. For year-round practice, our guide to getting started with CTFs shows how to switch from fixing vulnerabilities to finding them.
Legal and Ethical Considerations
Critical reminder: CyberPatriot images are built for you to change. Your school's computers, network, and accounts are not. Always get explicit written authorization before testing or reconfiguring any system you do not own.
- Practice on your own VMs: build clean Windows and Linux virtual machines for training, and never "practice hardening" on a shared school lab computer.
- Do not share competition material: the rules forbid posting image content, challenge wording, or scripts made for the competition. Sharing answers can disqualify your whole team.
- Respect the scenario: in the competition and in a real job, a security fix that breaks a business service is a failure, not a win.
- Follow your school's policies: where a school's rules are stricter than CyberPatriot's, for example on AI use, the school's rules apply.
Frequently Asked Questions
What is CyberPatriot in JROTC?
JROTC units compete in CyberPatriot's All Service Division, alongside Civil Air Patrol and Naval Sea Cadet Corps teams. Its registration fee is waived automatically, and each organization type (Army JROTC, Navy and Coast Guard JROTC, Civil Air Patrol, and so on) is its own category for some awards and Semifinal spots.
Who runs CyberPatriot?
The Air & Space Forces Association (AFA) runs CyberPatriot from Arlington, Virginia. The scoring system behind the images, the CyberPatriot Competition System, was built with the Center for Infrastructure Assurance and Security at the University of Texas at San Antonio.
Is CyberPatriot prestigious?
It is the largest youth cyber defense competition in the US, with 4,787 teams registered for CyberPatriot 18, so reaching the Platinum Tier, the Semifinals, or the National Finals stands out. Simply participating is less rare, but it still shows real hands-on experience.
Is CyberPatriot a CTF?
No. A capture the flag competition rewards you for finding hidden flags, usually by attacking something. CyberPatriot rewards you for securing systems: each scored fix on a Windows or Linux image adds points, and insecure changes remove them.
Do I need experience to join CyberPatriot?
No. CyberPatriot says it is "designed for any student, regardless of prior cybersecurity knowledge." Round 1 tests the basics, and the training and practice rounds include answer keys so new teams can learn from their mistakes.
Can I use ChatGPT in CyberPatriot?
Not during competition rounds. The CyberPatriot 19 Rules Book bans AI tools and AI-generated scripts during rounds, and bans paid AI products in connection with the competition at any time. Free AI tools are allowed only for training outside the rounds.
Last verified: October 2026. Dates, fees, scoring values, and rules checked on uscyberpatriot.org and in the CyberPatriot 19 Rules Book (September 2026 edition).
Your Next Steps
CyberPatriot rewards teams that know Windows and Linux administration cold, read the README before touching anything, and keep notes on every change. If you are a student, find a coach before the October 8 deadline. If you missed it, start practicing now and aim for CyberPatriot 20 next season: teams that show up already comfortable with users, permissions, and firewalls have the best shot at Platinum.
To build those skills alongside your team practice, start with the Linux users and permissions chapter, then crack the Shadow Cracker lab to see weak passwords from the attacker's side. Everything runs in the browser, which helps on a locked-down school laptop, and you can start with HackerDNA's free tier - no credit card required.