Moy says that the poor results of the NSS test are particularly surprising given that the vulnerabilities the lab tested were publicly described by government sources like CERT and MITRE, and the exploits they used came from the open-source penetration testingframework Metasploit.
The knowledge and experience gathered in the first year of the programme has led to the development the Framework including the competence goals, guidelines for providers, and mapping and testing tools for each of the skills.