Cybersecurity Merit Badge
Nine requirements, and the one that matters most is easy to throw away: 4(f) asks you to list your own cyber attack surface, and two later options are exactly the work of acting on that list, though the badge never connects them. Requirement 5(c) offers nine options and needs three, several of which are the same evening. One option needs the system owner's permission and has a legal edge. Two of the four cryptography routes need another person to take part.
The plan behind this
Keep the list you make in 4(f)
Requirement 4(f) is the only step on this badge that produces an artifact. Everything else is explained, described, defined or discussed. 4(f) asks you to write out your cyber attack surface: the accounts, apps, devices and networks through which somebody could reach your personal information.
Now look at what requirement 5 offers, one requirement later:
| option | what it actually is |
|---|---|
| 5(c)(8) | research best practices for a home computer or network, and write a checklist of five things your family can do |
| 5(c)(9) | find a real vulnerability on your home computer or network and, with the system owner's permission, fix it |
Those two are the second half of 4(f). The list tells you what to protect; these tell you to protect it. The badge does not connect them, and this plan does not draw an arrow where the badge states none, but a reader who keeps the 4(f) list has already done most of the thinking for both.
Write it somewhere you will still have it: a note file, not the back of a meeting handout.
Requirement 5(c): nine options, three needed, and some are the same evening
This is the largest menu on the badge. Picked carelessly it is three separate projects. Picked well it is one sitting.
| pick these together | why |
|---|---|
| 5(c)(1) a strong password, 5(c)(3) a password manager | The manager generates the strong password. Installing one and then setting a password with it is one job that answers two options |
| 5(c)(5) running processes, 5(c)(6) open network connections | The same terminal window and the same skill. If you open one you are already set up for the other |
| 5(c)(8) a home security checklist, 5(c)(9) find and fix a vulnerability | Both are your own home network, and 4(f) is the list they both work from |
The remaining three stand alone: 5(c)(2) multi-factor authentication, 5(c)(4) a virus scan, 5(c)(7) backing up a mobile device.
The whole of 5(c) needs your parent or guardian's permission before you start, and that covers all three of whatever you choose.
The one option with a legal edge
5(c)(9) Identify one or more other vulnerabilities on your home computer or network, or another computer or network you have permission to use, and discuss with your counselor. With permission from the system owner, take the necessary actions to fix it.
Permission is stated twice in one requirement, and that is not an accident. Everything else on this badge is done to your own devices or in a browser. This one sends you looking for weaknesses.
Scanning, probing or "testing" a network you do not own is not a grey area. It does not become acceptable because the intent was educational, because nothing broke, or because you meant to tell them afterwards. School networks, a friend's home network, a library and a coffee shop are all somebody else's systems.
If you want this option, the clean version is your own home network, with the person who pays for the internet connection told in advance what you are doing and what you propose to change. Requirement 2 is where the badge explains why this matters, and it is worth reading 2(b) again before choosing this option rather than after.
Cryptography: two of these four need another person
| route | can you do it alone? |
|---|---|
| 6(c)(1) build your own cipher and use it | Yes. Paper, or a few lines of code |
| 6(c)(2) set up an end-to-end encrypted app | Yes. An official app store and an account |
| 6(c)(3) hash a file, have it changed, hash it again | No. A fellow Scout or your counselor has to alter the file between the two checksums |
| 6(c)(4) create a PGP key, exchange public keys, send an encrypted message | No, and it is the largest. Other people must have PGP keys of their own, give you their public keys, take yours, and receive the message |
The badge prints all four as equal members of one list. 6(c)(4) is not equal. It needs software installed, a key pair generated, a keyring populated with other people's keys, and at least one other person who has done the same. If nobody in your troop already uses PGP, that option is a project rather than an evening.
6(c)(3) is the quiet one worth choosing, because the person who changes your file needs to do nothing but change it, and your counselor can do that in the meeting where you show it.
Requirement 7 is twelve answers, and it looks like one
Describe to your counselor four electronic devices you encounter that could be connected to the internet, why this connectivity can be useful, what risks are posed by the connectivity, and how they could be protected.
No letters. No sub-parts. One sentence, four devices, and three questions about each of them. That is twelve answers, and it is the shortest-looking requirement on the page.
Prepare it as a table rather than as a paragraph, and the shape of it stops being a trap.
Three permissions and one video that is not only this badge's
| step | what it needs |
|---|---|
| 1(a) | your parent or guardian's permission to view the safety video |
| 4(e)(2) | your parent or guardian's permission, if you take the film or book route |
| 5(c) | your parent or guardian's permission, covering all three options you choose |
| 5(c)(9) | the system owner's permission as well, which is a different person and a different question |
Five merit badges require the same Personal Safety Awareness "Digital Safety" video. On four of them, including this one, it is a lettered or numbered requirement in identical words: Cybersecurity 1(a), Programming 1(a), Digital Technology 1 and Photography 1(b). On Competitive Gaming it appears as a note inside requirement 2 rather than as a step of its own. Whether viewing it once can satisfy more than one badge is a question for your counselor and not one this page will answer, but it is worth raising rather than discovering.
What has no second source
Almost every badge can be read twice: the page, and then the printed requirements book or the badge pamphlet. This badge has neither. It has no pamphlet at all, and the 2025 printed requirements book does not contain it. The word cybersecurity does not appear in that book once.
That is not a problem to solve, it is a fact to record. It means the page is the only authority, so the date it was read matters more here than usual, and it is printed on this plan. Before you rely on any of this, open the official requirements and check they still say what this page says they say.
The Cybersecurity merit badge, drawn so the list you make early is still useful later. It is not a copy of the requirements: each step is a short label with a link to the official requirements, which are what actually governs and which change from year to year.
Sources for this page
- Cybersecurity Merit Badge Requirements, Merit Badge Hub, last modified 2025-12-31 · The requirements themselves, and the free official pamphlet linked from them.
- Guide to Advancement, 2025, Section 7.0.0.3 · The process every merit badge is earned through, which this page does not repeat.
- Guide to Advancement, 2025, Section 7.0.4.3 · Which version of a changed requirement applies to a Scout who has already started.
- Guide to Advancement, 2025, Section 4.0.0.1 · Why the requirements are not in the Guide to Advancement and are expected to change annually.
Last checked against its sources on .