Skip to content

SCORM & Third-Party Content Ingestion: Bring Your Own Courseware

1. Executive Summary & Value Proposition

Enterprises often invest substantial resources developing proprietary compliance courses or licensing bespoke e-learning content from specialized industry providers. Migrating to a modern Security Awareness Training platform should never mean abandoning those investments. SimuPhish’s SCORM Ingestion Engine provides native, turn-key support for industry-standard SCORM 1.2 and SCORM 2004 packages, allowing organizations to run their existing courseware alongside modern simulations on a single unified platform.


2. The Threat Landscape & The Real-World Problem Solved

  • The "Two-LMS" Overhead: Many companies run their security simulations on one tool while hosting proprietary compliance courses on an expensive, legacy HR LMS. This creates fragmented employee experiences, disjointed analytics, and manual spreadsheet consolidation during audits.
  • Vendor Lock-In: Traditional security awareness vendors lock customers into proprietary content formats, making it impossible to import external courses or export training history.
  • Large File Upload Bottlenecks: Modern e-learning modules featuring 4K video and branching animations often exceed 500MB to 2GB in size, failing on standard web upload forms.

3. How It Works (The User Journey)

The Administrator Experience

  1. Effortless Package Uploader: Upload standard SCORM .zip archives directly through the administrative portal. SimuPhish’s reliable upload pipeline easily handles large interactive packages even on standard connections.
  2. Automated Antivirus Inspection: Incoming archives are automatically scanned by integrated security engines to guarantee that third-party files contain zero malicious macros or embedded scripts.
  3. Automated Course Extraction: The system automatically extracts course structure, launch paths, mastery passing scores, and prerequisite rules.
  4. Unified Assignment & Tracking: Assign the third-party SCORM package just like any native SimuPhish course.

The Employee Experience

  1. The employee clicks their secure link and launches the course inside a seamless, responsive browser player.
  2. The runtime engine automatically saves lesson progression, quiz scores, and session duration, allowing employees to pause and resume seamlessly across devices.
  3. If an employee leaves mid-course, their progress is saved automatically, allowing them to resume seamlessly on desktop or mobile.
graph TD
    Author["Authoring Tool (Articulate / Captivate / Lectora)"] -->|Export ZIP| SCORMZip["Standard SCORM 1.2 / 2004 Package"]
    SCORMZip -->|Chunked Upload (Up to 2GB)| Platform["SimuPhish Ingestion Engine"]

    Platform --> ClamAV["ClamAV Antivirus Scanner"]
    ClamAV --> Manifest["Automated imsmanifest.xml Parser"]
    Manifest --> Player["Seamless Iframe Runtime Player"]

    Player --> CMI["Live CMI Sync: Score, Status, Time, Bookmark"]
    CMI --> UnifiedReports["Unified SOC 2 & ISO Compliance Ledger"]

4. Key Business Benefits & Measurable ROI

  • Protects Past E-Learning Investments: Continue utilizing existing training packages created in Articulate 360, Adobe Captivate, or Lectora.
  • Eliminates Separate LMS Subscription Costs: Consolidate cybersecurity, data privacy, and compliance training onto SimuPhish, decommissioning redundant LMS software licenses.
  • Unified Auditor Evidence: View employee simulation failure rates, native micro-course completions, and third-party SCORM scores in a single exportable audit report.

5. Competitive Edge: Why SimuPhish Wins

Capability SimuPhish Competitors
SCORM 1.2 & SCORM 2004 Support Yes: Full bi-directional JavaScript API adapters. Often restricted to SCORM 1.2 or proprietary formats.
Multi-Gigabyte Chunked Uploads Yes (Up to 2GB+): Resilient S3 chunking with progress bar. Common 100MB file upload limits resulting in HTTP 413 errors.
Integrated Antivirus Verification Yes (ClamAV): Pre-upload malware scanning. No scanning; blind file storage.

6. Target Buyer & Compliance Mapping

  • Primary Stakeholders: VP of Learning & Development, Chief Compliance Officer, CISO, Enterprise IT Architect.
  • Compliance Standards Fulfilled:
  • SCORM 1.2 & SCORM 2004 (2nd, 3rd, 4th Editions) Conformance.
  • Unified Training Records for SOC 2, ISO 27001, and HIPAA Audits.