Search for DoD cybersecurity certification requirements, and you will find job postings that say "DoD 8570 required," contract language that references 8140, and training providers who use both terms interchangeably. The terminology confusion is real, widespread, and actively misleading for professionals trying to figure out exactly what they need.
The DoD officially replaced Directive 8570 with DoD Manual 8140.03 in February 2023. The new framework expanded the scope of the old one significantly, but all certifications approved under 8570 remain valid under 8140. Nobody lost a qualification. The reason both terms persist is that the transition is still underway: the deadline for cybersecurity workforce elements to meet foundational qualification requirements under 8140 was February 2026, and many organizations, particularly defense contractors, are still working through compliance.
What makes this more than just a terminology problem is what it means for your career. DoD 8570 and 8140 create formal, mandatory certification requirements for anyone working with DoD information systems. That means the organizations that need to fill these roles are structurally required to hire certified professionals. Hold the right certification, and you qualify for thousands of government and defense contractor positions that require it by directive. That is not a soft preference: it is a compliance requirement your employer cannot waive.
This guide explains what changed between 8570 and 8140, who is required to hold a certification, and exactly which certifications satisfy which DoD role requirements, with a specific focus on the certifications that DestCert prepares you for.
DoD 8570 vs 8140: What Changed and What Did Not
DoD Directive 8570 organized the information assurance workforce into three categories: Information Assurance Technical (IAT), Information Assurance Management (IAM), and Information Assurance System Architect and Engineer (IASAE). Each category had three levels, and each level required specific baseline certifications. The framework worked well for its era, but it was narrow: it only addressed information assurance roles and left the broader cyber workforce without a unified qualification structure.
DoD Manual 8140.03, signed February 15, 2023, replaced that structure with the DoD Cyber Workforce Framework (DCWF), which defines work roles across seven workforce elements: cybersecurity, cyber IT, cyber effects, cyber intelligence, cyber enablers, data and artificial intelligence, and software engineering. The DCWF maps to 72 distinct work roles, replacing the older category-and-level system with a more flexible role-based qualification model.
Two things stayed the same. First, every certification approved under 8570 remains approved under 8140. Second, the IAT, IAM, and IASAE terminology persists in practice even though the formal framework has moved to DCWF work role codes. Most job postings, contract requirements, and hiring managers still use the 8570 language because it is familiar and because many organizations have not yet completed their formal transition to DCWF role assignments.
For practical purposes: if a job posting says "DoD 8570 IAT Level II required," that means Security+. That has not changed. What 8140 added is a broader framework that maps certifications to more work roles than 8570 addressed.
Who Is Required to Hold a DoD 8570/8140 Certification
The requirement applies broadly: all military, civilian, and contractor personnel who access or manage DoD information systems must hold an approved certification that matches their assigned work role and proficiency level.
Defense contractors are explicitly included. If your performance work statement requires cybersecurity functions, the certification requirement applies to you regardless of whether you are a government employee or a private sector contractor. The trend is also spreading: as the search results for this topic confirm, 8140 compliance requirements are increasingly flowing down from prime contractors to subcontractors. If your organization supports DoD programs, expect the certification requirement to reach you.
The February 2026 deadline specifically applied to DoD civilians and military personnel in cybersecurity workforce roles meeting foundational qualification requirements under the new DCWF structure. Contractor compliance timelines are driven by contract requirements rather than the DoD internal deadline, but the direction is clear: 8140 compliance is the standard that new contracts are written against.
The DoD 8570/8140 Certification Framework at a Glance
The IAT, IAM, and IASAE categories remain the clearest way to understand which certification you need for which role type. Here is how the certifications DestCert prepares you for mapping across the framework.
Category | Level | DestCert Certifications | Other Approved |
|---|---|---|---|
IAT (Technical) | Level I | Network+ | A+, CCNA Security, CND, SSCP |
IAT (Technical) | Level II | Security+ | CySA+, CCNA Security, GSEC |
IAT (Technical) | Level III | CISSP | CASP+, CISA, GCIH, CEDS |
IAM (Management) | Level I | Security+ | CAP, CND, GSLC, HCISPP |
IAM (Management) | Level II | CISM, CISSP | CAP, CASP+, CCISO, GSLC |
IAM (Management) | Level III | CISM, CISSP | CCISO, GSLC |
IASAE (Architecture) | Level I | CISSP | CASP+, CSSLP |
IASAE (Architecture) | Level II | CISSP | CASP+, CSSLP |
IASAE (Architecture) | Level III | CISSP, CCSP | CISSP-ISSAP, CISSP-ISSEP |
One important clarification: CRISC does not appear on the DoD 8570/8140 approved baseline certification list. CRISC is a strong credential for risk management and GRC roles in defense environments, and many defense contractors value it for those functions, but it does not satisfy the baseline qualification requirements under this framework. If your role requires DoD 8570/8140 compliance, CRISC alone will not meet it.
CISSP and DoD 8570/8140
CISSP is the single most broadly applicable certification in the entire DoD framework. It qualifies for IAT Level III, IAM Level II and III, and all three IASAE levels. That is five qualification categories satisfied by one certification, more than any other credential on the approved list.
Under DoD 8140, CISSP maps to 44% of approved work roles across five of the seven DCWF workforce elements. For professionals targeting senior technical, management, or architecture roles in government and defense environments, CISSP opens more doors than any other single certification. It is frequently required or preferred for senior government and defense contractor positions across all branches of the military and at major defense agencies.
For a detailed breakdown of how CISSP maps to specific DCWF work roles, proficiency levels, and the types of government positions it qualifies for, the CISSP for government and DoD jobs guide maps the full picture.
Looking for some exam prep guidance and mentoring?
Learn about our personal mentoring

CISM and DoD 8570/8140
CISM qualifies for IAM Level II and IAM Level III: the management and senior management tiers of the framework. For professionals targeting information security manager, security director, or CISO-track roles within the DoD or defense contracting environment, CISM is the primary management credential under 8570/8140.
IAM Level II and III positions are the roles responsible for overseeing security programs, managing security teams, reporting to leadership, and ensuring organizational compliance with DoD security requirements. CISM validates exactly the management thinking those roles require: governance, risk management, program leadership, and incident management.
Security+ and Network+ and DoD 8570/8140
Security+ is the most widely required certification in DoD and defense contractor environments because IAT Level II applies to the largest number of positions in the framework. System administrators, network security technicians, and cybersecurity analysts working on DoD systems are almost universally required to hold at a minimum an IAT Level II certification, and Security+ is the most accessible path to meeting that requirement.
Security+ also qualifies for IAM Level I, making it relevant for junior management and oversight roles. For professionals entering government or defense contractor work without prior security certifications, Security+ is the standard first step.
Network+ qualifies for IAT Level I: the foundational technical tier for personnel performing basic system and network security functions. For entry-level IT professionals in DoD environments who need a baseline certification before progressing to Security+, Network+ is the starting point.
CCSP and DoD 8570/8140
CCSP qualifies for IASAE Level III: the most senior architecture and engineering tier in the framework. For cloud security architects, cloud security engineers, and senior security professionals designing and overseeing DoD cloud infrastructure programs, CCSP is the relevant senior-level credential under this framework.
IASAE Level III represents the top tier of the architecture and engineering track for professionals who design and engineer enterprise-wide security architectures. As DoD programs increasingly migrate to cloud environments, CCSP's role in qualifying cloud security professionals for these senior positions is growing.
Which Certification Should You Pursue Based on Your Role
The right certification depends on what type of work you do or are targeting within the DoD or defense contractor environment.
- You are new to DoD or defense work with no security certifications: Security+ is the standard first certification. It satisfies IAT Level II and IAM Level I requirements, applies to the largest number of entry and mid-level positions, and gives you the foundational security knowledge that all subsequent certifications build on.
- You are in a technical security role (system administrator, network security, security analyst): Security+ gets you to IAT Level II. To advance to senior technical or architect roles, CISSP is the next logical step and the only single certification that qualifies for IAT Level III and all IASAE levels.
- You are in or targeting a security management or leadership role: CISM qualifies for IAM Level II and III. Pairing CISM with CISSP gives you the strongest possible credential combination for senior management and CISO-track positions in government and defense environments. For a full picture of how both certifications work together, the top cybersecurity certifications guide maps the full career-level picture.
- You are targeting cloud security architecture roles on DoD programs: CCSP qualifies for IASAE Level III and is the primary senior architecture credential for cloud-focused DoD positions.
- You are a defense contractor trying to determine compliance: The certifications your personnel need depend on the DCWF work roles assigned in your contracts. IAT Level II (Security+) is the most common baseline requirement. Senior management and architecture roles will require CISSP, CISM, or CCSP, depending on the specific work role code.
Why These Certifications Matter Beyond Compliance
DoD 8570/8140 is not just a compliance checkbox. It is the mechanism by which the government and defense sector create a reliable standard for security workforce competence. For professionals who hold the right certifications, the framework creates consistent, structural demand across thousands of positions.
Government and defense security roles consistently rank among the highest-paying positions in cybersecurity, driven by security clearance premiums, the density of senior roles, and the formal requirement for certified professionals. For a full breakdown of how government and defense roles compare across the compensation spectrum, the highest-paid cybersecurity jobs guide maps salary data across all senior security roles.
The CISO track in government and defense follows a clear path that CISSP and CISM support directly. For professionals targeting senior leadership positions in these environments, the how to become a CISO guide maps the full career progression, including how DoD credentials factor into the path.
Certification in 3 Days
Study everything you need to know for the AAISM exam in a 3-day bootcamp!
Frequently Asked Questions
Yes. CISSP satisfies IAT Level III, IAM Level II, IAM Level III, IASAE Level I, IASAE Level II, and IASAE Level III requirements. It is the most broadly applicable single certification in the framework. Under DoD 8140, CISSP maps to approximately 44% of approved DCWF work roles across five of the seven workforce elements.
Security+ is the most commonly pursued certification for IAT Level II. Other approved options include CySA+, CCNA Security, and GSEC, but Security+ is the most accessible entry point and the most widely recognized in defense contractor hiring contexts.
Yes. Contracted support personnel whose performance work statement requires cybersecurity functions must meet the same certification requirements as DoD employees. The requirement is driven by contract language rather than a single internal DoD deadline, but the expectation of compliance is consistent across new and renegotiated defense contracts.
IAT (Information Assurance Technical) certifications qualify professionals for hands-on technical roles: system administration, network security, and technical security operations. IAM (Information Assurance Management) certifications qualify professionals for oversight and management roles: security program management, security manager, and security director. CISSP spans both tracks. Security+ satisfies both IAT Level II and IAM Level I. CISM satisfies IAM Level II and III exclusively.
Government and Defense Careers Demand Certified Security Professionals. Build That Credential Now
DoD 8570 and 8140 do not create optional career enhancements. They create mandatory qualification requirements for an entire sector of the economy. The professionals who hold the right certifications are the only ones who can fill those roles. That is structural demand, not market preference, and it is not going away.
Destination Certification offers one of the most comprehensive CISSP preparation programs available, with expert-led instruction across all eight domains and an adaptive learning system that identifies your specific knowledge gaps. If you want to move through the material fast, the CISSP Bootcamp delivers five intensive days of live online instruction, Monday through Friday, ten hours per day. If you need more flexibility, the CISSP MasterClass gives you the same expert instruction in a self-paced format that adjusts to your schedule and focuses your study time on exactly what you still need to learn.
For professionals targeting IAM Level II and III roles, Destination Certification offers one of the most comprehensive CISM preparation programs available. If you want intensive preparation, the CISM Bootcamp delivers four intensive days of live online instruction, Monday through Thursday. If your schedule requires more flexibility, the CISM MasterClass gives you the same depth at your own pace, with timelines that fit around your current role.
Start building your knowledge base with the free CISSP MindMaps from Destination Certification, or download the free DestCert App for Security+ and CISSP practice questions on iOS and Android at no cost.
The certification requirement exists whether you are ready or not. The question is whether you will be.










