Which Certifications Satisfy DoD 8570 and 8140 Requirements? A Complete Guide

  •   min.
  • Updated on: July 27, 2026

    • Expert review
    • Home
    • /
    • Resources
    • /
    • Which Certifications Satisfy DoD 8570 and 8140 Requirements? A Complete Guide

    Search for DoD cybersecurity certification requirements, and you will find job postings that say "DoD 8570 required," contract language that references 8140, and training providers who use both terms interchangeably. The terminology confusion is real, widespread, and actively misleading for professionals trying to figure out exactly what they need.

    The DoD officially replaced Directive 8570 with DoD Manual 8140.03 in February 2023. The new framework expanded the scope of the old one significantly, but all certifications approved under 8570 remain valid under 8140. Nobody lost a qualification. The reason both terms persist is that the transition is still underway: the deadline for cybersecurity workforce elements to meet foundational qualification requirements under 8140 was February 2026, and many organizations, particularly defense contractors, are still working through compliance.

    What makes this more than just a terminology problem is what it means for your career. DoD 8570 and 8140 create formal, mandatory certification requirements for anyone working with DoD information systems. That means the organizations that need to fill these roles are structurally required to hire certified professionals. Hold the right certification, and you qualify for thousands of government and defense contractor positions that require it by directive. That is not a soft preference: it is a compliance requirement your employer cannot waive.

    This guide explains what changed between 8570 and 8140, who is required to hold a certification, and exactly which certifications satisfy which DoD role requirements, with a specific focus on the certifications that DestCert prepares you for.

    DoD 8570 vs 8140: What Changed and What Did Not

    DoD Directive 8570 organized the information assurance workforce into three categories: Information Assurance Technical (IAT), Information Assurance Management (IAM), and Information Assurance System Architect and Engineer (IASAE). Each category had three levels, and each level required specific baseline certifications. The framework worked well for its era, but it was narrow: it only addressed information assurance roles and left the broader cyber workforce without a unified qualification structure.

    DoD Manual 8140.03, signed February 15, 2023, replaced that structure with the DoD Cyber Workforce Framework (DCWF), which defines work roles across seven workforce elements: cybersecurity, cyber IT, cyber effects, cyber intelligence, cyber enablers, data and artificial intelligence, and software engineering. The DCWF maps to 72 distinct work roles, replacing the older category-and-level system with a more flexible role-based qualification model.

    Two things stayed the same. First, every certification approved under 8570 remains approved under 8140. Second, the IAT, IAM, and IASAE terminology persists in practice even though the formal framework has moved to DCWF work role codes. Most job postings, contract requirements, and hiring managers still use the 8570 language because it is familiar and because many organizations have not yet completed their formal transition to DCWF role assignments.

    For practical purposes: if a job posting says "DoD 8570 IAT Level II required," that means Security+. That has not changed. What 8140 added is a broader framework that maps certifications to more work roles than 8570 addressed.

    Who Is Required to Hold a DoD 8570/8140 Certification

    The requirement applies broadly: all military, civilian, and contractor personnel who access or manage DoD information systems must hold an approved certification that matches their assigned work role and proficiency level.

    Defense contractors are explicitly included. If your performance work statement requires cybersecurity functions, the certification requirement applies to you regardless of whether you are a government employee or a private sector contractor. The trend is also spreading: as the search results for this topic confirm, 8140 compliance requirements are increasingly flowing down from prime contractors to subcontractors. If your organization supports DoD programs, expect the certification requirement to reach you.

    The February 2026 deadline specifically applied to DoD civilians and military personnel in cybersecurity workforce roles meeting foundational qualification requirements under the new DCWF structure. Contractor compliance timelines are driven by contract requirements rather than the DoD internal deadline, but the direction is clear: 8140 compliance is the standard that new contracts are written against.

    The DoD 8570/8140 Certification Framework at a Glance

    The IAT, IAM, and IASAE categories remain the clearest way to understand which certification you need for which role type. Here is how the certifications DestCert prepares you for mapping across the framework.

    Category

    Level

    DestCert Certifications

    Other Approved

    IAT (Technical)

    Level I

    Network+

    A+, CCNA Security, CND, SSCP

    IAT (Technical)

    Level II

    Security+

    CySA+, CCNA Security, GSEC

    IAT (Technical)

    Level III

    CISSP

    CASP+, CISA, GCIH, CEDS

    IAM (Management)

    Level I

    Security+

    CAP, CND, GSLC, HCISPP

    IAM (Management)

    Level II

    CISM, CISSP

    CAP, CASP+, CCISO, GSLC

    IAM (Management)

    Level III

    CISM, CISSP

    CCISO, GSLC

    IASAE (Architecture)

    Level I

    CISSP

    CASP+, CSSLP

    IASAE (Architecture)

    Level II

    CISSP

    CASP+, CSSLP

    IASAE (Architecture)

    Level III

    CISSP, CCSP

    CISSP-ISSAP, CISSP-ISSEP

    One important clarification: CRISC does not appear on the DoD 8570/8140 approved baseline certification list. CRISC is a strong credential for risk management and GRC roles in defense environments, and many defense contractors value it for those functions, but it does not satisfy the baseline qualification requirements under this framework. If your role requires DoD 8570/8140 compliance, CRISC alone will not meet it.

    CISSP and DoD 8570/8140

    CISSP is the single most broadly applicable certification in the entire DoD framework. It qualifies for IAT Level III, IAM Level II and III, and all three IASAE levels. That is five qualification categories satisfied by one certification, more than any other credential on the approved list.

    Under DoD 8140, CISSP maps to 44% of approved work roles across five of the seven DCWF workforce elements. For professionals targeting senior technical, management, or architecture roles in government and defense environments, CISSP opens more doors than any other single certification. It is frequently required or preferred for senior government and defense contractor positions across all branches of the military and at major defense agencies.

    For a detailed breakdown of how CISSP maps to specific DCWF work roles, proficiency levels, and the types of government positions it qualifies for, the CISSP for government and DoD jobs guide maps the full picture.

    Looking for some exam prep guidance and mentoring?


    Learn about our personal mentoring

    Image of Lou Hablas mentor - Destination Certification

    CISM and DoD 8570/8140

    CISM qualifies for IAM Level II and IAM Level III: the management and senior management tiers of the framework. For professionals targeting information security manager, security director, or CISO-track roles within the DoD or defense contracting environment, CISM is the primary management credential under 8570/8140.

    IAM Level II and III positions are the roles responsible for overseeing security programs, managing security teams, reporting to leadership, and ensuring organizational compliance with DoD security requirements. CISM validates exactly the management thinking those roles require: governance, risk management, program leadership, and incident management.

    Security+ and Network+ and DoD 8570/8140

    Security+ is the most widely required certification in DoD and defense contractor environments because IAT Level II applies to the largest number of positions in the framework. System administrators, network security technicians, and cybersecurity analysts working on DoD systems are almost universally required to hold at a minimum an IAT Level II certification, and Security+ is the most accessible path to meeting that requirement.

    Security+ also qualifies for IAM Level I, making it relevant for junior management and oversight roles. For professionals entering government or defense contractor work without prior security certifications, Security+ is the standard first step.

    Network+ qualifies for IAT Level I: the foundational technical tier for personnel performing basic system and network security functions. For entry-level IT professionals in DoD environments who need a baseline certification before progressing to Security+, Network+ is the starting point.

    CCSP and DoD 8570/8140

    CCSP qualifies for IASAE Level III: the most senior architecture and engineering tier in the framework. For cloud security architects, cloud security engineers, and senior security professionals designing and overseeing DoD cloud infrastructure programs, CCSP is the relevant senior-level credential under this framework.

    IASAE Level III represents the top tier of the architecture and engineering track for professionals who design and engineer enterprise-wide security architectures. As DoD programs increasingly migrate to cloud environments, CCSP's role in qualifying cloud security professionals for these senior positions is growing.

    Which Certification Should You Pursue Based on Your Role

    The right certification depends on what type of work you do or are targeting within the DoD or defense contractor environment.

    • You are new to DoD or defense work with no security certifications: Security+ is the standard first certification. It satisfies IAT Level II and IAM Level I requirements, applies to the largest number of entry and mid-level positions, and gives you the foundational security knowledge that all subsequent certifications build on.
    • You are in a technical security role (system administrator, network security, security analyst): Security+ gets you to IAT Level II. To advance to senior technical or architect roles, CISSP is the next logical step and the only single certification that qualifies for IAT Level III and all IASAE levels.
    • You are in or targeting a security management or leadership role: CISM qualifies for IAM Level II and III. Pairing CISM with CISSP gives you the strongest possible credential combination for senior management and CISO-track positions in government and defense environments. For a full picture of how both certifications work together, the top cybersecurity certifications guide maps the full career-level picture.
    • You are targeting cloud security architecture roles on DoD programs: CCSP qualifies for IASAE Level III and is the primary senior architecture credential for cloud-focused DoD positions.
    • You are a defense contractor trying to determine compliance: The certifications your personnel need depend on the DCWF work roles assigned in your contracts. IAT Level II (Security+) is the most common baseline requirement. Senior management and architecture roles will require CISSP, CISM, or CCSP, depending on the specific work role code.

    Why These Certifications Matter Beyond Compliance

    DoD 8570/8140 is not just a compliance checkbox. It is the mechanism by which the government and defense sector create a reliable standard for security workforce competence. For professionals who hold the right certifications, the framework creates consistent, structural demand across thousands of positions.

    Government and defense security roles consistently rank among the highest-paying positions in cybersecurity, driven by security clearance premiums, the density of senior roles, and the formal requirement for certified professionals. For a full breakdown of how government and defense roles compare across the compensation spectrum, the highest-paid cybersecurity jobs guide maps salary data across all senior security roles.

    The CISO track in government and defense follows a clear path that CISSP and CISM support directly. For professionals targeting senior leadership positions in these environments, the how to become a CISO guide maps the full career progression, including how DoD credentials factor into the path.

    Certification in 3 Days 


    Study everything you need to know for the AAISM exam in a 3-day bootcamp!

    Frequently Asked Questions 

    Are DoD 8570 certifications still valid under DoD 8140?

    Yes. Every certification approved under DoD 8570 remains valid under DoD 8140. The transition to 8140 expanded the framework and added new work role mappings, but it did not invalidate existing certifications. CISSP, CISM, Security+, CCSP, and Network+ all remain approved, and their role qualifications are unchanged.

    Does CISSP satisfy DoD 8570 requirements?

    Yes. CISSP satisfies IAT Level III, IAM Level II, IAM Level III, IASAE Level I, IASAE Level II, and IASAE Level III requirements. It is the most broadly applicable single certification in the framework. Under DoD 8140, CISSP maps to approximately 44% of approved DCWF work roles across five of the seven workforce elements.

    What certification do I need for an IAT Level II position?

    Security+ is the most commonly pursued certification for IAT Level II. Other approved options include CySA+, CCNA Security, and GSEC, but Security+ is the most accessible entry point and the most widely recognized in defense contractor hiring contexts.

    Does the DoD 8570/8140 requirement apply to contractors?

    Yes. Contracted support personnel whose performance work statement requires cybersecurity functions must meet the same certification requirements as DoD employees. The requirement is driven by contract language rather than a single internal DoD deadline, but the expectation of compliance is consistent across new and renegotiated defense contracts.

    What is the difference between IAT and IAM certification requirements?

    IAT (Information Assurance Technical) certifications qualify professionals for hands-on technical roles: system administration, network security, and technical security operations. IAM (Information Assurance Management) certifications qualify professionals for oversight and management roles: security program management, security manager, and security director. CISSP spans both tracks. Security+ satisfies both IAT Level II and IAM Level I. CISM satisfies IAM Level II and III exclusively.

    Government and Defense Careers Demand Certified Security Professionals. Build That Credential Now

    DoD 8570 and 8140 do not create optional career enhancements. They create mandatory qualification requirements for an entire sector of the economy. The professionals who hold the right certifications are the only ones who can fill those roles. That is structural demand, not market preference, and it is not going away.

    Destination Certification offers one of the most comprehensive CISSP preparation programs available, with expert-led instruction across all eight domains and an adaptive learning system that identifies your specific knowledge gaps. If you want to move through the material fast, the CISSP Bootcamp delivers five intensive days of live online instruction, Monday through Friday, ten hours per day. If you need more flexibility, the CISSP MasterClass gives you the same expert instruction in a self-paced format that adjusts to your schedule and focuses your study time on exactly what you still need to learn.

    For professionals targeting IAM Level II and III roles, Destination Certification offers one of the most comprehensive CISM preparation programs available. If you want intensive preparation, the CISM Bootcamp delivers four intensive days of live online instruction, Monday through Thursday. If your schedule requires more flexibility, the CISM MasterClass gives you the same depth at your own pace, with timelines that fit around your current role.

    Start building your knowledge base with the free CISSP MindMaps from Destination Certification, or download the free DestCert App for Security+ and CISSP practice questions on iOS and Android at no cost.

    The certification requirement exists whether you are ready or not. The question is whether you will be.

    Image of Rob Witcher - Destination Certification

    Rob is the driving force behind the success of the Destination Certification CISSP program, leveraging over 15 years of security, privacy, and cloud assurance expertise. As a seasoned leader, he has guided numerous companies through high-profile security breaches and managed the development of multi-year security strategies. With a passion for education, Rob has delivered hundreds of globally acclaimed CCSP, CISSP, and ISACA classes, combining entertaining delivery with profound insights for exam success. You can reach out to Rob on LinkedIn.

    Free Class:
    Crack Cryptography for the CISSP Exam

    A free 3-part class that makes one of the CISSP's hardest topics click.

    • Why cryptography questions confuse even experienced security professionals on exam day
    • How symmetric and asymmetric encryption actually differ the way the CISSP tests it
    • What digital signatures are really doing and why the exam frames questions around them the way it does
    • A practice test at the end so you leave knowing exactly where your understanding holds up

    The easiest way to get your CISSP Certification 


    Learn about our CISSP MasterClass

    Image of masterclass video - Destination Certification