DoD Directive 8570.01 and its implementing manual, 8570.01-M, required every military member, DoD civilian, and contractor performing information assurance work to hold an approved baseline certification tied to their job category and level. DoDM 8140.03 canceled the 8570.01-M manual on February 15, 2023, but the DoD 8570.01 certification requirements still govern contractor personnel until the Defense Federal Acquisition Regulation Supplement (DFARS) is updated to authorize 8140 for contracts.1DoD Cyber Exchange. 8570 to 8140 Transition If your contract or position description still references 8570, the old matrix is what you have to meet.
Who Is Still Covered by 8570
The transition to 8140 is happening in phases. DoD civilians and service members in cybersecurity workforce roles were required to meet 8140 qualification standards by February 2025, with the remaining cyber-related workforce elements (cyberspace IT, cyberspace effects, intelligence, and cyberspace enablers) following in February 2026.2DoD Chief Information Officer. DoDM 8140.03 Cyberspace Workforce Qualification and Management Program
Contractors are the exception. Defense contractors remain under 8570 requirements until DFARS is updated to authorize 8140 implementation for contracted personnel.1DoD Cyber Exchange. 8570 to 8140 Transition Read your contract. If it cites 8570.01-M, IAT/IAM/IASAE/CSSP categories, or specific baseline certifications by level, the old framework is your compliance target.
The Four Workforce Categories
The 8570 manual organized information assurance personnel into four functional categories based on what they actually did.
- Information Assurance Technical (IAT). Hands-on system administration, network security configuration, and endpoint management.
- Information Assurance Management (IAM). Policy, oversight, accreditation, and compliance work rather than direct device configuration.
- Information Assurance System Architecture and Engineering (IASAE). Designing secure network architectures and integrating security controls across enterprise systems.
- Cybersecurity Service Provider (CSSP). Proactive defense work: threat analysis, incident response, infrastructure protection, auditing, and security operations management.
IAT, IAM, and IASAE each had three levels (I, II, III), with Level I covering entry-level functions and Level III covering enterprise-wide authority. CSSP was divided into five specialty areas: Analyst, Infrastructure Support, Incident Responder, Auditor, and Manager. Each cell in that grid mapped to an approved certification list.
Some positions also required a computing environment certification on top of the baseline, tied to the specific operating system or network equipment involved.1DoD Cyber Exchange. 8570 to 8140 Transition A Windows server admin, for example, might need both Security+ (baseline) and a Microsoft credential (computing environment).
Certifications That Satisfy Each Slot
IAT (Technical)
- Level I: CompTIA A+, Network+
- Level II: CompTIA Security+, CCNA Security
- Level III: CASP+ (now SecurityX) or CISSP
Security+ became the de facto standard for IAT Level II and is the single most common 8570 certification across the DoD workforce, largely because so many positions sit in that bracket.
IAM (Management)
- Level I: Security+ or CAP
- Level II: CISM or CISSP
- Level III: GSLC or CISSP-ISSMP
IASAE (Architecture and Engineering)
All three levels generally accept CISSP, SecurityX (formerly CASP+), or CSSLP, with Level III adding CISSP-ISSAP and CISSP-ISSEP.
CSSP
Requirements vary by specialty. Analyst and Incident Responder roles commonly accept CEH, CySA+, GCIH, and CHFI; Manager roles typically require CISM or CISSP-ISSMP.1DoD Cyber Exchange. 8570 to 8140 Transition
Costs of Getting Certified
CompTIA Security+, the most commonly required certification under 8570, costs $425 for a single exam attempt. The CISSP exam runs $749.3ISC2. How Much Do ISC2 Certification Exams Cost Preparation courses typically range from $2,000 to $5,000 for self-paced options and can exceed $10,000 for instructor-led bootcamps.
DoD-affiliated personnel have several ways to offset those costs. Active-duty service members can use their branch’s Credentialing Assistance program through the Credentialing Opportunities On-Line (COOL) system. DoD civilians can request agency-funded training through Standard Form 182, which requires supervisor and authorizing-official approval and usually creates a continued-service obligation. CompTIA also offers government pricing on exam vouchers and training materials to DoD personnel, federal employees, and government contractors who link their account to their organization through the CompTIA support portal using an official email address.4CompTIA. Does CompTIA Offer Government Discounts
Keeping the Certification Active
The 8570 requirement is not “pass once.” A lapsed credential means you no longer meet the qualification for your position, which can pull your system access and stop you from doing your job until it’s fixed.
CompTIA certifications (Security+, CySA+, CASP+/SecurityX) run on a three-year renewal cycle. Security+ requires 50 continuing education units over the cycle, with a total renewal fee of $150 for the three years.5CompTIA. Continuing Education Renewal Fees
ISC2 certifications (CISSP, SSCP, CCSP, CSSLP, and the ISSAP/ISSEP/ISSMP concentrations) carry an annual maintenance fee of $135, plus CPE credits completed within each three-year cycle. Requirements vary by credential.6ISC2. ISC2 Annual Maintenance Fees – Frequently Asked Questions
What Happens If You’re Not Compliant
Without a valid certification for your position, you cannot perform cybersecurity or information assurance functions under a DoD contract or in a covered government role. Contractors lose their billable seat. Civilians and military personnel can face reassignment or administrative action.
Personnel with privileged access face tighter consequences. Privileged users generally sign a Privileged Access Agreement binding them to maintain required clearances, certifications, and training. Violations can trigger revocation of privileged access, counseling, adverse personnel actions, criminal prosecution under the Uniform Code of Military Justice for military members, or loss of employment for civilians.
Confirming Exactly What Your Role Requires
Start with your position description. It should identify the functional category (IAT, IAM, IASAE, or CSSP) and the level or specialty. For contractor positions still governed by existing DFARS language, cross-reference that against the 8570.01-M certification matrix.
If your position has already moved to 8140, the qualification comes from the DoD Cyber Workforce Framework work role rather than the old category grid, and it combines education, training, and certification across basic, intermediate, and advanced proficiency levels. Higher-level qualifications satisfy lower ones. The current mappings live in the DoD 8140 Qualification Matrices on the Cyber Exchange site.7DoD Cyber Exchange. DoD 8140 Qualification Matrices
If your position description doesn’t clearly state a category, level, or work role, contact your organization’s Information Systems Security Manager. The ISSM holds the local mapping of positions to certification requirements. Bring your current certification transcripts to that conversation so you can identify the gap between what you hold and what your role requires in one sitting.