DoD 8570 Approved Baseline Certifications: IAT, IAM, IASAE, CSSP

The DoD 8570 baseline certifications were the approved credentials listed in DoD 8570.01-M that qualified a person to work on Department of Defense information systems, sorted by job category (IAT, IAM, IASAE, CSSP) and by level (I, II, III). The manual was cancelled on February 15, 2023 and replaced by DoDM 8140.03, but the certifications themselves still appear on contracts and job postings, and most of them carry directly into the newer framework.

How 8570 Sorted the Workforce

Every person who managed, maintained, or secured a DoD system fell into one of four functional categories. Information Assurance Technical (IAT) covered hands-on system operation. Information Assurance Management (IAM) covered policy and oversight. Information Assurance System Architecture and Engineering (IASAE) covered the people who designed and built secure networks. Cybersecurity Service Provider (CSSP) covered function-specific roles like analyst, incident responder, auditor, and infrastructure support.

Each of the first three categories split into three levels. Level I applied to workers responsible for individual workstations or small network segments. Level II covered broader responsibility across a facility or system. Level III applied to enterprise-wide environments where a single mistake could ripple across an entire organization. The higher the level, the more advanced the required certification.

The Approved Baseline Certifications

The lists below reflect the last published version of the 8570 approved baseline chart. You needed one certification from the row that matched your assigned category and level.

Information Assurance Technical (IAT)

  • Level I: A+ CE, Network+ CE, CCNA-Security, or SSCP
  • Level II: CCNA Security, CySA+, GICSP, GSEC, Security+ CE, or SSCP
  • Level III: CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, or GCIH

Information Assurance Management (IAM)

  • Level I: CAP, GSLC, or Security+ CE
  • Level II: CAP, CASP+ CE, CISM, CISSP (or Associate), GSLC, or CCISO
  • Level III: CISM, CISSP (or Associate), GSLC, or CCISO

IASAE

IASAE started at a higher floor. Level I and II accepted credentials like CASP+ CE or CISSP. Level III required a CISSP concentration, either the ISSAP or the ISSEP.

CSSP Specialties

CSSP roles were mapped to the specific function rather than to a numbered level. Analysts used CySA+ or CEH. Incident responders used GCIH or CSIH. Auditors used CISA or GSNA. Infrastructure support used CEH or SSCP.

One change worth flagging: Cisco retired the CCNA Security exam in February 2020 and replaced it with the broader CCNA (exam 200-301). If you earned CCNA Security before that date, it still counts for 8570 purposes. New candidates cannot sit that specific exam anymore.

Beyond the baseline, 8570 also required a Computing Environment or Operating System certificate tied to the systems you actually worked on. Under 8140, CE/OS certificates are no longer universally required, though individual DoD components can still mandate them for specific roles.

What Changed When 8140 Replaced 8570

DoDM 8140.03 shifted the qualification philosophy from a compliance checklist to a skills-based model. Where 8570 used four broad categories, 8140 uses the DoD Cyber Workforce Framework (DCWF), which defines 74 distinct work roles across seven workforce elements. Each work role maps to specific knowledge, skills, abilities, and tasks rather than a single certification box.

The level labels changed too. Level I, II, and III became Basic, Intermediate, and Advanced, describing demonstrated capability rather than just position in a network hierarchy. A single position can now carry a primary work role code plus up to two additional codes, giving supervisors more room to describe what the job actually involves.

Qualification under 8140 has two parts. The foundational qualification can be met through education, an approved training course, a personnel certification, or documented on-the-job experience in a DoD environment. Any certification used has to align with at least 70 percent of the core tasks and knowledge areas for your assigned work role and proficiency level. The residential qualification then involves supervised on-the-job performance in the designated role before you are cleared for unsupervised work.

Timelines are tight. You have nine months from the date you are assigned a cyberspace work role to complete foundational qualifications and twelve months to complete residential qualifications. Missing those deadlines can result in removal from duties tied to the work role.

The practical takeaway for someone holding an 8570 certification: the credential itself is still recognized, but it now has to line up with a specific DCWF work role and proficiency level rather than a category and Roman numeral.

Keeping a Certification Active

Earning the certification is only the first expense. Every major certifying body requires continuing education and periodic fees to keep the credential active, and the specifics vary by organization.

CompTIA runs a three-year renewal cycle. Security+ CE holders need 50 Continuing Education Units over that period, CySA+ requires 60, and CASP+ (SecurityX) requires 75. A+ and Network+ need 20 and 30 CEUs respectively. Credit-earning activities include instructor-led training, college courses, published articles, and industry conference attendance. The total renewal fee for Security+ CE is $150 for the three-year cycle, not an annual charge.

ISC2 works differently. CISSP holders pay a $135 Annual Maintenance Fee every year and accumulate 120 Continuing Professional Education credits over a three-year cycle. SSCP holders pay the same $135 annual fee. ISC2 also requires CPE activity during the cycle, with a minimum earned each year to prevent last-minute cramming.

If a certification lapses, you lose your compliance status. Under both 8570 and 8140, that means your privileged access to DoD systems is suspended until the credential is restored. On a defense contract, that suspension is not a paperwork inconvenience. Your employer cannot keep you on a project if you cannot touch the systems.