DoD 8570: Baseline Certifications, Waivers, and the 8140 Transition

DoD 8570 certification requirements were the Defense Department’s compliance-based system for credentialing anyone performing information assurance work on military networks. Signed in December 2005 as DoD Directive 8570.01-M, the manual tied specific commercial certifications to specific job categories and levels, so every role had a defined credential to hold.1Department of Defense. DoD 8570.01-M Information Assurance Workforce Improvement Program The directive was officially cancelled on February 15, 2023, when DoDM 8140.03 took effect and replaced it with a broader Cyberspace Workforce Qualification Program.2Department of Defense. DoDM 8140.03 Cyberspace Workforce Qualification and Management Program Many job postings, contracts, and internal policies still reference 8570, so the legacy rules and the current 8140 framework both matter.

How 8570 Structured the Workforce

The framework organized the information assurance workforce into categories based on the kind of security work performed, then subdivided each category into three levels reflecting scope of responsibility.1Department of Defense. DoD 8570.01-M Information Assurance Workforce Improvement Program Compliance was triggered by the work itself, not by a job title or military occupational specialty. A network administrator who spent only a fraction of the workday on security tasks still needed the appropriate certification if those tasks fell under information assurance.

Two primary categories carried most of the workforce:

  • Information Assurance Technical (IAT) covered hands-on roles configuring, maintaining, and troubleshooting security hardware and software.
  • Information Assurance Management (IAM) covered administrative and oversight roles handling policy development, risk management, and governance.

Two specialized categories rounded out the structure. Information Assurance System Architecture and Engineering (IASAE) covered design-focused roles building secure system architectures. Cybersecurity Service Provider (CSSP) covered operational roles broken into five sub-specialties: Analyst, Infrastructure Support, Incident Responder, Auditor, and Manager.

Within each category, Level I covered entry-level support in a local computing environment. Level II expanded to enterprise-wide network responsibilities. Level III represented the highest tier, involving oversight of enclave environments or complex security architecture.3Department of Defense Cyber Exchange. DoD 8570 Information Assurance Program Transition to DoD 8140 CWQP

Baseline Certifications by Category and Level

Each category-and-level combination mapped to a list of approved commercial certifications. The directive maintained an official baseline certification table (Table AP3.T2) listing which exams satisfied each requirement.1Department of Defense. DoD 8570.01-M Information Assurance Workforce Improvement Program The approved list evolved over the life of the program, but common requirements included:

  • IAT Level I: CompTIA A+, CompTIA Network+, or equivalent entry-level credentials.
  • IAT Level II: CompTIA Security+ or similar mid-tier certifications.
  • IAT Level III: Advanced credentials such as CASP+ or CISSP.
  • IAM Levels I through III: A parallel progression often starting with CAP or Security+ and scaling up to CISM or CISSP at the highest level.

A higher-level certification satisfied lower-level requirements in most cases, so someone holding a CISSP could fill an IAT Level II role without obtaining Security+ separately. Many DoD components offered voucher programs to cover exam costs, which made a real difference for junior enlisted and entry-level civilians.

Computing Environment Certifications

Baseline certifications were not the only requirement. Under 8570, personnel in technical roles also needed a computing environment or operating system certification specific to the systems they administered.4Department of Defense. DoD 8570.1 FAQs A Windows server administrator might need a Microsoft certification on top of Security+. These requirements were driven by the specific technology stack at the individual’s duty station, so two people in the same IAT level could need entirely different computing environment credentials.

Under the current 8140 framework, computing environment certifications are no longer required by default policy, though individual DoD components can still mandate them for specific roles or as part of resident qualification requirements.3Department of Defense Cyber Exchange. DoD 8570 Information Assurance Program Transition to DoD 8140 CWQP

What Changed Under DoD 8140

DoDM 8140.03 replaced 8570 with the Cyberspace Workforce Qualification Program on February 15, 2023.2Department of Defense. DoDM 8140.03 Cyberspace Workforce Qualification and Management Program The two programs differ in philosophy, structure, and scope. Where 8570 was a compliance checklist, the 8140 framework focuses on demonstrated capability across a broader range of cyber operations. The old system covered information assurance. The new one covers cybersecurity, cyber effects, intelligence operations in cyberspace, data science, artificial intelligence, and more.3Department of Defense Cyber Exchange. DoD 8570 Information Assurance Program Transition to DoD 8140 CWQP

Instead of IAT and IAM categories with Levels I through III, 8140 is built around the DoD Cyber Workforce Framework, which defines 74 specific work roles organized under seven workforce elements.5DoD CIO. Cyber Workforce Framework Each work role is tied to specific knowledge, skills, abilities, and tasks rather than a broad functional category. Proficiency levels changed from I/II/III to Basic, Intermediate, and Advanced.

The biggest practical change: certifications are no longer the only path. Under 8140, personnel can meet foundational qualification requirements through commercial certifications, DoD-owned training courses, or educational programs aligned to their work role and proficiency level.6Cyber Exchange. DoD 8140 Qualification Matrices Higher proficiency-level qualifications satisfy lower-level requirements, similar to the old system.

There is no direct crosswalk between legacy 8570 categories and 8140 work roles. Someone who was IAT Level II cannot simply look up the equivalent 8140 role, because the frameworks are structured differently enough that a one-to-one mapping does not exist.3Department of Defense Cyber Exchange. DoD 8570 Information Assurance Program Transition to DoD 8140 CWQP Other legacy features also dropped. 8140 does not require appointing letters, and it does not separately define privileged access requirements; instead, positions with privileged access are coded with the appropriate work role.

Qualification Timelines and Waivers

DoDM 8140.03 required all civilian employees and service members in cybersecurity work roles to be qualified within two years of the effective date (by February 2025), with personnel in cyberspace IT, effects, intelligence, and enabler roles following within three years (by February 2026).2Department of Defense. DoDM 8140.03 Cyberspace Workforce Qualification and Management Program

For individuals, the clock is shorter. DoD civilians and service members have nine months from assignment to a cyber work role to meet foundational qualification requirements, and twelve months to meet resident qualification requirements. These timelines run concurrently, so resident qualifications don’t start their clock after foundational ones are finished.7Cyber Exchange. DoD 8140 FAQ

During the qualification period, unqualified personnel can perform their assigned duties under direct supervision of a qualified individual. If direct supervision is not feasible and no waiver has been granted, the person must be reassigned to other duties.2Department of Defense. DoDM 8140.03 Cyberspace Workforce Qualification and Management Program

Waivers are available but narrow. Only OSD or DoD component heads (or their delegates) can grant them, and only when there are severe operational or personnel constraints. A waiver cannot exceed six months, and consecutive waivers are not authorized. The sole exception is deployment to a combat environment, where emergency circumstances may justify a longer waiver.7Cyber Exchange. DoD 8140 FAQ

Do Old 8570 Certifications Still Count?

Certifications earned under 8570 do not automatically satisfy 8140 requirements, but they are not worthless either. Industry certifications obtained under 8570 can carry over to 8140 qualification if they remain valid with the certifying organization and are applicable to the specific work role and proficiency level of the current position.3Department of Defense Cyber Exchange. DoD 8570 Information Assurance Program Transition to DoD 8140 CWQP

One catch matters. “Good for life” certifications, credentials that never expire, are not valid under 8140. They were already being phased out under 8570, and the new framework requires all certifications to be renewed on the provider’s schedule. There is no blanket grandfather clause. Job postings and position descriptions that still reference 8570 requirements are supposed to be updated, but regardless of what a posting says, new hires and incumbents need to meet 8140 standards for their assigned work role.3Department of Defense Cyber Exchange. DoD 8570 Information Assurance Program Transition to DoD 8140 CWQP

Keeping a Certification Current

Holding a certification is not a one-time event. Most commercial certifications recognized under both 8570 and 8140 require continuing education credits to stay current. CompTIA Security+, one of the most commonly held credentials in the DoD workforce, requires 50 continuing education units over a three-year renewal cycle.8CompTIA. CompTIA Security+ V7 – 50 CEUs Required for Certification Renewal CISSP holders face similar three-year cycles with their own CPE credit requirements set by ISC2.

Under 8140, allowing a certification to lapse means you no longer meet your qualification requirements. There is no grace period built into the DoD policy. If your cert expires, your qualification status changes. Personnel report continuing education credits to the certifying body on that body’s schedule, and defense tracking systems reflect the current status of each credential. Supervisors and information assurance managers are responsible for monitoring compliance within their units.

Where to Confirm Current Requirements for Your Role

The DoD Cyber Exchange at cyber.mil is the authoritative portal for both legacy 8570 reference materials and current 8140 qualification information.9Cyber Exchange. DoD 8140 Home Page The site publishes qualification matrices that map approved certifications, training, and education options to each DCWF work role and proficiency level.6Cyber Exchange. DoD 8140 Qualification Matrices These matrices are updated as new certification and training options are approved, so checking periodically is worth the effort, especially before a role change or new assignment. The DoD CIO’s website also maintains the DCWF work role definitions and the full text of DoDM 8140.03 for anyone who wants to read the policy itself.5DoD CIO. Cyber Workforce Framework