DoD 8570 Chart: Categories, Levels, and Approved Certifications

The DoD 8570 chart lists the baseline certifications approved for each Department of Defense information assurance job, sorted by category (IAT, IAM, IASAE, or CSSP) and by level within that category.1Department of Defense. DoD 8570 Approved Baseline Certifications To use it, find the category that matches your job function, find the level that matches the scope of the environment you work in, and pick any certification from that cell. Once you hold one, you meet the baseline requirement for that position.

Categories and Levels on the Chart

The chart splits the information assurance workforce into three main categories based on what you actually do, plus a separate track for cybersecurity service providers.2DoD Cyber Exchange. DoD 8570 Information Assurance IA Program Transition to DoD 8140 CWQP

  • Information Assurance Technical (IAT): hands-on technical work securing systems, networks, and enclaves.
  • Information Assurance Management (IAM): policy, oversight, and administrative work governing security programs.
  • Information Assurance System Architecture and Engineering (IASAE): designing and building secure systems.

Each of the three main categories has three levels tied to the scope of your environment. Level I is the computing environment, meaning individual workstations and local devices. Level II is the network environment, covering routers, switches, firewalls, and the infrastructure that links computing environments. Level III is the enclave environment, which spans at least two networks under a unified security policy.3Marine Corps Credentialing Opportunities Online. DoD Directive 8570 Information Assurance Training, Certification and Workforce Management FAQs The broader your access, the more rigorous the certification the chart demands.

IAT Approved Certifications

The technical track has the widest list because it covers the widest range of hands-on jobs.1Department of Defense. DoD 8570 Approved Baseline Certifications

  • IAT Level I: A+ CE, CCNA-Security, Network+ CE, or SSCP.
  • IAT Level II: CCNA Security, CySA+, GICSP, GSEC, Security+ CE, or SSCP.
  • IAT Level III: CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, or GCIH.

Security+ CE is the most common Level II choice because of its cost, difficulty, and broad recognition. At Level III, CISSP is the standard credential, while CASP+ CE suits people who want to stay on a technical rather than management track.

IAM Approved Certifications

The management track applies to personnel who develop security policies, manage risk, and run information assurance programs rather than configuring devices.1Department of Defense. DoD 8570 Approved Baseline Certifications

  • IAM Level I: CAP, GSLC, or Security+ CE.
  • IAM Level II: CAP, CASP+ CE, CISM, CISSP (or Associate), GSLC, or CCISO.
  • IAM Level III: CISM, CISSP (or Associate), GSLC, or CCISO.

Security+ CE satisfies IAM Level I and IAT Level II, which makes it one of the most versatile picks on the whole chart. CISSP and CISM dominate at the senior levels because both test governance and enterprise risk on top of technical knowledge.

IASAE Approved Certifications

System architecture and engineering roles design secure systems and evaluate security architectures. The list is narrower here because the work demands specialization.1Department of Defense. DoD 8570 Approved Baseline Certifications

  • IASAE Level I: CASP+ CE, CISSP (or Associate), or CSSLP.
  • IASAE Level II: CASP+ CE, CISSP (or Associate), or CSSLP.
  • IASAE Level III: CISSP-ISSAP or CISSP-ISSEP.

Levels I and II share the same list. Level III is the most exclusive tier on the chart: only the ISSAP (Information Systems Security Architecture Professional) and ISSEP (Information Systems Security Engineering Professional) concentrations qualify, and both require you to already hold a CISSP before you can sit for the concentration exam.

Cybersecurity Service Provider Certifications

CSSP roles sit outside the three-tier structure. They focus on active defense: monitoring networks, responding to intrusions, auditing controls, and managing defensive teams. The track breaks into five specialties, each with its own approved list.1Department of Defense. DoD 8570 Approved Baseline Certifications

  • Analyst: CEH, CFR, CCNA Cyber Ops, CCNA-Security, CySA+, GCIA, GCIH, GICSP, or SCYBER.
  • Infrastructure Support: CEH, CySA+, GICSP, SSCP, CHFI, or CFR.
  • Incident Responder: CEH, CFR, CCNA Cyber Ops, CCNA-Security, CHFI, CySA+, GCFA, GCIH, or SCYBER.
  • Auditor: CEH, CySA+, CISA, GSNA, or CFR.
  • Manager: CISM, CISSP-ISSMP, or CCISO.

CySA+ and CEH show up in nearly every specialty, so either is a solid pick if you expect to move between CSSP roles. CISA carries the most weight in auditor slots and is widely recognized outside the DoD as well. The Manager specialty is the smallest and hardest to enter, because CISM and CISSP-ISSMP both require years of documented experience.

Higher Certifications Cover Lower Levels

Within a single category, any certification approved at a higher level automatically satisfies the lower levels.4Cyber Exchange. DoD 8140 Qualification Matrices Hold a CISSP and take an IAT Level II position, and you already meet the baseline. You do not need to also earn Security+ CE. When you plan your certification path, aiming one level above your current job protects you from a compliance gap if you get reassigned upward.

Is the 8570 Chart Still in Effect?

The Department of Defense signed DoDM 8140.03 on February 15, 2023, formally cancelling DoD 8570.01-M and replacing the old compliance-based model with a broader qualification program built around the DoD Cyber Workforce Framework.5Department of Defense Chief Information Officer. DoDM 8140.03 Cyberspace Workforce Qualification and Management Program The 8570 chart still applies to contractors, though. Contractor personnel remain under 8570 policy until the Defense Federal Acquisition Regulation Supplement is updated to authorize 8140 for contractors, and that update has not yet taken effect.2DoD Cyber Exchange. DoD 8570 Information Assurance IA Program Transition to DoD 8140 CWQP Civilian and military positions should have transitioned to DCWF work roles by now, but if you are on a contract billet, the chart above is almost certainly what your contracting officer is checking against.

There is no automatic crosswalk between an 8570 certification and an 8140 qualification, though a given certification may still satisfy 8140 requirements depending on the specific work role and proficiency level.2DoD Cyber Exchange. DoD 8570 Information Assurance IA Program Transition to DoD 8140 CWQP If your position has been recoded, check the 8140 qualification matrix for that work role rather than assuming your existing certification carries over.

Keeping Your Certification Active

A baseline certification only counts while it is current. Let it lapse and you lose your compliant status and can lose system access, so plan on both fees and continuing education from the day you certify.

  • CompTIA (Security+, CySA+, SecurityX): $150 total for a three-year renewal cycle, paid when you submit continuing education units before expiration. Security+ and CySA+ require 50 CEUs over three years.6CompTIA. Continuing Education Renewal Fees
  • ISC2 (CISSP, SSCP, CCSP, CSSLP, ISSAP, ISSEP, ISSMP): $135 per year in annual maintenance fees; the entry-level CC certification runs $50 per year. CISSP holders owe 40 CPE credits per year.7ISC2. ISC2 Annual Maintenance Fees AMF Frequently Asked Questions
  • GIAC (GSEC, GCIH, GCIA, GCFA, and others): $499 every four years, with discounts for renewing multiple GIAC certifications within a two-year window.8GIAC Certifications. Renewal

Active-duty service members do not necessarily have to pay these costs out of pocket. Each branch runs a Credentialing Opportunities On-Line (COOL) program that can fund exams, study materials, and in some cases renewal fees. The Army’s Credentialing Assistance program caps at $2,000 per fiscal year and, combined with Tuition Assistance, cannot exceed $4,500 per fiscal year; as of March 2026, commissioned officers are no longer eligible.9Army COOL. Costs and Funding – Army Credentialing Assistance Navy COOL follows a similar submit-earn-report process.10Navy COOL. Navy COOL Home Submit the funding request before you schedule the exam. Retroactive reimbursement is rarely available.

Baseline certifications also do not replace the annual Cyber Awareness Challenge. The 60-minute course is the DoD’s end-user awareness standard, and skipping it suspends your network access regardless of what certifications you hold.11Cyber Exchange. Cyber Awareness Challenge Some organizations let it count toward your annual CPE or CEU total; check with your certifying body before you assume it does.