DoD 8570 requirements were the certification and training standards that governed anyone performing information assurance work on Department of Defense networks from 2005 until February 15, 2023, when DoD 8570.01-M was cancelled and replaced by DoDM 8140.03. If you’re reading a contract, job posting, or position description that still says “8570 compliant,” what it actually means today is that you need to be qualified under the newer 8140 Cyberspace Workforce Qualification and Management Program for the specific work role you’ll fill.
Because so much hiring language still uses the old vocabulary, it helps to understand both frameworks: what 8570 asked for, and what 8140 asks for now.
What DoD 8570 Required
DoD 8570.01-M divided the information assurance workforce into four functional categories, each with three levels reflecting scope and responsibility. A position’s category was set by the duties assigned to it, not by the job title, and the same title could carry different requirements depending on the network permissions involved.
- Information Assurance Technical (IAT) covered the hardware and software side. Level I was individual devices, Level II network segments, Level III enclave-wide environments.
- Information Assurance Management (IAM) covered administrative and policy work, supervising security programs at progressively larger scales.
- Information Assurance System Architecture and Engineering (IASAE) covered designing and building security architectures. All three levels required advanced credentials.
- Cyber Security Service Provider (CSSP) covered active defense, incident response, monitoring, and auditing roles.
Each category and level pointed to a short list of approved commercial certifications. The most commonly required were CompTIA A+ and Network+ at IAT Level I; Security+ or SSCP at IAT Level II; CISA or CISSP at IAT Level III; Security+ or Cloud+ at IAM Level I; CISM or CISSP at IAM Level III; CISSP-ISSAP or CISSP-ISSEP at IASAE Level III; and CEH or Cisco CyberOps Associate for CSSP analyst and responder roles.
IAT personnel with privileged access also had to hold a Computing Environment certification for the operating systems or security tools they supported. If you supported more than one, you needed a CE certification for whichever you spent the most time on. That requirement was locally controlled: your organization’s Information System Security Manager decided what qualified, and vendor training sometimes counted in place of a full certification.
Under 8570, U.S. citizenship was required for most positions involving the management or design of secure government networks. Local nationals and foreign nationals could not be assigned to IAT Level III or IAM Level III positions, and placement at Level II was conditional.
What Replaced It Under DoD 8140
DoDM 8140.03 scrapped the four-category structure in favor of the DoD Cyber Workforce Framework (DCWF), which is built around seven workforce elements and 74 distinct work roles. Instead of “IAT Level II,” you’re now assigned to a specific work role such as Cyber Defense Analyst (code 511), System Administrator (code 451), or Information Systems Security Manager (code 722). Each role has its own approved qualifications at three proficiency levels: Basic, Intermediate, and Advanced. A qualification approved at a higher level also satisfies lower ones.
The upshot is that qualification requirements now track what you actually do. A Vulnerability Assessment Analyst has a different certification menu than a Network Operations Specialist, even though both might have fallen under IAT Level II before.
Many familiar certifications carried over. CompTIA Security+ is approved across numerous work roles including Cyber Defense Analyst, Cyber Defense Incident Responder, System Administrator, and Information Systems Security Manager. CompTIA CASP+ covers many higher-proficiency roles that previously required CISSP. CySA+ and PenTest+ now appear for forensics, vulnerability assessment, and exploitation analysis roles. The full qualification matrices live on the DoD Cyber Exchange and are updated as new certifications get evaluated, so check the matrix for your specific work role before you spend money on an exam.
Certifications you earned under 8570 can carry over if they remain current with the issuing organization and map to your assigned work role and proficiency level. “Good for life” certifications that are no longer actively maintained are not valid under 8140, just as they were being phased out under the old rule.
Three Ways to Qualify
The biggest substantive change is that certifications are no longer the only path. Under 8140, you satisfy the foundational qualification requirement by meeting any one of three options:
- Education: a relevant post-secondary degree from an accredited institution, conferred within the past five years, unless you can show continuous relevant work with no more than three consecutive years of lapse. A high school diploma or equivalent is the minimum floor for all work roles at all proficiency levels.
- Training: approved training programs covering at least 70 percent of the core tasks and knowledge areas for the work role at the appropriate proficiency level, completed within the past five years unless continuous relevant work fills the gap.
- Experience: documented hands-on experience performing the work role’s tasks in a DoD environment. This pathway is aimed at incumbent federal civilians and service members already doing the job.
In practice, a systems administrator with a recent cybersecurity degree and continuous work experience might qualify without holding Security+ at all, depending on the component’s implementation. Certifications remain the most portable qualification, though, and they are effectively required for contractors because contractors have to be qualified before they start work.
Who Has to Comply and by When
The rules apply to DoD civilian employees, military personnel, local nationals, and support contractors. The 8140 framework preserves that scope and expands it beyond traditional IA work to the full cyberspace workforce.
The phased deadlines set by DoDM 8140.03 were:
- All civilians and service members in cybersecurity work roles had to be qualified under 8140 within two years of the effective date, meaning by February 2025.
- Those in cyberspace IT, cyberspace effects, intelligence, and cyberspace enabler roles must be qualified within three years, meaning by February 2026.
- Contractors must be qualified at the commencement of work. No grace period.
Once assigned to a cyber work role, civilians and service members have nine months to achieve foundational qualification requirements and twelve months to achieve resident qualification requirements. Those two clocks run concurrently, so you effectively have twelve months to be fully qualified. Under the old 8570, the window was six months to obtain the required baseline certification.
Waivers exist when operational or personnel constraints prevent meeting the deadline, but under 8140 they cannot exceed six months, and consecutive waivers are not authorized except in emergency situations during deployment to a combat environment. That is tighter than what 8570 allowed and reflects the intent to close the assignment-to-qualification gap.
Losing qualification status has practical consequences. You lose access to the systems you’re supposed to manage or defend, which makes you unable to do your job. For contractors, that can mean removal from the contract.
Certification Costs, Funding, and Maintenance
Exam fees add up. CompTIA Security+ costs $425. CISSP is $749. Certified Ethical Hacker runs from $550 for remote proctoring to $1,199 through Pearson VUE testing centers. Failed attempts double the bill.
DoD 8570 stated that training and certification must be provided at no cost to government employees, both military and civilian. Under 8140, components are directed to appropriately resource qualification requirements, and funding programs vary by service. The Navy and Marine Corps Credentials Program Offices cover exam vouchers, recertification fees, and annual maintenance fees for eligible civilian cyber workforce personnel; you generally need to be assigned to a designated cyber work role with at least one year of employment remaining. Neither program reimburses out-of-pocket costs already paid, and neither covers study materials or training courses.
Contractors typically get certification support from their employer, with most defense contractors building the expense into overhead. Policies vary, so ask about certification support before accepting an offer.
Maintenance is ongoing. CompTIA certifications renew every three years through Continuing Education Units and a renewal fee of $75 to $150 depending on the level. ISC2 charges CISSP holders an annual maintenance fee of $125 and requires Continuing Professional Education credits each year. Letting a certification lapse for missed fees or CPEs can mean retaking the exam from scratch. Under 8140, every certification must be actively renewed; “good for life” credentials no longer count. Your organization’s cyber workforce manager tracks compliance, and falling out of good standing carries the same consequences as never having been certified.
Background Investigations
Technical qualification is only half of network access. Everyone working on DoD networks must undergo a background investigation appropriate to the position’s sensitivity. The tiers have been updated since 8570 was written: the National Agency Check with Inquiries (NACI) has been replaced by the Tier 1 investigation, and the Single Scope Background Investigation (SSBI) required for top secret access has been replaced by the Tier 5 investigation.
Periodic reinvestigations every five or ten years have given way to Continuous Vetting under Trusted Workforce 2.0, which runs automated checks against criminal, terrorism, financial, and public records databases on an ongoing basis. Alerts go to adjudicators, who decide whether a clearance should be maintained, suspended, or revoked. All personnel also complete annual cybersecurity awareness training to keep their access, regardless of work role or proficiency level.