Fort Gordon cyber awareness training is now delivered under the installation’s current name, Fort Eisenhower, but the requirement itself hasn’t changed: every authorized user of a DoD information system on the installation must complete the DoD Cyber Awareness Challenge once each fiscal year, save the certificate, and get it recorded through their unit. Miss the deadline and your network access is suspended until you finish it.
Who Has To Take It
The Cyber Awareness Challenge applies to any authorized user of a DoD information system.1Center for Development of Security Excellence. Cyber Awareness Challenge DS-IA106.06 That covers active-duty service members, Department of the Army civilians, and contractors with network access. Rank and job title don’t change the rule. A general officer, a GS-7, and a contractor badge holder are all on the same clock.
The training is due once per fiscal year, which runs October 1 through September 30. Your personal expiration date is set by the day you last completed the course, and the tracking system watches it for you.
Where To Log In
The current course lives on cyber.mil. There are two access paths. DoD users with a Common Access Card go through Joint Knowledge Online (JKO); other authorized users can launch it directly from the DISA training page.2Cyber Exchange. Cyber Awareness Challenge Either way you’ll need a CAC and a working card reader.
You don’t strictly need a government-furnished computer. The Army Enterprise Azure Virtual Desktop lets you reach DoD systems from a personal device by installing the Windows App (Remote Desktop client) and signing in with an active Army 365 account. One catch: AVD access itself requires a current Cyber Awareness certificate and IT User Agreement, so if you’ve already lapsed, you’ll need a government workstation or help from a coworker to get back in.3Army Links. Army Enterprise Azure Virtual Desktop Registration
What the Course Looks Like
The Challenge is an interactive, scenario-based course on common cybersecurity threats and safe practices at work and at home. Expect vignettes on phishing, removable media, social engineering, mobile devices, and safeguarding personally identifiable information. Read the details in each scenario; the questions turn on them.
Before you begin, the system asks you to confirm identifying details and your unit. Work through the modules at your own pace. At the end you’ll land on a certificate screen that prompts you to enter your name and save the document. Save it. If you close that screen without saving, the system keeps no copy and you’ll have to retake the entire course to produce another one.4Cyber Exchange. Cyber Awareness Challenge – Certificate of Completion Download the PDF, and if you’re on AVD, pull it to your local machine before ending the remote session.
Getting Credit Recorded
Finishing the course doesn’t make you compliant on paper. The certificate has to reach the right tracking system. Send the saved PDF to your unit’s Information System Security Manager, or whoever fills the Information Assurance role in your organization. Most units accept it by encrypted email or through an internal upload portal.
The Army retired the Army Training and Certification Tracking System (ATCTS) in May 2025 and replaced it with the Streamlined Account Validation System. Prior-year completions should have migrated over, but ask your ISSM to confirm your current certificate shows up in the new system. Updates usually process within a day or two. Near the end of a fiscal year, when everyone is catching up at once, expect it to take longer.
What a Lapse Costs You
Letting the training expire is not a paperwork nuisance. Across DoD, failure to complete annual cyber awareness training results in suspension of access to both NIPRNet and SIPRNet. If your job runs on a computer, email, or any digital system on the installation, you effectively can’t work until access is restored.
Getting back in means completing the current year’s course, submitting the new certificate through your chain, and waiting for the tracking system and network administrators to update your account. That often takes several days because it requires manual action on the admin side. At Fort Eisenhower, where cyber operations are the installation’s core mission, an avoidable lapse during a busy operational period will not go over well.
If You’re in a Designated Cyber Work Role
The annual Challenge is the baseline for everyone. If you’re assigned to a designated cyber work role, it’s only the start. Under DoD Manual 8140.03, personnel in those roles must meet foundational qualification requirements within nine months of assignment and resident qualification requirements within twelve months, running concurrently. Certifications recognized under the old DoD 8570 framework were carried over and mapped to work roles and proficiency levels under 8140, so a current Security+, CEH, or CISSP may already satisfy part of your requirement — check with your Cyber Workforce Advisory Group representative.6Cyber Exchange. DoD 8140 FAQ
People in cyber work roles also owe at least 20 hours per year of continuing professional development.5Department of Defense CIO. DoDM 8140.03 Cyberspace Workforce Qualification and Management Program Individual commands at Fort Eisenhower may layer on their own requirements, so confirm the full picture with your supervisor.
Common Problems and How To Fix Them
The complaint you’ll hear most often is that someone finished the course but their certificate didn’t show up in the tracking system. Ask your ISSM whether they’ve uploaded it manually before assuming something broke. If the issue is on the JKO side, contact the JKO Help Desk at 757-203-5654 or js.jko.helpdesk@mail.mil, and include your full name, CAC status, organization, country of citizenship, and a description of the problem.7Joint Knowledge Online. Get Help Contact JKO
The other recurring problem is the unsaved certificate. There is no recovery. The system doesn’t hold onto it, and no help desk can pull one back.4Cyber Exchange. Cyber Awareness Challenge – Certificate of Completion Save the PDF first, then close the browser.
If the portal won’t recognize your CAC, check that your card reader drivers and DoD root certificates are current. ActivClient or the built-in Windows smart card middleware has to trust the DoD certificate chain. If you can’t sort it out on your own device, use a government workstation on the installation; it will already be configured correctly.