What Is DoD 8570? Certifications, Costs, and 8140 Transition

DoD Directive 8570 is the Department of Defense policy that set standardized certification and training requirements for military personnel, civilian employees, and contractors performing cybersecurity work on DoD information systems. It sorted the workforce into categories and levels, then required each person to hold a specific commercial certification for their role. As of February 15, 2023, the Department formally replaced it with the DoD 8140 Cyberspace Workforce Qualification Program, but 8570 categories, certifications, and language still appear throughout hiring, contract requirements, and command practice during the ongoing transition.

How the 8570 Workforce Is Organized

The 8570.01-M manual divides cybersecurity work into four categories based on job function.

  • Information Assurance Technical (IAT): Hands-on roles focused on securing, operating, and maintaining hardware, software, and the data they contain.
  • Information Assurance Management (IAM): Roles that develop, implement, and maintain cybersecurity policy and programs rather than touching systems directly.
  • Information Assurance System Architecture and Engineering (IASAE): Design-focused roles responsible for building and integrating secure systems and networks.
  • Cybersecurity Service Provider (CSSP): Specialized roles originally called Computer Network Defense Service Providers, covering analysts, incident responders, infrastructure support, auditors, and service provider managers.

IAT, IAM, and IASAE each split into three numbered levels. Level I positions operate and support individual computing environments — workstations and local systems where you follow established procedures. Level II moves into the network environment and multi-user systems where you implement security controls across shared infrastructure. Level III is the enterprise tier, covering organization-wide architecture and policy.

Approved Baseline Certifications

Every 8570 position requires a commercial certification from the Department’s approved baseline list, matched to the specific category and level. Holding a higher-level credential does not automatically satisfy a lower-level requirement unless that credential also appears on the list for that lower level.

IAT Certifications

  • IAT Level I: CompTIA A+ CE, CompTIA Network+ CE, CCNA-Security, or SSCP.
  • IAT Level II: CompTIA Security+ CE, CompTIA CySA+, CCNA Security, GICSP, GSEC, or SSCP.
  • IAT Level III: CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, or GCIH.

IAM Certifications

  • IAM Level I: CompTIA Security+ CE, GSLC, or CGRC (formerly CAP).
  • IAM Level II: CGRC, CASP+ CE, CISM, CISSP (or Associate), GSLC, or CCISO.
  • IAM Level III: CISM, CISSP (or Associate), GSLC, or CCISO.

IASAE Certifications

  • IASAE Level I: CASP+ CE, CISSP (or Associate), or CSSLP.
  • IASAE Level II: CASP+ CE, CISSP (or Associate), or CSSLP.
  • IASAE Level III: CISSP-ISSAP or CISSP-ISSEP.

The CAP credential from ISC2 was renamed Certified in Governance, Risk and Compliance (CGRC) in 2023. Older 8570 charts still listing CAP are pointing to the same certification.

Most 8570 positions also require a computing environment certification tied to the specific operating systems, platforms, or network gear you actually work with. Common examples include Microsoft server or Azure certifications for Windows environments, Red Hat (RHCSA) or Linux Professional Institute (LPIC) credentials for Linux shops, and Cisco certifications for network-focused roles. Your hiring organization tells you which one applies, and you typically have 90 to 180 days after starting to pass it. Under 8140, CE certifications are no longer a universal policy requirement, though individual commands can still mandate them.

Compliance Timelines and Consequences

Under DoD 8570, personnel assigned to a cybersecurity position have six months to obtain the required baseline certification. Miss that window without a waiver and you lose privileged access to DoD systems. For someone whose entire job depends on that access, losing it means you cannot do the work.

What happens next depends on your status. Military members may be reassigned to non-cyber duties. Civilian employees face potential reassignment as well. For contractors the stakes are usually sharpest, because contract language typically requires certified personnel, and falling out of compliance can mean removal from the contract entirely. Six months sounds generous until you factor in study time, exam scheduling, and the possibility of failing a first attempt.

Under 8140 the timelines shifted. Military members and DoD civilians must meet foundational qualification requirements within nine months and residential qualification requirements within twelve months of assignment to a cyber work role. Contractors must be qualified at the start of work, with no grace period in the policy itself. Waivers are available under 8140 only for severe operational or personnel constraints, cannot exceed six months, and cannot be issued consecutively.

What Certifications Cost, Up Front and Over Time

Exam prices vary widely by level. CompTIA A+ runs about $253 per exam and requires two exams (Core 1 and Core 2), so the full cost lands near $506. Security+ — arguably the most common 8570 certification because it appears across multiple categories and levels — costs approximately $425 per attempt. At the senior end, CISSP is $749 per attempt, and CISM is $575 for ISACA members or $760 for non-members. These are per-attempt fees; a failed attempt means paying again. Many employers and military services offer voucher programs or tuition assistance, so check what’s available before paying out of pocket.

Passing is only the first cost. Every approved certification requires ongoing maintenance.

CompTIA certifications are valid for three years. Renewing Security+ requires 50 continuing education units (CEUs) over that cycle, earned through training, conferences, published research, or professional development, plus a renewal fee at each three-year mark. ISC2 credentials like CISSP carry an annual maintenance fee of $135. ISACA certifications like CISM charge $45 per year for members and $85 for non-members, plus continuing professional education hours each year. Letting maintenance lapse doesn’t just dent your résumé; it can pull you out of compliance and out of the role.

The Move to DoD 8140 and What It Means for You

DoDM 8140.03 took effect February 15, 2023. The two frameworks are structured differently, and there is no direct crosswalk between them.

Where 8570 was compliance-based — find your category, find your level, get the listed certification — 8140 uses what the Department calls a demonstration of capability model. The DoD Cyber Workforce Framework (DCWF) replaces three categories and three levels with 74 granular work roles organized under seven workforce elements covering IT, cybersecurity, cyber effects, cyber intelligence, and cyber enablers. Qualifications can now be satisfied through a mix of certifications, DoD skills-based courses, and demonstrated experience, which helps people whose hands-on background didn’t map neatly to the old certification-only approach.

If you already hold 8570-approved certifications, they carry forward. They are aligned to specific DCWF work roles and proficiency levels under 8140, so you don’t start over, though your credentials may satisfy different requirements than they did before, depending on how your position is coded.

Rollout is phased. Cybersecurity workforce positions had a two-year implementation deadline from the manual’s effective date; the broader cyber workforce elements had three years. If you’re entering a DoD cyber role now, expect your requirements to be written in 8140 terms, but don’t be surprised when supervisors, job postings, and contract language still reference 8570 categories and certifications while the transition finishes.