Updated September 29, 2026: This guide uses the DoD 8140 Qualification Matrix V2.1, effective September 19, 2025, which is the current matrix in the DoD CIO’s 8140 document library as of this update. DoD’s 8140 web content has moved to cyberworkforce.mil; the old cyber.mil 8140 pages say they will sunset on December 31, 2026 (DoD Cyber Exchange).
If you work in cyber for the Department of Defense (now also styled the Department of War), or want to, the certification rules you need to know are DoD 8140, not the old DoD 8570 IAT and IAM levels. Under 8140, the question is no longer “Is this cert IAT Level II?” It is “Is this cert approved for my position’s work role, and at what proficiency level?”
This guide explains how the system works, which popular certifications qualify for which work roles, what changed for contractors in 2026, and how to pick a certification. Every role-to-certification mapping below comes straight from DoD’s published V2.1 matrix. If you want the history of the old IAT and IAM levels, see our IAM vs. IAT certifications guide.
From DoD 8570 to DoD 8140: what changed
DoD Manual 8140.03, “Cyberspace Workforce Qualification and Management Program,” took effect on February 15, 2023, and cancelled DoD 8570.01-M (DoDM 8140.03). DoD’s transition guide is blunt about the change: there is no crosswalk between 8570’s IAT, IAM and IASAE categories and the new work roles (DoD transition guide).
| DoD 8570 (old) | DoD 8140 (current) | |
|---|---|---|
| Governing document | DoD 8570.01-M | DoDM 8140.03 (effective Feb 15, 2023) |
| How jobs are grouped | Broad categories: IAT, IAM, IASAE, CSSP | DoD Cyber Workforce Framework (DCWF) work roles, each with its own tasks and KSATs |
| Levels | Level I, II, III | Proficiency levels: Basic, Intermediate, Advanced, set per work role |
| What qualifies you | An approved baseline certification (plus computing environment training) | One foundational option (education, training, or a certification approved for the role and level) plus residential (on-the-job) qualification |
| Keeping it | Keep the certification current | At least 20 hours of continuous professional development a year, or the certification’s own requirement |
| Contractors | Covered through DFARS 252.239-7001 | The 8570 clause was removed from the DFARS effective Feb 1, 2026; contracts are being updated to name DCWF work roles |
Certifications you earned under 8570 can still count, but only if they are current and approved for your work role and proficiency level. DoD also says computing environment certificates are not required under 8140 (DoD transition guide).
Work roles and proficiency levels explained
The DCWF is DoD’s standard list of cyber work roles. The DCWF Tool v5.2 (July 7, 2026) lists 76 work roles across seven elements: IT, Cybersecurity, Cyber Effects, Intelligence, Cyber Enablers, Data/AI and Software Engineering. It added two roles that month, 452 Secure Configuration Specialist and 633 System Security Engineer (DCWF document library).
Every cyber position is coded with one primary work role and up to two additional work roles, and each role is filled at one of three proficiency levels (DoDM 8140.03). DoD’s Proficiency Levels SOP defines them like this (DoD CIO):
- Basic: familiar with basic concepts and processes and able to apply them with frequent, specific guidance.
- Intermediate: extensive knowledge of basic concepts, needs only periodic high-level guidance, and can handle non-routine and sometimes complicated situations.
- Advanced: in-depth understanding of advanced concepts, works with little to no guidance, and can serve as a resource and guide others.
Your position description, not your job title or your grade, decides which roles and levels you must meet. Ask your cyber workforce program manager or supervisor if you don’t know yours.
How qualification works under 8140
- Foundational qualification. Meet one option for your work role and level: approved education, DoD or military training, approved commercial training, or an approved personnel certification. For some roles, documented experience is a conditional alternative.
- Residential qualification. Show you can do the job in your own environment through on-the-job qualification and any extra requirements your component sets. This is always required, whatever foundational option you use.
- Annual maintenance. At least 20 hours of continuous professional development a year, or your certification’s own requirement.
An option approved at a higher level also counts at lower levels in the same work role, and components may set stricter requirements (Qualification Matrix V2.1). DoD civilians and service members have 9 months to meet foundational and 12 months to meet residential qualification (DoDM 8140.03). DoD’s Supplemental Guidance for Cyber Workforce Management V1.1, effective September 1, 2026, says those clocks start at the DoD 8140 letter of designation, and that contractors must be foundationally qualified when they start cyber work (DoD CIO).
Which certifications qualify: popular certs by work role (Matrix V2.1)
The table shows every work role where each certification is an approved personnel certification option in Qualification Matrix V2.1, with the proficiency level it is listed at. Because a higher-level option also counts at lower levels, a cert listed at Intermediate also satisfies Basic for that role. The V2.1 matrix covers the IT, Cybersecurity and Cyber Enabler elements owned by the DoD CIO; matrices for the Intelligence, Cyber Effects, Data/AI and Software Engineering elements are still in development (DoD 8140 document library).
| Certification | Approved work roles and level (DoD 8140 Matrix V2.1) |
|---|---|
| CompTIA A+ | Basic: 411 Technical Support Specialist; 451 System Administrator; 521 Cyber Defense Infrastructure Support Specialist |
| CompTIA Network+ | Basic: 411 Technical Support Specialist; 441 Network Operations Specialist; 451 System Administrator; 521 Cyber Defense Infrastructure Support Specialist; 671 System Testing and Evaluation Specialist |
| CompTIA Security+ | Intermediate: 411 Technical Support Specialist; 421 Database Administrator; 431 Knowledge Manager; 441 Network Operations Specialist; 451 System Administrator; 511 Cyber Defense Analyst; 521 Cyber Defense Infrastructure Support Specialist; 531 Cyber Defense Incident Responder; 541 Vulnerability Assessment Analyst; 612 Security Control Assessor; 622 Secure Software Assessor; 641 Systems Requirements Planner; 661 Research & Development Specialist; 671 System Testing and Evaluation Specialist; 722 Information Systems Security Manager; 751 Cyber Workforce Developer and Manager; 752 Cyber Policy and Strategy Planner; 802 IT Project Manager; 805 IT Program Auditor |
| CompTIA CySA+ | Advanced: 211 Forensics Analyst; 212 Cyber Defense Forensics Analyst; 221 Cyber Crime Investigator; 511 Cyber Defense Analyst; 531 Cyber Defense Incident Responder; 541 Vulnerability Assessment Analyst; 612 Security Control Assessor Intermediate: 521 Cyber Defense Infrastructure Support Specialist |
| CompTIA PenTest+ | Advanced: 212 Cyber Defense Forensics Analyst Intermediate: 211 Forensics Analyst; 221 Cyber Crime Investigator; 511 Cyber Defense Analyst; 521 Cyber Defense Infrastructure Support Specialist; 531 Cyber Defense Incident Responder; 541 Vulnerability Assessment Analyst; 612 Security Control Assessor; 671 System Testing and Evaluation Specialist |
| CompTIA SecurityX | Advanced: 221 Cyber Crime Investigator; 411 Technical Support Specialist; 421 Database Administrator; 441 Network Operations Specialist; 451 System Administrator; 641 Systems Requirements Planner; 661 Research & Development Specialist; 751 Cyber Workforce Developer and Manager; 752 Cyber Policy and Strategy Planner Intermediate: 612 Security Control Assessor; 631 Information Systems Security Developer; 651 Enterprise Architect; 652 Security Architect; 722 Information Systems Security Manager; 801 Program Manager; 802 IT Project Manager; 805 IT Program Auditor |
| ISC2 CC | Basic: 511 Cyber Defense Analyst; 521 Cyber Defense Infrastructure Support Specialist; 531 Cyber Defense Incident Responder; 631 Information Systems Security Developer; 722 Information Systems Security Manager |
| ISC2 CISSP | Advanced: 421 Database Administrator; 611 Authorizing Official/Designated Representative; 612 Security Control Assessor; 722 Information Systems Security Manager; 751 Cyber Workforce Developer and Manager; 752 Cyber Policy and Strategy Planner; 801 Program Manager; 802 IT Project Manager; 804 IT Investment/Portfolio Manager; 805 IT Program Auditor |
| ISC2 CCSP | Advanced: 441 Network Operations Specialist; 451 System Administrator; 671 System Testing and Evaluation Specialist; 751 Cyber Workforce Developer and Manager; 752 Cyber Policy and Strategy Planner; 802 IT Project Manager; 805 IT Program Auditor Intermediate: 531 Cyber Defense Incident Responder; 611 Authorizing Official/Designated Representative; 631 Information Systems Security Developer; 641 Systems Requirements Planner; 651 Enterprise Architect; 652 Security Architect; 722 Information Systems Security Manager |
| ISACA CISM | Advanced: 541 Vulnerability Assessment Analyst; 611 Authorizing Official/Designated Representative; 612 Security Control Assessor; 652 Security Architect; 722 Information Systems Security Manager; 723 COMSEC Manager; 751 Cyber Workforce Developer and Manager; 752 Cyber Policy and Strategy Planner; 801 Program Manager; 802 IT Project Manager; 804 IT Investment/Portfolio Manager; 805 IT Program Auditor |
| ISACA CISA | Advanced: 411 Technical Support Specialist; 421 Database Administrator; 541 Vulnerability Assessment Analyst; 612 Security Control Assessor; 802 IT Project Manager; 805 IT Program Auditor |
| EC-Council CEH | Advanced: 661 Research & Development Specialist Intermediate: 441 Network Operations Specialist; 521 Cyber Defense Infrastructure Support Specialist; 531 Cyber Defense Incident Responder; 671 System Testing and Evaluation Specialist Basic: 511 Cyber Defense Analyst; 541 Vulnerability Assessment Analyst |
| EC-Council CEH (Practical) | Intermediate: 511 Cyber Defense Analyst; 531 Cyber Defense Incident Responder; 541 Vulnerability Assessment Analyst |
| GIAC GSEC | Intermediate: 411 Technical Support Specialist; 421 Database Administrator; 441 Network Operations Specialist; 451 System Administrator; 511 Cyber Defense Analyst; 521 Cyber Defense Infrastructure Support Specialist; 531 Cyber Defense Incident Responder; 541 Vulnerability Assessment Analyst; 611 Authorizing Official/Designated Representative; 612 Security Control Assessor; 622 Secure Software Assessor; 631 Information Systems Security Developer; 632 Systems Developer; 641 Systems Requirements Planner; 651 Enterprise Architect; 652 Security Architect; 671 System Testing and Evaluation Specialist; 711 Cyber Instructional Curriculum Developer; 722 Information Systems Security Manager; 723 COMSEC Manager; 802 IT Project Manager; 805 IT Program Auditor |
| Cisco CCNA | Advanced: 441 Network Operations Specialist |
A few patterns stand out. Security+ is listed at Intermediate for 19 work roles, from technical support and system administration to cyber defense analysis and security control assessment. CySA+ is an Advanced option for the core defensive roles (511, 531, 541 and 612). CISSP and CISM sit at Advanced for management, authorization and program roles. And ISC2 CC was added in V2.1 as a Basic option for five cybersecurity roles, including 511 and 722.
Certifications for the most common work roles
These are the full personnel certification lists from Matrix V2.1 for the roles job seekers ask about most. The lists include GIAC, EC-Council, FITSP and other certifications alongside the familiar CompTIA, ISC2 and ISACA ones.
| Work role | Basic | Intermediate | Advanced |
|---|---|---|---|
| 411 Technical Support Specialist | A+, Network+ | CND, GFACT, GSEC, Security+ | CCNP Security, CISA, FITSP-O, GICSP, SecurityX, SSCP |
| 441 Network Operations Specialist | CND, Network+ | CEH, Cloud+, GCIH, GICSP, GSEC, Security+, SSCP | CCNA, CCNP Security, CCSP, GCED, GCIA, GCLD, GDSA, GFACT, SecurityX |
| 451 System Administrator | A+, CND, Network+ | Cloud+, GICSP, GSEC, Security+, SSCP | CCNP Security, CCSP, FITSP-O, GFACT, SecurityX |
| 511 Cyber Defense Analyst | CC, CEH, GFACT, GISF | CEH(P), Cloud+, FITSP-O, GCED, GDSA, GMON, GRID, GSEC, PenTest+, Security+ | CBROPS, CFR, CySA+, GCFA, GCIA, GICSP |
| 521 Cyber Defense Infrastructure Support Specialist | A+, CC, CND, GCLD, GDSA, GFACT, Network+ | CEH, Cloud+, CySA+, GMON, GRID, GSEC, PenTest+, Security+, SSCP | CISSP-ISSAP, CISSP-ISSEP, GCIA, GICSP |
| 531 Cyber Defense Incident Responder | CC, GDSA, GISF | CBROPS, CCSP, CEH, CEH(P), Cloud+, ECIH, FITSP-O, GCED, GCIH, GRID, GSEC, PenTest+, RCCE Level 1, Security+ | CFR, CySA+, GCFA, GCIA, GICSP |
| 541 Vulnerability Assessment Analyst | CEH | CEH(P), Cloud+, CPTE, FITSP-A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, RCCE Level 1, Security+ | CFR, CISA, CISM, CySA+, GPEN, GSNA |
| 612 Security Control Assessor | No certification listed (education, training or experience options only) | CGRC/CAP, CISSO, Cloud+, FITSP-A, GCSA, GSEC, PenTest+, Security+, SecurityX | CCISO, CISA, CISM, CISSP, CISSP-ISSEP, CySA+, GSLC, GSNA |
| 652 Security Architect | GCLD, GISF | CCSP, CISSO, Cloud+, CSSLP, FITSP-D, GCSA, GMON, GSEC, SecurityX | CCNP Enterprise, CISM, CISSP-ISSAP, CISSP-ISSEP, GCIA, GDSA, GICSP |
| 722 Information Systems Security Manager | CC | CCISO, CCSP, CGRC/CAP, CISSO, Cloud+, GCSA, GMON, GSEC, Security+, SecurityX, SSCP | CISM, CISSP, CISSP-ISSMP, FITSP-M, GCIA, GCIH, GICSP, GSLC |
Notice that CISSP is not a listed option for 652 Security Architect in V2.1; the ISC2 options there are CISSP-ISSAP and CISSP-ISSEP (Advanced) and CCSP (Intermediate). Details like this are why you should always check your exact work role rather than relying on a general “approved list.”
Popular certifications that are not in the matrix
Some well-known certifications are not approved personnel certification options for any DoD CIO work role in V2.1. That includes OffSec OSCP, the Google Cybersecurity Certificate, AWS Certified Security – Specialty and Microsoft SC-200. They can still be valuable for your skills and career, but they won’t satisfy an 8140 foundational requirement by themselves. The CCNA appears only once, as an Advanced option for 441 Network Operations Specialist.
If you see a different list on a training vendor’s site, trust the DoD matrix. The authoritative files are the Qualification Matrix V2.1 spreadsheet and cover document in the DoD 8140 document library.
What changed for contractors in 2026
For years, contractors stayed on 8570 because DFARS clause 252.239-7001 still pointed to it. A May 27, 2026 memo from the DoW CIO says a DFARS class deviation, effective February 1, 2026, removed the references to DoDD 8140.01, DoD 8570.01-M and clause 252.239-7001. The memo directs components to make sure contractor cyber personnel meet the qualification requirements of their DCWF work roles and to update contracts; detailed guidance was still being developed (DoW CIO memo).
In practice, contractors should read the contract or task order. It should name the work roles and proficiency levels, and you must be foundationally qualified when you start the cyber work (Supplemental Guidance V1.1). The DoD CIO has also said qualification data collection is expected to begin this fall (cyberworkforce.mil).
Which 8140 certification should you pick?
- Entry-level IT (help desk, system administration): CompTIA A+ and Network+ are Basic options for 411 and 451. Security+ lifts you to Intermediate for those roles and many more.
- Your first security role: Security+ is the most flexible single cert in the matrix, listed at Intermediate for 19 roles. ISC2 CC is a cheaper Basic option for 511, 521, 531, 631 and 722.
- SOC analyst or incident responder (511, 531): CySA+ is an Advanced option for both. See our Security+ vs CySA+ comparison.
- Vulnerability assessment (541): CEH is Basic, PenTest+ and CEH (Practical) are Intermediate, and CySA+, CISA and CISM are Advanced.
- Security control assessor or ISSM (612, 722): CISSP and CISM are Advanced options for both.
- Cloud-heavy network or system roles (441, 451): CCSP is an Advanced option for both.
Not sure which cert to pursue next for a DoD role? Use the cybersecurity certification roadmap to match career goals to a sensible order.
How to check your own requirement
- Find your position’s primary and additional DCWF work roles and proficiency levels. Your supervisor or cyber workforce program manager has them.
- Open the current Qualification Matrix from the DoD 8140 document library and look up your work role code.
- Pick one foundational option at your level or higher. If you hold a certification that is listed, make sure it is current.
- Complete residential qualification with your organization and log your 20 hours of professional development each year.
- If you are a contractor, check the contract language as it is updated.
DoD cyber policy shifts often enough to miss if you only check quarterly. The CyberExperts Daily Brief summarizes what changed and why it matters, in about five minutes on weekday mornings. Get tomorrow’s brief.
Frequently asked questions
What is DoD 8140?
DoD 8140 is the Defense Department’s cyber workforce qualification program. DoD Manual 8140.03 took effect on February 15, 2023, and replaced DoD 8570.01-M. It qualifies people by DCWF work role and proficiency level instead of the old IAT and IAM levels.
Is DoD 8570 still in effect?
No. DoDM 8140.03 cancelled DoD 8570.01-M in 2023 for DoD civilians and service members, and a DFARS class deviation effective February 1, 2026 removed the 8570 contractor clause. Contracts are being updated to name DCWF work roles.
Does Security+ count for DoD 8140?
Yes. In Qualification Matrix V2.1, Security+ is an approved certification at the Intermediate level for 19 work roles, including 411, 451, 511, 531, 541, 612 and 722. Check your own work role, because the level is set per role.
Is there a crosswalk from IAT Level II to 8140?
No. DoD’s transition guide says there is no direct mapping between 8570 categories and DCWF work roles. Your certification counts only if it is current and approved for your position’s work role and level.
Does a certification alone qualify me under 8140?
No. A certification can meet the foundational requirement, but you also need residential (on-the-job) qualification and at least 20 hours of continuous professional development a year, or the certification’s own requirement.
Is OSCP approved for DoD 8140?
OSCP is not listed as an approved personnel certification in Qualification Matrix V2.1 for any DoD CIO work role. PenTest+, CEH, CEH (Practical) and several GIAC certifications are listed for roles such as 541 Vulnerability Assessment Analyst.
Where can I find the official DoD 8140 matrix?
On the DoD CIO’s DoD 8140 site at cyberworkforce.mil, in the Document Library. The current version is Qualification Matrix V2.1, effective September 19, 2025. The old cyber.mil pages are set to sunset on December 31, 2026.
Sources
- DoD CIO, DoD 8140 home page: cyberworkforce.mil
- DoD CIO, DoD 8140 Document Library: cyberworkforce.mil
- DoD 8140 Qualification Matrix V2.1, effective Sep 19, 2025 (XLSX): media.defense.gov
- DoD 8140 Qualification Matrix V2.1 cover document (PDF): media.defense.gov
- DoD Manual 8140.03, Cyberspace Workforce Qualification and Management Program (Feb 15, 2023): cyberworkforce.mil
- DoD CIO, DoD 8570 IA Program Transition to DoD 8140 (Aug 7, 2024): dl.dod.cyber.mil
- DoD CIO, DoD 8140 Proficiency Levels SOP V1.0 (Aug 30, 2024): cyberworkforce.mil
- DoD CIO, Supplemental Guidance for Cyber Workforce Management V1.1 (effective Sep 1, 2026): cyberworkforce.mil
- DoW CIO memo, 8140 requirements for contractors (May 27, 2026): cyberworkforce.mil
- DoD CIO, DCWF Tool v5.2 (Jul 7, 2026), DCWF Document Library: cyberworkforce.mil
- DoD Cyber Exchange, former DoD 8140 page (migration notice): cyber.mil
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.