There is often some confusion about the difference between IAM and IAT certifications. Many times these terms are confused and interchanged.
Both IAM and IAT were established by the Dept. of Defense in 2004. These are qualification standards meant to ensure that the Dept. of Defense IT systems are staffed with technical and management personnel who meet a certain standard of technical expertise.
IAT stands for Information Assurance Technical. The IAT certification levels are achieved by passing specific exams and having certain work experiences that meet particular requirements. These requirements are focused on technical knowledge and are geared toward technical staff.
Older article, current brief.
This article gives you the background. The brief gives you what changed next.
Get the weekday cyber brief for hiring signals, skills shifts, and major cyber developments shaping the market now.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
IAM stands for Information Assurance Management. The IAM certification levels are achieved by passing specific exams and having certain work experiences that meet particular requirements. These requirements are focused on management and are geared toward leadership staff.
Both IAT and IAM standards have three levels: 1, 2, and 3. Level 1 is considered entry-level certifications, level 2 are intermediate, and level 3 is expert level.
Government jobs and many commercial industry jobs require applicants to meet one of the certification levels as a minimum requirement for being considered for the position.
Below is the government-published chart that shows the IT certifications that fall into each of the IAT and IAM levels.
DoD 8570.01-M. DoD Approved Baseline Certifications
Older article, current brief.
This article gives you the background. The brief gives you what changed next.
Get the weekday cyber brief for the new exploitation, policy moves, and risk shifts this article could not cover when it was published.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
| IAT Level I | IAT Level II | IAT Level III |
| CompTIA A+ CompTIA Network+ SSCP |
GSEC CompTIA Security+ SCNP SSCP |
CISA GSE SCNA CISSP (or Associate) GCIH |
| IAM Level I | IAM Level II | IAM Level III |
| CAP GISF GSLC CompTIA Security+ |
CAP GSLC CISM CISSP (or Associate) |
GLSC CISM CISSP (or Associate) |
If you are working in or planning to work in the IT or cybersecurity field, then obtaining the appropriate certification levels is critical and can be quite lucrative.
Obtaining IAM1 or IAT1 level certifications is often the first step to gain an entry-level position in the IT field.
Obtaining IAM3 or IAT3 level certifications demonstrates expert-level knowledge and experience and is the objective of many experienced technical and management IT professionals.
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
How to Stay Secure Managing End-of-Life Software
Legacy software often operates under the "if it isn't broken, don't fix it" mentality until a security crisis forces action. However, managing...
Best 6 Tools to Eliminate CVEs in Container Images
Key Takeaways Container image CVEs often come from inherited base image packages, not only application code. The strongest tools reduce vulnerabilities before...
8 Best Virtual CISO Companies of 2026
The virtual CISO market has changed. A few years ago, many companies hired a vCISO mainly to prepare for SOC 2, satisfy...
The 5-Minute Cyber Brief: September 3, 2026
The fastest way to catch up on what changed after this article was published.