Certification guide for cleared IA candidates
DoD 8140 Certification List and Matrix: 8570 Guide
Find the official qualification options, interpret legacy certification levels and check the job requirement before paying for an exam.
View Information Assurance RolesIf you are trying to become an ISSO, ISSE, ISSM, security engineer, cyber compliance analyst, or RMF professional, the real question is simple: which certification helps you qualify for the role you actually want?
A certification can help clear a contract requirement, help a recruiter move your resume, and help a hiring manager trust your baseline knowledge. The wrong certification can also waste months and thousands of dollars.
DoD 8140 vs 8570: The Short Answer
DoD 8570 used broad workforce categories and certification levels. DoDM 8140.03 canceled the 8570 manual and now qualifies personnel against a specific DCWF work role at the Basic, Intermediate, or Advanced proficiency level. Under 8140, a certification can be one foundational qualification option; it is not the whole qualification model.
Cleared contractors still need to recognize 8570 terms because current DFARS clauses and some contract requirements continue to use IAT, IAM, and IASAE categories. Read the requisition, then confirm the contract requirement with the recruiter or security lead.
DoD 8140 Certification List: Find Approved Options by Work Role
There is no single certification that qualifies someone for every DoD cyber position. The official matrix organizes foundational options by DCWF work role and proficiency level. Education and training can also be options; completing a certification does not by itself complete all qualification requirements.
Open the official DoD 8140 Qualification Matrices and use the DoD matrix instructions to interpret the workbook. Record the version you use and confirm it with the organization before enrolling.
- Get the assigned role code. Ask for the primary DCWF role and any additional assigned roles. An ISSO or ISSE title alone is insufficient.
- Get the proficiency level. Identify Basic, Intermediate or Advanced for each role. Do not translate IAT II into Intermediate automatically.
- Find the matching matrix entry. Check certification, education and training options for that exact role and level. Read the notes and credential names.
- Check the remaining requirements. Confirm resident qualification, continuing development, component requirements and contract conditions with the workforce program manager or employer.
- Keep the confirmation. Record the selected option, matrix version, required completion date and confirming official before buying a voucher.
Worked lookup examples for cleared IA candidates
These examples show what to look up, not a determination that a particular credential qualifies.
- ISSO opening assigned 461, Basic: locate Systems Security Analyst and inspect the Basic qualification options. Compare an existing credential against that entry.
- ISSE opening assigned 652, Intermediate: locate Security Architect and inspect the Intermediate options. Do not substitute a generic IASAE II list.
- ISSM opening assigned 722, Advanced: locate Information Systems Security Manager and inspect the Advanced options and any additional assigned roles.
Lookup method source: DoD matrix instructions dated March 22, 2024. Qualification options change; use the current official matrix rather than treating the planning examples below as an approved list.
DoD 8140 Certification and Work Role Matrix
Start with the job you want, then verify the assigned DCWF work role, proficiency level, and approved qualification options. These common alignments are a candidate planning guide, not an official crosswalk.
| Target role | Legacy 8570 lens | Potential 8140 DCWF work roles | Certifications commonly considered |
|---|---|---|---|
| ISSO or RMF analyst | IAT II or III; sometimes IAM I or II, depending on duties | 461 Systems Security Analyst; 541 Vulnerability Assessment Analyst; 612 Security Control Assessor | Security+, CySA+, CGRC, SecurityX, or CISSP |
| ISSE or security architect | IASAE I, II, or III; sometimes IAT III | 631 Information Systems Security Developer; 652 Security Architect; 461 Systems Security Analyst | SecurityX, CISSP, CSSLP, CCSP, or CISSP-ISSEP |
| ISSM or IA manager | IAM II or III | 722 Information Systems Security Manager; sometimes 611 Authorizing Official or Designated Representative | CISSP, CISM, CGRC, SecurityX, or CISSP-ISSMP |
| Technical cyber or system operations | IAT I, II, or III | 451 System Administrator; 441 Network Operations Specialist; 511 Cyber Defense Analyst | A+, Network+, Security+, CySA+, SecurityX, or role specific GIAC credentials |
Job titles do not map one to one to DCWF work roles. Confirm the role code and proficiency level before paying for an exam. Review the current DoD 8140 Qualification Matrices for approved options.
How the 8570 to 8140 Transition Works
DoD 8570 was the old language most cleared candidates still recognize. It used broad categories like IAT, IAM, IASAE, and CSSP, and it was heavily certification driven.
DoD 8140 is the current framework. DoDM 8140.03 was issued in February 2023 and incorporates and cancels DoD 8570.01 Manual. It created a cyberspace workforce qualification model built around DCWF work roles, proficiency levels, foundational qualifications, resident qualifications, and continuous professional development.
The practical difference is this: DoD 8570 worked like a certification checklist. DoD 8140 works more like a work role qualification model.
Why You Still See DoD 8570 in Contractor Job Posts
Cleared contractor job postings still use 8570 language because contracts, labor categories, and hiring habits do not update overnight. Acquisition.gov still lists DFARS 252.239 7001 with contractor training and certification language tied to DoD 8570.01 Manual. The DoD Cyber Exchange transition guidance also says contractors remain under DoD 8570 policy until DFARS authorizes DoD 8140 implementation for contractor personnel.
That means candidates should understand both systems. If a posting says DoD 8570 compliant, ask which category and level. If a posting says DoD 8140, ask which DCWF work role and proficiency level.
Legacy IAT, IAM, and IASAE Categories Explained
The old baseline matrix centered on role type and level. Candidates in information assurance usually see three categories most often.
| Category | Practical meaning | Common role fit |
|---|---|---|
| IAT | Information Assurance Technical. The technical operator lane. | System administrator, network administrator, ISSO, security analyst, technical IA support. |
| IAM | Information Assurance Management. The program, oversight, risk, and leadership lane. | ISSM, senior ISSO, IA lead, cyber compliance manager, security program manager. |
| IASAE | Information Assurance System Architect and Engineer. The architecture and engineering lane. | ISSE, security architect, systems security engineer, cloud security engineer. |
Legacy 8570 Certification Table: IAT, IAM and IASAE
The table below shows selected baseline options from the July 2019 presentation hosted by NIST, slide 6. It preserves the names used in that historical source and is not an exhaustive or current approval list. Use it to interpret older job postings, then confirm the actual contract requirement.
| Category and level | Selected credentials in the source | Responsibility area |
|---|---|---|
| IAT I | A+ CE, Network+ CE, SSCP | Technical support and system operations |
| IAT II | Security+ CE, SSCP, CySA+, GSEC, GICSP | Technical security and administration |
| IAT III | CASP+ CE, CISA, CISSP (or Associate), GCED, GCIH | Advanced technical responsibilities |
| IAM I | CAP, GSLC, Security+ CE | Management and oversight |
| IAM II | CAP, CASP+ CE, CISM, CISSP (or Associate), GSLC, CCISO | Management and oversight |
| IAM III | CISM, CISSP (or Associate), GSLC, CCISO | Senior management and oversight |
| IASAE I | CASP+ CE, CISSP (or Associate), CSSLP | Architecture and engineering |
| IASAE II | CASP+ CE, CISSP (or Associate), CSSLP | Architecture and engineering |
| IASAE III | CISSP-ISSAP, CISSP-ISSEP | Advanced architecture and engineering |
Source: July 2019 workforce presentation, slide 6. CAP is the earlier name of CGRC; CASP+ is the earlier name of SecurityX. Confirm how the customer recognizes renamed credentials and whether an Associate designation is acceptable. Do not infer that an exam pass alone meets a requirement for a current certification.
IASAE I, II and III: Check the Exact Credential
The historical table lists CASP+ CE, CISSP (or Associate) and CSSLP for IASAE I and II. It lists CISSP-ISSAP and CISSP-ISSEP for IASAE III. A later ISC2 announcement dated June 28, 2021 adds CCSP to IASAE III and IAT III. This is why an older chart alone cannot establish every accepted option.
Separate the credential requirement from broader career development. Cloud, platform and engineering skills may strengthen an application, but they do not automatically replace a named baseline credential. For an 8140 requirement, return to the specific work role and proficiency level.
Does SSCP Meet DoD IAT II or IAM I Requirements?
The historical table lists SSCP under IAT I and IAT II, not IAM I. It lists Security+ CE under IAT II and IAM I. Those mappings are different even when both credentials are relevant to technical security work. Do not assume that SSCP satisfies a management requirement because it satisfies a technical one.
Under 8140, check SSCP against the assigned DCWF work role and proficiency level in the official matrix. Ask the employer to confirm the applicable contract requirement and credential status. Certification, clearance, experience and qualification for a particular position are separate questions.
CISSP vs SecurityX vs CISM
| Certification | Best signal | Best fit |
|---|---|---|
| CISSP | Broad senior security knowledge and market recognition. | Senior ISSO, ISSE, ISSM, security architect, IA lead, management growth. |
| CASP+ or SecurityX | Advanced technical practitioner credibility. | IAT Level III style roles, IASAE Level I or II style roles, senior technical IA roles. |
| CISM | Security management, governance, risk, and program leadership. | ISSM, security manager, cyber governance, IA program lead. |
CASP+ or SecurityX is not better than CISSP. CISSP is not automatically better than CASP+ or SecurityX. They solve different problems. If the contract names a certification, take that requirement seriously. If the contract allows several options, choose the one that matches the career lane you want.
Best Certifications for ISSO, ISSE, and ISSM Roles
- For ISSO roles. Start with baseline compliance and RMF credibility. Security+, CySA+, CGRC, CASP+ or SecurityX, and CISSP can all make sense depending on seniority.
- For ISSE roles. Focus on engineering and architecture credibility. CASP+ or SecurityX, CISSP, CISSP ISSEP, CSSLP, CCSP, cloud security certs, Linux certs, and GIAC certs may support the story.
- For ISSM roles. Focus on management, governance, and risk. CISSP, CISM, CGRC, GSLC, CASP+ or SecurityX, and CISSP ISSMP may matter depending on the program.
Open Roles by Certification Level
Use certifications to aim at roles, not just to decorate your resume. Here is the practical career mapping cleared candidates should consider.
| If you have | Look at roles like |
|---|---|
| Security+ | Junior ISSO, ISSO, cyber compliance analyst, system administrator with IA duties, RMF support analyst, security analyst. |
| CySA+ or CGRC | ISSO, RMF analyst, control evidence analyst, cyber compliance specialist, assessment support, security operations analyst. |
| CASP+ or SecurityX | Senior ISSO, ISSE, security engineer, IAT Level III style roles, IASAE Level I or II style roles, senior technical IA. |
| CISSP | Senior ISSO, ISSE, ISSM, security architect, cybersecurity manager, IAM Level II or III style roles, senior IA lead. |
| CISM | ISSM, security manager, cyber governance, risk manager, IA program lead. |
| ISSEP, ISSAP, CCSP, or CSSLP | Senior ISSE, security architect, cloud security architect, secure systems engineer, software security architect. |
Before You Pay for a Certification Exam
- Identify the opening. Save the job requisition, duties and named certification requirement.
- Confirm the framework. Record the 8570 category and level or the 8140 DCWF role code and proficiency level.
- Check what you already hold. Ask whether your current credential, education or training satisfies the applicable option.
- Confirm the deadline and status. Determine whether the credential must be active before application, start date or another specified milestone.
- Check the full commitment. Review issuer experience, endorsement and maintenance requirements as well as exam and training costs.
- Get employer confirmation. Record who confirmed the option and which source or contract requirement they used.
Bring the requisition and your current qualifications to a role fit conversation. Use public job details; do not submit classified information or sensitive contract material.
The Advice Candidates Usually Need
- If you have no certifications, confirm your target role and accepted qualification options first. Consider Security+ when the position accepts it and it fits your starting experience.
- If you want ISSO work, add RMF depth and consider CGRC.
- If you want ISSE work, build technical architecture depth and consider CASP+ or SecurityX, CISSP, or ISSEP depending on the role.
- If you want ISSM work, build leadership and risk experience, then look hard at CISSP, CISM, or CGRC.
- If you want to stay technical, do not chase only management certs.
- If you want to manage, do not hide behind technical certs.
- If the job posting names a cert, take it seriously.
- If the posting says DoD 8570 compliant, ask which category and level.
- If the posting says DoD 8140, ask which work role and proficiency level.
Related IA Career Guides and Roles
Review the role lane before paying for another exam. The right certification depends on whether you are trying to execute RMF, engineer secure architecture, or lead the IA program.
The Bottom Line
DoD 8140 replaced DoD 8570 for the current DoD cyber workforce qualification model, but cleared contractor job postings still use IAT, IAM, IASAE, and 8570 language because contracts and hiring habits do not change overnight.
Security+ is still the common baseline move. CASP+ or SecurityX is a strong advanced technical practitioner signal. CISSP is the broad senior security credential. CISM is strongest for management and governance. CGRC is useful for RMF and authorization work. The best certification is the one that matches the role, contract, labor category, and next step.
Sources and Reference Dates
Guide reviewed September 26, 2026. Historical certification examples retain their source dates; they are not a claim that a 2019 table is the current qualification matrix.
- DoD qualification matrix instructions, March 22, 2024
- NIST hosted workforce presentation, July 2019, slide 6
- ISC2 announcement: CCSP added to IASAE III and IAT III, June 28, 2021
- DoDM 8140.03: Cyberspace Workforce Qualification and Management Program
- DoD Cyber Exchange: DoD 8140 Qualification Matrices
- DoD Cyber Exchange: 8570 to 8140 Transition
- Acquisition.gov: DFARS 252.239 7001 Information Assurance Contractor Training and Certification
Frequently Asked Questions
Where can I find the official DoD 8140 certification list?
Use the DoD 8140 Qualification Matrices linked in this guide. Find the assigned DCWF work role and proficiency level, then check the available foundational qualification options. A job title or a certification name alone does not establish qualification. Confirm the matrix version and additional requirements with the employer or workforce program manager.
Does SSCP meet IAT II or IAM I requirements?
The historical 8570 table reproduced in the July 2019 presentation hosted by NIST lists SSCP in IAT I and IAT II, not IAM I. Do not treat SSCP and Security+ as interchangeable across all categories. For an 8140 position, verify SSCP against the assigned DCWF work role and proficiency level in the current matrix and confirm the contract requirement.
Which certifications appear in the legacy IASAE III category?
The July 2019 reference lists CISSP-ISSAP and CISSP-ISSEP. ISC2 announced the addition of CCSP to IASAE III in June 2021. These dated references explain legacy terminology; verify the applicable contract and current qualification options before choosing an exam. General CISSP and a specialized architecture credential are not interchangeable for every requirement.
Did DoD 8140 replace DoD 8570?
Yes. DoDM 8140.03 incorporates and cancels DoD 8570.01 Manual, but contractor job postings and contract language may still use 8570 terms such as IAT, IAM, and IASAE.
What is the difference between IAT, IAM, and IASAE?
IAT is the technical information assurance lane, IAM is the management and program lane, and IASAE is the architecture and engineering lane. Candidates should match certification choices to the role lane they are targeting.
What certification should an ISSO get first?
Confirm the target role and required qualification first. Security+ can be a practical option when the position accepts it, but an existing credential, education or training pathway may already meet the relevant foundational requirement. Ask the employer which option applies before paying for an exam.
Do you need CISSP to become an ISSE?
Not always. Some ISSE roles require CISSP, some accept CASP+ or SecurityX, and some care more about architecture, engineering, cloud, software, Linux, or customer specific experience. Senior ISSE candidates should still consider CISSP or CISSP ISSEP when it matches the target role.
Is CASP+ the same as SecurityX?
SecurityX is CompTIA's current name for the advanced security practitioner certification that many cleared job postings still call CASP+. Candidates should read the contract or job posting language carefully because market terminology can lag behind vendor naming.
What should I ask when a job posting says DoD 8570 compliant?
Ask which category and level the role requires, such as IAT Level II, IAT Level III, IAM Level II, or IASAE Level II. If the posting says DoD 8140, ask which DCWF work role and proficiency level applies.
Ready to use your IA certifications in cleared mission work?
Send your resume and include your clearance status, certifications, RMF experience, security engineering background, and the IA role you are targeting.