DoD 8570 & 8140: Understanding Defense IT Certification Requirements
DoD Directive 8570.01-M and its successor DoD 8140 mandate that all personnel performing Information Assurance (IA) functions must hold approved certifications. In Huntsville's defense market, this affects 8,000+ IT and cybersecurity positions across government and contractor organizations.
DoD 8570 vs 8140: Key Differences
| Aspect | DoD 8570 | DoD 8140 |
| Status | Legacy (still referenced) | Current standard |
| Workforce Categories | IAT, IAM, IASAE, CSSP | Expanded work roles |
| Certification Approach | Specific cert requirements | Qualification-based |
| Training Component | Cert only | Cert + education + experience |
| Implementation | Fully implemented | Phased implementation ongoing |
DoD 8570 Workforce Categories
Technical personnel maintaining and operating IA systems.
| Level | Approved Certifications | Typical Roles |
| IAT Level I | A+, Network+, SSCP, CCNA-Security | IT Support, Help Desk |
| IAT Level II | Security+, SSCP, CCNA-Security, CySA+, GICSP | System Admin, Network Admin |
| IAT Level III | CASP+, CISSP, CISA, GCIH, GCED | Senior Engineer, Architect |
Personnel managing IA programs and policies.
| Level | Approved Certifications | Typical Roles |
| IAM Level I | Security+, CAP, GSLC | Security Coordinator, Junior ISSO |
| IAM Level II | CASP+, CISSP, CISM, GSLC | ISSO, Security Manager |
| IAM Level III | CISSP, CISM, GSLC | ISSM, Chief Security Officer |
IASAE - IA System Architect and Engineer
Personnel designing and developing IA solutions.
| Level | Approved Certifications | Typical Roles |
| IASAE Level I | CASP+, CISSP, CSSLP | Junior Security Architect |
| IASAE Level II | CASP+, CISSP, CSSLP | Security Architect |
| IASAE Level III | CISSP-ISSAP, CISSP-ISSEP | Chief Security Architect |
CSSP - Cyber Security Service Provider
Personnel providing cybersecurity services to protect DoD networks.
| Category | Approved Certifications | Typical Roles |
| CSSP Analyst | Security+, CySA+, CEH, GCIA | SOC Analyst, Threat Analyst |
| CSSP Infrastructure | Security+, SSCP, CASP+ | Security Engineer |
| CSSP Incident Responder | Security+, CEH, GCIH, ECIH | Incident Responder |
| CSSP Auditor | Security+, CISA, GSNA | Security Auditor |
| CSSP Manager | CISSP, CISM | Cyber Operations Manager |
Most Valuable DoD Certifications by ROI
| Certification | Cost | Covers | Salary Boost |
| Security+ | $392 | IAT II, IAM I, CSSP | +$8,000 - $12,000 |
| CISSP | $749 | IAT III, IAM II/III, IASAE | +$20,000 - $30,000 |
| CASP+ | $494 | IAT III, IAM II, IASAE | +$12,000 - $18,000 |
| CySA+ | $392 | IAT II, CSSP Analyst | +$8,000 - $12,000 |
| CEH | $1,199 | CSSP roles | +$10,000 - $15,000 |
DoD 8140 Work Roles (New Framework)
DoD 8140 expands beyond 8570 with 54 defined work roles.
| Work Role Category | Example Roles | Certification Path |
| Securely Provision | Security Architect, Systems Developer | CISSP, CSSLP, CASP+ |
| Operate and Maintain | System Admin, Network Admin | Security+, CySA+ |
| Oversee and Govern | ISSO, Program Manager | CISSP, CISM, CAP |
| Protect and Defend | SOC Analyst, Incident Responder | Security+, CEH, GCIH |
| Analyze | Threat Analyst, Intel Analyst | CISSP, GCIA, GCTI |
| Collect and Operate | Cyber Operator | GPEN, OSCP, CEH |
| Investigate | Digital Forensics Analyst | GCFE, GCFA, EnCE |
Timeline Compliance Requirements
| Scenario | Requirement |
| New hire - no certification | Must obtain within 6 months |
| Role change requiring higher level | Must obtain within 6 months |
| Certification expiration | Renew before expiration or removed from IA duties |
| Waiver | Temporary, max 6 months, requires justification |
Certification Maintenance Requirements
| Certification | Validity | Renewal Requirement |
| Security+ | 3 years | 50 CEUs or retake exam |
| CISSP | 3 years | 40 CPEs/year + $125 AMF |
| CASP+ | 3 years | 75 CEUs or retake exam |
| CEH | 3 years | 120 ECE credits |
| CySA+ | 3 years | 60 CEUs or retake exam |
Huntsville Positions by DoD 8570 Category
| Category | Open Positions | Avg Salary Range |
| IAT Level II | 450+ positions | $75,000 - $105,000 |
| IAT Level III | 180+ positions | $105,000 - $145,000 |
| IAM Level II | 120+ positions | $110,000 - $150,000 |
| IAM Level III | 45+ positions | $145,000 - $185,000 |
| CSSP Analyst | 85+ positions | $85,000 - $125,000 |
| IASAE | 60+ positions | $125,000 - $175,000 |
Recommended Certification Path
- Start with Security+: Covers most entry positions, IAT II baseline
- Add CySA+ or CEH: For SOC/analyst track
- Pursue CISSP: After 5 years experience, opens senior roles
- Specialize: CISSP concentrations, GIAC advanced certs