Context
Two frameworks, one transition
DoD 8570.01-M set baseline certification requirements for anyone with privileged access to Department of Defense information systems. It organised the workforce into categories — technical, management, architecture and service provider — each with levels, and each level with a list of approved certifications.
DoD Directive 8140.01, with the qualification detail in Manual 8140.03, is replacing that model. Instead of broad categories it uses specific work roles drawn from the NICE Cybersecurity Workforce Framework, and it recognises a mix of education, training, certification and demonstrated experience rather than certification alone.
Both frameworks are referenced in live position descriptions during the transition. The matrix below reflects the 8570 baseline structure, which remains the fastest way to answer the practical question: which certification will satisfy this billet?
Interactive
Browse by category
Select a workforce category. Every level and its approved baseline certifications are listed below.
DoD 8570.01-M / 8140 pathway matrix
IAT Level I Entry technical roles on computing environments
IAT Level II Network environment roles, the largest single band
IAT Level III Enclave and advanced technical roles
IAM Level I First-line information assurance management
IAM Level II Programme and system-level management
IAM Level III Enterprise and enclave management
IASAE Level I System architecture and engineering, entry
IASAE Level II System architecture and engineering, journeyman
IASAE Level III Enclave and advanced architecture
CSSP Analyst Monitoring, detection and triage
CSSP Incident Responder Containment, eradication and recovery
CSSP Infrastructure Support Sensor and toolset administration
CSSP Auditor Assessment and compliance validation
CSSP Manager Service provider leadership
Full listing
Every category and level
The same data in printable table form. Certification names use their common short forms; continuing-education variants are marked “ce”.
IAT — Technical
| Level | Scope | Approved baseline certifications |
|---|---|---|
| IAT Level I | Entry technical roles on computing environments | A+ ce, CCNA-Security, CND, Network+ ce, SSCP |
| IAT Level II | Network environment roles, the largest single band | CCNA Security, CySA+, GICSP, GSEC, Security+ ce, CND, SSCP |
| IAT Level III | Enclave and advanced technical roles | CASP+ ce, CCNP Security, CISA, CISSP, GCED, GCIH, CCSP |
IAM — Management
| Level | Scope | Approved baseline certifications |
|---|---|---|
| IAM Level I | First-line information assurance management | CAP, CND, Cloud+, GSLC, Security+ ce, HCISPP |
| IAM Level II | Programme and system-level management | CAP, CASP+ ce, CISM, CISSP, GSLC, CCISO, HCISPP |
| IAM Level III | Enterprise and enclave management | CISM, CISSP, GSLC, CCISO |
IASAE — Architecture
| Level | Scope | Approved baseline certifications |
|---|---|---|
| IASAE Level I | System architecture and engineering, entry | CASP+ ce, CISSP, CSSLP |
| IASAE Level II | System architecture and engineering, journeyman | CASP+ ce, CISSP, CSSLP |
| IASAE Level III | Enclave and advanced architecture | CISSP-ISSAP, CISSP-ISSEP |
CSSP — Service provider
| Level | Scope | Approved baseline certifications |
|---|---|---|
| CSSP Analyst | Monitoring, detection and triage | CEH, CFR, CySA+, GCIA, GCIH, GICSP, Cloud+, PenTest+ |
| CSSP Incident Responder | Containment, eradication and recovery | CEH, CFR, CHFI, CySA+, GCFA, GCIH |
| CSSP Infrastructure Support | Sensor and toolset administration | CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+ |
| CSSP Auditor | Assessment and compliance validation | CEH, CySA+, CISA, GSNA, CFR, PenTest+ |
| CSSP Manager | Service provider leadership | CISM, CISSP-ISSMP, CCISO |
How to use it
Work backwards from the billet
- Find the position description for the role you want
- Identify the category and level it names, for example IAT Level II
- Pick the cheapest and fastest approved certification in that band
- Check whether COOL, Tuition Assistance or VA benefits cover the exam
- Book the exam before your funding window closes