In a secure operations center, military cybersecurity professionals, including cyber defense analysts and systems security analysts, collaborate at their workstations, utilizing the DoD 8140 framework to enhance their cyber defense capabilities.

DoD Directive 8140 replaced 8570 - and most transitioning military service members are still studying the wrong cert list. Here is the 2026 roadmap that maps to your MOS, your desired cybersecurity role, and the qualifications that actually count.

Key Takeaways

  • DoD 8140 (with DoDM 8140.02 and 8140.03) is the Department of Defense policy for managing its cyber workforce, replacing the previous DoD 8570 framework with a role-based system built on the DoD Cyber Workforce Framework (DCWF).
  • The framework categorizes the workforce into seven key elements - Cyber IT, Cybersecurity, Cyber Effects, Intelligence, Cyber Enablers, Software Engineering, and Data/AI - each with proficiency levels: Basic, Intermediate, and Advanced.
  • Around 225,000 positions will meet DoD 8140 qualification criteria, with compliance deadlines for cybersecurity workforce qualifications set at February 15, 2025, and February 15, 2026, for remaining workforce elements.
  • Transitioning service members, DoD civilian employees, and defense contractor personnel should map their MOS/AFSC/ratings to DCWF work roles and select certifications (Security+, CySA+, CISSP, CCNP Security) from the 8140 qualification matrices.
  • GI Bill, SkillBridge, and approved affiliate training programs can fund 8140-recognized certifications, helping individuals become mission-ready for federal cyber roles.

What Is DoDD 8140 and Why It Matters for the DoD Cyber Workforce

DoD 8140 is the Department of Defense's unified dod directive governing cyberspace workforce development. Finalized through DoDM 8140.02 (2021) and DoDM 8140.03 (February 2023), it establishes baseline standards for cybersecurity qualifications across every component and agency. DoD 8140 was implemented in 2023 for the cybersecurity workforce element and governs how the department identifies, qualifies, and tracks cybersecurity personnel.

The directive uses the dod cyber workforce framework - also called the dod cyberspace workforce framework - as the authoritative structure defining work roles, tasks, and KSATs. It requires industry certifications accredited by ANSI for compliance and supports recruitment and retention of cybersecurity personnel. The dod cio office serves as the Office of Primary Responsibility for IT, Cybersecurity, and cyberspace enabler workforce elements.

DoD 8140 affects all military, civilian, and contractor personnel performing common cybersecurity functions. Even civilian employees outside traditional "cyber" billets may be covered if their duties match a DCWF role. For security leaders, 8140 standardizes training and certification processes for cyber roles and improves workforce readiness by aligning talent to mission needs.

How 8140 Replaced 8570 (and What Changed)

DoD 8570 (mid-2000s) was certification-centric, tying approved certs to four broad IA workforce categories: IAT, IAM, IASAE, and CSSP. DoD 8140 replaces the previous DoD 8570 framework with a flexible, role-based model that covers far more than traditional network defense.

Key differences:

  • 8570: Fixed buckets (IAT I–III, IAM I–III, IASAE, CSSP), limited to IA/security roles, cert-only qualification.
  • 8140: 50–70+ discrete DCWF work roles, three proficiency levels (Basic, Intermediate, Advanced), and DoD 8140 allows for multiple ways to qualify - certifications, education, training, or documented experience.
  • Scope expansion: 8140 now covers cyber effects, the intelligence workforce, software engineering, data/AI, and cyber enablers - not just defensive security.
  • Timeline: DoDM 8140.03 officially cancelled 8570 on February 15, 2023. Compliance deadlines are February 15, 2025 (cybersecurity element) and February 15, 2026 (IT, Effects, Intelligence, Enablers).
  • Legacy labels persist: Many job announcements still reference "IAT II" or "8570," but the cybersecurity workforce framework under 8140 now governs actual qualification.

If you're studying from an old 8570 cert chart, you may be preparing for requirements that no longer exist. Always verify against the current 8140 matrices.

The DoD Cyber Workforce Framework (DCWF) Under 8140

The DCWF is the backbone of 8140's role-based approach. The DoD Cyber Workforce Framework organizes the cyberspace workforce by specific job roles, each with a unique numeric ID, defined tasks, and KSAT statements.

DoD 8140 establishes specific cybersecurity work roles spanning seven workforce elements:

  • Cyber IT: system administrator, technical support specialist, network technician, database administrator, data operations specialist
  • Cybersecurity: cyber defense analyst, cyber defense incident responder, cyber defense forensics analyst, vulnerability assessment analyst, security control assessor, information systems security manager, systems security analyst, control systems security specialist
  • Cyber Effects: access network operator, exploitation analyst, cyber operations roles
  • Intelligence (Cyberspace): digital network exploitation analyst, multi disciplined language analyst, host analyst, target analyst reporter, joint targeting analyst, network analyst
  • Cyber Enablers: cyber legal advisor, cyber workforce developer, cyber instructor, knowledge manager, evaluation specialist, ethics specialist, strategy planner, project manager, program manager, product support manager
  • Software Engineering: software developer, information systems security developer, secure software assessor, software test roles, product designer user interface, service designer user experience
  • Data/AI: data analyst, data officer, ai adoption specialist, ai innovation leader, adoption specialist, innovation leader

Additional roles include security architect, enterprise architect, systems requirements planner, forensics analyst, and cyber crime investigator. Each role maps to proficiency levels where DoD 8140 establishes proficiency levels: Basic, Intermediate, and Advanced.

Certification Requirements by 8140 Work Role

DoDM 8140.03 introduced the Cyber Workforce Qualification Program with foundational, residential, and continuous professional development requirements. Personnel qualifications include foundational, residential, and continuous professional development stages. DoD 8140 requires certification for cybersecurity roles, but some matrix entries remain blank or "TBD," requiring Component-level guidance.

It requires industry certifications accredited by ANSI, and 225,000 positions require DoD 8140 foundational qualifications across the force. The framework includes Cyber IT, Cybersecurity, and Cyber Enablers roles alongside effects, intelligence, software, and data/AI.

IAT Level I, II, III

IAT roles align with Cyber IT and entry-level cybersecurity DCWF roles responsible for configuring and securing defense information systems.

  • IAT Level I: CompTIA A+, Network+, Security+ (common foundational options)
  • IAT Level II: Security+, CySA+, CFR for intermediate proficiency
  • IAT Level III: CompTIA SecurityX (CASP+), CISSP, ccnp security for advanced roles

Always confirm requirements against your specific DCWF work role, not legacy 8570 charts.

IAM Level I, II, III

  • IAM Level I: Entry management roles - Security+ or CAP often appear in matrices
  • IAM Level II: Mid-level roles like information systems security manager - CISSP, CISM commonly listed
  • IAM Level III: Senior security leaders over enterprise programs - CISSP concentrations, advanced GIAC certs, plus leadership credentials where specified
  • 8140 looks beyond certs: experience, training, and cybersecurity education factor into qualification

IASAE Level I, II, III

IASAE roles map to security architect, enterprise architect, and information systems security developer positions. Matrices typically include CISSP-ISSAP, CISSP-ISSEP, and advanced GIAC engineering certs. Some roles also recognize ccnp security and cloud security credentials where they map to appropriate security controls and architecture KSATs.

CSSP Roles

CSSP roles - analyst, incident responder, infrastructure support, auditor, manager - now map to specific DCWF work roles supporting internal defense actions and cyber defense operations. Common certs include Security+, CySA+, CEH, CHFI, PenTest+, and GIAC blue-team credentials. CSSP billets often require qualification within 6–12 months of assignment, and personnel must implement and validate security controls as part of residential qualification.

How to Map Your MOS or Civilian Background to an 8140 Work Role

Every covered billet must be coded with a DCWF work role ID. Here is a simple approach:

  1. Identify your position description
  2. Find its DCWF work role code through your Component's manpower system
  3. Review tasks/KSATs for that role
  4. Match them to your MOS/AFSC/rating or civilian background

A Navy IT rating or Army 25B often maps to technical support specialist or network operations roles. An Air Force 1B4/1D7 may align with cyber defense analyst. Non-technical backgrounds - intel analysts, logisticians - may map into the intelligence workforce or cyber enabler roles like program manager or cyber workforce developer. Work with your unit cybersecurity manager to confirm your billet's official coding before selecting certs.

Top 8140-Recognized Certifications for the DoD Cyber Workforce

To obtain industry certification credentials that count, verify each cert against the current qualification matrices. Common high-value options:

  • CompTIA: Security+, CySA+, PenTest+, Cloud+, SecurityX (CASP+)
  • Cisco: CCNA, CyberOps Associate, ccnp security
  • ISC2: CISSP and concentrations (ISSAP, ISSEP, ISSMP)
  • EC-Council: CEH, CHFI, CND
  • GIAC & CertNexus: GIAC blue-team/red-team/DFIR certs, CertNexus CFR

Always align your certification choice to your DCWF role and proficiency level - not just popularity.

Using GI Bill, SkillBridge, and Affiliate Training for 8140 Compliance

DoD 8140 mandates ongoing professional development for compliance, and benefit programs can fund much of it. Post-9/11 GI Bill covers approved certification exams and training programs including Security+, CySA+, CISSP, and ccnp security. Verify VA approval for each course before enrolling.

SkillBridge provides 120–180 days of transition time for active-duty personnel to complete industry training aligned to cyberspace capabilities and DCWF roles. DoD-owned courses and affiliate training programs - such as DC3 Cyber Training Academy and Service cyber schoolhouses - also count as foundational or residential qualification options under DoDM 8140.03. Prioritize programs explicitly advertising alignment to DoD 8140 or the DCWF.

What Security Leaders Need to Know About 8140 Governance

Security leaders - CISOs, ISSMs, commanders, and program managers - must inventory cyber billets, assign DCWF work role codes, and track foundational and residential qualifications. DoD 8140 standardizes training and certification processes for cyber roles, and Components may impose stricter requirements.

The directive helps with workforce planning: identifying gaps in roles like cyber defense analyst, security architect, or data analyst, and targeting recruitment dollars toward mission readiness. Around 225,000 positions will have qualification criteria under DoD 8140, making governance a strategic imperative, not just a compliance checkbox.

Frequently Asked Questions: DoD 8140 Cybersecurity and the DoD Cyber Workforce

These FAQs address common questions about dod 8140 cybersecurity compliance not fully covered above.

1. Who exactly is covered under DoD 8140?

DoD 8140 applies to all military service members, dod civilian employees, defense contractor personnel, and certain foreign nationals performing functions under DCWF cyberspace work roles. Even if a billet is not labeled "cyber," duties matching a DCWF role trigger 8140 qualification requirements.

2. How do I know which certifications count for my 8140 work role?

The authoritative source is the DoDM 8140.03 Qualification Matrices, listing approved foundational and residential qualifications by DCWF work role and proficiency level. Obtain your billet's DCWF role code and consult the latest matrices rather than relying on outdated 8570 charts.

3. What happens if a matrix block is blank or marked "TBD" for my role?

A blank block means no specific option has been identified for that proficiency level; higher-level options may satisfy the requirement. Follow your Component's supplemental guidance and consult your cyber workforce manager to determine interim training plans.

4. Is commercial experience outside the Department of Defense recognized under 8140?

Prior commercial experience can help meet role proficiency expectations and hiring criteria, but experience alone does not waive mandatory certifications listed in 8140 matrices. It may allow faster progression toward intermediate and advanced proficiency levels.

5. How often do DoD 8140 certification requirements change?

The dod cio office periodically updates qualification matrices - adding new certs, retiring outdated ones, and adjusting role definitions. Review updates at least annually and adjust your certification plans accordingly.