ClearMatch
    ← Back to field notesA grid of six framed certificates on a wall, one carrying a gold seal
    ClearMatch#govcon#cyber#certifications#dod-8140#dod-8570

    DoD 8570 and 8140: the certification baseline behind cleared cyber jobs

    How DoD 8570 terminology maps to 8140 work-role qualifications, including the 2026 contractor transition, certification options, and qualification deadlines.

    Cleared cyber job postings often combine a clearance requirement with a workforce qualification requirement. They are separate checks. The required clearance depends on the position, and a certification is one possible way to demonstrate the qualifications for cyber work.

    DoD Manual 8140.03 replaced the 8570 manual in February 2023. Contractor implementation has since changed too: May 2026 guidance directs components to ensure contract support personnel meet the qualifications for their assigned cyber work roles and to update contracts accordingly. Advice that all contractors remain under 8570 until a future acquisition-rule change is now outdated. See the official contractor implementation memo.

    Here is how to read both frameworks in job ads and confirm what applies to the seat you are considering.

    Clearance and cyber qualifications answer different questions

    A clearance eligibility determination addresses eligibility for classified information at the required level. Access still requires authorization and need-to-know. Some cyber positions require Secret, some require TS/SCI, and others do not require classified access.

    Workforce qualification addresses whether a person meets the requirements for the assigned cyber duties. Neither Security+ nor CISSP grants a clearance. Holding TS/SCI does not establish that a person meets the cyber qualification requirement or has permission to administer a particular system.

    What 8570 terminology means

    The former Information Assurance Workforce Improvement Program grouped work into categories:

    Legacy categoryWhat it describes
    IATInformation Assurance Technical, Levels I–III
    IAMInformation Assurance Management, Levels I–III
    IASAEInformation Assurance System Architect and Engineer, Levels I–III
    CSSPCybersecurity Service Provider specialties, such as analyst or incident responder

    CSSP specialties are not another three-level ladder. The old certification matrix listed approved credentials for each category and level. Security+ was one approved IAT Level II option, not a universal requirement for every technical job. CISSP appeared in several senior technical and management categories.

    An old label such as “IAT II” still helps explain a posting, but it does not by itself establish the current qualification requirement. The official 8570-to-8140 transition guide explains the structural change; its older contractor-transition language must be read alongside the 2026 implementation memo.

    A pegboard of hand tools, each in its own painted outline, with one outline left empty

    How 8140 uses work roles

    8140 uses the cyber workforce framework's specific work roles and proficiency levels. A position might be coded for Systems Administrator or Cyber Defense Analyst, for example. The role code and proficiency level determine which qualification options apply.

    There is no universal conversion from an old IAT or IAM level to a new work role. Before paying for training, obtain the actual code and level from the employer and compare them with the current matrix in the official 8140 document library.

    DoDM 8140.03 distinguishes foundational qualification from qualification in the actual operating environment. Approved education, training, or certification can satisfy the foundational requirement. An experience-based alternative depends on the applicable approval process; listing years of work on a resume does not automatically establish compliance.

    The July 2026 supplemental guidance allows components to accept a degree discipline that is substantially similar to a listed discipline when they validate its relevance to the work role. It does not make every degree acceptable. The guidance also explains how documented continuous cyber work can support the recency requirement for an older approved degree or training.

    The 2026 contractor change

    The May 27 memo reports that the acquisition class deviation took effect February 1, 2026, removing the cited legacy references and clause. It directs components to apply work-role qualification requirements to contract support and update contracts. Implementation details therefore matter: a live posting may still contain legacy terminology while the relevant contract is being updated.

    Ask the hiring manager or contract workforce lead to confirm the governing requirement in writing. Do not infer it solely from the posting's use of “8570,” “8140,” or “Security+ equivalent.”

    Four hourglasses in a row, each drained to a different level

    Qualification deadlines are not the same for everyone

    The July 2026 supplemental guidance distinguishes the populations:

    • For military and civilian workforce members, the nine-month foundational and twelve-month residential qualification timelines begin with the official Letter of Designation under the guidance.
    • Contract support personnel must meet foundational requirements when commencing cyberspace work. The military and civilian timelines are not a general grace period for contractors.

    An employer may hire someone before they can perform the covered duties, but that is different from authorizing unqualified work. Confirm what duties you can perform while obtaining a credential and when the contract requires qualification.

    Continuing professional development and role-specific qualification maintenance also apply. July guidance ties continued foundational qualification to the designated work role, proficiency level, and annual development requirements. Ask how your employer records compliance, and maintain any credential you claim under the issuer's rules.

    Choosing a certification for a target role

    Start with a shortlist of actual jobs. Record the work-role code, proficiency level, credentials accepted, and when qualification must be complete. A credential is useful when it satisfies those requirements and develops skills relevant to the work.

    Security+ may fit your target roles, but this guide does not establish that it is the right first purchase for every candidate. Likewise, CISSP is not a universal entry requirement. ISC2's CISSP requirements generally require five years of qualifying experience across at least two domains, with a possible one-year waiver. Passing the exam without the required experience can lead to Associate of ISC2 status; it does not make you a CISSP.

    What to confirm before accepting a role

    1. Which work-role code and proficiency level apply?
    2. Which current matrix and contract requirements govern the position?
    3. Does your specific credential, education, training, or approved experience satisfy the requirement?
    4. Must you qualify before starting the covered duties, and what work is available while you finish?
    5. Who verifies and records qualification and ongoing development?

    ClearMatch uses your reported skills, certifications, and clearance to help find relevant jobs. It does not certify 8140 compliance or track the government's qualification record. The hiring organization must verify both your qualifications and the position's requirements.