DoD 8140 Explained: Which IT Certifications Actually Qualify You for US Government Cyber Jobs
If you have ever browsed cleared job postings or defense contractor listings, you have seen the requirement lines: "IAT Level II required" or "must meet DoD 8140 requirements." For a lot of IT professionals, government and contractor work is the most stable, best-benefited corner of the industry — and certifications are literally written into the hiring rules. Here is how the system actually works.
From 8570 to 8140: what changed
For years, DoD Directive 8570 defined rigid certification baselines: IAT (technical) and IAM (management) levels I through III, each with an approved certification list. DoD 8140 — the Cyber Workforce Framework — replaced that structure with work roles based on the NIST NICE framework. Instead of "you are IAT Level II," positions are now coded to specific work roles like System Administrator, Cyber Defense Analyst, or Information Systems Security Manager, each with foundational and residential qualification options.
In practice, two things remain true. First, certifications are still the fastest and most common way to qualify — each work role has an approved cert list. Second, the old 8570 language has not died. Contractors still write "IAT II" in job postings constantly, so you need to understand both vocabularies.
The certifications that carry the most weight
CompTIA Security+ is the single most important certification in this entire ecosystem. It qualified for IAT Level II under 8570 and maps to a wide band of 8140 work roles. For anyone targeting an entry or mid-level cleared technical position, Security+ is close to mandatory. It is the default answer to "which cert gets me in the door."
CompTIA CySA+ covers analyst work roles — cyber defense analyst and incident response positions — and stacks naturally on Security+.
CISSP is the heavyweight for senior technical and management roles. It qualified for both IAT Level III and IAM Level II/III under the old scheme and maps across senior 8140 work roles. If you are aiming at ISSM, security engineering lead, or architect positions in the defense space, CISSP is the standard. One caveat we covered in detail: passing the exam is not the same as being certified — see the CISSP endorsement process explained.
CISM and CISA from ISACA cover the management and audit sides. CISM maps to security manager work roles (and note that the CISM exam content changes in November 2026), while CISA is the go-to for audit and assessment roles.
CompTIA Network+ and A+ handle the foundational infrastructure roles — useful for getting a first cleared helpdesk or network technician position, then certifying upward while employed.
A realistic path into cleared work
The most common successful sequence looks like this: Security+ first, because it unlocks the widest set of positions. Land any cleared or clearance-sponsoring role, even helpdesk — the clearance itself often matters more to your long-term earnings than the job title. Then add CySA+ or a Cisco credential for technical depth, or start the CISSP experience clock if you are heading toward senior roles. Our certification stacking guide lays out the sequencing in more detail.
Two practical warnings. Certifications must be kept current with continuing education — an expired cert can genuinely cost you a position, and our CompTIA renewal guide covers how to avoid that. And always confirm the specific work role coding with the hiring manager or contract requirements, because individual contracts can be stricter than the framework baseline.
Get exam-ready
Every certification named here is one we cover with real exam questions: CompTIA (Security+, CySA+, Network+, A+), ISC2 (CISSP), and ISACA (CISM, CISA). For a defense-career investment, the math is simple: one exam pass on the first attempt pays for itself against a $400+ retake fee.