Back to blog
Career Advice11 min read

DoD 8140 in 2026: Which Certification Actually Qualifies You for Your Cyber Work Role?

DoD 8140 replaced the old 8570 baseline list with role based qualification, and most candidates still pick the wrong cert. Here is how to map your DCWF work role and proficiency level to a certification that actually counts in 2026.

Tom Ashford

Tom Ashford · Security Certifications Lead

26 July 2026

If you are trying to work out which DoD 8140 approved certifications will qualify you for a cyber role in 2026, the honest answer is the one nobody puts in a headline: there is no single approved list any more. DoD 8140 killed the one page chart that people spent fifteen years screenshotting. What replaced it is a matrix that maps certifications to specific work roles at specific proficiency levels, which means the correct certification for your colleague sitting two desks away may be the wrong certification for you.

That distinction costs people real money. Every year candidates pay for a certification because a recruiter said "you need IAT Level II", pass it, and then discover it does not satisfy the work role their position is actually coded for. This guide explains how DoD 8140 qualification works now, how to find the certification that maps to your work role, and which certifications give you the widest coverage if you do not yet know which role you will land in.

The short answer: your work role decides, not the certification

Under DoD 8140, qualification is driven by the DoD Cyber Workforce Framework (DCWF) code attached to your position, not by a generic tier label. Every position that performs cyber work is coded with one or more DCWF work roles, and each work role has its own qualification options at each proficiency level.

So the question is never "which certification is DoD approved". It is:

  1. What DCWF work role is my position coded for?
  2. What proficiency level (Basic, Intermediate or Advanced) does that position require?
  3. Which foundational qualification options does the current matrix accept for that role and level?

If you cannot answer question one, you cannot answer question three. Ask your supervisor, contracting officer's representative or HR for the DCWF work role code on the position description. On a contract, it should be in the labour category description or the statement of work.

Exam Tip: Do not buy a course based on a job advert that says "IAT Level II required". That phrase comes from DoD 8570.01-M, which was cancelled in 2023. It survives in job postings, contracts and HR systems as legacy shorthand. Confirm the DCWF work role code before you spend anything.

What actually changed when DoD 8140 replaced 8570

The Department of Defense signed DoD Manual 8140.03, "Cyberspace Workforce Qualification and Management Program", on 15 February 2023, and that manual cancelled DoD 8570.01-M. The programme covers roughly 225,000 military, civilian and contractor positions.

The shift is philosophical, not cosmetic. DoD 8570 was certification driven: find your tier, pick a cert off the list, done. DoD 8140 is competency driven and built on the DCWF, which itself derives from the NICE Workforce Framework for Cybersecurity (NIST SP 800-181 Rev. 1).

Three practical consequences follow from that.

A certification is now one route, not the only route. Foundational qualification can be met through education, training or certification, depending on what the matrix accepts for your role. Plenty of people qualify without sitting an exam at all.

Passing an exam no longer finishes the job. You also have to demonstrate on the job readiness, which the manual calls residential qualification, and then keep up continuous professional development.

Coverage varies wildly by certification. A certification that satisfies a dozen work roles is far more useful to a career than one that satisfies a single niche role, and the old tier chart hid that completely.

The three qualification components

ComponentWhat it meansTypical timing
Foundational qualificationEducation, training or certification accepted for your work role and proficiency levelWithin 9 months of assignment to the work role
Residential qualificationDemonstrated on the job readiness, signed off by your organisationWithin 12 months of assignment
Continuous professional developmentOngoing hours or activity to keep the qualification currentAnnually, ongoing

The 9 and 12 month clocks start when you are assigned to the work role, not when you are hired and not when you finish training. If you are moving into a coded position, work backwards from those dates when you plan your study.

How to find the certification that qualifies you

This is the process that avoids wasted exam fees. It takes about twenty minutes.

  1. Get your DCWF work role code and proficiency level. From the position description, the labour category, or your supervisor. A single position can carry more than one work role.
  2. Open the current Foundational Qualification Matrix. The DoD publishes it through the DoD Cyber Exchange. Version 2.1 carried an effective date of 19 September 2025, so check whether a newer version has superseded it before you rely on anything you read in a blog post, including this one.
  3. Find your work role row, then your proficiency level column. Basic, Intermediate and Advanced have different accepted options. An Advanced role will not accept a foundational certification.
  4. Read every accepted option, not just the certifications. If an accepted education or training route is faster and cheaper for you, take it.
  5. Check the certification is current and in good standing. An expired certification does not qualify you, and neither does one you passed but never claimed because you skipped the endorsement or experience requirement.
  6. Confirm in writing with your organisation before you pay. Say which work role, which level and which option you intend to use. Get the yes in an email.

Exam Tip: If your position carries two work roles, you need qualification for both. People routinely qualify for the headline role, miss the second one, and end up out of compliance while holding a perfectly good certification.

Which certifications cover the most DoD 8140 work roles

If you already know your role, use the matrix. If you are aiming at the DoD cyber workforce and want the certification that keeps the most doors open, breadth of coverage is the metric that matters.

CompTIA reports approval for seven of its certifications across 30 work roles under DoDM 8140.03, including Security+, CySA+, PenTest+ and SecurityX (formerly CASP+). Within that set, Security+ maps to more work roles than any other single CompTIA certification, around 20 by CompTIA's own count. On the senior side, CISSP is consistently cited as covering the widest span of oversee and govern roles across multiple workforce elements.

CertificationTypical fitWhy it earns its place
CompTIA Security+Entry to mid, cybersecurity and IT elementsThe single broadest foundational option, roughly 20 mapped work roles
CompTIA CySA+Defensive analysis, SOC and incident response rolesThe natural step up when your day job is detection and triage
CompTIA SecurityX (CAS-005)Senior technical practitioner rolesAdvanced technical depth without moving to a management credential
CompTIA PenTest+Offensive and vulnerability assessment rolesMaps to the assessment side that Security+ does not reach
ISC2 CISSPSenior, oversee and govern rolesThe widest senior coverage and the strongest civilian portability
ISACA CISMSecurity management rolesManagement framing rather than technical depth
ISACA CISAAudit, assessment and compliance rolesThe audit path the technical certs do not cover
ISC2 CGRCAuthorisation, RMF and control assessment rolesPurpose built for the RMF work the DoD runs on
EC-Council CEHProtect and defend, plus some assessment rolesLong standing DoD recognition, though check the current matrix version

Treat that table as orientation, not authority. Certifications get added and removed between matrix versions, and the version in force on the day you qualify is the only one that counts.

Which certification should you take for your track?

Assuming you have flexibility, here is how the decision usually resolves.

You are starting out, or coming from military or general IT

Take CompTIA Security+. It is the most efficient first move by a wide margin, because no other single certification opens as many mapped work roles at the foundational level, and it is recognised outside the DoD if you later move to the commercial sector. If you are also short on general IT grounding, look at whether the CompTIA trifecta makes sense before you specialise.

Note that Security+ moved to the SY0-801 objectives in 2026, so buy current material rather than whatever is discounted.

You work in a SOC, or do detection and incident response

Go CySA+ after Security+. Defensive analysis work roles are where CySA+ earns its keep, and the CS0-004 revision aligned it more tightly with the way modern SOC work is actually structured.

You are on the risk, audit or authorisation side

This is where people most often buy the wrong certification. If your work is control assessment, authorisation packages and RMF, ISC2 CGRC is built for exactly that and is frequently the better fit than a technical certification. If your work is audit proper, CISA is the one that maps.

You are moving into management or a senior oversight role

CISSP is the default, and its breadth across oversee and govern roles is the reason. CISM is the alternative when your remit is security programme management rather than broad technical governance.

One caution worth knowing before you plan a CISSP route: ISC2 cut its experience waiver list in April 2026, so a certification that used to buy you a year of the five year experience requirement may no longer do so. We covered what changed and which certifications still count separately.

You are on the offensive or assessment side

PenTest+ and, at the senior technical end, SecurityX cover ground that Security+ and CySA+ do not. CEH retains long standing DoD recognition and still appears in contract language, which sometimes decides it for you regardless of what you would otherwise choose.

Five mistakes that cost people money

Assuming the old 8570 chart still applies. It was cancelled in 2023. Many of the same certifications carried across, which is exactly why the mistake persists, but the mapping underneath them changed completely.

Buying based on job advert language. "IAT Level II" in a 2026 job posting tells you the HR template is old, not what will qualify you. Get the DCWF code.

Ignoring the proficiency level. The same work role accepts different options at Basic, Intermediate and Advanced. A certification that qualifies a Basic level position may not touch the Advanced one.

Treating the exam as the finish line. Foundational qualification is one of three components. You still need residential qualification within 12 months and ongoing continuous professional development, and neither of those is something a practice exam can do for you.

Letting a certification lapse. An expired certification is not a qualification. Track your renewal cycle and your continuing education hours from the day you pass, not from the month before expiry.

The 2026 deadlines that still matter

DoDM 8140.03 set staged implementation deadlines from its February 2023 effective date. Personnel in cybersecurity work roles were required to be qualified within two years, and personnel in the cyberspace IT, cyberspace effects, intelligence (cyberspace) and cyberspace enabler workforce elements followed within three years, landing in February 2026.

Those headline dates have now passed, which changes the nature of the pressure rather than removing it. The requirement is no longer a future project with a countdown attached, it is a live condition of employment. Anyone newly assigned to a coded work role picks up the 9 month foundational and 12 month residential clocks from the date of that assignment, and contractors bidding on cyber work are increasingly asked to evidence qualification at proposal stage rather than after award.

The practical implication for you: if you are moving into a DoD cyber position in 2026, you have roughly nine months from assignment to hold an accepted foundational qualification. An eight to twelve week study plan for the right certification fits comfortably inside that, provided you start on the right certification.

Ready to Start Practising?

Once you have confirmed the work role, the proficiency level and the certification that maps to it, the rest is exam preparation, and that part is entirely within your control.

CertCrush has full practice question banks and study material for the certifications that dominate the DoD 8140 matrix, including Security+, CySA+, PenTest+, SecurityX, CISSP, CISM, CISA and CGRC. Every question comes with a full explanation of why each option is right or wrong, because passing on the first attempt is what keeps you inside the nine month window.

Create a free CertCrush account and start practising today, or browse the full course catalogue to find the certification your work role actually needs.

DoD 8140DoD 8570DCWFSecurity+CISSPgovernment cyber jobscertification path
Tom Ashford

Written by

Tom Ashford · Security Certifications Lead

Tom spent over a decade in security operations and consulting before turning to full-time exam-prep writing. He covers the big security certifications — CISSP, CISM, CISA, Security+ and the rest of the alphabet — with a soft spot for the questions everyone gets wrong. His rule for every article: if it doesn’t help you score marks, it doesn’t go in.

All articles by Tom

Want a DoD 8140 practice course?

We don’t cover this exam yet — we build the most-requested courses first. One click tells us you want it.

Practising for something nearby?

Try real exam-style questions free — no account needed, full explanations included.