DoD 8140 Certification List and Chart: 56 Certs by Work Role

By The Defense Compliance Report Editorial Team · Updated September 2026

The DoD 8140 certification list in Matrix V2.1 (effective Sept. 19, 2025) names 56 commercial certifications. GSEC counts in 22 of its 37 in-scope work roles, more than any other certification; Security+ counts in 19, none at Advanced, according to The Defense Compliance Report's September 2026 analysis. Below: every cert by role, plus a lookup. Source and data.

Scope: The 37 roles are in V2.1's published DoD CIO qualification scope. Of the 56 commercial certs in the workbook, 55 appear there; GCTI appears only in pending-validation roles. This is a certification reference, not a ruling that a person is fully qualified. Scope and method.

Browse the full list · Find a work role · Check your certs · Download the CSV

Key DoD 8140 certification statistics

  • 22 of 37 work roles: GSEC is listed in 22 of the 37 work roles in DoD CIO-approved workforce elements, more than any other certification (The Defense Compliance Report analysis of DoD 8140 Matrix V2.1, September 2026). Source.
  • 19 roles, none at Advanced in V2.1: Security+ is listed in 19 of those 37 work roles, every time at the Intermediate level. It has no Advanced listing in V2.1 (The Defense Compliance Report analysis of Matrix V2.1, September 2026). Source.
  • 56 certifications: The DoD 8140 Foundational Qualification Matrix Version 2.1, effective Sept. 19, 2025, lists 56 commercial certifications from 10 vendors, plus 4 Defense Acquisition Workforce Improvement Act (DAWIA) credential labels from Defense Acquisition University (DoD CIO, Matrix V2.1). Source.
  • 17 certs for CMMC assessors: 17 certifications meet the Work Role 612 bar that 32 CFR 170.11 sets for CMMC Certified Assessors (Intermediate or higher): 9 listed at Intermediate and 8 at Advanced (The Defense Compliance Report analysis of Matrix V2.1, September 2026). Source.
  • 12 down to 8 for Lead CCAs: V2.1 cut the list of Work Role 612 certs at the Advanced level, the level a Lead CCA needs, from 12 to 8 (DoD's V2.1 change log, counted by The Defense Compliance Report). Source.
  • 3 listed, 13 count: For System Administrator (451), the matrix lists 3 certifications at Basic, but 13 count at Basic once higher-level listings are included under DoD's same-role rule (The Defense Compliance Report analysis of Matrix V2.1 and DoDM 8140.03). Source.
  • 13 roles at Advanced: GSLC is listed at the Advanced level in 13 approved work roles, more than any other certification. CISSP is listed in 10, all at Advanced (The Defense Compliance Report analysis of Matrix V2.1). Source.
  • 32 of 35 old certs: 32 of the 35 certifications on the January 30, 2024 archived DoD 8570 baseline chart also appear in the September 19, 2025 V2.1 workbook. HCISPP, SCYBER, and CCNA-Security are not (The Defense Compliance Report comparison, September 2026). Source.
  • 24 absent from the 2024 chart: 24 of the 56 commercial certs in the September 19, 2025 V2.1 workbook do not appear in the January 30, 2024 archived 8570 chart (The Defense Compliance Report comparison, September 2026). This is not a count of certs never approved under 8570. Source.
  • 25 lowered, 0 raised: V2.1's certification change log shows 21 listings added, 25 moved to a lower level, and 2 removed. None moved up (DoD Matrix V2.1 change log, counted by The Defense Compliance Report). Source.
  • 19 of 56 from GIAC: GIAC has more certifications on the V2.1 list than any other vendor (The Defense Compliance Report count of the V2.1 Certification Index). Source.
  • 3 roles with no cert: 3 of the 37 approved work roles list no certification at all: 462, 731, and 901 (DoD Matrix V2.1). Source.
  • Feb. 15, 2023: DoD Manual 8140.03 took effect and canceled the DoD 8570.01-M manual (DoDM 8140.03). Source.
  • 9 and 12 months: The September 1, 2026 supplemental guidance starts the military/civilian foundational and resident qualification periods at issuance of the DoD 8140 Letter of Designation. Letter issuance is at component discretion; the 2023 manual states assignment as the start. Confirm the recorded start with the component (DoD 8140 Supplemental Guidance V1.1, pp. 4–5). Source.
  • May 27, 2026 contractor update: DoD's contractor memo directs components to ensure contract support meets the assigned DCWF work-role qualifications and to update contracts. It says deviation text removing the old 8570 references and DFARS 252.239-7001 took effect February 1, 2026. The still-visible old clause is not the whole current rule. Source.

On this page: The full list · Check your certs · Chart by work role · Higher levels count lower · Most-accepted certs · Security+ · CMMC assessors (612) · ISSM (722) · 8570 and IAT II · V2.1 changes · How it works · Contractors · Method · Cite · Download · FAQ · Sources

What certifications are on the DoD 8140 list?

The latest matrix listed in the official library on September 29, 2026, Version 2.1 (effective Sept. 19, 2025), lists 56 commercial certifications from 10 vendors, plus 4 Defense Acquisition University credentials. A certification counts only for the work roles and levels DoD lists it for. 55 of the 56 appear in at least one of the 37 work roles in V2.1's published CIO scope; GCTI appears only in roles still pending validation.

Here's how to read the table. "Approved work roles" means the 37 roles in V2.1's published CIO scope throughout this page. The count shows how many list the cert at any level. "Highest level listed" is the top level it reaches in any of them. A cert at the bottom of this table isn't worse. It's narrower.

Table 1. Every certification on the DoD 8140 list (Matrix V2.1), ranked by approved work roles
RankCertName (shortened where shown)VendorApproved work roles (of 37)Roles where listed at AdvancedHighest level listedPending-validation rolesOn Jan. 30, 2024 8570 chart?
1GSECGIAC Security Essentials CertificationGIAC220Intermediate3Yes
2Security+CompTIA Security+CompTIA190Intermediate1Yes
3SecurityX / CASP+CompTIA SecurityX (formerly CASP+)CompTIA179Advanced0Yes
4GCSAGIAC Cloud Security AutomationGIAC148Advanced1No
4CCSPCertified Cloud Security ProfessionalISC2147Advanced1Yes
4Cloud+CompTIA Cloud+CompTIA140Intermediate1Yes
7GSLCGIAC Security Leadership CertificationGIAC1313Advanced1Yes
8CISMCertified Information Security ManagerISACA1212Advanced1Yes
8SSCPSystems Security Certified PractitionerISC2122Advanced2Yes
10GICSPGlobal Industrial Cyber Security ProfessionalGIAC118Advanced1Yes
11CISSPCertified Information Systems Security ProfessionalISC21010Advanced1Yes
11CCISOCertified Chief Information Security OfficerEC-Council109Advanced1Yes
11CISSOCertified Information Systems Security OfficerMile2107Advanced1No
14CISSP-ISSEPCISSP – Engineering ProfessionalISC299Advanced1Yes
14CFRCyberSec First ResponderCertNexus97Advanced0Yes
14GFACTGIAC Foundational Cybersecurity TechnologiesGIAC96Advanced0No
14RCCE Level 1Rocheston Certified Cybersecurity Engineer Level 1Rocheston96Advanced3No
14PenTest+CompTIA PenTest+CompTIA91Advanced1Yes
14CNDCertified Network DefenderEC-Council90Intermediate1Yes
20CySA+CompTIA CySA+CompTIA87Advanced2Yes
20GCLDGIAC Cloud Security EssentialsGIAC83Advanced1No
22GCIAGIAC Certified Intrusion AnalystGIAC77Advanced0Yes
22FITSP-MFederal IT Security Professional-Manager-NGFITSI76Advanced0No
22GISFGIAC Information Security FundamentalsGIAC73Advanced1No
22CEHCertified Ethical HackerEC-Council71Advanced0Yes
26CISACertified Information Systems AuditorISACA66Advanced0Yes
26GCIHGIAC Certified Incident HandlerGIAC62Advanced3Yes
26GDSAGIAC Defensible Security ArchitectGIAC62Advanced0No
29GCFAGIAC Certified Forensic AnalystGIAC55Advanced2Yes
29FITSP-AFederal IT Security Professional-Auditor-NGFITSI53Advanced0No
29CCCertified in CybersecurityISC250Basic0No
29CGRC/CAPCertified in Governance, Risk and Compliance (formerly CAP)ISC250Intermediate0Yes
29Network+CompTIA Network+CompTIA50Basic0Yes
34CCNP SecurityCisco CCNP SecurityCisco44Advanced0Yes
34CISSP-ISSAPCISSP – Architecture ProfessionalISC244Advanced1Yes
34FITSP-DFederal IT Security Professional-Designer-NGFITSI42Advanced0No
34FITSP-OFederal IT Security Professional-Operator-NGFITSI42Advanced1No
34GCEDGIAC Certified Enterprise DefenderGIAC41Advanced0Yes
34CSSLPCertified Secure Software Lifecycle ProfessionalISC240Intermediate1Yes
34GMONGIAC Continuous MonitoringGIAC40Intermediate0No
41CISSP-ISSMPCISSP – Management ProfessionalISC233Advanced0Yes
41GCFEGIAC Certified Forensic ExaminerGIAC33Advanced0No
41GSNAGIAC Systems and Network AuditorGIAC32Advanced1Yes
41A+CompTIA A+CompTIA30Basic0Yes
41CEH(P)Certified Ethical Hacker (Practical)EC-Council30Intermediate0No
41CHFIComputer Hacking Forensics InvestigatorEC-Council30Intermediate0Yes
41GRIDGIAC Response and Industrial DefenseGIAC30Intermediate0No
48CBROPSCisco CyberOps AssociateCisco21Advanced0Yes
48CSCCyber Secure CoderCertNexus20Intermediate0No
50CCNACisco Certified Network AssociateCisco11Advanced0No
50CCNP EnterpriseCisco CCNP EnterpriseCisco11Advanced0No
50GPENGIAC Penetration TesterGIAC11Advanced4No
50GREMGIAC Reverse Engineering MalwareGIAC11Advanced0No
50CPTECertified Penetration Testing EngineerMile210Intermediate0No
50ECIHCertified Incident HandlerEC-Council10Intermediate0No
56GCTIGIAC Cyber Threat IntelligenceGIAC00—4No

Source: DoD 8140 Foundational Qualification Matrix V2.1, effective Sept. 19, 2025, Certification Repository and Certification Index sheets; counts by The Defense Compliance Report, checked Sept. 29, 2026. "Pending-validation roles" are roles in elements the workbook marks Tentative. 8570 comparison: DoD Approved 8570 Baseline Certifications (archived).

The matrix also lists four DAWIA credentials. They come from the Defense Acquisition Workforce program, not a commercial exam, so we keep them out of the 56.

Table 2. DAWIA credentials on the DoD 8140 list (Matrix V2.1)
DAWIA credential (Defense Acquisition University)Approved work rolesLevel listed
DAWIA PM Advanced801 Program Manager, 802 IT Project ManagerAdvanced
DAWIA PM Practitioner801 Program Manager, 802 IT Project ManagerIntermediate
DAWIA LCL Advanced803 Product Support ManagerAdvanced
DAWIA LCL Foundational803 Product Support ManagerIntermediate

Source: DoD 8140 Foundational Qualification Matrix V2.1, Certification Repository sheet; checked Sept. 29, 2026.

GSEC counts in more DoD 8140 work roles than any other certificationBar chart: GSEC is listed in 22 of 37 approved DoD 8140 work roles, Security+ in 19, SecurityX in 17, and CISSP in 10. All 10 CISSP listings are at Advanced; the GSEC and Security+ listings are at Intermediate.GSEC counts in more DoD 8140 work roles than any other certificationEach role counted once at its highest listed level for that certification.Listed at AdvancedListed at IntermediateListed at Basic0510152025GSEC22Security+19SecurityX / CASP+17GCSA14CCSP14Cloud+14GSLC13CISM12SSCP12GICSP11CISSP10CCISO10CISSO10Approved DoD 8140 work roles where the cert is listed (of 37)Source: The Defense Compliance Report analysis of the DoD 8140 Foundational Qualification Matrix V2.1 (effective Sept. 19, 2025), checked Sept. 29, 2026.Certs listed in 10 or more of the 37 work roles in DoD CIO-approved workforce elements. Each role counted once, at its listed level.
Bar chart: GSEC is listed in 22 of 37 approved DoD 8140 work roles, Security+ in 19, SecurityX in 17, and CISSP in 10. All 10 CISSP listings are at Advanced; the GSEC and Security+ listings are at Intermediate.Download chart as PNG

Which DoD 8140 work roles does my certification cover?

Pick the certifications you hold, and the lookup shows every approved work role they count for and the highest level they reach. Security+ alone counts in 19 roles, up to Intermediate. Add CySA+ and you reach 22 roles, 7 of them at Advanced.

You can also flip it. Pick a work role and a level, and you get every certification that counts there. Results say whether a cert is listed at that exact level or counts because it's listed higher in the same role.

One warning before you use it. "No match here" means this V2.1 extract has no match for that cert, role, and level. It doesn't mean you're disqualified. Degrees and training can also qualify you, and your cyber workforce manager makes the final call.

Explore certification listings by credential or work role

Compare the dated Matrix V2.1 certification path in this browser using public static CSVs. No account, form, or email is requested. Search terms and selections stay in this browser; they are not saved or sent, and no personal data is collected. A listing is only one foundational qualification option; it does not establish full qualification.

Loading certification lookup…

DoD 8140 chart: which certifications count for each work role?

Each of the 37 approved work roles has its own list at Basic, Intermediate, and Advanced. 34 roles list at least one certification; 462 Control Systems Security Specialist, 731 Cyber Legal Advisor, and 901 Executive Cyber Leader list none. A certification listed at a higher level also counts at the lower levels of the same role.

To use the chart, find your role code and read across. The first three list columns show what DoD printed at each level. The last column counts the listed credentials, including DAWIA labels where shown, once higher listings roll down. It covers only the foundational certification option, not full qualification.

Cybersecurity work roles (13)

Table 3a. DoD 8140 certification chart: cybersecurity work roles (Matrix V2.1)
CodeWork roleListed at BasicListed at IntermediateListed at AdvancedCredentials that count at Basic / Int. / Adv.
212Cyber Defense Forensics Analyst—CHFI, RCCE Level 1CFR, CySA+, GCFA, GCFE, GREM, PenTest+8 / 8 / 6
462Control Systems Security Specialist———0 / 0 / 0
511Cyber Defense AnalystCC, CEH, GFACT, GISFCEH(P), Cloud+, FITSP-O, GCED, GDSA, GMON, GRID, GSEC, PenTest+, Security+CBROPS, CFR, CySA+, GCFA, GCIA, GICSP20 / 16 / 6
521Cyber Defense Infrastructure Support SpecialistA+, CC, CND, GCLD, GDSA, GFACT, Network+CEH, Cloud+, CySA+, GMON, GRID, GSEC, PenTest+, Security+, SSCPCISSP-ISSAP, CISSP-ISSEP, GCIA, GICSP20 / 13 / 4
531Cyber Defense Incident ResponderCC, GDSA, GISFCBROPS, CCSP, CEH, CEH(P), Cloud+, ECIH, FITSP-O, GCED, GCIH, GRID, GSEC, PenTest+, RCCE Level 1, Security+CFR, CySA+, GCFA, GCIA, GICSP22 / 19 / 5
541Vulnerability Assessment AnalystCEHCEH(P), Cloud+, CPTE, FITSP-A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, RCCE Level 1, Security+CFR, CISA, CISM, CySA+, GPEN, GSNA19 / 18 / 6
611Authorizing Official/Designated Representative—CCSP, CGRC/CAP, Cloud+, GSECCCISO, CISM, CISSP, CISSP-ISSEP, CISSP-ISSMP, FITSP-M, GCSA, GSLC12 / 12 / 8
612Security Control Assessor—CGRC/CAP, CISSO, Cloud+, FITSP-A, GCSA, GSEC, PenTest+, Security+, SecurityX / CASP+CCISO, CISA, CISM, CISSP, CISSP-ISSEP, CySA+, GSLC, GSNA17 / 17 / 8
622Secure Software AssessorGCLDCSC, CSSLP, GCSA, GSEC, Security+CISSP-ISSEP7 / 6 / 1
631Information Systems Security DeveloperCC, CND, GISF, SSCPCCSP, Cloud+, CSC, GCLD, GCSA, GSEC, SecurityX / CASP+CISSP-ISSEP, FITSP-D13 / 9 / 2
652Security ArchitectGCLD, GISFCCSP, CISSO, Cloud+, CSSLP, FITSP-D, GCSA, GMON, GSEC, SecurityX / CASP+CCNP Enterprise, CISM, CISSP-ISSAP, CISSP-ISSEP, GCIA, GDSA, GICSP18 / 16 / 7
722Information Systems Security ManagerCCCCISO, CCSP, CGRC/CAP, CISSO, Cloud+, GCSA, GMON, GSEC, Security+, SecurityX / CASP+, SSCPCISM, CISSP, CISSP-ISSMP, FITSP-M, GCIA, GCIH, GICSP, GSLC20 / 19 / 8
723COMSEC Manager—GSECCISM, CISSO, FITSP-M, GCIH, GCSA, GICSP, GSLC8 / 8 / 7

Source: DoD 8140 Foundational Qualification Matrix V2.1, Certification Repository and Matrix Outline & Notes sheets; last column calculated by The Defense Compliance Report under DoDM 8140.03 section 3.2.b(1)(c)5.a; checked Sept. 29, 2026.

Cyber IT work roles (10)

Table 3b. DoD 8140 certification chart: cyber IT work roles (Matrix V2.1)
CodeWork roleListed at BasicListed at IntermediateListed at AdvancedCredentials that count at Basic / Int. / Adv.
411Technical Support SpecialistA+, Network+CND, GFACT, GSEC, Security+CCNP Security, CISA, FITSP-O, GICSP, SecurityX / CASP+, SSCP12 / 10 / 6
421Database Administrator—Cloud+, GSEC, Security+, SSCPCCNP Security, CISA, CISSP, CISSP-ISSAP, CISSP-ISSEP, SecurityX / CASP+10 / 10 / 6
431Knowledge Manager—Security+, SSCP—2 / 2 / 0
441Network Operations SpecialistCND, Network+CEH, Cloud+, GCIH, GICSP, GSEC, Security+, SSCPCCNA, CCNP Security, CCSP, GCED, GCIA, GCLD, GDSA, GFACT, SecurityX / CASP+18 / 16 / 9
451System AdministratorA+, CND, Network+Cloud+, GICSP, GSEC, Security+, SSCPCCNP Security, CCSP, FITSP-O, GFACT, SecurityX / CASP+13 / 10 / 5
632Systems DeveloperCNDCSSLP, GCLD, GSECFITSP-D, GCSA, GISF, SSCP8 / 7 / 4
641Systems Requirements PlannerCNDCCSP, CFR, FITSP-M, GSEC, Security+, SSCPGCSA, GSLC, SecurityX / CASP+10 / 9 / 3
651Enterprise ArchitectCNDCCSP, Cloud+, CSSLP, FITSP-D, GDSA, GSEC, SecurityX / CASP+CISSO, CISSP-ISSAP, CISSP-ISSEP, GCIA, GCLD, GCSA, GICSP15 / 14 / 7
661Research & Development Specialist—Security+CEH, GCLD, RCCE Level 1, SecurityX / CASP+5 / 5 / 4
671System Testing and Evaluation SpecialistCND, Network+CEH, CFR, Cloud+, GSEC, PenTest+, Security+, SSCPCCSP10 / 8 / 1

Source: official V2.1 workbook, Certification Repository and Matrix Outline & Notes; same-role rule in DoDM 8140.03. Checked Sept. 29, 2026.

Cyber enabler work roles (14)

Table 3c. DoD 8140 certification chart: cyber enabler work roles (Matrix V2.1)
CodeWork roleListed at BasicListed at IntermediateListed at AdvancedCredentials that count at Basic / Int. / Adv.
211Forensics Analyst—CHFI, PenTest+CFR, CySA+, GCFA, GCFE, RCCE Level 17 / 7 / 5
221Cyber Crime InvestigatorGCIHCHFI, PenTest+CFR, CySA+, GCFA, GCFE, SecurityX / CASP+8 / 7 / 5
711Cyber Instructional Curriculum Developer—GSEC—1 / 1 / 0
712Cyber Instructor——CISSO1 / 1 / 1
731Cyber Legal Advisor———0 / 0 / 0
732Privacy Compliance Manager——CISSO, GSLC2 / 2 / 2
751Cyber Workforce Developer and Manager—Security+CCISO, CCSP, CFR, CISM, CISSP, GSLC, SecurityX / CASP+8 / 8 / 7
752Cyber Policy and Strategy Planner—Security+CCISO, CCSP, CISM, CISSO, CISSP, GSLC, SecurityX / CASP+8 / 8 / 7
801Program Manager—CGRC/CAP, DAWIA PM Practioner, SecurityX / CASP+CCISO, CISM, CISSO, CISSP, DAWIA PM Advanced, GFACT, GSLC, RCCE Level 111 / 11 / 8
802IT Project Manager—DAWIA PM Practioner, GSEC, Security+, SecurityX / CASP+CCISO, CCSP, CISA, CISM, CISSP, CISSP-ISSEP, CISSP-ISSMP, DAWIA PM Advanced, FITSP-A, FITSP-M, GFACT, GSLC, RCCE Level 117 / 17 / 13
803Product Support Manager—DAWIA LCL FoundationalCCISO, DAWIA LCL Advanced, GCSA, GFACT, GISF, GSLC, RCCE Level 18 / 8 / 7
804IT Investment/Portfolio Manager——CCISO, CISM, CISSO, CISSP, FITSP-A, FITSP-M, GCSA, GFACT, GSLC9 / 9 / 9
805IT Program Auditor—CGRC/CAP, GSEC, GSNA, Security+, SecurityX / CASP+, SSCPCCISO, CCSP, CISA, CISM, CISSP, FITSP-A, FITSP-M, GCSA, GISF, GSLC, RCCE Level 117 / 17 / 11
901Executive Cyber Leader———0 / 0 / 0

Source: official V2.1 workbook, Certification Repository and Matrix Outline & Notes; same-role rule in DoDM 8140.03. Checked Sept. 29, 2026.

Enabler roles have an extra door. DoD's 40-hour Cyber 101 course satisfies foundational qualification for cyber enabler work roles at all three levels, according to the V2.1 matrix notes. That's why 731 and 901 can have no certification listed and still have a path.

Work roles still pending DoD validation

The workbook lists 74 work roles in all. The other 37 sit in four elements the workbook marks "Tentative": cyber effects, intelligence (cyber), data/AI, and software engineering. Other offices own those elements. Eleven of those roles have certification rows outside this release's published CIO scope. They are pending-validation records in this workbook, not qualification rules for those elements. Use the responsible office's current guidance for those roles.

Table 3d. Certifications listed for pending-validation work roles (Matrix V2.1)
CodeWork roleElementOwnerCerts listed (pending validation)
111All-Source AnalystIntel (Cyber)OUSD(I&S)Advanced: CySA+, GCTI, RCCE Level 1
121Exploitation AnalystCyber EffectsPCA/USCYBERCOMAdvanced: GCIH, GPEN, PenTest+
131Joint Targeting AnalystCyber EffectsPCA/USCYBERCOMAdvanced: GPEN
132Target Digital Network AnalystCyber EffectsPCA/USCYBERCOMAdvanced: GCIH, GPEN
311All-Source Collection ManagerIntel (Cyber)OUSD(I&S)Advanced: GCFA, GCTI
312All-Source Collection Requirements ManagerIntel (Cyber)OUSD(I&S)Advanced: GCFA, GCTI
331Cyber Intelligence PlannerIntel (Cyber)OUSD(I&S)Advanced: GCTI
332Cyber Operations PlannerCyber EffectsPCA/USCYBERCOMAdvanced: GCIH, GPEN, RCCE Level 1
422Data AnalystData/AICDAOIntermediate: GSEC, SSCP; Advanced: CCISO, CISM, CISSP, GSLC
461Systems Security AnalystSoftware EngineeringOUSD(R&E)Basic: CND, SSCP; Intermediate: CCSP, Cloud+, GICSP, GISF, GSEC, Security+; Advanced: CISSO, CISSP-ISSEP, CySA+, FITSP-O, GCLD, GCSA, GSNA, RCCE Level 1
621Software DeveloperSoftware EngineeringOUSD(R&E)Intermediate: CSSLP, GSEC; Advanced: CISSP-ISSAP

Source: DoD 8140 Foundational Qualification Matrix V2.1, Certification Repository and the V2.1 scope statement (records outside the published CIO scope); checked Sept. 29, 2026.

Does a higher-level certification count at Basic or Intermediate?

Yes, inside the same work role. DoD Manual 8140.03 says certifications approved at a higher level also apply to lower levels within the work role. So for System Administrator (451), the matrix lists 3 certifications at Basic, but 13 count at Basic.

Reading only the Basic box misses the higher-level options. You see three names, but that is not the whole Basic list. But every cert in the Intermediate and Advanced boxes counts at Basic too.

Here's the math for 451. Basic: 3 listed at Basic + 5 at Intermediate + 5 at Advanced = 13. Intermediate: 5 + 5 = 10. Advanced: 5.

Table 4. System Administrator (451): certifications that count at each level
Level the position needsListed at BasicListed at IntermediateListed at AdvancedCerts that count
Basic35513
Intermediate05510
Advanced0055

Source: DoD 8140 Foundational Qualification Matrix V2.1, Certification Repository sheet; rule from DoDM 8140.03, section 3.2.b(1)(c)5.a; calculated by The Defense Compliance Report, checked Sept. 29, 2026.

Say your position is coded 451 at Basic and you hold CCSP. DoD lists CCSP at Advanced for 451, so it counts for your Basic position.

The rule never jumps roles, though. A cert listed for 451 says nothing about 511 or any other role. Across all 37 approved roles, the 384 listings DoD printed become 920 level matches once they roll down. The extra 536 aren't new approvals. They're the same approvals, read the way the manual says to read them.

System Administrator (451): 3 certs are listed at Basic, but 13 countGrouped bar chart: at Basic, 3 certifications are listed and 13 count. At Intermediate, 5 are listed and 10 count. At Advanced, 5 are listed and 5 count.System Administrator (451): 3 certs are listed at Basic, but 13 countListed at this levelCounted at this level02468101214Basic313Intermediate510Advanced55Certifications listed versus certifications that count at each levelSource: The Defense Compliance Report analysis of the DoD 8140 Foundational Qualification Matrix V2.1 (effective Sept. 19, 2025), checked Sept. 29, 2026.Rule: a cert approved at a higher level also counts at lower levels in the same work role (DoDM 8140.03, section 3.2.b(1)(c)5.a).
Grouped bar chart: at Basic, 3 certifications are listed and 13 count. At Intermediate, 5 are listed and 10 count. At Advanced, 5 are listed and 5 count.Download chart as PNG

Which certification counts in the most DoD 8140 work roles?

GSEC does. It's listed in 22 of the 37 approved work roles, all at Intermediate. Security+ is next at 19, then SecurityX (formerly CASP+) at 17, which is listed at Advanced in 9 of its roles. For Advanced-level listings, GSLC leads with 13 roles and CISM follows with 12.

GSEC has three more listed roles than Security+ in this V2.1 scope. That is a count of listings, not a claim about more jobs or a better certification.

Table 5. Certifications listed in 10 or more approved DoD 8140 work roles
CertApproved work roles (of 37)Listed at AdvancedListed at IntermediateListed at Basic
GSEC220220
Security+190190
SecurityX / CASP+17980
GCSA14860
CCSP14770
Cloud+140140
GSLC131300
CISM121200
SSCP12291
GICSP11830
CISSP101000
CCISO10910
CISSO10730

Source: DoD 8140 Foundational Qualification Matrix V2.1, Certification Repository sheet; counts by The Defense Compliance Report, checked Sept. 29, 2026. Each role counted once, at its listed level.

GSEC and Security+ don't cover the same roles, either. They overlap in 15 roles. GSEC reaches 7 roles Security+ doesn't, and Security+ reaches 4 that GSEC doesn't.

Table 6. Where GSEC and Security+ differ (approved work roles, Matrix V2.1)
Only GSEC counts (7 roles)Only Security+ counts (4 roles)
611 Authorizing Official/Designated Representative431 Knowledge Manager
631 Information Systems Security Developer661 Research & Development Specialist
632 Systems Developer751 Cyber Workforce Developer and Manager
651 Enterprise Architect752 Cyber Policy and Strategy Planner
652 Security Architect
711 Cyber Instructional Curriculum Developer
723 COMSEC Manager

Source: DoD 8140 Foundational Qualification Matrix V2.1; comparison by The Defense Compliance Report, checked Sept. 29, 2026.

These counts measure how many roles list a cert. They don't measure salary, job openings, or how good a cert is. A narrow cert can be exactly right for your role.

Which vendors have the most certs on the list?

GIAC has 19 of the 56 commercial certifications, about 1 in 3. ISC2 has 9 and CompTIA has 7.

Table 7. Certifications on the DoD 8140 V2.1 list, by vendor
VendorCerts on the V2.1 list
GIAC19
ISC29
CompTIA7
EC-Council6
Cisco4
FITSI4
CertNexus2
ISACA2
Mile22
Rocheston1
Total56

Source: DoD 8140 Foundational Qualification Matrix V2.1, Certification Index sheet; count by The Defense Compliance Report, checked Sept. 29, 2026.

Is Security+ enough for DoD 8140?

For 19 roles, it meets the listed foundational certification option up to Intermediate—not every qualification requirement. Security+ is listed in 19 of the 37 approved work roles, always at Intermediate, so it also covers Basic in those roles. It has no Advanced listing in V2.1.

Table 8. The 19 approved work roles that list Security+ (Matrix V2.1)
CodeWork roleElementSecurity+ listed at
411Technical Support SpecialistCyber ITIntermediate
421Database AdministratorCyber ITIntermediate
431Knowledge ManagerCyber ITIntermediate
441Network Operations SpecialistCyber ITIntermediate
451System AdministratorCyber ITIntermediate
511Cyber Defense AnalystCybersecurityIntermediate
521Cyber Defense Infrastructure Support SpecialistCybersecurityIntermediate
531Cyber Defense Incident ResponderCybersecurityIntermediate
541Vulnerability Assessment AnalystCybersecurityIntermediate
612Security Control AssessorCybersecurityIntermediate
622Secure Software AssessorCybersecurityIntermediate
641Systems Requirements PlannerCyber ITIntermediate
661Research & Development SpecialistCyber ITIntermediate
671System Testing and Evaluation SpecialistCyber ITIntermediate
722Information Systems Security ManagerCybersecurityIntermediate
751Cyber Workforce Developer and ManagerCyber EnablersIntermediate
752Cyber Policy and Strategy PlannerCyber EnablersIntermediate
802IT Project ManagerCyber EnablersIntermediate
805IT Program AuditorCyber EnablersIntermediate

Source: DoD 8140 Foundational Qualification Matrix V2.1, Certification Repository sheet; checked Sept. 29, 2026.

Say your position is Cyber Defense Analyst (511) at Advanced. Security+ won't cover it. The Advanced list for 511 is CBROPS, CFR, CySA+, GCFA, GCIA, GICSP.

Which DoD 8140 certifications meet the CMMC assessor requirement for Work Role 612?

17 do. The CMMC rule requires a CMMC Certified Assessor (CCA) to hold at least one qualification at the Intermediate level or higher for Security Control Assessor (612), and V2.1 lists 9 certifications at Intermediate and 8 at Advanced for that role. A Lead CCA needs Advanced, which leaves 8.

The rule is 32 CFR 170.11(b)(6) and (b)(10). It points straight at the DoD 8140 framework, which is why this table matters to anyone chasing a CMMC assessor credential.

Table 9. Certifications listed for Security Control Assessor (612), Matrix V2.1
Listed level for Work Role 612CertsCount
IntermediateCGRC/CAP, CISSO, Cloud+, FITSP-A, GCSA, GSEC, PenTest+, Security+, SecurityX / CASP+9
AdvancedCCISO, CISA, CISM, CISSP, CISSP-ISSEP, CySA+, GSLC, GSNA8

Source: DoD 8140 Foundational Qualification Matrix V2.1, Certification Repository sheet; CCA and Lead CCA levels from 32 CFR 170.11 (eCFR, current to Sept. 25, 2026); checked Sept. 29, 2026.

V2.1 changed this list. It moved CISSO, FITSP-A, and GCSA from Advanced down to Intermediate for 612, and it removed CPTE from 612. So the Advanced list, the one a Lead CCA needs, went from 12 certifications to 8. The CCA list (Intermediate or higher) went from 18 to 17.

A match here covers one gate, not the whole credential. A CCA also needs an active CCP, at least 3 years of cybersecurity experience, at least 1 year of assessment or audit experience, the required training and exam, and a favorable Tier 3 determination (or a DoD-approved equivalent when Tier 3 is not available to that candidate). Tier 3 does not grant a security clearance. Our guide on how to become a CMMC assessor (CCA) walks through the other gates. ISACA's CCA page lists an active CCP, the required CCA course, and an 8140 certification as exam-registration prerequisites; confirm your credential there before you pay.

What certifications does an ISSM need under DoD 8140?

For Information Systems Security Manager (722), V2.1 lists 20 certifications: 1 at Basic, 11 at Intermediate, and 8 at Advanced. Once higher listings roll down, 20 count at Basic, 19 at Intermediate, and 8 at Advanced.

Table 10. Certifications listed for Information Systems Security Manager (722), Matrix V2.1
Listed level for Work Role 722CertsCount
BasicCC1
IntermediateCCISO, CCSP, CGRC/CAP, CISSO, Cloud+, GCSA, GMON, GSEC, Security+, SecurityX / CASP+, SSCP11
AdvancedCISM, CISSP, CISSP-ISSMP, FITSP-M, GCIA, GCIH, GICSP, GSLC8

Source: DoD 8140 Foundational Qualification Matrix V2.1, Certification Repository sheet; checked Sept. 29, 2026.

Notice that CISSP and CISM sit in the Advanced row. If your ISSM position is coded Intermediate, Security+ or GSEC also counts.

What happened to the DoD 8570 chart and IAT Level II?

DoD Manual 8140.03 took effect Feb. 15, 2023, and canceled the 8570 manual. Of the 35 certifications on the January 30, 2024 archived 8570 baseline chart, 32 also appear in the V2.1 workbook, some under new names. HCISPP, SCYBER, and CCNA-Security are not.

The big change isn't the cert names. It's the boxes. The 8570 chart sorted people into categories like IAT Level II and IAM Level I. The V2.1 workbook registers 74 work roles and uses Basic, Intermediate, and Advanced levels. That is the register in this release, not a count of every current DCWF role. So "8140 IAT Level II" isn't a real thing. The question is always: which work role code, at which level?

Many charts shared online still show the old IAT and IAM boxes with an 8140 label on top. An IAT or IAM table describes the legacy system; it is not the current work-role matrix.

Table 11. What happened to the old IAT Level II certifications
Old IAT Level II certStill on the 8140 list?8140 approved work roles
CCNA-SecurityNo—
CySA+Yes8
GICSPYes11
GSECYes22
Security+ CEYes19
CNDYes9
SSCPYes12

Source: DoD Approved 8570 Baseline Certifications (archived page); DoD 8140 Matrix V2.1; comparison by The Defense Compliance Report, checked Sept. 29, 2026.

Table 12. Every certification on the old 8570 chart, and where it stands in 8140 V2.1
Cert on the old 8570 chart8570 categoriesOn V2.1?V2.1 labelV2.1 approved work rolesNote
A+ CEIAT IYesA+3
Network+ CEIAT IYesNetwork+5
SSCPIAT I, IAT II, CSSP Infrastructure SupportYesSSCP12
CNDIAT I, IAT II, IAM I, CSSP Infrastructure SupportYesCND9
CCNA-SecurityIAT I, IAT II, CSSP Analyst, CSSP Incident ResponderNo——Not on V2.1. Cisco retired it; plain CCNA is on V2.1 for 1 role (441).
CySA+IAT II, CSSP Analyst, CSSP Infrastructure Support, CSSP Incident Responder, CSSP AuditorYesCySA+8
GICSPIAT II, CSSP Analyst, CSSP Infrastructure SupportYesGICSP11
GSECIAT IIYesGSEC22
Security+ CEIAT II, IAM IYesSecurity+19
CASP+ CEIAT III, IAM II, IASAE I, IASAE IIYesSecurityX / CASP+17Renamed SecurityX
CCNP SecurityIAT IIIYesCCNP Security4
CISAIAT III, CSSP AuditorYesCISA6
CISSP (or Associate)IAT III, IAM II, IAM III, IASAE I, IASAE IIYesCISSP10V2.1 lists CISSP; the name comparison does not establish acceptance of Associate status
GCEDIAT IIIYesGCED4
GCIHIAT III, CSSP Analyst, CSSP Incident ResponderYesGCIH6
CCSPIAT III, IASAE IIIYesCCSP14
CAPIAM I, IAM IIYesCGRC/CAP5Renamed CGRC
Cloud+IAM I, CSSP Analyst, CSSP Infrastructure SupportYesCloud+14
GSLCIAM I, IAM II, IAM IIIYesGSLC13
HCISPPIAM I, IAM IINo——Not on V2.1.
CISMIAM II, IAM III, CSSP ManagerYesCISM12
CCISOIAM II, IAM III, CSSP ManagerYesCCISO10
CSSLPIASAE I, IASAE IIYesCSSLP4
CISSP-ISSAPIASAE IIIYesCISSP-ISSAP4
CISSP-ISSEPIASAE IIIYesCISSP-ISSEP9
CEHCSSP Analyst, CSSP Infrastructure Support, CSSP Incident Responder, CSSP AuditorYesCEH7
CFRCSSP Analyst, CSSP Infrastructure Support, CSSP Incident Responder, CSSP AuditorYesCFR9
CCNA Cyber OpsCSSP Analyst, CSSP Incident ResponderYesCBROPS2Renamed CyberOps Associate
GCIACSSP AnalystYesGCIA7
SCYBERCSSP Analyst, CSSP Incident ResponderNo——Not on V2.1.
PenTest+CSSP Analyst, CSSP Incident Responder, CSSP AuditorYesPenTest+9
CHFICSSP Infrastructure Support, CSSP Incident ResponderYesCHFI3
GCFACSSP Incident ResponderYesGCFA5
GSNACSSP AuditorYesGSNA3
CISSP-ISSMPCSSP ManagerYesCISSP-ISSMP3

Source: January 30, 2024 archived DoD chart and V2.1 workbook, checked Sept. 29, 2026. We matched renamed certs to their current labels: CASP+ to SecurityX, CAP to CGRC, and CCNA Cyber Ops to CyberOps Associate.

The two snapshots differ in another way. 24 of V2.1's 56 commercial certifications are absent from the January 30, 2024 archived 8570 chart: CC, CCNA, CCNP Enterprise, CEH(P), CISSO, CPTE, CSC, ECIH, FITSP-A, FITSP-D, FITSP-M, FITSP-O, GCFE, GCLD, GCSA, GCTI, GDSA, GFACT, GISF, GMON, GPEN, GREM, GRID, RCCE Level 1.

That does not make all 24 new to 8140. The archived DoD page says GISF had been on the 8570 approved list and was removed on January 25, 2013. The comparison above tests names in two dated snapshots, not every past approval. Matching a name also does not convert an old category or an Associate status into a current qualification. Archived source.

What changed in DoD 8140 matrix Version 2.1?

V2.1 took effect Sept. 19, 2025. Its certification change log has 60 entries: 21 listings added, 25 moved to a lower level, 2 removed, 9 unchanged, and 3 not evaluated. No listing moved up.

"Moved to a lower level" means DoD now lists that cert for a lower level in that one role. For example, GCSA for Security Control Assessor (612) went from Advanced to Intermediate. It remains listed for 612 at Intermediate. It no longer appears as a new Advanced option in V2.1; documented qualification under an earlier matrix is a separate question.

The most-added cert was ISC2's Certified in Cybersecurity (CC). It gained Basic listings in 5 roles. The earlier Matrix 2.0 (effective March 25, 2025) changed training content only; DoD said it made no updates to certifications.

This table shows the V2.1 list, not an individual's status. The September 2026 guidance preserves a documented foundational baseline while the member stays in the same role and level and meets annual professional-development requirements. A role or level change, or failure to meet those annual requirements, triggers qualification against the current matrix. Required upskilling still applies.

Table 13. DoD 8140 V2.1 certification change log, by type
Entry type in the V2.1 certification change logEntries
Added21
Level lowered25
Removed2
Level raised0
No change9
Not evaluated3
Total entries60

Source: DoD 8140 Foundational Qualification Matrix V2.1, Certification Change Log V2.1 sheet; counted by The Defense Compliance Report, checked Sept. 29, 2026.

DoD 8140 V2.1 lowered 25 certification listings and raised noneBar chart: the DoD 8140 V2.1 change log added 21 certification listings, lowered 25, removed 2, and raised none.DoD 8140 V2.1 lowered 25 certification listings and raised none051015202530Cert–work role listings21Added25Level lowered2Removed0Level raisedChange typeThe log also lists 9 unchanged entries and 3 not evaluated (60 entries in all).Source: DoD 8140 Foundational Qualification Matrix V2.1, Certification Change Log V2.1(effective Sept. 19, 2025); counted by The Defense Compliance Report, Sept. 29, 2026.
Bar chart: the DoD 8140 V2.1 change log added 21 certification listings, lowered 25, removed 2, and raised none.Download chart as PNG
Table 14. Every changed listing in DoD 8140 V2.1 (48 entries)
CodeWork roleCertV2.0 levelV2.1 levelChange
212Cyber Defense Forensics AnalystGREMNot listedAdvancedAdded
212Cyber Defense Forensics AnalystRCCE Level 1Not listedIntermediateAdded
511Cyber Defense AnalystCCNot listedBasicAdded
511Cyber Defense AnalystCEH(P)Not listedIntermediateAdded
511Cyber Defense AnalystFITSP-OAdvancedIntermediateLevel lowered
511Cyber Defense AnalystGDSAAdvancedIntermediateLevel lowered
511Cyber Defense AnalystGFACTIntermediateBasicLevel lowered
511Cyber Defense AnalystGISFIntermediateBasicLevel lowered
511Cyber Defense AnalystGMONNot listedIntermediateAdded
511Cyber Defense AnalystGRIDNot listedIntermediateAdded
521Cyber Defense Infrastructure Support SpecialistCCNot listedBasicAdded
521Cyber Defense Infrastructure Support SpecialistGCLDAdvancedBasicLevel lowered
521Cyber Defense Infrastructure Support SpecialistGDSAAdvancedBasicLevel lowered
521Cyber Defense Infrastructure Support SpecialistGFACTIntermediateBasicLevel lowered
521Cyber Defense Infrastructure Support SpecialistGMONNot listedIntermediateAdded
521Cyber Defense Infrastructure Support SpecialistGRIDNot listedIntermediateAdded
531Cyber Defense Incident ResponderCCNot listedBasicAdded
531Cyber Defense Incident ResponderCEH(P)Not listedIntermediateAdded
531Cyber Defense Incident ResponderECIHNot listedIntermediateAdded
531Cyber Defense Incident ResponderGDSAAdvancedBasicLevel lowered
531Cyber Defense Incident ResponderGISFIntermediateBasicLevel lowered
531Cyber Defense Incident ResponderGRIDNot listedIntermediateAdded
531Cyber Defense Incident ResponderRCCE Level 1Not listedIntermediateAdded
541Vulnerability Assessment AnalystCEH(P)Not listedIntermediateAdded
541Vulnerability Assessment AnalystCISSOAdvancedNot listedRemoved
541Vulnerability Assessment AnalystCPTEAdvancedIntermediateLevel lowered
541Vulnerability Assessment AnalystFITSP-AAdvancedIntermediateLevel lowered
541Vulnerability Assessment AnalystGCSAAdvancedIntermediateLevel lowered
541Vulnerability Assessment AnalystRCCE Level 1Not listedIntermediateAdded
612Security Control AssessorCISSOAdvancedIntermediateLevel lowered
612Security Control AssessorCPTEAdvancedNot listedRemoved
612Security Control AssessorFITSP-AAdvancedIntermediateLevel lowered
612Security Control AssessorGCSAAdvancedIntermediateLevel lowered
622Secure Software AssessorCSCAdvancedIntermediateLevel lowered
622Secure Software AssessorGCLDAdvancedBasicLevel lowered
622Secure Software AssessorGCSAAdvancedIntermediateLevel lowered
631Information Systems Security DeveloperCCNot listedBasicAdded
631Information Systems Security DeveloperGCSAAdvancedIntermediateLevel lowered
652Security ArchitectCCNP EnterpriseNot listedAdvancedAdded
652Security ArchitectCISSOAdvancedIntermediateLevel lowered
652Security ArchitectFITSP-DAdvancedIntermediateLevel lowered
652Security ArchitectGCLDAdvancedBasicLevel lowered
652Security ArchitectGCSAAdvancedIntermediateLevel lowered
652Security ArchitectGMONNot listedIntermediateAdded
722Information Systems Security ManagerCCNot listedBasicAdded
722Information Systems Security ManagerCISSOAdvancedIntermediateLevel lowered
722Information Systems Security ManagerGCSAAdvancedIntermediateLevel lowered
722Information Systems Security ManagerGMONNot listedIntermediateAdded

Source: DoD 8140 Foundational Qualification Matrix V2.1, Certification Change Log V2.1 sheet; checked Sept. 29, 2026. The 9 unchanged and 3 not-evaluated entries are in the change-log CSV.

How does DoD 8140 qualification work?

DoD civilians and service members qualify in two steps. First comes one foundational option: a degree, DoD or military training, commercial training, or a certification from the matrix. Then comes resident, on-the-job qualification. Continuous professional development starts in the fiscal year after both are complete: at least 20 hours a year, without excusing any certification body's continuing-education rules. Contractors have the resident-qualification exception below.

Think of foundational qualification as the ticket that gets you into the building. A certification is one way to get that ticket. For civilians and service members, on-the-job sign-off is the badge that lets you work there. They need both steps. All of this comes from DoD Manual 8140.03.

The three levels describe the job, not your rank or grade:

  • Basic: You know the basic ideas and can do routine work with frequent, specific guidance.
  • Intermediate: You know the basics well, need only occasional high-level guidance, and can handle tricky, non-routine situations.
  • Advanced: You understand advanced ideas, need little or no guidance, can guide others, and can handle complex, messy situations.
Table 15. DoD 8140 deadlines and time limits
WhoRuleSource
DoD civilians and service membersFoundational qualification within 9 months. The 2026 guidance starts the period at Letter of Designation issuance; letter issuance is at component discretion. The 2023 manual states assignment as the start.2026 guidance, pp. 4–5; manual 4.2.a(2)(a)
DoD civilians and service membersResident qualification within 12 months, with the same 2026 Letter of Designation guidance. Confirm the recorded start with the component.2026 guidance, pp. 4–5; manual 4.2.a(2)(b)
DoD civilians and service membersThe normal waiver limit is 6 months, without back-to-back waivers. The guidance includes exceptions for service-member training availability and combat deployment; an extension requires component approval.2026 guidance, Appendix A; manual 4.2.c
Contractor staffFoundational qualification when cyber work startsManual 4.2.b; 2026 guidance, p. 4
Cybersecurity workforce elementOriginal program rollout target for DoD civilians and service members: 2 years from Feb. 15, 2023 (Feb. 15, 2025), subject to applicable waivers and later guidanceManual 4.3.a(1)(a)
Cyber IT, cyber effects, intelligence (cyber), and cyber enabler elementsOriginal program rollout target for DoD civilians and service members: 3 years (Feb. 15, 2026), subject to applicable waivers and later guidanceManual 4.3.a(1)(b)
Personnel subject to the CPD requirementAt least 20 hours of continuous professional development a year; begins in the fiscal year after foundational and resident qualification. Certification continuing-education rules also remain.Manual 3.2.b(4)

Source: DoDM 8140.03, effective Feb. 15, 2023; DoD 8140 Supplemental Guidance V1.1, effective September 1, 2026; checked Sept. 29, 2026.

A few more rules from the manual:

  • Experience: Experience can stand in for the foundational step only for federal civilians who were already in covered IT, cybersecurity, or enabler positions when the manual took effect, in the absence of a qualifying degree, training, or certification held by that member, subject to the documented experience-evaluation process. It is not a general substitute for new hires or contractors.
  • How a cert gets on the list: A certification needs ISO/IEC 17024 accreditation. It also needs an independent review showing it covers at least 70% of the role's core tasks and knowledge, and a vote by DoD's Cyberspace Workforce Management Board.
  • Stricter rules: A DoD component can require more than the baseline. For example, it can require two foundational options instead of one.

Do defense contractors follow DoD 8140 or DoD 8570?

DoD's May 27, 2026 contractor memo directs components to ensure contract support meets the qualifications for its assigned DCWF work roles and to update contracts. Contractor staff must meet foundational qualification when cyber work starts. The old 8570 clause still appears on Acquisition.gov, but that page alone does not describe the full current rule.

Here's what each source says.

  • The manual: DoDM 8140.03 applies to "personnel who provide contracted services" (section 1.1.b). It says contractors must be fully qualified (1.2.c) and must meet foundational qualification at the start of cyber work (4.2.b). It tells DoD offices to write its requirements into new contracts and contract changes (2.5.h). It also says contract work should name the DCWF work role and proficiency level (3.1.b(2)). Manual.
  • The newer memo: The May 27, 2026 memo says class-deviation text removing the old 8570 references and DFARS 252.239-7001 took effect February 1, 2026. It directs components to ensure the specific work-role qualifications are met and to update contracts. Detailed implementation guidance was still under development when the memo was issued.
  • The old clause page: DFARS 252.239-7001 still displays its January 2008 wording and cites 8570. That retained webpage is not evidence that the newer direction does not apply, nor does the memo by itself tell you whether a particular existing contract has been amended.
  • The limits: Contractor staff cannot use the manual's federal-civilian experience alternative. Resident qualification applies to contractors only when the component requires it and the contract includes that requirement and how it will be met (4.2.b). Manual.

Read the current performance work statement and any modifications. If it still names 8570 categories like IAT II, the contracting officer can clarify how the newer direction applies to that contract. This is general information, not legal advice.

If you run an IT firm that staffs DoD contracts, our guide to CMMC for IT MSPs covers the company-level rules that sit next to these staffing rules. Subcontractors can check how CMMC flows down to them.

Staff certifications and your company's CMMC status are two separate requirements. If your company also handles controlled unclassified information on DoD contracts, Find My CMMC Path maps your CMMC level and the kind of help to look at first. Do not enter controlled unclassified information or sensitive contract data.

Why does this matter now?

The original rollout targets have passed: Feb. 15, 2025 for cybersecurity roles and Feb. 15, 2026 for the other elements listed in the 2023 manual. Those dates are not a finding that every individual is overdue. The September 2026 guidance addresses individual timelines, waivers, documented baselines, and reporting exemptions for new work roles.

The list also moves. V2.1 lowered 25 listings and removed 2. Four of those changes shrank the Lead CCA list from 12 certs to 8. A chart from even two years ago can steer you wrong, and the old 8570 charts are older still.

How we built this

We started with DoD's V2.1 workbook, linked from the DoD CIO Workforce Innovation Directorate's DoD 8140 Document Library. The library lists a September 30, 2025 upload; the workbook's effective date is September 19, 2025. Each certification record pairs a credential with a work role and a listed level.

  • Roles and scope: We matched the 426 records to the workbook's register of 74 work roles. V2.1's published CIO scope covers cybersecurity, cyber IT, and cyber enablers: 37 roles. The other four elements are outside that published scope. Counts use the 384 in-scope records unless they say otherwise; the 42 pending records are retained separately. All 56 commercial labels are in the index, but only 55 appear in the in-scope records. The four DAWIA labels are included in credential-row and level-match totals, not in the commercial-cert count or ranking.
  • Counting: We counted each credential once per role, at its listed level. For "credentials that count" at each level, we applied the manual's same-role rule (section 3.2.b(1)(c)5.a). The 36 Basic, 160 Intermediate, and 188 Advanced in-scope records produce 36 × 1 + 160 × 2 + 188 × 3 = 920 matches, including 536 inherited matches. The 111 possible role-level slots are 37 roles × 3 levels. Table 1 ranks only the 56 commercial labels, using shared ranks for ties; the summary CSV uses the same population.
  • Checks: We read the official workbook through a document-extraction service, independently keyed its Certification Repository records by role, credential, and level, and compared all 426 keys with our dataset. All matched. We recomputed all 920 level matches and checked the role counts, credential counts, vendor totals, rankings, chart values, and displayed subsets. We did not verify the raw file hash, Reference-sheet cell addresses, or every selectable Matrix Tool view. The files now use verified record locators rather than unverified cell addresses. The official Matrix and Repository SOP says the Matrix controls if it conflicts with the Repository.
  • Changes: We classified all 60 entries in the workbook's Certification Change Log V2.1. The 48 changed entries are 21 additions + 25 level changes + 2 removals. The 25 level changes are 16 Advanced-to-Intermediate + 5 Advanced-to-Basic + 4 Intermediate-to-Basic. The log also has 9 unchanged and 3 not-evaluated entries. The earlier 612 totals—12 at Advanced and 18 at Intermediate or higher—are reconstructed from that log, not from a separate full V2.0 workbook comparison. A record absent from the log is labeled "No entry," not assumed unchanged.
  • 8570 comparison: We read the January 30, 2024, 01:26:54 archived official page, counted its 35 distinct approved-table labels, and compared names with V2.1. We matched CASP+ to SecurityX / CASP+, CAP to CGRC/CAP, CCNA Cyber Ops to CBROPS, and CE labels to the corresponding V2.1 labels. The archive's Auditor cell says "PenTest"; its provider list identifies PenTest+, so these count as one. The CISSP name match does not establish acceptance of Associate status. There are 32 shared labels, 3 archive-only labels, and 24 V2.1 commercial labels absent from that snapshot. This is not an all-history comparison or a work-role qualification crosswalk.

Every CSV row carries its source, record locator, and check date (Sept. 29, 2026). Source labels are retained for matching. Short names in Table 1 are display labels; the CSV retains the source's certification name. The source spells one label "DAWIA PM Practioner"; the readable name uses "Practitioner." Vendor names are shortened consistently, such as GIAC, ISC2, and CompTIA. Raw source spelling is not proof of a vendor's current marketing name.

What this data does and doesn't show

It shows the certification path only. Degrees, DoD training, and commercial training can also qualify someone, and the Cyber 101 course covers enabler roles.

It doesn't decide whether a person is qualified. That also involves any required resident, on-the-job qualification, stricter component rules, and review of the person's records, including a documented baseline under an older list. Contractor resident requirements have the contract-specific exception explained above.

The 42 pending-validation records are the status of this V2.1 workbook, not a ruling on every other office's current qualifications. They may change. Role counts measure breadth, not salary, job demand, or quality. We use the cert labels DoD uses, so a few names differ from vendor marketing (for example, "SecurityX / CASP+").

How to cite this page

The Defense Compliance Report Editorial Team. "DoD 8140 Certification List and Chart: 56 Certs by Work Role." The Defense Compliance Report. Analysis of DoD 8140 Foundational Qualification Matrix V2.1 (effective Sept. 19, 2025); sources checked Sept. 29, 2026. https://thedefensecompliancereport.com/research/dod-8140-certification-list/

The certification mappings come from the U.S. Department of Defense's public matrix. You're welcome to reuse our counts, tables, charts, and CSV files with credit to The Defense Compliance Report. Keep DoD's attribution and all underlying source terms. Permission covers only DCR's original contribution, not third-party logos, course materials, or other rights we do not own; a link is not required.

Download the data

Six free CSV files, no sign-up. Each row carries its source and check date.

DoD 8140 certification FAQ

What certifications are approved under DoD 8140?

The V2.1 workbook (effective Sept. 19, 2025) lists 56 commercial certifications plus 4 DAWIA credential labels. Of the 56 commercial certs, 55 appear in the 37-role published CIO scope; GCTI appears only in pending records. A listed option applies to its assigned role and level, not every role. See Table 1 for the full list.

What are the approved work roles for DoD 8140 certifications?

37 roles sit in the three elements in V2.1's published CIO scope: cybersecurity (13), cyber IT (10), and cyber enablers (14). 34 list at least one certification. Another 37 roles in that workbook register are outside this published scope; that is not a count of all current DCWF roles. Source.

What is DoD 8140?

It's DoD's program for qualifying its cyber workforce by work role, set out in DoD Manual 8140.03, effective Feb. 15, 2023. It replaced the DoD 8570 manual.

Did DoD 8140 replace DoD 8570?

Yes. DoDM 8140.03 took effect Feb. 15, 2023, and canceled DoD 8570.01-M. The May 27, 2026 contractor memo also addresses the move to DCWF qualifications; the still-visible old 8570 clause page is not the whole current rule. Memo.

What is the difference between DoD 8570 and DoD 8140?

8570 sorted people into categories like IAT and IAM with one short cert list. 8140 uses work-role codes and three proficiency levels; the V2.1 workbook registers 74 roles. It provides several foundational paths: degrees, training, certifications, and a limited experience alternative. Resident qualification and at least 20 hours of yearly professional development are separate requirements, with the contractor exception described above. Manual.

What is an 8140 IAT Level II certification?

There isn't one; 8140 has no IAT levels. Of the 7 old IAT Level II certs, 6 are still on the 8140 list for specific work roles. CCNA-Security isn't.

Is there an official full list of all DoD 8140 certifications?

Yes. DoD's V2.1 workbook has a Certification Index with 57 entries: 56 commercial certs and a single DAWIA entry. The Certification Repository pairs the labels with roles and listed levels; pending records are not approval decisions. Table 1 and the CSV files turn that into one sortable list.

Is Security+ enough for DoD 8140?

For 19 of the 37 V2.1 in-scope roles, Security+ meets the listed foundational certification option at Basic or Intermediate. It has no Advanced listing in V2.1. That does not establish full qualification. Mappings; manual.

Does a higher-level certification count for lower levels?

Yes, within the same work role (DoDM 8140.03, section 3.2.b(1)(c)5.a). It never carries over to a different role.

What are the DoD 8140 certification requirements for an ISSM?

For Information Systems Security Manager (722), 20 certifications count at Basic, 19 at Intermediate, and 8 at Advanced. The 8 at Advanced are CISM, CISSP, CISSP-ISSMP, FITSP-M, GCIA, GCIH, GICSP, and GSLC.

Which certifications count for the CMMC CCA's Work Role 612 requirement?

17 certifications count at Intermediate or higher for Security Control Assessor (612), which is the bar 32 CFR 170.11 sets for CCAs. 8 count at Advanced, the bar for Lead CCAs.

How long do I have to get qualified?

DoD civilians and service members have 9 months for foundational qualification and 12 months for resident qualification. The September 2026 guidance uses Letter of Designation issuance as the start and leaves issuance at component discretion; confirm the recorded start with the component. Contractor staff must meet foundational qualification when they start cyber work. Guidance.

Do contractors have to follow DoD 8140?

Yes: the manual requires foundational qualification at the start of cyber work, and the May 27, 2026 memo directs components to ensure specific DCWF work-role qualifications are met and to update contracts. A contract still using 8570 wording needs contract-specific clarification; the old webpage alone is not the current rule. Manual; memo.

Is CEH still approved under DoD 8140?

Yes. CEH is listed in 7 approved work roles, and CEH (Practical) in 3.

Does a change in V2.1 mean I'm no longer qualified?

Not by itself. The September 2026 guidance preserves a documented foundational baseline while the member remains in the same role and level and completes annual professional development. Recoding or missed annual requirements triggers qualification against the current matrix; required upskilling still applies. Guidance, pp. 4–6.

Sources

  1. DoD CIO Workforce Innovation Directorate, DoD 8140 Document Library: V2.1 workbook listed with upload date September 30, 2025; V2.0 marked archive. Latest listed matrix checked September 29, 2026.
  2. DoD CIO, DoD 8140 Foundational Qualification Matrix V2.1 workbook, effective September 19, 2025: Certification Repository, Certification Index, Matrix Outline & Notes, Component Change Log V2.1, and Certification Change Log V2.1. Source-extracted records and derived counts checked September 29, 2026. Main CSV · Coverage counts.
  3. DoD CIO, V2.1 matrix companion document, pp. 1–2: effective date, published workforce-element scope, lower-level rule, and Cyber 101. Full text read September 29, 2026.
  4. DISA DoD Cyber Exchange, DoD 8140 Qualification Matrices. V2.1 notice checked September 29, 2026; current files linked in source 1.
  5. DoD, DoD Manual 8140.03, Cyberspace Workforce Qualification and Management Program, effective February 15, 2023. Sections 3.2, 3.3, 4.2, and 4.3 support the qualification rules. Full text read September 29, 2026.
  6. DoD Manual 8140.03, section 4.3, p. 21: original two- and three-year program rollout targets. The derived calendar dates are February 15, 2025 and February 15, 2026. Read September 29, 2026; later guidance is source 12.
  7. DoD CIO, DoD 8140 Matrix 2.0 Change Management Bulletin, effective March 25, 2025: no education or personnel-certification updates in V2.0. Read September 29, 2026. The V2.1 workbook labels its previous release March 26, 2025; that is a different date label from the bulletin's effective date.
  8. 32 CFR 170.11, CMMC Certified Assessor, especially (b)(3), (b)(4), (b)(6), and (b)(10). The retrieved eCFR displayed current through September 25, 2026. Full section read September 29, 2026.
  9. DFARS 252.239-7001, Information Assurance Contractor Training and Certification (January 2008). Retained clause-page wording checked September 29, 2026; it must be read alongside the newer direction in source 13.
  10. Contractor requirements in DoDM 8140.03, section 4.2.b: foundational requirements at commencement; resident qualification only when required by the component and included in the contract. Read September 29, 2026. Source 13 addresses implementation updates.
  11. DoD Cyber Exchange, DoD Approved 8570 Baseline Certifications, exact January 30, 2024 archive. Full approved-certification tables, provider list, and GISF/GSE January 25, 2013 removal note read September 29, 2026. Snapshot name comparison CSV.
  12. DoD 8140, Supplemental Guidance for Cyber Workforce Management V1.1, effective September 1, 2026, pp. 3–8 and Appendix A. Letter of Designation timing, continued baselines, recoding, upskilling, new-role reporting exemptions, and waiver exceptions. Full text read September 29, 2026.
  13. Chief Information Officer, Implementation of Cyberspace Workforce Policy Requirements for Contractors, May 27, 2026. The memo identifies February 1, 2026 as the effective date of the class-deviation text and directs DCWF qualification and contract updates. Full text read September 29, 2026.
  14. ISACA, CCA certification: exam-registration prerequisites and certification requirements. Read September 29, 2026. The role/level requirement is also set in source 8.
  15. DoD CIO, Matrix and Repository SOP, Version 1.1, issued April 19, 2024, p. 8: Matrix takes precedence over Repository discrepancies. Read September 29, 2026.

The Defense Compliance Report is an independent trade publication covering CMMC and Defense Industrial Base compliance.