DoD 8140 explained: which CompTIA certifications count
By the founder of CertOwl • Published • 6 min read
Quick answer
DoD 8140 is the Department of Defense rule that everyone in a cyber work role must hold an approved qualification. Seven CompTIA certifications count toward it, and Security+ qualifies for about 20 work roles, more than any other entry level credential.
Job postings for US defense work carry a strange little code: "must be 8570 compliant", "8140 baseline required", "IAT Level II". Behind that jargon sits one of the biggest reasons the CompTIA Security+ exists at the scale it does, and one of the most reliable doors into cyber work for people without experience. This guide unpacks the whole thing: what DoD 8140 is, how it replaced the old 8570 directive, which CompTIA certifications count, and what you would need to do, step by step, to qualify.
From 8570 to 8140: what changed and why it matters
For nearly two decades, DoD Directive 8570 was the rulebook. It said that anyone doing information assurance work for the US Department of Defense had to hold a baseline certification, and it sorted people into now famous buckets like IAT Level I, II and III. Those labels still haunt job postings today, which is why recruiters keep using them long after the paperwork moved on.
The replacement arrived in stages: the 8140 directive first, then the implementation instruction, and in February 2023 the manual, DoDM 8140.03, which is the document that changed daily life. Instead of three broad technical levels, the DoD now uses the DoD Cyber Workforce Framework, or DCWF, a catalogue of specific work roles such as cybersecurity defense analyst, systems administrator or vulnerability assessment analyst. Every billet, military, civilian or contractor, is coded to a work role, and every work role has its own qualification requirements at a Basic, Intermediate or Advanced proficiency level.
The second big change is flexibility. Under 8570 a certification was essentially the only way in. Under 8140 each work role can be qualified through one of three foundational paths: an accepted degree, an approved training course, or a personnel certification. In practice, certifications remain the most portable of the three, because a certificate travels with you between contracts and employers while a training course completion often does not.
The rollout was phased across workforce elements, and the final compliance deadline for military and civilian personnel in the core cyber roles fell in February 2026. In other words: the transition period is over. If you are aiming at this world now, 8140 is simply the rule of the road.
Who actually has to comply
The mandate covers everyone performing cyber work for the DoD: uniformed service members, DoD civilians, and the enormous population of contractor personnel working for defense companies. Estimates connected to the program put the affected workforce at roughly 225,000 positions. That is why this matters even if you have never considered a government job: the contractors, from the giants down to small subcontracting shops, all inherit the same requirement, and they hire from the open market constantly.
There is a practical consequence we described in our guide to Security+ jobs without experience: because a contractor cannot legally seat an unqualified person in a coded role, postings often read "certification required, experience preferred". It is one of the few corners of the industry where the paper formally outranks the resume.
The seven CompTIA certifications that count
CompTIA currently has seven certifications approved under DoDM 8140.03, spread across roughly 30 work roles. Where each one fits:
| CompTIA certification | Typical 8140 fit | Where it points |
|---|---|---|
| A+ | Basic | Technical support and help desk seats |
| Network+ | Basic | Network operations and infrastructure support |
| Security+ | Basic and Intermediate, about 20 work roles | Cyber defense, incident response, systems administration |
| CySA+ | Intermediate | Analyst and cyber defense roles |
| PenTest+ | Intermediate | Vulnerability assessment and penetration testing |
| Cloud+ | Basic and Intermediate | Cloud infrastructure roles |
| SecurityX (formerly CASP+) | Advanced | Senior engineers and architects |
Two notes on reading that table. First, the authoritative source is the qualification matrix published on the DoD Cyber Exchange at public.cyber.mil; work role mappings get updated, so anyone signing up for a specific billet should check the current matrix rather than a blog, ours included. Second, the table is about where a certification is accepted, not where it is sufficient on its own. Qualification also includes on the job requirements, which we cover below.
Why Security+ is the workhorse of the list
Security+ maps to about 20 different work roles, more than any other single credential on the list, covering both Basic and Intermediate proficiency in the cybersecurity family. That breadth is the whole story of its popularity: one exam, passed once, keeps you eligible for the widest slice of coded seats. It is the reason the certification shows up in so many job postings, and a big part of why we rate it as worth the money for anyone with US government ambitions.
If you are starting from zero, the classic sequence is Network+ first for the fundamentals, then Security+ for the 8140 breadth. The exam itself is a moderate one, which we broke down in our SY0-701 guide: 90 questions, 90 minutes, passing score 750 of 900, with performance based questions that reward practice over cramming.
How qualification actually works, step by step
Suppose you want a coded DoD role and plan to qualify through the certification path. The sequence looks like this.
Find the work role. Every posting for a coded billet names its DCWF work role or code. Look it up in the qualification matrix on the DoD Cyber Exchange to see which certifications are accepted at which proficiency level.
Earn the foundational qualification. That means passing the accepted exam. For most people entering the field this is Security+, and a realistic preparation window is 6 to 10 weeks for someone with some IT background, as we mapped in our study timeline article. Budget the exam cost too: the voucher runs $439 in 2026, which is not small, and the full cost picture includes the possibility of a retake.
Complete the residential part. 8140 qualification is not paper only. Each role also carries an on the job component, typically demonstrated within a set period after you are seated, under your command's or employer's program.
Keep it alive. The manual requires a minimum of 20 hours per year of continuous professional development. Conveniently, the continuing education you do to keep a CompTIA certification current counts toward that requirement, so the two clocks can run on the same activities rather than doubling your workload.
If you are outside the US defense orbit
Plenty of our readers are not American and never plan to touch a DoD contract. The 8140 story still matters to you in one indirect way: it guarantees enormous, steady demand for the certifications on that list, which keeps them maintained, recognized and worth holding everywhere else. But the mandate itself does not apply to you, and nothing about your local job market requires the alphabet soup. Judge the certifications on their content and your own market, not on a US regulation.
Test yourself: 3 quick questions
A company stores and processes customers' payment card data. Which regulatory framework directly defines the security requirements for handling such data?
The correct answer is PCI DSS because it is the industry standard that directly prescribes controls for protecting cardholder data, for example encryption, network segmentation, and access control. HIPAA relates to health data, SOX to financial reporting of public companies, and GDPR to personal data of EU citizens, so none of them specifically target card data.
An organization forms a committee that meets regularly to review and approve proposed changes to IT systems before they are implemented in production. What is such a body called?
A CAB (Change Advisory Board) is a body that evaluates, prioritizes, and approves change requests as part of the change management process. A steering committee provides strategic direction, but does not approve individual technical changes.
Which standard is an open JSON/REST protocol intended for the automated provisioning and deprovisioning of user accounts between an identity source and cloud (SaaS) applications?
SCIM is an open JSON/REST standard for automatically synchronizing account lifecycle (creation, update, deletion) between systems, typically toward SaaS applications. SAML serves to exchange authentication assertions/SSO, RADIUS provides AAA for network access, and Kerberos handles authentication via tickets.
Score: · Hundreds more with explanations, free in the app: Get CertOwl on the App Store
Frequently asked questions
Is Security+ still valid under DoD 8140?
Yes. Security+ is approved under DoDM 8140.03 and maps to about 20 work roles, more than any other single certification on CompTIA's list. The old "IAT Level II" label is retired, but the certification's role got bigger, not smaller.
Does 8140 apply to contractors?
Yes. Contractor personnel in coded cyber roles must be qualified just like military and civilian staff, which is why defense contractor job postings list certifications as hard requirements.
Which CompTIA certification should I get first for a DoD job?
For most people, Security+. It covers the widest set of work roles at entry level. If you are brand new to IT, Network+ first builds the foundation, then Security+ opens the coded seats.
CertOwl's Security+ track is completely free: bite-size daily lessons, spaced repetition flashcards, and original practice questions built from the SY0-701 objectives, including full 90-question timed simulations. A few focused minutes a day, on your phone, even offline.
Get CertOwl on the App StoreFree download · A+ and Network+ completely free
+ daily lessons, flashcards and full exam simulations