Workforce Solutions
DoD 8140 / 8570 Certification Requirements
How the IAT/IAM legacy framework maps to the new 8140.03 Work Role model - and how to keep your cyber workforce compliant on Day 1.
Legacy 8570: IAT and IAM
IAT (privileged technical access): Level I (A+, Network+, SSCP), Level II (Security+, CCNA Security, CySA+), Level III (CASP+, CISSP, CISA).
IAM (oversight and management): Level I (CAP, CND, Security+), Level II (CAP, CASP+, CISM, CISSP), Level III (CISM, CISSP, GSLC).
CSSP categories added for SOC roles: Analysts, Incident Responders, Infrastructure Support, Auditors.
8140.03 Work Role Model
Qualification through Education, Training, or Certification - not just exams. Each Work Role has Basic, Intermediate, Advanced proficiency.
NICE Framework categories: Securely Provision, Operate and Maintain, Oversee and Govern, Protect and Defend, Analyze, Collect and Operate, Investigate.
Map legacy roles deliberately: IAT II → Systems Administrator (Intermediate); IAM I → ISSO; IAM II → ISSM.
Practical Contractor Compliance
Map every billet to the Work Role or IAT/IAM level required by the SOW or DD254 - don't guess.
The six-month grace period is increasingly rare. Many AOs now require certification on Day 1. Submit candidates who don't qualify and they'll be denied access.
Track expirations relentlessly. Security+ expires in three years; CISSP requires CPEs. Lapsed cert = immediate access revocation.
Privileged access roles often need a Computing Environment cert on top of baseline (e.g., Security+ plus Azure Administrator Associate).
Building a Cert Development Program
Formal reimbursement policy covering exams, materials, training. Tier reimbursement by whether the cert is contractually required, strategically valuable, or aspirational.
Internal training calendar that doubles as a CPE generator.
Tracking system with automated 90-day expiration alerts.
Want help putting this into practice?
Desra Group delivers cleared cyber professionals certified on Day 1 with active expiration and CPE tracking.
Need the people to execute?
Desra Group places cleared cybersecurity, RMF/GRC, IT, and mission support professionals on defense and federal programs.
Related guides
This guide is provided for general informational purposes only and does not constitute legal or compliance advice. Specific obligations depend on your contracts and the data you handle.