Laptop displaying cyber security text in an office

DoD 8140 vs 8570: What Changed and What It Means for Your ISSO Career in 2026

·

·

The February 15, 2026 compliance deadline for DoD Directive 8140 came and went.

If you work in a DoD environment — as a contractor, GS employee, or uniformed service member in a cyber role — that deadline affects you. And if your organization is like most, nobody gave you a clean answer on what it actually means for your specific job.

This post cuts through the noise. I’ll tell you exactly what changed, what stayed the same, and what you should actually do next if you’re in an ISSO, ISSM, or related cyber role.

What Was DoD 8570?

DoD Directive 8570 (Information Assurance Workforce Improvement Program) was the framework DoD used for over a decade to baseline-certify its cybersecurity workforce. If you worked in an IA/cyber role, 8570 told you:

  • What category you fell into (IAT, IAM, IASAE, CSSP)
  • What level you were (Level I, II, or III within each category)
  • Which certifications were required or accepted for your role

For most ISSOs, this meant IAM Level I, II, or III depending on system sensitivity and scope. The certification ladder looked like this:

LevelCommon Accepted Certs
IAM Level ISecurity+, CAP, CND
IAM Level IICAP, CASP+, CISSP, GSLC, CISM
IAM Level IIICISSP, CISM, GSLC, CCISO

It wasn’t perfect, but it was predictable. You knew where you stood.

What Is DoD 8140?

DoD Directive 8140 (Cyberspace Workforce Management) replaced 8570 as the governing policy. But the real change came with its implementing document: DoD Manual 8140.03, which introduced the DoD Cyberspace Workforce Framework (DCWF).

The DCWF is based on the NICE Cybersecurity Workforce Framework (NIST SP 800-181). Instead of broad IA categories, it organizes the cyber workforce into Work Roles — 73 of them — each with specific Knowledge, Skills, and Abilities (KSAs) and associated certification requirements.

The key shift: 8570 was about what you are (your job category). 8140 is about what you do (your specific work role).

The February 2026 Deadline — What Actually Happened

Per DoD Manual 8140.03, February 15, 2026 was the deadline by which DoD Components were required to:

  1. Map all cyberspace workforce positions to DCWF Work Roles
  2. Identify qualification requirements for those roles
  3. Ensure personnel are working toward meeting those requirements

Here’s the honest reality from the field: Most organizations are not fully compliant, and enforcement is uneven.

What you’re more likely to see right now:

  • Your HR system has a new “Work Role” field in your position description
  • Your supervisor may have asked you to identify which DCWF work role fits your job
  • Large contractors (like LM, Raytheon, SAIC) are further along than smaller DoD components
  • DISA and combatant commands are generally ahead of the curve; smaller Program Offices are often still figuring it out

The deadline passed, but the transition is ongoing. This isn’t an excuse to ignore it — it’s context so you don’t panic either.

Where Do ISSOs Land in the DCWF?

This is the question nobody answers clearly. Here’s the direct answer:

If you’re an ISSO under 8570 (IAM category), your closest DCWF equivalent is:

Work Role: Cybersecurity Manager (MGT-001)
“Manages security implications within the organization; oversees the overall procurement, development, integration, modification, or operation of information security components.”

Or, depending on your scope:

Work Role: Information Systems Security Manager (MGT-002)
“Responsible for the cybersecurity of a program, organization, system, or enclave.”

Some ISSOs may also map to Security Architect (SEC-001) if your role involves designing security solutions, or Systems Security Analyst (ANA-001) if your work is heavily assessment-focused.

The practical takeaway: Talk to your security manager or Program Manager about how your position has been coded. If it’s been mapped to MGT-001 or MGT-002, the certification requirements haven’t changed dramatically from what 8570 required — CISSP, CISM, CASP+ are all still accepted qualifications.

Certification Requirements Under 8140 — What Changed?

For most ISSO roles mapped to MGT-001/MGT-002, the approved certification list looks very similar to 8570’s IAM Level II and Level III requirements:

Still valid and widely accepted:

  • CISSP (the gold standard — if you’re serious about this career, this is the one to get)
  • CISM (Certified Information Security Manager)
  • CASP+ (CompTIA Advanced Security Practitioner)
  • GSLC (GIAC Security Leadership Certification)

What 8140 adds:

  • More emphasis on role-specific training and continuous education, not just baseline certifications
  • The potential for “Alternative Credentials” — DoD-approved courses and OJT records can supplement or satisfy requirements in some cases
  • Cloud and DoD-specific certifications (like AWS Security Specialty for cloud ISSOs) may count depending on your Component’s supplemental policy

What’s effectively gone: The rigid IA/IAT/IAM category system no longer officially exists under 8140 — but many organizations still use 8570 language informally and in position descriptions that haven’t been updated yet.

What You Should Actually Do Right Now

Whether you’re a current ISSO or working toward the role, here’s the action sequence:

1. Find out your DCWF Work Role.
Ask your security manager or check your updated position description. If nobody knows, escalate — this is your hiring authority’s responsibility under 8140.

2. Look up the certification requirements for that Work Role in DoD Manual 8140.03, Appendix 3.
The manual is unclassified and available on the DoD Cyber Exchange (public). Find your Work Role, then find your Component’s approved certification list for that role.

3. If you don’t have a qualifying cert yet, prioritize CISSP.
CISSP satisfies DCWF qualifications across MGT-001, MGT-002, and several other work roles. It’s the most transferable credential in this space. If you’re not cert-eligible yet (under 5 years experience), CASP+ is the accepted alternative and requires no experience prerequisite.

Studying for CISSP? The ISC2 CISSP Official Study Guide covers all 8 domains and is what I’d recommend for self-paced study. For CASP+, CompTIA’s CertMaster is solid if you need the hands-on practice component.

4. Document your alignment.
If your Component is auditing 8140 compliance, they need records. Keep a copy of your current cert, your mapped Work Role, and any supplemental training that applies.

Contractors vs. GS Employees — Different Rules

One thing the generic 8140 articles miss: the practical enforcement differs significantly depending on whether you’re a contractor or government employee.

GS employees: Your position description should have been officially updated by your Component’s HR function. If it hasn’t, that’s your agency’s compliance gap — but your cert requirements haven’t changed. Keep your current qualifying cert active and ask when the PD update is coming.

Contractors: Your compliance obligation flows through your contract. If your contract SOW references 8570, you may still be held to those requirements until the contract is modified or re-competed. If it references 8140, your company’s FSO or security officer should have mapped your role and communicated requirements. If they haven’t, ask directly — your billability may depend on it.

Hawaii-based DoD personnel specifically: Pacific Command (INDOPACOM) has generally been consistent in enforcing cyber workforce qualification requirements. If you’re supporting PACOM, joint programs, or Navy systems in Hawaii, assume compliance is expected and plan accordingly.

Does This Affect ISSO Pay?

Short answer: indirectly, yes.

The reason is that 8140 compliance is increasingly appearing in contract requirements and job postings. Organizations that have mapped roles correctly and have compliant workforces are better positioned for contract awards. That drives demand for certified ISSOs — which drives salaries.

What’s actually happening in 2026:

  • ISSOs with CISSP in Hawaii/CONUS INDOPACOM range: $105K–$145K (GS-12/13 equivalent; contractor rates slightly higher)
  • ISSOs without a qualifying 8140 cert are increasingly excluded from new contract positions
  • Organizations are starting to require 8140 role alignment in job postings, not just 8570 category language

Bottom line: if you’re CISSP-certified or actively pursuing it, the 8140 transition works in your favor. If you’re still banking on an outdated cert or no cert at all, the window to get compliant is narrowing.

The One Thing Most ISSOs Get Wrong About 8140

They treat it as a compliance checkbox instead of a career lever.

The DCWF work role system, done right, is a roadmap. It tells you what skills, knowledge, and certs are valued at each level of the cyber career path. If you’re an ISSO today and want to move to ISSM or into a senior cyber leadership role, the DCWF shows you exactly what’s required — and it’s more specific than “get your CISSP and hope.”

Use it that way. Know your work role. Know what the next work role up requires. Build toward it deliberately.

Not in a DoD cyber seat yet? 8140 work roles also shape who gets hired in the first place — see the federal and DoD route into cybersecurity for how clearances and 8140 affect entry-level hiring, and the 6-month plan for getting a cybersecurity job with no experience if you’re starting from zero.

That’s how 8140 helps you — if you treat it as a career framework instead of a compliance burden. Want to see what that career path actually looks like? Here’s the full ISSM vs ISSO breakdown — what separates the roles, the salary jump, and the 3–5 year path to make the move.

Summary: What You Actually Need to Do

If you are…Action
ISSO with current CISSP/CISM/CASP+Confirm your DCWF Work Role mapping. You’re likely compliant.
ISSO without a qualifying certPrioritize CISSP (if 5+ yrs experience) or CASP+ (if not). Don’t wait.
Aspiring ISSO with Security+Security+ is IAT Level II (now mapped to Tech roles). For ISSO/IAM roles, you’ll need more. Get CAP or start the CISSP path.
Contractor with an 8570-era contractCheck your contract SOW. If 8570 is referenced, you may have more time — but assume 8140 is coming on re-compete.
GS employee whose PD hasn’t been updatedEscalate to your security manager. This is their problem to solve, but it affects you.

The bottom line: 8140 didn’t break anything for working ISSOs who already had solid certs. It created more clarity — and more urgency — around the certification and career path.


Need to track your RMF compliance across all 7 steps?
The ISSO’s RMF Checklist covers 100+ NIST SP 800-37 Rev 2 tasks — built for working ISSOs who need a practical tracking tool, not another policy document. Used by ISSOs supporting DoD, federal agencies, and defense contractors. $27 → Get it here

Questions about how 8140 applies to your specific situation? Email me at namshir17@gmail.com — I read every message.

As an Amazon Associate, RMF Insider earns from qualifying purchases. Some links in this post are affiliate links.

Related reading: Picking the certification that satisfies your 8140 work role is the next decision. See CISSP vs CISM for DoD 8140 for a straight comparison of cost, coverage, and which roles each one qualifies you for.

Pro Tools for Working ISSOs

Working a real ATO package right now?

Skip the spreadsheet rebuild. These are the exact tools I use in the field as an active DoD ISSO.


Get the free RMF Quick Reference

All 7 RMF steps on one page — free when you subscribe to the weekly ISSO Insider.

7 responses

  1. ISSM vs ISSO: Real Difference and Career Path to Make the Jump (2026)

    […] if you’re at 5 years. If you’re not there yet, go CAP → CASP+ → CISSP in sequence. Here’s what the cert requirements look like under DoD 8140 for ISSM roles […]

  2. ISSO Salary in 2026: DoD, Federal GS Pay, Contractor Rates & How to Earn More – RMFInsider

    […] INDOPACOM has historically enforced cyber workforce qualification requirements (DoD 8140 work role mapping, cert compliance) more consistently than many CONUS commands. This means the ceiling for unqualified ISSOs is lower, but the floor for certified ISSOs is more predictable. See: DoD 8140 vs 8570: What Changed and What It Means for Your ISSO Career. […]

  3. 25 ISSO Interview Questions DoD Contractors Actually Ask (With RMF Answers) – RMFInsider

    […] Strong answer: The primary work role for an ISSO is MGT-001 (Cybersecurity Manager) under 8140. In some organizations, ISSOs also map elements of OV-001 (Cybersecurity Oversight) depending on their specific responsibilities. The 8140 shift from 8570 means your qualifications should now be tied to DCWF work roles, not just IAT/IAM categories. If your organization is converting contracts to 8140 work role language, you want to make sure your role is mapped correctly — it affects what certs qualify you. See: DoD 8140 vs 8570: What Changed and What It Means for Your ISSO Career in 2026. […]

  4. CISSP Experience Waiver Changes 2026: CEH, CISA, and OSCP No Longer Count – RMFInsider

    […] It’s also worth reading the strategic signal: ISC2 is tightening the CISSP’s positioning as a senior credential. That’s consistent with where the certification sits in DoD career paths — the jump from ISSO toward ISSM and higher, which I broke down in DoD 8140 vs 8570: What It Means for Your ISSO Career. […]

  5. CISSP vs CISM for DoD 8140: Which Certification Should You Get? – RMFInsider

    […] roles your career will pass through. If you haven’t mapped that transition yet, start with DoD 8140 vs 8570, then come back to this […]

  6. What to Buy Before Your First Cleared Job: A Practical Checklist – RMFInsider

    […] still working through the clearance and hiring process rather than already holding an offer, my DoD 8140 breakdown covers how the certification and work-role landscape actually maps to entry-level cyber positions, […]

  7. Identity Monitoring and Your SF-86: Does Credit Freezing Help or Hurt a Clearance? – RMFInsider

    […] own house in order while you build toward roles like ISSO. If you’re early in that path, my DoD 8140 breakdown covers how workforce qualification and role mapping work today, and the ISSO salary numbers post […]

Leave a Reply

Discover more from RMFInsider

Subscribe now to keep reading and get access to the full archive.

Continue reading