The February 15, 2026 compliance deadline for DoD Directive 8140 came and went.
If you work in a DoD environment — as a contractor, GS employee, or uniformed service member in a cyber role — that deadline affects you. And if your organization is like most, nobody gave you a clean answer on what it actually means for your specific job.
This post cuts through the noise. I’ll tell you exactly what changed, what stayed the same, and what you should actually do next if you’re in an ISSO, ISSM, or related cyber role.
What Was DoD 8570?
DoD Directive 8570 (Information Assurance Workforce Improvement Program) was the framework DoD used for over a decade to baseline-certify its cybersecurity workforce. If you worked in an IA/cyber role, 8570 told you:
- What category you fell into (IAT, IAM, IASAE, CSSP)
- What level you were (Level I, II, or III within each category)
- Which certifications were required or accepted for your role
For most ISSOs, this meant IAM Level I, II, or III depending on system sensitivity and scope. The certification ladder looked like this:
| Level | Common Accepted Certs |
|---|---|
| IAM Level I | Security+, CAP, CND |
| IAM Level II | CAP, CASP+, CISSP, GSLC, CISM |
| IAM Level III | CISSP, CISM, GSLC, CCISO |
It wasn’t perfect, but it was predictable. You knew where you stood.
What Is DoD 8140?
DoD Directive 8140 (Cyberspace Workforce Management) replaced 8570 as the governing policy. But the real change came with its implementing document: DoD Manual 8140.03, which introduced the DoD Cyberspace Workforce Framework (DCWF).
The DCWF is based on the NICE Cybersecurity Workforce Framework (NIST SP 800-181). Instead of broad IA categories, it organizes the cyber workforce into Work Roles — 73 of them — each with specific Knowledge, Skills, and Abilities (KSAs) and associated certification requirements.
The key shift: 8570 was about what you are (your job category). 8140 is about what you do (your specific work role).
The February 2026 Deadline — What Actually Happened
Per DoD Manual 8140.03, February 15, 2026 was the deadline by which DoD Components were required to:
- Map all cyberspace workforce positions to DCWF Work Roles
- Identify qualification requirements for those roles
- Ensure personnel are working toward meeting those requirements
Here’s the honest reality from the field: Most organizations are not fully compliant, and enforcement is uneven.
What you’re more likely to see right now:
- Your HR system has a new “Work Role” field in your position description
- Your supervisor may have asked you to identify which DCWF work role fits your job
- Large contractors (like LM, Raytheon, SAIC) are further along than smaller DoD components
- DISA and combatant commands are generally ahead of the curve; smaller Program Offices are often still figuring it out
The deadline passed, but the transition is ongoing. This isn’t an excuse to ignore it — it’s context so you don’t panic either.
Where Do ISSOs Land in the DCWF?
This is the question nobody answers clearly. Here’s the direct answer:
If you’re an ISSO under 8570 (IAM category), your closest DCWF equivalent is:
Work Role: Cybersecurity Manager (MGT-001)
“Manages security implications within the organization; oversees the overall procurement, development, integration, modification, or operation of information security components.”
Or, depending on your scope:
Work Role: Information Systems Security Manager (MGT-002)
“Responsible for the cybersecurity of a program, organization, system, or enclave.”
Some ISSOs may also map to Security Architect (SEC-001) if your role involves designing security solutions, or Systems Security Analyst (ANA-001) if your work is heavily assessment-focused.
The practical takeaway: Talk to your security manager or Program Manager about how your position has been coded. If it’s been mapped to MGT-001 or MGT-002, the certification requirements haven’t changed dramatically from what 8570 required — CISSP, CISM, CASP+ are all still accepted qualifications.
Certification Requirements Under 8140 — What Changed?
For most ISSO roles mapped to MGT-001/MGT-002, the approved certification list looks very similar to 8570’s IAM Level II and Level III requirements:
Still valid and widely accepted:
- CISSP (the gold standard — if you’re serious about this career, this is the one to get)
- CISM (Certified Information Security Manager)
- CASP+ (CompTIA Advanced Security Practitioner)
- GSLC (GIAC Security Leadership Certification)
What 8140 adds:
- More emphasis on role-specific training and continuous education, not just baseline certifications
- The potential for “Alternative Credentials” — DoD-approved courses and OJT records can supplement or satisfy requirements in some cases
- Cloud and DoD-specific certifications (like AWS Security Specialty for cloud ISSOs) may count depending on your Component’s supplemental policy
What’s effectively gone: The rigid IA/IAT/IAM category system no longer officially exists under 8140 — but many organizations still use 8570 language informally and in position descriptions that haven’t been updated yet.
What You Should Actually Do Right Now
Whether you’re a current ISSO or working toward the role, here’s the action sequence:
1. Find out your DCWF Work Role.
Ask your security manager or check your updated position description. If nobody knows, escalate — this is your hiring authority’s responsibility under 8140.
2. Look up the certification requirements for that Work Role in DoD Manual 8140.03, Appendix 3.
The manual is unclassified and available on the DoD Cyber Exchange (public). Find your Work Role, then find your Component’s approved certification list for that role.
3. If you don’t have a qualifying cert yet, prioritize CISSP.
CISSP satisfies DCWF qualifications across MGT-001, MGT-002, and several other work roles. It’s the most transferable credential in this space. If you’re not cert-eligible yet (under 5 years experience), CASP+ is the accepted alternative and requires no experience prerequisite.
Studying for CISSP? The ISC2 CISSP Official Study Guide covers all 8 domains and is what I’d recommend for self-paced study. For CASP+, CompTIA’s CertMaster is solid if you need the hands-on practice component.
4. Document your alignment.
If your Component is auditing 8140 compliance, they need records. Keep a copy of your current cert, your mapped Work Role, and any supplemental training that applies.
Contractors vs. GS Employees — Different Rules
One thing the generic 8140 articles miss: the practical enforcement differs significantly depending on whether you’re a contractor or government employee.
GS employees: Your position description should have been officially updated by your Component’s HR function. If it hasn’t, that’s your agency’s compliance gap — but your cert requirements haven’t changed. Keep your current qualifying cert active and ask when the PD update is coming.
Contractors: Your compliance obligation flows through your contract. If your contract SOW references 8570, you may still be held to those requirements until the contract is modified or re-competed. If it references 8140, your company’s FSO or security officer should have mapped your role and communicated requirements. If they haven’t, ask directly — your billability may depend on it.
Hawaii-based DoD personnel specifically: Pacific Command (INDOPACOM) has generally been consistent in enforcing cyber workforce qualification requirements. If you’re supporting PACOM, joint programs, or Navy systems in Hawaii, assume compliance is expected and plan accordingly.
Does This Affect ISSO Pay?
Short answer: indirectly, yes.
The reason is that 8140 compliance is increasingly appearing in contract requirements and job postings. Organizations that have mapped roles correctly and have compliant workforces are better positioned for contract awards. That drives demand for certified ISSOs — which drives salaries.
What’s actually happening in 2026:
- ISSOs with CISSP in Hawaii/CONUS INDOPACOM range: $105K–$145K (GS-12/13 equivalent; contractor rates slightly higher)
- ISSOs without a qualifying 8140 cert are increasingly excluded from new contract positions
- Organizations are starting to require 8140 role alignment in job postings, not just 8570 category language
Bottom line: if you’re CISSP-certified or actively pursuing it, the 8140 transition works in your favor. If you’re still banking on an outdated cert or no cert at all, the window to get compliant is narrowing.
The One Thing Most ISSOs Get Wrong About 8140
They treat it as a compliance checkbox instead of a career lever.
The DCWF work role system, done right, is a roadmap. It tells you what skills, knowledge, and certs are valued at each level of the cyber career path. If you’re an ISSO today and want to move to ISSM or into a senior cyber leadership role, the DCWF shows you exactly what’s required — and it’s more specific than “get your CISSP and hope.”
Use it that way. Know your work role. Know what the next work role up requires. Build toward it deliberately.
Not in a DoD cyber seat yet? 8140 work roles also shape who gets hired in the first place — see the federal and DoD route into cybersecurity for how clearances and 8140 affect entry-level hiring, and the 6-month plan for getting a cybersecurity job with no experience if you’re starting from zero.
That’s how 8140 helps you — if you treat it as a career framework instead of a compliance burden. Want to see what that career path actually looks like? Here’s the full ISSM vs ISSO breakdown — what separates the roles, the salary jump, and the 3–5 year path to make the move.
Summary: What You Actually Need to Do
| If you are… | Action |
|---|---|
| ISSO with current CISSP/CISM/CASP+ | Confirm your DCWF Work Role mapping. You’re likely compliant. |
| ISSO without a qualifying cert | Prioritize CISSP (if 5+ yrs experience) or CASP+ (if not). Don’t wait. |
| Aspiring ISSO with Security+ | Security+ is IAT Level II (now mapped to Tech roles). For ISSO/IAM roles, you’ll need more. Get CAP or start the CISSP path. |
| Contractor with an 8570-era contract | Check your contract SOW. If 8570 is referenced, you may have more time — but assume 8140 is coming on re-compete. |
| GS employee whose PD hasn’t been updated | Escalate to your security manager. This is their problem to solve, but it affects you. |
The bottom line: 8140 didn’t break anything for working ISSOs who already had solid certs. It created more clarity — and more urgency — around the certification and career path.
Need to track your RMF compliance across all 7 steps?
The ISSO’s RMF Checklist covers 100+ NIST SP 800-37 Rev 2 tasks — built for working ISSOs who need a practical tracking tool, not another policy document. Used by ISSOs supporting DoD, federal agencies, and defense contractors. $27 → Get it here
Questions about how 8140 applies to your specific situation? Email me at namshir17@gmail.com — I read every message.
As an Amazon Associate, RMF Insider earns from qualifying purchases. Some links in this post are affiliate links.
Related reading: Picking the certification that satisfies your 8140 work role is the next decision. See CISSP vs CISM for DoD 8140 for a straight comparison of cost, coverage, and which roles each one qualifies you for.

Leave a Reply