IAM Level II
IAM — Information Assurance Management
IAM Level II is the mid management tier of the DoD 8570 baseline. Under DoD 8570.01-M it applied to positions managing the information assurance of a network environment — ISSMs and IA program leads at the network scope. A Level II certification also satisfies Level I.
IAT, IAM, IASAE and CSSP are the DoD baseline certification levels. A great deal of the contractor workforce is still held to them, so if you were told to “get IAT Level II,” this is what that means — and any one certification in the level satisfies it.
8140 is the newer framework, organized around work roles rather than these levels. There is no official crosswalk between the two — DoD CIO states plainly that the 8570 IA categories do not map to DCWF work roles — so treat “which level” and “which work role” as separate questions. How the two frameworks relate.
Certifications that satisfy IAM Level II
Any one of these satisfies the level. Reproduced exactly as DoD published them, which is why a few names look dated — 3 have since been renamed, retired or withdrawn. Where a name has changed, the change is noted beside it rather than swapped in.
- CAPRenamedCourse available
ISC2 renamed CAP to CGRC on 2023-02-15. Name only — exam content and qualifications unchanged, and existing badges were updated automatically.
- CASP+ CERenamedCourse available
CompTIA renamed CASP+ to SecurityX on 2024-12-17. Existing CASP+ holders keep their certification. No DoD source has approved “SecurityX” against this cell — the table predates the rename.
- CISMCourse available
- CISSP (or Associate)Course available
- GSLCCourse available
- CCISO
- HCISPPBeing withdrawn
ISC2 discontinued it. The last exam was 2023-12-01 and the credential goes inactive 2026-12-01. It sits in two IAM cells, so any contract still keyed to this table has a live problem there.
Which is easiest to obtain
Any one of these satisfies IAM Level II, so the real question is which costs you the least to get and keep. Ranked by barriers we can source — whether the credential requires work experience to be awarded, then exam length — not by how hard the exam is, which no vendor publishes. Covers the 5 we document in detail.
| Certification | To hold it | Exam | Renewal |
|---|---|---|---|
| CASP+ CECompTIA | Pass the exam | 165 min | 3y · no fee |
| GSLCGIAC | Pass the exam | 3 hr | 4y · $499 |
| CAPISC2 | 2 yr experience | 3 hr | 3y · $135 |
| CISSP (or Associate)ISC2 | 5 yr (or Associate) | 3 hr | 3y · $135 |
| CISMISACA | 5 yr experience | 4 hr | 3y · $45 |
Top row is the lightest lift — the fastest, cheapest route to satisfying IAM Level II. “Pass the exam” means the credential is yours the day you pass; an experience line means you can sit the exam but the credential isn’t awarded until you meet it (CISSP and CCSP grant “Associate” status meanwhile).
Not ranked, because you cannot earn it any more: HCISPP. If you already hold one, it may still count on a contract that names this level.
A higher IAM level satisfies a lower one — a Level III certification counts for Level I. It does not work the other way.
Where this came from
Reproduced verbatim from “DoD Approved 8570 Baseline Certifications,” published by the DoD Cyber Exchange as an extension of Appendix 3 to DoD 8570.01-M. DoD moved this section behind CAC login in late 2024, so it is no longer on the public web — this is the last public capture, dated 2024-10-02, and the original can’t be linked. Content had been unchanged since 2022-11-24.
Spelling and punctuation are the source’s, including its own errors — we flag them rather than silently correct them.
View the archived page