IAT Level II
IAT — Information Assurance Technical
IAT Level II is the most-cited tier of the DoD 8570 baseline — when a contract or recruiter says "8570 compliant" with no further detail, this is usually the cell they mean. Under DoD 8570.01-M it applied to privileged technical positions supporting a network environment, and Security+ CE sitting in this cell is the reason Security+ became the default DoD certification. A Level II certification also satisfies Level I.
IAT, IAM, IASAE and CSSP are the DoD baseline certification levels. A great deal of the contractor workforce is still held to them, so if you were told to “get IAT Level II,” this is what that means — and any one certification in the level satisfies it.
8140 is the newer framework, organized around work roles rather than these levels. There is no official crosswalk between the two — DoD CIO states plainly that the 8570 IA categories do not map to DCWF work roles — so treat “which level” and “which work role” as separate questions. How the two frameworks relate.
Certifications that satisfy IAT Level II
Any one of these satisfies the level. Reproduced exactly as DoD published them, which is why a few names look dated — 1 has since been renamed, retired or withdrawn. Where a name has changed, the change is noted beside it rather than swapped in.
- CCNA-SecurityRetiredCourse available
Cisco retired exam 210-260 on 2020-02-23. The table’s own footnote acknowledges this and points to a DoD CIO waiver for holders who were in a position requiring it. The rebranded CCNA (200-301) is the successor, but it is the waiver — not the rename — that DoD addressed.
- CySA+Course available
- GICSPCourse available
- GSECCourse available
- Security+ CECourse available
- CNDCourse available
EC-Council Certified Network Defender. Not the same thing as CND-SP, which was the former name of the CSSP category itself.
- SSCPCourse available
Which is easiest to obtain
Any one of these satisfies IAT Level II, so the real question is which costs you the least to get and keep. Ranked by barriers we can source — whether the credential requires work experience to be awarded, then exam length — not by how hard the exam is, which no vendor publishes. Covers the 6 we document in detail.
| Certification | To hold it | Exam | Renewal |
|---|---|---|---|
| Security+ CECompTIA | Pass the exam | 90 min | 3y · no fee |
| CySA+CompTIA | Pass the exam | 165 min | 3y · no fee |
| GICSPGIAC | Pass the exam | 3 hr | 4y · $499 |
| GSECGIAC | Pass the exam | 4 hr | 4y · $499 |
| CNDEC-Council | Pass the exam | 4 hr | 3y · $80 |
| SSCPISC2 | 1 yr experience | 2 hr | — |
Top row is the lightest lift — the fastest, cheapest route to satisfying IAT Level II. “Pass the exam” means the credential is yours the day you pass; an experience line means you can sit the exam but the credential isn’t awarded until you meet it (CISSP and CCSP grant “Associate” status meanwhile).
Not ranked, because you cannot earn it any more: CCNA-Security. If you already hold one, it may still count on a contract that names this level.
A higher IAT level satisfies a lower one — a Level III certification counts for Level I. It does not work the other way.
Where this came from
Reproduced verbatim from “DoD Approved 8570 Baseline Certifications,” published by the DoD Cyber Exchange as an extension of Appendix 3 to DoD 8570.01-M. DoD moved this section behind CAC login in late 2024, so it is no longer on the public web — this is the last public capture, dated 2024-10-02, and the original can’t be linked. Content had been unchanged since 2022-11-24.
Spelling and punctuation are the source’s, including its own errors — we flag them rather than silently correct them.
View the archived page