IAT Level II: which certification should you actually get?
By 8140.study · Published 2026-08-04 · Last updated 2026-08-04
You're here because a contract, an offer letter, or your security office said "IAT Level II." That phrase comes from the DoD 8570 baseline - seven certifications sit in the IAT Level II cell, and holding any one of them satisfies the requirement. Nobody needs two. So the real question is which one to spend your study hours on, and that's a comparison the table itself doesn't make. Here it is.
The seven, honestly compared
The cell lists Security+ CE, CySA+, GSEC, GICSP, CND, SSCP, and CCNA-Security. Strike the last one immediately: Cisco retired CCNA-Security in 2020. You can't earn it anymore - it survives on the list only because DoD published the table and then stopped maintaining it. That leaves six you can actually get.
Security+ (CompTIA, exam SY0-701). Up to 90 questions in 90 minutes, passing score 750 on a 100–900 scale. No enforced prerequisites - CompTIA recommends Network+ and two years of systems experience, but nothing stops you from sitting the exam without them. Renewal is CompTIA's continuing-education cycle: 50 CEUs across three years. It is the shortest exam on this list and the most widely recognized entry security certification in the industry - which matters, because a certification is also a signal to the next hiring manager, not just a compliance checkbox.
CySA+ (CompTIA, CS0-004). Up to 85 questions but 165 minutes - nearly twice the seat time - and CompTIA pitches it at people with a few years of SOC or vulnerability-analysis experience. It's a genuinely more advanced certification. The reason to choose it over Security+ appears below; if that reason isn't you, it's extra difficulty for the same checkbox. Our CySA+ course covers it when you're ready.
GSEC (GIAC). 106 questions over four hours, passing at 72%. No prerequisites, and GIAC exams are open-book, which changes how you prepare. Two things to know before choosing it: the associated SANS training is famously excellent and famously expensive (it is not required - you may challenge the exam), and renewal costs USD 499 every four years. GSEC is a fine certification that mostly makes sense when an employer is paying for SANS training anyway.
GICSP (GIAC). 82 questions, three hours, 71% to pass, same USD 499 four-year renewal. This one exists for a specific world: industrial control systems - SCADA, plant floors, OT networks. If that's your billet, it's arguably the right pick; if it isn't, it's a specialist credential answering a question nobody asked you.
CND (EC-Council, 312-38). 100 questions over four hours, with a passing cut that varies by exam form (60–85%). EC-Council expects you to either attend its official training or apply for eligibility first, and renewal means 120 continuing-education credits plus an USD 80/year membership fee - roughly USD 240 over the cycle. Between the eligibility hoop and the renewal overhead, it's hard to recommend over Security+ for this purpose.
SSCP (ISC2). 100–125 items in two hours, passing 700 of 1000 - and a formal requirement of one year of paid, full-time experience in its domains. That requirement is the decider: if you're transitioning into security, you may not be able to hold it yet. One genuine quirk in its favor: SSCP is the only certification that appears in both the IAT Level I and IAT Level II cells, so it covers either designation. Course here if it fits your situation.
When the answer isn't Security+
You already work in a SOC. Get CySA+ instead. Same IAT II checkbox, but CySA+ also sits in four of the five CSSP specialty cells - Analyst, Infrastructure Support, Incident Responder, and Auditor. If your career is heading anywhere near a cybersecurity service provider contract, one CySA+ covers requirements Security+ never will.
You work in industrial control systems. GICSP speaks your environment's language; Security+ doesn't. Take the specialist credential your billet actually describes.
Your employer is sending you to SANS. Take GSEC - the training is the best part of that ecosystem, and the certification falls out of it. Just budget for the USD 499 renewals as an ongoing cost of keeping it.
You already hold something higher. IAT levels cascade downward: a Level III certification - CISSP, CASP+/SecurityX, GCIH and the rest of that cell - satisfies Level II automatically. Don't earn a second certification for a requirement you already meet.
What it costs and how long it takes
Exam fees change often enough that we won't print a number that might be stale - check the vendor's current fee when you book. The honest planning figures are time and renewal: Security+ is typically weeks of evening study for someone with IT experience, not months, and its renewal runs on continuing education rather than a flat re-certification fee. GIAC's 499-dollar renewals and EC-Council's membership-plus-credits model are the expensive tails on this list - factor the five-year cost, not just year one.
Start now
The Security+ course - 36 lessons, 5 hands-on labs, a knowledge check in every module, and a 75-question practice exam scored by exam domain. The first module is free with a free account, no card; the rest is the subscription. Study until the practice exam says your weakest domain is ready, then book the real thing.
Know what your contract says but not what to do about it? Answer two questions and we’ll name the certification, the hours, and open the first lesson.
A note on currency: the 8570 baseline table this requirement comes from was published by DoD and later frozen - the manual behind it was cancelled in 2023, but legacy contract language keeps its terms in force, which is why offer letters still say "IAT Level II." The preserved table, with provenance, is here.