What to Expect from the DoD 8140 Directive Guide
Implemented in 2023, the DoD 8140 establishes a comprehensive, unified framework for developing a resilient and capable cybersecurity workforce. To address expanding requirements, the DoD has standardized cybersecurity training, certifications, and education processes to ensure the affected job roles are well-equipped and confidently prepared.
What’s Inside?
- Who is affected by Dod 8140?
- What are the DoD 8140 requirements?
- Approved certification and training
- Work role mapping to certifications
- Timeline and key dates
Who is Affected by DoD 8140
All DoD personnel assigned to positions requiring the performance of cyberspace work, in accordance with the DoD Cyberspace Workforce Framework (DCWF). This includes Service members, DoD civilian employees (including non-appropriated fund employees), personnel who provide contracted services (referred to in this issuance as "contractors"), and foreign nationals.
- Office of the Secretary of Defense
- Military Departments
- Chairman of the Joint Chiefs of Staff
- Combatant Commands
- Office of the Inspector General of the DoD
- US Coast Guard
- Defense Agencies
- DoD Field Activities
- All other organizational entities in the DoD
DoD 8140 Requires:
- Foundational Qualification
- Residential Qualification
- On the Job Qualification - Always Required
- Environment-Specific Requirements - Component Discretion
- Annual Maintenance
- Certification CPE's (Keep Current) or 20 Hours Annually
Compliance Timeline:
- DoD Cybersecurity Workforce
- Foundational - 15 February 2025
- Residential - 15 February 2026
- DoD Cyberspace IT, Cyberspace Effects, Intelligence (Cyberspace), and Cyberspace Enabler Workforce Elements
- Foundational - 15 February 2026
- Residential - 15 February 2027
Approved GIAC Certifications and Corresponding Affiliate Training*
*Additional certification options are continuously being added to the DoD8140 Directive.
Cyber Defense
- GIAC Defensible Security Architect Certification (GDSA) | SEC530: Defensible Security Architecture and Engineering Zero Trust
- GIAC Security Essentials Certification (GSEC) | SEC401: SANS Security Essentials Network, Endpoint & Cloud
- GIAC Information Security Fundamentals (GISF) | SEC301: Intro to Cyber Security
- GIAC Foundational Cybersecurity Technologies (GFACT) | SEC275: Foundations, Computers, Technology and Security
- GIAC Certified Intrusion Analyst (GCIA) | SEC503: Network Monitoring and Threat Detection In-Depth
- GIAC Continuous Monitoring Certification (GMON) | SEC511: Continuous Monitoring & Security Operations
Digital Forensics & Incident Response
- GIAC Certified Forensics Analyst (GCFA) | FOR508: Advanced Incident Response, Threat Hunting & Digital Forensics
- GIAC Cyber Threat Intelligence (GCTI) | FOR578 Cyber Threat Intelligence
- GIAC Certified Forensic Examiner (GCFE) | FOR500: Windows Forensic Analysis
- GIAC Reverse Engineering Malware Certification (GREM) | FOR610: Reverse-Engineering Malware
SANS EDU
8140 Framework Categories
The 8140 Framework Categories are a high-level grouping of common cybersecurity functions. Select a category below to help you identify the right certifications and affiliate training for your current or desired cybersecurity role.
Data/AI
Coming Soon!
Reviews
Read what others have to say about SANS Training.