Castmark PressIndependent study guides
Guides · August 2026

Does Security+ count toward DoD 8140?

Yes — CompTIA Security+ is an approved certification for multiple DoD cyber work roles. But 8140 qualifies people by work role rather than by certification, and which roles accept Security+ and under what conditions is set by the current DoD cyber workforce qualification matrix. Verify against it for your own position rather than relying on any book.

This question is asked in a form that cannot be answered: does Security+ count for 8140? It is like asking whether a passport gets you into a country. Usually, for many countries, subject to conditions — and the only answer that is any use to you is the one about your country and your passport.

The framework changed shape in a way that matters here. Under the older baseline-certification model, the answer really could be a lookup: find your level, find the certification, done. The current framework qualifies people against work roles, which is more sensible and considerably less quotable.

So this guide does two things. It explains how the qualification actually works, so you know what you are looking at. And it points you at the only document that can answer your specific case — because we will not print a role list that could be out of date by the time you read it.

What changed, and why the old answers stopped working

The DoD cyber workforce framework moved from a model built around baseline certifications mapped to categories and levels, toward one built around work roles and qualification. The older DoD 8570.01-M approach — with its familiar tables of levels and approved certifications — is not the current framework.

Under the current model, an individual is qualified for a specific work role, and a certification is one of the ways a qualification requirement can be met. That is a real change in logic: the question is no longer "which level am I and what certification does it need", it is "which work role am I in and what does that role require".

This is why the answers you find on forums age so badly. A confident table of levels and certifications is describing a framework that has been superseded, and the fact that it looks authoritative is exactly the problem.

Where Security+ sits

Security+ is an approved certification for multiple DoD cyber work roles. That is the honest general statement, and it is the one our own guide carries.

What it does not tell you is which roles, at what proficiency, in combination with what else, and whether your particular position is covered. Those are set by the current qualification matrix, and they are exactly the details that decide whether taking Security+ solves your problem.

Two conditions catch people out and are worth naming. First, a certification generally has to be current — an expired certification does not qualify you, which makes the continuing-education cycle a compliance matter and not merely a professional one. Second, a certification is often one component of a qualification rather than the whole of it; experience, training or role-specific requirements may sit alongside it.

So the useful sentence is not "Security+ counts". It is "Security+ is accepted for a number of roles, and I need to check mine".

How to actually check your position

Four steps, in this order, and the order matters because each one narrows the next.

Identify your work role — the DoD work role your position is coded to, not your job title and not your general area. This is the input to everything else, and it is the step people skip.

Find the current qualification requirements for that work role in the DoD cyber workforce qualification matrix on the DoD Cyber Exchange. That is the authoritative source, and it is maintained; a copy of it in a study guide is not.

Check whether Security+ appears among the accepted options for your role at your proficiency level, and what else the qualification requires alongside it.

Confirm with the people who administer this for your organisation — your component's cyber workforce manager, security manager or equivalent. They deal with the exceptions, the transition arrangements and the local implementation, and those are not visible in any public table.

What we will and will not tell you

We publish a list of what we are confident about and a list of what only the matrix can answer, because on a compliance question the boundary between the two is the most useful thing an independent publisher can give you.

QuestionAnswer hereWhere the real answer lives
Is Security+ approved for DoD cyber work roles?Yes, for multiple rolesConfirmed generally; role detail in the matrix
Which roles, at which proficiency?We will not print a listThe current qualification matrix, DoD Cyber Exchange
Does my specific position qualify?We cannot knowYour work role code, then the matrix, then your workforce manager
Does it have to be current?Generally yes — an expired certification does not qualifyThe qualification requirements for your role
Is a certification enough on its own?Often not — it may be one componentThe qualification requirements for your role
Is the old 8570 baseline table still valid?No — that is the superseded frameworkThe current DoD 8140 policy and manuals
The DoD's current published qualification requirements govern. Verify for your own position rather than relying on any book, including ours.

The practical advice, given all that

If you are in or heading toward a DoD cyber role and hold nothing, Security+ remains the highest-value single certification to hold, precisely because it is accepted across a broad set of roles rather than a narrow one. The uncertainty in this article is about which roles, not about whether it is worth having.

Check the matrix before you book, not after you pass. Ten minutes at the start can tell you that your role needs something else entirely, which is a much cheaper discovery to make in advance.

Diarise your renewal from the day you certify. If a qualification depends on holding a current certification, letting it lapse is a compliance event, not an administrative one.

And if you are choosing study material, one thing does not depend on any of this: check that the book is written for the exam code on your booking. SY0-701 is the exam currently being delivered; SY0-801 exists as draft V8 objectives with no published launch date.

The book for this exam

Cover of CompTIA Security+ Study Guide 2027 CompTIA Security+ Study Guide 2027 Written line by line against the CompTIA Security+ V8 objectives for exam SY0-801, while most guides on the shelf are still SY0-701 books. Everything is… See the book →

More on this exam

Common questions

Does CompTIA Security+ satisfy DoD 8140?

It is an approved certification for multiple DoD cyber work roles. Whether it satisfies the requirement for your position depends on your work role and proficiency level, which the current qualification matrix defines.

Is the old 8570 baseline certification table still valid?

No. That table belongs to the superseded framework. The current model qualifies people against work roles rather than mapping certifications to categories and levels, which is why old forum answers are unreliable.

Where do I check the requirements for my role?

The DoD cyber workforce qualification matrix on the DoD Cyber Exchange, using your position's work role code — then confirm with your component's cyber workforce or security manager, who handles exceptions and local implementation.

Does my certification have to be current?

Generally yes. An expired certification does not qualify you, which makes the continuing-education cycle a compliance requirement rather than an optional professional habit.

Is a certification on its own enough to qualify?

Often not. Under the current framework a certification may be one component of a work role qualification, alongside experience, training or role-specific requirements. The matrix states what your role needs.

Why will you not just publish the list of roles?

Because it is maintained and revised, and a stale compliance table is worse than no table. On a question that decides whether someone meets a requirement for their job, we would rather send you to the source than be the reason you were wrong.

Sources

  1. DoD Cyber Exchange, DoD 8140 workforce qualification resources — the current cyber workforce qualification matrix and work role requirements; the DoD's current published requirements govern — https://public.cyber.mil/wid/dod8140/
  2. DoD Directive 8140.01 and the DoD 8140 manuals — the work-role-based qualification framework that superseded the DoD 8570.01-M baseline certification model
  3. CompTIA, Security+ certification pages — CompTIA's statement that Security+ is an approved certification for multiple DoD cyber work roles — https://www.comptia.org/en-us/certifications/security/

Rules change. Where a figure or a procedure can move, the issuing agency’s current published instructions win over anything here.