For decision-makers · Government & defense workforce officer

Staff your workforce against the baseline — with the source it came from

You credential a public-sector or defense workforce against mandates you do not get to interpret loosely. What you need is not a vendor’s catalog — it is which certifications map to which baseline work roles, where that mapping is published, and the discipline to confirm it at the source before it reaches a billet. That is this page, with per-seat costs from official vendor pages and the funding channels your contracting office already uses. No provider paid for placement on this page, and none can — which is the only version of this that survives a source check.

The mandate

A staffing map, not a compliance verdict

Every figure below traces to a vendor’s official page, cited and dated on the linked certification pages, and every baseline mapping points back to the public qualification tables it came from. What this page will never do is tell you a certification “satisfies” a requirement — that determination belongs to the current DoD Cyber Exchange tables and your contracting officer, not to us. We give you the cited candidacy and the honest sequencing; the compliance judgment stays where the authority sits.

Workforce seat · Foundational IT & entry cyber

The entry tier your qualification pipeline starts from

Before anyone maps to a cyber work role, the foundational tier establishes the general IT and security literacy the qualification framework assumes. These are the credentials new civilian, military, and contractor personnel commonly acquire first — open to candidates with no prior certification and inexpensive to fund at scale.

CompTIA A+ two exams, $274 each — $548 total (fees as of 2026-06-13) · 3-yr renewal $75 · Core stage

The vendor-neutral IT-support baseline — hardware, operating systems, and troubleshooting breadth for entry technicians.

CC - Certified in Cybersecurity exam $199 (fee as of 2026-07-01) · 3-yr renewal $150 · Entry stage

An at-cost security-foundations credential for personnel moving toward a cyber work role but not yet certified.

Workforce seat · Network & infrastructure

The infrastructure seats that keep the environment accredited

Network and infrastructure personnel carry their own qualification expectations, and the ladder here moves from vendor-neutral fundamentals to the platform your enclave actually runs. Sequence the vendor-specific rung to the equipment in your environment rather than certifying broadly across platforms you do not operate.

CompTIA Network+ exam $399 (fee as of 2026-06-13) · 3-yr renewal $150 · Core stage

Vendor-neutral networking fundamentals — the common entry rung for infrastructure personnel.

Cisco CCNA exam $300 (fee as of 2026-06-13) · Core stage

The associate standard where your network runs on Cisco. Most infrastructure seats stop here productively.

CompTIA Cloud+ exam $399 (fee as of 2026-06-19) · 3-yr renewal $150 · Core stage

Vendor-neutral cloud infrastructure for hybrid enclaves moving workloads off premises.

Workforce seat · Cyber defense analyst

The defensive-operations tier the baselines lean on most

This is the seat where the qualification tables and your staffing plan overlap the most, because defensive analysis is the work most cyber contracts require. The baseline credential anchors the tier; the advancement rung adds the detection-and-response depth a working defensive analyst needs.

CompTIA Security+ exam $439 (fee as of 2026-06-13) · 3-yr renewal $150 · Core stage

The defensible defensive baseline, and the credential public qualification tables most frequently anchor to.

CompTIA CySA+ exam $439 (fee as of 2026-07-14) · 3-yr renewal $150 · Advanced stage

The working-analyst advancement rung: continuous monitoring, detection, and incident response.

Workforce seat · Security operations & testing

The offensive-and-assessment seats, staffed deliberately

Penetration testing and vulnerability assessment are specialized work roles with their own qualification expectations — smaller in headcount but distinct in the baselines. Fund this rung for the assessment seats your contract actually scopes, not as a general upskilling reward.

CompTIA PenTest+ exam $439 (fee as of 2026-06-19) · 3-yr renewal $150 · Advanced stage

A vendor-neutral penetration-testing and vulnerability-assessment credential for the offensive-security seats your scope defines.

Workforce seat · Security management & architecture

The leadership tier — and the experience gate you cannot staff around

Management and architecture work roles sit at the top of the qualification framework, and their flagship credentials are experience-gated by the certifying body. That gate is not a formality you can waive with training budget — it governs who is even eligible. Plan this tier for the seats already carrying the required years, and build the pipeline below it for everyone else.

CISSP - Certified Information Systems Security Professional exam $749 (fee as of 2026-07-05) · 3-yr renewal $405 · Expert stage

The management-and-architecture flagship the senior baselines reference — experience-gated, which governs eligibility before any exam.

The vendor’s gate, not ours: full certification requires 5 years of relevant paid experience — a vendor eligibility condition, and not one training spend can substitute for. Staff this rung only against seats that already meet it. ISC2 states that earning a post-secondary degree (bachelors or masters) in computer science, information technology (IT) or related fields may satisfy up to one year of the required experience, as may one additional credential from the ISC2 approved list, leaving a minimum of 4 years.

Per-seat budgeting

Budget the renewal, not just the exam

The exam fee acquires a credential; the renewal and continuing-education cycle keeps a workforce continuously qualified, which is the figure that recurs against your appropriation year over year. Each certification above lists its cited three-year renewal cost where the vendor publishes one — multiply by the billets you staff, not by headcount you might. Where a figure reads “pending,” the vendor page did not state it and we do not estimate; the linked cost pages carry the full breakdown, sources, and dates. Every number is the vendor’s published list price — planning context, not a promise of your GSA-schedule or volume pricing.

Funding levers

The public-funding channels your contracting office already runs

Two levers cover most public-sector certification programs. The GSA Multiple Award Schedule: training and exam vouchers can often be procured through pre-competed schedule vehicles, which keeps purchasing inside an approved, auditable channel your contracting office already uses. WIOA employer partnerships and state ETPL programs: workforce boards subsidize training for eligible personnel, and many certifications sit on state Eligible Training Provider Lists. Which channel fits a cohort depends on appropriation type, contract terms, and eligibility rules — this is planning context, not procurement or legal advice; your contracting and grants officers confirm what each source permits.

Choosing training

Official-first, and neutral on providers

Every certification above has a free-study page collecting the vendor’s own objectives and no-cost materials — the zero-dollar baseline any procured training should have to beat. Where a cohort needs structured, proctored, or lab-based instruction, route it through your approved acquisition channel rather than a single preferred vendor. One durable screen: none of the certifying bodies whose pages we reviewed publishes a pass rate or a post-certification salary, so ask any provider quoting either where the number came from — a useful question during evaluation.

Common questions

Workforce compliance and funding, answered honestly

What are the DoD 8140 approved certifications for our workforce?
There is no single approved list that fits every seat — approval is per assigned work role in your organization’s 8140 implementation, not a blanket catalog. Where a certification appears in the public baseline tables, the certification pages here say so with the source. Treat every mapping as planning context and confirm current status against the official DoD Cyber Exchange qualification tables before you staff against it: the tables are revised, work-role requirements differ, and your contracting officer’s interpretation governs what satisfies a given billet.
Is DoD 8570 still in effect, or has 8140 replaced it for workforce training?
8140 is the successor framework to the older 8570.01-M baseline model, but the transition is not uniform across every contract and command. Many active contracts and position descriptions still reference 8570 baseline tables during the migration, so the practical answer for a workforce officer is to confirm which framework and which baseline table your specific contract cites, rather than assuming one has fully retired the other. The certification mappings here note the baseline candidacy where public tables show it; the authoritative status always lives at the DoD Cyber Exchange.
How do we fund workforce certification training with public dollars?
Two channels cover most public-sector programs. Training and exam vouchers can often be procured through the GSA Multiple Award Schedule, which routes purchasing through pre-negotiated, competed vehicles your contracting office already uses. Separately, WIOA employer partnerships and state Eligible Training Provider List programs can subsidize training for eligible personnel. Which channel fits a given cohort depends on appropriation type, contract terms, and eligibility rules — this is planning context, not procurement or legal advice; your contracting and grants officers confirm what each funding source permits.
Can these certifications count for college credit or apprenticeship hours?
Sometimes. Several certifications carry American Council on Education credit recommendations, and where that evaluation exists it is cited on the certification page rather than asserted here. Registered apprenticeship programs can also credit related instruction toward structured cyber and IT pipelines. Both are worth confirming at the source — the ACE evaluation and your apprenticeship sponsor’s standards — because credit recommendations change and the receiving institution or program makes the final determination.
Does holding an approved certification satisfy our contract’s compliance requirement?
A certification is one input to compliance, not a guarantee of it. Meeting a baseline requirement typically also depends on the assigned work role, continuing-education status, background and eligibility conditions, and the specific language of your contract. The honest posture for a workforce officer is that the credential demonstrates candidacy against a published table, while your contracting officer’s interpretation of the contract governs whether a billet is actually satisfied. Confirm the current requirement at the DoD Cyber Exchange before treating any certification as sufficient on its own.

Other seats

If a different seat is the one you sit in

The costs and the evidence are the same across these; what changes is the decision each one is making. Pick the closer fit:

Need this baseline data inside your own workforce systems?

No training provider paid for anything on this page, and none can. RoleMath earns nothing today; the intended model is a fee when you ask us to source training, which is a separate step you have to request and which never changes a figure or a recommendation here. Terms are published on How we make money before anything activates.

If you want help sourcing it

Ask us to help you source it

Everything above is free to read and stands on its own. If you have decided you want training for a team and would rather not work through provider sites one at a time, send us what you need and we will point you at options that fit. The link below opens your own email with the questions already laid out — fill in what you know, delete what you don’t.

Email us what you’re looking for →

Sending that email asks us to reply — nothing more. Your details go to no training provider from it. If a provider introduction turns out to be the useful next step, we will tell you which providers and why, and it only happens if you say yes to those specific ones. RoleMath earns nothing from any provider as of July 2026; the intended model is a fee for an introduction you ask for, and it cannot change a price, a comparison or a recommendation on this site. How that works is set out on How we make money.

Prefer to write it yourself? [email protected].