- What DoD 8140 Actually Requires
- The Four CFR-Approved CSSP Roles
- CFR-410 Exam Mechanics: Format, Fees, and Scoring
- Domain-by-Domain Breakdown for 8140 Compliance
- Who Hires CFR-Certified Professionals
- Preparing for CFR-410 with 8140 Roles in Mind
- Maintaining CFR Certification and Staying Compliant
- Frequently Asked Questions
- CFR (CFR-410) is DoD 8140/8570.01-M approved for four CSSP roles: Analyst, Infrastructure Support, Incident Responder, and Auditor.
- The exam costs $367.50, includes a free retake with the voucher, and requires a 70%-73% passing score depending on exam form.
- Domain 2 (Protect) carries the highest weight at 24%; prioritizing it in your study plan is critical for both the exam and job performance.
- CFR is ANAB accredited under ISO/IEC 17024, the accreditation standard DoD 8140 explicitly recognizes for third-party credentials.
What DoD 8140 Actually Requires
DoD Directive 8140.01 - and its predecessor, DoD 8570.01-M - establishes the cybersecurity workforce framework for all Department of Defense personnel and contractors who access DoD information systems. The directive mandates that individuals performing privileged or elevated cybersecurity functions hold a qualifying baseline certification for their specific work role and level. Without that certification on file, personnel cannot be placed in those roles on DoD contracts, regardless of experience or clearance level.
The 8140 framework organizes cybersecurity work into specialty areas drawn from the NICE Cybersecurity Workforce Framework. For each work role, DoD has approved a specific list of third-party certifications that satisfy the baseline requirement. Critically, only certifications that are accredited under ISO/IEC 17024 - a standard for personnel certification bodies - are eligible for DoD 8140 approval. This is where the CyberSec First Responder (CFR) certification's ANAB accreditation becomes directly relevant.
Practitioners and hiring managers sometimes confuse 8570 and 8140. DoD 8570.01-M was the original policy; DoD 8140.01 is the updated directive that expands and modernizes the framework. During the transition period, approved certifications under 8570 - including CFR - retain their validity. If you're pursuing CFR for a DoD contract role in 2025 or 2026, it satisfies both the legacy 8570 references you may still see in contract language and the current 8140 requirements.
The Four CFR-Approved CSSP Roles
Within the DoD 8140 framework, CFR (exam code CFR-410) satisfies baseline certification requirements for four specific Cyber Security Service Provider (CSSP) work roles. Understanding exactly which roles are covered - and what each role actually does - is essential before you invest in the credential.
CSSP Analyst
The CSSP Analyst role focuses on analyzing data from multiple sources to identify malicious activity in real time. Personnel in this role work within Security Operations Centers (SOCs), reviewing alerts, correlating events across SIEM platforms, and escalating incidents to response teams. This is among the most common placements for CFR-certified professionals on DoD contracts.
CSSP Infrastructure Support
Infrastructure Support personnel test, implement, deploy, and maintain cybersecurity tools and hardware that protect organizational systems. They work with firewalls, intrusion detection and prevention systems (IDS/IPS), and endpoint protection platforms. On DoD programs, this role often sits at the intersection of system administration and security operations.
CSSP Incident Responder
The Incident Responder role is the most directly aligned with CFR's core subject matter. Personnel investigate, analyze, and respond to cyber incidents within network environments. They perform digital forensics, containment actions, eradication procedures, and post-incident analysis. CFR's Domain 4 (Respond) and Domain 5 (Recover) map almost precisely to the technical competencies DoD expects from this role.
CSSP Auditor
CSSP Auditors conduct independent comprehensive assessments of management, operational, and technical security controls within DoD systems. They evaluate compliance with security policies, identify gaps, and recommend corrective actions. The CFR's Domain 1 (Identify) - covering asset and risk assessment - provides direct grounding for this work.
Key Takeaway
If your contract statement of work specifies a CSSP Analyst, Infrastructure Support, Incident Responder, or Auditor role at any level, CFR-410 satisfies the baseline certification requirement under DoD 8140 - making it one of the most versatile single credentials available for DoD cyber operations personnel.
CFR-410 Exam Mechanics: Format, Fees, and Scoring
Before you sit for CFR-410, understanding the exact mechanics of the exam prevents costly surprises. This is a closed-book, non-adaptive exam administered through Pearson VUE - either at a physical testing center or via OnVUE remote proctoring from your home or office. You'll find complete step-by-step registration instructions in the CFR Exam Registration Guide: Pearson VUE Setup 2026.
| Attribute | Details |
|---|---|
| Exam Code | CFR-410 |
| Governing Body | CertNexus |
| Delivery | Pearson VUE (in-center or OnVUE remote) |
| Exam Fee | $367.50 |
| Question Count | 80 scored multiple-choice/multiple-response |
| Time Limit | 120 minutes |
| Passing Score | 70%-73% (statistically equated by exam form) |
| Free Retake | Included with voucher (30-day wait required) |
| Blueprint Version | v1.10, issued 5/1/2021, modified 2/22/2022 |
| Accreditation | ANAB (ISO/IEC 17024) |
| Certification Validity | 3 years |
The 80-question, 120-minute structure gives you an average of 90 seconds per question - manageable, but not generous on complex scenario-based items. The exam uses multiple-response questions (select all that apply) in addition to standard multiple-choice. These are disproportionately challenging because partial credit is not awarded; you must select every correct option and no incorrect options to receive credit.
The passing score range of 70%-73% reflects statistical equating across exam forms. CertNexus administers multiple forms of the CFR-410 exam, and the threshold adjusts slightly to account for variance in item difficulty. You will not know which form you receive on exam day, so preparing to exceed 75% correct is a practical target that provides a buffer regardless of form.
There are no formal prerequisites. CertNexus recommends candidates have two to five years of experience in CERT, CSIRT, or SOC environments - a recommendation that aligns with the depth of scenario knowledge the exam tests, particularly in the Respond and Recover domains.
Domain-by-Domain Breakdown for 8140 Compliance
The CFR-410 blueprint v1.10 organizes content across five domains that mirror the NIST Cybersecurity Framework functions. Each domain maps to specific DoD CSSP role competencies. Understanding this alignment helps you study not just for the exam, but for the actual technical expectations DoD programs place on certified personnel.
Domain 1: Identify (22%)
Covers asset management, risk assessment, threat intelligence, and vulnerability management. For CSSP Auditors specifically, this domain is foundational - you must be able to assess an organization's attack surface and translate technical findings into risk-based language.
- Asset and system inventory techniques
- Vulnerability scanning and interpretation (Nessus, OpenVAS)
- Threat intelligence frameworks (MITRE ATT&CK, kill chain)
- Risk scoring methodologies
Domain 2: Protect (24%) - Highest Weighted Domain
At 24%, Protect carries more exam weight than any other domain. Topics span identity and access management, data security, security architecture, and the configuration of protective controls across enterprise environments.
- Firewall rule analysis and network segmentation
- Encryption standards and key management
- IAM controls and privilege management
- Security baselines and hardening benchmarks (CIS, DISA STIGs)
Domain 3: Detect (18%)
Focused on continuous monitoring, SIEM analysis, anomaly detection, and indicator-of-compromise identification. CSSP Analysts draw most heavily on this domain in day-to-day operations.
- SIEM query construction and log analysis
- Network traffic analysis (Wireshark, NetFlow)
- IDS/IPS signature tuning and alert triage
- Behavioral analytics and baseline deviation
Domain 4: Respond (19%)
Covers the full incident response lifecycle - from initial triage through containment, eradication, and evidence handling. This domain directly underpins the CSSP Incident Responder role requirement.
- Incident classification and severity prioritization
- Digital forensics: memory, disk, and network artifacts
- Chain of custody procedures for DoD environments
- Malware analysis fundamentals
Domain 5: Recover (17%)
Addresses post-incident activities including recovery planning, lessons learned, business continuity, and system restoration. Though the lowest-weighted domain, it frequently appears in scenario-based questions that test judgment over technical recall.
- Backup and recovery validation procedures
- After-action reporting and improvement planning
- Communication protocols during recovery operations
- Resilience testing and continuity planning
You can explore additional practice coverage aligned to all five domains at CFR Exam Prep's practice test platform, which structures question sets by domain weight to reflect the actual exam distribution.
Who Hires CFR-Certified Professionals
The DoD 8140 mapping is the primary hiring driver for CFR. The credential appears in contract requirements issued by defense prime contractors, federal agencies operating under DoD authority, and intelligence community contractors that mirror 8140 workforce standards.
Common employers requiring CFR or equivalent 8140-approved credentials include large defense contractors supporting Army, Navy, Air Force, and CYBERCOM programs; federal civilian agencies with DoD-adjacent network operations centers; and managed security service providers (MSSPs) holding DoD contracts. Given that CFR covers all four CSSP roles, it can satisfy requirements across a wider range of task orders than credentials approved for only one or two roles.
Beyond the DoD space, financial institutions, critical infrastructure operators, and healthcare organizations increasingly reference the CFR as a recognized incident response credential - particularly for roles in security operations and threat hunting. The ANAB ISO/IEC 17024 accreditation provides external validation that carries weight with regulated industries beyond the federal market.
Preparing for CFR-410 with 8140 Roles in Mind
Because CFR-410 covers five distinct domains - each mapping to different CSSP role competencies - an effective study plan allocates time proportional to domain weight and your existing experience gaps. Candidates with SOC analyst backgrounds typically have strong footing in Domain 3 (Detect) but need deliberate work in Domain 5 (Recover) and the audit-oriented sections of Domain 1 (Identify).
Domain 2: Protect (Highest Weight - 24%)
- Review DISA STIG categories and CIS benchmark controls
- Practice IAM scenario questions focusing on least privilege
- Work through encryption and PKI application questions
Domains 1 & 4: Identify + Respond (22% + 19%)
- Map MITRE ATT&CK techniques to vulnerability scan findings
- Practice incident triage scenarios with classification decisions
- Review digital forensics artifact types and chain of custody rules
Domains 3 & 5: Detect + Recover (18% + 17%)
- Run SIEM log analysis exercises with sample event data
- Review IDS/IPS tuning scenarios and false positive management
- Study recovery planning frameworks and after-action report structure
Full Exam Simulation and Gap Closure
- Complete timed 80-question practice exams at CFR Exam Prep
- Focus remediation on any domain scoring below 70% in practice
- Review multiple-response question technique and elimination strategies
The domains are named after NIST CSF functions - Identify, Protect, Detect, Respond, Recover - which also serves as a useful memory anchor for how the exam is structured. Candidates who understand why each domain exists within an operational security program, not just what topics it lists, tend to perform better on the scenario-based questions that make up a meaningful portion of the 80 items.
For detailed steps on scheduling your exam through Pearson VUE once you're ready, see the CFR Exam Registration Guide: Pearson VUE Setup 2026. Scheduling logistics - including OnVUE system requirements and testing center policies - differ enough from other Pearson exams that reviewing them before your first attempt is worthwhile.
Maintaining CFR Certification and Staying 8140 Compliant
CFR certifications are valid for three years from the date of passing. For DoD 8140 compliance, maintaining an active certification is not optional - an expired credential disqualifies the holder from performing in the covered CSSP roles until it is renewed. Contract officers and security managers on DoD programs typically track certification expiration dates as part of workforce compliance reporting.
CertNexus offers two recertification pathways:
- Retake the CFR-410 exam - successfully passing the current exam version resets the three-year clock.
- Continuing Education Credits (CECs) - earn 90 CECs over the three-year period, with a minimum of 30 CECs per year. A $150 recertification fee applies to the CEC pathway.
The 30 CEC per year minimum is a meaningful constraint. Many professionals bank their CECs at the end of the certification cycle rather than accruing them steadily, only to find themselves short of the annual minimum when submitting for recertification. Building CEC-earning activities - training courses, conferences, publications, or relevant professional development - into your annual routine is far less stressful than a last-minute scramble.
For active DoD contracts, plan your recertification timeline conservatively. If your certification expires mid-contract, your program manager may need to reassign you or bring in a qualified replacement while your renewal processes - a disruption that affects both you and your employer. Renewing six months before expiration is a reasonable operational buffer.
More detail on all aspects of the CFR credential, including its DoD 8140 positioning, is covered in CFR DoD 8140 Approved Roles and Requirements 2026.
Frequently Asked Questions
Yes. CFR was approved under the original DoD 8570.01-M framework and retains that approval as DoD transitions to the updated 8140.01 directive. Contract language may still reference 8570, but CFR satisfies both. Always verify against the specific position description or PWS on your contract.
The passing threshold ranges from 70% to 73% depending on the exam form you receive. CertNexus uses statistical equating across multiple exam forms to ensure consistent standards. Targeting 75% or higher in practice testing provides a practical buffer regardless of which form you encounter on exam day.
Both options are available. Pearson VUE administers CFR-410 at physical testing centers globally and via OnVUE remote proctoring. OnVUE requires a qualifying workstation, webcam, and a clean testing environment. Full technical requirements and setup steps are covered in the CFR Exam Registration Guide: Pearson VUE Setup 2026.
CFR covers four CSSP roles: Analyst, Infrastructure Support, Incident Responder, and Auditor. This multi-role coverage makes CFR particularly valuable for personnel who may move between different CSSP positions across contracts, as a single active CFR certification satisfies the baseline requirement for all four roles.
An expired CFR certification means you no longer meet the 8140 baseline requirement for your covered CSSP role. Program compliance officers track certification dates, and an expired credential can result in removal from the covered position until renewal is complete. Plan recertification conservatively - at least six months before expiration - to avoid contract disruptions.