Skip to content
CompTIA Security+ and PenTest+

Security+ vs CySA+, and where SecurityX fits

Security+ vs CySA+: Security+ is the broad foundation, CySA+ the analyst step, SecurityX the expert tier. What each covers and the order to take them.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 5 min read

Take Security+ first. It’s CompTIA’s broad security foundation, and CySA+ is the next step if you want to work as a SOC or threat analyst. CySA+ assumes you already know what Security+ teaches and goes deeper into detection, vulnerability management and incident response. SecurityX (formerly CASP+) sits well above both. It’s an expert-level certification aimed at senior engineers and architects, and it isn’t a sensible target for anyone starting out.

So for most career starters, this isn’t really a choice between the two. It’s an order. The rest of this post shows what each exam covers, who it’s for, and the signals that tell you when to move from one to the next.

The three at a glance

All figures below come from CompTIA’s own exam pages, linked in each row. Exam versions change, so check the page before you book.

Security+ CySA+ SecurityX
Exam code SY0-701 (CompTIA page) V3 is CS0-003; V4 (CS0-004) is now current (V3 page, V4 page) CAS-005 (CompTIA page)
Level Foundation Intermediate, analyst-focused Expert (CompTIA Xpert Series)
Questions Up to 90 Up to 85 Up to 90
Time 90 minutes 165 minutes Up to 165 minutes
Scoring Pass at 750 (100–900 scale) Pass at 750 (100–900 scale) Pass/fail only, no scaled score
Typical job targets Junior security, IT with security duties, first SOC roles SOC analyst, threat or vulnerability analyst Security architect, senior security engineer

The questions are a mix of multiple-choice and performance-based. The performance-based ones ask you to do something in a simulated environment rather than pick an answer.

Which version of CySA+ should you take?

CySA+ is mid-change. CySA+ V4 is now the current version. The previous version, V3 (CS0-003), retires in English on 22 December 2026, according to CompTIA’s CS0-003 page. Both lead to the same certification.

The practical rule: if you are already deep into CS0-003 study and can sit the exam before the retirement date, finish. If you are starting now, study for V4, since study materials and practice will follow the current objectives. Check the exam code on CompTIA’s V4 page when you book.

Security+ is moving too. CompTIA’s Security+ page says Security+ V8 is expected on or around 17 November 2026. SY0-701 is still available, and CompTIA hasn’t confirmed its retirement date, so check that page, and our Security+ SY0-701 study guide, before you choose a version.

What Security+ covers

Security+ is broad by design. The SY0-701 domains are:

Domain Weight
General Security Concepts 12%
Threats, Vulnerabilities & Mitigations 22%
Security Architecture 18%
Security Operations 28%
Security Program Management & Oversight 20%

You learn the vocabulary of the whole field: cryptography basics, identity and access management, network and cloud architecture, common attacks, incident response stages, risk and governance. You’ll know a little about almost everything, which is exactly what an employer screening for a junior role wants to see.

What it does not prove is that you can sit in front of a SIEM and triage alerts quickly. That’s where CySA+ comes in.

What CySA+ covers

CySA+ narrows the focus to the analyst’s daily work. CompTIA lists four domains for both versions, with different weightings:

Domain V3 (CS0-003) V4
Security Operations 33% 34%
Vulnerability Management 30% 26%
Incident Response Management (V4: Incident Response and Management) 20% 24%
Reporting and Communication 17% 16%

In practice that means reading logs and packet captures, recognising indicators of compromise, prioritising vulnerability scan results, following an incident through containment and recovery, and writing it up for both technical and non-technical readers.

Here’s the kind of thing CySA+ expects you to read fluently. These Windows Security log entries come from a lab domain controller:

TimeCreated           EventID  Account          Source IP      Result
2026-10-08 02:14:07   4625     svc_backup       10.10.5.44     Failure (0xC000006A)
2026-10-08 02:14:08   4625     administrator    10.10.5.44     Failure (0xC000006A)
2026-10-08 02:14:08   4625     jdoe             10.10.5.44     Failure (0xC000006A)
...
2026-10-08 02:16:51   4624     svc_backup       10.10.5.44     Success (Logon Type 3)

Many failed logons for different accounts from one source, followed by a success. A Security+ candidate should recognise this as possible password spraying. A CySA+ candidate should also know the next steps:

If you’re aiming at the SOC, our SOC analyst roadmap shows where CySA+ fits alongside hands-on lab work.

Where SecurityX fits

SecurityX is CompTIA’s renamed CASP+. CompTIA rebranded CASP+ as SecurityX when it released the CAS-005 exam, and existing CASP+ holders were moved to the new name. Its domains are:

  • Governance, risk, and compliance (20%)
  • Security architecture (27%)
  • Security engineering (31%)
  • Security operations (22%)

The difference is the level of judgement it asks for. Security+ asks “what is this control?”. SecurityX asks you to design and defend an enterprise security architecture, choose between trade-offs and justify the decision.

CompTIA’s SecurityX page recommends a minimum of 10 years of general hands-on IT experience, including five years of hands-on security, plus Network+, Security+, CySA+, Cloud+ and PenTest+ or equivalent knowledge. That’s a clear signal it isn’t a beginner exam. Passing it without the experience behind it is unlikely to help you at interview, because the roles it targets hire on track record.

Security+ vs CySA+: how to decide what’s next

Use this decision table once you have Security+, or are close to it:

If you... Then consider...
Have no IT background yet Network+ or solid networking study first; see Security+ vs Network+
Are studying for or have just passed Security+ Get hands-on: build a lab, analyse logs, apply for junior roles. CySA+ can wait until you’ve touched real alerts.
Work in a SOC, help desk or IT ops role and handle security alerts CySA+ fits now, because it formalises what you’re already doing
Want to be a penetration tester PenTest+ (PT0-003) is the more direct next step than CySA+
Are a senior engineer or architect with years of security work SecurityX, or a vendor-neutral alternative such as CISSP

There’s no rule that you must collect every certification in order. Each one costs money and months of study, so take the next one when it fits the role you are applying for.

Security+ vs CISSP: a brief word

People often compare Security+ with CISSP, ISC2’s well-known certification. They aren’t really competitors. CISSP is aimed at experienced practitioners and managers, and it has a substantial work-experience requirement before you can be fully certified. Check ISC2’s CISSP page for the current rules. For a beginner, Security+ is the realistic first step. CISSP, like SecurityX, is a mid-career goal.

Questions

Can I skip Security+ and go straight to CySA+?

CompTIA doesn't strictly require Security+ first, but CySA+ assumes that knowledge. Most people who skip it end up learning the same material anyway, just with more difficulty.

Is CySA+ harder than Security+?

It's narrower but deeper, and the scenarios expect more analytical judgement. Most candidates find it harder unless they already work with alerts every day.

Does SecurityX replace CISSP?

No. They're separate certifications from different bodies, and employers treat them differently. Check job adverts in your target market to see which they ask for.

Will any of these certifications get me a job?

No certification guarantees a job. They help you get shortlisted. Lab evidence, communication and interview performance do the rest.