Take Security+ first. It’s CompTIA’s broad security foundation, and CySA+ is the next step if you want to work as a SOC or threat analyst. CySA+ assumes you already know what Security+ teaches and goes deeper into detection, vulnerability management and incident response. SecurityX (formerly CASP+) sits well above both. It’s an expert-level certification aimed at senior engineers and architects, and it isn’t a sensible target for anyone starting out.
So for most career starters, this isn’t really a choice between the two. It’s an order. The rest of this post shows what each exam covers, who it’s for, and the signals that tell you when to move from one to the next.
The three at a glance
All figures below come from CompTIA’s own exam pages, linked in each row. Exam versions change, so check the page before you book.
| Security+ | CySA+ | SecurityX | |
|---|---|---|---|
| Exam code | SY0-701 (CompTIA page) | V3 is CS0-003; V4 (CS0-004) is now current (V3 page, V4 page) | CAS-005 (CompTIA page) |
| Level | Foundation | Intermediate, analyst-focused | Expert (CompTIA Xpert Series) |
| Questions | Up to 90 | Up to 85 | Up to 90 |
| Time | 90 minutes | 165 minutes | Up to 165 minutes |
| Scoring | Pass at 750 (100–900 scale) | Pass at 750 (100–900 scale) | Pass/fail only, no scaled score |
| Typical job targets | Junior security, IT with security duties, first SOC roles | SOC analyst, threat or vulnerability analyst | Security architect, senior security engineer |
The questions are a mix of multiple-choice and performance-based. The performance-based ones ask you to do something in a simulated environment rather than pick an answer.
Which version of CySA+ should you take?
CySA+ is mid-change. CySA+ V4 is now the current version. The previous version, V3 (CS0-003), retires in English on 22 December 2026, according to CompTIA’s CS0-003 page. Both lead to the same certification.
The practical rule: if you are already deep into CS0-003 study and can sit the exam before the retirement date, finish. If you are starting now, study for V4, since study materials and practice will follow the current objectives. Check the exam code on CompTIA’s V4 page when you book.
Security+ is moving too. CompTIA’s Security+ page says Security+ V8 is expected on or around 17 November 2026. SY0-701 is still available, and CompTIA hasn’t confirmed its retirement date, so check that page, and our Security+ SY0-701 study guide, before you choose a version.
What Security+ covers
Security+ is broad by design. The SY0-701 domains are:
| Domain | Weight |
|---|---|
| General Security Concepts | 12% |
| Threats, Vulnerabilities & Mitigations | 22% |
| Security Architecture | 18% |
| Security Operations | 28% |
| Security Program Management & Oversight | 20% |
You learn the vocabulary of the whole field: cryptography basics, identity and access management, network and cloud architecture, common attacks, incident response stages, risk and governance. You’ll know a little about almost everything, which is exactly what an employer screening for a junior role wants to see.
What it does not prove is that you can sit in front of a SIEM and triage alerts quickly. That’s where CySA+ comes in.
What CySA+ covers
CySA+ narrows the focus to the analyst’s daily work. CompTIA lists four domains for both versions, with different weightings:
| Domain | V3 (CS0-003) | V4 |
|---|---|---|
| Security Operations | 33% | 34% |
| Vulnerability Management | 30% | 26% |
| Incident Response Management (V4: Incident Response and Management) | 20% | 24% |
| Reporting and Communication | 17% | 16% |
In practice that means reading logs and packet captures, recognising indicators of compromise, prioritising vulnerability scan results, following an incident through containment and recovery, and writing it up for both technical and non-technical readers.
Here’s the kind of thing CySA+ expects you to read fluently. These Windows Security log entries come from a lab domain controller:
TimeCreated EventID Account Source IP Result
2026-10-08 02:14:07 4625 svc_backup 10.10.5.44 Failure (0xC000006A)
2026-10-08 02:14:08 4625 administrator 10.10.5.44 Failure (0xC000006A)
2026-10-08 02:14:08 4625 jdoe 10.10.5.44 Failure (0xC000006A)
...
2026-10-08 02:16:51 4624 svc_backup 10.10.5.44 Success (Logon Type 3)
Many failed logons for different accounts from one source, followed by a success. A Security+ candidate should recognise this as possible password spraying. A CySA+ candidate should also know the next steps:
- Check what
svc_backupdid after logging on. - Decide whether to disable the account.
- Work out which host 10.10.5.44 is.
- Map the behaviour to MITRE ATT&CK technique T1110.003 (Password Spraying).
If you’re aiming at the SOC, our SOC analyst roadmap shows where CySA+ fits alongside hands-on lab work.
Where SecurityX fits
SecurityX is CompTIA’s renamed CASP+. CompTIA rebranded CASP+ as SecurityX when it released the CAS-005 exam, and existing CASP+ holders were moved to the new name. Its domains are:
- Governance, risk, and compliance (20%)
- Security architecture (27%)
- Security engineering (31%)
- Security operations (22%)
The difference is the level of judgement it asks for. Security+ asks “what is this control?”. SecurityX asks you to design and defend an enterprise security architecture, choose between trade-offs and justify the decision.
CompTIA’s SecurityX page recommends a minimum of 10 years of general hands-on IT experience, including five years of hands-on security, plus Network+, Security+, CySA+, Cloud+ and PenTest+ or equivalent knowledge. That’s a clear signal it isn’t a beginner exam. Passing it without the experience behind it is unlikely to help you at interview, because the roles it targets hire on track record.
Security+ vs CySA+: how to decide what’s next
Use this decision table once you have Security+, or are close to it:
| If you... | Then consider... |
|---|---|
| Have no IT background yet | Network+ or solid networking study first; see Security+ vs Network+ |
| Are studying for or have just passed Security+ | Get hands-on: build a lab, analyse logs, apply for junior roles. CySA+ can wait until you’ve touched real alerts. |
| Work in a SOC, help desk or IT ops role and handle security alerts | CySA+ fits now, because it formalises what you’re already doing |
| Want to be a penetration tester | PenTest+ (PT0-003) is the more direct next step than CySA+ |
| Are a senior engineer or architect with years of security work | SecurityX, or a vendor-neutral alternative such as CISSP |
There’s no rule that you must collect every certification in order. Each one costs money and months of study, so take the next one when it fits the role you are applying for.
Security+ vs CISSP: a brief word
People often compare Security+ with CISSP, ISC2’s well-known certification. They aren’t really competitors. CISSP is aimed at experienced practitioners and managers, and it has a substantial work-experience requirement before you can be fully certified. Check ISC2’s CISSP page for the current rules. For a beginner, Security+ is the realistic first step. CISSP, like SecurityX, is a mid-career goal.