For most people heading toward a security operations role, CySA+ is the right next certification after Security+. That answer holds for maybe two thirds of the candidates who ask, and the other third are better served by something else entirely, because the certification that should follow Security+ depends on the job you want in eighteen months rather than on where a credential sits in a marketing pyramid.
There is a structural reason the question is hard to answer well. Security+ is a breadth exam. It samples five domains and asks whether you can recognize concepts across all of them. Everything that comes after it is a depth exam, and depth only pays off in one direction at a time. Choosing well means understanding what kind of depth each certification actually builds, which is a different question from which one looks most impressive on a job board.
Security+ teaches you to recognize. The certifications after it teach you to do one specific thing. Picking the wrong one costs you a few hundred dollars and about ten weeks, which is survivable, but it also delays the depth the hiring manager was actually looking for.
What Does Security+ Leave You Unprepared For?
A Security+ holder can tell you what a SIEM is, why log correlation matters, and which control category a firewall rule falls into. What they usually cannot do on day one is sit in front of a live alert queue and decide which of forty alerts deserves a human. That gap is not a flaw in the certification. Breadth exams are supposed to establish shared vocabulary, and Security+ does that job well enough that DoD 8140 and a large share of enterprise job postings treat it as the entry gate.
The gap shows up in a specific way when candidates come back for a second course. They know the terminology cold and freeze the moment a scenario has more than one defensible answer. Triage is judgment under incomplete information, and judgment does not come from a definition list. Neither does writing an exploitation report a client will act on, or sizing a cloud storage tier, or arguing that a residual risk is acceptable. Each of those is a separate skill with its own certification behind it.
So the useful way to frame the decision is not “what is the next level up.” Ask instead what task you want to be trusted with, then work backward to the certification that trains it.
Study tip: Before choosing, pull up five job postings for the role you want and read only the responsibilities section. Ignore the certification wish list at the bottom, which is usually copied between postings and rarely reflects what the team does. The verbs in the responsibilities tell you which depth to buy.
Which CompTIA Certification Should You Take After Security+?
Here is the map, organized by the work rather than by the credential hierarchy.
| If You Want To | Take | Why |
|---|---|---|
| Work alerts in a SOC | CySA+ | Builds triage, detection, and vulnerability prioritization judgment |
| Break into systems for a living | PenTest+ | Scoping, exploitation, and the reporting half nobody expects |
| Secure or defend AI systems | SecAI+ | Model risk, prompt injection, and AI governance frameworks |
| Design the architecture, not run it | SecurityX | Expert tier, assumes years of hands on security work already |
| Secure cloud workloads | Cloud+ | Vendor neutral cloud operations, sizing, and resilience |
| Stop guessing at the command line | Linux+ | The prerequisite skill under most SOC and pentest tooling |
| Automate the repetitive work | AutoOps+ | Infrastructure automation and orchestration for ops teams |
| Run projects instead of tickets | Project+ | Lighter than PMP and does not require logged project hours |
One certification is missing from that table on purpose. Nothing says your next credential has to come from CompTIA at all, and for people who want a security practitioner role with an ISC2 name behind it, the SSCP sits between Security+ and CISSP in a way that suits hands on operations staff. Vendor loyalty is not a career strategy.
Is CySA+ the Right Next Step After Security+?
For anyone aiming at a security operations center, vulnerability management team, or incident response function, yes. CySA+ is the certification that turns recognition into triage. CompTIA launched the current version, CS0-004, on June 23, 2026: a maximum of 85 questions in 165 minutes with a passing score of 750 on a scale of 100 to 900. Weight moved toward cloud and hybrid environments, threat hunting, and the use of AI tooling inside security operations, which reflects how alert queues actually get worked now. Security Operations alone carries 34 percent of the exam. CompTIA suggests roughly four years in a SOC analyst or vulnerability analyst role, which is a recommendation rather than a gate, though it tells you the exam is written for people who have seen the work.
What trips people on CySA+ is rarely the content itself. The shift is in what the questions ask you to produce. Security+ asks you to identify the correct control. CySA+ hands you output from a scanner or a log and asks which finding you escalate, in what order, and what you tell the system owner. Candidates who study by memorizing the objectives list tend to score well on the recall items and lose the performance based questions, which is where the exam actually separates people. The fix is boring but reliable: spend real hours in front of real tool output, even in a home lab, until reading a scan result stops feeling like a translation exercise.
If you are weighing CySA+ against the newer AI security credential, that comparison has its own SecAI+ and CySA+ breakdown. For choosing study materials and formats, our guide to CySA+ prep options covers what tends to waste time.
When Does SecurityX Make Sense Instead?
Rarely, if Security+ is the only security credential you hold. SecurityX, exam code CAS-005, is CompTIA’s expert tier, and CompTIA recommends a minimum of ten years of general IT experience including five years of hands on security work. The exam runs a maximum of 90 questions in 165 minutes and is scored pass or fail with no scaled result, so you never learn how close you came. That scoring choice tells you something about the intent. This is a competency gate for architects, not a checkpoint on a learning path.
Plenty of candidates with the right background go straight from Security+ to SecurityX and pass, usually because they had eight or ten years of engineering work behind them and picked up Security+ late for a contract requirement. The recommendation is about experience, not about which exams you have already sat, and CompTIA does not enforce prerequisites. Someone two years into their first security job is a different case. They will get more out of CySA+ or PenTest+, and either one automatically renews Security+ along the way. The SecurityX overview walks through the domain structure in more detail.
What About the CompTIA Certs That Are Not Security Certs?
This is the half of the catalog nobody discusses in “what comes after Security+” conversations, and it is where a fair number of people should be looking. Security is a property of systems that somebody else designed and somebody else runs, not a discipline sitting on top of IT. Read those systems poorly and your security analysis stays shallow no matter how many security certifications you hold.
Linux+ is the clearest example. A large share of the tooling a security analyst touches runs on Linux, and candidates who cannot move confidently around a shell spend their first months in a SOC copying commands they do not understand. Our Linux+ XK0-006 exam guide covers the current version. Anyone who skipped Network+ on the way to Security+ has a similar hole, and it shows up the first time they need to explain why traffic is not reaching a segment.
| Certification | Fills This Gap |
|---|---|
| Server+ | Hardware, storage, and disaster recovery for on premises and hybrid estates |
| Cloud Essentials+ | The business and procurement side of cloud, useful for GRC leaning roles |
| Data+ | Reading and presenting data, which is most of what security metrics work is |
| DataSys+ | Database administration and the security controls that live inside it |
One caution on these. Under CompTIA’s renewal rules, a certification at the same level or below does not renew Security+, so treat them as skill investments rather than as ways to keep your existing credential current.
How Does Your Next Certification Affect Security+ Renewal?
Security+ expires three years from the date you pass. The standard renewal path is 50 continuing education units submitted through CompTIA’s CE portal plus an annual CE fee. Passing a higher level CompTIA certification is the alternative, and CompTIA states that earning a higher-level certification will automatically renew the lower-level one for eligible pairings, with the CE fee waived on the lower certification when the renewal is complete.
In practice this means CySA+, PenTest+, and SecurityX each renew Security+ when you pass them, and the renewed certification takes a new three year clock from your pass date. Renewing your highest CompTIA certification carries the ones beneath it, so someone holding A+, Network+, Security+, and CySA+ maintains the whole stack by keeping CySA+ current rather than tracking four separate expiration dates. CySA+ itself needs 60 CEUs across its three year window, ten more than Security+, which is consistent with how CompTIA scales the requirement by level. CompTIA publishes the eligible pairings, and they change when exam versions update, so check the current list rather than assuming a pairing still holds. Non CompTIA credentials behave differently. A CISSP or a CISM counts toward your CEU total but has to be submitted manually and does not trigger the automatic renewal or the fee waiver. The other detail worth catching early is that there is no grace period once a certification lapses. Miss the date and the only route back is sitting the current version of the exam at full price, which is a costly way to learn an administrative deadline.
Two of the certifications in the tables above are exceptions worth knowing before you buy. Neither SecAI+ nor AutoOps+ fully renews another CompTIA certification. They do contribute partial credit, with SecAI+ worth 15 CEUs toward Security+ and AutoOps+ worth 28, so either one gets you a meaningful way toward the 50 without finishing the job.
We have a trainer on staff whose stated life goal is to hold every CompTIA certification at the same time. He has never pulled it off. Not for lack of effort either, because he closes the gap and then CompTIA ships something new, and SecAI+, AutoOps+, DataAI, and CloudNetX have all arrived in the space of a couple of years. Completeness is not a reachable target against a catalog that keeps growing, which is about the strongest case I can make for choosing depth over the collection. He is one of the best instructors we have, and the count has nothing to do with why.
Study tip: Write down your Security+ expiration date the week you pass, then plan your next exam to land at least two months before it. Candidates who leave the renewal to the final quarter end up choosing a certification because it renews something rather than because they wanted the skill, and that is how people end up with a credential they never use.
Frequently Asked Questions
What certification should I get after Security+?
CySA+ for security operations and vulnerability management roles, PenTest+ for offensive security, SecAI+ for AI security work, and SecurityX only if you already have several years of hands on security experience. If your gap is technical rather than security specific, Linux+ or Network+ often pays off faster than another security credential.
Does CySA+ renew Security+?
Yes. CySA+ is a higher level CompTIA certification, so passing it automatically renews Security+ with no separate CEU submission and no CE fee on the lower certification. PenTest+ and SecurityX work the same way, and eligible pairings are published by CompTIA.
Is CySA+ harder than Security+?
It is harder in a different way rather than simply harder. The vocabulary is not much more advanced, but the questions ask you to make analyst decisions from tool output instead of identifying the correct concept, and the performance based questions carry more of the load. Candidates with real exposure to a SIEM or a vulnerability scanner usually find it manageable.
Can I skip CySA+ and go straight to SecurityX?
There is no enforced prerequisite, so yes. Whether you should depends on experience rather than exam history, since CompTIA recommends ten years of IT work including five in security for SecurityX. Someone with that background can skip ahead comfortably; someone two years into a first security role generally cannot.
What is the current version of the CySA+ exam?
CS0-004, which CompTIA launched on June 23, 2026. It allows a maximum of 85 questions in 165 minutes with a passing score of 750 on a 100 to 900 scale. Make sure any study materials you buy are aligned to CS0-004 rather than the previous CS0-003 objectives.
How long should I wait before taking another certification?
Long enough to do some of the work the certification describes. Stacking exams back to back produces a resume that looks strong and an interview that goes badly, because scenario questions in a hiring conversation expose the difference between passing and practicing. Six months of relevant work between credentials is a reasonable target.
VP of Educational Services | Training Camp
Jeff Porch is the VP of Educational Services and Operations at Training Camp, where he leads the company's educational initiatives with a focus on accelerated learning and student success. Beyond overseeing curriculum development, Jeff serves as the lead course designer for Training Camp's CompTIA Security+ program, one of their most popular offerings. He is deeply involved in the instructional side of the business — developing certification courses, training instructors, and ensuring that complex IT concepts are delivered in ways that maximize retention and minimize time-to-certification.
