Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Certification Guide

The CompTIA Cybersecurity Analyst
Certification Explained.

Everything you need to know about the CySA+ certification as of 2026, covering the four domains under the new V4 exam live since June 23, 2026, the exam format, recommended experience, career outcomes, DoD 8140 status, and how CySA+ compares to Security+ and PenTest+. A complete reference guide for anyone weighing the CySA+ or trying to understand what it covers.

CYSA_FAST_FACTS
Issuer: CompTIA
Exam: Max 85 questions, 165 minutes
Passing Score: 750 on a 100 to 900 scale
Experience: About 4 years recommended
DoD 8140 Approved (10 DCWF roles)
4 CySA+ Domains 85 Max Questions 165-MINUTE Exam 10 DCWF Work Roles SINCE 2017 CompTIA Issued
UPDATED 2026
The CySA+ Domains

Four Domains of the V4 Exam

01

Security Operations

Detecting malicious activity with SIEM, EDR, and threat hunting, plus AI in the SOC. The heaviest domain at 34%.

02

Vulnerability Management

Scanning, analyzing findings, and prioritizing fixes with risk-based approaches. 26% of the exam.

03

Incident Response and Management

Frameworks, the response process, and hands-on techniques. Grew to 24% in V4.

04

Reporting and Communication

Reports, dashboards, post-incident reviews, and SOC metrics. 16% of the exam.

Overview

What Is the CompTIA Cybersecurity Analyst?

CySA+ is CompTIA's intermediate cybersecurity analyst certification, first administered in 2017 and built for the defensive side of security: detecting, analyzing, and responding to threats.

It sits between Security+ and the expert-level SecurityX on CompTIA's cybersecurity path, and it tests the work SOC analysts actually do: analyzing logs and indicators, running vulnerability programs, responding to incidents, and reporting findings, with heavy use of performance-based questions rather than pure recall. A new V4 exam (CS0-004) went live on June 23, 2026, adding AI in security operations to the objectives and rebalancing the four domains, so most guides you'll find still describe the outgoing version.

The credential is ANAB-accredited under ISO/IEC 17024, approved under DoD 8140 across ten DCWF work roles, and renewed through continuing education. CySA+ is issued and maintained by CompTIA, the body behind Security+ and the largest vendor-neutral certification program in IT.

2017 First Administered
4 Domains
4 Yr Recommended Experience
Why CySA+ Matters

Why Is CySA+ the SOC Analyst Credential?

Four things that make CySA+ the standard validation for defensive security roles in 2026.

Performance-Based, Not Memorization-Based

CySA+ tests whether you can do the analyst job, not just describe it. Performance-based questions put real log output, vulnerability scan results, and incident scenarios in front of you, which is why hiring managers treat it as evidence of working skill. The credential is ANAB-accredited under the ISO/IEC 17024 personnel certification standard.

First CompTIA Analyst Cert to Test AI

The V4 exam, live since June 23, 2026, adds AI in security operations as a named objective: use cases, risks, and governance. The outgoing CS0-003 English exam remains available through December 22, 2026.

Built for a Job That's Everywhere

Banks, hospitals, agencies, and retailers all staff SOCs, and CySA+ maps to the roles they hire for. For the unfiltered picture of the work itself, read what a SOC analyst actually does all day.

DoD 8140 Approved

CySA+ is an approved qualification under DoD Manual 8140.03, mapped to ten work roles in the DoD Cyber Workforce Framework (DCWF) at the Advanced proficiency level on nine of them, including Cyber Defense Analyst, Cyber Defense Incident Responder, and Vulnerability Assessment Analyst.

The mappings span four workforce elements, including the Intelligence (Cyberspace) element through the All-Source Analyst role, unusual reach for an intermediate certification. Current qualification matrices are published at the DoD Cyber Exchange.

Advanced Proficiency 10 DCWF Roles 4 Workforce Elements
Fast Facts

What Are the Key Facts About CySA+?

Everything you need to know about the certification, the exam structure, and how to maintain CySA+ as of 2026.

01

The Certification

Certification Name
CompTIA Cybersecurity Analyst (CySA+)
Issued By
CompTIA
Current Exam
V4 (CS0-004), live June 23, 2026
Prior Exam
CS0-003 (English retires Dec 22, 2026)
First Administered
2017
Formal Prerequisites
None
Recommended Experience
About 4 years, SOC or vulnerability analyst
Accreditation
ANAB-accredited (ISO/IEC 17024)
DoD 8140 Status
Approved (10 DCWF roles, Advanced on 9)
02

Exam & Maintenance

Exam Format
Multiple choice + performance-based
Number of Items
Maximum of 85 questions
Exam Duration
165 minutes
Passing Score
750 on a scale of 100 to 900
Exam Cost
$439 retail voucher (as of June 2026)
Languages
English (translations coming)
Delivery
Pearson VUE test center or online
Validity
3 years
CE Requirement
60 CEUs over 3 years + annual CE fee
Alternate Renewal
Passing a higher CompTIA exam
Going Deeper

What Comes After the CySA+?

From the analyst seat, the paths branch three ways: cross to the offensive side, climb to the expert tier, or specialize in the AI security work now landing in every SOC.

PenTest+ (Offense)

The red team counterpart at the same tier. Analysts who understand how attacks are actually executed become sharper defenders, and many SOC professionals hold both credentials.

SecurityX (Expert)

CompTIA's expert-level credential, formerly known as CASP+, covering enterprise security architecture and engineering. Passing it also renews CySA+ automatically under the CE program.

SecAI+ (AI Security)

CompTIA's newest specialty, launched February 2026, goes deep on securing AI systems and using AI in security work. It pairs naturally with the analyst foundation CySA+ builds.

Certification Roadmap

Where Does CySA+ Fit in Your Career?

CySA+ is the middle of CompTIA's cybersecurity ladder: networking and security fundamentals build toward it, and offensive, expert, and leadership tracks branch out from it.

STAGE 02 You Are Here

Analyst Credential

The SOC standard

PRIMARY
CySA+
CompTIA · Cybersecurity Analyst
EC-Council CSA
EC-Council · Alternative SOC analyst credential
STAGE 03

Specialize

Pick your path

Offensive Security
Expert Level
Leadership
Decision Point

Is CySA+ Right For You?

Two questions to answer before you commit: are you ready for the exam, and is CySA+ the right certification for your goals. Here's a straight answer to both.

Q1

Are You Ready for CySA+?

Path A

Working Security Experience

You can sit the exam now.

There are no enforced prerequisites, so anyone can register. CompTIA recommends about 4 years in a SOC analyst or vulnerability analyst role for the V4 exam, and the performance-based questions assume you've actually read logs and scan output before. If you have Security+ level knowledge plus hands-on defensive work, you're in the exam's target zone.

Path B

Still Building the Foundation

Start with Security+.

If you're coming from general IT or early in your security career, Security+ first is the well-worn path. It covers the concepts CySA+ assumes you already hold, it's the credential entry-level security postings ask for by name, and the step from Security+ into CySA+ is exactly the jump CompTIA designed the ladder around.

Q2

Is CySA+ the Right Certification for Your Goals?

CySA+ Is a Strong Fit If...

  • You're targeting SOC analyst, incident responder, or vulnerability analyst roles, the jobs the exam is built around
  • You hold Security+ and want the next credential on the defensive track
  • You work federal or contractor roles where a DoD 8140 approved credential at Advanced proficiency matters
  • You want a certification that tests hands-on skill through performance-based questions rather than recall
  • You need to prove current skills, including the AI-in-the-SOC material the V4 exam now covers
  • You're already doing analyst work without a credential that documents it

Consider Alternatives If...

  • You're new to security with no hands-on exposure, where Security+ is the right starting point
  • Your goal is offensive security and penetration testing, where PenTest+ or CEH fits the ambition
  • You're a senior practitioner ready for architecture and engineering, where SecurityX is the level
  • Your interest is AI security specifically, where CompTIA's SecAI+ goes deeper on that specialty
  • You're headed for security management rather than analyst work, where CISM or CISSP serves the goal
  • Your work is audit and assurance, where CISA is the more direct credential
Career Paths

What Jobs Can You Get With CySA+?

CySA+ maps to defensive security roles across the private sector and the federal cyber workforce. Every card below is a DCWF work role verified on the DoD 8140 Matrix V2.1.

Security Operations

Cyber Defense Analyst

The SOC analyst role: monitoring, triaging, and investigating alerts across the enterprise. DCWF work role 511, where CySA+ qualifies at the Advanced proficiency level under DoD 8140.

Incident Response

Cyber Defense Incident Responder

Contains, eradicates, and recovers from confirmed security incidents. DCWF work role 531, mapped to CySA+ at the Advanced level and drawing directly on Domain 3.

Vulnerability Management

Vulnerability Assessment Analyst

Finds and prioritizes the weaknesses attackers would use first. DCWF work role 541, where CySA+ qualifies at the Advanced level, the exact skill set Domain 2 tests.

Forensics

Cyber Defense Forensics Analyst

Analyzes digital evidence to reconstruct what happened during an intrusion. DCWF work role 212, mapped to CySA+ at the Advanced level.

Threat Intelligence

All-Source Analyst

Fuses intelligence from multiple sources to assess cyber threats. DCWF work role 111 in the Intelligence (Cyberspace) workforce element, where CySA+ qualifies at the Advanced level.

Risk and Assessment

Security Control Assessor

Evaluates whether security controls are implemented correctly and operating as intended. DCWF work role 612, mapped to CySA+ at the Advanced level.

Comparison

How Does CySA+ Compare to Security+ and PenTest+?

Three CompTIA security credentials, three different jobs. Here's how they line up.

  CySA+ Security+ PenTest+
Issuer CompTIA CompTIA CompTIA
Focus Threat detection and response (blue team) Security fundamentals Penetration testing (red team)
Current Exam CS0-004 SY0-701 PT0-003
Exam Format Max 85 questions, 165 minutes Max 90 questions, 90 minutes Max 90 questions, 165 minutes
Passing Score 750 out of 900 750 out of 900 750 out of 900
Recommended Experience About 4 yrs, SOC or vulnerability analyst About 2 yrs in a security or IT role 3 to 4 yrs in a penetration testing role
Renewal 60 CEUs over 3 years 50 CEUs over 3 years 60 CEUs over 3 years
DoD 8140 Approved Yes (10 roles, Advanced on 9) Yes (20 roles, Intermediate) Yes (10 roles)
Best For SOC analysts and incident responders Breaking into cybersecurity Aspiring penetration testers

All three renew through CompTIA's Continuing Education program, and passing a higher-level exam renews the ones below it. Many defenders eventually add PenTest+ to understand the attacks they're detecting.

Ready to Get Certified?

Train for CySA+ with Training Camp.

Our CompTIA CySA+ boot camp covers all four domains over four days, with hands-on labs, your exam voucher, and a pass guarantee included, so working analysts leave exam-ready.

View Boot Camp
Dive Deeper

CySA+ Articles and Guides.

Certification decisions, SOC career reality checks, and salary data for the defensive security track.

Featured Decision Guide

CompTIA SecAI+ vs CySA+: What Comes Next After Security+

CompTIA's new SecAI+ certification gave the "what comes after Security+" question two very different answers. A domain-by-domain breakdown of both paths and how to pick the one that fits your career.

Read Article →
Career Insight

What Does a SOC Analyst Actually Do All Day?

The unfiltered picture of the job CySA+ trains you for: alert triage, tier structures, shift work, the burnout risk nobody mentions in job postings, and who actually thrives in the role.

Read Article →
Career Decision

Is CompTIA Security+ Worth It in 2026?

An honest take on the certification most CySA+ candidates earn first, including who it actually helps, what it pays, and the technical tracks that branch out from it.

Read Article →
Salary Guide

Highest Paid Cybersecurity Jobs: Careers with Top Earning Potential

Where the salary ceiling actually sits across security roles, from SOC analysts and consultants to managers and CISOs, and which certifications show up in the highest-paying postings.

Read Article →
Career Change

Career Change From IT: The Best Options, Salaries, and How to Make the Switch

The realistic paths out of IT operations, including the cybersecurity pivot that runs from Security+ through CySA+ into SOC analyst territory, with timelines and salary expectations.

Read Article →
Hiring Insight

What I Learned Talking to 100 IT Hiring Managers About Certifications

Which credentials actually move a resume to the top of the pile, which ones hiring managers ignore, and how certifications weigh against experience in real hiring decisions.

Read Article →
Salary Guide

CompTIA Security+ Salary Guide: What You Can Earn in 2025

Salary benchmarks by role, experience, and geography for the Security+ baseline, including the estimated pay impact of stacking CySA+ and other credentials on top of it.

Read Article →
Curriculum

Inside the Four CySA+ Domains.

The V4 exam objectives organize CySA+ into four domains, each carrying its own weight on the exam. Click any domain for what it covers.

Domains 01-02

Detect and Prioritize
01 Security Operations 34%

The heart of the exam and of the job: analyzing indicators of malicious activity across networks, endpoints, cloud, and identity systems using SIEM, EDR, and packet analysis tools, plus threat intelligence, threat hunting, and the V4 addition of AI use, risks, and governance in security operations.

02 Vulnerability Management 26%

Running the vulnerability program end to end: choosing the right scanning method, analyzing assessment tool output, and prioritizing and mitigating findings using risk-based approaches, scoring systems, and business context.

Domains 03-04

Respond and Report
03 Incident Response and Management 24%

What to do when detection turns into an incident: attack methodology frameworks like MITRE ATT&CK and the Cyber Kill Chain, the response process from preparation through recovery, and hands-on techniques including triage, evidence handling, and root cause identification.

04 Reporting and Communication 16%

Turning technical findings into action: vulnerability and incident reporting, dashboards, post-incident reviews, and the metrics that measure a SOC, such as detection time, response time, and remediation effectiveness.

Domains and weights reflect the CompTIA CySA+ V4 (CS0-004) exam objectives, live since June 23, 2026. The prior CS0-003 English exam remains available through December 22, 2026.

Frequently Asked Questions

Common Questions About CySA+.

The questions candidates ask most often when researching the CompTIA Cybersecurity Analyst certification.

What is the CySA+ certification?

CySA+ is CompTIA's intermediate cybersecurity analyst certification. It validates the ability to detect, analyze, and respond to threats: analyzing logs and indicators with SIEM and EDR tools, managing vulnerabilities, responding to incidents, and communicating findings. It sits above Security+ and below the expert-level SecurityX on CompTIA's cybersecurity path.

Who should get the CySA+?

CySA+ fits professionals headed into or already working defensive security roles: SOC analysts, incident responders, vulnerability analysts, and threat hunters. CompTIA recommends about 4 years in a SOC analyst or vulnerability analyst role for the V4 exam, though there's no enforced prerequisite. If you're newer to security, Security+ is usually the better first step.

What is the CySA+ exam like?

The CySA+ V4 exam (CS0-004) has a maximum of 85 questions delivered over 165 minutes, mixing multiple choice with performance-based questions where you analyze log output, interpret scan results, and work through simulated scenarios. The passing score is 750 on a scale of 100 to 900.

What changed in the CySA+ V4 exam?

CySA+ V4 (CS0-004) launched June 23, 2026. The four domain names stay the same but the weights rebalanced: Security Operations moved to 34 percent, Vulnerability Management to 26, Incident Response and Management to 24, and Reporting and Communication to 16. The biggest addition is AI in security operations, covering AI use cases, risks, and governance, which the prior exam didn't address.

Is the CS0-003 exam still available?

Yes, for now. CompTIA is running a transition window: the English CS0-003 exam remains available through December 22, 2026, with translated versions available until March 23, 2027. If you're deep into CS0-003 preparation you can still test on it; if you're starting fresh, prepare for CS0-004.

What experience do you need for CySA+?

There's no enforced prerequisite, so anyone can register. CompTIA recommends about 4 years in a SOC analyst or vulnerability analyst role for the V4 exam. In practice, the exam assumes Security+ level knowledge of networks, security concepts, and defensive tooling, and candidates without that foundation tend to struggle.

Do I need Security+ before CySA+?

Not formally. There's no required prerequisite for CySA+. But the exam builds directly on Security+ level knowledge, and most successful candidates either hold Security+ or have equivalent working knowledge. If you're starting from general IT, Security+ first is the well-worn path.

What are the four CySA+ domains?

Under the V4 (CS0-004) objectives, they are Security Operations at 34 percent, Vulnerability Management at 26 percent, Incident Response and Management at 24 percent, and Reporting and Communication at 16 percent.

Is the CySA+ exam hard?

It's a meaningful step up from Security+. The performance-based questions require actually doing analyst work: reading logs, interpreting vulnerability scan output, and making incident response decisions under time pressure. Candidates with real SOC exposure find it fair; candidates relying on memorization find it punishing. Hands-on practice with SIEM output and scan results is the difference-maker.

How do I maintain the CySA+ certification?

CySA+ is valid for three years through CompTIA's Continuing Education program. You renew by earning 60 continuing education units (CEUs) across the cycle and paying CompTIA's annual CE fee, or by passing a higher-level CompTIA exam such as SecurityX, which renews CySA+ automatically.

Is CySA+ approved for DoD 8140?

Yes. CySA+ appears on the DoD 8140 Approved Qualifications Matrix V2.1 mapped to ten DCWF work roles, at the Advanced proficiency level on nine of them, including Cyber Defense Analyst, Cyber Defense Incident Responder, and Vulnerability Assessment Analyst, and at the Intermediate level for Cyber Defense Infrastructure Support Specialist. See the full DoD 8140 work role paths.

What is the difference between CySA+ and Security+?

Security+ is the foundational credential that proves you understand security concepts; CySA+ proves you can do the analyst job those concepts support. Security+ has no experience expectation and a 90-minute exam; CySA+ recommends about 4 years of SOC or vulnerability work and runs 165 minutes with heavier performance-based content. Most people earn Security+ first and step up to CySA+ for analyst roles.

What is the difference between CySA+ and PenTest+?

They're two sides of the same fight. CySA+ is the blue team credential, focused on detecting, analyzing, and responding to attacks. PenTest+ is the red team credential, focused on planning and executing penetration tests. Both sit at the same intermediate tier and both are DoD 8140 approved; the choice comes down to whether you want to defend systems or legally attack them.

Get In Touch

Have Questions About CySA+?

Whether you're weighing the certification, working out funding, or planning training for a team, tell us where you are and we'll help you map out the right path.

+1
    100% Secure. NDA Compliant.
    CompTIA CySA+ Boot Camp 4 Days · Exam Voucher Included
    View Boot Camp