Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about the CySA+ certification as of 2026, covering the four domains under the new V4 exam live since June 23, 2026, the exam format, recommended experience, career outcomes, DoD 8140 status, and how CySA+ compares to Security+ and PenTest+. A complete reference guide for anyone weighing the CySA+ or trying to understand what it covers.
Detecting malicious activity with SIEM, EDR, and threat hunting, plus AI in the SOC. The heaviest domain at 34%.
Scanning, analyzing findings, and prioritizing fixes with risk-based approaches. 26% of the exam.
Frameworks, the response process, and hands-on techniques. Grew to 24% in V4.
Reports, dashboards, post-incident reviews, and SOC metrics. 16% of the exam.
CySA+ is CompTIA's intermediate cybersecurity analyst certification, first administered in 2017 and built for the defensive side of security: detecting, analyzing, and responding to threats.
It sits between Security+ and the expert-level SecurityX on CompTIA's cybersecurity path, and it tests the work SOC analysts actually do: analyzing logs and indicators, running vulnerability programs, responding to incidents, and reporting findings, with heavy use of performance-based questions rather than pure recall. A new V4 exam (CS0-004) went live on June 23, 2026, adding AI in security operations to the objectives and rebalancing the four domains, so most guides you'll find still describe the outgoing version.
The credential is ANAB-accredited under ISO/IEC 17024, approved under DoD 8140 across ten DCWF work roles, and renewed through continuing education. CySA+ is issued and maintained by CompTIA, the body behind Security+ and the largest vendor-neutral certification program in IT.
Four things that make CySA+ the standard validation for defensive security roles in 2026.
CySA+ tests whether you can do the analyst job, not just describe it. Performance-based questions put real log output, vulnerability scan results, and incident scenarios in front of you, which is why hiring managers treat it as evidence of working skill. The credential is ANAB-accredited under the ISO/IEC 17024 personnel certification standard.
The V4 exam, live since June 23, 2026, adds AI in security operations as a named objective: use cases, risks, and governance. The outgoing CS0-003 English exam remains available through December 22, 2026.
Banks, hospitals, agencies, and retailers all staff SOCs, and CySA+ maps to the roles they hire for. For the unfiltered picture of the work itself, read what a SOC analyst actually does all day.
CySA+ is an approved qualification under DoD Manual 8140.03, mapped to ten work roles in the DoD Cyber Workforce Framework (DCWF) at the Advanced proficiency level on nine of them, including Cyber Defense Analyst, Cyber Defense Incident Responder, and Vulnerability Assessment Analyst.
The mappings span four workforce elements, including the Intelligence (Cyberspace) element through the All-Source Analyst role, unusual reach for an intermediate certification. Current qualification matrices are published at the DoD Cyber Exchange.
Everything you need to know about the certification, the exam structure, and how to maintain CySA+ as of 2026.
From the analyst seat, the paths branch three ways: cross to the offensive side, climb to the expert tier, or specialize in the AI security work now landing in every SOC.
The red team counterpart at the same tier. Analysts who understand how attacks are actually executed become sharper defenders, and many SOC professionals hold both credentials.
CompTIA's expert-level credential, formerly known as CASP+, covering enterprise security architecture and engineering. Passing it also renews CySA+ automatically under the CE program.
CompTIA's newest specialty, launched February 2026, goes deep on securing AI systems and using AI in security work. It pairs naturally with the analyst foundation CySA+ builds.
CySA+ is the middle of CompTIA's cybersecurity ladder: networking and security fundamentals build toward it, and offensive, expert, and leadership tracks branch out from it.
Build the baseline
The SOC standard
Two questions to answer before you commit: are you ready for the exam, and is CySA+ the right certification for your goals. Here's a straight answer to both.
You can sit the exam now.
There are no enforced prerequisites, so anyone can register. CompTIA recommends about 4 years in a SOC analyst or vulnerability analyst role for the V4 exam, and the performance-based questions assume you've actually read logs and scan output before. If you have Security+ level knowledge plus hands-on defensive work, you're in the exam's target zone.
Start with Security+.
If you're coming from general IT or early in your security career, Security+ first is the well-worn path. It covers the concepts CySA+ assumes you already hold, it's the credential entry-level security postings ask for by name, and the step from Security+ into CySA+ is exactly the jump CompTIA designed the ladder around.
CySA+ maps to defensive security roles across the private sector and the federal cyber workforce. Every card below is a DCWF work role verified on the DoD 8140 Matrix V2.1.
The SOC analyst role: monitoring, triaging, and investigating alerts across the enterprise. DCWF work role 511, where CySA+ qualifies at the Advanced proficiency level under DoD 8140.
Contains, eradicates, and recovers from confirmed security incidents. DCWF work role 531, mapped to CySA+ at the Advanced level and drawing directly on Domain 3.
Finds and prioritizes the weaknesses attackers would use first. DCWF work role 541, where CySA+ qualifies at the Advanced level, the exact skill set Domain 2 tests.
Analyzes digital evidence to reconstruct what happened during an intrusion. DCWF work role 212, mapped to CySA+ at the Advanced level.
Fuses intelligence from multiple sources to assess cyber threats. DCWF work role 111 in the Intelligence (Cyberspace) workforce element, where CySA+ qualifies at the Advanced level.
Evaluates whether security controls are implemented correctly and operating as intended. DCWF work role 612, mapped to CySA+ at the Advanced level.
Three CompTIA security credentials, three different jobs. Here's how they line up.
| CySA+ | Security+ | PenTest+ | |
|---|---|---|---|
| Issuer | CompTIA | CompTIA | CompTIA |
| Focus | Threat detection and response (blue team) | Security fundamentals | Penetration testing (red team) |
| Current Exam | CS0-004 | SY0-701 | PT0-003 |
| Exam Format | Max 85 questions, 165 minutes | Max 90 questions, 90 minutes | Max 90 questions, 165 minutes |
| Passing Score | 750 out of 900 | 750 out of 900 | 750 out of 900 |
| Recommended Experience | About 4 yrs, SOC or vulnerability analyst | About 2 yrs in a security or IT role | 3 to 4 yrs in a penetration testing role |
| Renewal | 60 CEUs over 3 years | 50 CEUs over 3 years | 60 CEUs over 3 years |
| DoD 8140 Approved | Yes (10 roles, Advanced on 9) | Yes (20 roles, Intermediate) | Yes (10 roles) |
| Best For | SOC analysts and incident responders | Breaking into cybersecurity | Aspiring penetration testers |
All three renew through CompTIA's Continuing Education program, and passing a higher-level exam renews the ones below it. Many defenders eventually add PenTest+ to understand the attacks they're detecting.
Our CompTIA CySA+ boot camp covers all four domains over four days, with hands-on labs, your exam voucher, and a pass guarantee included, so working analysts leave exam-ready.
Certification decisions, SOC career reality checks, and salary data for the defensive security track.
CompTIA's new SecAI+ certification gave the "what comes after Security+" question two very different answers. A domain-by-domain breakdown of both paths and how to pick the one that fits your career.
The unfiltered picture of the job CySA+ trains you for: alert triage, tier structures, shift work, the burnout risk nobody mentions in job postings, and who actually thrives in the role.
An honest take on the certification most CySA+ candidates earn first, including who it actually helps, what it pays, and the technical tracks that branch out from it.
Where the salary ceiling actually sits across security roles, from SOC analysts and consultants to managers and CISOs, and which certifications show up in the highest-paying postings.
The realistic paths out of IT operations, including the cybersecurity pivot that runs from Security+ through CySA+ into SOC analyst territory, with timelines and salary expectations.
Which credentials actually move a resume to the top of the pile, which ones hiring managers ignore, and how certifications weigh against experience in real hiring decisions.
Salary benchmarks by role, experience, and geography for the Security+ baseline, including the estimated pay impact of stacking CySA+ and other credentials on top of it.
The V4 exam objectives organize CySA+ into four domains, each carrying its own weight on the exam. Click any domain for what it covers.
The heart of the exam and of the job: analyzing indicators of malicious activity across networks, endpoints, cloud, and identity systems using SIEM, EDR, and packet analysis tools, plus threat intelligence, threat hunting, and the V4 addition of AI use, risks, and governance in security operations.
Running the vulnerability program end to end: choosing the right scanning method, analyzing assessment tool output, and prioritizing and mitigating findings using risk-based approaches, scoring systems, and business context.
What to do when detection turns into an incident: attack methodology frameworks like MITRE ATT&CK and the Cyber Kill Chain, the response process from preparation through recovery, and hands-on techniques including triage, evidence handling, and root cause identification.
Turning technical findings into action: vulnerability and incident reporting, dashboards, post-incident reviews, and the metrics that measure a SOC, such as detection time, response time, and remediation effectiveness.
Domains and weights reflect the CompTIA CySA+ V4 (CS0-004) exam objectives, live since June 23, 2026. The prior CS0-003 English exam remains available through December 22, 2026.
The questions candidates ask most often when researching the CompTIA Cybersecurity Analyst certification.
CySA+ is CompTIA's intermediate cybersecurity analyst certification. It validates the ability to detect, analyze, and respond to threats: analyzing logs and indicators with SIEM and EDR tools, managing vulnerabilities, responding to incidents, and communicating findings. It sits above Security+ and below the expert-level SecurityX on CompTIA's cybersecurity path.
CySA+ fits professionals headed into or already working defensive security roles: SOC analysts, incident responders, vulnerability analysts, and threat hunters. CompTIA recommends about 4 years in a SOC analyst or vulnerability analyst role for the V4 exam, though there's no enforced prerequisite. If you're newer to security, Security+ is usually the better first step.
The CySA+ V4 exam (CS0-004) has a maximum of 85 questions delivered over 165 minutes, mixing multiple choice with performance-based questions where you analyze log output, interpret scan results, and work through simulated scenarios. The passing score is 750 on a scale of 100 to 900.
CySA+ V4 (CS0-004) launched June 23, 2026. The four domain names stay the same but the weights rebalanced: Security Operations moved to 34 percent, Vulnerability Management to 26, Incident Response and Management to 24, and Reporting and Communication to 16. The biggest addition is AI in security operations, covering AI use cases, risks, and governance, which the prior exam didn't address.
Yes, for now. CompTIA is running a transition window: the English CS0-003 exam remains available through December 22, 2026, with translated versions available until March 23, 2027. If you're deep into CS0-003 preparation you can still test on it; if you're starting fresh, prepare for CS0-004.
There's no enforced prerequisite, so anyone can register. CompTIA recommends about 4 years in a SOC analyst or vulnerability analyst role for the V4 exam. In practice, the exam assumes Security+ level knowledge of networks, security concepts, and defensive tooling, and candidates without that foundation tend to struggle.
Not formally. There's no required prerequisite for CySA+. But the exam builds directly on Security+ level knowledge, and most successful candidates either hold Security+ or have equivalent working knowledge. If you're starting from general IT, Security+ first is the well-worn path.
Under the V4 (CS0-004) objectives, they are Security Operations at 34 percent, Vulnerability Management at 26 percent, Incident Response and Management at 24 percent, and Reporting and Communication at 16 percent.
It's a meaningful step up from Security+. The performance-based questions require actually doing analyst work: reading logs, interpreting vulnerability scan output, and making incident response decisions under time pressure. Candidates with real SOC exposure find it fair; candidates relying on memorization find it punishing. Hands-on practice with SIEM output and scan results is the difference-maker.
CySA+ is valid for three years through CompTIA's Continuing Education program. You renew by earning 60 continuing education units (CEUs) across the cycle and paying CompTIA's annual CE fee, or by passing a higher-level CompTIA exam such as SecurityX, which renews CySA+ automatically.
Yes. CySA+ appears on the DoD 8140 Approved Qualifications Matrix V2.1 mapped to ten DCWF work roles, at the Advanced proficiency level on nine of them, including Cyber Defense Analyst, Cyber Defense Incident Responder, and Vulnerability Assessment Analyst, and at the Intermediate level for Cyber Defense Infrastructure Support Specialist. See the full DoD 8140 work role paths.
Security+ is the foundational credential that proves you understand security concepts; CySA+ proves you can do the analyst job those concepts support. Security+ has no experience expectation and a 90-minute exam; CySA+ recommends about 4 years of SOC or vulnerability work and runs 165 minutes with heavier performance-based content. Most people earn Security+ first and step up to CySA+ for analyst roles.
They're two sides of the same fight. CySA+ is the blue team credential, focused on detecting, analyzing, and responding to attacks. PenTest+ is the red team credential, focused on planning and executing penetration tests. Both sit at the same intermediate tier and both are DoD 8140 approved; the choice comes down to whether you want to defend systems or legally attack them.
Whether you're weighing the certification, working out funding, or planning training for a team, tell us where you are and we'll help you map out the right path.