Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Certification Guide

The CompTIA SecAI+
Certification Explained.

Everything you need to know about CompTIA SecAI+, CompTIA's first AI-security certification and the opening credential in its new Expansion Series, as of 2026. This guide covers the CY0-001 exam, the four domains and their weights, the frameworks it is built on, DoD 8140 status, and where it sits in the fast-emerging AI certification landscape.

SECAI_FAST_FACTS
Issuer: CompTIA
Exam: CY0-001, up to 60 questions, 60 min
Passing Score: 600 / 900
Prerequisites: None (Security+, CySA+ rec.)
Level: Specialty (Expansion Series)
1 Exam (CY0-001) 4 Domains 60 MIN Exam 600/900 To Pass SINCE FEB 2026 First AI Cert
UPDATED 2026
Overview

What Is CompTIA SecAI+?

CompTIA SecAI+ is CompTIA's first cybersecurity certification focused on artificial intelligence, launched in February 2026 as the opening credential in its new Expansion Series.

It validates two things security teams now need in the same person: the ability to secure AI systems against AI-specific threats, and the ability to use AI to strengthen security operations. It rounds that out with the governance side, applying frameworks like the NIST AI RMF and the EU AI Act to keep AI adoption compliant. CompTIA's own research found 56 percent of security professionals already use AI tools daily, while most organizations have no formal training on doing it safely, and SecAI+ is aimed squarely at that gap.

SecAI+ arrived as part of a wave. Across 2025 and 2026, AI security and governance credentials launched from nearly every major body, and SecAI+ is CompTIA's vendor-neutral entry. It has no formal prerequisites, though it is not entry level, CompTIA recommends the Security+ then CySA+ path first. It is issued by CompTIA under exam code CY0-001.

4 Domains
600 To Pass (of 900)
0 Prerequisites
The SecAI+ Domains

Four Domains of CY0-001

I

Basic AI Concepts

AI and ML foundations, LLMs, and the vocabulary the rest builds on. 17% of the exam.

II

Securing AI Systems

Defending against prompt injection, data poisoning, and adversarial attacks. The heaviest domain at 40%.

III

AI-Assisted Security

Using AI for detection, response, and SOC automation. 24% of the exam.

IV

AI Governance, Risk, and Compliance

NIST AI RMF, ISO 42001, and EU AI Act risk tiers. 19% of the exam.

Why SecAI+ Matters

Why Is SecAI+ a First of Its Kind?

Four things that set SecAI+ apart as the opening move in a brand-new category of certification in 2026.

CompTIA's First AI Security Certification

SecAI+ is the first vendor-neutral certification built around securing AI systems and using AI in security operations. It is the opening credential in CompTIA's new Expansion Series, a category that sits alongside the traditional career-path certs rather than inside the usual A+ to Security+ ladder.

Built on the Real Frameworks

SecAI+ is grounded in the frameworks employers actually use: the NIST AI RMF, the OWASP Top 10 for LLMs, MITRE ATLAS, ISO/IEC 42001, and EU AI Act risk tiers. It tests real defenses, prompt injection, data poisoning, adversarial examples, secure MLOps, not surface-level AI awareness.

A Brand-New, Fast-Moving Category

AI security certification barely existed 18 months ago. Now credentials are launching from CompTIA, ISACA, IAPP, and EC-Council at once. Our guide to which AI certifications will actually matter in 2026 maps the wave.

Where SecAI+ Recognition Comes From

SecAI+ is too new to appear on the DoD 8140 Matrix V2.1, so on its own it will not satisfy a cyber-coded position requirement today. Whether it is added in a future matrix update is worth watching. The current matrix is published at the DoD Cyber Exchange.

Its weight comes from the market and the moment. It is the first vendor-neutral AI security credential, it carries CompTIA's universal employer recognition, and it targets a skills gap organizations are hiring against right now.

First AI Security Cert Vendor-Neutral 3-Yr Validity
Fast Facts

What Are the Key Facts About SecAI+?

Everything you need to know about the certification, the CY0-001 exam, and how to maintain SecAI+ as of 2026.

01

The Certification

Certification Name
CompTIA SecAI+
Issued By
CompTIA
Exam Code
CY0-001 (V1)
Launched
February 17, 2026
Series
Expansion Series (first cert)
Level
Specialty (mid-level)
Prerequisites
None required
Recommended Path
Security+, then CySA+, then SecAI+
Accreditation
ANAB-accredited (ISO/IEC 17024)
DoD 8140 Status
Not listed in Matrix V2.1
02

Exam & Maintenance

Exam Format
Multiple choice and performance-based
Number of Questions
Maximum of 60
Exam Duration
60 minutes
Passing Score
600 (scale of 100 to 900)
Exam Cost
$298 voucher (CompTIA retail)
Delivery
Pearson VUE or OnVUE online
Languages
English and Japanese
Validity
3 years (CE renewal)
Frameworks
NIST AI RMF, OWASP LLM, MITRE ATLAS
The Bigger Picture

Where SecAI+ Fits in the AI Certification Wave.

SecAI+ did not arrive alone. In 2025 and 2026 the major certifying bodies each launched AI credentials, and they split cleanly by job. SecAI+ owns the hands-on practitioner lane, and CompTIA has signaled it is only the first, with AI-focused expansions planned for other pathways. The three tracks below cover the roles it deliberately does not.

AI Governance (IAPP AIGP)

For the policy and program side of AI. AIGP covers responsible AI governance, the legal and regulatory landscape, and building an AI governance program. It complements SecAI+'s technical focus with the compliance and policy view.

AI Security Management (ISACA AAISM)

For managers who set AI security strategy rather than implement it. AAISM sits at the management level, aligned to the CISM audience, where SecAI+ is for the practitioner who touches the keyboard.

AI Audit and Risk (ISACA AAIA, AAIR)

For those who verify and quantify rather than build. AAIA is for auditors checking AI controls, aligned to the CISA audience, and AAIR targets AI risk professionals. Together they cover the assurance side of the AI credential landscape.

Certification Roadmap

Where Does SecAI+ Fit in Your Career?

SecAI+ is a specialization, not a rung on the core ladder. It builds on Security+ and CySA+, then branches into the wider AI credential landscape depending on whether you build, manage, or audit AI.

STAGE 02 You Are Here

Specialize

The AI security credential

PRIMARY
SecAI+
CompTIA · Hands-on AI security (CY0-001)
Open Entry
No prerequisite credential, Security+ and CySA+ recommended
STAGE 03

Broaden

The AI credential landscape

Govern and Manage
Audit and Risk
Decision Point

Is SecAI+ Right For You?

Two questions to answer before you commit: can you sit it, and should you pursue SecAI+ specifically. Here's a straight answer to both.

Q1

Do You Qualify for SecAI+?

Short Answer

Anyone Can Sit CY0-001

No prerequisite credential required.

SecAI+ has no formal prerequisites, so there is nothing standing between you and the exam. Register, schedule through Pearson VUE, and take it at a test center or online through OnVUE. That open door is standard for CompTIA specialty exams.

Honest Caveat

It Is Not Entry Level

The exam assumes real security grounding.

CompTIA recommends three to four years of IT experience with at least two in security, plus the knowledge from Security+, CySA+, or PenTest+. The recommended path is Security+ then CySA+ then SecAI+. Come in without that base and the technical AI-security content will be a steep climb.

Q2

Is SecAI+ the Right Certification for Your Goals?

SecAI+ Is a Strong Fit If...

  • You are a security practitioner whose work now touches AI systems, tools, or threats
  • You already hold Security+ or CySA+ and want to specialize in the AI dimension
  • You want to prove hands-on skills like defending against prompt injection, data poisoning, and adversarial attacks
  • You are targeting AI security engineer, AI-focused analyst, or DevSecOps roles
  • You want an early-adopter advantage in a credential category that is just forming
  • Your organization is putting AI into production and needs people who can secure it

Consider Alternatives If...

  • You are brand new to security, where Security+ then CySA+ builds the base you need first
  • You need a DoD 8140 approved credential specifically, since SecAI+ is not on the matrix yet
  • Your role is AI governance and policy, where IAPP AIGP is the closer fit
  • You set AI security strategy as a manager, where ISACA AAISM targets that level
  • You audit or quantify AI risk, where ISACA AAIA or AAIR match the work
  • You want a conventional analyst path with the broadest recognition today, where CySA+ still leads
Career Paths

What Jobs Can You Get With SecAI+?

SecAI+ maps to the AI security roles organizations are creating as they move AI into production. Most run AI already, but few have dedicated AI security staff, which is the gap this credential speaks to.

Engineering

AI Security Engineer

Designs and implements the controls that protect AI systems, from model access and data pipelines to secure MLOps. The flagship destination for a SecAI+ holder on the technical track.

Operations

AI-Focused Security Analyst

Runs detection and response for AI-driven threats and uses AI tooling to speed up the SOC. SecAI+ maps directly to the analyst who has to defend against and work with AI daily.

SecOps

Security Operations Engineer

Builds the automation and detection pipelines a modern SOC runs on. The AI-assisted security domain lines up with the shift toward AI-augmented operations.

DevSecOps

DevSecOps Engineer

Integrates security, and now AI security, into CI/CD pipelines. SecAI+ covers securing AI components and models inside the delivery pipeline itself.

Consulting

AI Security Consultant

Advises organizations standing up AI systems on how to secure and govern them. The breadth of SecAI+, from technical defense to GRC, fits the advisory role well.

Governance

AI Risk and Compliance Specialist

Applies AI governance frameworks such as the NIST AI RMF and ISO/IEC 42001 to keep AI adoption compliant and defensible. The GRC domain is the bridge into this role.

Comparison

SecAI+ vs the ISACA AI Certifications.

The three most-confused AI security credentials all have "AI" in the name but are built for different people. Shortest version: SecAI+ implements, AAISM manages, AAIA audits.

  CompTIA SecAI+ ISACA AAISM ISACA AAIA
Issuer CompTIA ISACA ISACA
Who It's For Practitioners who implement AI security Managers who set AI security strategy Auditors who verify AI controls
Focus Hands-on AI security controls AI security program management AI audit and assurance
Level Specialty (mid-level) Advanced (management) Advanced (audit)
Prerequisites None (Security+, CySA+ rec.) Experience recommended Experience recommended
Aligned Audience Security engineers and analysts CISM-style security managers CISA-style IT auditors
DoD 8140 Not listed Not listed Not listed
Best For Building and defending AI systems Running an AI security program Assuring AI controls and compliance

All three are new AI credentials and none appears on the DoD 8140 Matrix yet. Pick by the work you do: implement, manage, or audit. Many teams end up holding more than one across different people.

Ready to Get Certified?

Train for SecAI+ with Training Camp.

Our CompTIA SecAI+ boot camp covers all four CY0-001 domains over four days, with hands-on labs for securing AI systems, using AI in the SOC, and applying AI governance frameworks, plus your exam voucher and an exam pass guarantee that includes a free retake, so you leave exam-ready.

View Boot Camp
Dive Deeper

SecAI+ and AI Certification Guides.

Whether SecAI+ is worth it, how it compares to the ISACA and EC-Council AI credentials, and how the whole AI cert landscape is taking shape.

Featured Worth It?

Is CompTIA SecAI+ Worth It?

A straight look at the case for SecAI+: the AI security skills gap, the early-adopter timing advantage, the salary premium data, and who should hold off. Written the month it launched.

Read Article →
The AI Cert Landscape

Which AI Certifications Will Actually Matter in 2026?

The map of the fast-emerging AI credential landscape, where SecAI+ fits among the governance, audit, and management certifications launching across every major body this year.

Read Article →
SecAI+ vs ISACA

CompTIA SecAI+ vs ISACA AI Certifications: A Direct Comparison

SecAI+, AAISM, and AAIA all have "AI" and "security" in the name but target completely different people. The plain-language guide to which one matches your actual job.

Read Article →
SecAI+ vs CySA+

CompTIA SecAI+ vs CySA+: What Comes Next After Security+

Why SecAI+ is not simply the next step after Security+, how it sits alongside CySA+ rather than above it, and how to choose based on where your career is headed.

Read Article →
Firsthand: The Beta

I Took the CompTIA SecAI+ Beta Exam: What You Need to Know

A firsthand account of sitting the SecAI+ beta, what the experience was actually like, how the material feels, and who the certification is really built for.

Read Article →
The Wider AI Wave

EC-Council's Four New AI Certifications: What Each One Validates

The wider AI wave beyond CompTIA and ISACA: EC-Council's AIE, CAIPM, COASP, and CRAGE, and which role each of the four is built for.

Read Article →
AI Risk (New)

AAIR Certification Guide: ISACA's New AI Risk Credential

A look at ISACA's AAIR, the AI risk credential built for CRISC holders and risk professionals, and how AI risk is becoming its own certification track.

Read Article →
Curriculum

Inside the Four SecAI+ Domains.

The CY0-001 exam is organized into four domains. Securing AI Systems dominates at 40 percent, so it is where most of your study should go. Click any domain for what it covers.

Domains I-II

Concepts and Defense
I Basic AI Concepts 17%

The AI and machine learning foundations a security professional needs: model types, training data, large language models and generative AI, and the vocabulary that the rest of the exam and the job build on.

II Securing AI Systems 40%

The largest domain. Defending AI systems against AI-specific threats: prompt injection, data poisoning, adversarial examples, model inversion and membership inference, model theft, secure MLOps, retrieval-augmented generation and vector database security, and model access controls.

Domains III-IV

Operations and Governance
III AI-Assisted Security 24%

Using AI to strengthen security operations: AI-assisted threat detection, triage and incident response, automating security workflows, and integrating AI safely into DevSecOps pipelines and the SOC.

IV AI Governance, Risk, and Compliance 19%

Governing AI responsibly: applying the NIST AI Risk Management Framework, ISO/IEC 42001, and EU AI Act risk tiers, managing third-party and model risk, and meeting the ethical and legal obligations of AI deployment.

Domains and weights reflect the CompTIA SecAI+ CY0-001 exam objectives. As a new certification, SecAI+ may see early refinements, so confirm the current objectives on CompTIA's site before scheduling.

Frequently Asked Questions

Common Questions About SecAI+.

The questions candidates ask most often when researching the CompTIA SecAI+ certification.

What is CompTIA SecAI+?

CompTIA SecAI+ is CompTIA's first certification focused on the intersection of artificial intelligence and cybersecurity. It validates the ability to secure AI systems, use AI tools to strengthen security operations, and govern AI responsibly. It's the first credential in CompTIA's new Expansion Series, designed to complement core certifications like Security+ and CySA+ rather than replace them.

When was CompTIA SecAI+ released?

CompTIA launched SecAI+ on February 17, 2026, under exam code CY0-001. It followed a public beta that closed in late 2025. As a brand-new certification, its resources and objectives are still settling in, so it's worth confirming the current exam objectives on the Official CompTIA page before you schedule.

What is the SecAI+ exam like?

The SecAI+ exam, CY0-001, has a maximum of 60 questions to complete in 60 minutes. It uses multiple-choice and performance-based questions, and the passing score is 600 on a scale of 100 to 900. Because CompTIA uses scaled scoring, 600 does not mean 60 percent correct. Performance-based questions put you into scenarios rather than testing recall alone.

What are the four SecAI+ domains?

The four domains are Basic AI Concepts (17 percent), Securing AI Systems (40 percent), AI-Assisted Security (24 percent), and AI Governance, Risk, and Compliance (19 percent). Securing AI Systems is by far the largest domain, so it deserves the most study time.

Are there prerequisites for SecAI+?

No formal prerequisites, so anyone can register and sit the exam. SecAI+ isn't an entry-level credential, though. CompTIA recommends three to four years of IT experience with at least two in cybersecurity, plus the knowledge from Security+, CySA+, or PenTest+. The recommended path is Security+ then CySA+ then SecAI+.

How much does the SecAI+ exam cost?

As of 2026, the SecAI+ CY0-001 exam voucher costs $298 USD at CompTIA retail, with small regional variations. Training Camp's SecAI+ boot camp includes the exam voucher in the program fee. Because pricing on a new certification can shift, confirm the current fee on the CompTIA store before booking.

What frameworks does SecAI+ cover?

SecAI+ is built around the recognized AI security and governance frameworks: the NIST AI Risk Management Framework, the OWASP Top 10 for large language models, MITRE ATLAS, ISO/IEC 42001, and the EU AI Act risk tiers. The technical content includes prompt injection, data poisoning, adversarial examples, model inversion, secure MLOps, and retrieval-augmented generation security.

Is SecAI+ on DoD 8140?

Not yet. SecAI+ doesn't appear on the DoD 8140 Approved Qualifications Matrix V2.1, which is expected for a certification this new. Its value today is market-driven: it's the first vendor-neutral AI security credential, and it addresses a skills gap that federal and enterprise employers are actively hiring against. Whether it's added to the matrix in a future update is something to watch. See the current DoD 8140 work role paths.

SecAI+ vs CySA+, which comes next after Security+?

For most people, CySA+ is the more conventional next step after Security+, and it carries DoD 8140 recognition that SecAI+ doesn't have yet. SecAI+ sits alongside CySA+ rather than above it, as a specialization for professionals who already have intermediate security skills and want to prove AI-security capability. Choose CySA+ for a proven analyst path, or SecAI+ to get ahead of the AI curve.

SecAI+ vs the ISACA AI certifications, which is right for me?

It comes down to your role. SecAI+ is for practitioners who implement AI security controls hands-on. ISACA's AAISM is for managers who set AI security strategy. ISACA's AAIA is for auditors who verify AI controls, and its AAIR targets AI risk professionals. They share the AI theme but are built for different jobs, so match the credential to the work you actually do.

What jobs can you get with SecAI+?

SecAI+ maps to roles such as AI Security Engineer, AI-Focused Security Analyst, Security Operations Engineer, DevSecOps Engineer, AI Security Consultant, and AI Risk and Compliance Specialist. With most organizations running AI in production but few having dedicated AI security staff, professionals who can prove these skills are in demand.

How long is SecAI+ valid and how do you renew it?

SecAI+ carries the Continuing Education designation and is valid for three years from your pass date. You renew it by earning continuing education units through CompTIA's Continuing Education program across the three-year cycle, or by retaking the current exam version.

Is CompTIA SecAI+ worth it in 2026?

For security professionals whose work now touches AI, there's a strong case: the skills gap is real, the salary premium for AI security skills is real, and being early carries a timing advantage. It's less suited to those brand new to security, who should build core skills first, or to executives focused purely on governance, where a management or governance credential fits better.

Get In Touch

Have Questions About SecAI+?

Whether you're weighing SecAI+ against CySA+ or the ISACA AI certs, or planning AI-security training for a team, tell us where you are and we'll help you map out the right path.

+1
    100% Secure. NDA Compliant.
    CompTIA SecAI+ Boot Camp 4 Days · Exam Voucher & Pass Guarantee
    View Boot Camp