Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about CompTIA SecAI+, CompTIA's first AI-security certification and the opening credential in its new Expansion Series, as of 2026. This guide covers the CY0-001 exam, the four domains and their weights, the frameworks it is built on, DoD 8140 status, and where it sits in the fast-emerging AI certification landscape.
CompTIA SecAI+ is CompTIA's first cybersecurity certification focused on artificial intelligence, launched in February 2026 as the opening credential in its new Expansion Series.
It validates two things security teams now need in the same person: the ability to secure AI systems against AI-specific threats, and the ability to use AI to strengthen security operations. It rounds that out with the governance side, applying frameworks like the NIST AI RMF and the EU AI Act to keep AI adoption compliant. CompTIA's own research found 56 percent of security professionals already use AI tools daily, while most organizations have no formal training on doing it safely, and SecAI+ is aimed squarely at that gap.
SecAI+ arrived as part of a wave. Across 2025 and 2026, AI security and governance credentials launched from nearly every major body, and SecAI+ is CompTIA's vendor-neutral entry. It has no formal prerequisites, though it is not entry level, CompTIA recommends the Security+ then CySA+ path first. It is issued by CompTIA under exam code CY0-001.
AI and ML foundations, LLMs, and the vocabulary the rest builds on. 17% of the exam.
Defending against prompt injection, data poisoning, and adversarial attacks. The heaviest domain at 40%.
Using AI for detection, response, and SOC automation. 24% of the exam.
NIST AI RMF, ISO 42001, and EU AI Act risk tiers. 19% of the exam.
Four things that set SecAI+ apart as the opening move in a brand-new category of certification in 2026.
SecAI+ is the first vendor-neutral certification built around securing AI systems and using AI in security operations. It is the opening credential in CompTIA's new Expansion Series, a category that sits alongside the traditional career-path certs rather than inside the usual A+ to Security+ ladder.
SecAI+ is grounded in the frameworks employers actually use: the NIST AI RMF, the OWASP Top 10 for LLMs, MITRE ATLAS, ISO/IEC 42001, and EU AI Act risk tiers. It tests real defenses, prompt injection, data poisoning, adversarial examples, secure MLOps, not surface-level AI awareness.
AI security certification barely existed 18 months ago. Now credentials are launching from CompTIA, ISACA, IAPP, and EC-Council at once. Our guide to which AI certifications will actually matter in 2026 maps the wave.
SecAI+ is too new to appear on the DoD 8140 Matrix V2.1, so on its own it will not satisfy a cyber-coded position requirement today. Whether it is added in a future matrix update is worth watching. The current matrix is published at the DoD Cyber Exchange.
Its weight comes from the market and the moment. It is the first vendor-neutral AI security credential, it carries CompTIA's universal employer recognition, and it targets a skills gap organizations are hiring against right now.
Everything you need to know about the certification, the CY0-001 exam, and how to maintain SecAI+ as of 2026.
SecAI+ did not arrive alone. In 2025 and 2026 the major certifying bodies each launched AI credentials, and they split cleanly by job. SecAI+ owns the hands-on practitioner lane, and CompTIA has signaled it is only the first, with AI-focused expansions planned for other pathways. The three tracks below cover the roles it deliberately does not.
For the policy and program side of AI. AIGP covers responsible AI governance, the legal and regulatory landscape, and building an AI governance program. It complements SecAI+'s technical focus with the compliance and policy view.
For managers who set AI security strategy rather than implement it. AAISM sits at the management level, aligned to the CISM audience, where SecAI+ is for the practitioner who touches the keyboard.
For those who verify and quantify rather than build. AAIA is for auditors checking AI controls, aligned to the CISA audience, and AAIR targets AI risk professionals. Together they cover the assurance side of the AI credential landscape.
SecAI+ is a specialization, not a rung on the core ladder. It builds on Security+ and CySA+, then branches into the wider AI credential landscape depending on whether you build, manage, or audit AI.
The security groundwork
The AI security credential
The AI credential landscape
Two questions to answer before you commit: can you sit it, and should you pursue SecAI+ specifically. Here's a straight answer to both.
No prerequisite credential required.
SecAI+ has no formal prerequisites, so there is nothing standing between you and the exam. Register, schedule through Pearson VUE, and take it at a test center or online through OnVUE. That open door is standard for CompTIA specialty exams.
The exam assumes real security grounding.
CompTIA recommends three to four years of IT experience with at least two in security, plus the knowledge from Security+, CySA+, or PenTest+. The recommended path is Security+ then CySA+ then SecAI+. Come in without that base and the technical AI-security content will be a steep climb.
SecAI+ maps to the AI security roles organizations are creating as they move AI into production. Most run AI already, but few have dedicated AI security staff, which is the gap this credential speaks to.
Designs and implements the controls that protect AI systems, from model access and data pipelines to secure MLOps. The flagship destination for a SecAI+ holder on the technical track.
Runs detection and response for AI-driven threats and uses AI tooling to speed up the SOC. SecAI+ maps directly to the analyst who has to defend against and work with AI daily.
Builds the automation and detection pipelines a modern SOC runs on. The AI-assisted security domain lines up with the shift toward AI-augmented operations.
Integrates security, and now AI security, into CI/CD pipelines. SecAI+ covers securing AI components and models inside the delivery pipeline itself.
Advises organizations standing up AI systems on how to secure and govern them. The breadth of SecAI+, from technical defense to GRC, fits the advisory role well.
Applies AI governance frameworks such as the NIST AI RMF and ISO/IEC 42001 to keep AI adoption compliant and defensible. The GRC domain is the bridge into this role.
The three most-confused AI security credentials all have "AI" in the name but are built for different people. Shortest version: SecAI+ implements, AAISM manages, AAIA audits.
| CompTIA SecAI+ | ISACA AAISM | ISACA AAIA | |
|---|---|---|---|
| Issuer | CompTIA | ISACA | ISACA |
| Who It's For | Practitioners who implement AI security | Managers who set AI security strategy | Auditors who verify AI controls |
| Focus | Hands-on AI security controls | AI security program management | AI audit and assurance |
| Level | Specialty (mid-level) | Advanced (management) | Advanced (audit) |
| Prerequisites | None (Security+, CySA+ rec.) | Experience recommended | Experience recommended |
| Aligned Audience | Security engineers and analysts | CISM-style security managers | CISA-style IT auditors |
| DoD 8140 | Not listed | Not listed | Not listed |
| Best For | Building and defending AI systems | Running an AI security program | Assuring AI controls and compliance |
All three are new AI credentials and none appears on the DoD 8140 Matrix yet. Pick by the work you do: implement, manage, or audit. Many teams end up holding more than one across different people.
Our CompTIA SecAI+ boot camp covers all four CY0-001 domains over four days, with hands-on labs for securing AI systems, using AI in the SOC, and applying AI governance frameworks, plus your exam voucher and an exam pass guarantee that includes a free retake, so you leave exam-ready.
Whether SecAI+ is worth it, how it compares to the ISACA and EC-Council AI credentials, and how the whole AI cert landscape is taking shape.
A straight look at the case for SecAI+: the AI security skills gap, the early-adopter timing advantage, the salary premium data, and who should hold off. Written the month it launched.
The map of the fast-emerging AI credential landscape, where SecAI+ fits among the governance, audit, and management certifications launching across every major body this year.
SecAI+, AAISM, and AAIA all have "AI" and "security" in the name but target completely different people. The plain-language guide to which one matches your actual job.
Why SecAI+ is not simply the next step after Security+, how it sits alongside CySA+ rather than above it, and how to choose based on where your career is headed.
A firsthand account of sitting the SecAI+ beta, what the experience was actually like, how the material feels, and who the certification is really built for.
The wider AI wave beyond CompTIA and ISACA: EC-Council's AIE, CAIPM, COASP, and CRAGE, and which role each of the four is built for.
A look at ISACA's AAIR, the AI risk credential built for CRISC holders and risk professionals, and how AI risk is becoming its own certification track.
The CY0-001 exam is organized into four domains. Securing AI Systems dominates at 40 percent, so it is where most of your study should go. Click any domain for what it covers.
The AI and machine learning foundations a security professional needs: model types, training data, large language models and generative AI, and the vocabulary that the rest of the exam and the job build on.
The largest domain. Defending AI systems against AI-specific threats: prompt injection, data poisoning, adversarial examples, model inversion and membership inference, model theft, secure MLOps, retrieval-augmented generation and vector database security, and model access controls.
Using AI to strengthen security operations: AI-assisted threat detection, triage and incident response, automating security workflows, and integrating AI safely into DevSecOps pipelines and the SOC.
Governing AI responsibly: applying the NIST AI Risk Management Framework, ISO/IEC 42001, and EU AI Act risk tiers, managing third-party and model risk, and meeting the ethical and legal obligations of AI deployment.
Domains and weights reflect the CompTIA SecAI+ CY0-001 exam objectives. As a new certification, SecAI+ may see early refinements, so confirm the current objectives on CompTIA's site before scheduling.
The questions candidates ask most often when researching the CompTIA SecAI+ certification.
CompTIA SecAI+ is CompTIA's first certification focused on the intersection of artificial intelligence and cybersecurity. It validates the ability to secure AI systems, use AI tools to strengthen security operations, and govern AI responsibly. It's the first credential in CompTIA's new Expansion Series, designed to complement core certifications like Security+ and CySA+ rather than replace them.
CompTIA launched SecAI+ on February 17, 2026, under exam code CY0-001. It followed a public beta that closed in late 2025. As a brand-new certification, its resources and objectives are still settling in, so it's worth confirming the current exam objectives on the Official CompTIA page before you schedule.
The SecAI+ exam, CY0-001, has a maximum of 60 questions to complete in 60 minutes. It uses multiple-choice and performance-based questions, and the passing score is 600 on a scale of 100 to 900. Because CompTIA uses scaled scoring, 600 does not mean 60 percent correct. Performance-based questions put you into scenarios rather than testing recall alone.
The four domains are Basic AI Concepts (17 percent), Securing AI Systems (40 percent), AI-Assisted Security (24 percent), and AI Governance, Risk, and Compliance (19 percent). Securing AI Systems is by far the largest domain, so it deserves the most study time.
No formal prerequisites, so anyone can register and sit the exam. SecAI+ isn't an entry-level credential, though. CompTIA recommends three to four years of IT experience with at least two in cybersecurity, plus the knowledge from Security+, CySA+, or PenTest+. The recommended path is Security+ then CySA+ then SecAI+.
As of 2026, the SecAI+ CY0-001 exam voucher costs $298 USD at CompTIA retail, with small regional variations. Training Camp's SecAI+ boot camp includes the exam voucher in the program fee. Because pricing on a new certification can shift, confirm the current fee on the CompTIA store before booking.
SecAI+ is built around the recognized AI security and governance frameworks: the NIST AI Risk Management Framework, the OWASP Top 10 for large language models, MITRE ATLAS, ISO/IEC 42001, and the EU AI Act risk tiers. The technical content includes prompt injection, data poisoning, adversarial examples, model inversion, secure MLOps, and retrieval-augmented generation security.
Not yet. SecAI+ doesn't appear on the DoD 8140 Approved Qualifications Matrix V2.1, which is expected for a certification this new. Its value today is market-driven: it's the first vendor-neutral AI security credential, and it addresses a skills gap that federal and enterprise employers are actively hiring against. Whether it's added to the matrix in a future update is something to watch. See the current DoD 8140 work role paths.
For most people, CySA+ is the more conventional next step after Security+, and it carries DoD 8140 recognition that SecAI+ doesn't have yet. SecAI+ sits alongside CySA+ rather than above it, as a specialization for professionals who already have intermediate security skills and want to prove AI-security capability. Choose CySA+ for a proven analyst path, or SecAI+ to get ahead of the AI curve.
It comes down to your role. SecAI+ is for practitioners who implement AI security controls hands-on. ISACA's AAISM is for managers who set AI security strategy. ISACA's AAIA is for auditors who verify AI controls, and its AAIR targets AI risk professionals. They share the AI theme but are built for different jobs, so match the credential to the work you actually do.
SecAI+ maps to roles such as AI Security Engineer, AI-Focused Security Analyst, Security Operations Engineer, DevSecOps Engineer, AI Security Consultant, and AI Risk and Compliance Specialist. With most organizations running AI in production but few having dedicated AI security staff, professionals who can prove these skills are in demand.
SecAI+ carries the Continuing Education designation and is valid for three years from your pass date. You renew it by earning continuing education units through CompTIA's Continuing Education program across the three-year cycle, or by retaking the current exam version.
For security professionals whose work now touches AI, there's a strong case: the skills gap is real, the salary premium for AI security skills is real, and being early carries a timing advantage. It's less suited to those brand new to security, who should build core skills first, or to executives focused purely on governance, where a management or governance credential fits better.
Whether you're weighing SecAI+ against CySA+ or the ISACA AI certs, or planning AI-security training for a team, tell us where you are and we'll help you map out the right path.