Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Certification Guide

The CompTIA SecurityX
Certification Explained.

Everything you need to know about CompTIA SecurityX, the expert-level capstone of the CompTIA cybersecurity pathway, as of 2026. This guide covers the CAS-005 exam, the four domains and their weights, the pass/fail format, DoD 8140 status, the senior roles it opens, and how it compares to CISSP and CySA+.

SECURITYX_FAST_FACTS
Issuer: CompTIA
Exam: CAS-005, up to 90 questions, 165 min
Scoring: Pass/fail (no scaled score)
Prerequisites: None (10 yrs recommended)
DoD 8140 Approved (Advanced)
1 Exam (CAS-005) 4 Domains 165 MIN Exam PASS/FAIL Scoring EXPERT Level
UPDATED 2026
The SecurityX Domains

Four Domains of CAS-005

I

Governance, Risk, and Compliance

Enterprise governance, regulatory alignment, and third-party risk. 20% of the exam.

II

Security Architecture

Secure design across on-premises, cloud, and hybrid environments, including zero trust.

III

Security Engineering

Cryptography, secure cloud, automation, and control implementation. The heaviest domain at 31%.

IV

Security Operations

Threat management, incident response, detection engineering, and vulnerability management.

Overview

What Is CompTIA SecurityX?

CompTIA SecurityX, formerly CompTIA Advanced Security Practitioner (CASP+), is CompTIA's expert-level cybersecurity certification and the capstone of its security pathway.

It validates the ability to architect, engineer, and integrate secure solutions across complex enterprise environments. The point is not recall. It is proving you can make senior judgment calls the way a security architect or lead engineer has to, choosing between competing designs, balancing risk against the business, and building controls that hold up in production.

SecurityX is vendor-neutral, ISO/IEC 17024 accredited, and approved under DoD 8140 at the Advanced proficiency level. It has no formal prerequisites, though CompTIA recommends 10 years of IT experience including 5 in security. The credential is issued and maintained by CompTIA, which rebranded it from CASP+ with the CAS-005 exam in December 2024.

2024 CAS-005 Released
4 Domains
0 Prerequisites
Why SecurityX Matters

Why Is SecurityX the Technical Capstone?

Four things that set SecurityX apart as the expert-level credential for senior security architects and engineers in 2026.

The Expert Tier of the CompTIA Pathway

Security+ proves you understand security fundamentals and CySA+ proves you can analyze threats. SecurityX proves you can architect and lead an entire security posture. It sits at the top of the CompTIA cybersecurity track, the difference between knowing how a firewall works and designing the architecture that decides where firewalls go.

Hands-On, Not Memorization

SecurityX is scored pass or fail with no published passing score, and it leans heavily on performance-based questions. Those are hands-on simulations where you configure controls, analyze logs, and choose between competing designs. You cannot memorize your way through them.

Technical, Where CISSP Is Managerial

SecurityX targets the senior engineer who designs and implements security architectures but does not necessarily manage teams or budgets. Our guide to the newest 2026 certifications covers how it stacks up.

DoD 8140 Approved at Advanced

SecurityX is an approved qualification under DoD Manual 8140.03, listed on the Approved Qualifications Matrix V2.1 as SecurityX / CASP+ and mapped to 17 work roles in the DoD Cyber Workforce Framework (DCWF) across the Advanced and Intermediate proficiency levels.

It anchors many of the Advanced cybersecurity positions alongside CISSP, which is a major reason it carries weight for federal and contractor work. Current qualification matrices are published at the DoD Cyber Exchange.

Advanced Proficiency 17 DCWF Roles ISO/IEC 17024 Accredited
Fast Facts

What Are the Key Facts About SecurityX?

Everything you need to know about the certification, the CAS-005 exam, and how to maintain SecurityX as of 2026.

01

The Certification

Certification Name
CompTIA SecurityX
Formerly
CompTIA Advanced Security Practitioner (CASP+)
Issued By
CompTIA
Current Exam
CAS-005, released December 17, 2024
Level
Expert (advanced practitioner)
Prerequisites
None required
Recommended Experience
10 years IT, 5 in security
Accreditation
ANSI accredited (ISO/IEC 17024)
DoD 8140 Status
Approved (Advanced, 17 DCWF roles)
02

Exam & Maintenance

Exam Format
Multiple choice and performance-based
Number of Questions
Up to 90
Exam Duration
165 minutes
Passing Score
Pass/fail (no scaled score published)
Exam Cost
About $512 (CompTIA retail)
Delivery
Pearson VUE, online or test center
Validity
3 years
Renewal
75 CEUs over 3 years (CE program)
Voucher Note
Unexpired CASP+ vouchers remain valid
Going Deeper

What Comes After SecurityX?

SecurityX is the technical capstone of the CompTIA pathway. From here, most professionals move toward management and leadership. The three credentials below are the common next steps, and each carries an experience requirement SecurityX does not.

CISSP (Broad Senior Security)

ISC2's flagship credential and the natural move for a SecurityX holder heading toward broad senior or management roles. It spans eight domains and, like SecurityX, sits at the Advanced level under DoD 8140. CISSP requires five years of verified experience.

CISM (Security Management)

ISACA's Certified Information Security Manager focuses on governance, risk, and running a security program. It's the tighter fit for a SecurityX architect moving deliberately into management. CISM requires five years of security management experience.

CCISO (Executive Leadership)

EC-Council's Certified Chief Information Security Officer targets the executive seat, covering security strategy, governance, finance, and program management. It's the leadership endpoint for a SecurityX holder aiming at a CISO track, and it expects senior management experience.

Certification Roadmap

Where Does SecurityX Fit in Your Career?

SecurityX sits at the top of the CompTIA cybersecurity pathway. It builds on the security fundamentals of Security+ and the analyst skills of CySA+, and from there the path branches into security management and leadership.

STAGE 02 You Are Here

Expert Credential

The technical capstone

PRIMARY
SecurityX
CompTIA · Expert-level security architecture and engineering
Open Entry
No prerequisite credential, 10 years experience recommended
STAGE 03

Move Up

Toward management

Management
Executive Leadership
Decision Point

Is SecurityX Right For You?

Two questions to answer before you commit: can you sit it, and should you pursue SecurityX specifically. Here's a straight answer to both.

Q1

Do You Qualify for SecurityX?

Short Answer

Anyone Can Sit CAS-005

No prerequisite credential required.

SecurityX has no formal prerequisites, so there is no required certification standing between you and the exam. Unlike CISSP, you do not need to document years of experience before you sit it. Purchase the voucher, schedule through Pearson VUE, and take it online or at a test center.

Honest Caveat

Experience Is the Real Gate

The exam assumes you have lived it.

CompTIA recommends 10 years of IT experience including 5 in security, and the performance-based questions reward it. The scenarios assume you have sat through architecture reviews and incident bridges, not just read about them. Candidates who try to memorize their way in tend to struggle.

Q2

Is SecurityX the Right Certification for Your Goals?

SecurityX Is a Strong Fit If...

  • You are a senior practitioner who designs and implements security, and you want to stay technical rather than move into pure management
  • You are targeting security architect, senior security engineer, or enterprise architect roles
  • You need a DoD 8140 approved credential at the Advanced level for federal or contractor work
  • You want a hands-on exam that proves architecture and engineering judgment, not recall
  • You already hold Security+ or CySA+ and want the expert-level capstone of the CompTIA pathway
  • You want an advanced credential without a prerequisite certification or a hard experience requirement to sit

Consider Alternatives If...

  • You are moving toward security management and leadership, where CISSP or CISM fit the work better
  • You are early in your career without years of hands-on security experience, where Security+ then CySA+ builds the base first
  • You want a SOC and threat-detection focus, where CySA+ is purpose-built for that work
  • You want an offensive security specialization, where PenTest+ is the closer match
  • You need a management credential your organization specifically lists, where the named cert matters more than the tier
  • You cannot yet draw on real enterprise architecture or incident experience the scenarios assume
Career Paths

What Jobs Can You Get With SecurityX?

SecurityX maps to senior architecture, engineering, and strategy roles. Several are DCWF work roles where SecurityX qualifies at the Intermediate or Advanced proficiency level under DoD 8140.

Architecture

Security Architect

Designs the security controls, patterns, and infrastructure an enterprise runs on. This is DCWF work role 652, where SecurityX qualifies at the Intermediate proficiency level under DoD 8140.

Engineering

Senior Security Engineer

Builds and integrates the secure solutions an architecture calls for, from cryptography to cloud and automation. Maps to DCWF work role 631, where SecurityX qualifies at the Intermediate level.

Architecture

Enterprise Architect

Aligns security architecture with the broader enterprise technology strategy. This is DCWF work role 651, where SecurityX qualifies at the Intermediate proficiency level.

Security Management

Information Systems Security Manager

Owns the security posture of a system or program. This is DCWF work role 722, where SecurityX qualifies at the Intermediate proficiency level under DoD 8140.

Research

Research and Development Specialist

Evaluates and advances security technologies and techniques for the enterprise. This is DCWF work role 661, where SecurityX qualifies at the Advanced proficiency level.

Strategy

Cyber Policy and Strategy Planner

Sets cyber policy and long-range security strategy. This is DCWF work role 752, where SecurityX qualifies at the Advanced proficiency level.

Comparison

How Does SecurityX Compare to CISSP and CySA+?

Shortest version: SecurityX is for the senior technical architect, CISSP is for the security manager, and CySA+ is for the analyst. Here's how they line up.

  SecurityX CISSP CySA+
Issuer CompTIA ISC2 CompTIA
Focus Advanced security architecture and engineering Broad security management and leadership Security analytics and threat detection
Prerequisites None (rec. 10 years experience) 5 years experience required None (rec. Security+ and 4 years)
Exam Format Up to 90 items, 165 min, PBQ Adaptive, 100 to 150 items, 3 hrs Up to 85 items, 165 min, PBQ
Passing Score Pass/fail (no scaled score) 700 of 1000 750 of 900
Renewal 75 CEUs over 3 years 120 CPEs over 3 years 60 CEUs over 3 years
DoD 8140 Approved Yes (Advanced) Yes (Advanced) Yes (Advanced)
Best For Senior architects and engineers Security managers and leaders SOC and detection analysts

Pricing and renewal details vary by region and membership status. All three appear on the DoD 8140 Approved Qualifications Matrix V2.1 and reach the Advanced proficiency level for at least some work roles.

Ready to Get Certified?

Train for SecurityX with Training Camp.

Our CompTIA SecurityX boot camp covers all four CAS-005 domains over five days, focused on the scenario-based questions where you choose between competing security designs, with your exam voucher and exam assurance included, so you leave exam-ready.

View Boot Camp
Dive Deeper

SecurityX Articles and Guides.

Where SecurityX sits in the pathway, how it maps to DoD 8140, and how it stacks up against CISSP.

Featured What's New

New Certifications Coming in 2026: What's Actually Worth Your Time

A look at the credentials worth pursuing, leading with SecurityX replacing CASP+, what the CAS-005 changed for senior engineers and architects, and where it sits against CISSP.

Read Article →
DoD 8140

Which Certifications Qualify for DoD 8140 Work Roles? A DCWF Map

How the certifications map to DCWF work roles and proficiency levels, with SecurityX and CISSP anchoring the Advanced positions across the cybersecurity element.

Read Article →
Roadmap

CompTIA Stackable Certifications: Build a Path to Cyber and Network Mastery

How the CompTIA stack fits together, from Security+ and CySA+ up to SecurityX at the top of the cybersecurity track, and how to sequence the credentials in the right order.

Read Article →
Comparison

The Complete CISSP Guide

The management-focused senior credential SecurityX is most often weighed against. What CISSP covers, how it differs from a technical architect track, and who each one fits.

Read Article →
Pathway Start

Is CompTIA Security+ Worth It in 2026?

The foundation of the CompTIA security pathway that leads toward SecurityX. A candid look at what Security+ costs, what it opens up, and where it sits in the progression.

Read Article →
Pathway

The Complete CompTIA Certification Guide

The full CompTIA map, from entry credentials through the cybersecurity and infrastructure tracks, and how the pieces sequence toward expert-level credentials like SecurityX.

Read Article →
Cost and Budget

How to Save Money on CompTIA Exam Vouchers

Legitimate ways to cut CompTIA exam costs, from authorized partner and academic discounts to employer reimbursement and military programs, updated for current pricing.

Read Article →
Curriculum

Inside the Four SecurityX Domains.

The CAS-005 exam is organized into four domains, each carrying its own weight. Security Engineering is the largest at 31 percent, and Security Architecture is close behind. Click any domain for what it covers.

Domains I-II

Governance to Architecture
I Governance, Risk, and Compliance 20%

Applying security governance, risk management, and compliance across the enterprise: regulatory and legal considerations, third-party and supply chain risk, and aligning security programs to business objectives and audit requirements.

II Security Architecture 27%

Designing secure architectures across on-premises, cloud, and hybrid environments: zero trust, network and endpoint design, data protection, and the architecture decisions that determine where controls belong.

Domains III-IV

Engineering to Operations
III Security Engineering 31%

The largest domain. Engineering and integrating secure solutions: cryptography and public key infrastructure, secure cloud and automation, identity and access, and implementing the controls an architecture calls for.

IV Security Operations 22%

Running enterprise security operations: threat management and hunting, incident response, monitoring and detection engineering, vulnerability management, and the analysis that keeps a resilient enterprise defended.

Domains and weights reflect the CompTIA SecurityX CAS-005 exam objectives, released December 17, 2024. CompTIA refreshes the exam on roughly a three-year cycle.

Frequently Asked Questions

Common Questions About SecurityX.

The questions candidates ask most often when researching the CompTIA SecurityX certification.

What is CompTIA SecurityX?

CompTIA SecurityX is CompTIA's expert-level cybersecurity certification for senior security architects and engineers who design and implement secure solutions across complex enterprise environments. It sits at the top of CompTIA's cybersecurity pathway, above Security+ and CySA+, and it validates hands-on architecture and engineering judgment rather than memorization.

Is SecurityX the same as CASP+?

Yes. SecurityX is the rebranded name for what was CompTIA Advanced Security Practitioner (CASP+). CompTIA rebranded the credential to SecurityX with the release of the CAS-005 exam on December 17, 2024, and retired the previous CASP+ CAS-004 exam in June 2025. Unexpired CASP+ vouchers remain valid for the SecurityX exam.

What is the current SecurityX exam?

The current exam is CAS-005, released December 17, 2024. It updated the previous CAS-004 with heavier coverage of cloud security, automation and infrastructure as code, and zero trust architecture, reflecting what senior security engineers and architects actually do today.

What are the four SecurityX domains?

Under CAS-005 the four domains are Governance, Risk, and Compliance (20 percent), Security Architecture (27 percent), Security Engineering (31 percent), and Security Operations (22 percent). Security Engineering is the largest domain and carries the most weight on the exam.

Does SecurityX have a passing score?

No published numeric passing score. SecurityX is scored pass or fail, and CompTIA doesn't publish the passing threshold or a scaled score. This is unusual among certifications and reflects the exam's heavy use of performance-based questions, hands-on simulations you can't memorize your way through.

Are there prerequisites for SecurityX?

No. SecurityX has no formal prerequisites, so anyone can register and sit the exam. CompTIA recommends at least 10 years of general hands-on IT experience, including at least 5 years of broad hands-on security experience, before attempting CAS-005, because the exam assumes real enterprise experience.

How much does the SecurityX exam cost?

As of 2026, the SecurityX CAS-005 exam costs approximately $512 USD at CompTIA retail, with small regional variations. Training Camp's SecurityX boot camp includes the exam voucher in the program fee, along with exam assurance that covers a second voucher and a course retake.

What jobs can you get with SecurityX?

SecurityX maps to senior technical roles such as Security Architect, Senior Security Engineer, Enterprise Architect, Information Systems Security Manager, Research and Development Specialist, and Cyber Policy and Strategy Planner. Several of these are DCWF work roles where SecurityX qualifies at the Intermediate or Advanced proficiency level under DoD 8140.

Is CompTIA SecurityX approved for DoD 8140?

Yes. SecurityX appears on the DoD 8140 Approved Qualifications Matrix V2.1, listed as SecurityX / CASP+, mapped to 17 DCWF work roles across the Advanced and Intermediate proficiency levels. It anchors many of the Advanced cybersecurity positions alongside CISSP, which is a major reason it holds value for federal and contractor work. See the full DoD 8140 work role paths.

How long is SecurityX valid and how do you renew it?

SecurityX carries the Continuing Education designation and is valid for three years from your pass date. You renew it by earning 75 continuing education units through CompTIA's Continuing Education program across the three-year cycle, or by retaking the current exam version.

SecurityX vs CISSP, which should you choose?

Choose SecurityX if you want to stay technical, designing and implementing security architectures as a senior engineer or architect. Choose CISSP if you're moving toward security management and leadership. SecurityX is hands-on and heavy on performance-based questions with no experience requirement to sit, while CISSP is management-focused and requires five years of verified experience. Many senior professionals eventually hold both.

How hard is the SecurityX exam?

SecurityX is one of the most challenging cybersecurity exams. The difficulty isn't trivia, it's judgment. The performance-based questions put you into hands-on simulations where you configure controls, analyze logs, and choose between competing security designs. Candidates who have lived through real architecture reviews and incident response tend to find it manageable, while those relying on memorization struggle.

Is CompTIA SecurityX worth it in 2026?

For senior practitioners who want to prove hands-on architecture and engineering skill and stay technical, yes. SecurityX is the expert-level capstone of the CompTIA cybersecurity pathway, it anchors Advanced positions on the DoD 8140 matrix, and it targets the senior engineer who designs security rather than manages teams. It's less suited to those early in their careers or those aiming squarely at management, where CISSP fits better.

Get In Touch

Have Questions About SecurityX?

Whether you're weighing the certification, comparing it to CISSP, or planning advanced security training for a team, tell us where you are and we'll help you map out the right path.

+1
    100% Secure. NDA Compliant.
    CompTIA SecurityX Boot Camp 5 Days · Exam Voucher Included
    View Boot Camp