Security+ vs CySA+
Security+ validates skills for core security functions, from general security concepts to security program management. CySA+ concentrates on detecting, analyzing, and responding to threats in security operations and vulnerability management roles. Neither exam is a formal prerequisite for the other.
Side by Side
| Security+ | CySA+ | |
|---|---|---|
| Full name | CompTIA Security+ | CompTIA Cybersecurity Analyst |
| Issuer | CompTIA | CompTIA |
| Level | Entry | Intermediate |
| Exam type | Multiple choice and performance-based | Multiple choice and performance-based |
| Questions | Maximum of 90 | Maximum of 85 |
| Duration | 90 minutes | 165 minutes |
| Passing score | 750 on a scale of 100 to 900 | 750 on a scale of 100 to 900 |
| Exam fee | $439 | $439 |
| Prerequisites | None required. CompTIA recommends Network+ and two years of experience in a security or systems administrator job role. | None required. CompTIA recommends about four years in a SOC analyst or vulnerability analyst role, plus Security+ or equivalent knowledge. |
| Validity | 3 years | 3 years |
| Renewal | Earn 50 CEUs in the three-year cycle and pay a $150 CE fee, complete the CertMaster CE course, pass the latest Security+ exam, or earn a higher-level CompTIA certification such as CySA+, PenTest+, or SecurityX. | Earn 60 CEUs in the three-year cycle and pay a $150 CE fee, pass the latest CySA+ exam, or earn SecurityX. Earning PenTest+ also renews CySA+. |
| Exam domains | General security concepts; Threats, vulnerabilities, and mitigations; Security architecture; Security operations; Security program management and oversight | Security Operations; Vulnerability Management; Incident Response and Management; Reporting and Communication |
Main Differences
- +Focus: Security+ domains cover general security concepts, threats and vulnerabilities, security architecture, security operations, and program management. CySA+ domains cover security operations, vulnerability management, incident response, and reporting and communication.
- +Recommended experience: CompTIA suggests Network+ and two years in a security or systems administrator role before Security+. For CySA+ it suggests about four years as a SOC analyst or vulnerability analyst.
- +Exam: Security+ (SY0-701) has up to 90 questions in 90 minutes. CySA+ (CS0-004) has up to 85 questions in 165 minutes. Both pass at 750 on a 100 to 900 scale and mix multiple-choice with performance-based questions.
- +Renewal: both certifications run on a three-year cycle with a $150 CE fee. Security+ needs 50 CEUs and CySA+ needs 60. Earning CySA+ also fully renews Security+.
Certification Details
Frequently Asked Questions
Do you need Security+ before CySA+?→
No. Security+ is not required for CySA+. CompTIA recommends the Network+, Security+, CySA+ order and says skipping Security+ makes sense mainly for candidates with substantial security experience.
Do Security+ and CySA+ cost the same?→
Yes. CompTIA lists both exam vouchers at $439 in its US store, and a voucher with Retake Assurance costs $579 for either exam.
Sources
- CompTIA Security+ V7
- CompTIA CySA+ V4
- CompTIA: The new CompTIA Cybersecurity Analyst (CySA+), your questions answered
- CompTIA CE: CEUs required per certification
- CompTIA CE: Continuing education renewal fees
- CompTIA CE: Earn a higher-level CompTIA certification
- CompTIA Security+
- CompTIA Security+ V8
- CompTIA Help: Testing options for CompTIA certifications
- CompTIA CE: Renew with a single activity
- CompTIA CySA+
- CompTIA CySA+ V3
- CompTIA press release: CompTIA updates CySA+ certification
- CompTIA Certification Retake Policy
Exam details come from official issuer pages and are listed in the sources above. Fees and exam versions change; confirm with the issuer before registering.