Updated September 2026: CompTIA CySA+ V4 (CS0-004) launched June 23, 2026 and is the exam new candidates should plan for. CySA+ V3 (CS0-003) remains available in English until December 22, 2026. This guide focuses on CS0-004 domains, who the cert is for, and a practical study path — without inventing fee numbers you should confirm on CompTIA’s site when you schedule.
Security+ proves you know the language. CySA+ proves you can use it in a SOC: triage alerts, prioritize vulnerabilities, and communicate risk without drowning your manager in CVSS theater.
If you are still choosing a first cert, start with How to Pass CompTIA Security+ in 2026. For the wider map, see Best Cybersecurity Certifications in 2026. Career changers should pair this with How to Transition to a Cybersecurity Career at Any Age. Management-track readers comparing depth later often look at CISSP without reading a shelf of books.
See What Changed After the Backstory
Get the newer cyber developments shaping the story today, without digging through the noise.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Who CompTIA CySA+ is for
CySA+ fits people who already touch tickets, logs, or vulnerability queues and need a vendor-neutral analyst credential hiring managers recognize:
- SOC analysts (Tier 1–2) who want a structured detection and response outline
- Vulnerability or threat analysts who need to defend prioritization decisions
- IT admins moving into security operations with Security+ (or equivalent) already in hand
- Career changers who can show labs — not just flashcards — around SIEM, EDR, and IR basics
CompTIA recommends roughly four years of hands-on SOC or vulnerability work. That is a recommendation, not a gate. What fails candidates is weak practice with analysis, not a missing birthday on a résumé.
CS0-004 at a glance (verify before you pay)
According to CompTIA’s CySA+ V4 page:
- Exam code: CS0-004 (V4). V3 CS0-003 retires in English December 22, 2026.
- Launch: June 23, 2026
- Length: up to 85 questions, 165 minutes
- Passing score: 750 on a 100–900 scale
- Question types: multiple-choice and performance-based
- Languages: English first; additional languages rolling out
Exam fees change and bundles vary. Check CompTIA’s checkout (or your employer voucher) the week you schedule — do not trust a blog’s price from last quarter.
CS0-004 domains (what the exam actually weighs)
Official V4 domain weights:
- Security Operations — 34%. Architecture and logging that support detection; indicators across network, endpoint, cloud, and identity; SIEM/EDR/packet/threat-intel workflows; threat hunting concepts; automation/process improvement; AI use-cases and governance risks in the SOC.
- Vulnerability Management — 26%. Choosing scan methods, reading tool output, risk-based prioritization, and tying findings to controls and compliance language.
- Incident Response and Management — 24%. Attack frameworks (for example MITRE ATT&CK / kill chain thinking), IR phases, triage, evidence handling, containment, eradication, recovery, and root cause.
- Reporting and Communication — 16%. Dashboards and reports for vuln and IR audiences; metrics such as detection and remediation time; post-incident reviews stakeholders will actually read.
If you only memorize port numbers, you will hate the PBQs. CySA+ rewards people who can explain why this alert matters now.
V3 (CS0-003) vs V4 (CS0-004) — which should you take?
New starters in fall 2026: study CS0-004. Training products and practice banks are catching up to V4, and you avoid a mid-prep exam retirement.
Already deep into CS0-003 materials: you can still sit V3 while English remains available (through December 22, 2026). Only do that if your practice scores are already exam-ready — do not start a fresh V3 plan in October.
A study plan that does not require buying every book
- Weeks 1–2 — Map the domains. Read CompTIA’s objectives once end-to-end. Build a one-page cheat sheet per domain in your own words.
- Weeks 3–5 — Security operations reps. Live in a SIEM trial or open stack (even a home ELK/Wazuh lab). Practice writing the story: evidence → hypothesis → next action.
- Weeks 4–6 — Vulnerability management. Run authenticated vs unauthenticated scans in a lab. Practice ranking findings with business context, not only CVSS.
- Weeks 6–7 — IR drills. Walk a ransomware-ish and a business-email-compromise tabletop. Write the containment steps as if your manager will paste them into Slack.
- Week 8 — Practice exams + PBQs. Time yourself. Review every miss by objective ID. Stop when scores are stable, not when you finish a book.
Official CertMaster / CompTIA labs help if your employer pays. If not, a disciplined lab plus one solid practice bank beats three unread PDFs.
Practice tips that still work
- Explain every PBQ out loud before clicking. If you cannot narrate the triage, you are guessing.
- Keep a “false positive graveyard” notebook — why the alert looked real, what disproved it.
- Rehearse short executive summaries. Domain 4 is not fluff; it is how analysts keep funding and trust.
- Sleep before the exam. CySA+ is a long sit; fatigue creates silly misreads.
CySA+ vs Security+ vs CISSP — where it fits
Security+ is the broad baseline. CySA+ is the analyst’s next step — detection, vuln prioritization, and IR communication. CISSP is a different game: broader managerial scope and experience expectations. Many people do Security+ → CySA+ (or cloud/security specialty) → CISSP years later. Use the 2026 certs guide if you need the career framing, not just the exam outline.
FAQ
Is CySA+ harder than Security+?
For most people, yes — not because of trivia, but because PBQs expect analyst judgment. If Security+ felt comfortable, CySA+ is the natural stretch.
Do I need Security+ before CySA+?
Not strictly. CompTIA recommends Security+/Network+ level knowledge. If you already work a SOC queue, you can go straight to CySA+; if terms like SIEM and CVE still blur, earn the baseline first.
How long is CySA+ valid?
CompTIA certifications typically run on a three-year renewal cycle via continuing education or retake. Confirm your cert’s renewal rules in your CompTIA account after you pass.
Will CS0-003 study materials still help for CS0-004?
Core analyst skills transfer. Domain weights and AI/cloud SOC emphasis differ on V4 — use CS0-004 objectives as the checklist, and treat V3 books as secondary.
What I would tell my relative now
Pick CS0-004 unless you are already exam-ready on V3. Build a tiny lab you actually open three nights a week. Write short incident notes like a human, not a CVSS bot. And once you pass, keep the signal coming — certifications get interviews; staying current keeps you useful. That is what the weekday brief is for: five minutes, weekday mornings, what changed in security and why it matters.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.