Updated September 2026: CompTIA SecurityX is the certification formerly known as CASP+. CompTIA renamed it when the V5 exam, CAS-005, launched on December 17, 2024, and existing CASP+ holders kept their status. The older CAS-004 exam retired on June 17, 2025. CompTIA estimates CAS-005 will retire in 2027 and hasn’t announced a successor date on its SecurityX page.
SecurityX is CompTIA’s top cybersecurity certification, aimed at security architects and senior security engineers. It proves you can design and build secure systems across on-premises, cloud and hybrid environments, automate and run security operations, apply advanced cryptography, and handle governance, risk and compliance. Unlike CISSP or CISM, it’s a hands-on technical exam with performance-based questions, and there’s no experience you have to document to get certified.
This guide covers who SecurityX is for, the CAS-005 exam facts, the four domains and weights, cost and renewal, a study plan, career value, and how SecurityX compares with CISSP, CISM, CCSP and CySA+. For one engineer’s first-hand take on the exam under its old name, read CASP vs. CISSP: My Experience.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Who CompTIA SecurityX is for
- Senior security engineers who design and implement controls, not just operate them
- Security architects working across cloud, on-premises and hybrid environments
- Experienced CySA+ or PenTest+ holders who want to stay technical rather than move into management
- DoD and contractor staff whose work roles list SecurityX (CompTIA maps it to roles such as security architect and security control assessor)
CompTIA recommends at least 10 years of general hands-on IT experience, including 5 years of hands-on security, plus Network+, Security+, CySA+, Cloud+ and PenTest+ or equivalent knowledge (CompTIA). That’s a recommendation, not an eligibility gate, but the exam is written for people with that background.
SecurityX CAS-005 exam facts (2026)
| Item | Details |
|---|---|
| Exam code | CAS-005 (SecurityX V5) |
| Formerly | CompTIA Advanced Security Practitioner (CASP+) |
| Launch date | December 17, 2024 |
| Previous exam | CAS-004 retired June 17, 2025 |
| Retirement | Usually three years after launch; CompTIA estimates 2027 |
| Number of questions | Maximum of 90, multiple-choice and performance-based |
| Time limit | Maximum of 165 minutes |
| Passing score | Pass/fail only; no scaled score |
| Languages | English (other languages to be determined) |
| Recommended experience | 10 years of hands-on IT, including 5 years of hands-on security |
| Exam price (US) | $544 on CompTIA’s U.S. online store (checked September 26, 2026) |
| Renewal | Every three years: 75 CEUs plus a $150 CE fee, or another CompTIA renewal option |
Sources: CompTIA’s SecurityX page, the CompTIA store voucher listing, and CompTIA’s continuing education pages on CEUs and fees. Prices vary by country and change, so confirm at checkout.
The four CAS-005 domains and their weights
| Domain | Weight | What it covers |
|---|---|---|
| 1. Governance, risk and compliance | 20% | Security program documentation, program management, frameworks (COBIT, ITIL, NIST CSF), configuration management, GRC tools, data governance, risk management, threat modeling (ATT&CK, CAPEC, STRIDE), attack surface and compliance strategies |
| 2. Security architecture | 27% | Cloud capabilities (CASB, CI/CD, Terraform, Ansible, containers, serverless), cloud data security and controls, network architecture and microsegmentation, security boundaries, deperimeterization (SASE, SD-WAN) and zero trust |
| 3. Security engineering | 31% | Automation (PowerShell, Bash, Python, IaC, cloud APIs, generative AI, SOAR), vulnerability management and SCAP, advanced cryptography (post-quantum, homomorphic encryption, forward secrecy) and cryptographic use cases and techniques |
| 4. Security operations | 22% | SIEM monitoring and data analysis, vulnerabilities and mitigations, threat hunting and intelligence (STIX/TAXII, Sigma, YARA, Snort), and incident response including malware analysis and reverse engineering |
Security engineering is the biggest domain and the one most likely to show up in performance-based questions. Domain list and weights: CompTIA SecurityX exam details.
What SecurityX costs in 2026
- Exam voucher: $544 on CompTIA’s U.S. online store as of September 26, 2026 (CompTIA store). The store also sells a voucher with Retake Assurance for $709.
- Discounts: Authorized partners resell vouchers, often below retail, and CompTIA offers academic pricing to eligible students.
- Training: Optional. CompTIA sells CertMaster Perform, Practice and Labs; many experienced engineers pass with the official objectives, one good book or video course, a lab and a practice bank.
- Renewal: SecurityX is valid for three years. To renew with continuing education, earn 75 CEUs and pay $150 in CE fees during the cycle (CEUs, fees). You can also renew by passing the latest version of the exam or completing CompTIA’s CertMaster CE course. When you renew SecurityX, CompTIA also renews the lower-level CompTIA certifications it covers without extra CE fees.
A 12-week SecurityX study plan
This assumes about eight hours a week and several years of hands-on security work. The exam rewards people who have built things, so every week includes lab time.
- Weeks 1 to 2: objectives and gaps. Download the CAS-005 objectives and rate yourself on every bullet. Most candidates are strong in one or two domains and weak in the rest; plan around the weak ones.
- Weeks 3 to 5: security architecture. Cloud security (CASB, shared responsibility, container and serverless security), segmentation, SASE and zero trust. Build a small cloud or lab environment and apply the controls yourself.
- Weeks 6 to 8: security engineering. Write small automation scripts in PowerShell, Bash or Python; practice infrastructure as code; review PKI, post-quantum cryptography, key management and cryptographic use cases. This is 31% of the exam.
- Weeks 9 to 10: security operations. SIEM tuning and correlation, threat hunting with Sigma and YARA, incident response and basic malware analysis in a sandbox.
- Week 11: governance, risk and compliance. Frameworks, risk analysis (quantitative vs qualitative), third-party risk and threat modeling with ATT&CK and STRIDE.
- Week 12: timed practice. Full-length practice exams with performance-based questions under the 165-minute limit. Because scoring is pass/fail, aim for comfortable margins across all four domains.
Is SecurityX worth it? Jobs and career value
SecurityX maps to NICE and DoD 8140 work roles including security architect, systems requirements planner, security control assessor, and research and development specialist (CompTIA). It’s most valuable where job postings or contracts name it, and for engineers who want an advanced credential that tests hands-on skill rather than management knowledge.
BLS doesn’t track pay by certification. For context, it reports May 2025 median pay of $129,180 for information security analysts, with 21% projected employment growth from 2025 to 2035 (BLS), and $134,050 for computer network architects (BLS).
SecurityX vs CISSP, CISM, CCSP and CySA+
- SecurityX vs CISSP: CISSP is broader, more managerial, and more often named in senior job postings, and it requires five years of verified experience. SecurityX is hands-on, with performance-based questions and no documented experience requirement. Donald Korinchak compares the two from experience in CASP vs. CISSP: My Experience.
- SecurityX vs CISM: CISM is ISACA’s management certification. SecurityX is the technical path for people who want to keep building.
- SecurityX vs CCSP: CCSP goes deeper on cloud security plus legal and compliance topics. SecurityX covers cloud as part of wider enterprise architecture. For platform-specific depth, pair it with AWS Certified Security – Specialty.
- SecurityX vs CySA+ and PenTest+: CySA+ and PenTest+ are the intermediate CompTIA steps for defensive and offensive work. SecurityX sits above both, and CompTIA recommends equivalent knowledge of them before you attempt it. For Microsoft SOC roles, Microsoft SC-200 is a vendor-specific alternative.
- Hands-on offense: If you want to prove you can compromise systems, OSCP is the practical exam to look at instead.
Planning your next certification? See the full certification roadmap for the order to take them by career goal.
What I would tell a friend starting SecurityX
Don’t study SecurityX like a vocabulary test. Build the architectures it describes, script the automation, and break your own lab. The performance-based questions are where experienced engineers pass and memorizers fail. And keep reading about real incidents: architecture decisions look very different once you’ve seen how attackers get around them.
Architecture decisions last years. Attack techniques change weekly. The CyberExperts Daily Brief covers what changed in security and why it matters, in five minutes, weekday mornings. Get tomorrow’s brief.
Frequently asked questions
Is SecurityX the same as CASP+?
Yes. CompTIA renamed CASP+ to SecurityX when it launched the CAS-005 exam on December 17, 2024. Existing CASP+ holders kept their status, and the older CAS-004 exam retired on June 17, 2025.
How many questions are on the SecurityX exam?
A maximum of 90 multiple-choice and performance-based questions, with up to 165 minutes to finish.
What is the passing score for SecurityX?
There isn’t a numeric one. SecurityX is scored pass/fail only, with no scaled score.
How much does the SecurityX exam cost?
$544 on CompTIA’s U.S. online store as of September 26, 2026. Authorized partners may sell vouchers for less, and prices vary by country.
What experience do I need for SecurityX?
None is required to register. CompTIA recommends at least 10 years of general hands-on IT experience, including 5 years of hands-on security, and knowledge equivalent to Network+, Security+, CySA+, Cloud+ and PenTest+.
How do I renew SecurityX?
Every three years. Earn 75 continuing education units and pay $150 in CE fees during the cycle, pass the latest version of the exam, or complete CompTIA’s CertMaster CE course.
Is SecurityX better than CISSP?
They prove different things. SecurityX is a hands-on technical exam for architects and senior engineers. CISSP is broader, more managerial and requires five years of verified experience. Many senior practitioners hold both.
Sources
- CompTIA, SecurityX certification and CAS-005 exam details: comptia.org
- CompTIA, SecurityX voucher (U.S. store price): shop.comptia.org
- CompTIA, Earn continuing education units (CEU requirements): comptia.org
- CompTIA, Continuing education renewal fees: comptia.org
- BLS, Information security analysts: bls.gov
- BLS, Computer network architects: bls.gov
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.