Exampractice
IT & Networking

CompTIA CySA+ Certification Guide

Full reference for CompTIA CySA+ — the CS0-003 to CS0-004 transition, exam domains and format, cost, recommended experience and a domain-led prep plan.

Liam Anderson · 7 min read
Security operations centre screens sized to the four CompTIA CySA+ CS0-004 exam domains with an analyst silhouette

Anyone researching the CompTIA Cybersecurity Analyst certification (CySA+) in 2026 hits an immediate complication: two exam versions are live at once. CS0-004 launched on 23 June 2026, while CS0-003 is in its sunset window — the English CS0-003 exam retires on 22 December 2026, with translated versions running until March 2027. So before anything else, the question this guide must answer is not "what is CySA+?" but "which exam should I book?" — and the answer shapes everything from the study materials you buy to the deadline you work to.

This is the full reference for the certification: the version decision, what the exam tests domain by domain, format and scoring, requirements, cost, renewal, and a preparation plan built around the domain weightings. Two neighbouring questions have their own dedicated guides: whether the certification actually pays off for analyst hiring is covered in is CompTIA CySA+ worth it, and the "which first, in what order" question against Security+ is settled in Security+ vs CySA+.

CS0-003 or CS0-004: which exam should you sit?

As of August 2026, both versions grant the identical "CompTIA CySA+" credential — exam codes never appear in the certificate name — and your certification is valid for three years from your pass date regardless of which version you passed. The decision is therefore practical, not reputational:

  • Choose CS0-004 if you are starting your preparation now. It is the current version, its materials will remain relevant for the exam's whole life, and you face no deadline pressure. At launch it is available in English, with other languages listed by CompTIA as coming later.
  • Finishing CS0-003 prep makes sense only with a near-term exam date. If you are already deep into CS0-003 study, the English exam remains bookable until 22 December 2026. The risk is obvious: any slip in your schedule collides with a hard retirement date, and CompTIA's English CS0-003 learning products retire even earlier, on 22 November 2026.
  • Do not start CS0-003 from scratch. New candidates buying materials today for an exam that retires within months are volunteering for deadline risk with no offsetting benefit.

The remainder of this guide describes the current CS0-004 exam unless stated otherwise.

What CySA+ is — and where it sits in a security career

CySA+ is CompTIA's intermediate, vendor-neutral certification for the blue-team analyst: the person who monitors, detects, investigates and responds rather than the one who builds infrastructure or breaks into it. It maps most directly onto security operations centre (SOC) analyst and vulnerability analyst roles, where the daily work is triaging alerts, hunting through logs, prioritising vulnerabilities and writing up incidents for people who were not in the room.

Within CompTIA's security track, it occupies the step above Security+. There are no enforced prerequisites — nothing stops you registering tomorrow — but CompTIA's recommended profile is demanding: around four years in a SOC analyst or vulnerability analyst role, with Network+ and Security+ level knowledge assumed. Read that as a description of the exam's pitch, not a gate. Questions presume you already understand core security concepts and networking; CySA+ tests whether you can apply them under analyst conditions.

The requirements question, answered plainly

Because "CySA+ requirements" is one of the most-searched phrases around this certification, here is the precise position: required — nothing; recommended — approximately four years of hands-on analyst experience plus Security+ and Network+ level knowledge. Candidates well short of that profile do pass, but they compensate with lab time. What you cannot compensate for is having never looked at real logs, alerts or vulnerability scan output, because the performance-based questions are built from exactly those artefacts.

The four CS0-004 domains, and what each really asks of you

CompTIA publishes the complete objectives free on its CySA+ page; download them before buying anything else. The domain structure tells you where to spend your hours:

Security Operations — 34%

The largest domain, and the heart of the analyst job: monitoring, detection and the interpretation of security data. Expect to demonstrate that you can look at output — log excerpts, alerts, indicators — and say what is happening and what matters. If your background is study rather than SOC shifts, this domain is where lab practice pays off most.

Vulnerability Management — 26%

Scanning, interpreting results, prioritising findings and understanding remediation in context. The tested skill is judgement: given a set of vulnerabilities, which one threatens this environment most, and what do you recommend? Candidates who only memorise scoring terminology, without practising prioritisation decisions, feel this domain's weight on exam day.

Incident Response & Management — 24%

The lifecycle of an incident from detection through containment to recovery and lessons learned. Scenario questions dominate: something has happened, evidence is in front of you, and the exam wants the appropriate next action — not a recited framework.

Reporting & Communication — 16%

The smallest domain and the most underestimated. Analysts exist to make findings usable by other people, and the exam tests whether you know what belongs in vulnerability reports and incident communications, and for which audience. Do not let its size tempt you to skip it; at these weightings, no domain is optional for a comfortable pass.

Exam format, scoring and delivery

The CS0-004 exam runs to a maximum of 85 questions in 165 minutes, combining multiple-choice with performance-based questions (PBQs), and the passing score is 750 on CompTIA's 100–900 scale. Three practical implications:

  • The 165-minute window is nearly double the time-per-question of CompTIA's 90-minute exams — a signal of how analysis-heavy the questions are. PBQs that drop you into simulated analyst tasks absorb time quickly, so bank minutes on the multiple-choice items.
  • "Maximum of 85" means your sitting may contain fewer scored items, since CompTIA seeds unscored questions. A shorter-than-expected exam is normal.
  • 750 is a scaled score, not 75% — chasing a per-question percentage is the wrong mental model. Aim for consistent strength across all four domains.

Delivery is through Pearson VUE, at a test centre or online via OnVUE proctoring.

Cost and renewal

As listed by CompTIA's authorised resellers following the June 2026 price rise, the US retail price for CySA+ is $439 — up from $425 — and pricing varies by country and region, with authorised voucher resellers legitimately selling below retail. Confirm the current figure for your market on CompTIA's site before budgeting.

Plan beyond the first voucher:

  • Retakes. No waiting period applies before a second attempt, but a 14-day wait applies from the third attempt onward, and each attempt requires a new full-price voucher unless you purchased a retake bundle.
  • Renewal. CySA+ is valid for three years and renews through CompTIA's Continuing Education programme. CompTIA's renewal pages list 60 continuing education units (CEUs) for CySA+ (V3), and its fee table places CySA+ in the $150-per-three-year-cycle tier when renewing via CEU upload. Alternatives include passing the latest exam version or earning a higher CompTIA certification — under CompTIA's stackable model, renewing a higher certification automatically renews the ones beneath it, and you pay CE fees only for your highest cert.

A domain-weighted preparation plan

CompTIA publishes no official study-hours figure, so honest planning starts from your distance to the recommended experience profile rather than from someone else's invented number. Whatever your timeline, let the weightings allocate it — roughly a third of your effort to Security Operations, a quarter each to Vulnerability Management and Incident Response, and a deliberate, non-zero slice to Reporting & Communication.

Sequence the work in this order:

  1. Objectives first. Download the CS0-004 objectives and grade yourself per line. Your grading tells you whether you are revising or learning — the two need very different schedules.
  2. Shore up assumed knowledge. If Security+-level fundamentals are shaky, fix that before CySA+ material, because every domain builds on them.
  3. Study by domain, heaviest first, using materials written for CS0-004 specifically — the version is young enough that older CS0-003 resources still dominate search results.
  4. Get hands on artefacts. For each domain, practise against the real thing: read logs, run and interpret a vulnerability scan on a home lab, write a one-page incident summary. PBQs reward candidates who have handled analyst artefacts and expose those who have only read about them.
  5. Benchmark with practice questions, then close loops. Score practice sets by domain, send your weakest domain back to step 4, and repeat. Resist re-drilling identical questions until you recognise answers — that measures memory of a question bank, not readiness for a live exam that will phrase everything differently. ExamPractice hosts free sample CompTIA CySA+ practice questions, with fuller sets and timed simulation for subscribers; as with any resource in this transition year, check which exam version a question set targets before relying on it.
  6. Finish with a full timed simulation at the real 165-minute length, because pacing across PBQs is itself a skill the exam tests.

Readiness checklist

Book with Pearson VUE when you can honestly tick all five:

  • Timed practice scores are consistently comfortable, with no single domain dragging.
  • You can interpret an unfamiliar log excerpt or scan result without reaching for notes.
  • You can walk through an incident lifecycle and justify the next action at each stage.
  • You know what a vulnerability report and an incident communication should contain, and for whom.
  • Every objective line is marked "can do" or "close enough to finish this week" — none marked "never touched".

Booking CySA+ with confidence

CySA+ in 2026 rewards candidates who respect two things: the version transition and the domain weightings. Start on CS0-004 unless you are genuinely weeks from a CS0-003 sitting; spend your hours where the weightings point; and treat practice results, not calendar pressure, as your booking signal. For the wider context — neighbouring certifications like PenTest+ and SecurityX, and where each sits in the security ladder — browse the CompTIA exams hub, and if the analyst path itself is what you are weighing up, the worth-it verdict and the Security+ ordering question are each one click away above.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like