CompTIA A+ Certification Guide for Beginners
·10 min read
What CompTIA A+ covers, how the 220-1201 and 220-1202 exams work, and a step-by-step plan to earn the certification as a complete beginner.
Continue readingFull reference for CompTIA CySA+ — the CS0-003 to CS0-004 transition, exam domains and format, cost, recommended experience and a domain-led prep plan.

Anyone researching the CompTIA Cybersecurity Analyst certification (CySA+) in 2026 hits an immediate complication: two exam versions are live at once. CS0-004 launched on 23 June 2026, while CS0-003 is in its sunset window — the English CS0-003 exam retires on 22 December 2026, with translated versions running until March 2027. So before anything else, the question this guide must answer is not "what is CySA+?" but "which exam should I book?" — and the answer shapes everything from the study materials you buy to the deadline you work to.
This is the full reference for the certification: the version decision, what the exam tests domain by domain, format and scoring, requirements, cost, renewal, and a preparation plan built around the domain weightings. Two neighbouring questions have their own dedicated guides: whether the certification actually pays off for analyst hiring is covered in is CompTIA CySA+ worth it, and the "which first, in what order" question against Security+ is settled in Security+ vs CySA+.
As of August 2026, both versions grant the identical "CompTIA CySA+" credential — exam codes never appear in the certificate name — and your certification is valid for three years from your pass date regardless of which version you passed. The decision is therefore practical, not reputational:
The remainder of this guide describes the current CS0-004 exam unless stated otherwise.
CySA+ is CompTIA's intermediate, vendor-neutral certification for the blue-team analyst: the person who monitors, detects, investigates and responds rather than the one who builds infrastructure or breaks into it. It maps most directly onto security operations centre (SOC) analyst and vulnerability analyst roles, where the daily work is triaging alerts, hunting through logs, prioritising vulnerabilities and writing up incidents for people who were not in the room.
Within CompTIA's security track, it occupies the step above Security+. There are no enforced prerequisites — nothing stops you registering tomorrow — but CompTIA's recommended profile is demanding: around four years in a SOC analyst or vulnerability analyst role, with Network+ and Security+ level knowledge assumed. Read that as a description of the exam's pitch, not a gate. Questions presume you already understand core security concepts and networking; CySA+ tests whether you can apply them under analyst conditions.
Because "CySA+ requirements" is one of the most-searched phrases around this certification, here is the precise position: required — nothing; recommended — approximately four years of hands-on analyst experience plus Security+ and Network+ level knowledge. Candidates well short of that profile do pass, but they compensate with lab time. What you cannot compensate for is having never looked at real logs, alerts or vulnerability scan output, because the performance-based questions are built from exactly those artefacts.
CompTIA publishes the complete objectives free on its CySA+ page; download them before buying anything else. The domain structure tells you where to spend your hours:
The largest domain, and the heart of the analyst job: monitoring, detection and the interpretation of security data. Expect to demonstrate that you can look at output — log excerpts, alerts, indicators — and say what is happening and what matters. If your background is study rather than SOC shifts, this domain is where lab practice pays off most.
Scanning, interpreting results, prioritising findings and understanding remediation in context. The tested skill is judgement: given a set of vulnerabilities, which one threatens this environment most, and what do you recommend? Candidates who only memorise scoring terminology, without practising prioritisation decisions, feel this domain's weight on exam day.
The lifecycle of an incident from detection through containment to recovery and lessons learned. Scenario questions dominate: something has happened, evidence is in front of you, and the exam wants the appropriate next action — not a recited framework.
The smallest domain and the most underestimated. Analysts exist to make findings usable by other people, and the exam tests whether you know what belongs in vulnerability reports and incident communications, and for which audience. Do not let its size tempt you to skip it; at these weightings, no domain is optional for a comfortable pass.
The CS0-004 exam runs to a maximum of 85 questions in 165 minutes, combining multiple-choice with performance-based questions (PBQs), and the passing score is 750 on CompTIA's 100–900 scale. Three practical implications:
Delivery is through Pearson VUE, at a test centre or online via OnVUE proctoring.
As listed by CompTIA's authorised resellers following the June 2026 price rise, the US retail price for CySA+ is $439 — up from $425 — and pricing varies by country and region, with authorised voucher resellers legitimately selling below retail. Confirm the current figure for your market on CompTIA's site before budgeting.
Plan beyond the first voucher:
CompTIA publishes no official study-hours figure, so honest planning starts from your distance to the recommended experience profile rather than from someone else's invented number. Whatever your timeline, let the weightings allocate it — roughly a third of your effort to Security Operations, a quarter each to Vulnerability Management and Incident Response, and a deliberate, non-zero slice to Reporting & Communication.
Sequence the work in this order:
Book with Pearson VUE when you can honestly tick all five:
CySA+ in 2026 rewards candidates who respect two things: the version transition and the domain weightings. Start on CS0-004 unless you are genuinely weeks from a CS0-003 sitting; spend your hours where the weightings point; and treat practice results, not calendar pressure, as your booking signal. For the wider context — neighbouring certifications like PenTest+ and SecurityX, and where each sits in the security ladder — browse the CompTIA exams hub, and if the analyst path itself is what you are weighing up, the worth-it verdict and the Security+ ordering question are each one click away above.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·10 min read
What CompTIA A+ covers, how the 220-1201 and 220-1202 exams work, and a step-by-step plan to earn the certification as a complete beginner.
Continue reading·10 min read
What CompTIA Network+ covers, how the N10-009 exam works, who should take it and a practical preparation plan — everything in one guide.
Continue reading·9 min read
What CompTIA Security+ is, the SY0-701 exam format and cost, who the certification suits, and a practical five-step route to earning and keeping it.
Continue reading