CompTIA spent a good part of 2026 rebuilding pieces of its certification lineup, and the piece getting the most attention is CompTIA SecAI+, the vendor’s first credential built specifically around AI security. It launched February 17, 2026, under exam code CY0-001, and it exists because security teams are running into a problem most of them did not choose: generative AI and machine learning systems are showing up in production faster than anyone is building real governance or defense around them.
If you already hold Security+, CySA+, or PenTest+, or you are trying to figure out whether AI security is a real specialty or just another acronym to chase, here is what CY0-001 actually tests, what it costs, who CompTIA actually built it for, and what the job market is paying people who can do this work.
Why CompTIA Built a Certification Just for AI Security
The timing was not random. CompTIA’s own messaging around the launch points to a specific gap: organizations are adopting generative AI, machine learning platforms, and intelligent automation faster than they are building the security maturity to match. That is not just a vendor talking point invented to sell an exam. ISC2’s 2025 Cybersecurity Workforce Study found that 41% of security professionals named AI skills as their most pressing need, ahead of cloud security at 36%, and 69% said their teams had already deployed AI tools, were actively testing them, or were in early evaluation.
That is a workforce using AI faster than it is securing it. SecAI+ is CompTIA’s attempt to give that workforce a standard to train against, rather than leaving AI security as something people pick up ad hoc from vendor documentation and conference talks. CompTIA is not the only vendor racing to formalize AI skills into a credential either. Amazon rolled out its own AWS Certified AI Practitioner exam to fill a similar gap earlier in 2026, so the pattern is bigger than one vendor’s roadmap.
Inside the CY0-001 Exam: Format, Domains, and Cost
SecAI+ is not a broad AI literacy test. CompTIA built it narrow on purpose, focused specifically on securing AI systems and using AI inside security operations, not on general AI development or data science. The official SecAI+ certification page lays out four domains that make that focus explicit.
The Four Exam Domains and What Each One Actually Tests
- Basic AI Concepts Related to Cybersecurity (17%): terminology, how models and data pipelines actually work, and the vocabulary needed to talk about AI risk with technical precision instead of buzzwords.
- Securing AI Systems (40%): the largest domain by a wide margin, covering how to protect training data, models, and AI infrastructure from manipulation, poisoning, and unauthorized access.
- AI-Assisted Security (24%): using AI tools inside security operations itself, from alert triage to detection, and knowing where automation can be trusted versus where a human still has to sign off.
- AI Governance, Risk, and Compliance (19%): policy, oversight, and the regulatory landscape now shaping how organizations are expected to manage AI risk.
That weighting tells you what CompTIA thinks matters most right now. Nearly two out of every five questions test your ability to actually defend an AI system, not just describe one in the abstract.
Exam Format, Length, and Passing Score
The exam runs a maximum of 60 questions, a mix of multiple-choice and performance-based items, inside a 60-minute window. The performance-based questions drop you into a scenario, such as reviewing a suspicious model output, flagging a specific risk, or deciding whether a human needs to validate a decision, rather than asking you to pick a definition off a list. Passing score is 600 on a 100 to 900 scale. CompTIA offers the exam in English and Japanese and estimates roughly a three-year cycle before CY0-001 sees its next major revision.
What It Costs and Where to Take It
Current listings put the single-attempt SecAI+ voucher at $359, in line with pricing across CompTIA’s other core-series exams. DirectCertify’s own CY0-001 practice material, built around the current version of the exam, is available for candidates who want to test their readiness before booking a seat.
Who CompTIA Built SecAI+ For (and Who Should Skip It)
CompTIA does not enforce a hard prerequisite. You can technically register for CY0-001 without holding any prior certification. That does not mean it is a beginner exam.
The Recommended Background
CompTIA recommends candidates come in with real experience rather than fresh enthusiasm:
- 3 to 4 years of general IT experience
- At least 2 years of hands-on cybersecurity work
- A prior credential in Security+, CySA+, or PenTest+, or equivalent hands-on experience covering the same ground
In practice, that lines up with the job titles CompTIA points to as typical candidates: security analysts and SOC professionals, cloud and DevSecOps engineers, security engineers, and governance, risk, and compliance staff who are suddenly being asked to own AI risk on top of their existing scope.
Who Should Wait
If you are new to cybersecurity entirely, SecAI+ is the wrong starting point. Sit for Security+ first and build the foundational vocabulary and risk framework that SecAI+ assumes you already have. CompTIA has been explicit that SecAI+ is a complementary, additive credential rather than a replacement for Security+, CySA+, or PenTest+. It adds AI-specific depth to a role you are already qualified for. It does not qualify you for security work from scratch.
SecAI+ vs. Security+, CySA+, and PenTest+: How It Actually Fits
CompTIA’s core security lineup now has four pieces that overlap in places and diverge sharply in others. Here is how they stack up.
| Certification | Focus | Level | Best For |
|---|---|---|---|
| Security+ (SY0-701) | Broad, foundational cybersecurity concepts across five domains | Core, entry to mid | Building a baseline before specializing |
| CySA+ (CS0-003) | Threat detection, monitoring, and incident response | Core, intermediate | SOC analysts and detection-focused roles |
| PenTest+ (PT0-003) | Offensive testing and vulnerability assessment | Core, intermediate | Security testers and red-team-adjacent roles |
| SecAI+ (CY0-001) | Securing AI systems, AI-assisted operations, AI governance | Core, intermediate, AI-focused | Security pros adding AI-specific depth to an existing role |
Security+: The Foundation Everything Else Assumes
Security+ stays CompTIA’s baseline cybersecurity certification, covering general security concepts, threats and vulnerabilities, security architecture, security operations, and program management across five broad domains. SecAI+ does not retest any of that ground. It assumes you already have it.
CySA+: Where Detection and Monitoring Live
CySA+ stays focused on the detection and response side of security work, reading telemetry, triaging alerts, and running incident response. SecAI+ overlaps with that territory only in its AI-Assisted Security domain, where it asks whether you know how to use AI tools inside that same detection workflow responsibly. The two are complementary rather than competing.
PenTest+: Offensive Testing Stays a Separate Track
PenTest+ covers offensive security and structured vulnerability testing, and SecAI+ does not replace it. If your role involves adversarial testing of AI models specifically, such as prompt injection or model extraction attacks, SecAI+ gives you the defensive and governance framing around that risk, but it is not a substitute for hands-on offensive testing skills that PenTest+ validates.
The Same Year CompTIA Refreshed Security+ Too
SecAI+ did not launch in isolation. CompTIA moved on two fronts of its core lineup in the same calendar year, and the timing matters if you are planning which exam to sit first.
What Changed in the Security+ SY0-701 Refresh
CompTIA announced a refresh of the Security+ SY0-701 exam objectives in mid-April 2026, driven by the same forces behind SecAI+: AI-driven threats, expanding cloud attack surfaces, and new federal compliance requirements including CMMC 2.0. The current objectives stayed in place through June 30, 2026, and the updated objective set went live in test delivery on July 1, 2026, just weeks before this was written. Importantly, this is a content refresh, not a new exam version. SY0-701 remains the single active Security+ exam, just with updated coverage of generative AI risk, supply chain security, and zero trust architecture baked into the existing 28 sub-objectives.
The Broader Xpert Series: Where SecurityX Fits (and Doesn’t)
It is worth clearing up a common mix-up. CompTIA’s Xpert Series, which includes SecurityX, DataAI, and CloudNetX, is a separate expert-level tier aimed at senior architects with years of hands-on experience. SecurityX replaced the older CASP+ credential back in December 2024, so it predates this year’s changes and is not part of the 2026 news. SecAI+ sits in CompTIA’s core tier alongside Security+, CySA+, and PenTest+, not in the Xpert Series, and it targets working practitioners rather than architects designing enterprise-wide security programs.
What AI Security Roles Actually Pay in 2026
The certification only matters if the underlying skill is worth something in the market, and the data on that is fairly clear. ZipRecruiter puts the national average AI security engineer salary in the United States at roughly $152,773 a year as of July 2026, with a broader range that runs from around $150,000 for junior roles up past $240,000 for senior and staff-level positions. Postings that specifically require AI-related security skills also carry a real premium: the median base salary for those roles runs about $32,000 higher than comparable postings that do not mention AI skills at all.
A few things are driving that gap beyond general cybersecurity hiring growth:
- Generative AI and large language model deployments are moving from pilot projects to production faster than governance teams can keep pace with
- Regulatory pressure, including CMMC 2.0 and emerging AI-specific compliance rules, is pushing organizations to formally assign ownership of AI risk rather than leave it ambiguous
- A widening split between general security operations roles and AI-specific specialists, the same split reflected in CompTIA carving SecAI+ out as its own credential instead of folding it into Security+
- Continued growth in cloud and SOC hiring generally, which AI security work sits on top of rather than replaces
None of that is a promise that a CY0-001 badge alone moves your salary. It does mean the underlying skills, threat-modeling a model pipeline, defending training data, and governing how AI gets used inside a security program, map directly to what employers are actively budgeting for right now. For a wider view of how AI-related credentials compare across the cybersecurity field, our breakdown of which cybersecurity certifications are dominating hiring conversations in 2026 covers where SecAI+ fits alongside options outside CompTIA’s own lineup.
Should You Pursue CompTIA SecAI+ Right Now?
Before registering, it is worth working through a short, honest checklist rather than signing up because the certification is new.
- Confirm you already hold, or can demonstrate equivalent experience to, Security+, CySA+, or PenTest+, since SecAI+ assumes that baseline rather than teaching it from the ground up.
- Check whether your current role, or the one you actually want next, touches AI systems in practice: model deployment, MLOps pipelines, AI vendor risk review, or security tooling that now runs on AI. If it does not yet, SecAI+ may be early for you rather than wrong for you.
- If you are still deciding between AI security and a broader cloud security specialty, our comparison of cloud security certification options for 2026 is a useful side-by-side before committing to one path.
One thing worth being direct about: DirectCertify prepares candidates for CompTIA exams as an independent study resource. We are not CompTIA, and nothing in this piece is sponsored, reviewed, or endorsed by CompTIA. Treat the specifics above, objectives, pricing, and transition dates, as a snapshot, and confirm anything time-sensitive directly on CompTIA’s own certification page before you register.