Skip to content
Special Offer! Get 40% Off Today with Code: GET40 (40% OFF)
CompTIA

CompTIA CySA+ Just Changed: What CS0-004 Actually Tests That the Old Exam Didn’t

CompTIA quietly retired the exam that has defined the Cybersecurity Analyst credential since 2023. On June 23, 2026, CS0-004 became the live version of CySA+, and the outgoing CS0-003 has a hard retirement date of December 22, 2026 for English-language testing. If you sat for CySA+ any time before this summer, or you’re weighing whether to start studying right now, the version you land on determines what you’re actually being tested on, not just which exam code shows up on your certificate.

This isn’t a cosmetic refresh. CompTIA moved weight between domains, added dedicated coverage for artificial intelligence risk and cloud-native security operations, and kept the underlying job role the exam validates largely unchanged. That combination, same career outcome, different test, is exactly the kind of change that trips people up if they’re studying from year-old material. CompTIA laid out the reasoning behind the update in its own CySA+ V4 announcement, framing it as a response to how much SOC work has shifted toward cloud tooling and AI-assisted attacks since CS0-003 launched.

What Actually Changed Between CS0-003 and CS0-004

The headline shift is where CompTIA put the exam weight. Security Operations and Incident Response both grew, Vulnerability Management shrank, and the format underneath all of it, up to 85 questions mixing multiple choice with performance-based tasks, stayed exactly the same.

Domain CS0-003 Weight CS0-004 Weight
Security Operations 33% 34%
Vulnerability Management 30% 26%
Incident Response and Management 20% 24%
Reporting and Communication 17% 16%

New AI, Cloud, and Zero Trust Content

The four-point jump in Incident Response tells you where CompTIA thinks analysts are spending more of their actual workday, and the new material layered into the other domains backs that up. CS0-004 adds objectives that CS0-003 never touched:

  • Identifying and responding to AI-specific risks, including model manipulation and data poisoning against the machine learning tools a SOC increasingly relies on
  • Behavioral analytics applied across a broader attack surface, not just signature-based detection on the network perimeter
  • Cloud-native monitoring and response, reflecting how much SOC tooling now lives outside an on-premises data center
  • Zero trust architecture concepts as something an analyst is expected to operate within, not just define

None of this replaces the exam’s core identity. CySA+ is still, at heart, a test of whether someone can take telemetry from a SOC toolset and turn it into a defensible decision. CompTIA just widened the definition of what that toolset looks like in 2026.

What Stayed the Same

A few things carried over unchanged, which matters if you’re comparing study guides from either version:

  • Maximum of 85 questions, still a mix of multiple choice and performance-based simulations
  • Passing score of 750 on a 100 to 900 scale
  • No hard prerequisite to register, though CompTIA still recommends roughly four years of hands-on SOC or vulnerability analyst experience plus Security+ level knowledge going in
  • Retail exam voucher price of $425 in the United States

Should You Rush to Take CS0-003 Before It Retires?

December 22, 2026 sounds far off from where most people are reading this, but exam scheduling backs up fast in the weeks before a retirement deadline, and testing centers do run out of slots. Anyone already deep into CS0-003 study material has a real decision to make, not a hypothetical one.

A few honest considerations before defaulting to whichever exam is more convenient:

  1. If you’ve already booked training or a bootcamp built around CS0-003, finishing on that version and testing before the December cutoff avoids restarting your study plan from a different domain weighting.
  2. If you’re just starting from scratch, CS0-004 is the better use of your time. You’ll be tested on the SOC environment you’re actually walking into, not the one from three years ago, and there’s no reason to certify on a version that stops being sold within months.
  3. The certification itself does not expire or become invalid once the exam retires. Earning CS0-003 in November 2026 still produces a permanent CySA+ credential on your CompTIA transcript; only the ability to sit for that specific exam version goes away.
  4. Non-English test takers get more runway. Japanese, Portuguese, and Spanish versions of CS0-003 don’t retire until March 23, 2027, roughly three months after the English cutoff.

What CySA+ Actually Qualifies You For in 2026

CySA+ has always sat in an odd spot between Security+ and the more specialized penetration testing or GRC credentials. It’s built for the person already doing detection and response work, not someone breaking into security from zero.

The Roles Employers Actually Hire For

  • SOC Analyst, tier 1 through tier 2
  • Vulnerability Analyst or Vulnerability Management Engineer
  • Threat Intelligence Analyst
  • Incident Response Analyst

Real Salary and Demand Numbers

The market signal here is stronger than the average certification writeup suggests. According to ZipRecruiter’s 2026 salary data, the average annual pay reported for roles tied to CompTIA’s Cybersecurity Analyst credential sits at roughly $107,500 as of mid-2026, with a working range that stretches well past $135,000 for information security analyst titles more broadly on Glassdoor’s reporting.

Job posting volume backs up that this isn’t a niche credential. Employers listed over 123,000 cybersecurity analyst openings over the trailing twelve months through May 2026, with a median advertised salary above $130,000. Even narrowing to postings that specifically reference cybersecurity analyst work rather than the broader security field, the median still lands above $120,000. That’s a meaningfully different picture than a certification chasing declining demand, which is exactly the kind of signal worth checking before committing months of study to any exam.

Cost, Prerequisites, and Where CySA+ Fits Among Other CompTIA Exams

At $425 for the exam voucher, CySA+ sits above Security+ and below the specialist-level SecurityX credential that replaced CASP+ in 2025. CompTIA doesn’t gate registration behind a hard prerequisite, but treating that as an invitation to skip Security+ entirely is a mistake for most candidates. The exam objectives assume you already think in Security+ terms, ports, protocols, common attack types, before adding the analyst-level judgment CySA+ actually tests.

For candidates who already hold Security+ and are deciding what comes next, CySA+ is the natural analyst-track step up. Full details on the current exam, including the official objectives and testing logistics, are on the CS0-004 exam page. CompTIA’s own CySA+ certification page is the authoritative source for exact pricing, since exam vouchers and regional pricing do shift over the course of a year.

Is CySA+ Still Worth It, or Should You Look at Something Else First?

Worth being direct about the trade-offs here rather than just selling the credential. CySA+ is a strong fit if you’re already working incident response or vulnerability management tasks and want a credential that documents skills you’re using daily. It’s a weaker fit if you’re brand new to security and haven’t sat for Security+ yet, since you’ll spend more of your study time backfilling fundamentals than learning the analyst-specific material the exam actually rewards.

If cloud security specifically is your target rather than general SOC work, it’s worth comparing against a cloud-focused path. We recently covered how ISC2 rebuilt its CCSP outline for 2026, which leans further into cloud-native architecture than CySA+ does. And if the AI risk content in CS0-004 is what caught your attention, GIAC’s newer security lineup goes considerably deeper on that specific ground, covered in our look at GIAC’s three new AI security certifications. Neither replaces CySA+ for a generalist SOC role, but both are worth knowing about before you commit to one path.

Anyone building toward a broader security architecture role eventually should also look at what that track actually demands day to day. Our breakdown of the Microsoft cybersecurity architect exam is a useful comparison point for how the analyst track and the architect track diverge once you’re a few years in.

PracticeTestSoftware is an independent certification prep provider and has no affiliation with, endorsement from, or sponsorship by CompTIA. Exam codes, pricing, retirement dates, and blueprint details change on CompTIA’s own schedule, so confirm anything time-sensitive directly on CompTIA’s official certification pages before you register.

Frequently Asked Questions

When exactly does the old CySA+ exam retire?
CS0-003 retires for English-language testing on December 22, 2026. Japanese, Portuguese, and Spanish versions stay available until March 23, 2027. After those dates, CS0-004 is the only version offered.
How much does the CySA+ CS0-004 exam cost?
The retail voucher price is $425 in the United States. Pricing can vary slightly through employer bundles, academic discounts, or CompTIA’s own bundle offers, so check the official certification page for current pricing before buying a voucher.
Do I need Security+ before I can take CySA+?
No, CompTIA doesn’t enforce a hard prerequisite. But the exam objectives assume Security+ level knowledge of networking and security fundamentals, so most candidates who skip it end up studying that material anyway just to keep up with CySA+ content.
Will my CS0-003 certification stop being valid once the exam retires?
No. Once you’ve earned CySA+ on any version, it stays on your CompTIA certification record permanently. Retirement only affects whether you can still register to sit for that specific exam version going forward, not certifications already earned.
What’s new about the AI content on the CS0-004 exam?
CS0-004 adds objectives covering AI-specific risks such as model manipulation and data poisoning, alongside behavioral analytics used to detect threats across a wider attack surface than the prior version tested. CS0-003 did not cover AI-specific attack scenarios at all.
Is CySA+ enough on its own to get a SOC analyst job?
It significantly helps but rarely stands alone. Most SOC analyst postings pair certification with some hands-on lab or entry-level experience, since the exam validates knowledge of the tools and workflow but employers still want to see it applied, even in a home lab or internship setting.

{
“@context”: “https://schema.org”,
“@type”: “FAQPage”,
“mainEntity”: [
{
“@type”: “Question”,
“name”: “When exactly does the old CySA+ exam retire?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “CS0-003 retires for English-language testing on December 22, 2026. Japanese, Portuguese, and Spanish versions stay available until March 23, 2027. After those dates, CS0-004 is the only version offered.”
}
},
{
“@type”: “Question”,
“name”: “How much does the CySA+ CS0-004 exam cost?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “The retail voucher price is $425 in the United States. Pricing can vary slightly through employer bundles, academic discounts, or CompTIA’s own bundle offers, so check the official certification page for current pricing before buying a voucher.”
}
},
{
“@type”: “Question”,
“name”: “Do I need Security+ before I can take CySA+?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “No, CompTIA doesn’t enforce a hard prerequisite. But the exam objectives assume Security+ level knowledge of networking and security fundamentals, so most candidates who skip it end up studying that material anyway just to keep up with CySA+ content.”
}
},
{
“@type”: “Question”,
“name”: “Will my CS0-003 certification stop being valid once the exam retires?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “No. Once you’ve earned CySA+ on any version, it stays on your CompTIA certification record permanently. Retirement only affects whether you can still register to sit for that specific exam version going forward, not certifications already earned.”
}
},
{
“@type”: “Question”,
“name”: “What’s new about the AI content on the CS0-004 exam?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “CS0-004 adds objectives covering AI-specific risks such as model manipulation and data poisoning, alongside behavioral analytics used to detect threats across a wider attack surface than the prior version tested. CS0-003 did not cover AI-specific attack scenarios at all.”
}
},
{
“@type”: “Question”,
“name”: “Is CySA+ enough on its own to get a SOC analyst job?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “It significantly helps but rarely stands alone. Most SOC analyst postings pair certification with some hands-on lab or entry-level experience, since the exam validates knowledge of the tools and workflow but employers still want to see it applied, even in a home lab or internship setting.”
}
}
]
}

Leave a comment

Your email address will not be published. Required fields are marked *