CY0-001 vs Security+: which CompTIA exam do you need?

Updated September 20, 2026

Security+ and SecAI+ are not competing exams and you do not choose between them. Security+ is CompTIA’s broad, entry-level security certification. SecAI+ (CY0-001) assumes you already have that knowledge and applies it to a single new problem: artificial intelligence, both as something to defend and as something to defend with.

If you are new to security, Security+ first. If you are already working in security and AI systems have started landing in your scope, SecAI+ is the one that teaches you something new.

The core difference

Security+SecAI+ (CY0-001)
PositionEntry-level, foundationalSpecialist, builds on experience
Recommended experienceRoughly 1–2 years3–4 years IT, 2+ years security
ScopeAll of security, broadlySecurity and AI, specifically
Assumes you knowLittleWhat a control, threat and risk are
Typical candidateMoving into securityAlready in security

Security+ teaches you the vocabulary of the field. SecAI+ assumes the vocabulary and asks what changes when the asset you are protecting is a model, or when the attacker is using generative AI.

Is Security+ a prerequisite?

No. CompTIA enforces no prerequisites for SecAI+ — you can book it today regardless of what you hold. What CompTIA does is recommend knowledge at the level of Security+, CySA+ or PenTest+, plus 3–4 years in IT and two or more hands-on in cybersecurity.

That recommendation is meaningful. The exam does not stop to explain what defence in depth is, what least privilege means, or why segmentation matters. It expects you to bring that and to apply it to a new class of system.

What SecAI+ adds that Security+ does not cover

Four things, matching the exam’s domains:

AI concepts for security people (17%). What a model is, how training data becomes behaviour, what inference means, and why generative systems fail in ways traditional software does not.

Securing AI systems (40%). The largest domain and the genuinely new material: protecting training data, protecting models and their outputs, and securing the environments where AI runs, whether cloud or on-premises. Security+ has nothing equivalent.

AI-assisted security (24%). Using AI inside your own defensive work — detection, triage, security operations. This is the mirror image of the previous domain and the exam expects you to tell them apart.

AI governance, risk and compliance (19%). Frameworks for adopting AI responsibly and lawfully. Security+ touches governance generically; SecAI+ makes it AI-specific.

Which should you sit?

Take Security+ first if you are early in your career, changing into security, or need a certification that employers recognise as a baseline. It opens more doors simply because more job adverts name it.

Take SecAI+ if you already work in security and any of the following is true: your organisation is deploying AI systems you are now responsible for, you are being asked about AI risk by people above you, or your SOC is adopting AI tooling and you need to evaluate it credibly.

Take both, in that order, if you are early-career and want to specialise. SecAI+ is far more useful sitting on top of a solid foundation than standing alone.

A note on how new SecAI+ is

CY0-001 launched in February 2026, with an estimated retirement around three years later. Being early has a trade-off. The upside is scarcity: few people hold it, and the subject matter is in demand. The downside is that fewer employers recognise the name yet, and third-party study material is thinner than for a certification that has existed for a decade.

Security+ has neither problem, and neither advantage. That asymmetry, more than the content, is usually what decides the order for people who intend to take both.