CompTIA SecAI+ Study Guide (CY0-001): All 4 Domains, Weights and a 4-Week Plan

A security analyst holding a magnifying glass over a glowing cube while a friendly robot assistant fits a padlock on it

CompTIA SecAI+ (exam code CY0-001) is CompTIA’s vendor-neutral certification for securing AI systems and using AI in security operations. The exam has up to 60 questions in 60 minutes, you need 600 on a 100–900 scale to pass, and the US exam voucher costs $298.

This guide walks through the four domains in CompTIA’s published SecAI+ objectives, what each one asks you to do, how to split your study time, and how SecAI+ compares with Security+ and ISACA’s AAISM. Every exam fact comes from CompTIA’s own pages. Nothing here comes from the live exam.

SecAI+ (CY0-001) at a glance

Full nameCompTIA SecAI+ (V1)
Exam codeCY0-001
LaunchedFebruary 17, 2026
LevelExpansion certification. CompTIA says it is not entry level
Cost$298 US exam voucher, or $332 with Retake Assurance (prices vary by country)
QuestionsUp to 60, multiple-choice and performance-based
Time60 minutes
Passing score600 on a 100–900 scale
DeliveryPearson VUE test center or online remote proctoring
LanguagesEnglish and Japanese
PrerequisitesNone required
Recommended experience3–4 years in IT, including 2+ years of hands-on cybersecurity, plus Security+, CySA+, PenTest+ or equivalent
Valid for3 years
Renewal15 CEUs plus a $75 continuing education fee per three-year cycle, or pass a qualifying higher-level CompTIA exam
RetakesNo wait before a second attempt, 14 days before a third. You pay full price for every attempt
Expected retirementAbout 3 years after launch (CompTIA’s estimate)

Checked against CompTIA’s SecAI+ certification page and FAQ, its CEU requirements, renewal fees and retake policy on October 6, 2026.

Who SecAI+ is for

CompTIA built SecAI+ for people who already work in security and now have to deal with AI, either as something to protect or as a tool to use. Its FAQ names security analysts, SOC analysts, penetration testers, cloud engineers, DevSecOps engineers and risk and compliance professionals.

  • It is not entry level. CompTIA says the exam assumes a strong cybersecurity foundation and then extends it into AI concepts, AI-specific threats, AI-assisted security operations and AI governance.
  • It adds to a core cert rather than replacing one. CompTIA says many employers will expect Security+, CySA+, PenTest+ or SecurityX alongside SecAI+.
  • It is vendor-neutral. You study controls and frameworks that apply across cloud, on-premises and hybrid environments, not one company’s tools.
  • Government recognition is still pending. CompTIA says it has applied for ISO/IEC 17024 accreditation and is mapping SecAI+ to DoD 8140 and NICE work roles, and that you should treat both as pending until they are officially granted. If you need a DoD 8140 cert for your job today, check the current approved list first.

If you are newer to security, start with Security+ (compared below). If you are a security manager rather than a hands-on practitioner, look at ISACA’s AAISM too. Our roundup of AI security certifications covers the full field, including GIAC and EC-Council options.

The four SecAI+ domains (CompTIA’s published outline)

The weights come from CompTIA’s SecAI+ (V1) exam objectives summary. The question counts are our own arithmetic on a full 60-question exam. CompTIA says the exam has a maximum of 60 questions, so yours may have fewer. Treat the counts as rough.

DomainWeightQuestions if you get 60 (our estimate)
1. Basic AI concepts related to cybersecurity17%about 10
2. Securing AI systems40%about 24
3. AI-assisted security24%about 14
4. AI governance, risk, and compliance19%about 11

Securing AI systems is 40% on its own, more than domains 1 and 4 combined. If your time is short, that is where it goes. Below is what each domain covers according to CompTIA’s page summary, followed by our advice on how to study it. The full objectives document, with every sub-objective, is free from the SecAI+ page after a short form. Make it your syllabus.

Domain 1: Basic AI concepts related to cybersecurity (17%)

CompTIA’s summary lists three skills:

  • Explain core AI principles and terminology: machine learning, deep learning, natural language processing and automation.
  • Identify AI applications in security: use cases in threat detection, defense and security operations.
  • Recognize AI-driven threats: automated phishing, polymorphic malware, adversarial machine learning and malicious use of generative AI.

How to study it. Be able to explain machine learning, deep learning and NLP in a sentence each, and say where a large language model fits. Our plain-English AI glossary is a quick refresher. For each threat CompTIA names, know what AI changes compared with the older version of the attack: phishing that is personalized at scale, malware that rewrites itself to dodge signatures, and attacks aimed at the model instead of the host. This is the smallest domain, so if you already work with AI tools, don’t over-invest here.

Domain 2: Securing AI systems (40%)

The biggest domain. CompTIA’s summary:

  • Implement security controls: protect AI systems, data and models with technical safeguards.
  • Secure AI deployment environments: apply best practices across on-premises, cloud and hybrid infrastructure.
  • Mitigate adversarial risks: defend against attacks on AI models, data pipelines and inference layers.

How to study it. Draw the life of an AI system: training data, the model, the pipeline that builds and ships it, the inference endpoint, and the application on top. For each stage, write down the attack and the control. A few pairs to start with:

  • Poisoned or tampered training data: data provenance, integrity checks and tight write access to datasets.
  • Prompt injection against an LLM app: input and output filtering, least-privilege access for any tools the model can call, and human approval for risky actions.
  • Model theft or abuse through an API: authentication, rate limiting and monitoring of the endpoint.
  • Leaks through the model: keeping secrets and sensitive data out of prompts and training sets in the first place.

Most of these are controls you already know (identity, encryption, segmentation, secrets management, logging) applied to new assets. CompTIA’s FAQ also says questions ask you to apply AI threat-modeling resources and to analyze evidence of AI-related attacks to suggest compensating controls. The page summary doesn’t name the resources, so check the full objectives document. Public references that security teams commonly use include MITRE ATLAS and the OWASP Top 10 for LLM Applications.

Domain 3: AI-assisted security (24%)

This domain flips the view: AI as a tool for the defender. CompTIA’s summary:

  • Enhance detection and response: use AI-driven tools to spot anomalies, detect threats and speed up remediation.
  • Automate security workflows: use AI for event triage, alert correlation and response orchestration.
  • Apply AI techniques in operations: bring AI into threat modeling, behavior analysis and continuous monitoring.

How to study it. Think like a SOC lead. Where does AI save analyst time (triage, correlation, summarizing an incident) and where does it need a human check (containment, anything that changes production)? Know how AI tools fail too: false positives and negatives, models that drift as normal behavior changes, and generative AI that sounds confident while being wrong. Our explainer on why AI makes things up covers that last one. If your SIEM, EDR or SOAR platform has AI features, try them on real alerts and note where you would and wouldn’t trust the output.

Domain 4: AI governance, risk, and compliance (19%)

CompTIA’s summary:

  • Understand regulatory frameworks: identify global governance requirements and what they mean for AI adoption.
  • Integrate GRC into AI projects: build governance, risk management and compliance into the whole AI lifecycle.
  • Ensure responsible AI use: apply ethical guidelines, legal standards and frameworks such as GDPR and the NIST AI RMF. CompTIA’s FAQ also mentions the EU AI Act.

How to study it. Learn the NIST AI Risk Management Framework’s four core functions: govern, map, measure and manage. NIST explains each one free in its AI Resource Center. For GDPR and the EU AI Act, focus on what they mean for an AI project: personal data in prompts and training sets, and the EU AI Act’s risk-based approach to AI uses. Then know the everyday GRC artifacts. We have practical guides to building an AI inventory, an AI acceptable-use policy and AI questions for vendor security reviews.

What SecAI+ questions look like

CompTIA says the exam mixes multiple-choice and performance-based questions. According to its FAQ, you’ll be asked to interpret scenarios, apply AI threat-modeling resources, recommend or configure security controls for AI systems and data, and analyze evidence of AI-related attacks to suggest compensating controls.

Budget your time. Sixty minutes for up to 60 questions is roughly a minute each, and performance-based questions take longer than that. Practice under a timer before exam day.

A 4-week SecAI+ study plan

This plan assumes you already have Security+-level knowledge and can give it 8 to 10 hours a week, about 35 hours in total. That figure is our estimate, not CompTIA’s. For comparison, CompTIA estimates 30–60 hours for its CertMaster Perform course. Time follows the domain weights.

WeekFocusWhat to finish
1Objectives, Domain 1 (17%), start Domain 2Download the objectives and turn every bullet into a checklist. Cover AI terms and AI-driven threats. Draw your AI lifecycle map.
2Domain 2 (40%)Write an attack and a control for every lifecycle stage. Threat-model one AI app you know, end to end.
3Domains 3 (24%) and 4 (19%)SOC use cases, automation and where humans stay in the loop. NIST AI RMF functions, GDPR and EU AI Act basics, GRC artifacts.
4Practice and reviewWork through CompTIA’s free sample questions and ours, log every miss by domain, re-study the weakest domain, then book the exam.

Want a more detailed version? How to pass CompTIA SecAI+ breaks the plan down further, and the free AI study plan generator builds a schedule around your exam date.

Official CompTIA prep resources and prices

You don’t have to buy anything to start. The objectives document is the syllabus, and it’s free. Here is what CompTIA sells for SecAI+ on its US site:

ResourceUS priceWhat CompTIA says it is
Exam objectives and sample practice questionsFree (short form on the SecAI+ page)The full objective list for SecAI+ (V1)
CertMaster Perform$508CompTIA’s recommended all-in-one prep: instruction, labs, assessments and practice tests. Estimated 30–60 hours
CertMaster Labs$147Live virtual lab environment with guided tasks. Estimated 15–25 hours
CertMaster Study$118Learning and reinforcing key concepts
Exam voucher$298One attempt
Voucher plus Retake Assurance$332Voucher with a retake
Complete Bundle with Retake$628CertMaster products bundled with a voucher and Retake Assurance

For more practice, our free SecAI+ practice questions are original questions written from CompTIA’s published objectives, with explanations. Skip brain dumps. They’re often wrong, and CompTIA’s exam policies include a page on unauthorized training materials. To budget the whole thing, see what an AI certification actually costs.

SecAI+ vs Security+ vs AAISM

Here is how SecAI+ sits next to CompTIA’s core security certification and ISACA’s management-level AI security certification. They aren’t really competitors: each one fits a different stage of a security career.

Security+ (SY0-701)SecAI+ (CY0-001)ISACA AAISM
BodyCompTIACompTIAISACA
FocusCore security skillsSecuring AI systems and using AI in securityManaging an AI security program
Required firstNothing (Network+ and 2 years in a security or sysadmin role recommended)Nothing (3–4 years in IT, 2+ in security recommended)An active CISM or CISSP
ExamUp to 90 questions, 90 minutesUp to 60 questions, 60 minutes90 questions, 150 minutes
Passing score750 on 100–900600 on 100–900450 on 200–800
US price$439$298$459 ISACA members, $599 non-members, plus a $50 application fee
Keeping it50 CEUs and a $150 fee per three years15 CEUs and a $75 fee per three years10 CPE hours a year (30 over three years), an annual fee, and an active CISM or CISSP

Security+ details from CompTIA’s Security+ V7 page and CEU and fee tables; AAISM details from ISACA’s AAISM pages and candidate guide. All checked on October 6, 2026.

SecAI+ vs Security+. It isn’t either/or. Security+ is one of the core certs CompTIA expects SecAI+ candidates to have, and SecAI+ builds on it. If you don’t have Security+-level knowledge yet, start there. One timing note: CompTIA says Security+ V8 (SY0-801) is expected to launch on or around November 17, 2026, with expanded coverage of areas such as AI-related risks, and the English V7 exam retires June 11, 2027. If you already hold Security+, CompTIA says earning SecAI+ counts as 15 CEUs toward renewing it (Security+ needs 50 over three years).

SecAI+ vs AAISM. Different audiences. ISACA’s Advanced in AI Security Management is only open to people with an active CISM or CISSP, and its domains are AI governance and program management (31%), AI risk management (31%) and AI technologies and controls (38%). It suits security managers and CISOs. SecAI+ suits the people who configure controls, run the SOC and test systems. A manager who holds CISM might reasonably take both.

Is SecAI+ worth it?

If you work in security and your organization is adopting AI, SecAI+ is a reasonably priced way to show you can handle both sides: protecting AI and using it. It is a harder sell if you have no security background, because CompTIA designed it as an add-on to a core cert. And if your job needs a DoD 8140-approved certification, remember that mapping is still pending. Our full take is in Is CompTIA SecAI+ worth it?

Comparing it with other AI certifications? See our ranking of AI certifications, the AI certification cost and requirements index, or how renewal works across AI certs →

HOW TO // AI is not affiliated with or endorsed by CompTIA. SecAI+, Security+ and CY0-001 are CompTIA certifications and exams; we reference them descriptively. Everything on this page is based on CompTIA’s published materials, and our practice questions are original. Exam details can change, so check the official SecAI+ page before you book.

Related guides

Frequently asked questions

What is CompTIA SecAI+?

CompTIA SecAI+ (exam CY0-001) is a vendor-neutral certification that validates your ability to secure AI systems, defend against AI-driven threats and use AI responsibly in security operations. It launched February 17, 2026 and is aimed at working security professionals, not beginners.

How many questions are on the SecAI+ exam?

The CY0-001 exam has a maximum of 60 questions, a mix of multiple-choice and performance-based, and you get 60 minutes to finish.

What is the passing score for SecAI+?

You need 600 on a scale of 100–900 to pass the SecAI+ exam, according to CompTIA.

How much does the SecAI+ exam cost?

CompTIA's US list price for a SecAI+ exam voucher is $298, or $332 with Retake Assurance. Prices vary by country, and CompTIA charges full price for every attempt.

Do I need Security+ before SecAI+?

No. SecAI+ has no formal prerequisite. CompTIA recommends 3–4 years in IT, including at least 2 years of hands-on cybersecurity, and Security+, CySA+, PenTest+ or equivalent experience.

What are the SecAI+ exam domains?

There are four: Basic AI concepts related to cybersecurity (17%), Securing AI systems (40%), AI-assisted security (24%), and AI governance, risk, and compliance (19%).

How long is SecAI+ valid and how do you renew it?

SecAI+ is valid for three years. You renew it by earning 15 continuing education units and paying CompTIA's $75 CE fee, or by passing a qualifying higher-level CompTIA exam.

Is SecAI+ approved for DoD 8140?

Not yet, as of October 6, 2026. CompTIA says it has applied for ISO/IEC 17024 accreditation and is mapping SecAI+ to DoD 8140 and NICE work roles, and that candidates should treat these as pending until they are officially granted.

How long should I study for SecAI+?

CompTIA doesn't publish a study-time figure for the exam itself, but it estimates 30–60 hours for its CertMaster Perform course. With Security+-level knowledge, our 4-week plan works out to about 35 hours.

Scroll to Top