- What Is CompTIA SecAI+ and Where Does It Fit?
- Formal Prerequisites: What CompTIA Actually Requires
- The Recommended Experience Profile
- Domain-by-Domain Readiness Check
- Exam Mechanics: Format, Fees, and Registration
- Who Hires SecAI+ Holders and for What Roles?
- A Domain-Weighted Study Schedule
- Retake Policy and Keeping the Cert Active
- Frequently Asked Questions
- SecAI+ has no formal prerequisites, but CompTIA recommends 3-4 years of IT experience including 2+ years in hands-on cybersecurity.
- The exam costs $359 USD (single voucher) or $408 with a retake bundle; maximum 60 questions in 60 minutes.
- Domain 2 - Securing AI Systems carries the heaviest weight at 40% and covers model controls, gateway controls, and AI monitoring.
- A passing score of 600 on a 100-900 scale is required; the cert is valid for 3 years and renewable at $50/year in CE fees.
What Is CompTIA SecAI+ and Where Does It Fit?
Launched on February 17, 2026, the CompTIA Security AI+ - marketed as SecAI+ - is the first vendor-neutral certification purpose-built for the intersection of artificial intelligence and cybersecurity. It sits inside CompTIA's relatively new Expansion certification series, which is designed for mid-career professionals who already hold a foundational cert and want to move into a specialized discipline without jumping to an advanced-tier credential like CASP+.
The certification is ANSI/ISO 17024 accredited, which means it meets internationally recognized standards for personnel certification. For hiring managers - especially in regulated industries - that accreditation matters when justifying a candidate's credentials on a contract or government requirement.
The current exam version is CY0-001 V1, with Exam Objectives Document Version 1.1 governing what appears on the test. Candidates preparing now should download that objectives document directly from CompTIA and cross-reference every topic against their existing knowledge gaps.
Formal Prerequisites: What CompTIA Actually Requires
Here is the short answer: CompTIA lists no formal prerequisites for SecAI+. There is no gate-keeping requirement that forces you to hold Security+ or any other certification before you can register and sit the exam. Anyone can purchase a voucher and attempt CY0-001.
That said, "no formal prerequisites" does not mean "no preparation required." The exam objectives assume a working vocabulary in both cybersecurity and AI systems that a brand-new IT professional is unlikely to have. CompTIA is explicit about this in its recommendations.
CompTIA's Recommended Starting Point
CompTIA recommends that candidates bring the following to the table before attempting SecAI+:
- 3-4 years of general IT experience, covering networking, systems administration, or a related technical discipline.
- 2 or more years of hands-on cybersecurity experience - not just theoretical exposure but actual work with security tools, incident workflows, or security engineering tasks.
- Holding Security+, CySA+, or PenTest+ (or a recognized equivalent from another vendor) is specifically called out as the ideal prior certification background.
Key Takeaway
If you hold Security+ and have spent two or more years working in a SOC, on a blue team, or in a security engineering role, you are likely positioned at exactly the experience level CompTIA designed SecAI+ for. The exam builds on that foundation - it does not repeat it.
Candidates who hold CySA+ have a particular advantage: the analytical and detection mindset that CySA+ instills maps directly onto Domain 3 (AI-assisted Security) and Domain 2's monitoring and auditing requirements. PenTest+ holders will find Domain 1's AI concepts section more approachable because they already think adversarially about system inputs and outputs - a mental model that transfers cleanly to AI attack surfaces.
The Recommended Experience Profile
Beyond certifications, the practical experience that most directly prepares a candidate for SecAI+ comes from a handful of real-world work contexts. This is not a certification that rewards pure memorization. The performance-based questions (PBQs) that appear on the exam require candidates to do something - configure, analyze, or respond - not just recall a definition.
The experience types that align most tightly with the four SecAI+ domains include:
- SOC or detection engineering work: Familiarity with SIEM platforms, alert triage, and behavioral analytics feeds directly into Domain 3 (AI-assisted Security, 24%) and the monitoring components of Domain 2.
- Cloud or infrastructure security: Understanding access controls, identity management, and network segmentation prepares candidates for the access controls and data security controls subdomains within Domain 2's 40% weight.
- Risk and compliance exposure: Anyone who has worked with frameworks like NIST, ISO 27001, or internal GRC processes will find Domain 4 (AI Governance, Risk, and Compliance, 19%) familiar in structure, even if the AI-specific content is new.
- AI or ML adjacent work: Direct experience with model deployment, data pipelines, or MLOps is helpful for Domain 1 and Domain 2 but is not required - the exam tests AI security concepts, not data science depth.
For a deeper look at the question types you will encounter once you sit down at the Pearson VUE terminal, SecAI+ Performance-Based Questions: How to Prepare breaks down exactly what PBQ scenarios look like and how to approach them.
Domain-by-Domain Readiness Check
Before registering, honest candidates should run a self-assessment against each of the four SecAI+ domains. The domain weights are not equal, and your prep time should reflect that imbalance.
Domain 1: Basic AI Concepts Related to Cybersecurity (17%)
This domain establishes the AI vocabulary the rest of the exam assumes. Expect questions on AI/ML fundamentals as they relate to threat actors, attack surfaces, and defensive tooling.
- Types of AI/ML models and how they are exploited
- Adversarial inputs, prompt injection, and model poisoning at a conceptual level
- How AI changes the threat landscape (both for attackers and defenders)
Domain 2: Securing AI Systems (40%) - Highest Weight
This is the core of SecAI+ and the domain that most directly reflects the job tasks the cert is designed to validate. Nearly half of your scored points live here.
- Model controls: Protecting AI model integrity, versioning, and deployment pipelines
- Gateway controls: API security, input validation, and traffic inspection for AI endpoints
- Access controls: Identity, least-privilege principles applied to AI systems and training data
- Data security controls: Securing training datasets, inference data, and output handling
- Monitoring and auditing for AI systems: Logging model behavior, detecting drift, and maintaining audit trails
Domain 3: AI-assisted Security (24%)
Covers how security practitioners use AI tools to enhance detection, response, and threat intelligence workflows.
- AI-powered SIEM and SOAR integrations
- Automated threat hunting and anomaly detection
- Evaluating AI tool outputs for reliability and bias in security contexts
Domain 4: AI Governance, Risk, and Compliance (19%)
Addresses the policy, regulatory, and ethical frameworks surrounding AI deployment in security-sensitive environments.
- AI risk frameworks and responsible use policies
- Regulatory considerations (sector-specific AI rules, data privacy intersections)
- Ethical AI principles and their practical security implications
Exam Mechanics: Format, Fees, and Registration
SecAI+ is administered exclusively through Pearson VUE, either at a physical test center or via OnVUE remote proctoring from your own machine. Both delivery methods use the same exam version (CY0-001) and the same scoring scale.
| Detail | Specifics |
|---|---|
| Exam Code | CY0-001 V1 |
| Maximum Questions | 60 (all 60 scored) |
| Question Types | Multiple-choice and performance-based questions (PBQs) |
| Time Limit | 60 minutes |
| Passing Score | 600 (scale: 100-900) |
| Single Voucher Price | $359 USD |
| Retake Bundle Price | $408 USD |
| Delivery | Pearson VUE test center or OnVUE remote |
| Cert Validity | 3 years |
| Annual CE Fee | $50 USD |
The 60-minute time limit deserves close attention. With up to 60 questions - some of which are scenario-based PBQs that require multiple steps - candidates average roughly one minute per question with no buffer. Candidates who have not practiced under timed conditions often report being caught off guard by how quickly the clock moves. Running full-length SecAI+ practice tests under timed conditions is one of the most effective ways to calibrate your pace before exam day.
Who Hires SecAI+ Holders and for What Roles?
Because SecAI+ launched in February 2026, the hiring market is still forming around it. However, the domains map to specific job functions that organizations are actively staffing regardless of what certification badge is attached to them.
The roles most directly served by SecAI+ competencies include:
- AI Security Engineer: Responsible for securing AI model pipelines, APIs, and data infrastructure - Domain 2 is essentially the job description.
- Security Operations Analyst (AI-augmented SOC): Increasingly, SOCs run AI-assisted triage and detection. Domain 3 skills are directly applicable.
- GRC Analyst with AI focus: As regulatory bodies move toward AI-specific compliance requirements, Domain 4 knowledge translates into auditable, billable expertise.
- Cloud Security Architect: Model deployment lives in cloud environments. The access control and data security components of Domain 2 align with cloud security architecture responsibilities.
- Threat Intelligence Analyst: AI is reshaping how threat intelligence is collected and actioned. Domain 1 and Domain 3 together address both the threat side and the tool side of that shift.
Government contractors and defense-sector employers in particular respond to ANSI/ISO 17024 accreditation when evaluating which certifications satisfy contract-required baseline qualifications. The full scope of what you need to know going into the exam is covered in detail at SecAI+ Prerequisites and Experience Requirements 2026.
A Domain-Weighted Study Schedule
Given the domain weight distribution - 40% on Domain 2, 24% on Domain 3, 19% on Domain 4, and 17% on Domain 1 - a four-week study schedule should mirror those proportions rather than treating each domain equally.
Domain 1 + Domain 4 Foundation
- Build AI vocabulary: model types, attack categories, adversarial concepts
- Map existing GRC knowledge to AI-specific frameworks in Domain 4
- Identify terminology gaps early so they do not slow you down in Domain 2
Domain 2 - Part 1: Model and Gateway Controls
- Deep dive into AI model integrity, versioning security, and supply chain risks
- Study gateway controls: API security patterns and input validation for AI endpoints
- Begin timed practice questions focused on Domain 2 topics
Domain 2 - Part 2 + Domain 3
- Access controls, data security, and monitoring/auditing for AI systems
- Transition to Domain 3: AI-assisted detection, SOAR integrations, and anomaly tools
- Practice PBQ-style scenarios - see how to prepare for SecAI+ PBQs
Full Integration + Timed Exams
- Run complete 60-question practice exams under 60-minute time limits
- Review every missed question by domain to identify remaining weak areas
- Use full-length SecAI+ practice tests to simulate exam day conditions
The logic here is deliberate: Domain 4 and Domain 1 share foundational vocabulary that reduces cognitive load when you hit the dense technical content of Domain 2 in weeks two and three. Spending two full weeks on Domain 2 is justified by its 40% exam weight - it is the domain where passing scores are most often made or broken.
Retake Policy and Keeping the Cert Active
CompTIA's standard retake policy applies to SecAI+. After a failed first attempt, there is no mandatory waiting period before scheduling a second attempt. From the third attempt onward, candidates must wait at least 14 days between sittings. There is no published cap on total attempts.
Once earned, SecAI+ is valid for three years. Renewal requires participation in CompTIA's Continuing Education (CE) program, which carries an annual fee of $50. CEUs can be earned through activities like completing other CompTIA training, attending industry conferences, publishing relevant content, or holding other qualifying certifications.
Frequently Asked Questions
No. CompTIA lists no formal prerequisites for SecAI+. However, CompTIA recommends holding Security+, CySA+, or PenTest+ (or an equivalent certification) combined with 3-4 years of IT experience and at least 2 years of hands-on cybersecurity work. Attempting SecAI+ without that background is possible but significantly increases the difficulty of the material.
A single exam voucher costs $359 USD. The retake bundle - which includes one retake attempt - costs $408 USD, a $49 premium over the single voucher. For candidates who are uncertain about their readiness, the bundle is worth considering since a standalone second attempt would cost another full $359. You must use the voucher within a standard validity window, so read the terms when purchasing.
The passing score is 600 on a 100-900 scaled scoring range. CompTIA uses scaled scoring to account for slight variation in difficulty between different question sets. Your raw number of correct answers is converted to a scaled score, and you need at least 600 to pass. CompTIA has not publicly disclosed pass rate data since the exam launched on February 17, 2026.
Domain 2 - Securing AI Systems carries 40% of the exam weight - the single largest domain by a wide margin. Its five subtopics (model controls, gateway controls, access controls, data security controls, and monitoring and auditing) represent the core technical competencies the cert validates. Any study plan that does not allocate at least 40% of preparation time to Domain 2 is misaligned with where the points actually live.
Yes. Pearson VUE's OnVUE platform supports remote proctoring for SecAI+. Before your exam date, you will need to run Pearson's system check tool to confirm your hardware, camera, and internet connection meet requirements. OnVUE has strict rules about your testing environment - no secondary monitors, no other people in the room, and a clear desk. Run the system check at least 48 hours before your scheduled time so you can resolve any technical issues without last-minute stress.
Ready to Start Practicing?
Test your SecAI+ readiness with full-length practice exams built around the official CY0-001 V1 objectives. Timed, domain-mapped, and updated to reflect Exam Objectives Document Version 1.1 - the same version governing your actual exam.
Start Free Practice Test