CySA+ study guide
CompTIA Cybersecurity Analyst (CySA+) validates blue-team skills: detecting and analyzing threats, managing vulnerabilities, and responding to incidents in a SOC. It meets DoD 8140 requirements for many analyst roles.
Details below were checked in October 2026 against official and widely cited sources. Exams, prices, and requirements change, so confirm with the certifying body before you register.
Version change: CySA+ CS0-004 launched in June 2026. The English CS0-003 exam is reported to retire on December 22, 2026. CS0-004 adds AI in security operations and expands cloud, automation, and zero trust coverage.
Eligibility
- There are no formal prerequisites.
- CompTIA recommends Network+ and Security+ (or equivalent knowledge) and about four years of hands-on security experience.
Exam format & cost
| Current exam | CS0-004 (CS0-003 is still available until it retires) |
|---|---|
| Length | Up to 85 questions, 165 minutes, multiple choice and performance-based |
| Passing score | 750 on a 100–900 scale |
| Exam fee | About $404–$425 (US). Check CompTIA's store |
| Renewal | Valid for 3 years. Renew with CompTIA continuing education units or a qualifying higher certification |
Domains
| Domain | Weight |
|---|---|
| 1. Security Operations | 34% |
| 2. Vulnerability Management | 26% |
| 3. Incident Response and Management | 24% |
| 4. Reporting and Communication | 16% |
CS0-004 weights. CS0-003 used 33/30/20/17.
How to study
- Practice reading logs and alerts. Many questions give you evidence and ask what's happening.
- Prioritize vulnerabilities by exploitability and asset criticality, not just CVSS score.
- Know the incident response lifecycle and the order of volatility for evidence.
- Learn how to tailor reports for executives versus technical teams.
Ready to test yourself on CySA+?
Start CySA+ practice