CompTIA SecurityX

CompTIA · CAS-005 · Expert

CompTIA · CompTIA Cybersecurity Pathway

CompTIA SecurityX

CAS-005● activeExpert
Official CompTIA source · comptia.org ↗

CAS-005 · ● Active · Expert · CompTIA

CompTIA SecurityX (CAS-005) is the rebranded successor to CASP+ (CAS-004), launched December 17, 2024. This advanced-level certification emphasizes enterprise security architecture, governance/risk/compliance (GRC), and engineering at scale. It is DoD 8140 approved for IAT III / IAM III federal positions. The previous CASP+ exam (CAS-004) retired June 17, 2025; all future candidates must take CAS-005.


Exam facts

FieldValue
Cost$509 USD
Duration165 minutes
QuestionsMax 90 (heavily performance-based questions / PBQs)
PassingPass/fail (no scaled score reported)
FormatMultiple choice / Performance-based questions (PBQs)
DeliveryPearson VUE or OnVUE (online proctored)
LanguagesEnglish
Valid3 years
Renewal75 CEUs required per 3-year cycle ($150 renewal fee per 3 years or $50/year)
PrerequisitesCompTIA recommends: 10 years IT experience, 5 years technical security experience
ReleasedDecember 17, 2024
RetiringCAS-004 (predecessor) retired June 17, 2025

Vendor source — CompTIA SecurityX ↗ Official exam guide — CAS-005 Exam Objectives (Version 3.0) ↗ Exam topics — CompTIA Blog: Introducing SecurityX ↗


About

CompTIA SecurityX (CAS-005) is the 2024 rebranding and evolution of CASP+ (CAS-004), reflecting CompTIA's shift toward governance, risk, and compliance (GRC) alongside traditional security engineering and architecture. The exam is ANSI accredited and reflects a significant pivot in emphasis: where CASP+ focused heavily on hands-on technical security engineering, SecurityX balances GRC (governance frameworks, risk management, compliance) with security architecture and operations. It is DoD 8140-approved for federal Senior Cyber Engineer positions and IAT III / IAM III work roles. The certification is designed for senior security engineers, architects, and leaders with substantial hands-on experience (CompTIA recommends 10 years IT, 5 years security).


Domain context — Security

Vendor-neutral advanced security architecture, engineering, and governance at enterprise scale. Encompasses cryptographic systems, zero-trust design, threat hunting, incident response, cloud/hybrid security, supply chain security, and compliance frameworks. Cross-references: CISSP, ISSAP, GIAC GSE.

Read full deep dive — CompTIA Cybersecurity Pathway →


Topics covered

CompTIA SecurityX CAS-005 exam blueprint (Version 3.0) covers four primary domains with approximate weights:

  • Governance, Risk, Compliance (GRC) (~20%) — Security policies, risk assessments, threat modeling, third-party/supply chain risk, data integrity/confidentiality, compliance frameworks (PCI-DSS, HIPAA, SOC 2, GDPR), incident response, breach notification
  • Security Architecture (~25%) — Enterprise environment design, hybrid cloud/on-premises, zero-trust and perimeter design, cryptographic solutions, IAM architecture, secure communications protocols
  • Security Engineering (~25%) — Systems integration/configuration, vulnerability management, advanced threat protection, cloud security engineering, automation/orchestration, secure development (DevSecOps)
  • Security Operations (~30%) — Monitoring/detection/incident response, advanced threat hunting and forensics, SIEM/SOC at enterprise scale, automation and playbook development, disaster recovery and business continuity, security metrics

Source: CAS-005 Exam Objectives PDF ↗


Common skills at Security · Expert

Shared competencies expected of security professionals at the expert level across all vendors and specializations.

  • Enterprise security architecture across heterogeneous and hybrid environments
  • Advanced cryptography including post-quantum readiness and key management
  • Zero-trust design and advanced perimeter security strategies
  • Governance, risk, and compliance (GRC) frameworks at enterprise scale
  • Supply chain security and third-party risk management
  • Advanced threat hunting and behavioral analytics
  • Incident response and forensic investigation at scale
  • Secure software supply chain and DevSecOps practices
  • Security metrics and boardroom-level reporting

Recommended courses at Security · Expert

ProviderTitleCostURL
CBT NuggetsCompTIA SecurityX (CAS-005) Online TrainingSubscription↗
Dion TrainingCompTIA SecurityX Complete Course, Labs, & Practice Exams$X–$Y↗
PluralsightCompTIA SecurityX / CASP+ Learning PathSubscription↗
UdemyCompTIA SecurityX (CAS-005) Complete Course & Practice Exam$10–$15 (on sale)↗
CybraryCompTIA CAS-005 SecurityX (formerly CASP)Free↗
New HorizonsCompTIA SecurityX Certification Training$X↗
LearnQuestCompTIA SecurityX Exam Voucher Training$X↗
CompTIA (Official)SecurityX Educational Units & CE ResourcesFree/Paid↗

Course-selection rule: Each course is specifically for CAS-005 SecurityX, not generic CompTIA security. Most include sandbox labs for practicing enterprise scenarios, cryptography, and threat response.


Practice exams

ProviderTitleCostURL
MeasureUpCAS-005 CompTIA SecurityX Practice Test$X↗
MeasureUpCAS-005 Diagnostic AssessmentFree↗
Dion TrainingCAS-005 Practice Exam Pack (Unlimited)$X↗
ExamTopicsFree CAS-005 Practice QuestionsFree↗
EDUSUMFree Sample Questions & Study GuideFree↗

Note: Boson ExamSim does not yet offer a CAS-005 product as of May 2026. CertMaster (CompTIA's official practice platform) coverage is still being rolled out for SecurityX.


Books

TitleAuthorPublisherYearISBNURL
CompTIA SecurityX (CAS-005) Study GuideSteve Brown (and others)Sybex / Pearson (in development)2025TBD↗
COMPTIA SECURITYX Question Bank & Study GuideAnand MAmazon Self-Pub2025N/A↗
CASP+ CompTIA Advanced Security Practitioner Study Guide: Exam CAS-004Nadean Tanner, Jeff ParkerSybex2022978-1119754954↗

Book rule: Full CAS-005-specific study guides from major publishers (Pearson, Sybex) are in active development as of May 2026. The CASP+ CAS-004 study guide above is the most recent comprehensive reference for SecurityX prerequisites and overlap. Many candidates use older CASP+ books as foundational prep before the CAS-005 exam.


Typical job titles at Security · Expert

Senior Security Engineer · Security Architect · Chief Security Architect (CSA) / Senior CSA · Federal Senior Cyber Engineer · Security Operations Manager · Incident Response Lead / Forensics Director · Enterprise Risk Manager

(Job titles drawn from current job-board postings that list SecurityX or equivalent advanced security certs as required or preferred.)


Salary

RegionRangeSource
USD$127,450–$185,000Infosec Institute ↗
ZARR850,000–R1,600,000Based on comparable advanced security architect roles (no SecurityX-specific ZAR data available; extrapolated from CISSP/advanced security market rates)
GBP£70,000–£110,000Based on UK advanced security architect roles (limited SecurityX-specific data; aligned with CISSP/advanced UK rates)

Salary rule: USD data is SecurityX-specific survey from Infosec Institute (May 2026). ZAR and GBP ranges are extrapolated from comparable advanced security architect roles and CISSP equivalents, as direct SecurityX salary data by region is still sparse. CompTIA-certified security professionals at the advanced level (SecurityX/CISSP) typically earn 15–25% premium over mid-level roles (CySA+/PenTest+).


Skills validated

Cert-specific technologies, frameworks, and practices that this exam directly tests.

  • Enterprise security architecture across heterogeneous infrastructure (on-premises, hybrid cloud, multi-cloud)
  • Advanced cryptography — algorithms, implementations, key management, hardware security modules (HSMs), cryptanalysis, post-quantum readiness
  • Zero-trust architecture — NIST SP 800-207, identity-centric security, microsegmentation
  • Hybrid and cloud security — AWS, Azure, GCP; shared responsibility models; Infrastructure-as-Code (IaC) security
  • Identity and access management (IAM) at enterprise scale — federated identity, attribute-based access control (ABAC), privilege management
  • Advanced incident response and forensic investigation — NIST incident response lifecycle, eDiscovery, legal hold, chain of custody
  • Advanced threat hunting — MITRE ATT&CK framework, behavioral analytics, log analysis, threat intelligence integration
  • Security engineering in complex federated systems — systems design, secure integration, authentication protocols
  • Governance, risk, and compliance (GRC) — risk frameworks (NIST RMF, ISO 27001), compliance automation, policy management, audit trails
  • Vendor and supply chain risk management — third-party assessment, SLAs, vendor dependency mapping
  • Secure DevOps and software supply chain security — container security, GitOps, SAST/DAST/IAST, secure code review, artifact signing
  • Security metrics and analytics — board-level reporting, key risk indicators (KRIs), security dashboards
  • Business continuity and disaster recovery (BC/DR) planning — RTO/RPO, failover strategies, recovery testing
  • Emerging technologies — AI/ML security implications, blockchain, quantum computing readiness

Related certifications

  • Stacks with: CompTIA CySA+ (CS0-003) or PenTest+ (PT0-002) for cross-domain security breadth; AWS Certified Security – Specialty for cloud depth; Azure Security Engineer Expert (AZ-500) for Microsoft ecosystem
  • Prerequisite for: CISSP (ISC²) — SecurityX validates hands-on expertise; ISSAP (ISC²) — architecture specialization; ISSMP (ISC²) — management track
  • Replaces: CAS-004 (CASP+ V4, retired June 17, 2025); CAS-003, CAS-002 (earlier CASP versions, retired)
  • Equivalents at this level: CISSP (ISC², broader governance focus), GIAC GSE (hands-on technical depth), CCSP (cloud-specific), CISM (risk/governance focus)
  • Vendor overview: CompTIA Vendor Overview ↗

Sources


Last verified: 2026-05-01 Parent ecosystem: CompTIA Cybersecurity Pathway Parent domain: Security Vendor overview: CompTIA Overview

Rate this cert
…
Was this helpful?
Comments (—)
0/2000