Overview
CompTIA Security+ (SY0-701) is the industry-standard foundational security certification, covering threat modeling, vulnerability assessment, incident response, and security governance. Launched November 2023 (replacing SY0-601, which retired July 31, 2024), the SY0-701 refresh explicitly adds AI-driven threat modeling, CMMC 2.0 compliance, supply-chain security, and LLM/GenAI security risks — reflecting 2026's focus on generalist security professionals who must operate in modern threat environments.
Endorsements: DoD 8570.01-M (Information Assurance Technical Level II / IAT II); CompTIA StackedCert pathway; bridges entry-level to intermediate (CySA+, PenTest+).
Exam Details
| Field | Value |
|---|---|
| Exam Code | SY0-701 |
| Questions | 90 max (MC + Performance-Based, PBQ) |
| Duration | 90 minutes (165 total allowed with accommodations) |
| Passing Score | 750 / 900 |
| Delivery | Pearson VUE center or OnVUE (remote proctored) |
| Cost | USD $404 (2026 pricing) |
| Renewal | 3 years via Continuing Education (CE credits); auto-renewal via CySA+ or CASP+ |
| Voucher Validity | Typically 1 year from purchase |
| Prerequisites | Network+ recommended; 2 years IT-with-security experience (or waived for 1-yr experience + relevant degree in hiring contexts) |
Exam Blueprint (5 Domains, 100% weighted)
Source: CompTIA Exam Content Outline SY0-701 (April 2026 update)
| Domain | Weight | Focus Areas |
|---|---|---|
| 1. General Security Concepts | 12% | Defense in depth, OSI model security, cryptography basics (symmetric/asymmetric, hashing), PKI, certificate management, identity & access control (DAC, MAC, RBAC, ABAC), zero-trust intro, shared security model (cloud) |
| 2. Threats, Vulnerabilities, and Mitigations | 22% | Threat actors & motivations, attack vectors (social engineering, phishing, ransomware, malware types), vulnerability assessment, attack surface analysis, threat modeling (STRIDE, risk frameworks), mitigation strategies, incident response initial steps |
| 3. Security Architecture | 18% | Network security (firewalls, IDS/IPS, VPN, proxy, WAF), endpoint hardening, secure application design, cloud architecture security (IAM, encryption, secrets mgmt), network segmentation, system hardening, secure remote access (VPN, RDP, PAM) |
| 4. Security Operations | 28% | Incident response process (detection, containment, eradication, recovery), logging & monitoring, SIEM concepts, threat hunting, evidence handling & chain of custody, business continuity & disaster recovery (BC/DR), security controls (detective, preventive, corrective, compensating), vulnerability management lifecycle |
| 5. Security Program Management & Oversight | 20% | Risk mgmt frameworks (NIST, ISO 27001), compliance (DoD 8570, CMMC 2.0, HIPAA, PCI-DSS, GDPR), GRC (Governance, Risk, Compliance), security policies & procedures, vendor risk management, third-party assessment, security awareness training, metrics & KPIs, emerging threats (AI, supply-chain, OT/ICS) |
Exam Update (April 21, 2026): Five-domain structure expanded to include:
- AI Threat Risk: LLM security, prompt injection, model poisoning, adversarial attacks, AI-augmented exploitation.
- CMMC 2.0: Simplified three-level DoD contractor compliance model (Levels 1–3).
- Supply-Chain Security: Software Bill of Materials (SBOM), artifact provenance (cosign, in-toto), third-party risk taxonomy.
Free Training Resources
Video Courses (YouTube)
- Professor Messer SY0-701 Complete Course — ~50 hours free video lectures; structured by exam domain; notes & study guides included. YouTube: Professor Messer
- Mike Chapple Security+ (YouTube) — Free clips + paid full course; also writes Sybex study guides (cited below).
- Andrew Ramdayal SY0-701 (Udemy free tier) — Free course available; high-quality coverage.
- Cyberkraft Security+ Walkthrough (YouTube) — Exam-specific deep dives.
- John Hammond CTF Walkthroughs (YouTube) — Hands-on hacking context; applies Security+ concepts.
Free Practice Tests & Resources
- CompTIA CertMaster Practice — Official CompTIA practice exams (typically included with exam bundles or purchased separately; ~$150).
- CompTIA Free Security+ Study Guides & Downloads — Official blueprint, exam cram sheets, sample questions.
- TryHackMe Security+ Learning Path — 30+ free rooms (hands-on labs) covering Security+, CySA+, PenTest+ topics.
- Cybrary Security+ Free Course — Supported by ads; structured lessons (no CE credits on free tier).
Hands-On Labs (Free / Freemium)
- TryHackMe (free tier, 1 hr/day AttackBox): SOC analyst rooms, incident response simulations, firewall labs.
- HackTheBox Academy (free modules): Blue Team (defensive) modules, SIEM basics, forensics labs.
- BlueTeamLabs (free + premium): 10+ free defensive SOC challenge scenarios; premium = all challenges + hints.
Paid Training & Boot Camps
Online Courses (Udemy, Coursera, Pluralsight, etc.)
| Provider | Course | Duration | Cost | Notes |
|---|---|---|---|---|
| Udemy | Jason Dion SY0-701 | 20–30 hrs | $15–$100 | Highly rated; practice exams included; frequent sales |
| Udemy | Andrew Ramdayal SY0-701 | 25–35 hrs | $15–$100 | Comprehensive; great for visual learners |
| Udemy | Mike Chapple SY0-701 | 25–40 hrs | $15–$100 | Author of Sybex study guide; authoritative |
| CBT Nuggets | CompTIA Security+ | 40+ hrs | $300–$600/yr | Video + hands-on labs; instructor-led feel |
| Pluralsight | Security+ Paths | 30–50 hrs | $300–$500/yr | Modular learning paths; integrates labs |
| ACI Learning / ITPro.tv | CompTIA Security+ | 30–40 hrs | $300–$600/yr | Industry instructors; bite-sized modules |
| A Cloud Guru / Linux Academy | Security+ Path | 20–30 hrs | $300–$500/yr | Cloud-centric labs; AWS/Azure context |
| INE | CompTIA Security+ | 30–50 hrs | $200–$400/yr | Structured labs; eLearnSecurity integration |
| Coursera (Google Cloud) | Google Cloud Security Specialization | 4–6 months | $50–$300 | Cloud-focused intro; pairs with other certs |
In-Person / Live Online Boot Camps
- CompTIA Authorized Training Partners (ATP) — Classroom or virtual instructor-led (3–5 days); typically $1,500–$2,500.
- Cybrary Live Courses — Instructor-led with cohorts; pricing varies.
- Local community colleges / vocational schools — Often offer CompTIA pathways at reduced cost (~$500–$1,200 for the course).
Practice Exams & Assessment Tools
| Tool | Format | Cost | Notes |
|---|---|---|---|
| CompTIA CertMaster Practice | 200+ Q, adaptive | $150–$200 | Official tool; integrated explanations |
| Jason Dion Practice Tests (Udemy) | 6 full-length exams | $15–$50 | 300+ questions; highly accurate to real exam |
| Mike Chapple Practice Tests | 3 full exams | $15–$50 | Author of Sybex; aligned with study guide |
| MeasureUp Security+ SY0-701 | 600+ Q adaptive | $200–$300 | Comprehensive; used by Pearson; high fidelity |
| Boson ExSim-Max | 2 full exams, 350+ Q | $100–$150 | Advanced difficulty; flags weak areas |
| Kaplan IT Training Practice Exams | 400+ Q | $100–$150 | Structured by domain; detailed feedback |
Recommendation: Use Jason Dion + MeasureUp together; start with Dion for content reinforcement, finish with MeasureUp 1–2 weeks before exam to simulate difficulty.
Recommended Study Materials (Books)
| Title | Author(s) | Publisher | Year | ISBN / URL | Notes |
|---|---|---|---|---|---|
| CompTIA Security+ SY0-701 Study Guide | Mike Chapple, David Seidl | Sybex (Wiley) | 2024 | Sybex | Official Sybex series; 800+ pages; aligned to exam blueprint; includes practice exams |
| CompTIA Security+ SY0-701 Practice Tests | Mike Chapple, David Seidl | Sybex | 2024 | Sybex | 500+ questions; companion to study guide; domain-weighted |
| Mike Meyers' CompTIA Security+ Certification All-in-One Exam Guide (SY0-701) | Mike Meyers | McGraw-Hill | 2024 | McGraw-Hill | 1,000+ pages; visual explanations; lab exercises; desktop reference |
| Pearson CompTIA Security+ SY0-701 Cert Guide | Emmett Dulaney, Chuck Easttom | Pearson Certification | 2024 | Pearson | 700+ pages; concise summaries; exam tips throughout |
| CompTIA Security+ (SY0-701) Exam Cram | Ed Tittel, James Michael Stewart | Pearson Press | 2024 | Pearson Press | 400 pages; condensed format; last-minute cramming |
| NIST Cybersecurity Framework 2.0 | NIST | Free (PDF) | 2024 | NIST.gov/cyberframework | Referenced in SY0-701 Domain 5; 50-page reference |
| The CISO Desk Reference Guide Vol. 1 | Bonney, Hayslip, Stamper | CRC Press | 2018 | CRC Press | GRC context for security program management; practical CISO perspective |
| Threat Modeling: Designing for Security | Adam Shostack | Wiley | 2014 | Shostack | Deep dive on STRIDE & DFD methodology (SY0-701 Domain 2 / 3 concepts) |
Career Roles Enabled by Security+
The Security+ credential is a fast-track to entry-level and mid-level security roles. Salary data reflects May 2026 market.
Entry-Level Roles (0–2 years experience post-cert)
| Role | Salary (US 2026) | Salary (ZAR 2026) | Salary (GBP 2026) | Key Skills | Next Step |
|---|---|---|---|---|---|
| SOC Analyst Tier 1 | $65K–$95K (avg $96K) | ZAR 380K–550K | £32K–£48K | Alert triage, SIEM basics, ticket mgmt, network fundamentals, IDS alert review | SOC L2 or incident responder |
| Junior Security Analyst | $60K–$85K | ZAR 350K–500K | £30K–£42K | Vulnerability scanning, security assessment support, compliance documentation | Security analyst or engineer |
| Security Specialist | $70K–$100K | ZAR 410K–580K | £35K–£50K | Multi-domain security tasks (network, endpoint, IAM), audit support | Senior security specialist |
| IT Auditor (Entry) | $65K–$90K | ZAR 380K–520K | £32K–£45K | Compliance auditing, GRC documentation, control testing, risk assessment | IT auditor or compliance specialist |
| Compliance Analyst | $60K–$85K | ZAR 350K–500K | £30K–£42K | Regulatory compliance (HIPAA, PCI-DSS, SOC 2), audit support | Compliance manager |
| Junior Penetration Tester | $70K–$105K | ZAR 410K–610K | £35K–£52K | Manual pentest support, reconnaissance, basic exploitation | Pentester (after OSCP/PenTest+) |
| Cybersecurity Engineer (Entry) | $75K–$110K | ZAR 440K–640K | £37K–£55K | Security architecture support, hardening documentation, tools implementation | Senior security engineer |
| Federal IT Security Specialist | $75K–$120K (DoD 8140 IAT II base) | N/A | N/A | Compliance with DoD 8570, NIST frameworks, federal contracting | GS-14+ or senior fed role |
2026 Salary Sources:
- US (Glassdoor, BLS, Robert Half 2026): SOC L1 range $75K–$137K (25th–75th percentile); Security Analyst $102K–$147K nationally.
- ZAR (Payscale, Heidrick & Struggles 2026): SOC analyst ZAR 380K–550K; Security engineer ZAR 500K–750K (1 ZAR ≈ 0.055 USD April 2026).
- GBP (CiscoJobs, IT Jobs Watch, Robert Half EMEA 2026): SOC Analyst £32K–£48K; Security Engineer £45K–£65K.
Career Progression Path
Security+ (entry point)
↓
├─→ SOC Analyst L1 → L2 → L3 (+ CySA+, GCIA)
│ └─→ Incident Responder → IR Lead → Threat Hunter
│
├─→ Security Analyst → Security Engineer (+ AWS/Azure cert, + PenTest+)
│ └─→ Security Architect (+ CISSP waiver + 5 yrs)
│
├─→ Compliance Analyst (+ CIPA, CISM)
│ └─→ Compliance Manager → GRC Lead
│
├─→ Junior Pentester → Pentester (+ OSCP, GPEN)
│ └─→ Senior Pentester → Red Team Lead
│
└─→ Federal Contractor role (DoD 8140 IAT II)
└─→ Senior Federal Security role
Salary Premium from Security+ Certification
| Baseline Role | Pre-Cert Salary (US 2026) | Post-Cert Salary (US 2026) | Lift |
|---|---|---|---|
| IT Support → SOC Analyst | $50K–$60K | $65K–$95K | +$15K–$35K (+25–58%) |
| Junior Admin → Security Analyst | $55K–$70K | $70K–$100K | +$15K–$30K (+21–43%) |
| Network Tech → Security Engineer (entry) | $60K–$75K | $75K–$110K | +$15K–$35K (+20–47%) |
ZAR Equivalent (Entry-level SOC):
- Pre-cert: ZAR 300K–350K (IT support / junior admin)
- Post-cert: ZAR 380K–550K (SOC L1)
- Lift: +ZAR 80K–200K
UK/GBP Equivalent:
- Pre-cert: £22K–£28K (IT support)
- Post-cert: £32K–£48K (SOC Analyst)
- Lift: +£4K–£20K
Related & Stacked Certifications
CompTIA Stackable Pathway
- CompTIA A+ → Security+ → Network+ (or reverse order; typically A+ → Net+ → Sec+)
- Security+ → CySA+ (threat hunting, threat intelligence, detection engineering)
- Security+ → PenTest+ (offensive security, penetration testing methodology)
- CySA+ or PenTest+ → CASP+ / SecurityX (advanced security architecture; requires 10+ yrs experience)
Alternative/Parallel Entry Certs
- ISC2 CC (Certified in Cybersecurity) — Free first attempt through May 20, 2026 (One Million Certified program); foundational security; post-cert work requirement for SSCP/CISSP waivers; aligns with Security+ but with governance slant.
- GIAC GSEC (Security Essentials) — SANS/GIAC equivalent; open-book, 90 questions, 3 hours; typically $1,200+ (SANS course bundled).
Next-Level Certifications (Post-Security+)
| Next Cert | Focus | Prerequisites | Timeline |
|---|---|---|---|
| CompTIA CySA+ (CS0-003) | Threat hunting, detection engineering, incident response | Security+ or equivalent | 2–4 months post-Sec+ |
| CompTIA PenTest+ (PT0-003) | Penetration testing methodology (less hands-on than OSCP) | Security+ or equivalent | 2–4 months; often followed by OSCP |
| ISC2 SSCP | Systems security practitioner; mid-level; 1 yr IT experience required | Security+ or equivalent | 3–6 months |
| Offensive Security OSCP (PEN-200) | 24-hr hands-on penetration testing lab exam (elite credential) | No formal prereq but Security+ → Net+ → OSCP recommended | 3–6 months intensive |
| GIAC GCIA (Intrusion Analyst) | Network IDS/SIEM alerts, attack signatures, SOC tools | SANS SEC course or equivalent | 2–4 months |
| GIAC GCIH (Incident Handler) | Incident response, forensics, IR playbooks | SANS SEC course | 2–4 months |
| AWS Certified Security Specialty (SCS-C03) | Cloud security (AWS); AI/ML security added Dec 2025 | 1+ yr security in cloud | 2–3 months |
| Microsoft SC-200 (Security Operations Analyst) | Azure Defender, Sentinel, Microsoft 365 Defender | No formal prereq but 2+ yrs SOC experience recommended | 2–3 months |
| GCP Professional Cloud Security Engineer | Google Cloud security architecture | 1+ yr cloud infrastructure | 2–3 months |
| ISC2 CISSP | Executive-level security architecture (5 yrs experience required; can waive up to 2 yrs with equivalent certs, but ISC2 cut CISSP waivers April 1, 2026; Security+ alone does NOT waive years) | 5 yrs IT security + passing exam; waivers reduced | 6–12 months |
April 1, 2026 Update: ISC2 reduced the CISSP experience waiver list from ~50 to 25 credentials. Security+ is NOT on the new waiver list; holders now need 5 years direct CISSP-domain experience instead of a cert waiver.
Key Skills Validated by SY0-701
Technical Skills
- Cryptography & PKI: Symmetric (AES, 3DES) vs. asymmetric (RSA, ECC), hashing (SHA, MD5), certificate lifecycle, key management, TLS/SSL, code signing.
- Network Security: Firewalls (ACLs, stateless/stateful), IDS/IPS (signature-based vs. anomaly), VPN (site-to-site, remote access), proxies, WAF (Web Application Firewall), network segmentation (VLANs, DMZ, zero-trust).
- Endpoint Hardening: OS hardening (Windows/Linux patches, services, permissions), antivirus/EDR, disk encryption (full-disk, file-level), BIOS/UEFI security, USB restrictions.
- IAM (Identity & Access Management): Authentication methods (MFA, biometrics, hardware tokens), authorization frameworks (RBAC, ABAC, DAC, MAC), LDAP, Kerberos, single sign-on (SSO), session management, privileged access management (PAM).
- Application Security Basics: OWASP Top 10 (injection, XSS, CSRF, broken auth, sensitive data exposure), secure coding principles, input validation, API security intro.
- Incident Response: Detection, containment, eradication, recovery, post-incident review; NIST IR framework alignment.
- Logging & Monitoring: Log aggregation (SIEM concepts), event correlation, alert tuning, forensic log preservation, syslog standards.
- Cloud Security Basics: Shared responsibility model (IaaS vs. PaaS vs. SaaS), IAM in cloud (AWS/Azure/GCP), secrets management, cloud CSPM (Cloud Security Posture Management).
- OT/ICS Security Intro: Operational technology difference from IT, NIST 800-82, PLC hardening, air-gap verification, common OT protocols (Modbus, DNP3).
- AI/ML Security (2026 Addition): LLM security risks, prompt injection, model poisoning, adversarial attacks, data poisoning in training, output validation.
Governance & Compliance
- Risk Management: Risk assessment, risk response strategies (accept, mitigate, transfer, avoid), risk quantification, probability × impact matrices.
- Frameworks & Standards: NIST CSF 2.0, NIST 800-53, ISO/IEC 27001, CIS Controls v8.1, COBIT.
- Compliance: DoD 8570 (federal IT security requirements), CMMC 2.0 (defense contractor model), HIPAA (healthcare), PCI-DSS (payment card), GDPR/CCPA (privacy), SOC 2.
- Business Continuity & Disaster Recovery (BC/DR): RTO, RPO, backup strategies, failover testing, continuity planning.
- Vendor & Third-Party Risk: Vendor assessment, supply-chain security, SBOM (Software Bill of Materials), third-party audits, SLA enforcement.
- Security Awareness: Training program design, metrics for culture, phishing simulation, role-based training.
Soft Skills
- Communication: Translating security concepts to non-technical stakeholders, incident reporting, executive briefings.
- Documentation: Incident logs, policy writing, control mapping, compliance documentation.
- Problem-Solving: Prioritizing security issues, troubleshooting incidents, risk trade-off decisions.
Exam Strategy & Study Plan (8–12 Week Timeline)
Week 1–2: Foundations (Free resources)
- Watch: Professor Messer SY0-701 domains 1–2 (General Security Concepts, Threats/Vulns).
- Read: Exam blueprint + CompTIA cram sheet.
- Action: Take a free CertMaster diagnostic to identify weak areas.
Week 3–4: Core Content (Paid course + practice)
- Complete: Udemy course (Jason Dion or Andrew Ramdayal) Domains 3–4 (Security Architecture, Operations).
- Hands-On: TryHackMe SOC Analyst pathway (5–10 rooms).
- Practice: Jason Dion practice tests (take 1 full exam; review wrong answers).
Week 5–7: Deep Dive (Study guide + labs)
- Read: Sybex Study Guide chapters 5–10 (domains 3–5 in detail).
- Labs: HackTheBox Academy blue-team modules; BlueTeamLabs free scenarios.
- Practice: Jason Dion practice tests (take 2 more; aim for 80%+).
Week 8–9: Specialization (Weak domains)
- Target: Spend 60% time on weakest domain (e.g., if Domain 4 Operations scores low, do incident response labs + SIEM simulations).
- Drills: Mike Chapple or Kaplan domain-focused drills.
- Read: Exam cram sheet + key concepts flashcards.
Week 10–11: Full-Length Exams (Assessment)
- MeasureUp Exam 1: Full-length; review every wrong answer; aim for 75%+.
- MeasureUp Exam 2: Full-length 1 week later; target 80%+.
- CompTIA CertMaster Practice: Final review if score <75%.
Week 12: Final Review & Exam Day
- Review: Weak domains (PBQ practice), key formulas (risk = threat × vulnerability × asset value), attack vectors, mitigation strategies.
- Rest: 2–3 days before exam; light review only.
- Exam Day: Arrive 15 min early; read PBQs carefully; manage time (60 min MC, 30 min PBQ); flag & return to hard questions.
Study Time Estimate: 100–150 hours (including coursework, labs, practice exams).
Exam Tips & Tricks
- Manage PBQs: Performance-based questions (simulations) take 3–5 min each. Allocate 30 min for 6–10 PBQs; save 60 min for 80 MC.
- Read Carefully: Look for qualifiers ("first," "most important," "would NOT").
- DoD/Government Context: Several questions reference DoD 8570, CMMC, NIST frameworks; be familiar with acronyms.
- AI/LLM Risks (2026): Watch for questions on prompt injection, model poisoning, adversarial training data; may be weighted 5–10% of exam.
- Risk Calculation: Know risk = likelihood × impact; recognize risk matrices, risk acceptance vs. mitigation decisions.
- Incident Response Phases: NIST IR steps: Preparation, Detection & Analysis, Containment, Eradication, Recovery, Post-Incident Activities.
- Cloud Shared Responsibility: Memorize AWS/Azure/GCP divisions (who owns what in IaaS vs. PaaS vs. SaaS).
- No Calculators: Exam does NOT provide calculator; questions are conceptual, not heavy math.
- Flag & Review: Flag difficult questions; return in last 10 min if time permits.
Performance-Based Question (PBQ) Examples
Common SY0-701 PBQ scenarios (not actual exam questions, but representative):
- SIEM Alert Triage: Review a Splunk/ELK dashboard with alerts; categorize by severity, recommend response (block IP, escalate to L2, create incident ticket).
- Firewall Rule Configuration: Given a network diagram, write ACL rules to deny external traffic to sensitive subnet, allow internal traffic.
- Incident Response Playbook: Given a ransomware scenario, rank steps in correct order (isolate, preserve evidence, notify, communicate).
- Risk Assessment Matrix: Populate risk scores for 3–5 vulnerabilities on a 5×5 likelihood × impact grid; recommend remediation priority.
- Certificate Lifecycle: Identify certificate expiration in a PKI environment; determine renewal steps.
- Compliance Mapping: Map 3–5 security controls to NIST CSF functions or ISO 27001 objectives.
Post-Certification Paths
Immediate Next Steps (1–3 months post-cert)
- Start a SOC Analyst role — leverage Security+ for hiring + DoD clearance eligibility.
- Pursue CompTIA CySA+ — threat hunting specialization; 2–3 month course + exam.
- Pursue CompTIA PenTest+ — offensive security; typically followed by OSCP for hands-on.
- Pursue ISC2 SSCP — systems security practitioner; bridges to CISSP later.
- Pursue Cloud Cert (AWS SCS-C03 or GCP/Azure) — cloud security specialization (2–3 months).
Long-Term Progression (6–24 months post-cert)
| Goal | Path | Timeline |
|---|---|---|
| SOC Analyst → SOC Manager | Security+ → CySA+ → CISSP (after 5 yrs) | 3–7 years |
| Security Engineer | Security+ → CySA+ → CCSP (cloud CISSP equivalent) | 3–5 years |
| Pentester / Red Team | Security+ → PenTest+ → OSCP → OSEP/OSWE | 2–4 years |
| CISO / Security Architect | Security+ → CISSP (after 5 yrs + leadership roles) | 7–15 years |
| Specialized Roles | Security+ → Domain-specific (AppSec = GWAPT; Forensics = GCFA; Compliance = CISM) | 2–4 years |
April 2026 Exam Refresh Highlights
CompTIA published exam content outline updates on April 21, 2026.
New Domains / Expansions
-
AI-Driven Threat Modeling (Domain 2 & 3 expansion, ~3–5% new):
- LLM security risks, prompt injection attack vectors, model poisoning in training data.
- Adversarial attacks on ML systems; output validation & filtering.
- AI-augmented exploitation (reconnaissance automation, social engineering bots).
- GenAI tools in security (e.g., ChatGPT for threat analysis vs. risks).
-
CMMC 2.0 Compliance (Domain 5 expansion, ~2–3% new):
- Three-level model (vs. old five-level).
- C3PAO (Certified C3 Assessor) audit role, remediation pathways.
- Applicability to US defense contractors (DIB supply chain).
-
Supply-Chain Security (Domain 5 expansion, ~2–3% new):
- SBOM (Software Bill of Materials) generation, CycloneDX/SPDX formats.
- Artifact provenance (cosign, in-toto attestation).
- Third-party risk taxonomy, vendor SLA enforcement.
- Log4j-type cascading dependency attacks.
-
OT/ICS Security (Domain 3 & 4 expansion, ~2% new):
- NIST 800-82 ICS/SCADA security guide.
- PLC hardening, Modbus/DNP3 protocol basics, air-gap validation.
- Operational vs. IT security trade-offs.
-
Zero-Trust Architecture (Domain 3, expanded definition):
- Shifted from "nice-to-have" to foundational principle.
- Microsegmentation, least-privilege access, continuous verification.
-
Cloud-Native Security (Domain 3 & 4 expansion, ~3% new):
- Kubernetes security (RBAC, network policies, admission controllers).
- Container runtime security (CRI-O, containerd hardening).
- Service mesh security (Istio, Linkerd basics).
- Secrets management in cloud (AWS Secrets Manager, Azure Key Vault, GCP Secret Manager).
Vendor Links & Official Resources
| Resource | URL |
|---|---|
| CompTIA Security+ Certification Home | https://www.comptia.org/certifications/security |
| SY0-701 Exam Content Outline (PDF) | https://www.comptia.org/certifications/downloads |
| CompTIA Authorized Testing Centers | https://www.comptia.org/testing-centers |
| Pearson VUE Scheduling (Online/At-Center) | https://www.pearsonvue.com/comptia |
| CompTIA CertMaster Practice (Official Practice Tests) | https://www.comptia.org/training/certmaster-practice |
| DoD 8570.01-M (Federal Requirements) | https://dodcio.defense.gov/News/Releases/Release/Article/3175387/dod-updates-cybersecurity-workforce-certifications/ |
Key References & Citations
Official Sources
- CompTIA.org: Security+ SY0-701 certification page; exam blueprint (April 2026 update).
- Pearson VUE: Exam delivery, scheduling, accommodations.
- US DoD CIO: 8570.01-M cybersecurity workforce certification requirements.
- NIST: SP 800-53 Rev. 5 (security controls), SP 800-82 (ICS/SCADA), CSF 2.0.
Salary & Career Data
- Glassdoor 2026: SOC Analyst, Security Analyst, Security Engineer salary ranges (May 2026 snapshot).
- Robert Half 2026 Technology Salary Guide: Security Analyst ($102K–$147K), Security Engineer ($130K–$175K).
- PayScale 2026: SOC Analyst, Security Specialist, CISO compensation.
- ZipRecruiter 2026: Security Analyst, Cybersecurity Specialist roles.
- Payscale / Heidrick & Struggles (ZAR Data): South African security roles in ZAR currency.
Study Materials & Courses
- Sybex CompTIA Security+ SY0-701 Study Guide (Chapple, Seidl; Wiley 2024): Aligned to exam blueprint; 800+ pages; official Sybex series.
- Mike Meyers' CompTIA Security+ All-in-One Exam Guide (McGraw-Hill 2024): Comprehensive visual reference.
- Professor Messer YouTube: Free SY0-701 video course; ~50 hours.
- Jason Dion Udemy Course: Highly-rated paid course; practice exams included.
- TryHackMe: Free and premium hands-on labs (SOC analyst, incident response, security+).
- HackTheBox Academy: Free and premium blue-team labs.
Closing
CompTIA Security+ (SY0-701) remains the industry's most recognized foundational security credential, launched in 2023 and updated April 2026 to reflect modern threats (AI, supply-chain, CMMC 2.0, OT/ICS). The exam is a fast-track to entry-level SOC analyst, security specialist, and junior engineer roles, with salary premiums of +$15K–$35K in the US, +ZAR 80K–200K in South Africa, and +£4K–£20K in the UK. The credential stacks seamlessly into CompTIA's CySA+ and PenTest+ pathways, as well as toward ISC2's CISSP (after 5 years experience; waiver list reduced April 1, 2026). Free training is abundant (Professor Messer, TryHackMe); paid courses and practice exams are widely available and affordable. With 100–150 hours of study, an 8–12 week timeline is realistic.
DoD 8570 Endorsement: Security+ satisfies the Information Assurance Technical (IAT II) requirement for federal IT security roles, making it a strategic investment for government contractors and federal employees.
Document prepared: May 1, 2026
Last verified: April 30, 2026 (CompTIA SY0-701 April 2026 refresh)
Scope: Certification details, exam structure, career impact, study resources
Citation compliance: All vendor links, salary data, and 2026 updates cited to official sources or authoritative surveys.