AssociateVendor-neutralISO 17024CompTIA· issued from US

CySA+

CompTIA Cybersecurity Analyst+

SOC analyst skills: triage, log analysis, vulnerability management basics.

Exam fee
$404
Ongoing
$50/yr AMF · 20 CPE/yr
Study time
60–120 hrs
Delivery
Test center
Validity
3 yrs (renewal cycle)

› Quality score

27.0 / 40

Four-axis SecProve rubric, each 0–10. SecProve editorial assessment — each axis carries a written justification so you can push back on any single call without dismissing the whole score.

Blueprint rigor
How well-defined and rigorous the exam blueprint is.
Solid SOC-analyst blueprint. Some critics say it overlaps Security+ more than it differentiates.
7.0/10
Practical evidence
Hands-on labs / written reports vs pure MCQ.
PBQs include log-triage and vuln-scope simulations — closer to the SOC bench than CompTIA's other certs.
5.0/10
Currency & upkeep
How aggressively content is kept current with the field.
Refreshed in 2023 (CS0-003) with DFIR and threat-intel content.
7.0/10
Market recognition
How often this signal actually moves a hiring decision.
DoD 8570 IAT-II / CSSP-Analyst; widely accepted on SOC postings. [Holders: 50k, 2024-12] [DoD 8140 listed]
8.0/10

› Market signals

public, citable inputs to the recognition score
Holders worldwide
50,000
as of 2024-12 · source
DoD 8140 baseline
Listed
IAT-II, CSSP-Analyst, CSSP-IR

› Built for these roles

SOC Analyst (Tier 1–2)Vulnerability AnalystJunior Threat HunterSecurity Operations Engineer

› Exam format

Up to 85 questions, 165 minutes. Mix of multiple-choice and performance-based items — log triage, alert review, scoping a vuln scan. Pearson VUE in person or online proctored.

Passing score
750/900 (~83%)
Retake policy
Fee: $404 per attempt
Wait: 0d between attempts

Immediate first retake; 14-day wait between subsequent attempts.

› Recertification

60 CompTIA CEUs over the three-year cycle (avg 20/yr) plus the $50/yr Continuing Education Program fee. Higher-tier CompTIA certs auto-renew CySA+.

› 3-year cost of ownership

Exam (1×)
$404
AMF (3×)
$150@$50/yr
Total
$554

Excludes study materials, training, retake risk, and lost-wage opportunity. Use as a floor estimate.

› NICE Framework work roles

The NIST NICE work-role IDs this cert maps to. NICCS lookup.

PD-WRL-001PD-WRL-008IO-WRL-001
Recognition
GlobalUSEUUK
Exam languages
enja

› Core domains covered

The 3 domains this cert is centrally about. Passing the exam demonstrates working knowledge of each.

› Also touched

Present in the blueprint but not the primary focus — you’ll be introduced but shouldn’t expect depth.

› Prerequisites

Experience

Three to four years of hands-on experience in an information-security or related role recommended.

Knowledge assumed
  • Security+ level knowledge
  • Log analysis and SIEM basics
  • Vulnerability management concepts

› Progression

requiredrecommended

Where this cert fits in the typical learning path. Required edges are vendor-gated; recommended edges reflect de facto industry progression.

Required prereqs (0)

No vendor-gated prereqs.

Recommended priors (1)
CySA+
CompTIA
Required by (0)

No certs require this one.

Recommended next (2)

› Study materials

Curated starting points. Not exhaustive — vet each against your learning style and the current exam version.

Official guides
  • CompTIA CySA+ Study Guide (CS0-003) by Mike ChappleSybex
  • CompTIA CySA+ Cert Guide (CS0-003)Pearson IT Certification
Training providers
Practice tests
  • Boson ExSim-Max for CySA+ CS0-003
  • Jason Dion Practice Exams (Udemy)

› Version & lifecycle

Current version
CS0-003
Released
2023-06
Prior-version EOL
2024-12

CS0-002 retired 2024-12. Performance-based questions test SOC analyst skills.

› Salary signal

SOC analyst tier 2 / threat hunter, US, 2–5 years.

$75K$110K
median $92K

Robert Half Salary Guide + Glassdoor 'SOC Analyst' aggregations · 2024 · US base only · p25–p75 range

› How it compares

vs
GCIH

Hands-on incident-response depth (GCIH) vs CySA+'s broader SOC analyst coverage.

↔ Compare side-by-side
vs
Security+

Natural CompTIA next step from Security+ for SOC analyst tracks.

↔ Compare side-by-side

› Careers that commonly pursue this cert

SOC Analyst

Monitor, detect, and respond to security threats in a Security Operations Center. The front line of cyber defense.

Vulnerability Management Lead

Owns the end-to-end find → prioritize → fix → verify loop at scale, now increasingly AI-driven.

Threat Exposure Management / Attack Surface Analyst

External-first role: inventories what an attacker can see, tracks what's new, and drives closure through the org. The outside-in counterpart to vuln management.

See this cert’s domains highlighted on the interactive map, or compare it against the rest of the catalog.