CASP+ to SecurityX (CAS-005): What Actually Changed

CASP+ to SecurityX (CAS-005): What Actually Changed

SecurityX (CAS-005): What Actually Changed

If you know CompTIA's advanced security credential as CASP+, you're not out of date — you're just one rename behind. CASP+ became SecurityX, and the exam moved from CAS-004 to CAS-005. But the change is more than a new label. This article explains what stayed the same, what's genuinely new, and what it means for how you study.

For the full current picture, see the complete SecurityX guide. This piece focuses on the transition.

The rename, briefly

CompTIA retired the CASP+ name and folded the certification into its Xpert Series as SecurityX, alongside credentials like DataX and CloudNetX. The final CASP+ exam, CAS-004, retired on June 17, 2025. CAS-005 is now the only current version.

If you already held CASP+, your credential was recognized as SecurityX without re-testing — the underlying certification is continuous. What changed for new candidates is the exam content and structure.

What stayed the same

The DNA is intact. SecurityX is still:

  • An expert-level, hands-on certification for senior technical practitioners — architects and engineers, not managers.
  • Pass/fail with no scaled score.
  • Up to 90 questions in 165 minutes, mixing multiple-choice, multiple-select, and performance-based items.
  • Aimed at people with roughly 10 years of IT experience, including about 5 in hands-on security.
  • ANSI-accredited to ISO 17024.

So if you studied CASP+ before, you're not starting over. Much of your foundation carries directly.

What's genuinely new in CAS-005

Here's where your study time needs to shift. CompTIA modernized the content to reflect how enterprises actually operate now:

  • Consolidated objectives. The objective count dropped from 28 to 23. The exam is streamlined, not easier — overlapping topics were merged, not removed.
  • AI security. SecurityX now addresses the information-security challenges of artificial intelligence, including AI threat modeling — a topic that barely existed when CASP+ launched.
  • Post-quantum cryptography. Entirely new. Earlier versions covered traditional cryptography; CAS-005 expects awareness of the post-quantum shift.
  • Zero trust and SASE as core architecture. These moved from passing mentions to central architectural concepts you're expected to design around.
  • Compliance-as-code. Automated compliance checking integrated into DevOps pipelines, reflecting modern secure delivery.
  • Cloud-native and hybrid by default. Where CASP+ often assumed traditional infrastructure, SecurityX assumes cloud-native and hybrid environments as the baseline.

The four-domain structure — Governance, Risk, and Compliance; Security Architecture; Security Engineering; and Security Operations — organizes all of this. We break down each domain and its weight in the domains guide.

How to study if you're coming from CASP+

Three moves make the transition efficient:

  1. Don't re-study what you already know cold. Your CASP+ foundation in risk, architecture, and operations largely holds. Skim it, confirm it, move on.
  2. Front-load the new topics. Give real attention to AI security, post-quantum cryptography, zero trust/SASE architecture, and compliance-as-code. These are the most likely to catch an experienced candidate off guard.
  3. Refresh your hands-on skills for cloud-native and DevSecOps. If your day-to-day is still traditional infrastructure, the cloud-native default is where lab practice pays off most.

A realistic schedule that accounts for both the familiar and the new is laid out in the study plan.

Make sure your materials are current

The single biggest mistake in this transition is studying from CAS-004 materials. They'll cover the shared foundation but miss the new content entirely — and using unofficial "brain dumps" also violates CompTIA's candidate agreement, which can cost you your certification. Use current, official CAS-005 resources.

Study the current objectives: CompTIA CertMaster Perform for SecurityX (CAS-005) integrates up-to-date learning and hands-on labs. When you're ready to certify, an official CAS-005 voucher is here. As an Authorized CompTIA Partner, we carry official, current versions only.

A note on voucher eligibility: Voucher eligibility depends on your exam testing location, per CompTIA policy. Testing in an emerging-market region? We don't sell those here — contact us.

FAQ

Is SecurityX just a rebrand of CASP+? It's a rebrand and a content update. The name changed and CAS-004 became CAS-005, which consolidated objectives and added modern topics.

Is my CASP+ certification still valid? Yes. Existing holders were recognized as SecurityX without re-testing. The certification is continuous.

Can I still take the CASP+ (CAS-004) exam? No. CAS-004 retired on June 17, 2025. CAS-005 is the only current version.

Is CAS-005 easier because it has fewer objectives? No. Objectives were consolidated from 28 to 23 by merging overlap. The exam is streamlined, not lighter.

What are the most important new topics to study? AI security and threat modeling, post-quantum cryptography, zero trust and SASE architecture, and compliance-as-code — plus a cloud-native, hybrid default.

Can I study from my old CASP+ materials? Only for the shared foundation, and even then cautiously. You'll miss the new content, so use current CAS-005 resources.

0 comments

Leave a comment