CompTIA CySA+: CS0-003 or CS0-004 — Which Should You Take?
Two exam codes, one certification, and a deadline in the middle. Here's how to decide — and why the answer is simpler than most candidates think.
The short answer
CompTIA CySA+ V4 (CS0-004) launched on June 23, 2026. For almost everyone reading this today, that's the exam you're taking — either because CS0-003 is already gone in your region, or because the window left on it is too narrow to bet a study plan on.
There's exactly one scenario where CS0-003 is still worth chasing: you're already deep in V3 preparation, your practice scores are consistently above 80%, and you can get a confirmed test appointment in the next few weeks. Everyone else: plan for CS0-004 and stop reading about V3.
The rest of this guide explains why — and what actually changed, so you know what you're studying.
⚠️ A note on the retirement date. CompTIA has confirmed the CS0-004 launch date (June 23, 2026) but has not published an equally clear retirement date for CS0-003. CompTIA's usual practice is to leave the outgoing version bookable for roughly six months after a new launch, which would put CS0-003's exit around December 2026 — but several training providers have reported it as a same-day switchover on June 23. The two claims can't both be right, and this is not something to take on trust from a blog post (including this one). Check CompTIA's official CySA+ page and, more decisively, try to schedule a CS0-003 appointment in Pearson VUE. If the version isn't there, the decision has been made for you.
What did not change
This is the reassuring part. CS0-004 keeps the same shape as CS0-003:
| CS0-003 (V3) | CS0-004 (V4) | |
|---|---|---|
| Questions | Max 85 | Max 85 |
| Question types | Multiple-choice + PBQs | Multiple-choice + PBQs |
| Duration | 165 minutes | 165 minutes |
| Passing score | 750 (scale 100–900) | 750 (scale 100–900) |
| Domains | 4 | 4 (same names) |
| Recommended experience | ~4 years SOC / vuln analyst | ~4 years SOC / vuln analyst |
| Retail voucher (US) | — | $425 |
| Validity | 3 years | 3 years |
Same four domain names, too: Security Operations, Vulnerability Management, Incident Response and Management, Reporting and Communication.
And critically: CompTIA treats V3 and V4 as the same certification. A CySA+ earned on CS0-003 doesn't expire early, doesn't get downgraded, and doesn't need re-testing on V4. It's valid for its full three years and renews through the normal CE program. No employer will ask which exam code you sat.
So this isn't a "which certification is better" decision. It's a scheduling decision.
What did change
1. Domain weights shifted toward incident response
| Domain | CS0-003 | CS0-004 | Change |
|---|---|---|---|
| Security Operations | 33% | 34% | +1 |
| Vulnerability Management | 30% | 26% | −4 |
| Incident Response & Management | 20% | 24% | +4 |
| Reporting & Communication | 17% | 16% | −1 |
The practical read: V4 cares more about what happens during and after an incident, and somewhat less about the mechanics of scanning and prioritisation. If you're rebalancing a study plan, take four points of time out of vulnerability scanning and put them into the IR lifecycle.
2. AI is now on the exam — properly
This is the substantive addition. CS0-003 didn't address AI in any direct way. CS0-004 introduces dedicated coverage of:
- AI use cases within the SOC — where automation actually fits in triage and detection workflows
- AI-related security risks — the threat side
- AI governance and oversight — who's accountable for what the model does
- AI-enhanced threat detection and response workflows
If you study from CS0-003 materials and sit CS0-004, this is the hole you fall into. It's not a footnote.
3. Modern security architecture
V4 expects you to understand Zero Trust Network Access (ZTNA) and Secure Access Service Edge (SASE) properly, not as buzzwords — plus cloud-native security operations and hybrid environment monitoring. V3 touched Zero Trust; V4 expands it.
4. Risk-based vulnerability management
The biggest change inside a shrinking domain. V4 adds:
- SBOM (Software Bill of Materials)
- EPSS (Exploit Prediction Scoring System) for prioritisation — a genuine shift away from CVSS-score-ranking toward exploitability-based triage
- Risk-based remediation planning
- Software supply chain security
Vulnerability Management lost four points of weight but got harder to fake. Knowing how to read a scanner report isn't enough; V4 wants to know how you'd choose what to fix first.
5. Automation across the stack
SIEM, SOAR, EDR, XDR, and automated threat intelligence workflows are all explicitly expected. V3 had SIEM and SOAR; V4 pushes further into XDR and AI-assisted SOC workflows.
The decision, in three questions
1. Can you get a CS0-003 appointment right now? If no — decision made. Take CS0-004.
2. If yes: are your practice scores already holding above 80% on V3 material? If no — take CS0-004. Rushing a V3 attempt to beat a deadline is how people fail an exam they'd have passed calmly two months later. A fail costs you a $425 voucher and the timeline anyway.
3. If yes to both: how soon can you actually sit it? Within a few weeks, with an appointment already booked? Finish on V3 — your materials are mature and there's no benefit to restarting. Anything vaguer than that? Take CS0-004.
Special case — starting from scratch. If you haven't begun studying, there is no argument for CS0-003. None. You'd be racing a deadline to earn a credential identical to the one with no deadline, using materials that are about to be superseded.
The materials trap
The single most expensive mistake in an exam transition is buying a 12-month CertMaster access key for a version you won't sit.
- Verify the version on the product page before you buy. "CySA+ CertMaster Learn" isn't specific enough — you want the exam code.
- Ask about migration. CompTIA generally transitions existing CertMaster licences to the new version when an exam refreshes, but the terms vary by product and timing. Confirm before you assume.
- Third-party content is the bigger risk. Courses, practice tests, and study guides tagged CS0-003 will leave you blind on AI, EPSS, SBOM, ZTNA/SASE, and XDR. Look for material explicitly tagged CS0-004 — and be sceptical of anything that just says "CySA+" with a 2026 date on it.
What to buy, in what order
- CertMaster Learn + Labs (integrated) — your spine. Domain 1 alone is 34% and heavily PBQ-driven; reading won't get you there.
- CertMaster Practice — added around six weeks out, for adaptive drilling on weak areas.
- Exam voucher (with Retake Assurance) — bought once your practice scores hold above 80%.
If you prefer reading to video, swap Learn for the eBook and add CertMaster Labs separately. What you almost certainly don't need is both Learn and the eBook.
🛒 CySA+ materials at Security365
📚 CySA+ CertMaster Learn + Labs — the integrated eLearning + hands-on bundle. The standard starting point. 🧪 CySA+ CertMaster Labs — $144 (reg. $199). Standalone labs if you already have courseware. 🎯 CySA+ CertMaster Practice — adaptive practice for the final stretch. 📖 CySA+ eBook — also available in Spanish, Portuguese, and Japanese. 🛡️ Browse all CompTIA products
Buying for CS0-004? Our CySA+ CertMaster catalogue is transitioning to the V4 objectives following the June 2026 launch. Message us on WhatsApp before you order and we'll confirm exactly which exam version your access key covers — it takes two minutes and saves a wasted licence.
Everything we sell is genuine, sourced through official channels, with full official access durations and support if a code doesn't redeem.
Where CySA+ sits — and why it's still worth it
CySA+ is the intermediate rung between Security+ and SecurityX, and it's still the most direct vendor-neutral proof that you can operate in a SOC rather than recite terminology. It's approved under DoD Directive 8140.03M, maps to multiple DCWF and NICE work roles, and shows up as a preferred or required credential in SOC analyst, incident responder, and vulnerability analyst postings.
A useful bonus most candidates overlook: earning CySA+ automatically renews your Security+, Network+, and A+ — no CEU submission, no separate fees. If you're maintaining a stack, that's real money.
Related reading: the complete CySA+ (CS0-003) guide for the deeper domain-by-domain breakdown, and how to renew CySA+ with CEUs for what happens after you pass.
FAQ
Is CS0-003 retired? CS0-004 launched June 23, 2026. CompTIA hasn't published a clearly confirmed CS0-003 retirement date, and provider reports conflict between a same-day switchover and the usual ~six-month overlap (which would mean around December 2026). Check CompTIA's certification page and try to schedule in Pearson VUE — availability is the only answer that matters.
Does my existing CySA+ from CS0-003 still count? Yes, fully. CompTIA treats both versions as the same certification. It's valid three years from the date you passed and renews through the CE program as normal. No re-test.
Is CS0-004 harder than CS0-003? Not structurally — same 85 questions, 165 minutes, 750 to pass. It's broader: AI, EPSS, SBOM, ZTNA/SASE, and XDR are new surface area. If anything, the shift toward incident response and risk-based prioritisation rewards working analysts and punishes pure memorisation slightly more.
How much does the CS0-004 exam cost? The US retail voucher price is $425. Bundles with Retake Assurance usually work out cheaper than buying a voucher and a retake separately.
How long should I study? CompTIA suggests 30–55 hours for candidates who already meet the recommended ~4 years of hands-on experience. Realistically, most candidates without that background need 120–160 hours over about eight weeks. Weight your time by domain: Security Operations at 34% deserves more than double what Reporting and Communication at 16% gets.
Do I need Security+ first? There's no enforced prerequisite, but CompTIA recommends Network+/Security+ knowledge, and the exam assumes it. You need to know how a network works and how to secure it before you can analyse it.
Can I use CS0-003 materials for CS0-004? For the shared foundations, mostly yes. But you'll be missing entire objectives — AI use/risk/governance, EPSS, SBOM, expanded ZTNA and SASE, XDR. Treat V3 material as supplementary, never as your primary source.
Should I wait for CS0-004 study materials to mature? No. The exam is live and job postings don't wait. The objectives are published, and CompTIA's own CertMaster line is aligned from launch. Waiting for the "perfect" third-party course costs you more than it saves.
📚 CySA+ CertMaster Learn + Labs · 🧪 CertMaster Labs · 🎯 CertMaster Practice · 📖 CySA+ eBook · 🛡️ All CompTIA
Not sure which version your key should cover? Ask us before you order — fast response via WhatsApp. 👉 Get in touch
0 comments