CompTIA SecAI+ CY0-001 AI security certification banner showing an analyst guarding a machine learning model pipeline

AI Security Certification: What CompTIA Packs Into Sixty Minutes

CompTIA SecAI+, exam code CY0-001, went live on 17 February 2026, and it is the first CompTIA certification written entirely around artificial intelligence rather than mentioning it in passing. The shape of the paper says more than the name does. Forty percent of it sits in a single domain, Securing AI Systems, while the domain that explains what a transformer or a GAN is gets seventeen. That balance is what separates this AI security certification from an AI literacy course: it assumes you can already define the technology and wants to know whether you can defend it. The format adds its own pressure, because a maximum of sixty questions, including performance-based items, has to be finished in sixty minutes. This article covers the four domains and their exact weightings, what the largest domain really asks, why the clock is the hardest part, who CompTIA says should sit it, and how to prepare for an exam with almost no public exam history behind it.

What Is CompTIA SecAI+ and When Did It Launch?

SecAI+ is CompTIA’s AI security certification, exam code CY0-001, released on 17 February 2026. It covers basic AI concepts for cybersecurity, securing AI systems, AI-assisted security work, and AI governance, risk and compliance. The exam is offered in English and Japanese and mixes multiple-choice questions with performance-based ones.

“CompTIA SecAI+ is the first certification in our expansion series, designed to help you secure, govern and responsibly integrate artificial intelligence into your cybersecurity operations.”

CompTIA, SecAI+ certification page

The phrase worth holding onto there is “into your cybersecurity operations”. SecAI+ is not a data science credential wearing a security badge. It is a security credential that treats AI as one more system to defend, one more toolset to use, and one more source of organisational risk to govern.

That framing explains why an experienced analyst finds the material familiar in structure even when the subject matter is new. Access control is still access control. It is just being applied to a model endpoint rather than a file share.

How Are the Four SecAI+ Domains Weighted?

The four CY0-001 domains are weighted 17, 40, 24 and 19 percent. Securing AI Systems dominates at 40 percent, AI-assisted Security follows at 24 percent, AI Governance, Risk and Compliance takes 19 percent, and Basic AI Concepts Related to Cybersecurity is the smallest at 17 percent. Defensive work therefore outweighs conceptual knowledge by more than two to one.

Domain Weight What it covers
Basic AI Concepts Related to Cybersecurity 17% AI types and techniques, model training methods, prompt engineering, why data security matters, data types, watermarking, retrieval-augmented generation and AI lifecycle security
Securing AI Systems 40% Threat-modeling resources, model and gateway controls, access controls, data security, monitoring and auditing, and attack analysis with compensating controls
AI-assisted Security 24% AI-enabled tooling, security use cases from anomaly detection to fraud detection, AI-generated attack vectors, and security task automation
AI Governance, Risk, and Compliance 19% Organisational structures, responsible AI risk management, compliance frameworks and data governance and sovereignty

Read those weightings as a study budget and the plan writes itself. Two hours on Securing AI Systems buys twice the marks that two hours on basic concepts does, and the concepts domain is the one most candidates instinctively start with because it feels like the foundation.

What Does the 40 Percent Domain Actually Test?

Securing AI Systems is the heart of CY0-001 and covers six areas: threat-modeling resources, model and gateway controls, access controls, data security, monitoring and auditing, and attack analysis with compensating controls. It names specific resources including the OWASP Top 10, the MIT AI Risk Repository, MITRE ATLAS and the CVE AI Working Group.

Four AI attack types named in the SecAI+ CY0-001 objectives: prompt injection, poisoning, model theft and supply chain

That list of named resources is a gift, because it tells you exactly what vocabulary the questions will use. If you have never opened MITRE ATLAS, the phrase “adversarial technique” will mean something vaguer to you than it does to the exam writer.

The controls are specific, not generic

Model and gateway controls include guardrails, prompt firewalls, rate and token limits, modality limits and endpoint access restrictions. Those are concrete mechanisms with concrete failure modes, and questions tend to give you a scenario and ask which control would have prevented it.

  • Prompt injection and jailbreaking, countered at the gateway
  • Data poisoning and backdoored models, countered in the training pipeline
  • Model theft, countered through endpoint access and rate limiting
  • Supply chain compromise, countered by provenance and lineage checks

Data security in this domain also goes further than most candidates expect. Alongside encryption in transit and at rest, the objectives name encryption in use, plus anonymisation, classification, redaction, masking and minimisation. The OWASP LLM Top 10 and the MITRE ATLAS knowledge base are the two free references that map most directly onto this material.

Why Are Sixty Questions in Sixty Minutes the Real Difficulty?

Because that is one minute per question, and some of those questions are performance based. CY0-001 presents a maximum of 60 items in 60 minutes, and the pass mark is 600 on a scale of 100 to 900. The exam costs $298 and is delivered through Pearson VUE. No other CompTIA security exam compresses a mixed-format paper into a single hour.

Item Detail
Exam code CY0-001
Questions Maximum 60, multiple choice and performance based
Duration 60 minutes
Passing score 600 on a scale of 100 to 900
Fee $298 USD
Delivery Pearson VUE

The practical effect is that recall speed matters as much as depth. A candidate who knows the material but has to reason it out from first principles will run short, while one who has drilled the vocabulary answers the same question in fifteen seconds and banks the difference for a performance-based item.

There is a second effect worth planning for. With a scaled score there is no fixed number of correct answers to aim at, so leaving items blank because you ran out of time is the most avoidable way to fail. CompTIA’s own SecAI+ practice questions are the cheapest way to calibrate your pace before booking.

Who Is SecAI+ Actually For?

CompTIA recommends three to four years in IT plus two or more years of hands-on cybersecurity experience, and names Security+, CySA+ or PenTest+ as suitable background. That places SecAI+ above the entry tier. It is written for practising security professionals whose organisations have started deploying AI, not for newcomers looking for a first credential.

AI-assisted security use cases in the SecAI+ CY0-001 syllabus including anomaly detection and fraud detection

Anyone weighing it against Security+ is comparing the wrong pair. Security+ establishes that you understand security at all; SecAI+ assumes that and asks what happens when the thing you are securing is a model. The natural progression runs from the foundational exam through an analyst credential and only then into this one.

Where the recommended background shows

The AI-assisted Security domain, worth 24 percent, is the clearest example. It covers using AI tooling for signature matching, code quality review, vulnerability analysis, penetration testing, anomaly detection, threat modelling and fraud detection. Every one of those is a job someone already does manually, and the questions assume you know what good looks like without the AI.

If your analyst background is thin, the CySA+ material is the sensible gap filler, and the CySA+ certification overview covers what that involves. The broader CompTIA cyber certification hub maps how the security track fits together.

How Much Governance and Compliance Is on the Paper?

Nineteen percent, which is more than most technical candidates expect. AI Governance, Risk and Compliance covers organisational structures such as an AI Centre of Excellence, policies and designated roles, then risk management including bias, data leakage, reputational risk, intellectual property and shadow AI, then compliance frameworks and data governance and sovereignty.

Shadow AI deserves singling out. It is the domain’s most current idea and the one with the least written about it: employees using consumer AI tools with company data, outside any approved process. The exam treats it as a named risk category rather than a novelty.

The compliance frameworks named in the objectives are the European Union AI Act, OECD standards, ISO AI standards and the NIST AI Risk Management Framework. You are not expected to recite clauses. You are expected to know which framework governs what, and the NIST AI risk framework is the one whose structure most closely mirrors how the domain is organised.

How Do You Prepare for an Exam With No Exam History?

Work from the objectives rather than from community wisdom, because six months after launch there is very little community wisdom to work from. The published objectives are unusually specific for a version one exam, naming individual controls, attack types and frameworks, which makes them a reliable checklist in a way that a broader blueprint would not be.

  1. Read the full objectives list once end to end before studying anything, so you can see how heavily the second domain outweighs the rest.
  2. Build a vocabulary sheet from the named items alone, covering prompt injection, poisoning, jailbreaking, model theft, guardrails, prompt firewalls, token limits and retrieval-augmented generation.
  3. Spend the bulk of your study time on Securing AI Systems, treating its six sub-areas as six separate passes rather than one long block.
  4. Work through AI-assisted Security next, mapping each use case onto a task you already perform manually so the AI layer is the only new part.
  5. Cover governance last and treat it as recognition rather than recall, since the questions ask which framework applies rather than what it says.
  6. Rehearse against the clock at a full sixty questions in sixty minutes, because pace is the single biggest difference between this exam and every other CompTIA security paper.

The exam objectives themselves are the study plan. A complete breakdown of the SecAI+ exam objectives sits alongside the weightings, and CompTIA’s official SecAI+ page confirms the format and the recommended experience.

Frequently Asked Questions

When did CompTIA SecAI+ launch?

On 17 February 2026. It is version one of the certification, carrying exam series code CY0-001, and CompTIA describes it as the first entry in an expansion series.

How many questions are on the CY0-001 exam?

A maximum of sixty, mixing multiple-choice with performance-based items. You get sixty minutes for the whole paper, which works out at roughly one minute per question.

What is the passing score for SecAI+?

Six hundred on a scale of 100 to 900. Because the score is scaled rather than a raw percentage, there is no fixed number of correct answers to target.

How much does the SecAI+ exam cost?

Two hundred and ninety-eight US dollars, delivered through Pearson VUE. That places it between CompTIA’s analyst-level and expert-level credentials on price.

Which SecAI+ domain is the largest?

Securing AI Systems at 40 percent. AI-assisted Security follows at 24, governance at 19, and basic AI concepts is the smallest at 17 percent.

What experience does CompTIA recommend?

Three to four years in IT and two or more years of hands-on cybersecurity. Security+, CySA+ or PenTest+ are named as suitable prior credentials rather than formal prerequisites.

Is SecAI+ the same as an AI certification?

No. It is a security certification about AI. Only 17 percent covers AI concepts themselves, while the rest is about defending, using and governing AI systems.

Does the exam cover prompt injection?

Yes, by name. Prompt injection sits in the attack analysis objectives of the largest domain, alongside poisoning, jailbreaking, backdoors, trojans, model theft and supply chain attacks.

What languages is SecAI+ offered in?

English and Japanese. That is a narrower spread than CompTIA’s long-established exams, which is normal for a certification in its first year.

Is a brand new certification worth taking?

It depends on your employer’s AI adoption. Where AI systems are already in production, being early is the whole advantage, since almost nobody on the market holds it yet.

Conclusion

SecAI+ is defined by two numbers. Forty percent of the paper is Securing AI Systems, which means the exam cares far more about defending models than explaining them. And sixty questions in sixty minutes means fluency, not just knowledge, decides the outcome. Build the vocabulary from the named controls and attacks, spend your study time in proportion to the weightings, and rehearse against the clock.

For a practising analyst whose organisation has already put AI into production, this AI security certification is a genuinely early credential in a category that is only going to grow. Start from the published objectives, and check your pace against realistic practice material before you book the hour.

Rating: 5 / 5 (1 votes)