EnglishDeutschFrançaisEspañolPortuguês

The CompTIA Certification Path in 2026: Which One First?

The CompTIA certification path and roadmap for 2026: which cert to take first, when you can skip A+, and what follows Security+. CompTIA recommends an order.

If you are new to the field and the help desk is where you want to land, start with A+. Already working in IT and comfortable with networks, with a security desk as the target? Book Security+ and skip what sits under it. If you have not settled on IT as a career at all, Tech+ is the shortest way to find out. Your entry point comes from the work you have already done.

CompTIA publishes recommendations, never requirements. Every exam page lists “recommended experience” and nothing stronger, and CompTIA states outright that you can sit CySA+ without earning Security+. The pyramid diagrams that put A+ at the bottom describe a common route, not an obligation.

Which CompTIA Certification Should You Take First?

Every passing score below is a scaled score rather than a share of correct answers. CompTIA never publishes how raw answers map onto the scale, so the number marks the bar and nothing more.

Tech+ (FC0-U71) is for someone still deciding whether IT is the job. CompTIA lists no prior experience as necessary, and the exam runs a maximum of 70 questions in 60 minutes. It is also the one exam on this page whose question types CompTIA lists as multiple-choice only. You clear it at 650. The role CompTIA prints beside it, “Career Builder”, is a polite way of saying it is not yet a job title.

A+ is the help desk credential, and it is two exams: 220-1201 and 220-1202, taken in either order but from the same version. Core 1 covers hardware and networking, and you clear it at 675. CompTIA sets the Core 2 bar higher at 700, for operating systems and security. Both run a maximum of 90 questions in 90 minutes with performance-based questions mixed in.

Security+ (SY0-701) is where anyone who already understands how a network works should start. CompTIA sets the bar at 750 on its 100–900 scale and recommends Network+ plus two years in a security or systems administrator role first. The most common fork on this path is whether you need the Network+ exam or only the networking knowledge. The Network+ versus Security+ comparison walks through how to tell.

Can You Skip A+?

Most people reading this can. CompTIA recommends 12 months in an IT support specialist role before A+, so the exam was written for someone already doing the job. If you have that year behind you and networking or security is the target, the year is the qualification and A+ only certifies what your CV shows.

Defense employers ask for A+ by name: CompTIA maps it to DoD 8140 work roles including technical support specialist, system administrator and cyber defense infrastructure support specialist. And if the help desk is where you want to work, A+ is the credential for that desk.

A+ renews nothing above it, but Network+ and Security+ each fully renew A+, so the A+ on your CV stays current with either of them, at no separate fee.

Does CompTIA’s Roadmap Make You Take Them in Order?

No, and it publishes a recommended order anyway: Network+, then Security+, then CySA+, then advanced cybersecurity specializations. Asked whether you can go straight to CySA+, CompTIA answers that you can, and that it rarely makes sense without substantial cybersecurity experience.

CompTIA’s own recommended-experience lines carry the same progression, with one gap in the middle: above A+, CySA+ is the only exam here whose line names no earlier certification at all. What it wants behind you:

  • A+: 12 months of hands-on IT support work
  • Network+: A+ plus nine to twelve months as a junior network administrator
  • Security+: Network+ plus two years in a security or systems administrator role
  • CySA+: about four years as a SOC or vulnerability analyst
  • SecurityX: ten years in IT, five of them hands-on in security, with Network+, Security+, CySA+, Cloud+ and PenTest+ or equivalent knowledge

Read down that list and the sequence is built mostly of years worked rather than exams passed.

Each certification is a receipt for experience you already have. Skip one where the experience is real and you lose little; skip one where it is missing and the next exam finds the hole for you. If you cannot tell which side of that line you are on, sit a timed set against the current objectives before you book. Knowing when you are ready is a question of evidence. Pass-IT builds practice questions for these exams from the published objectives.

What Comes After Security+?

CompTIA files the next three certifications as mid-career.

CySA+ (CS0-004) is the blue-team route, and CompTIA uses that term itself. Security operations alone accounts for 34% of the exam. CySA+ versus Security+ covers whether the step below it is skippable.

PenTest+ (PT0-003) is the red-team counterpart, for the people CompTIA calls ethical hackers. Attacks and exploits is the heaviest domain at 35%. It gets the same 165 minutes CySA+ gets, for a maximum of 90 questions, and the same 750 bar. CompTIA recommends three to four years in the role.

SecAI+ (CY0-001) is an expansion certification in CompTIA’s own words: AI and automation skills that complement a security certification you already hold. It is the shortest exam of the security family, a maximum of 60 questions in 60 minutes. At 600 it also carries the lowest bar here, and CompTIA recommends Security+, CySA+ or PenTest+ behind you before you sit it.

SecurityX (CAS-005) sits at the far end of the path: CompTIA recommends ten years of general IT experience with five of them hands-on in security. It also belongs to a small group of CompTIA exams with no scaled score at all: pass or fail. Why SecurityX is not the sequel to Security+ is worth reading first.

Which CompTIA Path for Cloud, Linux or Data Jobs?

CompTIA stacks its certifications into two pathways: cybersecurity, sequenced exam by exam, and infrastructure, which pairs A+, Network+, Security+, Server+, Linux+ and Cloud+ into specialist- and professional-level stacks and stops there. Data+ and Project+ appear in neither stack. You build the order here yourself, from the recommended-experience line on each exam page and the renewal chain.

Linux+ (XK0-006) recommends 12 months on Linux servers and sets its bar at 720. Renewing it renews A+. Cloud+ (CV0-004) recommends two to three years as a systems administrator or cloud engineer and passes at 750. Cloud+ is one of the CompTIA certifications approved under DoD 8140, a list CompTIA’s own pages put at seven or eight depending on which one you read. Renewal depends on the version. CompTIA’s table gives Cloud+ V3 the widest reach outside the security stack, renewing A+, Network+ and Linux+. It lists the current V4, CV0-004, as renewing no other CompTIA certification. Book Cloud+ today and it renews Cloud+ and nothing else. For the vendor exams alongside it, see the cloud certification roadmap.

Server+ (SK0-005) has held the same version since 2021 and publishes no retirement date, though draft objectives for a V6 sit on the same page as the Security+ V8 drafts. It recommends A+ plus two years in a server environment and passes at 750. Data+ (DA0-002) and Project+ (PK0-005) are side entrances: Data+ passes at 675 for the data analyst role, Project+ at 710 for IT project manager. Neither renews another CompTIA certification, so take either one only if that job title is the one you want.

Do CompTIA Certifications Expire?

Yes. CompTIA writes that your certification expires three years from the date you earn it, and you renew through its Continuing Education program. Tech+ sits outside that clock. CompTIA lists FC0-U71 with no expiration and FC0-U71-CE at five years, renewed by passing the newest version of the exam rather than by CE units and a fee.

Holding several does not mean renewing several. CompTIA’s rule: meet the renewal requirements for your highest-level certification and the lower ones renew with it. Hold Network+ and Security+, and Security+ is the only one you work on. SecurityX carries the most, renewing CySA+, PenTest+, Security+, Network+ and A+.

The catch sits in CompTIA’s own footnote: CE fees are not waived if the higher certification does not fully renew the lower one. Security+ fully renews Network+ and A+; CySA+ or PenTest+ fully renew Security+ and everything under it. Data+, Project+, SecAI+ and the current Cloud+ renew only themselves, so each keeps its own cycle and fee. Server+ renews A+ in CompTIA’s table, but only an A+ earned on the 1100-series exams. A+ is the reverse case: it renews nothing above it. But Network+, Security+, Linux+, CySA+, PenTest+ and SecurityX all fully renew A+, so it costs you nothing extra once you hold one of them.

Versions expire too. Security+ SY0-701 launched in November 2023, and CompTIA lists retirement as usually three years after launch, estimated 2026. The successor is already visible: the draft objectives CompTIA publishes for Security+ V8 name the exam SY0-801 on their cover page. No launch date is announced. Book Security+ today and you are booking SY0-701. If you are planning to sit it next spring instead, check the exam page before you buy any material.

Ready to start practicing?

7-day free trial, cancel anytime.

Download on the App Store