CompTIA SecAI+ launched on February 17, 2026, and a common misconception has followed it since: that it’s the next rung above Security+.
It isn’t. SecAI+ is the first certification in CompTIA’s Expansion Series, and the whole point of that series is that it sits beside what you already hold rather than above it.
An Expansion, Not a Promotion
CompTIA’s security certifications aren’t one straight line. Security+ is the foundation. CySA+ and PenTest+ branch from it into defensive and offensive work, and SecurityX is the expert-level path.
SecAI+ doesn’t slot into any of those positions. It assumes you already understand security fundamentals and asks a narrower question: can you secure AI systems, and can you use AI in security work without being fooled by it?
That has two consequences worth knowing before you book.
It won’t substitute for a missing foundation. If you don’t hold Security+ or equivalent experience, SecAI+ will not fill that gap, and the exam is written assuming you don’t need it filled.
And it doesn’t replace or invalidate anything you already hold.
What the Exam Actually Tests
Four domains, and the weighting tells you where the exam’s center of gravity is:
| Domain | Weight |
|---|---|
| Securing AI systems | 40% |
| AI-assisted security | 24% |
| AI governance, risk, and compliance | 19% |
| Basic AI concepts related to cybersecurity | 17% |
Two-fifths of the exam is a single domain. Per the CY0-001 objectives, Securing AI Systems covers AI threat modeling, technical controls, access control for models, data, agents and APIs, data security, monitoring and auditing, and the evidence left by attacks such as prompt injection and data poisoning.
The three remaining domains split the rest fairly evenly, and the smallest one is the conceptual material. If you’re planning study time by domain count rather than by weight, you’ll spend it in the wrong place.
Format: a maximum of 60 questions in 60 minutes, multiple-choice and performance-based, passing score 600 on a 100–900 scale.
Treat the 60-minute limit as a pacing risk, especially if performance-based questions come up. That’s worth rehearsing before exam day rather than discovering on it.
Who Should Take It, and Who Should Wait
CompTIA recommends 3–4 years in IT with 2+ years hands-on in cybersecurity, plus Security+, CySA+, PenTest+ or equivalent knowledge.
Take it if your organization is deploying AI systems and you’re the person responsible for assessing whether they’re safe. That’s the gap SecAI+ is built for.
Wait if you’re still working toward your first security certification. Start with Security+ unless you already have senior security architecture experience, in which case SecurityX is the expert-level route. Either way, come back to this one afterward.
How to Prepare
The 40% domain is where the exam is won, and because SecAI+ is new, expect fewer mature SecAI+-specific prep resources than you’d find for Security+. Plan to lean on primary sources: the NIST AI Risk Management Framework, your own cloud provider’s AI security documentation, and hands-on time in an authorized lab or a test deployment you own.
Then test the pacing under real conditions. Our SecAI+ practice questions are built domain by domain against the published blueprint, with the largest share on Securing AI Systems. The readiness score tells you when the 60-minute constraint has stopped being the thing that fails you.