CySA+ CS0-004 vs CS0-003: What Changed and Which Version to Take
· 7 min read · CompTIA Certifications
The short answer
CompTIA released CySA+ CS0-004 (V4) on 23 June 2026. CS0-003 retires 22 December 2026, so both are bookable right now.
- Already studying CS0-003 and can test before 22 December? Finish on CS0-003. Your credential is identical either way.
- Starting from scratch, or testing in 2027? Study for CS0-004. Don't invest months in an exam that will be gone.
- Undecided and testing in Q4 2026? Go CS0-004 — the overlap in material is large, and you avoid a hard deadline.
Key dates
| Event | Date |
|---|---|
| CS0-004 (V4) available | 23 June 2026 |
| CS0-003 retirement | 22 December 2026 |
| Overlap window (both bookable) | ~6 months |
Always confirm dates on CompTIA's own certification pages before booking — retirement schedules have shifted before.
Domain weightings: what moved
The biggest structural point is what didn't change: CS0-004 keeps the same four domains, with the same names, as CS0-003. This is a content refresh, not a restructure. What shifted is how much each domain is worth.
| Domain | CS0-004 | CS0-003 | Change |
|---|---|---|---|
| 1. Security Operations | 34% | 33% | +1 |
| 2. Vulnerability Management | 26% | 30% | −4 |
| 3. Incident Response & Management | 24% | 20% | +4 |
| 4. Reporting & Communication | 16% | 17% | −1 |
What this means for your study plan: Incident Response & Management gained the most, moving from a fifth of the exam to nearly a quarter. If you built a CS0-003 schedule, take time from Vulnerability Management and give it to incident handling — containment decisions, eradication and recovery sequencing, and post-incident activity.
Security Operations remains the largest single domain, and Security Operations plus Vulnerability Management together are still 60% of the exam.
What's new in CS0-004
V4 updates the content to match how SOC work actually looks in 2026. The four areas that grew:
- AI-assisted analysis. Using AI tooling in detection and triage — and, just as importantly, understanding its failure modes. Expect questions on validating AI-generated output rather than trusting it.
- Cloud-native and hybrid environments. Monitoring, logging, and responding across cloud and on-premises estates, where the telemetry and the control boundaries differ.
- Automation and SOAR. Playbook design and orchestration, and judging what should and shouldn't be automated.
- Zero trust. How zero trust architecture changes what an analyst sees, what they can contain, and where the trust boundaries sit.
None of these are entirely absent from CS0-003 — SOAR and cloud both appear there — but V4 gives them materially more weight and treats them as core analyst work rather than emerging topics.
Exam logistics: unchanged
- Questions: maximum of 85, multiple-choice and performance-based
- Time limit: 165 minutes
- Passing score: 750 on a scale of 100–900
- Recommended experience: Network+, Security+, and about four years of hands-on security experience
Does your CS0-003 study carry over?
Mostly, yes. Because the domain structure is identical, the great majority of what you have already learned still applies. The analyst fundamentals — reading logs, interpreting scan output, prioritising with CVSS and EPSS and the CISA KEV catalog, running an incident through its lifecycle, and writing it up for people who aren't analysts — are unchanged.
Budget your top-up time for the four new areas above, and rebalance toward incident response. For most people mid-way through CS0-003 preparation, switching to CS0-004 costs a few weeks, not a restart.
Which should you take?
| Your situation | Take |
|---|---|
| Exam booked, testing within weeks, studied CS0-003 | CS0-003 |
| Most of the way through CS0-003 material, can test before 22 Dec 2026 | CS0-003 |
| Just starting, whatever your timeline | CS0-004 |
| Testing in 2027 or later | CS0-004 |
| Working in a cloud-native or heavily automated SOC | CS0-004 |
| Retaking after a recent CS0-003 fail, before the deadline | CS0-003 |
One thing people get wrong
The exam version is not part of the credential. A CySA+ earned on CS0-003 and one earned on CS0-004 are the same certification on your CV, both valid for three years from your test date. Employers do not see a version number. Choose based on your timeline and study position, not on prestige.
Frequently asked questions
Will CS0-003 practice questions still help me for CS0-004?
Yes, for the shared material — which is most of it. The four domains and the core analyst skills carry over. Supplement with study on AI-assisted analysis, cloud-native and hybrid monitoring, SOAR, and zero trust.
Do I need to retake CySA+ if I passed CS0-003?
No. Your certification stays valid for three years from your test date regardless of which version you sat. Renew through continuing education as normal.
Is CS0-004 harder than CS0-003?
Not structurally — same length, same time, same passing score. It is broader in the newer topic areas, so it can feel harder if your experience is entirely on-premises and manual. If you already work in a cloud or automated environment, parts of it will feel more familiar than CS0-003 did.
Can I mix study material from both versions?
For the shared domains, yes. Just be careful with anything that quotes domain weightings — CS0-003 material will tell you Vulnerability Management is 30% of the exam, and under CS0-004 it is 26%.
Start practising
Our CySA+ material covers the shared CS0-004 and CS0-003 domains, with free questions, answers, and explanations — no signup.
Exam details in this article were verified against CompTIA's published CySA+ V4 information in July 2026. Dates and objectives can change — confirm on CompTIA's own site before booking. Interested in the previous transition? See our CS0-003 vs CS0-002 comparison.