Exam facts & prep options

CompTIA CySA+

CompTIA CySA+ is an intermediate, vendor-neutral cybersecurity analyst certification exam that validates threat detection, vulnerability management, incident response, and reporting skills; the current CySA+ V4 (exam series code CS0-004, launched June 23, 2026) is a maximum-85-question, 165-minute exam with a 750/100-900 passing standard, delivered by Pearson VUE at test centers or via OnVUE online proctoring.

Official exam site
Start preparing1 prep option listed

Jump to prep options ↓

QuestionsMaximum of 85 questions (multiple-choice and performance-based)
Testing time165 minutes
ScoringPassing score of 750 on a scale of 100 to 900
Exam feeUSD 439 (CySA+ exam voucher, U.S. list price embedded in the official V4 exam page's store data)

Prep options

Study resources for CySA+

Independent prep

Courses and study resources

Exam overview

What to know before choosing your prep

Who runs it
CompTIA
Category
Cybersecurity
Current version
CySA+ V4 (exam series code CS0-004, launched June 23, 2026); the prior V3 (CS0-003) remains available during a transition period, with the English V3 exam retiring December 22, 2026 and its translations March 23, 2027
Where it applies
Global
Exam languages
English
Score scale
100–900
Testing provider
Pearson VUE
Format
Computer-based; multiple-choice and performance-based questions at a Pearson VUE test center or online with OnVUE remote proctoring
Availability
Year-round by appointment at Pearson VUE test centers or online 24/7 via OnVUE
Remote testing
Available

Exam structure

Maximum of 85 multiple-choice and performance-based questions (simulation PBQs) across four domains: Security Operations (34%), Vulnerability Management (26%), Incident Response and Management (24%), and Reporting and Communication (16%).

Where rules vary

Vendor-neutral certification delivered worldwide through Pearson VUE test centers and OnVUE online proctoring; CompTIA's site offers country/market selection for the exam voucher pricing.

Eligibility

No formal prerequisite; CompTIA recommends about 4 years in a SOC analyst or vulnerability analyst role

Retake policy

No waiting period between the first and second attempt; at least 14 calendar days before the third and each subsequent attempt; full exam price paid each attempt