Skip to main content
Cybersecurity

SecurityX (formerly CASP+)

Hands-on senior security generalist cert, quietly respected, mostly in defence/contractor space.

DifficultyIntermediate+
Study4–6 months
Exam (indicative)£324
Valid3 years

Vendor record

Renamed

CASP+ became SecurityX on 17 December 2024 with the V5 exam. Existing CASP+ holders keep their certification and their continuing-education status.

Source: CompTIA, read on 17 September 2026. Prices are not recorded here; vendor pricing varies by region, currency and promotion.

Everything else on this page is POST's own reading of the UK market, not a vendor claim.

Compare
POST verdict

Overrated

Market-level call. Not personal advice.

Respected on US DoD 8570 paperwork. In UK hiring, most experienced interviewers have never asked for it and aren't looking for it.

Confidence
Medium
Signal
Low
Why this confidence
UK hiring pattern data is thinner for CASP+ than for GIAC or Microsoft certs. The cert is genuinely rare on UK job specs outside of US-headquartered defence contractors operating in the UK. Confidence is medium because the population of CASP+ holders in UK SOC roles is small enough to make pattern recognition noisy.
Why this signal strength
US DoD 8570 compliance is the primary driver of CASP+ demand. UK cleared defence work runs on different frameworks. NCSC guidance, JSP 440 and Cyber Essentials Plus alignment, where CASP+ has no formal standing. UK MSSPs and finance SOCs do not name it in job specs.
Who this pays off for
  • UK-based analysts working for US defence contractors where DoD 8570 compliance is a contractual obligation for the UK entity, not a local hiring preference
  • Security generalists targeting roles that require both UK and US clearance alignment where the employer explicitly maps CASP+ into their skills matrix
  • Practitioners who have already held CISSP for several years and want a hands-on complement that tests applied senior generalist skill rather than conceptual breadth
Who walks away with nothing
  • A UK senior security credential on par with CISSP. Hiring managers at UK finance SOCs and MSSPs rarely give it equivalent weight
  • A substitute for domain-specific depth certs like GCIH or GCIA. Generalist breadth at senior level is harder to sell in UK SOC hiring than clear specialist signal
  • A DoD-equivalent signal in UK cleared work. UK defence primes do not operate under DoD 8570 and the credential has no structural role in UK MoD or NCSC frameworks
The named failure mode

DoD-to-UK-cleared transfer assumption. UK analysts who've worked on US-contract roles attempt to carry CASP+ into UK MoD or NCSC-adjacent hiring pipelines expecting parity. The frameworks don't map and the credential gets treated as an unfamiliar general cert rather than a compliance signal.

Recruiter signal, not marketing

DoD 8570 IAT Level III compliance for US-contract roles operated from the UK. A CompTIA ecosystem senior credential for practitioners already in the CompTIA pathway. Does not unlock UK cleared defence roles, does not substitute for GIAC at UK MSSPs, and does not carry meaningful weight at UK finance SOCs.

Falsifiability
  • NCSC or UK MoD formally incorporates CASP+ into published UK cyber workforce frameworks, which would immediately change its standing in cleared UK hiring
  • US defence contractor presence in the UK grows substantially and standardises on US certification frameworks across UK entities, expanding the addressable market
  • CompTIA restructures CASP+ into a more vendor-integrated or specialised credential rather than the current senior generalist format, which could sharpen or dilute its signal

This tells you whether the cert is worth pursuing. It does not tell you whether it is worth pursuing for you.

See if it's right for you

This cert in isolation tells you very little. Here is where it actually sits. The pathways that use it, and the roles it realistically supports.

  • Senior technical security roles in gov/contractor world
  • CISSP alternative for ICs
Practitioner take

CASP+ exists in an awkward gap. CompTIA's senior security cert, vendor-neutral, technical rather than managerial, and DoD 8570-approved at the highest tier. That last point is most of why it still sells. Outside US federal and UK MoD-adjacent contracting, recruiters reach for CISSP every time when they want a senior security signal, and most hiring managers in commercial UK enterprise have never seen it on a CV. Take CASP+ if you're targeting a job spec that names it. Don't take it speculatively. The exam is hard enough that the time is better spent on CISSP if your target isn't gov-adjacent.

Authored opinion. Updated against current hiring conditions, not vendor marketing.

Recommended prior knowledge

  • Security+
  • Years of hands-on security work

Common misconceptions

  • SecurityX (formerly CASP+) alone clears HR filters; it doesn't replace shipped, documented work.

What this cert does NOT guarantee

  • Civilian commercial recognition at CISSP level

Practitioner judgement. External evidence review pending.

Last reviewed: not yet reviewed · UK market

The next step

A cert is a signal. A Career Verdict tells you whether the signal is worth sending.

A Career Verdict tells you whether this cert earns its place on your specific route, what it won't fix, and what to sit before or after it.

A route shows what is possible. A Career Verdict makes the call.

POST ATLASVerdict no. PA-2026-0512
Career analysis report

Career Verdict

Helpdesk → Security Architect

“Realistic, but not by adding another certification.”
  1. 01
    The callA clear judgement on whether your route is realistic, and under what conditions.
  2. 02
    Where the route breaksThe most likely point to stall, and why it happens in practice.
  3. 03
    What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Generated within POST’s practitioner-authored assessment frameworkPOST ATLAS

Career Verdict

£39One-off payment. No subscription.
  • The callA single written judgement on whether the route is realistic for you.
  • Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
  • Where you standThe strongest and weakest parts of your current position, named.
  • Salary realityWhat this route actually pays, set against what you've been told it pays.
See the Career Verdict

Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.

Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.