Skip to main content
Cybersecurity

CySA+

Blue-team extension of Security+. Useful for SOC promotion talks, weaker as a first cert.

DifficultyIntermediate+
Study2–4 months
Exam£240
Valid3 years
Compare
POST verdict
WorkableMarket-level call. Not personal advice.

A solid analyst-track cert that recruiters quietly prefer to Sec+ for SOC roles, but rarely require by name. The right second cert for the wrong reason in most CVs that carry it.

Confidence: Medium Signal strength: Medium
UK SOC hiring is fragmented across CompTIA, GIAC and vendor-specific tracks. CySA+ holds steady as an analyst-track signal without being a default filter, which makes the call less mechanical than Sec+.
SOC analyst JDs list it as preferred more often than required. BTL1, Splunk Core and SC-200 have eaten into its share among detection-focused hiring managers.
Who this pays off for
  • Sec+ holders moving into a first SOC analyst seat
  • Helpdesk or sysadmin staff with hands-on log triage time targeting tier 1 SOC
  • Apprentices in CompTIA-stack shops who need an analyst-track follow-on to Sec+
Who walks away with nothing
  • Career changers with no SOC exposure. The cert teaches vocabulary, not shift discipline.
  • Pentest-curious candidates. CySA+ is defensive; OSCP, PNPT or CPTS do the offensive work.
  • Detection engineers and threat hunters. BTL1 and SANS GCIA hit harder at that level.
The named failure mode

Treating CySA+ as a Sec+ upgrade rather than a role-track decision. Candidates stack it on top of Sec+ with no SIEM time, walk into a SOC interview, and freeze on the first realistic ticket triage question. The Sec+-plus-CySA+-without-a-SIEM pattern is the most common rejection on UK SOC shortlists.

Recruiter signal, not marketing

A more credible analyst signal than Sec+ alone, and a CompTIA-stack route into SOC for shops that mandate vendor-neutral certs. It does not replace operational SIEM time, and it does not bridge into detection engineering without separate tooling evidence.

Falsifiability
  • CompTIA repositions CySA+ around hands-on detection and ATT&CK rather than multiple choice
  • Microsoft SC-200 becomes the default UK SOC tick-box and CySA+ loses its second-cert slot
  • Blue Team Level 1 reaches recruiter recognition parity with CompTIA in mainstream UK hiring

This tells you whether the cert is worth pursuing. It does not tell you whether it is worth pursuing for you.

See if it's right for you

This cert in isolation tells you very little. Here is where it actually sits. The pathways that use it, and the roles it realistically supports.

  • SOC tier-2 conversations
  • Detection-engineering interview language
  • DoD 8570 compliance
Practitioner take

CySA+ sits in an awkward middle. It's harder than Security+ and genuinely teaches you to read alerts, but the analyst roles it nominally qualifies you for usually want Security+ plus a home SOC lab and a Splunk Fundamentals badge instead. Take CySA+ when you're already in a SOC and want to formalise what you do day-to-day, or when you're targeting a Microsoft-shop SOC where vendor-neutral analyst credentials still get a tick in the box. If you're trying to break into security from scratch, BTL1 demonstrates the same skills more credibly and costs about the same.

Authored opinion. Updated against current hiring conditions, not vendor marketing.

Recommended prior knowledge

  • Security+ knowledge
  • Hands-on log analysis

Common misconceptions

  • CySA+ alone clears HR filters; it doesn't replace shipped, documented work.

What this cert does NOT guarantee

  • Senior detection roles alone
  • Engineering positions

Where this fits

A cert is only useful for some routes. Here's where this one earns its place.

The next step

A cert is a signal. A Career Verdict tells you whether the signal is worth sending.

A Career Verdict tells you whether this cert earns its place on your specific route, what it won't fix, and what to sit before or after it.

A route shows what people usually do. A Career Verdict judges whether it's realistic for you.

Get a judgement on your situation£39, one-off. Built for your inputs, yours to keep.

Built on POST's practitioner-authored assessment framework, calibrated by James from twenty years across helpdesk, infrastructure and security. Framework is human-authored; the verdict applies it to your inputs.