Skip to main content
IT Support → Sysadmin (the honest on-ramp)Listed as a relevant cert for that lane. Back to pathway
Cybersecurity

CySA+

Blue-team extension of Security+. Useful for SOC promotion talks, weaker as a first cert.

DifficultyIntermediate+
Study2–4 months
Exam (indicative)£240
Valid3 years

Vendor record

Live

V4 (CS0-004) launched on 23 June 2026. The V3 exam (CS0-003) retires in English on 22 December 2026, with the Japanese, Portuguese and Spanish versions following on 23 March 2027. Book V4 unless you are already deep into V3 material.

Source: CompTIA, read on 17 September 2026. Prices are not recorded here; vendor pricing varies by region, currency and promotion.

Everything else on this page is POST's own reading of the UK market, not a vendor claim.

Compare
POST verdict

Workable

Market-level call. Not personal advice.

A solid analyst-track cert that recruiters quietly prefer to Sec+ for SOC roles, but rarely require by name. The right second cert for the wrong reason in most CVs that carry it.

Confidence
Medium
Signal
Medium
Why this confidence
UK SOC hiring is fragmented across CompTIA, GIAC and vendor-specific tracks. CySA+ holds steady as an analyst-track signal without being a default filter, which makes the call less mechanical than Sec+.
Why this signal strength
SOC analyst JDs list it as preferred more often than required. BTL1, Splunk Core and SC-200 have eaten into its share among detection-focused hiring managers.
Who this pays off for
  • Sec+ holders moving into a first SOC analyst seat
  • Helpdesk or sysadmin staff with hands-on log triage time targeting tier 1 SOC
  • Apprentices in CompTIA-stack shops who need an analyst-track follow-on to Sec+
Who walks away with nothing
  • Career changers with no SOC exposure. The cert teaches vocabulary, not shift discipline.
  • Pentest-curious candidates. CySA+ is defensive; OSCP, PNPT or CPTS do the offensive work.
  • Detection engineers and threat hunters. BTL1 and SANS GCIA hit harder at that level.
The named failure mode

Treating CySA+ as a Sec+ upgrade rather than a role-track decision. Candidates stack it on top of Sec+ with no SIEM time, walk into a SOC interview, and freeze on the first realistic ticket triage question. The Sec+-plus-CySA+-without-a-SIEM pattern is the most common rejection on UK SOC shortlists.

Recruiter signal, not marketing

A more credible analyst signal than Sec+ alone, and a CompTIA-stack route into SOC for shops that mandate vendor-neutral certs. It does not replace operational SIEM time, and it does not bridge into detection engineering without separate tooling evidence.

Falsifiability
  • CompTIA repositions CySA+ around hands-on detection and ATT&CK rather than multiple choice
  • Microsoft SC-200 becomes the default UK SOC tick-box and CySA+ loses its second-cert slot
  • Blue Team Level 1 reaches recruiter recognition parity with CompTIA in mainstream UK hiring

This tells you whether the cert is worth pursuing. It does not tell you whether it is worth pursuing for you.

See if it's right for you

This cert in isolation tells you very little. Here is where it actually sits. The pathways that use it, and the roles it realistically supports.

  • SOC tier-2 conversations
  • Detection-engineering interview language
  • DoD 8570 compliance
Practitioner take

CySA+ sits in an awkward middle. It's harder than Security+ and genuinely teaches you to read alerts, but the analyst roles it nominally qualifies you for usually want Security+ plus a home SOC lab and a Splunk Fundamentals badge instead. Take CySA+ when you're already in a SOC and want to formalise what you do day-to-day, or when you're targeting a Microsoft-shop SOC where vendor-neutral analyst credentials still get a tick in the box. If you're trying to break into security from scratch, BTL1 demonstrates the same skills more credibly and costs about the same.

Authored opinion. Updated against current hiring conditions, not vendor marketing.

Recommended prior knowledge

  • Security+ knowledge
  • Hands-on log analysis

Common misconceptions

  • CySA+ alone clears HR filters; it doesn't replace shipped, documented work.

What this cert does NOT guarantee

  • Senior detection roles alone
  • Engineering positions

Practitioner judgement. External evidence review pending.

Last reviewed: not yet reviewed · UK market

Where this fits

A cert is only useful for some routes. Here's where this one earns its place.

The next step

A cert is a signal. A Career Verdict tells you whether the signal is worth sending.

A Career Verdict tells you whether this cert earns its place on your specific route, what it won't fix, and what to sit before or after it.

A route shows what is possible. A Career Verdict makes the call.

POST ATLASVerdict no. PA-2026-0512
Career analysis report

Career Verdict

Helpdesk → Security Architect

“Realistic, but not by adding another certification.”
  1. 01
    The callA clear judgement on whether your route is realistic, and under what conditions.
  2. 02
    Where the route breaksThe most likely point to stall, and why it happens in practice.
  3. 03
    What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Generated within POST’s practitioner-authored assessment frameworkPOST ATLAS

Career Verdict

£39One-off payment. No subscription.
  • The callA single written judgement on whether the route is realistic for you.
  • Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
  • Where you standThe strongest and weakest parts of your current position, named.
  • Salary realityWhat this route actually pays, set against what you've been told it pays.
See the Career Verdict

Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.

Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.