Triage BoardGet the app

Getting certified · Analyst certifications

Cybersecurity analyst certifications and the order to take them

The certifications a security operations center (SOC) analyst usually weighs fall into three tiers: a foundation (CompTIA Security+), an analyst tier (CompTIA CySA+ CS0-004, or GIAC GCIH for incident handling), and later architecture or management credentials (CompTIA SecurityX, ISC2 CISSP). CySA+ sits in the middle tier. It assumes Security+-level knowledge and tests what an analyst does on shift: monitoring, vulnerability work, incident response and reporting.

Where CySA+ sits on CompTIA's ladder

SecurityXCySA+ and PenTest+Security+Network+A+
CompTIA's continuing-education hierarchy, lowest to highest (CompTIA CE program FAQ, checked October 2026). Renewing a higher certification renews the ones below it.

The analyst-track certifications side by side

Format and entry facts from each issuer's page, checked October 2026
CertificationIssuerFocusFormatPassingExperience
CySA+ (CS0-004)CompTIASOC, vulnerability, incident analystmax 85 · 165 min750 / 100–900~4 yrs recommended
Security+ (SY0-701)CompTIAFoundational securitymax 90 · 90 min750 / 100–900Network+ and 2 yrs recommended
PenTest+ (PT0-003)CompTIAPenetration testingmax 90 · 165 min750 / 100–9003–4 yrs recommended
SecurityX (CAS-005)CompTIAArchitect, engineermax 90 · 165 minPass/fail only10 yrs IT, 5 security, recommended
CISSPISC2Security management, 8 domains100–150 adaptive · 3 h700 / 10005 yrs required
CEH (v13)EC-CouncilEthical hacking125 · 4 h60–85%, form-dependent2 yrs or EC-Council training
GCIHGIACIncident handling106 · 4 h69%None stated

Sources: CompTIA CySA+ V4, CompTIA Security+ V7, CompTIA PenTest+, CompTIA SecurityX, ISC2 CISSP experience requirements, EC-Council CEH, GIAC GCIH. The CISSP waiver can cut its five years by one.

Choosing by the job you want next

Monitoring and triage

For alert queues, log review and incident work, CySA+ is the CompTIA exam built for that seat; its CS0-004 weights put 34% on security operations. GIAC GCIH covers incident handling for a different issuer. If you have not taken the foundation exam yet, the CySA+ vs Security+ comparison shows how the two fit together, and the CySA+ requirements separate what is recommended from what is required.

Offensive testing

PenTest+ sits on the same CompTIA rung as CySA+ and covers the attacker's side: scoping, exploitation and reporting a test. The CySA+ vs PenTest+ comparison sets the two exams side by side.

Architecture and management

SecurityX (formerly CASP+) and CISSP aim at engineers, architects and managers with long experience. CISSP requires five years of paid work across its domains; ISC2's list of credentials that can waive one of those years includes CySA+ (ISC2 experience requirements, checked October 2026). See CySA+ vs CISSP and CySA+ vs SecurityX for the side-by-side facts.

Check the exam code before you buy study materialTrap

  • CySA+ CS0-003 retires in English on December 22, 2026; CS0-004 launched June 23, 2026 (CompTIA, checked October 2026).
  • Security+ SY0-801 launches November 17, 2026, and SY0-701 retires in English on June 11, 2027.
  • A book or course that names the old code may still be on sale after its exam is gone.

Choosing among the credentials

Which certification should I start with?

CompTIA describes Security+ as the baseline and CySA+ as applying those concepts in operations (CompTIA FAQ, June 12, 2026). Before either, the route into an analyst job starts with networking and a first IT role.

Should I treat EC-Council's Certified SOC Analyst as a CySA+ alternative?

It is a separate credential from a different issuer; check EC-Council's listing for its exam format and compare the two side by side. Certified SOC Analyst (CSA) does appear on CompTIA's list of non-CompTIA certifications that can renew CySA+ (CompTIA CySA+ renewal options, checked October 2026); the CySA+ renewal guide lists the rest.

Which of these count for the DoD 8140 role I am applying for?

CompTIA maps CySA+, Security+ and SecurityX together to five US Department of Defense (DoD) work roles: 461, 511, 531, 541 and 612 (CompTIA framework alignment, checked October 2026). The CySA+ requirements page lists every role CompTIA gives CySA+.

Will a certification raise my pay?

The US Bureau of Labor Statistics (BLS) does not report pay by certification. It says many employers prefer certified candidates, and it puts the median wage for information security analysts at $129,180 (May 2025); the BLS salary breakdown shows the range.

Before you close this tab

  • Security+ is the foundation; CySA+ is CompTIA's analyst exam; SecurityX and CISSP come later.
  • CySA+ and PenTest+ share a rung, so pick between them by the work you want.
  • CySA+ is on ISC2's list for the CISSP one-year experience waiver (checked October 2026).
  • Name the exam code on every purchase: CS0-004 for CySA+ now.

Sources

  1. CompTIA CySA+ V4 (CS0-004) exam page (checked October 9, 2026)
  2. CompTIA blog: The New CompTIA CySA+ (V4), Your Certification Questions Answered · published June 12, 2026 (checked October 9, 2026)
  3. CompTIA CE program FAQ (checked October 9, 2026)
  4. CompTIA Security+ V7 (SY0-701) exam page (checked October 9, 2026)
  5. CompTIA PenTest+ exam page (checked October 9, 2026)
  6. CompTIA SecurityX exam page (checked October 9, 2026)
  7. ISC2, CISSP experience requirements (checked October 7, 2026)
  8. EC-Council, Certified Ethical Hacker (CEH) (checked October 9, 2026)
  9. GIAC, Certified Incident Handler (GCIH) (checked October 9, 2026)

Facts checked. Now practice.

Take CySA+ practice questions with you in our app for iPhone and Android.