What the CompTIA SecAI+ CY0-001 is and who it is for
The CompTIA SecAI+ is the first certification purpose built for AI security. It validates that you can secure AI systems, defend against threats that use AI, and apply AI governance and compliance frameworks in a real working environment.
CompTIA aims it at cybersecurity professionals with three to four years of experience who want to specialise in AI security. In practice that means security analysts and engineers whose organisations are rolling out AI tools or building their own models.
The current version is V1, series code CY0-001, and it launched on 17 February 2026. Because it is so new, there is far less mature study material around than for older CompTIA exams, which shapes how you should prepare.
CompTIA SecAI+ CY0-001 at a glance
| Item | Detail |
|---|---|
| Exam code | CY0-001 |
| Questions | Up to 60, including performance based questions |
| Time allowed | 60 minutes |
| Passing score | 600 on a scale of 900 |
| Exam fee | US$298 per voucher |
| Languages | English and Japanese |
What is on the exam
Four domains, and one of them dominates. Securing AI systems is 40% of the exam on its own, more than the two smallest domains combined.
Basic AI concepts related to cybersecurity (17%). The groundwork you need before you can secure anything: the main types of AI and machine learning, how models are trained, tuned and deployed, what large language models and other generative systems do, and the data pipelines that feed them. The focus is security relevance, not mathematics.
Securing AI systems (40%). The heart of the exam. It covers the attacks that target AI directly, such as prompt injection, data poisoning, model theft, adversarial inputs and leakage of sensitive training data, and the controls that defend against them: access control around models and data, input and output validation, monitoring of model behaviour, secure deployment and protecting the supply chain of models and datasets. This is where most of the performance based content sits, so expect to apply controls to a scenario rather than just name them.
AI-assisted security (24%). The other side of the coin: using AI to improve security work. That includes AI in threat detection, alert triage, automation and analysis, as well as understanding how attackers use AI to scale phishing, social engineering and malicious code. Questions test whether you know where AI tools help, where they introduce new risks and how to use them responsibly.
AI governance, risk and compliance (19%). The policies, frameworks and oversight that organisations put around AI. Expect questions on AI risk assessment, responsible and ethical use, transparency and accountability, data privacy obligations, and aligning AI programmes with governance and compliance frameworks.
Why people fail it
The first problem is the material. The CY0-001 only launched on 17 February 2026, so most candidates are working from general textbooks, AI courses that are not about security, and generic practice questions that look nothing like the real exam. They arrive knowing a lot about AI in broad terms and very little about how CompTIA frames AI security scenarios.
The second is weighting. Securing AI systems is 40% of the exam and holds most of the performance based questions. Candidates who spread their time evenly across four domains, or who spend too long on the comfortable concepts domain, walk in under prepared for the part that decides the result.
Then there is time. Up to 60 questions in 60 minutes gives you about a minute per question, and a single PBQ can take several. If you have never practised against a clock, the last questions are where you lose marks.
A study plan that fits the exam
Six weeks, weighted to the domains: two full weeks on securing AI systems, one each for the other three, and a final week of timed practice.
- Week 1: basic AI concepts. Model types, training and deployment, generative AI and data pipelines, always with an eye on where the security weak points sit. At the end of the week, try the free SecAI+ practice questions to see how the scenarios are written.
- Week 2: securing AI systems, part one. The attacks: prompt injection, poisoning, adversarial inputs, model theft and data leakage. For each one, be able to say how it works, what it targets and how you would spot it.
- Week 3: securing AI systems, part two. The defences: access control, validation, monitoring, secure deployment and supply chain protection. Work the matching questions in the CY0-001 practice question pack, and read the explanations for the PBQs in particular.
- Week 4: AI-assisted security. AI in detection, triage and automation, and how attackers use the same tools. Focus on the trade offs, because questions often ask for the most appropriate use rather than a possible one.
- Week 5: AI governance, risk and compliance. Risk assessment, responsible use, privacy and framework alignment. Finish the week with a mixed set across all four domains.
- Week 6: timed runs. Use the questions only PDF for full sittings against the 60 minute limit, score by domain, and put the remaining days into whichever area comes out lowest, which for most people is still securing AI systems.
On exam day
The exam is available in English and Japanese. When you book, check the delivery options and the identification and workspace requirements on the CompTIA site, and if you test online, run the system check on the computer you will use well before the day.
Pacing matters more here than on most exams. With up to 60 questions in 60 minutes, set yourself a rough checkpoint at the halfway mark and keep to it. If a PBQ looks long, flag it if the interface allows and come back once the multiple choice items are done. The passing score is 600 on a scale of 900. It is a scaled score rather than a percentage, so do not try to tally your marks during the exam. Answer every question before time runs out.
Frequently asked questions
Do I need a machine learning background?
No, but you do need a security background. CompTIA aims the exam at cybersecurity professionals with three to four years of experience, and the AI content is taught from a security angle. You need to understand how AI systems are built and deployed well enough to see where they can be attacked, not to build models yourself.
What happens if I fail? Can I retake it?
You can retake it, but each attempt needs a new voucher at the full fee, currently US$298. CompTIA publishes its retake policy, including any waiting period, on its website, so check it before you rebook. The practice pack is refunded if you fail, but the voucher is not.
Is the practice question pack enough on its own?
No. The pack is 126 practice questions, MCQs and PBQs, mapped to the CY0-001 objectives, with an explanation for every answer and every wrong option, and it grows each month as more questions are confirmed. It is practice: it shows you how CompTIA frames AI security scenarios and highlights your weak domains. It is not a course, so use it alongside the official objectives and a proper study resource.
When you want to test yourself on the real question style, get the 126 question CY0-001 pack for US$39, pass or your money back.
