If you are studying for the CompTIA CySA+ certification right now, there is one date you need to have on your calendar: June 23, 2026. That is the day the CS0-003 exam retires and the CS0-004 becomes the only version available (~six months from the release of the new exam). If you have been working through CS0-003 study materials and have not yet taken the exam, you have a choice to make: test before June 23rd under the current objectives, or shift your preparation to the new exam. Either way, understanding what is actually changing will help you make that decision and plan your study time more effectively.
The most important thing to know first is what is not changing. CS0-004 keeps the same exam format as CS0-003: a maximum of 85 questions, a 165-minute testing window, a score range of 100 to 900, and a passing score of 750. The exam still covers four domains, and those domains have the same names: Security Operations, Vulnerability Management, Incident Response and Management, and Reporting and Communication. The foundational skills that CySA+ has always tested, including threat hunting, log analysis, vulnerability scanning, and incident response, are still present in the new objectives.
What has changed is the weight of those domains. Security Operations increased slightly from 33 percent to 34 percent. Vulnerability Management dropped from 30 percent to 26 percent, a four-point decrease that represents a meaningful shift in exam coverage. Incident Response and Management gained four points, moving from 20 percent to 24 percent, making it the domain with the largest single change. Reporting and Communication dropped one point from 17 to 16 percent. The practical implication is that CS0-004 places more emphasis on what happens during and after an incident and somewhat less emphasis on the mechanics of vulnerability scanning and prioritization.
The biggest substantive addition to CS0-004 is the explicit coverage of artificial intelligence. The CS0-003 objectives did not address AI in any direct way. The CS0-004 introduces three distinct AI-related topic areas, each representing a different dimension of how AI intersects with cybersecurity analyst work.
The first is AI use in security operations. CS0-004 covers how security analysts can use AI as a tool in their daily work: analyzing log files across dissimilar data sources, investigating incidents by correlating events, creating documentation and routine reports, performing event correlation across devices, and supporting automation and orchestration workflows. This reflects the reality that AI tools are already being used inside SOC environments and analysts are expected to understand how to use them effectively and appropriately.
The second new area is AI governance. Organizations deploying AI tools face legal and compliance obligations, and CS0-004 tests whether analysts understand that landscape. Topics include AI usage policies that define which tools are permitted and for which tasks, the concept of an AI data leak in which sensitive information fed to an AI model can potentially be retrieved by other users of that same model, and the broader legal and regulatory considerations that govern how AI may or may not be used within certain industries.
The third new area is AI security risks. CS0-004 introduces four specific risk categories: hallucinations, which occur when an AI generates confident-sounding output that has no factual basis; data exposure, in which data provided to an AI language model becomes part of its training and can surface in results delivered to other users; model poisoning, in which an attacker manipulates an AI model’s training data or parameters to produce biased, incorrect, or attacker-controlled outputs; and malicious prompts, also called prompt injection, in which crafted inputs are used to override an AI system’s instructions, leak data, or cause unauthorized actions.
CS0-004 also updates the security controls framework. The CS0-003 organized control types as managerial, operational, and technical. The CS0-004 uses physical, technical, and administrative as its three control types. Control functions are also explicitly enumerated in the new objectives: deterrent, preventive, detective, responsive, corrective, and compensating. If you have existing study notes organized around the CS0-003 control taxonomy, this is one area worth revisiting before you test.
For candidates currently studying with Total Seminars CS0-003 materials: if you can test before December 2026, the existing course fully covers the CS0-003 objectives. If you are just starting now, you will want to use CS0-004 aligned materials. Total Seminars is building CS0-004 course content and will have resources available with the release of the new exam. The new exam goes live June 23rd.
Talk to you next week.
Here’s a preview!