Straight answer first: CS0-003 and CS0-004 are both live right now, and they earn the exact same certification. CompTIA launched CySA+ CS0-004 on June 23, 2026, and the older CS0-003 doesn’t retire until December 22, 2026. Until that date, you can pick which exam you take — and your certification says “CompTIA CySA+” either way. Nobody’s resume says CS0-003 on it.
So the real question isn’t “which version is better.” It’s “which version is better for you, given your timeline and the study materials you’ve already got.” Let’s work through it the way a tech would: what actually changed, what didn’t, and then the decision.
What didn’t change (more than you’d think)
Version updates sound scarier than they are. Think of it like a firmware update on a firewall you already run: same box, same job, mostly the same rules — but the threat signatures got refreshed to match what attackers are doing this year. That’s CS0-004 in one sentence.
Here’s what carries straight over from CS0-003:
- Exam format: up to 85 questions, 165 minutes, scored 100–900, passing at 750. Identical.
- The four domains: Security Operations, Vulnerability Management, Incident Response & Management, Reporting & Communication. Same four, same names.
- The certification itself: one CySA+ cert, either exam. If you pass CS0-003 in November, your cert is exactly as current as someone who passed CS0-004 the same week, with the same renewal clock.
What changed: the weights shifted, and AI walked in the door
Two real changes. First, the domain weights moved — not dramatically, but in a direction that tells you where the job is heading:
| Domain | CS0-003 | CS0-004 | Shift |
|---|---|---|---|
| Security Operations | 33% | 34% | +1 |
| Vulnerability Management | 30% | 26% | −4 |
| Incident Response & Management | 20% | 24% | +4 |
| Reporting & Communication | 17% | 16% | −1 |
Read that middle pair together: vulnerability management gave up four points and incident response picked up four. CompTIA is saying what every SOC lead already knows — scanning and patching matter, but the analyst who can run an incident end to end is the one who gets the call at 2 a.m. Nearly a quarter of CS0-004 is incident response now.
Second — and this is the headline change — CS0-004 adds AI content across three angles:
- Using AI as an analyst tool — where it genuinely speeds up triage and where it doesn’t.
- AI governance — the policy and compliance side of letting these tools near production data.
- AI as a risk surface — prompt injection, model poisoning, data exposure, and the fact that these tools will confidently hand you a wrong answer. If you’ve ever had a chatbot invent a config setting that doesn’t exist, congratulations: you’ve already met the failure mode CS0-004 wants you to understand.
There’s also refreshed coverage of cloud and hybrid environments and updated security-control content. Evolution, not revolution.
Which one should you take?
Here’s the decision, and it comes down to two questions: when can you realistically test, and what materials are you holding?
Take CS0-003 if you’re already down the road
If you’ve been studying with CS0-003 materials — ours or anyone’s — and you can be exam-ready before December 22, 2026, finish the job on CS0-003. Switching versions mid-study means re-mapping everything you’ve done against new objectives to chase content you mostly already know. That’s motion, not progress.
The readiness rule doesn’t change with the version number: when you’re consistently scoring 85% or better on realistic practice questions, you’re ready to book. Below that, you study the gaps and keep practicing. Our CySA+ e-book + TotalTester bundle is built around the CS0-003 objectives — if that’s your exam, that’s your practice engine, and December leaves you a real runway.
Take CS0-004 if you’re starting now (or testing next year)
Starting from zero today? Go CS0-004. By the time you’re exam-ready you’ll be close to the retirement date anyway, and there’s no sense racing a deadline you don’t have to race. And to be straight with you about our own shelf: our CySA+ TotalTester and e-book currently map to CS0-003 — check the version note on any product page before you buy study materials anywhere, because mismatched objectives are the most common self-inflicted wound in cert prep.
Either way, the CySA+ exam voucher is version-agnostic — it books whichever exam you register for, and buying it below retail is the same money-saving move on both versions.
The edge case: you’re close, but not December-close
If you’re maybe 60% through CS0-003 prep but can’t test until January — that’s the one genuinely annoying spot. The good news: the overlap between versions is large. Your security operations, vulnerability management, and reporting knowledge transfers nearly whole. Spend your remaining study time on the CS0-004 objective list, weight the incident-response domain harder, and add the AI material. You’re topping up, not starting over.
FAQ
When does CS0-003 retire?
December 22, 2026 for the English exam. Until then, both versions are available and you choose at registration.
Is the certification different if I take CS0-003?
No. Both exams grant the same CompTIA CySA+ certification with the same renewal cycle. The version code matters for your studying, not your resume.
Is CS0-004 harder?
It’s not built to be harder — same format, same passing score, same four domains. It’s built to be current: more incident response, new AI coverage. If you’re comfortable with those areas, the difficulty is comparable.
Do I need to retest if I passed CS0-003?
No. Your CySA+ is valid on its normal three-year renewal cycle regardless of which exam version you passed.
What’s actually new in CS0-004?
Domain-weight shifts (incident response up to 24%, vulnerability management down to 26%) and new AI content — using AI tools as an analyst, AI governance, and AI-specific risks like prompt injection and model poisoning. We covered the change in detail when it was announced: what’s new in CS0-004.
Bottom line
Same cert, two doors, one closing December 22. If your materials and your calendar line up with CS0-003, walk through that door before it shuts — deliberately, at an 85% practice score, not in a panic. If you’re starting fresh, learn the current threat landscape on CS0-004 and don’t look back. And if CySA+ is your next rung after Security+, the ladder logic is the same one that got you here: study, practice until it’s boring, book the exam when you’re ready.