CySA+ CS0-003 to CS0-004: What Changed, and Which One to Sit
For a few months both versions are live at once. Which one you should book depends on when you can realistically sit it — and the answer is not automatically “the newest”.

On this page
CompTIA CySA+ is mid-career blue-team certification — detection, analysis and response. It is currently in a transition window with two live versions, which makes “which one do I book” a real question rather than a trivial one.
The dates that actually matter
Official V3 learning products disappear on 22 November, a full month before the V3 exam does. If you intend to sit CS0-003, buy your study material before that date — otherwise you are preparing for a live exam with no current official resources.
Which version should you sit?
| Your situation | Sit |
|---|---|
| Already deep into CS0-003 material and can test before 22 Dec 2026 | CS0-003. Finish what you started |
| Starting from scratch today | CS0-004. No reason to learn a version that expires within months |
| Testing in a language other than English | Either — translated V3 runs to 23 Mar 2027 |
| Unsure you can be ready before December | CS0-004. Do not gamble on a hard deadline |
| Employer requires it this quarter | Whichever you can pass soonest — the credential is identical |
The key point: the certification is the same either way. CySA+ is CySA+; the exam version is not printed on your credential and the three-year renewal cycle is unchanged. Choose on readiness and deadline, not prestige.
CS0-003 domains and weights
Security operations and vulnerability management are 63% between them. That distribution tells you what CySA+ is really testing: day-to-day analyst work, not incident-command theory.
Reporting and Communication at 17% is the domain candidates most often underestimate. It is nearly a fifth of the exam and it is the easiest to prepare, because the content is stable and largely about audience, format and escalation rather than technology.
What each domain actually asks
The domain titles are broad enough to be unhelpful on their own. Here is what sits behind each.
Security Operations — 33%
The analyst’s day. Reading and correlating logs, recognising malicious activity in network and host telemetry, understanding attack techniques well enough to spot them, and using the tooling — SIEM queries, packet analysis, endpoint telemetry. Questions tend to show you evidence and ask what it indicates or what you check next.
Vulnerability Management — 30%
Scanning, interpreting results, and — the part that carries most of the marks — prioritisation. Knowing that a vulnerability exists is easy; deciding which of two hundred findings gets fixed this sprint is the tested skill. Expect scoring systems, asset context, exploitability and compensating controls.
Incident Response Management — 20%
The process end to end: preparation, detection and analysis, containment, eradication, recovery, and lessons learned. Also the artefacts — what evidence to preserve and how — and the decision points where an analyst escalates rather than acts.
Reporting and Communication — 17%
Vulnerability and incident reporting, stakeholder communication, and the metrics that get reported upward. Mostly about audience: the same finding is described differently to an engineer, a service owner and an executive. Stable, learnable content — and nearly a fifth of the exam.
Exam format
Multiple-choice plus performance-based questions. CompTIA recommends Network+ and Security+ or equivalent knowledge, with a minimum of four years of hands-on experience as an incident response analyst, SOC analyst or equivalent.
What changed in V4
CompTIA rebalanced the domains and added coverage of AI, cloud, automation and zero trust — the same modernisation pattern visible across the current CompTIA refresh cycle and in SecurityX CAS-005.
If you are sitting V4, treat those four areas as additive study on top of any V3 material you already have. The analyst fundamentals — triage, vulnerability prioritisation, response process, reporting — carry across essentially intact.
How to prepare
The study-time calculator will tell you whether the December deadline is realistic for your schedule.
Frequently Asked Questions
When does CySA+ CS0-003 retire?
The English CS0-003 exam retires on 22 December 2026. English learning products retire a month earlier on 22 November 2026, and translated versions run until 23 March 2027.
Is CS0-004 available now?
Yes. CySA+ V4 launched on 23 June 2026, so both V3 and V4 are bookable at the time of writing.
Is a CySA+ earned on CS0-003 worth less?
No. The certification is CySA+ regardless of which exam version you passed, and it carries the same three-year renewal cycle. The version number is not printed on your credential.
What is the passing score for CS0-003?
750 on a scale of 100 to 900, from a maximum of 85 questions in 165 minutes.
Practise CySA+ Before You Book
500–1,000+ practice questions with worked explanations, written against the current exam objectives.
CySA+ Practice TestPractice Before You Book
500–1,000+ practice questions per exam with detailed explanations, across Azure, AWS, GCP, security, and AI certifications.
