Certification news
Security+ V8

CompTIA publishes final Security+ SY0-801 objectives ahead of the November 17 launch

The final exam objectives for Security+ V8 are out. The exam is expected to launch on or around November 17, 2026, and the English SY0-701 exam retires on June 11, 2027.

What changes

CompTIA has published the final exam objectives for Security+ V8, exam code SY0-801. The document is Exam Objectives Document Version 2.0 and is linked from the Security+ V8 page. It lists 27 objectives in five domains.

The V8 domain weights are General Security Concepts 16%, Threats, Vulnerabilities, and Attacks 24%, Security Architecture 19%, Security Operations 27%, and Security Program Management and Oversight 14%.

For SY0-701, the weights are General Security Concepts 12%, Threats, Vulnerabilities, and Mitigations 22%, Security Architecture 18%, Security Operations 28%, and Security Program Management and Oversight 20%. Domain 2 now ends in Attacks instead of Mitigations, and the governance domain drops by six points.

Objective 2.6 asks you to summarize threats and vulnerabilities associated with AI usage. It lists model manipulation, poisoning, prompt injection, data loss, bias, explainability, hallucinations, jailbreaking, evasion, privacy, ethical considerations, session hijacking and code execution. Objective 2.4 lists large language models as a vulnerability and attack surface. Objective 4.6 adds AI capabilities to security automation, including agentic tools, chatbots, predictive analysis and AI-augmented baselines.

When it applies

CompTIA expects Security+ V8 to launch on or around November 17, 2026.

SY0-701 retires on June 11, 2027 for English. The Japanese, Portuguese, Spanish and Thai versions retire on August 13, 2027. CompTIA estimates that V8 itself will retire about three years after launch.

The test format stays the same: a maximum of 90 questions, a mix of multiple-choice and performance-based items, 90 minutes, and a passing score of 750 on a scale of 100 to 900. The recommended experience is two years of hands-on work as a security administrator.

What it means for your study

If you test before mid-2027, you can choose between the two exams. SY0-701 stays open until its retirement date, and SY0-801 is expected from November 2026. Pick one exam code and study to that objectives document only.

If you move to SY0-801, start with the new weights. Threats, Vulnerabilities, and Attacks now carries 24%, while Security Program Management and Oversight falls to 14%. Add AI threats, large language models as an attack surface and AI in security automation to your plan.

CompTIA says the bulleted examples in the objectives are not exhaustive. Other technologies, processes or tasks linked to an objective may also appear on the exam, so learn the concept behind each bullet, not only the term.

Prepare for Security+

More updates

Exam change

CISM exam moves to a new content outline on November 3, 2026

From November 3, 2026, the CISM exam follows a new Exam Content Outline. The domain weights become 18, 20, 33 and 29 percent. ISACA adds enterprise architecture and information security architecture and puts more emphasis on security strategy and program development. Exams taken through November 2 follow the 2022 outline. The detailed topic list for the new outline is not yet published.

Topical Requirement

Third-Party Topical Requirement takes effect, CIA testing starts no earlier than March 2027

The IIA's Third-Party Topical Requirement took effect on September 15, 2026. Scored CIA questions on a new Topical Requirement appear at least six months after its effective date, so not before March 15, 2027. The IIA's CIA exam reference list says testing starts in March 2027. The CIA syllabus itself has not changed. The Cybersecurity Topical Requirement is already in scope.