Skip to content
All articles
September 14, 2026 14 min read

Security+ SY0-701 vs SY0-801: Every Change in the Draft Objectives, and Which Exam to Take

Chris Rees

Chris Rees

25+ years in IT · Pluralsight author, 4.6/5 across 2,000+ ratings

Security+ SY0-701 vs SY0-801: Every Change in the Draft Objectives, and Which Exam to Take
www.skillthropic.com

CompTIA has published draft objectives for the next Security+ exam, SY0-801, and the current one, SY0-701, has a retirement date. For roughly seven months both will be on the table, and every candidate who is mid-study has the same question: does this change anything for me? This post answers it from the two objectives documents themselves, the 701 outline (version 7.0) and the 801 draft (version 1.4), rather than from summaries of them. Several widely repeated claims about 801 turn out to be wrong.

The dates, and which of them are confirmed

Event Date Status
SY0-701 launched November 7, 2023 Confirmed (CompTIA)
SY0-801 draft objectives (v1.4) Published 2025, circulating now Confirmed (the document exists)
SY0-801 preview / early availability Around October 20, 2026 Estimate from training partners, not CompTIA
SY0-801 general availability Mid-to-late November 2026 Estimate
SY0-701 retirement (English) June 11, 2027 Confirmed (CompTIA's Security+ page)
SY0-701 retirement (Japanese, Portuguese, Spanish, Thai) August 13, 2027 Confirmed

The overlap is the number that matters. CompTIA's habit is to run the outgoing exam for about six months after the new one launches; from a November 2026 launch to a June 11, 2027 retirement is closer to seven. Two things do not change with the version: a Security+ certification is valid for three years from the day you pass regardless of which exam you sat, and employers do not distinguish between them.

One caution on the estimates. CompTIA has slipped Security+ launch dates before, and the draft still lists the question count and exam length as "TBD". Treat October and November as the plan, not a promise. The June 2027 date is the one to build around, because it is the one CompTIA has committed to.

Same shape, different weights

Both exams have five domains with the same names, with one exception: Domain 2 is renamed from Threats, Vulnerabilities, and Mitigations to Threats, Vulnerabilities, and Attacks. The mitigations did not disappear; they moved to Domain 4, which is a pattern you will see repeatedly below. The weights shift more than the names do.

Paired bar chart of the five Security+ domain weights, SY0-701 against the SY0-801 draft: General Security Concepts 12 to 16 percent, Threats 22 to 24, Architecture 18 to 19, Operations 28 to 27, Program Management 20 to 14 SY0-701 SY0-801 draft 1.0 General Security Concepts +4 points 2.0 Threats, Vulnerabilities & Attacks (was Mitigations) +2 points 3.0 Security Architecture +1 point 4.0 Security Operations −1 point 5.0 Security Program Management & Oversight −6 points 12% 16% 22% 24% 18% 19% 28% 27% 20% 14%
Domain weights, SY0-701 against the SY0-801 draft. Governance loses six points, the largest single move; General Security Concepts gains four while losing an objective.
Domain SY0-701 SY0-801 draft Objectives 701 → 801
1.0 General Security Concepts 12% 16% 4 → 3
2.0 Threats, Vulnerabilities, and Attacks 22% 24% 5 → 6
3.0 Security Architecture 18% 19% 4 → 4
4.0 Security Operations 28% 27% 9 → 8
5.0 Security Program Management and Oversight 20% 14% 6 → 6

Two of these deserve a second look. Domain 1 gains four points while dropping from four objectives to three: 701's separate objectives for control types (1.1) and fundamental concepts (1.2) collapse into a single 1.1 that also adds defense in depth, least privilege and Zero Trust principles. A smaller list carrying more weight means the questions on it go deeper, not wider. Domain 5 loses six points, the biggest move in either direction, and it loses them partly because two of its heaviest topics were relocated to Domain 3.

What is genuinely new: one AI objective, and AI threaded through three others

The headline change is real but smaller than the headlines suggest. There is exactly one new objective built around AI:

2.6 Summarize threats and vulnerabilities associated with artificial intelligence (AI) usage. Thirteen bullets: model manipulation, poisoning, prompt injection, data loss, bias, explainability, hallucinations, jailbreaking, evasion, privacy, ethical considerations, session hijacking, and code execution.

Then AI appears inside three existing objectives:

  • 2.4 vulnerabilities and attack surfaces lists large language models (LLMs) as one item among twenty. The claim you will read elsewhere that "objective 2.4 is about LLMs" is wrong; 2.4 is the vulnerability-types objective, and LLMs are one bullet in it.
  • 2.5 indicators of malicious activity adds deepfake and quishing (QR-code phishing) to the social engineering list.
  • 4.6 automation and orchestration gains an AI block: agentic, chatbot, predictive analysis, and AI-augmented baselines as capabilities.
How deep does it go? The verb on 2.6 is summarize, the lowest rung on CompTIA's scale. You need to recognize prompt injection, poisoning and jailbreaking and say what each does; you do not need to defend an AI system. That is the whole of CompTIA SecAI+, a separate certification with four domains on the subject. If you already understand prompt injection and data poisoning at the SecAI+ level, 2.6 is an afternoon.

What moved, and where to find it now

Most of the "new" content in 801 is old content in a new place. If you are studying from 701 material, this is the map that stops you from thinking a topic was cut when it was only renumbered.

Diagram of topics relocating between domains from SY0-701 to the SY0-801 draft: deception technology and Zero Trust leave Domain 1, mitigation techniques leave Domain 2, firewalls and network access control leave Domain 3, all landing in Domains 3 and 4; CVSS and CVE move from Domain 4 to Domain 2; data roles and recovery metrics move from Domain 5 to Domain 3 SY0-701 SY0-801 DRAFT 1.0 General Concepts 2.0 Threats & Vulns 3.0 Architecture 4.0 Operations 5.0 Program Mgmt 1.0 General Concepts 2.0 Threats & Attacks 3.0 Architecture 4.0 Operations 5.0 Program Mgmt CVSS, CVE · 4.3 → 2.1 Zero Trust detail · 1.2 → 3.2 Data roles, RTO/RPO · 5.x → 3.x Mitigations · 2.5 → 4.1 Firewalls, NAC · 3.2, 4.5 → 4.1 Honeypots & co. · 1.2 → 4.1 Each arrow is a topic that survives in the draft under a different domain; the number is where it lived in SY0-701.
Nothing on this diagram was cut. Domain 4 becomes the home of every "how do we defend against it" topic; Domain 3 absorbs the data governance that used to sit in Domain 5.
Topic In SY0-701 In the SY0-801 draft
Mitigation techniques (segmentation, patching, hardening, least privilege) 2.5 4.1, now titled apply mitigating controls, techniques, and solutions
Firewall types, port security (802.1X), NAC 3.2 and 4.5 4.1
Deception technology (honeypot, honeynet, honeyfile, honeytoken) 1.2 4.1, with canary account added
Zero Trust control plane and data plane 1.2 3.2, as Zero Trust architecture: user authentication, device health and inventory, application access control
CVSS, CVE, vulnerability prioritization 4.3 2.1, a new objective on the characteristics of threats and vulnerabilities
Data roles (owner, controller, processor, custodian, steward) 5.1 3.3, with data operator and data subprocessor added
RTO, RPO, MTTR, MTBF 5.2 (business impact analysis) 3.4, as recovery metrics
SLE, ALE, ARO 5.2 5.2 (stays)

The practical consequence: Domain 4's first objective is now enormous. It absorbs 701's mitigation list, its hardening objective, its firewall and web-filter objective, and the deception technology from Domain 1, and adds rate limiting, captive portals, endpoint posture checks, secrets scanning of repositories, and BIMI beside SPF, DKIM and DMARC. If you study one objective in 801 hardest, it is 4.1.

What was dropped or demoted

This is the list the summaries get backwards. Several of them claim 801 adds SASE and SD-WAN; in fact 701 already listed both under 3.2, and the 801 draft removes them, replacing the pair with Security Service Edge (SSE). Container security, also widely claimed as new, is not mentioned anywhere in the draft; containerization was a 701 topic under 3.1 and is gone.

Also removed or reduced to a single word:

  • Cryptography (1.3). Blockchain and open public ledger are gone. Key stretching is gone. Steganography, tokenization and data masking collapse into one word, obfuscation; TPM, HSM, key management system and secure enclave collapse into tools.
  • Threat actors (2.2). Shadow IT is no longer an actor; it reappears as a vulnerability in 2.4. The actor list gains terrorist, competitor and accidental/unintentional.
  • Vulnerabilities (2.4). Memory injection, buffer overflow and the named web vulnerabilities (SQLi, XSS) leave the vulnerability list; injection and buffer overflow survive as application attacks in 2.5. VM escape and resource reuse are gone.
  • Indicators (2.5). Bloatware, RFID cloning, amplified and reflected DDoS as named variants, credential replay, and the cryptographic attacks (downgrade, collision, birthday) are gone; protocol downgrade survives as a network attack.
  • Architecture (3.1). ICS/SCADA, RTOS, embedded systems, IoT and virtualization leave the architecture list. IoT and OT survive, but as threat vectors in 2.3. Software-defined networking and centralized-versus-decentralized are gone.
  • Infrastructure (3.2). Jump servers, proxy servers, load balancers and inline-versus-tap device attributes are gone from the objective text.
  • IAM (4.5). Attribute-based access control is dropped; time-based and just-in-time are added as access control models. The privileged access management block (password vaulting, ephemeral credentials) is gone; somewhere you are is no longer a listed factor.
  • Risk (5.2). The risk appetite types (expansionary, conservative, neutral), key risk indicators, risk threshold, and the assessment cadences (ad hoc, recurring, one-time, continuous) are gone. Exemption and exception are gone as sub-bullets of accept.
  • Governance (5.1). Governance structures (boards, committees, government entities) are gone. So are business partners agreements and work orders from 5.3, and questionnaires.

And one structural change that says a lot: the acronym list at the back of the document shrinks from roughly three hundred entries in 701 to about a hundred in the draft. That is not a shorter exam; it is a signal that the draft was written for scenario questions rather than definition recall.

What was added beyond AI

The additions cluster in Domain 2, where the threat-vector objective roughly doubles, and in the operational objectives of Domains 4 and 5.

Objective Added in the SY0-801 draft
2.3 Threat vectors RCS messaging, collaboration tools, QR codes, CAPTCHA, RTF and PDF attachments, browser extensions, cookies and session tokens, password managers as a vector, VNC, living-off-the-land tools, logistics and SaaS providers, IoT cameras/sensors/printers, OT, RF and NFC
2.4 Vulnerabilities Hardcoded secrets, unsafe exception handling, unmanaged or stale credentials, rogue devices, identity providers, public repositories, public object storage
2.5 Indicators Fileless malware, adware, tailgating, shoulder surfing, skimming, forced entry, sniffing, spoofing, cache poisoning, whaling, spear phishing, an explicit IoC list (hash, IP, domain, malicious process, file-system artifact, timestamp, log manipulation, plaintext strings), user enumeration, MFA bypass
3.1 Architecture Multicloud, cloud deployment models, proprietary vs. open source, and a business considerations block: data sovereignty, ownership, environmental requirements
3.2 Infrastructure End-to-end encrypted messaging, out-of-band management, gMSAs, privilege creep, a Zero Trust architecture block
3.3 Data Structured vs. unstructured, secret and top secret classifications, de-identification, data transpose, geofencing, a data-lifecycle block, and compliance by data type including child/minor data
3.4 Resilience Autoscaling, backup immutability and restoration testing, redundant power supplies, surge protectors
4.3 Vulnerability management IPAM, CSPM, source code review, penetration test report review
4.5 IAM Account types (user, privileged global/local, service, third-party, emergency access), passkeys, backup codes, compromised-credential monitoring, access review
4.7 Incident response Negotiation as a phase, internal and external advisories, notification and external reporting (stakeholders, customers, law enforcement, mandatory), post-incident reporting (PIR)
4.8 Investigation Memory dumps, bit-level copies, IPFIX, surveillance footage, HR and legal as stakeholders, log-parsing techniques
5.1 Governance RFCs, runbooks, reference architectures, and clean desk, BYOD, data disposal, vulnerability disclosure and privacy policies
5.3 Third-party risk RFP, RFI, RFQ and EOI, service-level objectives, a vendor registry, and a limitations block including vendor lock-in
5.4 Compliance Compliance training on AML/CTF and anti-bribery, opt-in/opt-out, data correction, legal hold and legal orders
5.5 Audits MITRE ATT&CK, the Cyber Kill Chain and the Diamond Model as reference sources; sampling, interviews, audit charters, functional and behavioral testing
5.6 Awareness Learning management systems, personnel behavior risk scoring, business email compromise as a training topic

The negotiation phase in 4.7 is the one that will surprise people: ransomware negotiation is now explicitly part of the incident-response process CompTIA expects an entry-level candidate to recognize. And the appearance of ATT&CK, the Kill Chain and the Diamond Model in 5.5 means the frameworks that used to be CySA+ territory are now fair game on Security+; the free interactive ATT&CK matrix on this site covers the first of those.

Exam mechanics

SY0-701 SY0-801 draft
Questions Maximum of 90 TBD
Length 90 minutes TBD
Passing score 750 on a 100–900 scale 750 on a 100–900 scale
Question types Multiple choice and performance-based Multiple choice and performance-based
Recommended experience Two years in IT administration with a security focus "Security administrator with two years of hands-on experience"

The wording on experience shifts from IT administrator with a security focus to security administrator. That is a small phrase with a real meaning: CompTIA is describing 801's candidate as someone already doing security work, and the objectives read that way.

Which exam should you take?

The decision is driven by one variable: the date you will realistically be ready to sit, not the date you would like to.

Ready before November 2026. Take 701. There is no other option, and no reason to want one.

Ready between November 2026 and roughly April 2027. Take 701 if you have already started studying for it. The question pool is mature, every practice test on the market maps to it, the certification is worth exactly the same to an employer, and it is valid for three years either way. Switching to 801 mid-study buys you nothing except the risk of being an early candidate on a new pool with a question count nobody has confirmed. Take 801 only if you are starting from zero and want the AI objective on your transcript.

Ready after April 2027. Study for 801. A 701 attempt booked close to the June 11 cliff leaves no room for a retake, and after that date the exam does not exist. Six weeks of margin is the least you want.

The one trap. Vouchers and study plans that assume 701 will still be available in the second half of 2027 will not survive contact with the calendar. If you are buying a voucher now, check whether it is exam-specific and whether it expires before June 11, 2027.

If you are caught between them

Measured by topic, the two exams overlap by roughly four fifths. The delta above is the study delta. If you prepared on 701 material and end up sitting 801, add these and you are covered:

  1. Objective 2.6, all thirteen bullets. Recognize each AI attack and its effect. The LLM primer and the prompt injection post on this site are pitched at exactly this depth.
  2. The 2.3 threat-vector list, which is where most of the genuinely new vocabulary lives: RCS, quishing, living-off-the-land, session tokens, browser extensions.
  3. 4.7's new phases: negotiation, advisories, mandatory notification, PIR.
  4. 4.5's account types and the credential-hygiene additions: passkeys, backup codes, compromised-credential monitoring.
  5. 5.5's frameworks: ATT&CK, Kill Chain, Diamond Model, at the level of knowing what each is for.
  6. The renumbering. Practice questions labeled by objective will mislead you if you assume 701 numbers. 4.5 is IAM in 801 (it was 4.6); 4.6 is automation (was 4.7); 4.7 is incident response (was 4.8); 4.8 is investigation (was 4.9).

A note on the guides on this site: every Skillthropic Security+ guide will be updated to the SY0-801 objectives once CompTIA publishes the final version, and the update is free for anyone who already owns a guide or the collection. Buying for 701 now does not mean buying again for 801.

What you do not need to do is start over. The control categories and types, PKI, threat actors, Zero Trust, incident response, identity and access management, vulnerability management and quantitative risk are all still there, sometimes under a new number. The exam that is coming is the exam you know, with the defensive material gathered into one place, the governance detail thinned, and one objective's worth of AI added.

Key takeaways
  • SY0-701 retires on June 11, 2027 (CompTIA-confirmed). SY0-801 is expected to open around late October 2026, with general availability in November; those dates are estimates.
  • Same five domains. Domain 2 is renamed Attacks; weights move to 16 / 24 / 19 / 27 / 14. Governance loses six points.
  • One new objective, 2.6 AI threats and vulnerabilities, at the summarize level. LLMs are one bullet in 2.4; AI capabilities are one block in 4.6.
  • Most "new" content is relocated: mitigations, firewalls, NAC and honeypots consolidate into 4.1; CVSS/CVE move to 2.1; data roles and RTO/RPO move to Domain 3.
  • Dropped: SASE and SD-WAN (replaced by SSE), containerization, blockchain, key stretching, attribute-based access control, the PAM tools block, risk appetite types. Container security is not added, whatever you have read.
  • Passing score stays 750. Question count and length are TBD in the draft.
  • If you will be ready before April 2027 and have started on 701, sit 701. If later, study 801. Never book 701 without six weeks of margin before June 11.
  • Skillthropic's Security+ guides will be updated to 801 when the objectives are final; the update is free for existing owners.

#SecurityPlus #SY0701 #SY0801 #CompTIA

Share this article

Keep reading

Enjoyed this? Get the AI security news that matters.

Join The AI Security Brief for the top AI security news, plus what's important to the C-suite. Free, straight to your inbox.

No spam. Unsubscribe anytime.

Security+ · all five domains

One purchase covers both exams

The Complete Security+ Collection covers all five domains with exam-style questions you answer in the browser and a PDF of every guide to keep. Every guide will be updated to the SY0-801 objectives when CompTIA finalizes them, and the update is free for anyone who already owns it. Domain 1 is free, in full, so you can judge the writing first.

Get the Security+ collection