Security+ SY0-701 vs SY0-801: Every Change in the Draft Objectives, and Which Exam to Take

Chris Rees
25+ years in IT · Pluralsight author, 4.6/5 across 2,000+ ratings

www.skillthropic.comCompTIA has published draft objectives for the next Security+ exam, SY0-801, and the current one, SY0-701, has a retirement date. For roughly seven months both will be on the table, and every candidate who is mid-study has the same question: does this change anything for me? This post answers it from the two objectives documents themselves, the 701 outline (version 7.0) and the 801 draft (version 1.4), rather than from summaries of them. Several widely repeated claims about 801 turn out to be wrong.
The dates, and which of them are confirmed
| Event | Date | Status |
|---|---|---|
| SY0-701 launched | November 7, 2023 | Confirmed (CompTIA) |
| SY0-801 draft objectives (v1.4) | Published 2025, circulating now | Confirmed (the document exists) |
| SY0-801 preview / early availability | Around October 20, 2026 | Estimate from training partners, not CompTIA |
| SY0-801 general availability | Mid-to-late November 2026 | Estimate |
| SY0-701 retirement (English) | June 11, 2027 | Confirmed (CompTIA's Security+ page) |
| SY0-701 retirement (Japanese, Portuguese, Spanish, Thai) | August 13, 2027 | Confirmed |
The overlap is the number that matters. CompTIA's habit is to run the outgoing exam for about six months after the new one launches; from a November 2026 launch to a June 11, 2027 retirement is closer to seven. Two things do not change with the version: a Security+ certification is valid for three years from the day you pass regardless of which exam you sat, and employers do not distinguish between them.
One caution on the estimates. CompTIA has slipped Security+ launch dates before, and the draft still lists the question count and exam length as "TBD". Treat October and November as the plan, not a promise. The June 2027 date is the one to build around, because it is the one CompTIA has committed to.
Same shape, different weights
Both exams have five domains with the same names, with one exception: Domain 2 is renamed from Threats, Vulnerabilities, and Mitigations to Threats, Vulnerabilities, and Attacks. The mitigations did not disappear; they moved to Domain 4, which is a pattern you will see repeatedly below. The weights shift more than the names do.
| Domain | SY0-701 | SY0-801 draft | Objectives 701 → 801 |
|---|---|---|---|
| 1.0 General Security Concepts | 12% | 16% | 4 → 3 |
| 2.0 Threats, Vulnerabilities, and Attacks | 22% | 24% | 5 → 6 |
| 3.0 Security Architecture | 18% | 19% | 4 → 4 |
| 4.0 Security Operations | 28% | 27% | 9 → 8 |
| 5.0 Security Program Management and Oversight | 20% | 14% | 6 → 6 |
Two of these deserve a second look. Domain 1 gains four points while dropping from four objectives to three: 701's separate objectives for control types (1.1) and fundamental concepts (1.2) collapse into a single 1.1 that also adds defense in depth, least privilege and Zero Trust principles. A smaller list carrying more weight means the questions on it go deeper, not wider. Domain 5 loses six points, the biggest move in either direction, and it loses them partly because two of its heaviest topics were relocated to Domain 3.
What is genuinely new: one AI objective, and AI threaded through three others
The headline change is real but smaller than the headlines suggest. There is exactly one new objective built around AI:
2.6 Summarize threats and vulnerabilities associated with artificial intelligence (AI) usage. Thirteen bullets: model manipulation, poisoning, prompt injection, data loss, bias, explainability, hallucinations, jailbreaking, evasion, privacy, ethical considerations, session hijacking, and code execution.
Then AI appears inside three existing objectives:
- 2.4 vulnerabilities and attack surfaces lists large language models (LLMs) as one item among twenty. The claim you will read elsewhere that "objective 2.4 is about LLMs" is wrong; 2.4 is the vulnerability-types objective, and LLMs are one bullet in it.
- 2.5 indicators of malicious activity adds deepfake and quishing (QR-code phishing) to the social engineering list.
- 4.6 automation and orchestration gains an AI block: agentic, chatbot, predictive analysis, and AI-augmented baselines as capabilities.
What moved, and where to find it now
Most of the "new" content in 801 is old content in a new place. If you are studying from 701 material, this is the map that stops you from thinking a topic was cut when it was only renumbered.
| Topic | In SY0-701 | In the SY0-801 draft |
|---|---|---|
| Mitigation techniques (segmentation, patching, hardening, least privilege) | 2.5 | 4.1, now titled apply mitigating controls, techniques, and solutions |
| Firewall types, port security (802.1X), NAC | 3.2 and 4.5 | 4.1 |
| Deception technology (honeypot, honeynet, honeyfile, honeytoken) | 1.2 | 4.1, with canary account added |
| Zero Trust control plane and data plane | 1.2 | 3.2, as Zero Trust architecture: user authentication, device health and inventory, application access control |
| CVSS, CVE, vulnerability prioritization | 4.3 | 2.1, a new objective on the characteristics of threats and vulnerabilities |
| Data roles (owner, controller, processor, custodian, steward) | 5.1 | 3.3, with data operator and data subprocessor added |
| RTO, RPO, MTTR, MTBF | 5.2 (business impact analysis) | 3.4, as recovery metrics |
| SLE, ALE, ARO | 5.2 | 5.2 (stays) |
The practical consequence: Domain 4's first objective is now enormous. It absorbs 701's mitigation list, its hardening objective, its firewall and web-filter objective, and the deception technology from Domain 1, and adds rate limiting, captive portals, endpoint posture checks, secrets scanning of repositories, and BIMI beside SPF, DKIM and DMARC. If you study one objective in 801 hardest, it is 4.1.
What was dropped or demoted
This is the list the summaries get backwards. Several of them claim 801 adds SASE and SD-WAN; in fact 701 already listed both under 3.2, and the 801 draft removes them, replacing the pair with Security Service Edge (SSE). Container security, also widely claimed as new, is not mentioned anywhere in the draft; containerization was a 701 topic under 3.1 and is gone.
Also removed or reduced to a single word:
- Cryptography (1.3). Blockchain and open public ledger are gone. Key stretching is gone. Steganography, tokenization and data masking collapse into one word, obfuscation; TPM, HSM, key management system and secure enclave collapse into tools.
- Threat actors (2.2). Shadow IT is no longer an actor; it reappears as a vulnerability in 2.4. The actor list gains terrorist, competitor and accidental/unintentional.
- Vulnerabilities (2.4). Memory injection, buffer overflow and the named web vulnerabilities (SQLi, XSS) leave the vulnerability list; injection and buffer overflow survive as application attacks in 2.5. VM escape and resource reuse are gone.
- Indicators (2.5). Bloatware, RFID cloning, amplified and reflected DDoS as named variants, credential replay, and the cryptographic attacks (downgrade, collision, birthday) are gone; protocol downgrade survives as a network attack.
- Architecture (3.1). ICS/SCADA, RTOS, embedded systems, IoT and virtualization leave the architecture list. IoT and OT survive, but as threat vectors in 2.3. Software-defined networking and centralized-versus-decentralized are gone.
- Infrastructure (3.2). Jump servers, proxy servers, load balancers and inline-versus-tap device attributes are gone from the objective text.
- IAM (4.5). Attribute-based access control is dropped; time-based and just-in-time are added as access control models. The privileged access management block (password vaulting, ephemeral credentials) is gone; somewhere you are is no longer a listed factor.
- Risk (5.2). The risk appetite types (expansionary, conservative, neutral), key risk indicators, risk threshold, and the assessment cadences (ad hoc, recurring, one-time, continuous) are gone. Exemption and exception are gone as sub-bullets of accept.
- Governance (5.1). Governance structures (boards, committees, government entities) are gone. So are business partners agreements and work orders from 5.3, and questionnaires.
And one structural change that says a lot: the acronym list at the back of the document shrinks from roughly three hundred entries in 701 to about a hundred in the draft. That is not a shorter exam; it is a signal that the draft was written for scenario questions rather than definition recall.
What was added beyond AI
The additions cluster in Domain 2, where the threat-vector objective roughly doubles, and in the operational objectives of Domains 4 and 5.
| Objective | Added in the SY0-801 draft |
|---|---|
| 2.3 Threat vectors | RCS messaging, collaboration tools, QR codes, CAPTCHA, RTF and PDF attachments, browser extensions, cookies and session tokens, password managers as a vector, VNC, living-off-the-land tools, logistics and SaaS providers, IoT cameras/sensors/printers, OT, RF and NFC |
| 2.4 Vulnerabilities | Hardcoded secrets, unsafe exception handling, unmanaged or stale credentials, rogue devices, identity providers, public repositories, public object storage |
| 2.5 Indicators | Fileless malware, adware, tailgating, shoulder surfing, skimming, forced entry, sniffing, spoofing, cache poisoning, whaling, spear phishing, an explicit IoC list (hash, IP, domain, malicious process, file-system artifact, timestamp, log manipulation, plaintext strings), user enumeration, MFA bypass |
| 3.1 Architecture | Multicloud, cloud deployment models, proprietary vs. open source, and a business considerations block: data sovereignty, ownership, environmental requirements |
| 3.2 Infrastructure | End-to-end encrypted messaging, out-of-band management, gMSAs, privilege creep, a Zero Trust architecture block |
| 3.3 Data | Structured vs. unstructured, secret and top secret classifications, de-identification, data transpose, geofencing, a data-lifecycle block, and compliance by data type including child/minor data |
| 3.4 Resilience | Autoscaling, backup immutability and restoration testing, redundant power supplies, surge protectors |
| 4.3 Vulnerability management | IPAM, CSPM, source code review, penetration test report review |
| 4.5 IAM | Account types (user, privileged global/local, service, third-party, emergency access), passkeys, backup codes, compromised-credential monitoring, access review |
| 4.7 Incident response | Negotiation as a phase, internal and external advisories, notification and external reporting (stakeholders, customers, law enforcement, mandatory), post-incident reporting (PIR) |
| 4.8 Investigation | Memory dumps, bit-level copies, IPFIX, surveillance footage, HR and legal as stakeholders, log-parsing techniques |
| 5.1 Governance | RFCs, runbooks, reference architectures, and clean desk, BYOD, data disposal, vulnerability disclosure and privacy policies |
| 5.3 Third-party risk | RFP, RFI, RFQ and EOI, service-level objectives, a vendor registry, and a limitations block including vendor lock-in |
| 5.4 Compliance | Compliance training on AML/CTF and anti-bribery, opt-in/opt-out, data correction, legal hold and legal orders |
| 5.5 Audits | MITRE ATT&CK, the Cyber Kill Chain and the Diamond Model as reference sources; sampling, interviews, audit charters, functional and behavioral testing |
| 5.6 Awareness | Learning management systems, personnel behavior risk scoring, business email compromise as a training topic |
The negotiation phase in 4.7 is the one that will surprise people: ransomware negotiation is now explicitly part of the incident-response process CompTIA expects an entry-level candidate to recognize. And the appearance of ATT&CK, the Kill Chain and the Diamond Model in 5.5 means the frameworks that used to be CySA+ territory are now fair game on Security+; the free interactive ATT&CK matrix on this site covers the first of those.
Exam mechanics
| SY0-701 | SY0-801 draft | |
|---|---|---|
| Questions | Maximum of 90 | TBD |
| Length | 90 minutes | TBD |
| Passing score | 750 on a 100–900 scale | 750 on a 100–900 scale |
| Question types | Multiple choice and performance-based | Multiple choice and performance-based |
| Recommended experience | Two years in IT administration with a security focus | "Security administrator with two years of hands-on experience" |
The wording on experience shifts from IT administrator with a security focus to security administrator. That is a small phrase with a real meaning: CompTIA is describing 801's candidate as someone already doing security work, and the objectives read that way.
Which exam should you take?
The decision is driven by one variable: the date you will realistically be ready to sit, not the date you would like to.
Ready before November 2026. Take 701. There is no other option, and no reason to want one.
Ready between November 2026 and roughly April 2027. Take 701 if you have already started studying for it. The question pool is mature, every practice test on the market maps to it, the certification is worth exactly the same to an employer, and it is valid for three years either way. Switching to 801 mid-study buys you nothing except the risk of being an early candidate on a new pool with a question count nobody has confirmed. Take 801 only if you are starting from zero and want the AI objective on your transcript.
Ready after April 2027. Study for 801. A 701 attempt booked close to the June 11 cliff leaves no room for a retake, and after that date the exam does not exist. Six weeks of margin is the least you want.
If you are caught between them
Measured by topic, the two exams overlap by roughly four fifths. The delta above is the study delta. If you prepared on 701 material and end up sitting 801, add these and you are covered:
- Objective 2.6, all thirteen bullets. Recognize each AI attack and its effect. The LLM primer and the prompt injection post on this site are pitched at exactly this depth.
- The 2.3 threat-vector list, which is where most of the genuinely new vocabulary lives: RCS, quishing, living-off-the-land, session tokens, browser extensions.
- 4.7's new phases: negotiation, advisories, mandatory notification, PIR.
- 4.5's account types and the credential-hygiene additions: passkeys, backup codes, compromised-credential monitoring.
- 5.5's frameworks: ATT&CK, Kill Chain, Diamond Model, at the level of knowing what each is for.
- The renumbering. Practice questions labeled by objective will mislead you if you assume 701 numbers. 4.5 is IAM in 801 (it was 4.6); 4.6 is automation (was 4.7); 4.7 is incident response (was 4.8); 4.8 is investigation (was 4.9).
A note on the guides on this site: every Skillthropic Security+ guide will be updated to the SY0-801 objectives once CompTIA publishes the final version, and the update is free for anyone who already owns a guide or the collection. Buying for 701 now does not mean buying again for 801.
What you do not need to do is start over. The control categories and types, PKI, threat actors, Zero Trust, incident response, identity and access management, vulnerability management and quantitative risk are all still there, sometimes under a new number. The exam that is coming is the exam you know, with the defensive material gathered into one place, the governance detail thinned, and one objective's worth of AI added.
- SY0-701 retires on June 11, 2027 (CompTIA-confirmed). SY0-801 is expected to open around late October 2026, with general availability in November; those dates are estimates.
- Same five domains. Domain 2 is renamed Attacks; weights move to 16 / 24 / 19 / 27 / 14. Governance loses six points.
- One new objective, 2.6 AI threats and vulnerabilities, at the summarize level. LLMs are one bullet in 2.4; AI capabilities are one block in 4.6.
- Most "new" content is relocated: mitigations, firewalls, NAC and honeypots consolidate into 4.1; CVSS/CVE move to 2.1; data roles and RTO/RPO move to Domain 3.
- Dropped: SASE and SD-WAN (replaced by SSE), containerization, blockchain, key stretching, attribute-based access control, the PAM tools block, risk appetite types. Container security is not added, whatever you have read.
- Passing score stays 750. Question count and length are TBD in the draft.
- If you will be ready before April 2027 and have started on 701, sit 701. If later, study 801. Never book 701 without six weeks of margin before June 11.
- Skillthropic's Security+ guides will be updated to 801 when the objectives are final; the update is free for existing owners.
#SecurityPlus #SY0701 #SY0801 #CompTIA
Keep reading
Introducing the Interactive MITRE ATT&CK Matrix: Every Tactic and Technique, Clickable and Explained
The official ATT&CK site is a reference. We built a place to learn it: all 15 tactics, 222 techniques and 475 sub-techniques, each clickable, with plain-English detail, what a defender sees, where it lands on your exam, three worked attack stories that walk the matrix left to right, and a tactic drill. Free, no sign-up.
Read Exam prepHow Long Does It Take to Study for CompTIA SecAI+?
A realistic timeline for preparing for the CompTIA SecAI+ exam, based on your starting point, study pace, and how you study.
Read Exam prepIs CompTIA SecAI+ Worth It? Who Should Get the AI Security Certification
Wondering whether CompTIA SecAI+ is worth your time and money? An honest look at who benefits, what it proves, and the right time to take it.
ReadEnjoyed this? Get the AI security news that matters.
Join The AI Security Brief for the top AI security news, plus what's important to the C-suite. Free, straight to your inbox.
No spam. Unsubscribe anytime.
One purchase covers both exams
The Complete Security+ Collection covers all five domains with exam-style questions you answer in the browser and a PDF of every guide to keep. Every guide will be updated to the SY0-801 objectives when CompTIA finalizes them, and the update is free for anyone who already owns it. Domain 1 is free, in full, so you can judge the writing first.
Get the Security+ collection