CompTIA’s SecurityX (formerly CASP+) is an advanced, hands-on cybersecurity certification designed for security architects and senior security engineers who design, implement, and manage enterprise security solutions. It validates technical depth across architecture, engineering, and operations, not just policy knowledge. Two exam codes are currently in circulation: CAS-004, which remains widely referenced, and CAS-005, the V5 version released under the SecurityX rebrand.
- Vendor: CompTIA
- Current exam codes: CAS-004 (previous version) and CAS-005 (SecurityX V5)
- Focus: Hands-on enterprise security architecture, engineering, and implementation
- Accreditation: ANSI/ISO 17024–compliant; accepted for DoD 8570/8140 categories
- Who it is for: Senior technical practitioners who want to stay in engineering, not move into management
Table of Contents
- What are the key facts about the CASP+ exam?
- Who should pursue the SecurityX certification?
- What does the CASP+ exam actually cover?
- How does exam registration and delivery work?
- How does SecurityX compare to CISSP, Security+, and other credentials?
- How should you build your CASP+ study plan?
- What career outcomes can you expect after earning SecurityX?
- How do you renew the SecurityX certification?
- What are your next steps to get started?
- Key Takeaways
What are the key facts about the CASP+ exam?
The numbers you need before committing to this credential:
- Exam codes: CAS-004 (current widespread reference) / CAS-005 (SecurityX V5 rebrand)
- Questions: Up to 90 questions, combining multiple-choice and performance-based items
- Time limit: 165 minutes
- Scoring: Pass/fail (no numeric score reported)
- Exam fee: Approximately $509
- Prep time: Typically several months depending on experience level
- Validity: 3 years, renewable through CompTIA’s continuing education program
At a glance: The exam fee varies by location, and total preparation costs can range widely depending on study materials and lab access, with options from self-study to instructor-led training.
Who should pursue the SecurityX certification?
SecurityX is built for practitioners who operate at the senior technical level. If your daily work involves designing security architectures, evaluating enterprise risk controls, or implementing cryptographic solutions across hybrid environments, this credential validates exactly those skills.
CompTIA recommends candidates have extensive general IT administration experience including significant hands-on security work before sitting for the exam. That guidance is a recommendation, not an enforced prerequisite, but it reflects the genuine difficulty of the performance-based items.
- Primary audience: Security architects, senior security engineers, and principal technical practitioners
- Employer types: Enterprise organizations, defense contractors, and federal-adjacent agencies
- Career stage: Mid-to-senior level; not an entry-level or early-career credential
- Career direction: Best suited for professionals who want to deepen technical expertise rather than transition into management or governance roles
Pro Tip: If your goal is to move into a CISO or security management role, a management-focused credential may serve that path better. SecurityX is the right choice when you want to stay hands-on and advance as a technical authority.
What does the CASP+ exam actually cover?
SecurityX V5 reorganized and narrowed the domain structure compared to the previous version, sharpening the focus on practical engineering tasks. The four domains cover Governance, Risk & Compliance, Security Architecture, Security Engineering, and Security Operations, with roughly balanced emphasis across these areas.
Each domain tests applied knowledge, not just recall. Security Architecture covers hybrid and cloud design, zero-trust frameworks, and resilience planning. Security Engineering goes deep on cryptography, key management, secure software development, and automation. Security Operations addresses incident detection, threat hunting, and response procedures. Governance, Risk & Compliance ties the technical work to regulatory frameworks and enterprise risk posture.

Performance-based items test practical skills such as configuring firewall policies, troubleshooting PKI chains, or designing network segments under constraints within the exam interface.
How does exam registration and delivery work?
The logistics are straightforward once you know where to look.
- Registration: Purchase the exam voucher through CompTIA’s official store, then schedule through Pearson VUE
- Delivery options: In-person at a Pearson VUE authorized testing center or online proctored
- Format: Up to 90 questions, 165 minutes, multiple-choice plus performance-based items
- Scoring: Pass/fail; results are typically available immediately after the exam
- Exam fee: Approximately $509 for the voucher
- Total prep budget: Self-study paths can stay near the $500–$1,000 range; instructor-led options with lab access can reach $3,000
Pro Tip: Before purchasing a voucher, confirm whether your employer or a specific job listing expects CAS-004 or CAS-005. The SecurityX rebrand introduced CAS-005 as the current version, but some postings and training materials still reference CAS-004. Scheduling the wrong version wastes both time and money.
Reviewing what to expect on exam day before you sit can reduce test-day friction considerably, particularly for the performance-based sections.
How does SecurityX compare to CISSP, Security+, and other credentials?
The clearest distinction is technical depth versus management breadth. SecurityX validates hands-on engineering ability: you are expected to implement, configure, and troubleshoot, not just advise or govern. CISSP, by contrast, is structured around security management domains and is the standard credential for professionals moving toward security leadership or CISO-track roles.
- Security+: Entry-to-mid-level; validates foundational concepts and is a common starting point before CASP+/SecurityX
- CySA+: Intermediate; focuses on threat analysis and SOC-level operations rather than architecture and engineering
- CISSP: Management and governance oriented; broader in scope but less focused on hands-on technical implementation
- SecurityX/CASP+: Senior technical; validates architecture, engineering, and operational implementation across enterprise environments
A dual-certification strategy, holding both SecurityX and CISSP, is common among senior practitioners who need to communicate with both engineering teams and executive leadership. SecurityX covers the technical credibility; CISSP covers the governance and management vocabulary. For professionals who want to explore advanced-level credential pathways, understanding where each credential sits in the hierarchy helps avoid redundant study time.
How should you build your CASP+ study plan?
A structured 2–6 month plan, matched to your current experience level, produces the most consistent results.
- Map the objectives. Download the official CompTIA SecurityX exam objectives for CAS-005 and audit your existing knowledge against each domain. Identify gaps before spending a single hour studying.
- Complete a guided course. Work through a mapped course that covers all four domains. Totalcyber’s CompTIA-aligned training catalog includes structured options built around the current objectives.
- Build lab time. Performance-based items require practice in real or simulated environments. Set up a home lab or use a cloud-based lab platform to practice cryptographic configurations, network segmentation, and incident response workflows.
- Run timed practice exams. Study plans that combine mapped objectives, performance-based labs, and repeated timed practice exams produce the strongest readiness gains for the performance-based sections.
- Final review. In the last two weeks, focus on weak domains, review flagged practice questions, and simulate full exam conditions.
For budget planning: self-study using free objectives, open-source labs, and one or two practice exam sets can stay under $1,000. Instructor-led training with structured lab access typically runs $1,500–$3,000 total. Practical study strategies for IT certification exams can help you decide which approach fits your schedule and learning style.
Pro Tip: Treat the official exam objectives as your syllabus, not a checklist. Every performance-based task on the exam maps to a specific objective. If you can perform the task in a lab, you can answer the question under pressure.

What career outcomes can you expect after earning SecurityX?
SecurityX holders are positioned for senior technical roles across enterprise and government sectors. Common job titles that specify the credential include security architect, senior security engineer, principal security engineer, and information systems security officer (ISSO).
The DoD 8570/8140 recognition makes SecurityX particularly valuable for defense contractor and federal agency positions, where specific certification categories are required for privileged access roles. Organizations operating under those frameworks often mandate SecurityX-level credentials for technical positions that CISSP alone does not satisfy.
Salary signal: U.S. holders of CASP+/SecurityX report average salaries near $100,000 per year, with higher compensation in federal and enterprise environments where the credential satisfies compliance requirements.
The career benefits of recognized certifications in this tier extend beyond salary. SecurityX signals to hiring managers that a candidate can operate independently at the architecture and engineering level, which shortens the evaluation process for senior roles.
How do you renew the SecurityX certification?
The certification is valid for multiple years from the date of passing. Renewal requires earning continuing education units (CEUs) through CompTIA’s continuing education program, with specific CEU requirements over the cycle.
- Approved CEU activities: Completing relevant training courses, attending industry conferences, publishing security research, completing higher-level certifications, or teaching security content
- Submission: CEUs are logged and submitted through CompTIA’s CertMetrics portal
- Alternative renewal: Retaking and passing the current exam version resets the three-year clock
- Stacking: Earning a qualifying higher-level certification can satisfy the renewal requirement automatically
Pro Tip: Log CEU activities as you complete them rather than reconstructing your activity history at the end of year three. CertMetrics accepts documentation in real time, and a missing record is harder to recover than a timely submission.
What are your next steps to get started?
- Confirm the exam version. Verify whether your employer or target job postings specify CAS-004 or CAS-005 before purchasing a voucher.
- Audit your experience. Assess whether your background aligns with the recommended 10 years of IT experience and 5 years in security.
- Download the official objectives. Pull the SecurityX V5 exam objectives from CompTIA’s website and map them against your current knowledge.
- Choose your training path. Decide between self-study, on-demand courses, or instructor-led training based on your timeline and budget.
- Schedule lab time. Build hands-on practice into your weekly schedule from week one, not just the final month.
- Register through Pearson VUE. Purchase your exam voucher from CompTIA and book your seat through Pearson VUE.
- Track CEUs from day one. Once you pass, begin logging qualifying activities immediately.
For candidates ready to start structured preparation, Totalcyber’s cybersecurity training programs offer mapped, hands-on coursework aligned to CompTIA objectives. Use the training prerequisites checklist to confirm readiness before committing to a course.

Key Takeaways
SecurityX (CASP+) is CompTIA’s advanced, hands-on certification for senior security engineers and architects, validated through a pass/fail exam of up to 90 questions in 165 minutes, with a 3-year renewal cycle.
| Point | Details |
|---|---|
| Exam codes and version | CAS-004 is widely referenced; CAS-005 is the current SecurityX V5 version. |
| Exam format and cost | Up to 90 questions, 165 minutes, pass/fail scoring; exam fee is approximately $509. |
| Experience baseline | CompTIA recommends roughly 10 years in IT and 5 years of hands-on security experience before sitting. |
| Prep timeline and budget | Plan 2–6 months of study; total costs range from roughly $500 to $3,000 depending on training path. |
| Career and DoD value | Holders report average U.S. salaries near $100,000/year; the credential satisfies DoD 8570/8140 requirements for technical roles. |