CompTIA Security+5 min readPublished September 23, 2026Updated September 23, 2026

CompTIA Security+ in 2026: SY0-701 vs SY0-801 (V8) — Dates, Domain Weights, and Which Exam to Take

Security+ V8 (SY0-801) is due on or around 17 November 2026, and SY0-701 retires in English on 11 June 2027. Both have up to 90 questions in 90 minutes with 750 of 900 to pass. The official domain weights side by side, what changes, how to decide which version to sit, and the concepts and formulas the exam leans on hardest.

Prepared by the QuizCram editorial team using official source materials.

CompTIA Security+ in 2026: SY0-701 vs SY0-801 (V8) — Dates, Domain Weights, and Which Exam to Take

The Short Answer

Two Security+ exams will overlap from late 2026. SY0-701 (Security+ V7), live since 7 November 2023, retires in English on 11 June 2027. SY0-801 (V8) is scheduled to launch on or around 17 November 2026, in English first. The format does not change: a maximum of 90 questions, multiple-choice plus performance-based, in 90 minutes, with 750 on a 100–900 scale to pass. Both lead to the same certification, valid for three years.

If you are already studying for SY0-701 and can sit it before June 2027, stay on 701. If you are starting from zero with an exam date in 2027, look at 801 — but expect fewer study materials for the first months after launch.

SY0-701 (V7)SY0-801 (V8)
Launch7 November 2023On or around 17 November 2026
RetirementEnglish 11 June 2027; Japanese, Portuguese, Spanish and Thai 13 August 2027Estimated three years after launch
Questions and timeUp to 90, multiple-choice and performance-based; 90 minutesSame
Passing score750 (scale 100–900)750 (scale 100–900)
LanguagesEnglish, Japanese, Portuguese, Spanish, ThaiEnglish at launch
Recommended experienceNetwork+ and two years in a security or systems administrator roleTwo years of hands-on experience as a security administrator

Our free Security+ practice questions follow the SY0-701 objectives and explain why each distractor is wrong; the practice quiz is a quick way to see where you stand.

Domain Weights: 701 vs 801

Both versions keep five domains with nearly the same names. The weights shift: V8 puts more on fundamentals, threats and architecture, and less on governance.

DomainSY0-701SY0-801Change
1. General Security Concepts12%16%+4
2. Threats, Vulnerabilities and Mitigations (V8: …and Attacks)22%24%+2
3. Security Architecture18%19%+1
4. Security Operations28%27%−1
5. Security Program Management and Oversight20%14%−6

CompTIA describes V8 as expanding coverage of AI-related risks, security operations and modern environments. Security operations remains the largest domain in both — the day-to-day work of hardening, monitoring, identity and incident response is where the most points sit either way.

Which Version Should You Take?

  • Take SY0-701 if you have already started studying for it, if you need the certification for a job or contract before mid-2027, or if you rely on third-party courses and practice tests — the 701 ecosystem is mature.
  • Consider SY0-801 if you are starting fresh and will test after it launches, or if your employer asks for the newest version. Allow for a few months after launch before books, courses and practice banks fully catch up.
  • Do not wait for 801 just because it is newer. Employers and job postings ask for "Security+", not a version, and a certification earned on 701 stays valid for its full three years after 701 retires.
The retirement date is a hard stop. A 701 voucher cannot be used for 701 after 11 June 2027 (English). If you are cutting it close, book the appointment now — end-of-life months fill up.

What the Exam Leans On Hardest

Security+ is a vocabulary-precise exam: many items turn on the difference between two close terms. These are the areas that generate the most questions in both versions:

  • Control categories and types. Technical, managerial, operational and physical categories; preventive, deterrent, detective, corrective, compensating and directive types. Expect items that describe a control and ask which it is.
  • Cryptography by purpose. Symmetric vs asymmetric, hashing vs encryption, salting, digital signatures (integrity and non-repudiation), certificates and PKI, key escrow.
  • Attacks and their indicators. Social engineering, malware types, password attacks, application attacks such as injection and cross-site scripting, and the log or behaviour that reveals each.
  • Architecture choices. Cloud responsibility models, segmentation, zero trust, high availability, backups and recovery sites.
  • Identity and access. MFA factors, SSO and federation, privileged access management, and access-control models.
  • Incident response in order. Preparation, detection, analysis, containment, eradication, recovery, lessons learned — items often ask for the next step.
  • Risk math. The formulas below appear as short calculations and as definitions.
TermMeaning
SLE (single loss expectancy)Asset value × exposure factor
ARO (annualised rate of occurrence)How many times a year the loss is expected
ALE (annualised loss expectancy)SLE × ARO
RTO (recovery time objective)How long a system can be down before the impact is unacceptable
RPO (recovery point objective)How much data, measured in time, the business can afford to lose
MTTR / MTBFMean time to repair / mean time between failures

Performance-Based Questions

A few questions are simulations: configuring firewall rules, matching attacks to indicators, placing controls on a network diagram. They often appear first and take far longer than multiple-choice items. A common strategy is to flag them, answer the multiple-choice questions, then return with the remaining time — the exam lets you review and change answers before you submit. Partial credit is possible on many simulations, so never leave one blank.

How to Prepare

  1. Download the official objectives for your version and use them as a checklist; every item maps to an objective.
  2. Study by domain in weight order — security operations, threats, program management or architecture, then general concepts for 701; threats and operations first for 801.
  3. Build a term sheet of look-alike pairs (IDS/IPS, vulnerability scan/penetration test, hot/warm/cold site, RTO/RPO) and drill it daily.
  4. Practise scenario items, where the task is the best control rather than any valid one. Our Security+ practice test explains the trade-off behind each answer.
  5. Coming from A+? Much of the port and hardware knowledge carries over — see our A+ Core 1 ports and numbers cheat sheet as a refresher.

Frequently Asked Questions

When does Security+ SY0-701 retire?

The English SY0-701 exam retires on 11 June 2027. The Japanese, Portuguese, Spanish and Thai versions retire on 13 August 2027.

When does Security+ SY0-801 come out?

CompTIA lists Security+ V8 (SY0-801) as launching on or around 17 November 2026, in English.

Is SY0-801 harder than SY0-701?

The format and passing score are the same — up to 90 questions in 90 minutes, 750 of 900 to pass. The content shifts weight toward general concepts, threats and architecture and away from governance, and adds coverage of AI-related risks.

What is the passing score for Security+?

750 on a scale of 100 to 900 for both SY0-701 and SY0-801. It is a scaled score, not a percentage of questions answered correctly.

Does my Security+ expire when SY0-701 retires?

No. The certification is valid for three years from the day you pass, whichever exam version you took, and is renewed through CompTIA's continuing-education program.

Sources

Put it into practice

Drill these concepts with free CompTIA Security+ quizzes — instant explanations and source notes.

Keep reading