← All certifications

CompTIA SecurityX

CompTIA

Advanced practitioner certification, renamed from CASP+. Appears at the Advanced level for System Administrator (451) and at Intermediate for ISSM (722).

We have a course for this

Built from this exam's published objectives. The first module is free.

Baseline certification levels

This certification satisfies these DoD baseline levels — the IAT / IAM / IASAE / CSSP requirement many contracts still state. It's a separate question from the 8140 work roles above, and there is no official mapping between the two.

What this qualifies you for

Listed specifically for 12 work roles — up to Advanced proficiency. Because options cascade downward, a cert listed at Advanced also satisfies Intermediate and Basic for that role.

411Technical Support SpecialistProvides technical support to customers who need assistance utilizing client level hardware and software in accordance with established or approved organizational process components. (i.e., Master Incident Management Plan, when applicable).Advanced421Database AdministratorAdministers databases and/or data management systems that allow for the storage, query, and utilization of data.Advanced441Network Operations (NETOPS) SpecialistPlans, implements, and operates network services/systems, to include hardware and virtual environments.Advanced451System Administrator (SYSADMIN)Installs, configures, troubleshoots, and maintains hardware, software, and administers system accounts.Advanced541Vulnerability Assessment AnalystPerforms assessments of systems and networks within the NE or enclave and identifies where those systems/networks deviate from acceptable configurations, enclave policy, or local policy. Measures effectiveness of defense-in-depth architecture against known vulnerabilities.Advanced612Security Control AssessorConducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST 800-37).Intermediate631Information Systems Security DeveloperDesigns, develops, tests, and evaluates information system security throughout the systems development lifecycle.Intermediate641Systems Requirements PlannerConsults with customers to evaluate functional requirements and translate functional requirements into technical solutions.Advanced651Enterprise ArchitectDevelops and maintains business, systems, and information processes to support enterprise mission needs; develops information technology (IT) rules and requirements that describe baseline and target architectures.Intermediate652Security ArchitectDesigns enterprise and systems security throughout the development lifecycle; translates technology and environmental conditions (e.g., law and regulation) into security designs and processes.Intermediate661Research & Development (R&D) SpecialistConducts software and systems engineering and software systems research in order to develop new capabilities, ensuring cybersecurity is fully integrated. Conducts comprehensive technology research to evaluate potential vulnerabilities in cyberspace systems.Advanced722Information Systems Security Manager (ISSM)Responsible for the cybersecurity of a program, organization, system, or enclave.Intermediate
Also listed for 14 Cyberspace Enablers roles — but so is every other certification

The Enablers matrix isn’t role-differentiated: the same certification options are listed for all 14 roles at every proficiency level. We verified that across all 14. So this is true, and it carries no information about this credential specifically — which is why it isn’t in the count above.

Renewal

3year cycle75CEU per cycle

This is the issuer’s clock. 8140 runs a second one — 20 hours of CPD a year, at every proficiency level, which applies even if you hold no certification at all. How that works

Verifying it

CompTIA has no public lookup a third party can use on their own — verification depends on a badge URL you share.

A badge URL the holder shares. Credly proves a badge exists, not who holds it.

Exam blueprint

Verified against CompTIA’s published outline.

CAS-005 · V5

Current

Max 90 questions · max 165 minutes · pass/fail only, no scaled score

Governance, risk, and compliance20%
Security architecture27%
Security engineering31%
Security operations22%

Scored pass/fail with no scaled score — unusual for CompTIA. The 8140 matrix still lists this credential under its former name, CASP+.

Source: CompTIA SecurityX certification page · dated 2024-12-17 · checked 2026-07-16