Security+ SY0-701 vs SY0-801: what is changing in V8
By 8140.study · Published 2026-09-15 · Last updated 2026-09-15
This page compares the two versions using CompTIA’s own documents only: the Security+ certification page for SY0-701 and the draft V8 objectives for SY0-801. We update it when CompTIA changes either one.
The exam format in the draft matches SY0-701
| SY0-701 | SY0-801 draft | |
|---|---|---|
| Maximum questions | 90 | 90 |
| Time limit | 90 minutes | 90 minutes |
| Passing score | 750 (scale of 100 to 900) | 750 (scale of 100 to 900) |
| Question types | Multiple-choice and performance-based | Multiple-choice and performance-based |
So your time management practice carries over: plan for roughly a minute per question, and expect performance-based questions to take longer than multiple-choice. Every current SY0-701 detail, with its source, is on our Security+ certification page.
Domain weights: SY0-701 vs the SY0-801 draft
| Domain | SY0-701 | SY0-801 draft | Change |
|---|---|---|---|
| 1.0 General Security Concepts | 12% | 16% | +4 points |
| 2.0 Threats, Vulnerabilities, and Attacks | 22% | 24% | +2 points |
| 3.0 Security Architecture | 18% | 19% | +1 points |
| 4.0 Security Operations | 28% | 27% | -1 points |
| 5.0 Security Program Management and Oversight | 20% | 14% | -6 points |
General Security Concepts gains the most, from 12% to 16%. Security Program Management and Oversight loses the most, from 20% to 14%. Domain 2 is renamed from Threats, Vulnerabilities, and Mitigations to Threats, Vulnerabilities, and Attacks, and gains 2 points. Security Operations stays the largest domain at 27%.
Study tip: weight your hours to the version you will actually sit. If that is SY0-701, keep Security Operations (28%) as your biggest block and do not shortchange governance, which is still 20% of that exam. If you are planning around SY0-801, the draft shifts time from governance and compliance toward core concepts and threats.
What the draft says about AI
The draft includes objective 2.6, “Summarize threats and vulnerabilities associated with artificial intelligence (AI) usage,” which lists items such as prompt injection, poisoning, jailbreaking, and hallucinations. Large language models also appear as an attack surface in objective 2.4, and AI capabilities appear under automation and orchestration in objective 4.6. The AI topics are broken down one by one here.
The draft SY0-801 objectives, domain by domain
The draft lists 27 objectives across the five domains. SY0-701 has 28, according to CompTIA. Titles below are exactly as they appear in draft document version 1.5.
1.0 General Security Concepts (16%)
- 1.1 Explain security concepts and controls.
- 1.2 Given a scenario, demonstrate the impact of change management processes on security.
- 1.3 Explain the importance of using appropriate cryptographic solutions.
2.0 Threats, Vulnerabilities, and Attacks (24%)
- 2.1 Explain characteristics of threats and vulnerabilities.
- 2.2 Describe common threat actors and motivations.
- 2.3 Describe threat vectors and sources.
- 2.4 Explain types of vulnerabilities and attack surfaces.
- 2.5 Given a scenario, analyze indicators of malicious activity.
- 2.6 Summarize threats and vulnerabilities associated with artificial intelligence (AI) usage.
3.0 Security Architecture (19%)
- 3.1 Compare and contrast security implications of different architecture models.
- 3.2 Given a scenario, manage the security architecture to best protect the infrastructure.
- 3.3 Summarize concepts and strategies used to protect data.
- 3.4 Explain the importance of resilience and recovery in security architecture.
4.0 Security Operations (27%)
- 4.1 Given a scenario, apply mitigating controls, techniques, and solutions to secure the environment.
- 4.2 Explain the security implications of proper hardware, software, and data asset management.
- 4.3 Given a scenario, perform tasks associated with vulnerability management.
- 4.4 Explain security alerting and monitoring concepts and tools.
- 4.5 Given a scenario, apply concepts related to identity and access management.
- 4.6 Given a scenario, apply automation and orchestration solutions to secure operations.
- 4.7 Summarize concepts associated with incident response activities.
- 4.8 Given a scenario, use data, artifacts and sources to support a security investigation.
5.0 Security Program Management and Oversight (14%)
- 5.1 Explain the importance of governance, risk, and compliance artifacts.
- 5.2 Explain the impact of risk management processes on the security of the organization.
- 5.3 Explain the assessment and management processes associated with third-party risk.
- 5.4 Summarize elements of effective security compliance.
- 5.5 Explain concepts associated with audit and assessment activities.
- 5.6 Given a scenario, apply security awareness concepts to improve organizational security.
Should you take SY0-701 or wait for SY0-801?
SY0-701 stays available until CompTIA retires it: June 11, 2027 for the English exam and August 13, 2027 for Japanese, Portuguese, Spanish, and Thai, according to CompTIA’s Security+ page as of September 15, 2026. CompTIA has not published a release date for SY0-801. We track the dates, confirmed and reported, here.
If you are already studying, or you need the certification for a job soon, SY0-701 is the exam available to you today and its study material is mature. If you have not started and your realistic exam date is late in the SY0-701 window, plan around the draft SY0-801 objectives and watch for the final version.
FAQ
What is the difference between SY0-701 and SY0-801?
In CompTIA's draft SY0-801 objectives (document version 1.5), the exam format is the same as SY0-701: up to 90 questions, 90 minutes, and a passing score of 750. The domain weights change, Domain 2 is renamed Threats, Vulnerabilities, and Attacks, and objective 2.6 covers threats and vulnerabilities of AI usage. The objectives are a draft and can change.
Is SY0-801 available yet?
No, as of September 15, 2026. SY0-701 is the current exam. CompTIA has posted SY0-801 as draft objectives and has not published a release date.
How many objectives does the draft SY0-801 have?
The draft lists 27 objectives across five domains: 3 in General Security Concepts, 6 in Threats, Vulnerabilities, and Attacks, 4 in Security Architecture, 8 in Security Operations, and 6 in Security Program Management and Oversight. SY0-701 has 28, according to CompTIA.
Studying for Security+ now? Our Security+ course follows the current SY0-701 blueprint, and its first module, General Security Concepts, is free. Or start with our 10 free Security+ practice questions.