CompTIA SecAI+ (CY0-001)
A vendor-neutral AI security certification with no certification prerequisite, weighted 40% toward securing AI systems — the most engineer-facing of the AI security credentials, and the newest and least proven.
- src
- CompTIA — SecAI+ certification page (comptia.org/en-us/certifications/secai)
- chk
SecAI+ is the AI security exam an engineer can actually sit. That sounds like faint praise until you look at the alternatives: ISACA's AAISM requires an active CISM or CISSP, and the IAPP's AIGP is governance-first and written for a much broader audience.
This one has no certification prerequisite and puts 40% of its marks on securing AI systems.
Where the marks are
Unusually easy to prioritise. Securing AI Systems is 40% on its own — model and endpoint security, prompt injection defence, permissions, supply chain, guardrails. Nothing else is close.
The rest splits fairly evenly: AI-assisted Security 24%, AI Governance, Risk and Compliance 19%, and Basic AI Concepts 17%.
If you have thirty hours, spend fifteen of them in the first domain and you will have covered the exam roughly in proportion to how it is scored.
Choosing between the three AI security certifications
This site covers all three, and the choice is usually made for you by the prerequisite rather than by the syllabus.
SecAI+ — no gate, engineer-facing, 40% on building and defending AI systems. The one that matches the work if you are on the AI security engineer path.
AAISM — requires CISM or CISSP. A management credential for people who already hold a senior security certification and have acquired AI inside their remit.
AIGP — no gate, but governance-first, and its audience deliberately includes legal and policy people rather than only engineers.
The honest caveat
It launched on 17 February 2026. That is recent enough that almost no hiring manager has formed a view of what it means, and a certification's value in hiring is entirely a matter of what people believe about it.
So the syllabus is the return here, not the badge — and the syllabus is good. Two fifths of it is the actual technical work of securing an AI system, which is more than any competing credential devotes to the same material. Study it for that, and treat the recognition as something that may or may not arrive.
Before you book
Sixty questions in sixty minutes. One minute each, with performance-based items mixed in. That pace rewards familiarity over deliberation, so practise until the vocabulary is automatic rather than reconstructed.
600 on a 100–900 scale to pass. Valid three years, renewable through CompTIA's continuing education programme rather than by resitting.
CompTIA does not publish a price on the certification page. Vouchers go through the CompTIA store and resellers, and the figure varies by region and bundle — so check before budgeting rather than trusting a number quoted elsewhere.
Exam domains
Securing AI Systems
40%AI-assisted Security
24%AI Governance, Risk, and Compliance
19%Basic AI Concepts Related to Cybersecurity
17%Preparation path
- 1
Understand what this exam is and how new it is
SecAI+ launched on 17 February 2026 as CY0-001 version 1. It is vendor-neutral and has no certification prerequisite, which distinguishes it from AAISM. It is also unproven in hiring, so weigh it as a study framework first and as a hiring signal second.
~2 hours - 2
Concentrate on securing AI systems — it is 40% on its own
Two fifths of the exam sit in one domain, which is unusual and makes prioritisation easy. Model and endpoint security, prompt injection defence, permissions, supply chain and guardrails. Vendor-neutral sources cover this material better than any single product's documentation.
~30 hours - 3
Learn the governance and risk vocabulary
Nineteen per cent is governance, risk and compliance, and the expected answers use published framework language rather than an engineer's. The NIST AI Risk Management Framework is the most useful free source, and the EU AI Act supplies the regulatory shape.
~15 hours - 4
Prepare for the AI-assisted security domain by using the tools
At 24% this covers AI applied to detection, triage and vulnerability work, including how to validate what it produces. It rewards having actually run an AI-assisted workflow and watched it be confidently wrong, which is the judgement the questions probe.
~15 hours
Frequently asked questions
Career Roadmaps
- AI Security Engineer RoadmapA defensive security path for engineers who secure LLM and agent systems, covering AI threat modelling, prompt injection defence, supply chain integrity, agent permissions, guardrails, governance and incident response.
- Cloud Security Engineer RoadmapA path into cloud security as an engineering discipline, covering the shared responsibility model, identity, network segmentation, encryption, workload hardening, detection, governance as code, threat modelling and incident response.