Skip to content

CompTIA SecAI+ (CY0-001)

A vendor-neutral AI security certification with no certification prerequisite, weighted 40% toward securing AI systems — the most engineer-facing of the AI security credentials, and the newest and least proven.

CompTIA
Exam cost
CompTIA does not publish a price on the SecAI+ certification page; vouchers are sold through the CompTIA store and authorised resellers, and the figure varies by region and bundle
src
CompTIA — SecAI+ certification page (comptia.org/en-us/certifications/secai)
chk
Duration
60 minutes
Passing score
600 on a scale of 100–900
Valid for
3 years, renewable through CompTIA's continuing education programme

SecAI+ is the AI security exam an engineer can actually sit. That sounds like faint praise until you look at the alternatives: ISACA's AAISM requires an active CISM or CISSP, and the IAPP's AIGP is governance-first and written for a much broader audience.

This one has no certification prerequisite and puts 40% of its marks on securing AI systems.

Where the marks are

Unusually easy to prioritise. Securing AI Systems is 40% on its own — model and endpoint security, prompt injection defence, permissions, supply chain, guardrails. Nothing else is close.

The rest splits fairly evenly: AI-assisted Security 24%, AI Governance, Risk and Compliance 19%, and Basic AI Concepts 17%.

If you have thirty hours, spend fifteen of them in the first domain and you will have covered the exam roughly in proportion to how it is scored.

Choosing between the three AI security certifications

This site covers all three, and the choice is usually made for you by the prerequisite rather than by the syllabus.

SecAI+ — no gate, engineer-facing, 40% on building and defending AI systems. The one that matches the work if you are on the AI security engineer path.

AAISM — requires CISM or CISSP. A management credential for people who already hold a senior security certification and have acquired AI inside their remit.

AIGP — no gate, but governance-first, and its audience deliberately includes legal and policy people rather than only engineers.

The honest caveat

It launched on 17 February 2026. That is recent enough that almost no hiring manager has formed a view of what it means, and a certification's value in hiring is entirely a matter of what people believe about it.

So the syllabus is the return here, not the badge — and the syllabus is good. Two fifths of it is the actual technical work of securing an AI system, which is more than any competing credential devotes to the same material. Study it for that, and treat the recognition as something that may or may not arrive.

Before you book

Sixty questions in sixty minutes. One minute each, with performance-based items mixed in. That pace rewards familiarity over deliberation, so practise until the vocabulary is automatic rather than reconstructed.

600 on a 100–900 scale to pass. Valid three years, renewable through CompTIA's continuing education programme rather than by resitting.

CompTIA does not publish a price on the certification page. Vouchers go through the CompTIA store and resellers, and the figure varies by region and bundle — so check before budgeting rather than trusting a number quoted elsewhere.

Your progress0%

Exam domains

Securing AI Systems

40%
Securing models, training data and inference endpointsPrompt injection and adversarial input defenceAccess control and permissions for AI componentsAI supply chain and model provenanceGuardrails and output validationMonitoring and logging of AI system behaviour

AI-assisted Security

24%
Using AI to support detection and triageAI in vulnerability management and threat intelligenceAutomating security operations with AI toolingEvaluating and validating AI-generated security outputLimitations and failure modes of AI-assisted workflows

AI Governance, Risk, and Compliance

19%
AI risk identification and assessmentRegulatory and standards landscape for AIPolicy, acceptable use and accountabilityThird-party and vendor AI riskAuditing and evidencing AI controls

Basic AI Concepts Related to Cybersecurity

17%
Machine learning and generative model fundamentalsTraining, fine-tuning and inferenceRetrieval-augmented generation and agentsAI terminology as used in security contextsWhere AI capability ends and where controls must begin

Preparation path

  1. 1

    Understand what this exam is and how new it is

    SecAI+ launched on 17 February 2026 as CY0-001 version 1. It is vendor-neutral and has no certification prerequisite, which distinguishes it from AAISM. It is also unproven in hiring, so weigh it as a study framework first and as a hiring signal second.

    ~2 hours
  2. 2

    Concentrate on securing AI systems — it is 40% on its own

    Two fifths of the exam sit in one domain, which is unusual and makes prioritisation easy. Model and endpoint security, prompt injection defence, permissions, supply chain and guardrails. Vendor-neutral sources cover this material better than any single product's documentation.

    ~30 hours
  3. 3

    Learn the governance and risk vocabulary

    Nineteen per cent is governance, risk and compliance, and the expected answers use published framework language rather than an engineer's. The NIST AI Risk Management Framework is the most useful free source, and the EU AI Act supplies the regulatory shape.

    ~15 hours
  4. 4

    Prepare for the AI-assisted security domain by using the tools

    At 24% this covers AI applied to detection, triage and vulnerability work, including how to validate what it produces. It rewards having actually run an AI-assisted workflow and watched it be confidently wrong, which is the judgement the questions probe.

    ~15 hours

Frequently asked questions

Career Roadmaps