Blog  /  CompTIA

CompTIA’s AI Certifications: Nine Names, One Exam

Nine AI credentials, one you can actually sit today - CompTIA SecAI+ CY0-001

Search for "CompTIA AI certification" and you will find nine names. Eight of them are announcements. One is an exam you can book.

That distinction matters more than it sounds, because a roadmap entry and a certification look identical in a blog post, on a LinkedIn feed, and in a training provider's course list. Here is which is which, as of today.

The one that exists: SecAI+

CompTIA SecAI+ launched on 17 February 2026. It is a full certification with an exam code, an objectives document and a pass mark, and it sits alongside Security+ and CySA+ rather than replacing either.

Exam codeCY0-001
QuestionsMaximum of 60, multiple choice and performance-based
Length60 minutes
Pass mark600 on a scale of 100–900
Recommended3–4 years in IT, 2+ years hands-on cybersecurity, and Security+, CySA+ or PenTest+

Sixty questions in sixty minutes is a fast exam. Performance-based items eat time out of proportion to their count, so the practical pressure is higher than a minute-per-question suggests.

What it actually tests

Read the weightings before you decide whether this is your exam, because they are not evenly spread and the shape of them tells you what CompTIA thinks the job is.

DomainWeight
Securing AI systems40%
AI-assisted security24%
AI governance, risk and compliance19%
Basic AI concepts related to cybersecurity17%
Two fifths of the exam is defending AI systems — not using AI to defend everything else. If you expected a certification about pointing a language model at your SIEM, the weighting says otherwise.

Only 17% is foundational AI concepts, which tells you what CompTIA assumes you already know walking in. This is not an entry point into AI. It is a security certification for people who now have AI systems inside their estate and are responsible for the consequences.

The remaining 43% splits between using AI in security operations — threat detection, automation — and the governance side: compliance, risk, and being able to answer for how a model reached a decision.

The two that are courses, not certifications

These come up constantly in the same conversation and they are a different kind of thing. Both are worth doing. Neither puts letters after your name.

  • AI Essentials — foundational, aimed at any role rather than IT specifically. Released July 2024.
  • AI Help Desk Essentials — announced 25 February 2026. Scenario-driven training for support teams on using generative AI for ticket summarisation, incident diagnosis, log analysis and user communication. It carries a competency assessment at the end, which is not the same as a certification exam.

If someone offers you a "CompTIA AI certification" and what arrives is one of these, you have not been misled exactly — but you have not bought what you thought you bought.

The seven that are announced

CompTIA published an AI roadmap covering six domains: software development, cybersecurity, systems operations, data analytics, prompt engineering and AI systems architecture. The plan is a series of Expansions that build on existing certifications.

  • PenTest AI+ — penetration testers
  • CySA AI+ — security analysts
  • Data AI+ — data analysts
  • AI SysOp+ — systems operations
  • AI Scripting+ — tech support and network operations
  • AI Architect+ — AI systems architects
  • AI Prompt+ — prompt engineers

SecAI+ was the first of these to ship. None of the other seven has a published exam code or a launch date that we can find, and we look regularly. Treat any course promising to prepare you for one of them as preparing you for a document that does not exist yet.

Should you sit SecAI+?

Yes, if you already hold Security+ or CySA+, you have a couple of years of hands-on security behind you, and your organisation has started putting AI systems into production. The governance domain alone is worth the preparation time if you are the person who gets asked whether the model is compliant.

Not yet, if you are early in a security career. The recommended experience is three to four years in IT before you start, and the 17% foundational weighting means the exam will not teach you the basics on the way past. Security+ first.

Wait, if your role maps to one of the other seven. A pen tester wanting PenTest AI+ gains little from sitting a security-engineering exam instead. There is no advantage in being early to the wrong certification.

What we would tell you on the phone

AI certifications are in the phase where the marketing runs ahead of the exams. That is not a criticism of CompTIA — it is what a roadmap is for — but it does mean the honest answer to "which AI certification should I get" is often "the one that exists, if it fits your job, and otherwise wait."

We would rather tell you that than sell you a class. If you want to talk through where SecAI+ sits against what you already hold, or whether your team is better served by AI Essentials for now, ask us — and if the answer is that you should not spend the money yet, we will say so.

Tell us what you already hold and what your organisation is actually deploying. That is usually enough to say whether this exam is worth your February.

More from the blog