Cyber securitySOT-001

CompTIA SecOT+ (SOT-001): Complete Certification Guide

By SkillsNest · 18 September 2026

CompTIA SecOT+ SOT-001 OT cybersecurity certification

Discover the CompTIA SecOT+ (SOT-001) certification, what it covers, who it is for, the skills you'll need and how to prepare for a career securing operational technology environments.

Operational technology is becoming more connected, more intelligent and more exposed to cyber threats. The systems that control factories, energy networks, utilities, transport and other critical services can no longer be protected through traditional IT security alone.

CompTIA SecOT+ is being developed to address that need.

Known by its exam code SOT-001, CompTIA SecOT+ is an upcoming vendor-neutral certification focused on securing operational technology environments. It is designed for professionals who need to understand the relationship between cybersecurity, industrial operations, system availability and physical safety.

In this guide, we explain what CompTIA SecOT+ is, who it is for, what the current exam objectives cover and how you can begin preparing.

Want to follow the development of the qualification? Visit the Skills Nest CompTIA SecOT+ (SOT-001) certification page for course, practice test and mock exam updates.

What is CompTIA SecOT+?

CompTIA SecOT+ is an upcoming cybersecurity certification centred on operational technology, usually shortened to OT. It aims to validate the knowledge and practical skills needed to protect and manage industrial and cyber-physical environments.

Unlike a certification that concentrates mainly on conventional business IT, SecOT+ considers systems that can directly affect machinery, production, essential services and human safety. These may include:

  • Industrial control systems (ICS)
  • Supervisory control and data acquisition (SCADA) systems
  • Programmable logic controllers (PLCs)
  • Distributed control systems (DCS)
  • Building management and automation systems
  • Industrial networks, sensors and connected devices
  • Safety instrumented systems

CompTIA currently lists the SOT-001 objectives as being under development. Candidates should therefore treat all published details as provisional until CompTIA releases the final exam objectives.

What is operational technology security?

Operational technology security is the protection of the hardware, software, networks and processes used to monitor or control physical operations.

In a normal IT environment, cybersecurity frequently prioritises the confidentiality, integrity and availability of data. These principles still matter in OT, but the order of priorities may change. Availability, reliability and safety can be critical because an interruption could stop production, damage equipment or create a risk to people and the environment.

For example, restarting an office laptop to install an urgent security update may be straightforward. Restarting part of an industrial process can require extensive planning, engineering approval and a carefully controlled maintenance window.

This difference is one reason specialised OT cybersecurity knowledge is increasingly important.

Why is OT cybersecurity becoming more important?

Historically, many industrial systems operated in isolated or highly restricted environments. Today, organisations increasingly connect OT systems to corporate networks, cloud platforms, remote support tools and data analytics services.

This convergence between IT and OT can improve efficiency and visibility, but it can also create new attack paths. Common challenges include:

  • Legacy devices that cannot be easily patched
  • Systems that must remain available continuously
  • Remote access by employees, suppliers and engineers
  • Limited visibility of industrial assets and communications
  • Insecure or specialist industrial protocols
  • Long equipment lifecycles
  • Supply-chain and third-party risks
  • Ransomware and other threats crossing from IT into OT
  • Security decisions that could affect physical safety

Organisations therefore need people who can apply cybersecurity controls without disrupting essential operational processes.

Who is CompTIA SecOT+ for?

SecOT+ is not positioned as a first introduction to computing. It is more likely to suit professionals who already have experience in cybersecurity, networking, industrial operations, engineering or critical infrastructure.

Potential candidates may include:

  • OT or ICS security analysts
  • Cybersecurity analysts moving into industrial security
  • Control systems engineers
  • Industrial network engineers
  • Security architects
  • Incident responders
  • Risk and compliance professionals working with OT
  • Manufacturing or infrastructure technology specialists
  • IT professionals responsible for converged IT and OT environments

The certification could also be valuable for professionals who support organisations in sectors such as manufacturing, energy, water, transport, logistics, healthcare, pharmaceuticals and building automation.

What does the SOT-001 exam cover?

The current draft CompTIA SecOT+ objectives are organised into six broad domains. These may be revised before the exam launches, so always check the latest information from CompTIA.

1. OT Systems and Safety Foundations

This area establishes how OT differs from conventional IT. Candidates should understand industrial system components, device roles, communication methods, operational processes and safety considerations.

It is important to recognise that an OT security decision can have a physical consequence. Cybersecurity controls must work alongside engineering requirements, reliability targets and safety procedures.

2. OT Risk Management

OT risk management connects security activity to operational and organisational objectives. It includes identifying and assessing risk, understanding governance and compliance requirements, prioritising remediation and managing change in sensitive environments.

A technically strong control is not useful if it creates an unacceptable operational or safety risk. Candidates must learn to assess threats, vulnerabilities, likelihood and impact in the context of real industrial operations.

3. OT Threat Intelligence

Threat intelligence helps organisations understand the adversaries, techniques and indicators relevant to their environment. In OT, this requires awareness of threats targeting industrial systems and critical infrastructure rather than relying only on general IT threat models.

Candidates should be able to use intelligence to improve monitoring, risk decisions and defensive planning.

4. OT Cybersecurity Architecture, Design and Engineering

This domain concerns the secure design and protection of operational environments. Topics may include network segmentation, secure zones and conduits, physical controls, device hardening, identity and access management, remote access and resilient architecture.

Good OT security architecture uses layers of protection while respecting the performance, availability and safety needs of the industrial process.

5. OT Security Operations

OT security operations cover the day-to-day work required to maintain visibility and reduce risk. This may include asset management, security monitoring, vulnerability handling, access control, maintenance activity and the management of portable or removable media.

Accurate asset information is especially important. An organisation cannot effectively protect equipment if it does not know what is connected, what each device does and how critical it is to the wider process.

6. OT Incident Management

OT incident management addresses preparation, detection, containment, investigation, recovery and lessons learned. Responders must work closely with operational, engineering, safety and business teams.

An action that is routine during an IT incident, such as isolating a system immediately, may create additional risks in an industrial environment. OT incident response therefore requires technical ability, careful coordination and a strong understanding of physical processes.

Is CompTIA SecOT+ the same as Security+?

No. CompTIA Security+ and CompTIA SecOT+ focus on related but different areas.

Security+ validates broad foundational cybersecurity knowledge across threats, architecture, operations, identity, risk and cryptography. SecOT+ applies cybersecurity principles specifically to operational technology and industrial environments, where safety, reliability and physical processes are central concerns.

Security+ may provide useful background knowledge, but it should not be treated as a replacement for dedicated OT security study.

Is SecOT+ vendor-neutral?

CompTIA certifications are designed to validate skills that are not limited to one technology vendor. That approach is particularly useful in OT because industrial environments commonly contain equipment from multiple manufacturers, different generations of technology and a mixture of specialist protocols.

A vendor-neutral certification can help learners build transferable principles before studying product-specific platforms or technologies used by an employer.

How should you prepare for CompTIA SecOT+ SOT-001?

Because the exam is still under development, preparation should begin with the fundamentals rather than unverified exam claims or memorised question dumps.

Review the latest official objectives

Use CompTIA’s exam objectives under development page to check the latest draft. Objectives can change before launch, so revisit the page regularly.

Understand the difference between IT and OT

Build a clear understanding of industrial systems, control processes and the importance of safety and availability. Avoid assuming that every standard IT security response can be transferred directly into an OT environment.

Strengthen your networking and cybersecurity foundations

Review networking, segmentation, identity, access control, vulnerability management, monitoring and incident response. These skills provide a foundation for understanding their specialised use in OT.

Study real operational scenarios

Use scenario-based practice to consider how security decisions affect production, safety and recovery. Ask what could happen physically if a device fails, a network segment is isolated or a control process is interrupted.

Use practice tests carefully

Good practice questions should test your understanding and explain why an answer is correct. They should not claim to reproduce live exam questions. Use mock exams to identify weak areas, then return to the objectives and study those topics in more depth.

Skills Nest is preparing independent learning and exam-preparation resources. Visit the CompTIA SecOT+ SOT-001 page to see when the course, practice questions and mock exams become available.

What jobs could SecOT+ support?

SecOT+ may support professional development towards roles such as:

  • OT cybersecurity analyst
  • ICS security analyst
  • OT security engineer
  • Industrial cybersecurity consultant
  • Critical infrastructure security specialist
  • OT incident responder
  • OT vulnerability management specialist
  • Industrial security architect

A certification alone does not guarantee a job. Employers may also look for relevant technical experience, knowledge of industrial processes, sector-specific standards, networking skills and the ability to work safely with operational teams.

Frequently asked questions about CompTIA SecOT+

What does SecOT+ stand for?

SecOT+ is CompTIA’s certification focused on securing operational technology environments.

What is the CompTIA SecOT+ exam code?

The current exam series code is SOT-001.

Has CompTIA SecOT+ launched?

CompTIA currently presents the SecOT+ objectives as being under development. Check CompTIA’s official website for the final launch details and exam specifications.

How many questions are in the SOT-001 exam?

The final question count should be confirmed from CompTIA when the examination is officially released. Avoid relying on unofficial figures while the objectives remain in draft form.

What is the SecOT+ pass mark?

CompTIA has not yet published final exam specifications on its under-development objectives page. Check the official certification information when it becomes available.

Do I need OT experience before taking SecOT+?

The certification is aimed at people working around OT cybersecurity, industrial systems and critical infrastructure. Previous cybersecurity, networking, engineering or operational experience is likely to make the material easier to understand.

Can beginners study SecOT+?

Beginners can start learning OT security concepts, but SecOT+ is unlikely to be the best first IT qualification. Building a foundation in networking and cybersecurity first may create a clearer route into the subject.

Start preparing for the future of OT cybersecurity

As operational environments become more connected, organisations need professionals who understand both cybersecurity and the practical realities of industrial systems. CompTIA SecOT+ is being developed to validate that combination of knowledge across safety, risk, threat intelligence, architecture, security operations and incident management.

If you work in cybersecurity, engineering, manufacturing or critical infrastructure, SOT-001 could become a valuable next step in your development.

Explore the Skills Nest CompTIA SecOT+ (SOT-001) certification page and return for updates as new training, practice tests and mock exams are published.


Suggested image alt text: CompTIA SecOT+ SOT-001 operational technology cybersecurity certification guide

Suggested blog excerpt: CompTIA SecOT+ (SOT-001) is an upcoming certification focused on operational technology cybersecurity. Discover who it is for, what the draft exam domains cover and how to prepare.

Suggested internal link anchor text:

  • CompTIA SecOT+ SOT-001 certification
  • SecOT+ training and practice tests
  • Prepare for the CompTIA SecOT+ exam

Disclaimer: Skills Nest is an independent training and exam-preparation platform. It is not affiliated with or endorsed by CompTIA. CompTIA, SecOT+ and related marks are trademarks of CompTIA. Exam objectives and specifications may change before launch.