Build skills. Pass exams. Advance your career.

Exam guideSY0-801

CompTIA Security+ SY0-701 vs SY0-801: What’s Changing?

By SkillsNest · 29 September 2026

CompTIA Security+ SY0-701 vs SY0-801 V8 comparison

Compare CompTIA Security+ SY0-701 with the upcoming SY0-801 (V8). Explore the key changes, draft domain weightings, new AI security topics, and what the update means for Security+ learners.

CompTIA Security+ SY0-701 vs SY0-801: What’s Changing in Security+ V8?

CompTIA Security+ is preparing for its next major update.

The current Security+ exam, SY0-701, covers the core cybersecurity knowledge and practical skills expected from professionals beginning or developing a career in security.

Its successor, CompTIA Security+ SY0-801, also referred to as Security+ V8, is on the horizon.

But how different is SY0-801 from SY0-701? What is changing in the Security+ syllabus? And if you're already studying for SY0-701, should you continue or wait for the new exam?

In this guide, we'll compare the two versions and look at the most important changes currently associated with Security+ SY0-801 / V8.

Important: SY0-801 is an upcoming version of Security+. Details discussed in this article may change as CompTIA finalises the new exam. Always check the latest official CompTIA exam objectives before preparing for an exam.


SY0-701 vs SY0-801 at a glance

The move from SY0-701 to SY0-801 is not simply a change of exam code. Security+ is being updated to reflect changes in cybersecurity, including evolving threats, artificial intelligence and modern security operations.

AreaSecurity+ SY0-701Security+ SY0-801 / V8 Draft
StatusCurrent Security+ examUpcoming Security+ version
Number of domains55
General Security Concepts12%16%
Threats domain22%24%
Security Architecture18%19%
Security Operations28%27%
Security Program Management & Oversight20%14%
AI securityLimited compared with V8More explicit coverage
Domain 2Threats, Vulnerabilities, and MitigationsThreats, Vulnerabilities, and Attacks
Overall focusModern cybersecurity fundamentalsUpdated threats, AI and modern security operations

The overall structure remains familiar, but the emphasis within Security+ is changing.


1. The five-domain structure remains

One of the first things existing Security+ learners will notice is that SY0-801 does not appear to completely restructure the certification.

SY0-701 currently consists of five domains:

  1. General Security Concepts
  2. Threats, Vulnerabilities, and Mitigations
  3. Security Architecture
  4. Security Operations
  5. Security Program Management and Oversight

The SY0-801 draft structure also contains five domains.

One noticeable change is Domain 2, which changes from:

Threats, Vulnerabilities, and Mitigations

to:

Threats, Vulnerabilities, and Attacks

The overall structure should therefore look familiar to someone who has already studied SY0-701, although the content and emphasis within the domains are evolving.


2. General Security Concepts receives more emphasis

In SY0-701, General Security Concepts accounts for 12% of the exam.

In the current SY0-801 draft, this increases to 16%.

That's a four-percentage-point increase and one of the more noticeable weighting changes.

Security+ has always required candidates to understand the principles behind cybersecurity rather than simply memorising individual attacks or products.

These foundations include areas such as:

  • security controls
  • authentication and authorisation
  • cryptography
  • Zero Trust
  • fundamental security principles
  • secure design concepts

The increased weighting suggests that strong cybersecurity fundamentals will continue to be extremely important for Security+ candidates.


3. Threats and vulnerabilities receive greater weighting

SY0-701 allocates 22% of the exam to Threats, Vulnerabilities, and Mitigations.

The corresponding SY0-801 draft domain increases to 24% and becomes Threats, Vulnerabilities, and Attacks.

Modern attack surfaces continue to expand.

Organisations now rely heavily on:

  • cloud services
  • APIs
  • remote infrastructure
  • automation
  • mobile devices
  • interconnected applications
  • artificial intelligence systems

As these technologies evolve, attackers develop new ways to target them.

Security+ V8 therefore needs to reflect a cybersecurity environment that continues to change.


4. Artificial intelligence becomes much more visible

Perhaps one of the most interesting developments in Security+ V8 is the increased attention given to artificial intelligence and AI-related security.

Cybersecurity professionals increasingly need to understand AI from two directions:

  1. How attackers can target or misuse AI systems
  2. How defenders can use AI to improve security operations

The developing SY0-801 material introduces more explicit AI-related concepts, including areas such as:

  • prompt injection
  • model manipulation and poisoning
  • AI-related data loss
  • hallucinations
  • jailbreaking
  • privacy considerations
  • deepfakes
  • AI-assisted security capabilities
  • agentic systems
  • predictive analysis
  • AI-augmented security baselines

This does not mean Security+ is becoming an AI specialist certification.

Instead, it reflects the reality that cybersecurity professionals are increasingly encountering AI systems as part of the environments they protect.

AI is becoming part of mainstream cybersecurity, so it makes sense for Security+ to evolve alongside it.


5. Security Architecture increases slightly

Security Architecture represents 18% of SY0-701.

The current SY0-801 draft increases this slightly to 19%.

This is only a small weighting change, but Security Architecture remains an important part of the certification.

Security professionals need to understand not only how attacks happen but also how systems can be designed to reduce risk.

This can include areas such as:

  • secure infrastructure
  • resilience
  • cloud environments
  • network architecture
  • data protection
  • segmentation
  • secure design principles

The one-percentage-point increase suggests evolution rather than a major restructuring of this part of Security+.


6. Security Operations remains the largest domain

Security Operations is currently the largest SY0-701 domain at 28%.

In the current SY0-801 draft, this falls very slightly to 27%, but it remains the largest individual domain.

That is important because it shows that practical security operations continue to sit at the centre of Security+.

Security professionals need to understand areas such as:

  • security monitoring
  • identity and access management
  • vulnerability management
  • incident response
  • security tooling
  • operational security processes
  • alerting and analysis

Security operations are also becoming increasingly influenced by automation and AI-assisted capabilities.

For learners, the key message is simple:

Hands-on security operations remain central to Security+.


7. Security Program Management and Oversight decreases

The largest weighting change appears in Security Program Management and Oversight.

In SY0-701, it accounts for:

20%

In the current SY0-801 draft, it falls to:

14%

That's a six-percentage-point reduction.

Governance, risk, compliance, policies and security programme management still remain important cybersecurity topics.

However, the draft weighting indicates that the balance of Security+ is shifting somewhat towards security fundamentals, threats, architecture and technical security areas.

A lower weighting does not mean candidates can ignore this domain.

At 14%, it would still represent a meaningful part of the exam.


8. Newer attack techniques and terminology appear

Cybersecurity changes quickly, so certification objectives need to evolve with it.

Security+ V8 introduces or gives greater visibility to a number of contemporary security concepts.

Examples appearing in developing V8 material include areas such as:

  • passkeys
  • QR-code phishing or "quishing"
  • fileless malware
  • living-off-the-land techniques
  • secrets scanning
  • cloud security posture management
  • alert tuning
  • break-glass access
  • behavioural risk
  • modern email security
  • AI-related attacks
  • AI-assisted defensive capabilities

Not every existing concept disappears simply because new terminology is introduced.

Instead, SY0-801 appears to modernise Security+ around the technologies and threats cybersecurity professionals increasingly encounter.


SY0-701 vs SY0-801 domain weighting comparison

Here's the clearest way to see the proposed shift:

Security+ DomainSY0-701SY0-801 DraftChange
General Security Concepts12%16%+4%
Threats / Vulnerabilities22%24%+2%
Security Architecture18%19%+1%
Security Operations28%27%-1%
Security Program Management & Oversight20%14%-6%
Total100%100%

The overall direction is fairly clear.

Security+ V8 currently appears to give more weight to security fundamentals and threats, while Security Operations remains the largest domain.

At the same time, Security Program Management and Oversight receives a smaller proportion of the overall weighting.


Is SY0-801 harder than SY0-701?

It's too early to say that SY0-801 is objectively harder than SY0-701.

A newer syllabus does not automatically mean a more difficult exam.

What does appear clear is that candidates preparing for SY0-801 will need familiarity with security concepts that have become increasingly relevant since SY0-701 was developed.

AI security is an obvious example.

Someone with strong SY0-701 knowledge should recognise a considerable amount of the foundational material.

However, once SY0-801 becomes available, candidates intending to take that exam should prepare against the final SY0-801 objectives, rather than relying entirely on SY0-701 material.


Should I stop studying for SY0-701?

No.

If you're currently preparing for Security+, don't abandon your SY0-701 studies simply because the next version is being developed.

You can explore the current CompTIA Security+ SY0-701 certification resources on SkillsNest.

Core cybersecurity knowledge does not suddenly become obsolete when an exam version changes.

Topics such as:

  • network security
  • authentication
  • cryptography
  • vulnerabilities
  • incident response
  • access control
  • security architecture
  • risk
  • security operations

remain valuable regardless of the exam version.

What changes is the precise exam blueprint against which that knowledge is assessed.


Can I use SY0-701 material to prepare for SY0-801?

SY0-701 material can provide a useful foundation because successive versions of Security+ naturally contain conceptual overlap.

However, once you decide to take SY0-801, you should use learning material specifically aligned with the final SY0-801 objectives.

This becomes particularly important for new or expanded areas such as AI security and other terminology introduced in Security+ V8.

A sensible approach is:

Studying for the current Security+ exam?

Continue using SY0-701 learning material appropriate to that exam.

Planning to take Security+ V8?

Use dedicated SY0-801 training once the final objectives and suitable learning resources are available.

SkillsNest has already created a dedicated CompTIA Security+ SY0-801 (V8) certification page, where new resources will appear as they are published.


What happens to SY0-701 when SY0-801 launches?

When certification versions change, learners need to pay close attention to the exam code associated with their training and exam booking.

For SkillsNest learners, we're keeping the two Security+ versions separate.

Our existing CompTIA Security+ SY0-701 resources remain on their dedicated certification page.

We've also created a separate CompTIA Security+ SY0-801 (V8) page in preparation for the upcoming version.

This makes it easier to identify which exam version your training, practice questions and mock exams are designed for.

We won't silently mix SY0-701 and SY0-801 preparation material together.


How SkillsNest is preparing for Security+ SY0-801

SkillsNest is preparing dedicated learning and exam-preparation resources for CompTIA Security+ SY0-801.

Planned resources include:

  • Security+ SY0-801 training
  • topic-based practice questions
  • detailed answer explanations
  • mock exams
  • exam-preparation resources

These resources are coming soon.

You can bookmark our CompTIA Security+ SY0-801 (V8) page now.

As the new exam is finalised, SkillsNest will update its SY0-801 material against confirmed objectives rather than treating draft information as final.


SY0-701 vs SY0-801: the key takeaway

Security+ SY0-801 appears to be an evolution rather than a complete reinvention of CompTIA Security+.

The five-domain structure remains recognisable, but the weighting changes.

General Security Concepts and threats receive more emphasis.

Security Operations remains the largest domain.

Security Program Management and Oversight receives less weighting.

And perhaps most noticeably, AI security becomes a much more explicit part of the Security+ syllabus.

For existing learners, there is no reason to panic or automatically abandon SY0-701 preparation.

For future learners, SY0-801 is designed to bring Security+ closer to the cybersecurity environment organisations are dealing with today.

The most important rule is simple:

Study for the exam code you intend to take.

SkillsNest will continue supporting SY0-701 while preparing dedicated Security+ SY0-801 training, practice questions and mock exams.


Prepare for CompTIA Security+

Studying for SY0-701?

Explore the current CompTIA Security+ SY0-701 certification resources on SkillsNest.

Looking ahead to Security+ V8?

Visit our CompTIA Security+ SY0-801 (V8) certification page.

SY0-801 training, practice questions and mock exams are coming soon.


SkillsNest is an independent training and exam-preparation platform. SkillsNest is not affiliated with or endorsed by CompTIA. CompTIA, Security+ and related marks are trademarks of CompTIA. Information in this article relating to draft SY0-801 domains, weightings or objectives may change before the final exam is released.

Related articles