Table of Contents
CompTIA is preparing the next version of its most popular cybersecurity certification. The current Security+ SY0-701 (V7) exam is being replaced by Security+ SY0-801 (V8), and the headline change is exactly what you’d expect in 2026: artificial intelligence. CompTIA has published draft objectives for the new exam, so we now have a clear picture of what’s coming, what’s new, and what it means for your study plan.
In this post, I’ll walk you through what’s changing, whether you should take 701 now or wait for 801, what happens if you run out of time, and exactly how to prepare for both the theory and the performance-based questions (PBQs). I’ve also put together a free downloadable comparison spreadsheet (Excel and PDF) so you can see the 701 vs 801 changes side by side. Grab it at the end of the post.
A note on dates: CompTIA’s published objectives for SY0-801 are still a draft, and some details remain marked “to be confirmed.” Always check the official CompTIA Security+ page for the final blueprint and confirmed dates before you book your exam.
Security+ 801: The Headline Facts
- Current exam: Security+ SY0-701 (V7), live since November 7, 2023
- New exam: Security+ SY0-801 (V8) — draft objectives published, launch expected late 2026
- SY0-701 retirement: estimated 2026 by CompTIA, with the usual overlap period after 801 goes live
- The big change: a brand-new focus on AI — Large Language Models and AI-driven threats — plus a heavier weighting on day-to-day security operations
The exam stays vendor-neutral and continues to validate the same core role: someone who can assess security posture, respond to incidents, and secure modern cloud, hybrid, and on-premises environments. If you already hold a Security+, it stays valid for three years from your test date regardless of which version you sat — 701 and 801 carry equal weight on your CV.
SY0-701 vs SY0-801: Domains and Weightings Compared
Both versions keep the same five-domain structure. The names and weightings shift slightly. Here’s the side-by-side, based on CompTIA’s draft V8 objectives:
| SY0-701 (V7, current) | SY0-801 (V8, draft) |
|---|---|
| 1.0 General Security Concepts — 12% | 1.0 General Security Concepts — 16% |
| 2.0 Threats, Vulnerabilities, and Mitigations — 22% | 2.0 Threats, Vulnerabilities, and Attacks — 24% |
| 3.0 Security Architecture — 18% | 3.0 Security Architecture — 19% |
| 4.0 Security Operations — 28% | 4.0 Security Operations — 27% |
| 5.0 Security Program Management and Oversight — 20% | 5.0 Security Program Management and Oversight — 14% |
Two things stand out. General Security Concepts grows (12% to 16%), and Security Program Management shrinks (20% to 14%). Security Operations stays the largest single domain in both versions, so it remains the area where most of your study time should go.
What’s NEW in SY0-801
The headline: dedicated AI content
This is the change everyone is talking about. SY0-801 adds AI as examinable material for the first time in a meaningful way. Based on the draft objectives, the new AI content lands in three places:
- Large Language Models (LLMs) as a vulnerability (2.4) — understanding the security weaknesses introduced when organizations use LLMs, such as prompt injection, data leakage, and over-trusting AI output.
- AI in threats and attacks (2.6) — how attackers use AI to create more convincing phishing, deepfakes, and automated attacks.
- AI in security automation (4.6) — how AI and automation are used defensively in security operations to detect, triage, and respond to threats faster.
The reassuring part: CompTIA isn’t expecting you to be an AI engineer. They want you to understand how AI changes the threat landscape and how it’s used in defense. That’s a manageable amount of new study, and we cover it in our Security+ material.
A heavier focus on doing, not just describing
In line with the wider industry, 801 leans further into practical, operations-focused skills. Expect the wording of objectives to push toward analyzing, responding, and operating rather than simply listing or defining — which is exactly what the performance-based questions test.
What’s CHANGED
Most of 701 carries straight over. The genuinely new study is the AI material above. Beyond that, the changes are refinements rather than a teardown:
- Domain 2 was renamed from “Threats, Vulnerabilities, and Mitigations” to “Threats, Vulnerabilities, and Attacks” — a small shift in emphasis toward how attacks actually unfold.
- General Security Concepts gain weight — controls, security principles, change management, and cryptography remain core and now carry more weight.
- Security Architecture continues its 701 emphasis on cloud, hybrid, and zero-trust environments, with refinements around modern deployment patterns.
- Security Program Management shrinks in weight, though governance, risk, and compliance (GRC) awareness is still tested.
If you’ve already started studying for 701, the vast majority of your effort transfers directly. You are not starting over.
Should You Take SY0-701 Now, or Wait for SY0-801?
This is the question I get most, so here’s my honest take.
If you can be exam-ready before 701 retires, take 701 now. Three reasons:
- The current version is fully supported, with mature study materials, labs, and practice exams.
- A Security+ earned on 701 is identical on your CV to one earned on 801 — employers don’t ask which version you sat — and it’s valid for three years.
- You bank the certification now and get on with your career while others wait for the new blueprint to settle.
If you’re starting from scratch and realistically won’t be ready until well into 2027, plan for 801. By then 701 may be retired, and there’s no sense studying for an exam you can’t sit. The foundations are the same either way, so you won’t waste effort — you’ll simply add the AI topics on top.
The one group who should think carefully: people who are nearly ready. If you’re a few weeks out, push hard and pass 701 before the window closes. Being caught mid-study by a version change is the one scenario worth avoiding.
What If You Fail or Miss the 701 Window?
Don’t panic — the consequences are smaller than people fear.
- If you fail 701 while it’s still available, you simply rebook and retake 701. Nothing changes.
- If 701 retires before you pass, you move to 801 — but your study is not wasted. Because roughly 80–90% of the content overlaps, switching means adding the new AI material and adjusting to the new weightings, rather than relearning the certification from scratch.
- Realistic extra effort to switch from 701 to 801: the three AI topic areas (LLM vulnerabilities, AI in attacks, AI in automation) plus a quick re-read of the heavier-weighted domains. For most students, those are days of study, not months.
So the downside of missing the window is modest. That’s reassuring, but it’s still better to bank 701 if you can.
How to Prepare: Theory
Security+ is broad, so structure beats cramming. A practical approach:
- Study by domain, weighted by the exam. Security Operations is the biggest domain in both versions — give it the most time. Then Threats/Vulnerabilities, then Architecture.
- Map every study session to an objective. Work through the official objectives list and tick topics off. This stops you from over-studying familiar areas and missing weak ones.
- Use active recall, not re-reading. After each topic, close the book and explain it aloud or write it from memory. If you can’t, you don’t know it yet.
- Drill practice questions mapped to the objectives. Questions reveal gaps far faster than reading does. Review every wrong answer until you understand why it was wrong.
- Add the AI material early. It’s new and unfamiliar, so don’t leave it to the end. Understand LLM risks, AI-assisted attacks, and AI in defensive automation as their own study block.
How to Prepare: Performance-Based Questions (PBQs)
PBQs are where many candidates lose marks, because you can’t bluff them — you have to do the task. They often appear early in the exam and carry significant weight, so prepare for them deliberately:
- Build a small hands-on lab. A firewall, an IDS/IPS, a VPN, and a SIEM collecting logs from endpoints and network devices are enough to practice the scenarios PBQs are built from.
- Practice reading logs and configs. Many PBQs show you output and ask you to identify the attack, the misconfiguration, or the correct mitigation. The skill is interpretation under time pressure.
- Match attacks to mitigations. Drill the link between a given threat and the control that stops it — this is a recurring PBQ pattern.
- Configure controls, don’t just describe them. Set up firewall rules, ACLs, and access policies yourself so the steps are second nature.
- Practice under time. PBQs are time-hungry. Some candidates flag and skip them, then return at the end. Decide your strategy before exam day.
This is exactly why hands-on practice matters more than passive watching — and where our labs and live equipment come in.
Recommended Books for Security+
I’ve written hands-on and study books covering the CompTIA certifications, all available on Amazon:
- 101 Labs – CompTIA Security+ — Over 100 hands-on labs mapped to the Security+ objectives, with full step-by-step instructions and screenshots [COMING SOON]
- CompTIA Security+ Course — theory and lab course on howtonetwork
Recommended Study Resources at 101Labs and HowToNetwork
To pass Security+ — current or new version — you need three things: theory, hands-on practice, and exam practice. Here’s where to get all three:
- HowToNetwork — Security+ Study Guides — Theory lessons and explanations for every Security+ domain
- 101Labs — Hands-On Security+ Labs — Step-by-step labs you can follow along with, covering the practical skills the PBQs test
- 101Labs — Practice Exams and PBQs — Realistic exam-style questions and performance-based questions that mirror test day
Download the Free SY0-701 vs SY0-801 Comparison Chart
I’ve put together a clear side-by-side comparison of the Security+ domains and objectives — what’s new, what’s changed, and what’s been removed — built directly from CompTIA’s official objectives documents, with the AI topics flagged.
It’s free to download as a PDF. No email required, no signup, just click and download.
📥 Download the SY0-701 vs SY0-801 comparison chart (PDF)
Ready to Pass Security+?
Security+ remains one of the most recognized and respected entry points into a cybersecurity career, and the 801 update — with its focus on AI and practical operations — only makes it more relevant to employers’ needs. Whether you’re sitting the current 701 or the new 801, the path is the same: solid theory, real hands-on practice, and plenty of exam-style questions.
If you’re serious about passing, 101Labs has the hands-on labs and practice exams to get you there.