CY0-001 is CompTIA’s SecAI+ certification exam, launched in 2026 to validate cybersecurity professionals who secure AI systems, use AI to improve defensive operations, and govern AI responsibly. CompTIA’s current objectives document is version 1.1 and organizes the exam around four weighted domains: Basic AI Concepts Related to Cybersecurity at 17%, Securing AI Systems at 40%, AI-assisted Security at 24%, and AI Governance, Risk, and Compliance at 19%.
The current CY0-001 objective document says the successful candidate should understand important AI concepts, secure AI systems with technical controls, use AI to strengthen security posture and automate security tasks, and understand how GRC affects AI globally. CompTIA positions the experience level at roughly 3–4 years in IT with about 2 years of hands-on cybersecurity.
Basic AI concepts are framed through cybersecurity use
The 17% foundation domain includes generative AI, machine learning, statistical learning, transformers, deep learning, NLP, large and small language models, GANs, supervised/unsupervised/reinforcement learning, fine-tuning, pruning, quantization, and prompt engineering.
The goal is not to become an AI researcher. Candidates need enough technical literacy to understand where security controls and attacks apply.
Data security is part of AI fundamentals
CompTIA explicitly includes cleansing, verification, lineage, integrity, provenance, augmentation, balancing, structured/semi-structured/unstructured data, watermarking, RAG, vector storage, and embeddings.
This is important because AI security begins with the data pipeline, not only the model endpoint.
Security applies throughout the AI lifecycle
The foundation domain also includes business use case, data collection, preparation, model development/selection, evaluation, deployment, validation, monitoring/maintenance, feedback, and human-centric design.
Human-in-the-loop, human oversight, and human validation are part of the blueprint because some security or risk decisions should not be delegated blindly to automated systems.
Securing AI Systems is the largest domain at 40%
This domain begins with threat-modeling resources such as the OWASP LLM Top 10, OWASP ML Security Top 10, MIT AI Risk Repository, MITRE ATLAS, CVE AI Working Group resources, and general threat-modeling frameworks.
Security professionals should know how to use structured threat knowledge to identify likely attack paths and choose controls.
Guardrails and gateway controls protect model interaction
The objectives include model evaluation, prompt templates, prompt firewalls, rate limits, token limits, input quotas, modality limits, endpoint access controls, and guardrail testing.
These controls sit between users or applications and AI systems and can limit unsafe input, excessive resource use, or uncontrolled model behavior.
Access control and data protection are separate requirements
Model access, data access, agent access, API/network access, encryption in transit/at rest/in use, anonymization, classification, redaction, masking, and minimization all appear explicitly.
A cybersecurity foundation helps here: identity, authorization, encryption, and data handling remain familiar security concepts even when the workload is AI.
Monitoring covers quality, abuse, cost, and compliance
Prompt/query and response monitoring, log protection and sanitization, confidence levels, rate monitoring, AI cost monitoring, hallucinations, accuracy, bias/fairness, and access auditing are all testable.
AI operations creates telemetry that traditional security teams may not have monitored before, including tokens, prompts, and quality signals.
Attack analysis includes AI-specific and familiar security failures
The 40% domain lists prompt injection, poisoning, jailbreaking, hallucinations, input manipulation, guardrail bypass, model inversion, theft, supply-chain attacks, membership inference, insecure output handling, model DoS, sensitive-information disclosure, insecure plug-ins, excessive agency, and overreliance.
Compensating controls include firewalls, guardrails, access control, data integrity, encryption, templates, rate limiting, and least privilege.
AI-assisted Security covers both defense and attacker enablement
The 24% domain includes AI tools for vulnerability analysis, anomaly detection, pattern recognition, incident management, threat modeling, fraud detection, summarization, code quality, and automated penetration testing. It also covers deepfakes, reconnaissance, social engineering, obfuscation, automated attack generation, payloads, malware, and DDoS.
The security-analytics mindset is useful because AI can accelerate defensive analysis while also accelerating adversary workflows.
Governance, risk, and compliance completes the blueprint
The 19% domain includes AI Centers of Excellence, AI roles, responsible-AI principles, bias, data leakage, reputational loss, model accuracy, IP risk, autonomous systems, the EU AI Act, OECD standards, ISO AI standards, NIST AI RMF, corporate AI policies, sensitive-data governance, and third-party evaluations.
The current CompTIA objectives document also makes clear that the examples are not exhaustive. AI security changes rapidly, so candidates should understand the control principles behind the listed technologies rather than treat the bullet list as a fixed catalog. A new model gateway or agent framework can still be analyzed through access control, data integrity, monitoring, threat modeling, and governance.
Prompt engineering is included in the foundation domain because prompts can act as both application logic and attack input. System prompts, user prompts, zero-shot, one-shot, multi-shot, roles, and templates shape model behavior. Security teams need enough prompt literacy to understand where injection, policy bypass, or unsafe instructions enter the system.
RAG belongs in the data-security foundation because retrieval introduces new data stores and trust boundaries. Embeddings, vector databases, source documents, and retrieval results can expose sensitive information or be poisoned. A secured model can still produce harmful results if the retrieval layer returns manipulated context.
Model guardrails and prompt firewalls should be understood as layered controls, not perfect guarantees. Guardrails can restrict content or actions; gateway controls can limit requests and enforce quotas; authorization can restrict users and tools. Attackers may try to bypass one layer, so defense should not depend on a single filter.
Agent access appears explicitly because agents can act on external systems. Excessive agency becomes dangerous when a model can call tools, send messages, change records, or execute workflows beyond the user’s legitimate intent. Least privilege, approval boundaries, logging, and safe defaults become especially important when AI moves from generating text to taking actions.
Model inversion, membership inference, and model theft are reminders that confidentiality applies to learned behavior as well as source data. Attackers may try to recover sensitive training information, determine whether a record was present, or extract useful model behavior. Data minimization and access control remain relevant even after training.
AI-assisted security also requires analyst skepticism. Summarization, anomaly detection, vulnerability analysis, and code assistance can accelerate work, but hallucination and automation bias can make incorrect output persuasive. Human validation is not a contradiction to AI-assisted defense; it is part of secure use.
The governance role list is unusually explicit. CompTIA expects candidates to distinguish responsibilities of data scientists, AI architects, MLOps engineers, security architects, governance engineers, risk analysts, auditors, and data engineers. The point is accountability: someone should own model development, platform control, risk, and independent review.
The objective document’s hardware/software list includes sandboxes, cloud VMs, GPUs, Python/R environments, IDEs, Jupyter, chatbots, LLMs, GitHub, local model tools, vector databases, NoSQL, and graph databases. These are preparation examples, not a mandatory vendor stack. A defensive lab can use whichever safe tooling demonstrates the objective.
CompTIA announced SecAI+ as its first Expansion Series certification and positioned it as complementary to existing cybersecurity foundations such as Security+, CySA+, and PenTest+. That explains the recommended experience level: CY0-001 assumes candidates already understand ordinary cybersecurity controls and are now extending those skills into AI systems.
SecAI+ also distinguishes security controls around AI from the use of AI as a security tool. That distinction matters because an analyst can be excellent at using an AI assistant for summarization yet still fail to secure the model, data, agent permissions, or third-party integrations behind it. The blueprint treats those as separate competencies.
Human-centric design is part of the foundation because security controls affect people. Users need understandable warnings, appropriate escalation, and ways to challenge or correct automated output. Human oversight is especially important when AI influences high-impact security or governance decisions.
Third-party compliance evaluation is another practical scope item. Organizations rarely build every model, dataset, plug-in, or cloud service themselves. Security professionals need to evaluate vendors, contracts, security posture, model/data handling, updates, and evidence of compliance rather than assuming outsourced technology transfers the risk.
CompTIA’s current objective document carries ANSI/ISO 17024 accreditation language and notes regular reviews and updates. That reinforces a useful study habit: learn the objectives as security capabilities, not only named products. AI platforms change rapidly, but least privilege, integrity, monitoring, threat modeling, and accountable governance remain durable.
The 40% weighting of Securing AI Systems is the strongest preparation signal in the blueprint. Candidates should spend substantial scenario time on how controls interact around models, data, agents, APIs, logs, and third parties. AI vocabulary matters, but secure implementation and attack analysis are the center of gravity.
The 24% AI-assisted Security domain also prevents SecAI+ from being only a defensive-hardening certification. Security professionals are expected to use AI to improve analysis and automation while recognizing how adversaries use the same technology. Safe adoption and secure protection are two sides of the role.
For final scope review, build one list of technologies and one list of security outcomes. Technologies will change quickly; outcomes such as confidentiality, integrity, least privilege, safe automation, accountability, auditability, and resilience remain stable. Use the outcomes to reason about unfamiliar tools on exam day.
The current blueprint also reflects a zero-trust style of thinking around AI: verify identities, minimize data, restrict endpoints and agents, monitor behavior, and assume outputs can be wrong or manipulated. Traditional security principles remain useful, but AI introduces new objects—prompts, embeddings, models, and agent tools—that must be included in the trust model.
That is the core scope.
Within the broader CompTIA certification portfolio, SecAI+ is the bridge between cybersecurity practice and AI security. It expects candidates to secure the technology, use the technology, and govern the technology at the same time.