Eight weeks at ten to twelve hours a week is enough to pass CySA+ if you already hold Security+ and you have touched a SIEM, a vulnerability scanner, or a ticket queue. That is the honest entry condition. The exam changed in 2026: CompTIA launched CySA+ v4 under exam code CS0-004 on 23 June 2026, and the v3 exam, CS0-003, retires in English on 22 December 2026. CS0-004 is a maximum of 85 questions in 165 minutes, mixing multiple choice with performance-based questions, and you pass at 750 on a scale of 100 to 900. The plan below is built for CS0-004 and its four domains: Security Operations at 34 percent, Vulnerability Management at 26 percent, Incident Response and Management at 24 percent, and Reporting and Communication at 16 percent.
Decide Which Exam You Are Sitting Before Week 1
If you are reading this in late 2026 you still have a choice, and it is not a close one for anyone starting from scratch. CS0-003 disappears on 22 December 2026, which means a voucher you buy now has to be burned inside a shrinking window and a certification earned on the retiring version still expires in three years anyway. Study CS0-004.
The domain weights shifted enough to matter. CS0-003 weighted Vulnerability Management at 30 percent and Incident Response Management at 20 percent. CS0-004 pulls vulnerability work down to 26 percent and pushes incident response and management up to 24 percent, with Security Operations up a point to 34 percent. If you are reusing older study material, you are over-prepared on scanner mechanics and under-prepared on response and containment decisions.
Budget before you schedule. As of 2026 a single CySA+ voucher runs roughly $439 after CompTIA raised prices in late May, with a retake bundle around $579. Renewal is 60 CEUs over three years, and the continuing education fee is $150 for the three-year cycle if you renew by uploading CEUs rather than by passing a newer exam. Price increases are their own kind of study motivation.
Is CySA+ the Right Second Cert?
CySA+ is a defensive analyst exam, not a governance exam. It pays off if you are heading toward SOC work, vulnerability management, incident response, or a security control assessor role. It is approved under DoDM 8140.03 for a useful spread of work roles, including Cyber Defense Analyst (511), Cyber Defense Incident Responder (531), Vulnerability Assessment Analyst (541), Cyber Defense Forensics Analyst (212), and Security Control Assessor (612). That last one is why the cert shows up on RMF-adjacent job postings.
If your target is an ISSO or ISSM seat, check the DoD 8140 matrix for ISSO work roles first, because the qualifying cert list for those roles is not the same list. And if you are still choosing between this and other second certs, the comparison of Security+ against CySA+ and CCNA lays out which one your first year of experience actually supports.
The 8-Week Schedule
Ten to twelve hours a week, split as roughly six hours of study, three hours of hands-on, and two hours of questions. The structure follows the CS0-004 weights instead of the textbook chapter order, which means you start where the points are.
Weeks 1 and 2: Security Operations
- Week 1: system and network architecture concepts, logging and log ingestion, standardized data formats, and the analyst view of identity and access. Build or open a lab SIEM and push real logs into it. Wazuh or an Elastic stack both work.
- Week 2: threat intelligence and threat hunting, indicators of compromise, the attack frameworks CompTIA expects you to reason with (MITRE ATT&CK, the Diamond Model, the Cyber Kill Chain), and efficiency through automation and scripting. Write one script that parses a log file and flags something. It does not need to be elegant.
Weeks 3 and 4: Vulnerability Management
- Week 3: scanning methods and types, asset discovery, special considerations for cloud, containers, operational technology, and web applications. Run an actual credentialed scan against a lab host and then run an uncredentialed one so you can see the difference in output volume.
- Week 4: analysis and prioritization. CVSS v3.1 and v4 base metrics, CVE and CWE, exploitability context, and the difference between a high CVSS score and a high organizational risk. Practice writing a two-sentence justification for why a 9.8 got deferred and a 6.5 got patched this week.
Weeks 5 and 6: Incident Response and Management
- Week 5: the response lifecycle, preparation and detection, evidence handling, chain of custody, and the forensic mindset. Work through a memory capture and a disk image in a lab even if you never touch forensics at work, because the exam asks about order of volatility.
- Week 6: containment, eradication, recovery, and post-incident activity. Root cause analysis, lessons learned, and the decisions that separate an isolated host from a segmented network. This is the domain that grew in CS0-004, so give it the full allocation.
Weeks 7 and 8: Reporting, Communication, and Exam Conditioning
- Week 7: vulnerability management reporting, stakeholder identification, action plans, compliance reporting, and the metrics analysts are asked to produce. Then take a full-length timed practice exam and score it honestly.
- Week 8: work only your weakest two domains, retake a full-length exam mid-week, and spend the last three days on performance-based questions and rest. Do not learn new material in week 8.
Materials That Earn Their Place
You need three things and nothing else: one primary text or video course aligned to CS0-004, one performance-based question bank, and a lab. CompTIA CertMaster Labs and the official study guide are the safe default. Third-party video courses catch up to a new exam code within a couple of months of launch, so check the publication date against 23 June 2026 before you buy.
- A primary course aligned to CS0-004, worked through once at normal speed and once at higher speed for review.
- A question bank with detailed answer explanations, used for diagnosis rather than memorization. If you cannot explain why the wrong answers are wrong, the question did not teach you anything.
- A lab with a SIEM, a scanner, and at least two hosts to attack and defend. A single machine running virtualization is enough.
- A one-page notes file you write yourself, holding only the facts that refuse to stick. Port numbers, CVSS metric abbreviations, and log field names live here.
How to Handle the Performance-Based Questions
The PBQs are where CySA+ separates from Security+. They ask you to read output and make a call: which host to isolate, which finding to escalate, which log line explains the alert. Reading comprehension under time pressure is the actual skill.
Two habits help. First, do the PBQs last. They are worth more but they are time sinks, and answering 60 multiple-choice questions first banks points you know you have. Second, practice reading unfamiliar tool output without panicking. Open a Nessus export, a Zeek log, and a Windows event log, and make yourself narrate what each field means out loud. The exam will show you a format you have never seen, and the win condition is staying calm enough to parse it.
Why Candidates Fail CySA+
The failure patterns are consistent and they are not knowledge gaps. They are process gaps.
- Treating it like Security+ with harder vocabulary. Security+ rewards recognizing the right term. CySA+ rewards choosing the best action given incomplete evidence, and two of the four options are usually defensible.
- Running out of time on the PBQs. Eighty-five questions in 165 minutes is not generous once a simulation eats fifteen minutes.
- Memorizing CVSS scores instead of understanding the metrics. The exam gives you a vector string and expects you to reason about attack vector, privileges required, and user interaction.
- Never touching a scanner or a SIEM. You can pass with pure book study, but the hands-on domains punish it, and those are 60 percent of the exam.
- Studying v3 material for a v4 exam. Check the exam objectives document against CS0-004 and throw out anything that predates 23 June 2026.
Download the official CS0-004 exam objectives PDF in week 1 and keep it open. Every bullet on that document is fair game, and the objectives are the only authoritative scope statement. Anything a course covers that is not on the objectives is background, and anything on the objectives your course skipped is a hole you have to fill yourself.
The Week Before
Schedule the exam in week 3, not week 7. A booked date changes how you study. Sit your last full practice exam at least four days out so you have time to fix what it finds, and take the day before off entirely. If you have run a Security+ campaign before, the same rhythm applies, and the Security+ eight-week plan has the scheduling detail on booking windows and testing center logistics that is worth copying over.
CySA+ is a good second cert for anyone already inside the tent, and a poor first one. If you are not there yet, the ranking of entry-level certifications by actual job demand is a better starting point than any study plan. For everyone else: eight weeks, twelve hours, book the date, and work the weights.
If passing CySA+ is one step in a bigger move into a cleared analyst or assessor seat, the exam is the easy part and the job search is not. Zero to Hired is the system I built for turning a cert stack into interviews, and it covers the resume and application work that has to happen while you are still studying.


Leave a Reply