Castmark PressIndependent study guides
Guides · August 2026

Security+ or SecOT+: which CompTIA security certification fits you?

Security+ is the general baseline: it is the certification job descriptions and qualification lists name, and it assumes an IT environment. SecOT+ is CompTIA's first certification written entirely for operational technology — plants, utilities, ICS and SCADA — where safety and integrity outrank confidentiality. Take Security+ first unless you already work in OT.

These two certifications get compared as though they were rungs on the same ladder. They are not. They are two different rooms, and which one you should be standing in depends on what is on the other side of the wall from your desk — a data centre, or a plant floor.

The confusion is worth clearing up before you spend money, because the wrong choice here is not a small detour. Security+ is a broad baseline recognised almost everywhere. SecOT+ is deep in a domain where most of Security+'s reflexes are actively wrong.

This guide sets out what each one is for, the single technical difference that explains most of the rest, and a decision rule that takes about thirty seconds.

What each one is actually for

Security+ is the general security baseline. It covers threats, architecture, operations and governance across the environments most organisations run, and its value is partly that everybody has heard of it: it is the certification named in job descriptions, in internal promotion criteria, and in qualification frameworks. Its exam is versioned as SY0-701 today, with V8 — SY0-801 — in draft.

SecOT+ is CompTIA's first certification written entirely for operational technology: the control systems that run plants, utilities, water treatment, manufacturing lines and building systems. Its exam code is SOT-001, and it is new, which cuts both ways — it is uncontested territory, and it has less hiring recognition than a certification that has existed for two decades.

The overlap between them is smaller than the shared word "security" suggests. What Security+ teaches about patching, network segmentation, incident response and availability has to be substantially rethought before it can be applied to a system that cannot be taken offline and may not have been patched since it was commissioned.

The one difference that explains the rest

In IT security, the ordering runs confidentiality, integrity, availability. In operational technology it does not. NIST's guidance on OT security states that OT security objectives typically prioritise integrity and availability, followed by confidentiality — while treating safety as an overarching priority above all three.

Note the specific ordering, because it is a favourite of exam writers and it is frequently misquoted. Integrity comes before availability. And safety is not a fourth item on the list; it sits over the whole list, because in OT a security failure can injure someone rather than leak something.

That single reordering cascades through everything. Patching becomes a scheduled-outage negotiation rather than a Tuesday. Isolating an infected host may be the most dangerous available action. A control system that fails safe and a server that fails closed are not the same instinct.

The vocabulary is hierarchical too, and it is worth getting right: OT is the umbrella term, ICS sits under it, and SCADA, DCS and PLC sit under that. OT is not a synonym for ICS.

Choosing between them

The decision rule is short enough to apply now. If your work touches a plant floor, a substation, a treatment works, a production line or a building management system, SecOT+ addresses the environment you are actually in. If your work is servers, endpoints, cloud, identity and networks, Security+ is your certification.

If you are entering the field with no employer yet, take Security+ first. Recognition matters more than specificity when nobody knows you, and the general baseline opens more doors — including doors into OT roles, many of which list Security+ and none of which will penalise you for holding it.

If you already work in OT and hold nothing, the sequence is a genuine question. Security+ first gives you the vocabulary the wider security profession uses and the certification your HR system recognises. SecOT+ first gives you the material that matches your actual job. Most people are better served taking Security+ first and SecOT+ second — but if your employer is asking for OT-specific evidence now, that inverts.

What you should not do is treat SecOT+ as an advanced Security+. It is not a level above; it is a different subject with its own priorities, and it can be taken by someone who has never held Security+ at all.

The timing problem, for both

Both certifications are in motion right now, which complicates buying study material more than it complicates the decision.

Security+ has SY0-701 live and V8 in draft on CompTIA's exams-under-development page, with no launch date published. Buy for the code on your booking.

SecOT+ is new enough that the material market barely exists. That is an opportunity if you are early and a risk if you buy carelessly — verify that anything you buy is written against the SOT-001 objectives rather than adapted from IT security material with the word "industrial" inserted. The tell is the same as always: does it get the OT priority ordering right, and does it treat OT as the umbrella rather than as a synonym for ICS?

For either exam, CompTIA's current published objectives win over anything printed in any book, including ours.

The book for this exam

Cover of CompTIA Security+ Study Guide 2027 CompTIA Security+ Study Guide 2027 Written line by line against the CompTIA Security+ V8 objectives for exam SY0-801, while most guides on the shelf are still SY0-701 books. Everything is… See the book →

More on this exam

Common questions

Is SecOT+ harder than Security+?

It is not a level above — it is a different subject. It is harder for someone with no exposure to control systems and more intuitive for someone who works with them daily. Difficulty here tracks your background rather than the certification's rank.

Do I need Security+ before SecOT+?

No. SecOT+ has no prerequisite requiring it. But if you are new to security and have no employer yet, Security+ first is usually the better sequence, because it is the certification hiring systems already recognise.

Does Security+ cover OT at all?

It touches it. Security+ includes industrial and embedded systems among the environments it surveys, but it surveys them from an IT starting point. It does not rebuild the priorities around safety and integrity the way an OT-specific certification has to.

Which is better for getting hired?

Security+, for most people, most of the time — it appears in far more job descriptions and qualification frameworks. SecOT+ is better for a specific and growing set of roles where general security certifications do not demonstrate what the employer needs.

Is the OT security triad reversed compared to IT?

Not exactly reversed, and the detail matters. NIST's OT guidance puts integrity and availability ahead of confidentiality — integrity first — with safety as an overarching priority above the triad rather than inside it.

Sources

  1. NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security — the statement that OT security objectives typically prioritise integrity and availability, followed by confidentiality, with safety as an overarching priority
  2. CompTIA, "Security+ (Plus) Certification" — the current SY0-701 exam details — https://www.comptia.org/en-us/certifications/security/
  3. CompTIA, "CompTIA Exam Objectives Under Development" — carries both the draft Security+ V8 and the draft SecOT+ V1 objectives, consulted August 2026 — https://www.comptia.org/en-us/resources/comptia-exam-objectives-under-development/
  4. DRAFT CompTIA SecOT+ V1 Exam Objectives, exam number SOT-001 — the objective structure for the OT certification

Rules change. Where a figure or a procedure can move, the issuing agency’s current published instructions win over anything here.