SY0-701 is the Security+ exam CompTIA is currently delivering: a maximum of 90 questions, 90 minutes, passing score 750 on a 100-900 scale. SY0-801 exists only as draft V8 objectives, with no launch date published as of August 2026. Buy for the code printed on your booking.
There are two Security+ exam codes in circulation, and buying a book written for the wrong one costs weeks. SY0-701 is the exam you can schedule and sit today. SY0-801 — Security+ V8 — exists as draft objectives that CompTIA has published for public review on its exam-development page.
The confusion is understandable, because CompTIA's own public pages do not treat the two the same way. The certification page describes the live exam. The exams-under-development page carries a draft objectives download and no dates at all. The exam number SY0-801 is printed inside that draft document, not on the marketing pages.
This guide sets out what the V8 draft actually changes, what is genuinely new in it, what CompTIA has not published — and how to decide which code you are preparing for.
SY0-701 is Security+ V7 and it is the exam being delivered. CompTIA's certification page gives its shape: a maximum of 90 questions, a mix of multiple-choice and performance-based items, 90 minutes, and a passing score of 750 on a scale of 100 to 900. It launched in November 2023, and CompTIA's own page notes that its exams usually retire around three years after launch.
SY0-801 appears only on CompTIA's "Exam Objectives Under Development" page, as a draft objectives download that has been revised more than once. The document itself carries the exam number — SY0-801 V8 — even though that code does not yet appear on the public certification pages.
CompTIA has announced neither a launch date for V8 nor a retirement date for SY0-701. Discussion among instructors in CompTIA's own instructor community points at a launch around November 2026 and a retirement of SY0-701 in 2027, but the people saying so state plainly that there is no firm date. Treat those as weather, not as a schedule: confirm on CompTIA's pages before you book anything.
The five domains keep their shape, and four of them keep their names: General Security Concepts, Security Architecture, Security Operations, and Security Program Management and Oversight. One is renamed — Domain 2 moves from "Threats, Vulnerabilities, and Mitigations" in V7 to "Threats, Vulnerabilities, and Attacks" in the V8 draft.
The weights move. The draft distributes the exam as 16 percent General Security Concepts, 24 percent Threats, Vulnerabilities and Attacks, 19 percent Security Architecture, 27 percent Security Operations, and 14 percent Security Program Management and Oversight. Security Operations remains the heaviest domain; Threats gains ground.
The objective count falls from 28 to 27, redistributed three, six, four, eight and six across the five domains, and those 27 objectives break down into 849 individual sub-points. That number is why a book written against V7 and lightly edited does not cover this exam: the sub-points are where the testable detail lives.
What did not move is worth saying too, because a lot of secondhand commentary gets it wrong. Threat actors are still in 2.1. Architecture still opens at 3.1. No large topic jumped domains between the two versions.
The clearest way to tell a native SY0-801 book from a reissued SY0-701 one is vocabulary. Terms that appear in the draft objectives and simply do not exist in 2023-era material include passkeys and passwordless authentication, quishing, RCS as a message vector, BIMI alongside DMARC, SPF and DKIM, living-off-the-land tooling, canary accounts, secrets scanning, alert tuning, break-glass emergency access, just-in-time privilege elevation, and backup immutability.
Artificial intelligence stops being a mention and becomes scope. The draft puts large language model risk and AI usage into the threat objectives, and puts agentic AI, chatbots, predictive analytics and AI-augmented baselines into security operations. A guide that name-drops AI in a sidebar has not covered this.
Incident response gains a step with no equivalent in the NIST sequence most candidates learned: negotiation with ransomware operators, alongside notification of stakeholders, customers and law enforcement. If you have been studying the four-phase NIST cycle, the exam's own sequence is the one being tested.
And Domain 5 asks for arithmetic rather than definitions. Single loss expectancy, annualized rate of occurrence and annualized loss expectancy are listed explicitly under business-level considerations: SLE is asset value multiplied by exposure factor, and ALE is SLE multiplied by ARO. Expect to compute, not to recognize.
The draft objectives mark the number of questions and the exam duration as to be determined. Any book, course or blog that prints "90 questions in 90 minutes" for SY0-801 is copying the V7 figures and hoping they carry over. They may well. They are not published, and we do not print them.
The passing score is published, and it does carry: 750 on a scale of 100 to 900. Question types are published too — multiple-choice and performance-based.
Draft objectives are drafts. CompTIA revises them, and the version number shown on the download page has not always matched the version declared inside the file. Before you schedule, download the current objectives from CompTIA and check them against whatever you are studying from. The day Security+ V8 disappears from the exams-under-development page is the day the final version exists.
The decision is your test date, not your preference. If you are sitting in the next few months, you are sitting SY0-701, and a V7 book is the right purchase — buying ahead helps nobody.
If your exam falls after the switch, or you are starting a long study run now and will certify on the new code, the V8 material is what you want. Our Security+ guide is written line by line against the V8 draft objectives, and it says "Draft-Aligned Edition" on the cover for exactly that reason: you should know what it was built from before you buy, and you should verify the current official objectives with CompTIA before you schedule.
One thing that does not depend on the code: everything in our guide is printed in the book. There is no online test bank, no access code to redeem, and nothing behind a URL that can expire before your exam date.
No. As of this guide's date the exam being delivered is SY0-701; SY0-801 exists as draft objectives on CompTIA's exams-under-development page. CompTIA's scheduling pages are the only place to confirm what is bookable on any given day.
CompTIA has not announced a date. Instructors in CompTIA's own community have discussed 2027, while stating there is no firm date. Plan around your own exam booking, not around a rumoured retirement.
The draft objectives mark both as to be determined. We will not print a number CompTIA has not published. What is published is the passing score — 750 on a 100 to 900 scale — and the question types, multiple-choice and performance-based.
Structurally, moderately: one domain renamed, the weights redistributed, 28 objectives becoming 27 across 849 sub-points. Materially, more than the structure suggests — the new vocabulary and the AI objectives are where a V7 book leaves you exposed.
It means the book was developed against the V8 draft objectives available at press time, and says so on the cover rather than in the small print. If CompTIA revises the objectives before launch, the current official objectives win over anything printed in any book, including ours.
No. Castmark Press is an independent publisher. Our guide is not affiliated with, endorsed by or sponsored by CompTIA, Inc., and its questions are original study questions, not official examination questions.
Rules change. Where a figure or a procedure can move, the issuing agency’s current published instructions win over anything here.