Castmark PressIndependent study guides
Guides · August 2026

Everything genuinely new in the Security+ V8 objectives

The V8 draft is not a renumbering. It renames Domain 2, redistributes the weights, and introduces roughly twenty terms absent from SY0-701 material — passkeys, quishing, BIMI, living-off-the-land tooling, canary accounts, secrets scanning, alert tuning, break-glass access, agentic AI, ransomware negotiation and behavioural risk scoring among them.

Every exam revision produces the same two claims: that nothing much changed, and that everything changed. Both are wrong here, and the way to settle it is not to argue about the structure but to read the vocabulary.

Structure moves modestly between SY0-701 and the V8 draft. One domain is renamed, the weights shift, and twenty-eight objectives become twenty-seven. If that were all, a lightly edited V7 book would cover the exam.

It is not all. The draft's 849 sub-points contain roughly twenty terms that a 2023-era guide has no reason to mention, because in 2023 several of them did not exist as exam concepts. Those terms are the difference between a book written for this exam and a book reissued for it — and they are what this guide lists, objective by objective.

First, the structure that did move

Domain 2 is renamed: "Threats, Vulnerabilities, and Mitigations" in V7 becomes "Threats, Vulnerabilities, and Attacks" in the V8 draft. The other four keep their names — General Security Concepts, Security Architecture, Security Operations, and Security Program Management and Oversight.

The weights redistribute across those five domains, and the objective count drops from twenty-eight to twenty-seven, spread three, six, four, eight and six.

What did not move deserves saying, because secondhand commentary frequently gets it wrong: threat actors are still in 2.1 and architecture still opens at 3.1. No large topic jumped domains between versions.

The V8 draft domain weights

The draft distributes the exam as follows. Security Operations remains the heaviest domain by some distance, and Threats gains ground on the previous version.

DomainV8 draft weightObjectives
1.0 General Security Concepts16%3
2.0 Threats, Vulnerabilities, and Attacks24%6
3.0 Security Architecture19%4
4.0 Security Operations27%8
5.0 Security Program Management and Oversight14%6
Twenty-seven objectives across 849 sub-points. Draft figures — CompTIA's published objectives win at any point they differ.

The vocabulary that dates a book

This is the useful part. Each of these appears in the V8 draft and in no SY0-701 material, because most of them entered mainstream security practice after the previous exam was written. If your study guide does not teach them, it was not written for this exam.

Authentication is where the change is most visible. Passkeys and passwordless authentication arrive in the identity and access objectives, and they bring their own exam-relevant nuance rather than being a synonym for multi-factor. Break-glass emergency access, just-in-time privilege elevation, time-of-day access models and monitoring for compromised credentials sit alongside them.

Social engineering picks up two delivery routes that did not exist in the older material: quishing — phishing delivered through a QR code — and RCS as a message vector. Email authentication gains BIMI, taught alongside DMARC, SPF and DKIM rather than instead of them.

Operations gains the vocabulary of a working SOC rather than a textbook one: alert tuning, secrets scanning, canary accounts, endpoint posture and compliance checking, and living-off-the-land tooling as an attacker technique rather than a footnote.

Where each new term sits

The objective numbers matter more than the terms themselves, because they tell you which chapter of any guide should be teaching them — and let you check a book's index against the exam it claims to cover.

TermObjectiveWhy it is new
Passkeys, passwordless4.5Syncable authenticators changed the authentication model after SY0-701 was written
Quishing (QR-code phishing)2.5A delivery route that became mainstream after the previous exam
RCS as a message vector2.3Rich messaging replaced SMS as an attack surface
Living-off-the-land tools2.3Named as a technique rather than left implicit
BIMI (with DMARC, SPF, DKIM)4.1Email authentication gained a fourth component
Canary accounts, secrets scanning4.1Detection practice that moved from mature SOCs into the syllabus
Alert tuning4.4Recognises that alert volume, not alert absence, is the operational problem
Break-glass access, JIT elevation4.5Privilege management shifted from standing access to time-bounded access
Agentic AI, AI-augmented baselines4.6AI enters operations as scope, not as a mention
Ransomware negotiation4.7An incident-response step with no equivalent in the NIST sequence
Behavioural risk scoring5.6Human risk measured rather than asserted
Backup immutability3.4Ransomware changed what a backup has to survive

Two changes that are more than vocabulary

Artificial intelligence stops being a mention and becomes scope. The draft puts large language model risk into the threat objectives and puts agentic AI, chatbots, predictive analytics and AI-augmented baselines into security operations. A guide that gives AI a sidebar has not covered this; a guide that gives it chapters has.

And Domain 5 asks for arithmetic rather than definitions. Single loss expectancy, annualised rate of occurrence and annualised loss expectancy are listed explicitly under business-level considerations. SLE is asset value multiplied by exposure factor; ALE is SLE multiplied by ARO. Expect to compute a figure and then decide what it means, not to recognise a definition.

There is a third change worth naming even though it is not vocabulary: incident response gains negotiation with ransomware operators as a step, alongside notification of stakeholders, customers and law enforcement. Candidates who learned the four-phase NIST cycle will find the exam's own sequence differs, and the exam's sequence is the one being tested.

What is still unpublished

The draft marks the number of questions and the exam duration as to be determined. We will not print figures CompTIA has not published, and any source giving you "90 questions in 90 minutes" for SY0-801 has copied them from V7.

The passing score is published and does carry across: 750 on a scale of 100 to 900. So do the question types — multiple-choice and performance-based.

Everything above is drawn from a draft. CompTIA revises drafts, and the version number displayed on the download page has not always matched the version declared inside the file. Download the current objectives before you schedule and check them against whatever you are studying from.

The book for this exam

Cover of CompTIA Security+ Study Guide 2027 CompTIA Security+ Study Guide 2027 Written line by line against the CompTIA Security+ V8 objectives for exam SY0-801, while most guides on the shelf are still SY0-701 books. Everything is… See the book →

More on this exam

Common questions

Is a SY0-701 book enough for SY0-801 if I just read the new terms elsewhere?

It is a poor substitute. The new vocabulary is not a glossary appended to old material — passkeys change how the authentication objectives are taught, and the AI objectives change what security operations covers. The terms are the visible symptom, not the whole change.

How many objectives and sub-points does V8 have?

Twenty-seven objectives across the five domains, distributed three, six, four, eight and six, breaking down into 849 individual sub-points in the draft. SY0-701 had twenty-eight objectives.

Did any topic move from one domain to another?

Not substantially. Threat actors remain in 2.1 and architecture still opens at 3.1. Claims that whole topics jumped domains between the versions do not hold up against the two objective lists.

How much of the exam is AI?

CompTIA publishes weights at the domain level, not per topic, so we will not invent a percentage. What is certain from the draft: AI risk appears in the threat objectives and AI-assisted operations appear in Domain 4, which carries the largest weight of the five.

Are these the final objectives?

No. They are draft objectives published for review, and CompTIA revises them. When Security+ V8 disappears from the exams-under-development page, the final version exists — verify against it before you schedule.

Sources

  1. DRAFT CompTIA Security+ V8 Exam Objectives, exam number SY0-801 V8 — domain names and weights, 27 objectives across 849 sub-points, question count and duration marked TBD
  2. CompTIA, "CompTIA Exam Objectives Under Development" — the page hosting the draft, consulted August 2026 — https://www.comptia.org/en-us/resources/comptia-exam-objectives-under-development/
  3. CompTIA Security+ SY0-701 exam objectives — 28 objectives and the V7 domain names, used for the version-to-version comparison
  4. CompTIA, "Security+ (Plus) Certification" — published passing score of 750 on a 100-900 scale and the multiple-choice plus performance-based question types — https://www.comptia.org/en-us/certifications/security/
  5. NIST SP 800-61 Rev. 3 — the incident-response sequence against which the exam's own objective 4.7 sequence is compared

Rules change. Where a figure or a procedure can move, the issuing agency’s current published instructions win over anything here.