CompTIA SecurityX
(CAS-005)

The advanced-tier, ANSI-accredited, performance-based certification for technical cybersecurity leaders. Successor to CASP+. Required for many DoD 8140 work roles.

The CompTIA SecurityX (CAS-005) exam validates that a candidate can architect, engineer, integrate, and implement secure solutions across complex enterprise environments, on-premises, cloud, and hybrid, while leading the governance and operational disciplines that keep a resilient enterprise resilient.

Where Security+ proves you understand cybersecurity concepts, SecurityX proves you can operate the field. The exam emphasizes hands-on, performance-based questions, cryptographic implementation, threat modeling, automation workflows, incident response, and emerging considerations like AI in security operations.

It is the only major hands-on, performance-based, ANSI/ISO 17024 accredited certification at the advanced practitioner tier, and the credential of record for senior security engineers, architects, and SOC leads.

// EXAM SPECIFICATION v3.0 · 2024+
VendorCompTIA, Inc.
Exam CodeCAS-005
PredecessorCASP+ (deprecated)
QuestionsUp to 90
Duration165 minutes
FormatPBQ + MCQ
PassingPass / Fail (no scaled score)
Validity3 years (CEU renewable)
AccreditationANSI · ISO 17024 · DoD 8140
Recommended XP10y IT / 5y security
// DOMAINS
Exam Domains

Four domains. One integrated practice.

The CAS-005 exam blueprint maps to four interlocking domains. Weights below reflect approximate exam distribution.

D / 01
Governance, Risk & Compliance
Risk management strategy, threat modeling, regulatory frameworks (GDPR, HIPAA, PCI-DSS, NIST), audit readiness, and the GRC tooling that ties them together.
~20%
D / 02
Security Architecture
Designing resilient enterprise architectures across on-prem, cloud, and hybrid. Zero-trust, segmentation, identity federation, cryptographic primitives, and emerging AI/ML-aware design.
~27%
D / 03
Security Engineering
Implementation work, IAM, endpoint hardening, PKI, secure software development integration, container and serverless security, and automation pipelines that ship secure-by-default.
~31%
D / 04
Security Operations
Detection engineering, threat hunting, incident response, forensics, and the automation layer that scales a SOC. Includes adversarial AI considerations and supply-chain incident scenarios.
~22%
// AUTHORITY
From the source

What CompTIA
says about SecurityX.

CompTIA itself describes the cert in two specific ways. The CAS-005 release positioned it as the only hands-on, performance-based credential at the advanced practitioner tier, distinct from management-track exams. The broader Xpert Series roadmap framed it as a validator of expert-level competence in defined job roles.

// LAUNCH RELEASE · DEC 17, 2024
CompTIA SecurityX is “the only hands-on, performance-based certification” at the advanced practitioner tier — built for working engineers, not managers.
Patrick Lane
Director, Cybersecurity Product Management, CompTIA
// XPERT SERIES ROADMAP · JUL 2023
Every Xpert Series exam validates “deep expertise in job roles recognized as being at the expert level.”
Thomas Reilly
Chief Product Officer, CompTIA

// Both statements are publicly released material from official CompTIA press releases. Quotation length is limited and attribution is direct to the speaker and the source release. Use the source links to verify.

// DoD 8140 / DCWF
DoD 8140 Approved

Nineteen DCWF work roles.

CompTIA SecurityX (CAS-005) is approved under DoDM 8140.03 for 19 work roles in the DoD Cyber Workforce Framework (DCWF). Roles are grouped by Workforce Element. DCWF codes shown in parentheses match the DoD 8140 Foundational Qualification Matrix at public.cyber.mil.

// IT (Cyberspace)
  • Systems Requirements Planner641
  • Enterprise Architect651
  • Research & Development Specialist661
// Cybersecurity
  • Cyber Defense Analyst511
  • Cyber Defense Incident Responder531
  • Vulnerability Assessment Analyst541
  • Security Control Assessor612
  • Secure Software Assessor622
  • Information Systems Security Developer631
  • Security Architect652
  • Information Systems Security Manager722
  • COMSEC Manager723
// Software Engineering
  • Systems Security Analyst461
// Cyberspace Enablers
  • Cyber Crime Investigator221
  • Program Manager801
  • IT Project Manager802
  • Product Support Manager803
  • IT Investment/Portfolio Manager804
  • IT Program Auditor805

A note on DoD 8570 versus DoD 8140. The legacy DoDM 8570.01-M framework (with its IAT, IAM, and IASAE categories at Levels I, II, and III) was superseded by DoDM 8140.03 in February 2023. The 8140 framework replaces category/level structure with specific DCWF work roles. CompTIA SecurityX inherits all the approvals previously held by CASP+ under 8570 and is now approved under 8140 for the work roles listed above.

// Source: CompTIA Framework Alignment (comptia.org/en-us/resources/comptia-framework-alignment). Verify the current Foundational Qualification Matrix at public.cyber.mil/wid/dod8140/qualifications-matrices for your specific work role before relying on this mapping.

Ready to certify?

The cert opens doors.
The bootcamp gets you through.

The bootcamp is built around structured instruction, expert-led review, and hands-on practice with the kind of scenarios the CAS-005 exam tests. Exam results vary based on prior experience, study time, technical background, and exam readiness. We do not guarantee exam outcomes. Pick a format and reserve your seat.

cas-005 · prep
$ ./check_eligibility
✓ candidate profile sufficient
$ ./schedule_exam
→ opening pearson voucher portal...
ready_