CompTIA Certifications List: The Path From A+ to Security+ and Which to Take First
Every current CompTIA certification with its exam code, US voucher price, passing score and renewal cycle, then the beginner path: A+ vs Network+, Network+ vs Security+, timeline, cost, and when to skip a step.
CompTIA currently offers 17 certifications, from Tech+ ($129) to the two A+ exams ($548 together). For most people entering IT, the path is A+, then Network+, then Security+: four exams, since A+ is two. Every certification except Tech+ expires after three years and renews through continuing education.
CompTIA's own certifications catalog lists far more items than 17, but most of the extras are training courses and competency badges rather than proctored certifications, which is why published counts vary. Below is the annotated list CompTIA does not publish in one place, followed by the part most people actually need: which certification to take first, how the A+, Network+ and Security+ path works, what it costs, and when to skip a step.
Last updated 25 September 2026. Prices and exam codes checked against comptia.org.
Quick takeaways
- There are 17 real CompTIA certifications, not the 11 to 13 older listicles report. SecOT+ is announced for December 2026.
- The standard beginner path is A+, then Network+, then Security+, often called the CompTIA trifecta. It is four exams and $1,386 in US list-price vouchers.
- A+ codes changed: the current pair is 220-1201 and 220-1202. The older 220-1101 and 220-1102 retired on 25 September 2025.
- Security+ SY0-701 is current, and CompTIA says Security+ V8 is expected on or around 17 November 2026.
- ITF+ is now Tech+ (FC0-U71), CASP+ is now SecurityX (CAS-005), and DataX is now DataAI.
- Renewal costs $75 or $150 per three-year cycle, unless you renew by passing a higher certification.
- Security+ is the one that most often changes what jobs you qualify for, including US Department of Defense 8140 roles.
Every current CompTIA certification
Voucher prices are US list prices for a single attempt, exam only, before any student or bulk discount. Passing scores are on CompTIA's 100 to 900 scale unless noted.
| Certification | Exam code | Voucher | Questions | Minutes | Pass | Valid | CEUs |
|---|---|---|---|---|---|---|---|
| Tech+ | FC0-U71 | $129 | 70 | 60 | 650 | No expiry (CE version 5 yrs) | None |
| A+ | 220-1201 + 220-1202 | $548 total | 90 each | 90 each | 675 / 700 | 3 yrs | 20 |
| Network+ | N10-009 | $399 | 90 | 90 | 720 | 3 yrs | 30 |
| Security+ | SY0-701 | $439 | 90 | 90 | 750 | 3 yrs | 50 |
| CySA+ | CS0-004 | $439 | 85 | 165 | 750 | 3 yrs | 60 |
| PenTest+ | PT0-003 | $439 | 90 | 165 | 750 | 3 yrs | 60 |
| SecurityX | CAS-005 | $544 | 90 | 165 | Pass/fail | 3 yrs | 75 |
| CloudNetX | CNX-001 | $544 | 90 | 165 | Pass/fail | 3 yrs | 75 |
| Cloud+ | CV0-004 | $399 | 90 | 90 | 750 | 3 yrs | 50 |
| Linux+ | XK0-006 | $399 | 90 | 90 | 720 | 3 yrs | 50 |
| Server+ | SK0-005 | $399 | 90 | 90 | 750 | 3 yrs | 30 |
| Data+ | DA0-002 | $264 | 90 | 90 | 675 | 3 yrs | 20 |
| DataSys+ | DS0-001 | $399 | 90 | 90 | 700 | 3 yrs | 30 |
| DataAI | DY0-001 | $544 | 90 | 165 | Pass/fail | 3 yrs | 75 |
| Project+ | PK0-005 | $399 | 90 | 90 | 710 | 3 yrs | 30 |
| SecAI+ | CY0-001 | $298 | 60 | 60 | 600 | 3 yrs | 15 |
| AutoOps+ | AT0-001 | $298 | 60 | 60 | 600 | 3 yrs | 15 |
One more is announced but not yet live: SecOT+ (SOT-001), for operational technology security, arriving December 2026. CompTIA has not published its price, length or passing score.
Three details the table makes easy to miss. Three exams (SecurityX, CloudNetX and DataAI) are pass/fail with no scaled score at all. Tech+ is the only certification with a version that never expires, and the only one with no performance-based questions. Project+ is no longer a lifetime credential: earned on or after 1 October 2025, it renews every three years like the rest.

Exam codes that changed recently
This is where most published CompTIA lists go wrong, because a code that was correct 18 months ago is often wrong now.
| Certification | Old code | Current code | What happened |
|---|---|---|---|
| A+ | 220-1101 / 220-1102 | 220-1201 / 220-1202 | V15 launched 25 March 2025; V14 retired 25 September 2025 |
| ITF+ | FC0-U61 | FC0-U71 (as Tech+) | Renamed, launched July 2024 |
| CASP+ | CAS-004 | CAS-005 (as SecurityX) | Rebranded December 2024 |
| CySA+ | CS0-003 | CS0-004 | V3 retires in English 22 December 2026 |
| Linux+ | XK0-005 | XK0-006 | V8 launched July 2025 |
| Data+ | DA0-001 | DA0-002 | V2 launched October 2025 |
Security+ SY0-701 is still the current exam. CompTIA's Security+ page says V8 is expected to launch on or around 17 November 2026, with more coverage of AI-related risks and security operations. CompTIA has not published a retirement date for SY0-701, so treat any specific date you see elsewhere as unconfirmed. A Security+ earned on SY0-701 stays valid for its full three years either way. Network+ N10-009 launched 20 June 2024, and CompTIA estimates its retirement in 2027.
The CompTIA path: A+, then Network+, then Security+
The three certifications map to the three layers a support-to-security career is built on, and each one assumes the last.
| Cert | Exams | Pass | Broad focus | Assumes | Typical roles |
|---|---|---|---|---|---|
| A+ | 2 (220-1201, 220-1202) | 675 / 700 | Hardware, OS, mobile, troubleshooting, support | Nothing | Help desk, desktop support, field technician |
| Network+ | 1 (N10-009) | 720 | Networking, IP addressing, subnetting, routing and switching | A+ level basics | Network technician, junior admin, NOC |
| Security+ | 1 (SY0-701) | 750 | Threats, cryptography, identity, risk, security operations | Networking basics | Security analyst, SOC analyst, junior security admin |
The order matters because the knowledge stacks. You cannot secure a network you do not understand, and networks are hard to understand without the hardware and operating-system grounding A+ gives you. Taken in order, each exam makes the next one easier. CompTIA's own recommendations follow the same line: A+ recommends 12 months in IT support, Network+ recommends A+ plus 9 to 12 months of hands-on networking, and Security+ recommends Network+ plus about two years in security or systems administration. None of these is a hard prerequisite. You can sit any exam without holding the one below it.

A realistic timeline from zero
Studying steadily around a job, most career switchers land in the same range.
| Stage | Typical time from zero |
|---|---|
| A+ Core 1 | 4 to 8 weeks |
| A+ Core 2 | 4 to 8 weeks |
| Network+ | 6 to 10 weeks |
| Security+ | 6 to 10 weeks |
| Total | Roughly 6 to 12 months |
Two things compress it: existing IT support experience, and treating it like a part-time course rather than an occasional hobby. Two things stretch it: long gaps between exams, and booking before your practice scores clear the bar with margin, which is how people end up buying retake vouchers.
What the path costs
At US list prices, A+ is $548 (two exams at $274), Network+ is $399 and Security+ is $439, so the three certifications are $1,386 in exam vouchers before any study material. A retake costs another full voucher for that exam. Students verified through CompTIA's academic store can buy discounted vouchers, and some employers, workforce programs and veterans benefits cover them.
Renewal is the cost people forget. CompTIA's continuing education FAQ requires CE within three years of earning or renewing:
- $75 per three-year cycle: A+, Data+, SecAI+, AutoOps+
- $150 per three-year cycle: Network+, Security+, CySA+, PenTest+, SecurityX, Cloud+, Linux+, Server+, DataSys+, DataAI, CloudNetX, Project+
- $0: Tech+ (renew by passing the latest exam version)
There is a way around the fee. Passing a higher certification renews the ones below it, and renewing through a CertMaster CE course carries no separate CE fee. The hierarchy runs SecurityX at the top, renewing CySA+ and PenTest+, which renew Security+, which renews Network+, which renews A+. Someone who earns Security+ within three years of A+ has already renewed their A+ without paying a CE fee. See Security+ renewal for the details on that one.
A+ vs Network+: which first?
If you are new to IT, take A+ first. If you already work in desktop support or want an infrastructure role, you can go straight to Network+.

The honest difficulty read: A+ is harder in breadth (two exams over a huge surface area) and Network+ is harder in depth (subnetting math and routing concepts that are new to most beginners). A+ is also the bigger commitment: two exams, two sittings, two vouchers.
Take A+ first if you are new to IT with no professional support experience, are targeting help desk, desktop support or field technician work, or want the broad foundation before specializing.
Start at Network+ if you already do support work that A+ would mostly validate, want a networking or infrastructure role quickly, or have a job posting that names Network+. Be honest about subnetting and routing, since that is where people without the foundation struggle. If you are choosing between Network+ and Cisco's CCNA, Network+ is vendor-neutral and closer to A+ in difficulty, while CCNA goes deeper on hands-on configuration and is the bigger step. For the full N10-009 breakdown, see the Network+ exam objectives.
Network+ vs Security+: which next?
Network+ certifies that you can build, configure and troubleshoot networks. Security+ certifies that you can secure them. They are close in format and different in purpose.
| Attribute | Network+ (N10-009) | Security+ (SY0-701) |
|---|---|---|
| What it certifies | Networking: infrastructure, configuration, troubleshooting | Security: threats, cryptography, identity, risk, operations |
| Max questions | 90 | 90 |
| Time | 90 minutes | 90 minutes |
| Passing score | 720 of 900 | 750 of 900 |
| Domains | 5 | 5 |
| Recommended experience | A+ plus 9 to 12 months networking | Network+ plus about 2 years security or sysadmin |
| DoD 8140 | Some roles | Baseline for many roles |

Take Network+ first if your target is networking or infrastructure, or you are not yet comfortable with IP addressing, subnetting and how traffic moves.
Go straight to Security+ if the job postings you want list Security+, you already understand basic networking, or you need to meet a DoD 8140 requirement, where Security+ is the workhorse certification.
Most candidates rate Security+ slightly harder. Network+ is concrete: subnetting, port numbers and troubleshooting steps have right answers you can drill. Security+ is more conceptual: choose the best control in a scenario, where two answers can both look correct. Both open with performance-based questions, and those are the real difficulty spike on each. For the Security+ format in detail, see how many questions are on the Security+ exam.
When to skip a step
Not everyone needs all three, and pretending otherwise wastes money.
- You already have hands-on IT experience. With one to two years in support, many people skip A+ and start at Network+.
- Your target is strictly cybersecurity, fast. Some career switchers go A+ then straight to Security+. It works for the certification, though the networking gap tends to show up on the job.
- A vendor path fits better. For some networking careers, CCNA is a stronger signal than Network+. If a posting names a specific certification, chase that one.
- You are still deciding whether IT is for you. That is what Tech+ is for. It sits below A+ and is not aimed at job seekers.
Two beginners from the same starting point show the idea. One wants a help desk job in three months: her shortest path is A+ alone, because that is what local help desk postings ask for. The other wants a security analyst role within a year: his is A+, then Network+, then Security+, because Security+ is what those postings request and the two below it make it far more passable.
Beyond CompTIA: two other beginner options
Two non-CompTIA credentials come up in every beginner list.

- Google IT Support. A course certificate delivered through Coursera, with no prerequisites and no renewal exam. It teaches similar foundations to A+ and suits career changers testing the water, but it is not a vendor exam certification, and not every employer treats it as a substitute for A+.
- ISC2 Certified in Cybersecurity (CC). An entry-level security certification designed for people with no work experience, with an annual maintenance fee. ISC2's One Million Certified in Cybersecurity program, which gave away the course and exam, stopped accepting new participants on 20 May 2026, per ISC2. Existing codes must be used by 31 December 2026, and the exam is now sold like other ISC2 exams, so do not plan around an older article that says CC costs nothing.
A certification is a door, not the room. It gets your resume past a filter; hands-on practice, a home lab and small projects you can talk about are what carry the interview.
Difficulty across the full list, honestly ranked
CompTIA does not publish pass rates, and neither will we invent them. What can be stated factually is the experience each exam assumes, which is the most reliable available proxy for difficulty.
| Tier | Certifications | Experience CompTIA recommends |
|---|---|---|
| Entry | Tech+ | None |
| Foundation | A+ | 12 months in IT support |
| Intermediate | Network+, Linux+, Project+, Data+ | 9 to 24 months in the relevant role |
| Professional | Security+, Cloud+, Server+, DataSys+, SecAI+, AutoOps+ | 2 to 3 years |
| Advanced | CySA+, PenTest+ | 3 to 4 years specialising |
| Expert | SecurityX, CloudNetX, DataAI | 10+ years total, 5+ years specialised |
The three expert-tier exams are also the three scored pass/fail, and they run to 165 minutes. SecurityX asks for a minimum of ten years in IT including five hands-on in security, which puts it well outside the range of anyone treating it as a next step after Security+.
One real question from each exam on the path
These are taken word for word from the PrepClubs banks, so you can see how the style shifts from A+ to Network+ to Security+.
A+: from PrepClubs A+ Core 2 (220-1202) Practice Test 4, question 33 (Security):
A technician wants to protect the data on a laptop's drive so that if the laptop is stolen, the contents cannot be read without the credentials. Which built-in Windows feature accomplishes this?
- A. BitLocker full-disk encryption
- B. EFS on one folder of user files
- C. A password-protected screen lock
- D. A BIOS supervisor password
Answer: A. BitLocker encrypts the whole volume, including the operating system and page file, so a thief who pulls the drive and mounts it elsewhere gets nothing readable. EFS on one folder (B) leaves the rest of the volume in the clear, a screen lock (C) protects only the running session, and a BIOS supervisor password (D) blocks firmware changes, not access to the drive. A+ questions test whether you can match a tool to a need.
Network+: from PrepClubs Network+ Practice Test 3 (N10-009), question 24 (Network Troubleshooting):
Why does sustained 3% packet loss cause audible gaps in VoIP calls, while a TCP file download over the same path still completes intact, only more slowly?
- A. RTP voice travels over UDP, so lost packets are never resent
- B. Voice packets are larger, so each loss removes more audio
- C. Routers always queue TCP downloads ahead of VoIP traffic
- D. Voice codecs resend lost frames, which adds noticeable delay
Answer: A. Voice media rides RTP over UDP, which has no acknowledgements or retransmission, so a lost packet is simply missing when it is due to play. TCP detects each loss and resends it, so the download completes, just slower. Voice packets are small (B is wrong), QoS normally prioritises voice rather than queuing it behind bulk data (C), and codecs do not resend frames that would arrive too late (D). Network+ asks you to explain why a network behaves the way it does.
Security+: from PrepClubs Security+ Practice Test 3 (SY0-701), question 43 (Security Architecture):
An administrator argues that the nightly RAID 1 mirror on the file server means the team does not need a separate backup process. Why is this reasoning flawed from a resilience standpoint?
- A. RAID tolerates drive failure but replicates deletions and corruption
- B. RAID mirroring keeps versioned point-in-time copies on disk
- C. RAID 1 rebuilds restore files that users delete by mistake
- D. RAID and backups defend against the same set of failure modes
Answer: A. RAID 1 keeps the server running when a drive dies, but every write is mirrored instantly, so a deletion, corruption or ransomware encryption lands on both disks. Only separate point-in-time backups let you roll back. Mirroring keeps no version history (B), a rebuild copies the mirror that already has the deletion (C), and D is the exact misconception being tested. Security+ asks you to judge which control fits the risk.
Where PrepClubs fits
Being direct about our scope: PrepClubs covers three of the 17 certifications on this list, the three on the beginner path. Each has an original question bank written against the current exam objectives, never reproduced live exam items, with a written rationale on every answer:
- A+: 925 questions, a 25-question diagnostic plus five full-length tests for Core 1 (220-1201) and five for Core 2 (220-1202).
- Network+: a 25-question diagnostic plus 29 full-length 90-question tests for N10-009.
- Security+: 925 questions, a 25-question diagnostic plus ten full-length tests for SY0-701.
We do not have banks for Linux+, Cloud+, CySA+, PenTest+, Server+, Data+, DataSys+, DataAI, Project+, SecAI+, AutoOps+, SecurityX, CloudNetX or Tech+. For those, CompTIA's own CertMaster products or another provider will serve you better. PrepClubs is not a certifying body and is not affiliated with CompTIA.
FAQ
How many CompTIA certifications are there?
There are 17 currently offered proctored certifications, with an eighteenth, SecOT+, due in December 2026. Published counts vary because CompTIA's catalog also lists training courses, "Essentials" badges and TestOut-derived products that carry a competency certificate rather than a certification. Older articles reporting 11 or 13 predate SecAI+, AutoOps+, CloudNetX and the Tech+ rename.
What order should I take CompTIA certifications in?
For most beginners: A+, then Network+, then Security+. A+ gives the hardware and operating-system foundation, Network+ builds networking depth on top, and Security+ secures the networks you now understand. None is a hard prerequisite, so experienced candidates often start at Network+ or Security+.
Is the CompTIA trifecta three exams or four?
Four. A+ requires two separate exams, Core 1 (220-1201) and Core 2 (220-1202), plus one Network+ exam (N10-009) and one Security+ exam (SY0-701). At US list prices that is $1,386 in vouchers.
Which CompTIA certification is considered the best?
Security+, judged by how often it appears in job postings. It is the baseline security credential recognised under US Department of Defense 8140 requirements, which makes it effectively mandatory for many government and contractor roles. A+ is the best first certification for someone with no IT experience.
What is the hardest CompTIA cert?
By CompTIA's recommended experience, SecurityX (CAS-005): at least ten years in IT including five hands-on in security, 165 minutes, scored pass/fail. CloudNetX and DataAI sit at the same tier. Among widely taken certifications, CySA+ and PenTest+ are the steepest step up from Security+.
How much do CompTIA certifications cost?
Vouchers run from $129 (Tech+) to $548 (A+, two exams at $274). Network+ is $399 and Security+ is $439. CompTIA's bundles with training run from $265 for Tech+ to $1,293 for the A+ complete bundle with a retake. Renewal costs $75 or $150 every three years unless you renew by passing a higher certification.
Do CompTIA certifications expire?
All except Tech+ expire three years after you earn or last renew them. Tech+ has a non-expiring version alongside a five-year CE version. Project+ earned on or after 1 October 2025 follows the three-year cycle; anything earned by 30 September 2025 stays valid for life.
What is the passing score for CompTIA exams?
Most use a 100 to 900 scale: 675 for A+ Core 1, 700 for A+ Core 2, 720 for Network+ and Linux+, 750 for Security+, CySA+, PenTest+, Cloud+ and Server+, and 650 for Tech+. SecurityX, CloudNetX and DataAI are pass/fail.
Related on PrepClubs
- How hard is CompTIA A+?: format, scoring, cost and jobs for the first step.
- CompTIA A+ practice test: drilling Core 1 and Core 2 with a study plan.
- CompTIA Network+ practice test: the N10-009 domains and how to drill them.
- Security+ practice test: using a full-length SY0-701 bank the right way.
- CISSP vs ISACA CISA: where the path goes after several years in security or audit.
Practise the three on the path
If your next exam is A+, Network+ or Security+, the fastest way to keep the path affordable is to pass each one the first time, because every retake is another voucher. Each PrepClubs bank has full-length tests that match the real question count and timing for the current codes (220-1201 and 220-1202, N10-009, SY0-701). More than 3,700 students have prepared with PrepClubs, and access is backed by our Money-back Guarantee.
Practice at prepclubs.com/tests/a-plus, prepclubs.com/tests/network-plus or prepclubs.com/tests/security-plus.
Practise for this exam
CompTIA A+ (220-1201 and 220-1202) practice tests
Full-length timed forms across every exam domain at the official weighting, with a clear rationale for every answer. Start with the 25-question diagnostic to see which domains need the most work.


