Click to upload or drag and drop
PDF, DOCX, PPTX, TXT, JPG, JPEG, PNG, HEIC, ODP, ODT, BMP, or TIFF
up to 20MB
Uploading...
Yes, CASP+ is still worth it, and it is now called CompTIA SecurityX. CompTIA renamed CASP+ to SecurityX on December 17, 2024, launching the CAS-005 exam the same day. It is the same expert-level, hands-on security certification, still vendor-neutral and still mapped to US Department of Defense 8140 work roles. Only the name and the exam version changed.
If you have been eyeing CASP+ and suddenly see "SecurityX" everywhere, you are not missing a new certification. You are looking at the same one under a new brand. The rename caused real confusion, so here is exactly what changed, what did not, and who should still take it.
CompTIA moved its top security credential into a new family it calls the Xpert series, and CASP+ became SecurityX as part of that. The old exam, CAS-004, retired in 2025, and the current exam is CAS-005. The exam was also restructured from five domains down to four: Governance, Risk, and Compliance (20 percent), Security Architecture (27 percent), Security Engineering (31 percent), and Security Operations (22 percent). Security Engineering is now the single largest domain, which reflects CompTIA leaning further into hands-on implementation rather than policy.
Almost everything that made CASP+ valuable carried over. It is still the expert tier above Security+, CySA+, and PenTest+. It is still vendor-neutral, so it is not tied to one cloud or product. It is still performance-based, dropping you into simulated environments rather than only asking multiple choice. It is still graded pass or fail with no scaled score, which surprises people expecting a number like the 750 on Security+. And it still maps to DoD 8140 work roles, which keeps it relevant for federal and defense-contractor hiring. Existing CASP+ holders kept their certification and their continuing-education standing, and simply received updated SecurityX badges.
For the right person, yes. SecurityX targets senior security engineers and architects, the people who design and implement security across an enterprise rather than manage it from a policy seat. CompTIA recommends roughly ten years in IT with five in security before attempting it, and the exam earns that recommendation. If you are at that level, SecurityX is one of the few advanced, hands-on, vendor-neutral options, and it costs 529 dollars against four-figure prices for some competing tracks. For DoD 8140 environments in particular, it is often the most direct path to meeting a work-role requirement.
Where it is not worth it: if you are early in your career, Security+ is the correct starting point, and SecurityX will feel like drinking from a firehose. And if your goal is purely managerial, a governance-focused certification may fit better than SecurityX, which keeps you technical.
People weighing SecurityX often also consider CISSP. The simplest distinction: SecurityX is hands-on and engineering-heavy, while CISSP is broad and management-oriented, covering eight domains with an emphasis on governance and risk. If you build and implement, SecurityX fits. If you are moving toward security management and want the name recognition, CISSP fits. Many senior practitioners eventually hold both because they prove different things.
The biggest preparation mistake is using old material. Anything labeled CASP+ with five domains and a CAS-004 code predates the current exam. Study CAS-005 aligned content, and weight your effort toward Security Engineering and Security Architecture, which are 58 percent of the exam combined. Because SecurityX is scenario-driven, turn your notes into questions that force trade-offs rather than recall. You can build unlimited practice questions from your own material with the CompTIA SecurityX practice exam generator, then generate a set to find your weak domains before test day.
The Governance, Risk, and Compliance domain is also where SecurityX meets the day job for many candidates. If your organization struggles to keep obligations, controls, and evidence in one place, seeing how a dedicated tool for tracking compliance obligations and controls works in practice makes the abstract GRC concepts on the exam far more concrete, because you are mapping them to something real.
A certification is only worth taking if it signals something hiring managers value, and SecurityX signals a specific thing: that you can implement and integrate security across a real enterprise, not just talk about it. Because the exam is performance-based and vendor-neutral, it is hard to pass by cramming acronyms, which is exactly why it carries weight. In defense and federal contracting, its mapping to DoD 8140 work roles can be a direct hiring or contract requirement, so it moves from nice-to-have to mandatory. In the private sector, it reads as evidence of senior, hands-on security depth at the architect and engineer level. Salary surveys consistently place advanced security roles among the better-paid IT positions, and while no certification guarantees a raise, SecurityX is the kind of credential that gets a senior candidate past the first screen for those roles. It also pairs well with a cloud certification, since most enterprises now run hybrid environments where SecurityX architecture skills and cloud-specific knowledge reinforce each other.
Do I need to retake anything if I hold CASP+? No. Your certification is unchanged, your continuing-education clock keeps running, and you now hold the SecurityX badge. Should I put CASP+ or SecurityX on my resume? Lead with SecurityX and note "formerly CASP+" in parentheses so applicant-tracking systems match both terms. Is CAS-004 still an option? No, the CAS-004 exam has retired, so CAS-005 is the only version you can sit. Will the rename hurt name recognition? Short term, some hiring managers still search CASP+, which is why listing both names on your resume matters for the next year or two.
CASP+ did not disappear; it grew up and got a new name. SecurityX (CAS-005) is the same respected, hands-on, vendor-neutral advanced security certification, restructured into four domains with a heavier engineering focus. If you are a senior security professional, especially in a DoD 8140 environment, it is still very much worth it. Just make sure you study the current exam, not the version that shared its old name.
From the same family of tools