CY0-001 exam format: questions, passing score, time and cost

Updated September 20, 2026

CY0-001 is a short exam with an unusual amount packed into it. Sixty minutes, up to sixty questions, and a mix of multiple choice and performance-based items. Here are the published facts.

Exam codeCY0-001
CertificationCompTIA SecAI+
VersionV1
Duration60 minutes
Number of questionsMaximum of 60
Question typesMultiple choice and performance-based
Passing score600 on a scale of 100–900
LanguagesEnglish and Japanese
LaunchedFebruary 17, 2026
Estimated retirementAround three years after launch
PriceNot published on the certification page; check at booking

One minute per question

That ratio is the defining feature of this exam. Sixty questions in sixty minutes leaves no room for extended deliberation, and performance-based items eat more than their share of the clock.

The practical consequence: do not let a single performance-based question consume ten minutes. Answer what you can, mark it, and come back. Candidates who fail this exam on time rather than on knowledge almost always did so by sinking early minutes into one simulation.

Performance-based questions

CompTIA’s performance-based items ask you to do something rather than pick something — matching, ordering, classifying, or completing a configuration in a simulated interface. On a SecAI+ paper they typically involve things like sorting threats into categories, mapping controls to a pipeline stage, or ordering the steps of an incident response.

Two habits help:

  • Read the task statement fully before touching anything. These items often have two parts and people answer only the first.
  • Partial credit generally exists. An incomplete answer beats an empty one, so never leave a simulation blank because you could not finish it.

The scale is 100–900, not 0–100

600 out of 900 is the pass mark, which is roughly 67% of the scale — but the scale does not start at zero, so it does not translate to “67% of questions correct”. CompTIA scales scores, and questions carry different weights. Aim well clear of the line rather than calculating how many you can afford to miss.

Domain weighting drives everything

DomainWeightRough questions
Basic AI concepts related to cybersecurity17%~10
Securing AI systems40%~24
AI-assisted security24%~14
AI governance, risk, and compliance19%~11

The question counts are approximate — CompTIA publishes percentages, not counts, and the exam holds a maximum of sixty items. But the shape is clear: roughly two of every five questions come from one domain.

CompTIA recommends 3–4 years in IT with 2+ years of hands-on cybersecurity work, and prior knowledge at the level of Security+, CySA+ or PenTest+. None of this is enforced — there is no gate at booking — but the questions are written for someone who already thinks in terms of controls, threats and risk.

Booking

SecAI+ is delivered through CompTIA’s usual channels: a Pearson VUE test centre or online proctored at home. If you test online, run the system check in advance on the machine and network you will actually use.

What the short format means for revision

A sixty-minute exam cannot go deep on any single topic, which changes how you should revise. Breadth beats depth here. You are far more likely to meet one question on each of twenty concepts than five questions on one. That makes flashcard-style recall of terminology unusually valuable, and makes deep-diving a single framework a poor use of the last week.

It also means you cannot afford blind spots. On a ninety-question exam you can drop a whole subtopic and still pass; on sixty questions with a 600 threshold, two unfamiliar areas can be decisive.

Retirement

CompTIA gives an estimated retirement of around three years after launch, which places it near early 2029. That is an estimate rather than a commitment, but it means a pass now carries a useful shelf life.