Security+ V8 (SY0-801): what moves, what is new and how to re-plan your study
Security+ V8 (SY0-801), expected on or around 17 November 2026, keeps five similar domains but changes their weights. General Security Concepts rises from 12 to 16 per cent, and Security Program Management and Oversight falls from 20 to 14 per cent. Objectives drop from 28 to 27, a new objective covers AI threats, and mitigation moves into Security Operations. The format and pass mark stay the same.
Many Security+ courses on sale this autumn were written for V7, and plenty of candidates will carry them into V8 without checking. The two exams look alike, so the gap shows late. By then you may have spent a fifth of your hours on a domain that has lost almost a third of its weight. Here is exactly what moves in SY0-801 and what it does to your plan.
What changes when V8 (SY0-801) arrives?
CompTIA expects to launch V8 (SY0-801) on or around 17 November 2026. It replaces V7 (SY0-701), and both lead to the same Security+ credential. We checked every figure below against CompTIA's SY0-701 and SY0-801 exam objectives in October 2026.
| Domain | V7 (SY0-701) | V8 (SY0-801) | Change |
|---|---|---|---|
| 1 · General Security Concepts | 12% | 16% | +4 points |
| 2 · Threats, Vulnerabilities and Mitigations (V7); Threats, Vulnerabilities and Attacks (V8) | 22% | 24% | +2 points |
| 3 · Security Architecture | 18% | 19% | +1 point |
| 4 · Security Operations | 28% | 27% | −1 point |
| 5 · Security Program Management and Oversight | 20% | 14% | −6 points |
| Number of objectives | 28 | 27 | −1 |
What stays the same matters as much as what moves. Both versions have up to 90 questions in 90 minutes, mixing multiple-choice and performance-based questions. Both need a scaled score of 750 on a scale of 100 to 900, and both use the same question formats.
So V8 changes what you study, not how you sit the exam. Four changes do most of the work.
Which four changes affect your study?
- Weight moves towards concepts and threats. Domains 1 and 2 together rise from 34 to 40 per cent of the exam. Domain 5 falls from 20 to 14 per cent, the largest single drop.
- Mitigation moves into operations. V7 objective 2.5, mitigation techniques, leaves the threat domain. In V8 it sits inside objective 4.1, Apply mitigating controls to secure the environment. The threat domain is renamed Threats, Vulnerabilities and Attacks.
- A new objective on artificial intelligence. V8 objective 2.6 asks you to summarise threats and vulnerabilities of AI usage: the risks of using AI tools and of attacks on them. It has no V7 equivalent.
- Governance is reframed. Objective 5.1 becomes "governance, risk and compliance artifacts": policies, standards, procedures and guidelines.
AI also appears inside operations. In V8, objective 4.6 on automation and orchestration covers scripts and tools that speed up secure work, including AI-assisted work.
Security Operations stays the largest domain in both versions, so a one-point drop there changes little. The larger effect is where individual objectives now sit.
How do the V7 objectives map onto V8?
The book matches each V8 objective to its closest V7 objective by content. That mapping is the author's judgement, not an official CompTIA crosswalk. It still shows where your existing notes belong.
| V7 (SY0-701) objective | Where it lands in V8 (SY0-801) |
|---|---|
| 1.1 and 1.2 | Merged into 1.1, security concepts and controls |
| 1.3 and 1.4 | Renumbered as 1.2, change management, and 1.3, cryptography |
| 2.1 and 2.4 | Renumbered as 2.2, threat actors, and 2.5, indicators of malicious activity |
| 2.2 and 2.3 | Spread across 2.1, 2.3 and 2.4: threats, vectors and attack surfaces |
| 2.5, mitigation techniques | Into 4.1, mitigating controls |
| 4.5 | Into 3.2, protecting the infrastructure, alongside V7 3.2 |
| 4.6 to 4.9 | Renumbered as 4.5 to 4.8 |
| None | New 2.6, threats and vulnerabilities of AI usage |
Domain 3 keeps 3.1, 3.3 and 3.4 in place, and Domain 5 keeps 5.1 to 5.6 one to one.
Two consequences follow. First, an objective number in old notes may now point at a different topic. A flashcard labelled 4.6 meant identity and access in V7. In V8, 4.6 is automation and orchestration. Relabel your notes by topic, not by number.
Second, Domain 4 shrinks from nine objectives to eight while barely losing weight. Each remaining operations objective carries a little more of the exam, which is one more reason to give them lab time.
What does V8 change for your study hours?
Split your hours in proportion to the weights of the version you will sit, then move hours towards the objectives you rated lowest. The book uses 60 to 100 hours as a working assumption for someone with IT experience. Here is an 80-hour plan on each set of weights.
| Domain | V7 hours | V8 hours |
|---|---|---|
| General Security Concepts | 10 | 13 |
| Threats and Vulnerabilities (Mitigations in V7, Attacks in V8) | 18 | 19 |
| Security Architecture | 14 | 15 |
| Security Operations | 22 | 22 |
| Security Program Management and Oversight | 16 | 11 |
The V8 column is the book's starting split. The V7 column applies the same method to the V7 weights. Five hours leave governance, and most of them go to controls, cryptography and threats.
Give objective 2.6 its own slot in that plan. It has no V7 objective, so you need a V8 source for at least that objective.
Is your study material V7 or V8?
Run a two-minute test before you study another hour. Open your course, book or question bank and look for the exam code and the domain weights.
- SY0-801 with weights of 16, 24, 19, 27 and 14 per cent means V8
- SY0-701 with weights of 12, 22, 18, 28 and 20 per cent means V7
- 27 objectives means V8; 28 means V7
- Any other code, such as SY0-601, means an older exam altogether
V7 material is not worthless if you move to V8. Most of Domains 3, 4 and 5 map one to one, and core topics such as cryptography, change management and incident response carry over. Keep what teaches them well. Then add a V8 source for objective 2.6, re-sort mitigation under operations and relabel your notes.
Practice tests are different. A question bank on V7 weights over-tests governance and under-tests concepts for a V8 candidate. Its scores tell you less than they seem to, so replace it with one built on SY0-801.
Which version you should sit is a separate decision, driven by your start date, weekly hours and language. V7 or V8: which Security+ exam to take sets out that rule.
What to do this week
Download the SY0-801 exam objectives from comptia.org. Check the version number, the domain weights and the launch date before you buy anything else. Then rate yourself from 1 to 5 on all 27 objectives. Your five lowest scores become the first targets in your plan.
If you have not seen the objectives in plain English yet, the Security+ exam format and domains map lays out all 27 with the question formats. How many hours to study for Security+ then turns your new split into weeks.
Chapter 5 of the book sets every V8 objective beside its closest V7 match, ready to rate. Appendix B turns the result into a dated weekly plan. The weights have moved once, so your plan only needs to move once, provided you move it now.
- Open your course or question bank and find its domain weights: 12, 22, 18, 28 and 20 per cent means it was written for V7.
- Download the SY0-801 exam objectives from comptia.org and check the version number, weights and launch date.
- Rate yourself from 1 to 5 on all 27 V8 objectives and mark your five lowest scores.
- Re-split your study hours on the V8 weights and give objective 2.6, AI threats, its own slot.
Questions readers ask
How should I show which version I passed on my CV?
Does CompTIA recommend different experience for V8?
Will V8 be available in my language at launch?
Can I use CompTIA's CertMaster hour estimates for V8?
- CompTIA Security+ page
- SY0-801 exam objectives
- SY0-701 exam objectives
This guide is independent and is not endorsed by CompTIA. Facts change: confirm them on the official page before you act.