IT training across Europe - tecnovy makes you future-ready.

CompTIA Cybersecurity Analyst (CySA+) Certification

An alert is not a finding. It is a line somebody has to assess, place and then either close or escalate, often under time pressure and with incomplete data. CompTIA CySA+ is the certification for exactly that work: detection, analysis, response, and the reporting afterwards. At 34 percent the largest part of the exam sits on security operations, which is the work that actually fills an ordinary day in a SOC.
Attendance certificate4.8/5 on ProvenExpert

What this module delivers.

Assessing alerts, prioritising vulnerabilities by risk, working incidents and reporting on them: that is CySA+. You work with data rather than plans, and your team then tells noise apart from real incidents.

How the training runs

Method
Four exam domains along the incident timeline
Outcome
Exam at Pearson VUE, fee not included

Dates & booking

Choose a date that fits

1 dates

  • EUREuro
  • USDUS Dollar
  • CHFSwiss Franc

Sessions with this symbol offer up to 25% group discount. Click “Details & Registration” to learn more.

05–08 Oct 2026CEST
Mon–Thu 09:00–17:00
Online training Group Discount
Time zone CEST
Language German
Trainer Michael Schmitz
Seats 5+ seats
10% Earlybird Discount

4,598 $−459 $4,139 $

excl. VAT

Fit

Who this module is designed for

Typical roles

  • You assess alerts from monitoring systems and decide what counts as an incident.
  • You prioritise vulnerabilities and justify which get closed first.
  • You report findings to both engineering and management in the same week.

Prerequisites

No prerequisites

You can start right away. What you need: English, because CS0-004 is so far only offered in English. Helpful: security fundamentals at CompTIA Security+ level, around four years of practice in analysis, monitoring or vulnerability management.

Consider instead CompTIA Security+ · CompTIA - Security+ (Plus) Certification Fits better if you want to place security first, before assessing alerts daily.

Curriculum

CompTIA CySA+ Curriculum in Detail

The course follows the four CS0-004 exam domains along the course of an incident: first day-to-day security operations, then vulnerability management, then the response to a concrete incident, and finally the reports others decide from.

01Security operations

At 34 percent the largest exam domain, and the basis for everything after it.

  • Reading system components and network architecture from a detection viewpoint
  • Analysing log, network and endpoint data as indicators
  • Translating threat intelligence into your own environment
  • Automating recurring checks instead of repeating them by hand
02Vulnerability management

The part where a long list becomes a justified order of work.

  • Planning and running scans, and reading their results critically
  • Recognising false positives before they cost effort
  • Prioritising by exploitability and by actual business impact
  • Tracking remediation and evidencing that it worked
03Incident response and management

What happens once an alert has become a confirmed incident.

  • The phases of incident response from preparation through to review
  • Containment, eradication and recovery in the right order
  • Preserving evidence so that it survives an investigation
  • Root cause analysis, so the same incident does not happen twice
04Reporting and communication

The smallest domain at 16 percent, and the one analytical work most often fails on.

  • Preparing findings differently for engineering and for management
  • Metrics that support a decision, rather than numbers that only impress
  • Reporting obligations and coordination with others during an incident
  • Wording recommendations so that they can actually be acted on
Official syllabus(external link)

Outcome

What you will be able to do afterwards

  1. 01

    You assess alerts by context and separate noise from real incidents.

  2. 02

    You analyse log and network data and evidence an attack path with it.

  3. 03

    You prioritise vulnerabilities by exploitability and business impact.

  4. 04

    You plan vulnerability scans and interpret their results critically.

  5. 05

    You carry out the incident response steps from containment through to recovery.

  6. 06

    You preserve evidence so that it survives a later investigation.

  7. 07

    You write findings up so that engineering and management can decide from them.

CompTIA Cybersecurity Analyst (CySA+)

CompTIA awards the certification once you pass the examination. It evidences analytical work: detection, assessment and response, rather than planning measures. Unlike the certificates of many other schemes this certification expires three years after you pass; you keep it valid with 60 continuing education units, or renew it by earning a higher CompTIA certification.

Certification terms comptia.org ↗

Examination

CompTIA CySA+ examination

750Pass mark, scale to 900

Questions
max. 85
Working time
165 min
Format
Multiple Choice + PBQ
Delivery
Pearson VUE / OnVUE
Exam language
EN

Pearson VUE administers the examination, not tecnovy, at a test centre or online proctored. At 165 minutes it is the longest on this board. Exam version as of August 2026: CS0-004; the previous CS0-003 retires in English on 22 December 2026.

Official examination rules comptia.org ↗

Proof of attendance

Certificate of participation

≥80%attendance

The tecnovy certificate of participation records your attendance of the CompTIA CySA+ training, not a passed CompTIA examination.

Sample of the tecnovy certificate of participation Open the Certificate Showroom tecnovy →

Offer scope

What the course price does not cover

Not included

  • Fee for the CompTIA examinationThe examination fee is not included in the seminar price, comes to around CHF 350 excl. VAT (about EUR 375) and can be added at the booking step, which shows the amount converted at the daily rate.

Trainers

Michael Schmitz

Michael Schmitz

Trainer & Coach

Why tecnovy

What you get on top with us

02

Certificate Showroom

Get your certificate of participation and, if you have one, add your exam certificate from E-Learning. Fully automated, beautifully designed. Just for you, only at tecnovy.

03

Flexible Date Change

If you are not able to attend the course, you can rebook your training free of charge up to one week before the start of the training.

04

Attend Twice, Pay Once

You are welcome to visit the training course online again within a year as a refresher or exam preparation.

05

Learn from Experts

We always guarantee you the use of didactically and methodically first-class qualified trainers who draw their knowledge from training experience as well as professional practical and project experience.

FAQs

Frequently asked questions

01Which exam version does the training cover?
The training follows CS0-004, the current version CompTIA released in June 2026. The previous version CS0-003 can still be sat in English until 22 December 2026.
02What language is the examination in?
CS0-004 is so far offered only in English; CompTIA announces French, Japanese, Spanish and Portuguese, with German not among them. The tecnovy training runs in German.
03What is the difference between CySA+ and Security+?
Security+ covers the breadth and addresses everyone who shares responsibility for security. CySA+ picks up afterwards and covers the analytical work: assessing alerts, prioritising vulnerabilities, working incidents and reporting on them.
04Do I need Security+ before CySA+?
No. CompTIA sets no formal prerequisites for any of its examinations. Security fundamentals and around four years of practice in analysis or monitoring are recommended.
05How long is the CompTIA CySA+ certification valid?
Three years from passing. You keep it valid with 60 continuing education units, the highest count among the CompTIA certifications at tecnovy, or renew it through a higher CompTIA certification.
06What happens if I do not pass the examination?
CompTIA requires no waiting period between the first and second attempt; from the third onwards there are 14 days between each. Every further attempt costs the examination fee again.
07What materials do I receive?
You receive the training materials for all four exam domains, plus a photo record of the flipcharts produced during the course, including the incident timelines you work through together.

What does your training at tecnovy look like?

CySA+CompTIA Cybersecurity Analyst (CySA+) Certification

Ready for the next step?

Choose a public date or plan the course for your team.

Feedback Form
What should we improve?

Tell us what we can do better next time.

Success
Error

© Copyright 2026, tecnovy GmbH, All Rights Reserved