Blog4 min read
Your Security+ Expires in Three Years. Here Is What Renews It.
Renewing Security+ takes 50 CEUs in a three-year cycle. The routes that finish it in one activity, the ones capped well short, and what CompTIA rejects.
Passing Security+ is not the end of paperwork. The certification lasts three years, starting from the day you pass. Renewal costs 50 continuing education units (CEUs) and a fee. Fifty is more than it sounds. Plan for it. Here's what counts toward those 50, what doesn't, and the one route that can finish the whole thing in a single activity.
Three ways to renew with no CEUs
CompTIA lists three ways to renew the certification that don't involve submitting any activities. No tallying and no waiting on a reviewer.
The first is a CertMaster CE course. CompTIA calls it the fastest option, and Security+ is one of only three certifications it covers, alongside A+ and Network+. The course fee includes the CE fee, which is not nothing. Holders of the higher certifications can't use this route, so renewing SecurityX is harder than renewing Security+.
The second is passing the newest version of the exam. Sitting the current Security+ again renews it on the spot, which is worth knowing before you book anything else.
The third is earning a higher-level CompTIA certification. It applies to some certifications and not others. Read your own renewal requirements instead of assuming.
Everything else? That means earning CEUs and uploading proof of every one of them.
Fifty units, and the rules that decide them
So what counts? Five kinds of activity:
- training and higher education
- IT industry participation
- non-CompTIA certifications
- publishing
- related work experience
Three conditions apply to all five. Miss one, and the activity is worthless.
Timing. The activity has to happen within your three-year cycle. Something you did before you certified is useless here.
Relevance. At least half the content must relate to the exam objectives you are renewing against. CompTIA is clear that it looks at both topics and the cognitive level of the material. If you can't point at the objective a course maps to, that's your answer.
Documentation. Every activity needs paper. Paperwork is where most submissions fail, and it fails them at the last step, after the studying and the money are already spent.
The caps are the part people miss
Here's the catch. A live webinar earns one CEU per hour, which sounds good until you read the ceiling. So, how far do webinars get you? Not far at all. They are capped at 10 CEUs for Security+, conferences carry the same cap of 10, and sitting through webinars until the number goes up quietly tops out at a fifth of what you actually need.
There is no such ceiling on a training course. One CEU per hour, up to the full 50, and a college course is worth 10 CEUs for each three to four credit-hour class, so five classes would cover the whole requirement between them. Teaching or mentoring earns one CEU an hour and caps at 20. Creating instructional materials earns two CEUs an hour and also caps at 20. Sitting in a CompTIA exam development workshop as a subject matter expert has no cap and can cover the full 50 on its own.
There is a shortcut for anyone working under the Department of Defense, and it is the single biggest one on this page for the people it applies to. The DoD Cybersecurity Fundamentals and Cyberspace Operations Fundamentals courses are pre-approved and carry 25 CEUs for Security+. That's half the requirement in one submission. Worth checking before you pay for anything.
One certification can do the whole job
Were you going to sit another exam anyway? Then a qualifying non-CompTIA certification is the efficient route. CompTIA publishes an approved list per certification, and for Security+, most entries are worth the full 50. These all sit there at 50, which is really the entire renewal in one activity:
- CISSP
- CISA and CISM
- SSCP
- CEH
- AWS Certified Security Specialty
- the CCNP Security exams
Read the list. The numbers are not uniform. Microsoft Certified: Security Operations Analyst Associate appears at 38 CEUs, not 50. It is a qualifying certification that still leaves you 12 short.
What gets rejected
So what does CompTIA actually want to see? It is specific about proof, and specific in a way that catches people who did the work but lost the renewal on the evidence.
For a certification, submit the certificate or the badge link issued by the certifying body. It has to show your name and the exact name of the certification. The date goes on there too. Training completion certificates, score reports, and emails are not valid submissions for that activity.
For a webinar or a conference session, you need an outline of the content, plus either a completion certificate or the registration email. Your name and the session name have to appear on it, along with the date and the hours. On-demand webinars and YouTube videos count only if you can show proof of registration or completion, which is not something most YouTube watching produces.
The SY0-701 wrinkle
One date changes the arithmetic here. It matters most for anyone certified recently. The English SY0-701 exam retires on June 11, 2027. If your three-year window closes after that, the route of passing the newest version means sitting a different exam from the one you passed, against a different set of exam objectives. Nobody needs to panic about that. It is worth deciding early rather than in the last month, because a retake you planned for is a study project and a retake you didn't is a scramble.
Whichever route you pick, the CE fee applies unless the course price already covers it, and the submission has to be approved before your expiration date rather than on it. Three years feels very long right up until the final quarter of it.
If the exam route is the one you are heading for, the format is worth re-meeting early. Try a free performance-based question before you commit to a date.