CCA logo
Focused certification exam prep
Start practice

CCA Certification

TL;DR
  • IIBA-CCA is issued by IIBA in collaboration with the IEEE Computer Society, not a generic security vendor.
  • The exam is 75 knowledge-based multiple-choice questions in 90 minutes, delivered via PSI remote proctoring.
  • Data Security and User Access Control are tied as the heaviest domains at 15% each.
  • Member exam fee is USD 250; non-members pay USD 405, which includes first-year IIBA membership.

What Is the CCA Certification?

The Certificate in Cybersecurity Analysis (CCA) is a credential built for professionals who sit at the intersection of business analysis and cybersecurity - people who need to translate security risk into business language, and business requirements into secure design decisions. It is not a hands-on penetration testing badge or a network engineering certificate; it is a knowledge-based credential that validates your ability to analyze, communicate, and manage cybersecurity risk within an organizational context.

If you're still sorting out the basics, our companion pieces What Is CCA?, CCA Meaning, and What Does CCA Stand For? cover the terminology from the ground up. This article goes deeper into the mechanics - the domains, the fees, the format - that actually determine whether you pass.

Who Offers the IIBA-CCA and Why It Matters

The credential is administered by the International Institute of Business Analysis (IIBA) in collaboration with the IEEE Computer Society, and its official designation is IIBA-CCA. That pairing matters: IIBA brings its business-analysis rigor around requirements, stakeholder communication, and risk framing, while the IEEE Computer Society lends technical credibility on the cybersecurity content itself. This dual sponsorship is why the exam blends analytical thinking with concrete security controls rather than testing pure technical trivia.

Why the Sponsor Matters: Because IIBA-CCA sits under a business analysis body rather than a purely technical certifying organization, expect questions that test how you'd evaluate and communicate risk - not just whether you can recite a firewall configuration.

Exam Format: 75 Questions, 90 Minutes

The IIBA-CCA exam consists of 75 knowledge-based multiple-choice questions to be completed in 90 minutes. That works out to a little over a minute per question on average, which leaves limited room for second-guessing on any single item. Results are reported strictly as pass/fail - you won't receive a granular score breakdown by domain.

The 2026 IIBA-CCA Handbook is the authoritative source for the blueprint, and it's worth reading in full before you commit to a study timeline. For a broader look at how difficult candidates find the exam relative to its format, see How Hard Is the CCA Exam? Complete Difficulty Guide 2026, and for details on what score you actually need, check CCA Passing Score 2026: Exactly What You Need to Pass.

The Eight CCA Exam Domains

The CCA blueprint is organized into eight examination domains. This is a critical distinction: the exam has eight domains, while the optional learning program is structured around nine separate courses. Don't confuse the two when you're building a study plan.

Domain 1: Cybersecurity Overview and Basic Concepts - 14%

Foundational terminology, the CIA triad, threat actors, and how cybersecurity fits into overall business strategy.

  • Core vocabulary examiners assume you already know

Domain 2: Enterprise Risk - 14%

Risk identification, assessment, and treatment at an organizational level, including how risk appetite shapes security decisions.

  • Risk registers and enterprise risk frameworks

Domain 3: Cybersecurity Risks and Controls - 12%

Mapping specific threats to the controls designed to mitigate them, and understanding control categories.

  • Preventive, detective, and corrective control types

Domain 4: Securing the Layers - 5%

The smallest domain by weight, covering defense-in-depth concepts across network, application, and physical layers.

  • Layered security architecture basics

Domain 5: Data Security - 15%

Tied for the largest domain. Covers data classification, encryption concepts, data lifecycle protection, and privacy considerations.

  • How data is protected at rest, in transit, and in use

Domain 6: User Access Control - 15%

Also tied for the largest domain. Focuses on identity management, authentication, authorization models, and access governance.

  • Least privilege and role-based access concepts

Domain 7: Solution Delivery - 13%

How security is built into solution design and delivery, connecting back to the business-analyst lens of the credential.

  • Security requirements within delivery lifecycles

Domain 8: Operations - 12%

Ongoing operational security practices: monitoring, incident response fundamentals, and maintaining a secure posture over time.

  • Day-to-day operational security responsibilities

Key Takeaway

Because Data Security and User Access Control together represent 30% of the exam, they deserve the largest share of your study hours - but Securing the Layers at only 5% should not be ignored entirely, since every point counts on a pass/fail exam.

For a domain-by-domain breakdown with study angles for each, read CCA Exam Domains 2026: Complete Guide to All 8 Content Areas.

CCA Fees and Registration Mechanics

Understanding the fee structure upfront helps you avoid surprises during registration. Here's how the pricing breaks down:

ItemMember PriceNon-Member Price
Standard exam feeUSD 250USD 405 (includes first-year IIBA membership)
Retake feeUSD 195USD 350
Learning + exam packageUSD 395USD 550

Note that the non-member exam price bundles first-year IIBA membership, which partially explains the gap between the two tiers. Once you purchase your exam, you must complete it within 6 months - plan your study window accordingly. The learning program itself is optional; candidates are only required to agree to IIBA's ethics and professional standards, not to complete formal coursework. For a full pricing walkthrough including how the optional package compares to self-study, see CCA Certification Cost 2026: Complete Pricing Breakdown. If you're unsure whether you meet eligibility criteria before paying, review CCA Requirements 2026: Eligibility, Prerequisites & How to Qualify first.

Remote Proctoring Requirements

The IIBA-CCA exam is delivered through PSI as a remote-proctored test, which means you can sit for it from home or office rather than traveling to a test center. That convenience comes with strict technical and environmental requirements:

  • Valid government-issued identification for check-in
  • A compatible computer with a functioning webcam and microphone
  • A secure, private testing environment free from interruptions
  • No reference materials, calculators, or scheduled breaks permitted during the session

Because there is zero tolerance for outside materials or breaks, treat the 90-minute window as a single uninterrupted sprint. Test your equipment well ahead of your scheduled slot - connectivity or webcam failures during check-in can jeopardize your appointment. For scheduling windows and how far in advance to book, see CCA Exam Dates 2026: Testing Windows, Deadlines & Scheduling.

Who Hires CCA-Certified Professionals

Because the CCA sits between business analysis and cybersecurity, it tends to appeal to hybrid roles rather than purely technical security engineering positions. Typical fits include business analysts moving into security-adjacent projects, risk and compliance professionals who need a structured way to discuss cybersecurity controls with technical teams, IT auditors, and project or product professionals responsible for ensuring security requirements are captured during solution delivery.

Organizations that run formal business analysis practices - especially those in regulated industries handling sensitive data - are the most likely to recognize and value the credential, since it signals fluency in both risk language and control implementation. To explore concrete role titles and where the credential shows up in job postings, browse CCA Jobs, and for a broader discussion of compensation trends, see CCA Salary Guide 2026: Complete Earnings Analysis.

Mapping a Study Plan to the Domain Weights

Rather than following a generic study calendar, build your schedule around the actual domain weights. A simple, CCA-specific approach:

Week 1

Foundations and Risk

  • Domain 1: Cybersecurity Overview and Basic Concepts
  • Domain 2: Enterprise Risk
Week 2

Controls and Architecture

  • Domain 3: Cybersecurity Risks and Controls
  • Domain 4: Securing the Layers
Week 3

The Two Heaviest Domains

  • Domain 5: Data Security
  • Domain 6: User Access Control
Week 4

Delivery, Operations, and Review

  • Domain 7: Solution Delivery
  • Domain 8: Operations
  • Full-length timed practice runs at 75 questions / 90 minutes

Notice Week 3 is dedicated entirely to Data Security and User Access Control - together they carry 30% of the exam, more than any other pairing. Spaced repetition and active recall techniques can help here, but only if you apply them specifically to control types, access models, and data classification schemes rather than generic flashcards. For a more detailed week-by-week breakdown, read CCA Study Guide 2026: How to Pass on Your First Attempt, and once you're closer to test day, our CCA Cheat Sheet 2026: One-Page Review of Must-Know Facts condenses the eight domains into a single reference page. You can also run realistic timed drills on our practice test platform to get comfortable with the 90-minute pace before exam day.

Life After Passing: No Recertification

One of the more attractive features of the IIBA-CCA is what happens after you pass: the certificate does not expire, and there is no recertification cycle or continuing development units (CDUs) required to maintain it. Once earned, it stays on your credential list indefinitely, unlike many technical certifications that require periodic renewal fees and CDU tracking. This makes the upfront investment - whether at the member or non-member fee tier - a one-time decision rather than an ongoing subscription.

No Ongoing Maintenance: Because there's no recertification requirement, the entire value calculation for the CCA hinges on the exam fee and preparation time, not on years of future CDU costs.

How the CCA Compares to Related Learning Options

Candidates often ask whether the optional learning-and-exam package is worth the price difference over the standalone exam. The package bundles structured coursework across the nine learning-program courses with the exam voucher, which can be useful if you prefer guided instruction over self-directed study using the handbook and outside resources. Since the learning program is explicitly optional, self-study candidates are on equal footing for passing - the coursework isn't a prerequisite, just a preparation option.

If you're weighing whether pursuing the credential at all makes sense for your career stage, Is the CCA Certification Worth It? Complete ROI Analysis 2026 walks through that decision in more depth, and CCA Pass Rate 2026: What the Data Shows looks at what's publicly known about outcomes. For readers who found this page while researching the acronym generally, related explainers include What Is A CCA?, What Does CCA Mean?, and What Is CCA Certification?. If you decide to pursue formal instruction, CCA Training outlines available options, and CCA Certification offers a broader overview of the credential path. You can also start practicing domain-specific questions right away on our practice test platform.

Frequently Asked Questions

Who administers the CCA certification?

The IIBA-CCA is administered by the International Institute of Business Analysis (IIBA) in collaboration with the IEEE Computer Society. Exams are delivered remotely through PSI.

How many questions are on the CCA exam and how long do I have?

The exam contains 75 knowledge-based multiple-choice questions and must be completed within 90 minutes, with no scheduled breaks.

Which CCA exam domains carry the most weight?

Data Security and User Access Control are tied as the largest domains, each worth 15% of the exam, together representing 30% of total content.

Is the CCA learning program required to sit for the exam?

No. The learning program is optional. Candidates only need to agree to IIBA's ethics and professional standards to register for the exam itself.

Does the CCA certification expire?

No. The certificate does not expire and requires no recertification or continuing development units (CDUs) once you pass.

Ready to pass your CCA exam?

Put this into practice with free CCA questions across every exam domain.