- The IIBA-CCA exam is 75 knowledge-based questions in 90 minutes, scored pass/fail.
- Data Security and User Access Control tie as the heaviest domains at 15% each.
- Non-member exam fee is USD 405 and includes first-year IIBA membership; members pay USD 250.
- Once purchased, the exam must be scheduled and completed within 6 months.
Quick Facts Snapshot
Before diving into domain-level detail, bookmark this section as your last-minute reference. The Certificate in Cybersecurity Analysis (CCA) is issued by the International Institute of Business Analysis (IIBA) in collaboration with the IEEE Computer Society, under the official designation IIBA-CCA. Everything below comes straight from the 2026 IIBA-CCA Handbook and IIBA's certification pages - no guesswork, no borrowed facts from unrelated "CCA" credentials.
| Item | Detail |
|---|---|
| Certifying body | IIBA, in collaboration with IEEE Computer Society |
| Delivery method | PSI online remote-proctored exam |
| Question count / time | 75 knowledge-based multiple-choice questions / 90 minutes |
| Exam fee (member / non-member) | USD 250 / USD 405 (non-member fee includes first-year membership) |
| Retake fee (member / non-member) | USD 195 / USD 350 |
| Learning + exam package | USD 395 (member) / USD 550 (non-member) |
| Time to complete after purchase | 6 months |
| Scoring | Pass/Fail |
| Renewal requirement | None - certificate does not expire |
For a deeper narrative walkthrough of every number here, see the CCA Certification Cost breakdown and the CCA Exam Dates guide for scheduling logistics.
The Eight Domains at a Glance
The CCA blueprint is organized into eight examination domains - not to be confused with the nine courses in IIBA's optional learning program, which cover the same ground but are structured differently for teaching purposes. Only the eight domains below determine question distribution on exam day.
Domain 1: Cybersecurity Overview and Basic Concepts (14%)
Foundational vocabulary, the CIA triad, threat actors, and how security fits into overall business risk posture.
- Know the difference between threats, vulnerabilities, and risks
Domain 2: Enterprise Risk (14%)
Risk assessment frameworks, risk appetite, and how organizations prioritize security investment.
- Understand qualitative vs. quantitative risk scoring
Domain 3: Cybersecurity Risks and Controls (12%)
Mapping specific risks to preventive, detective, and corrective controls.
- Be able to classify a control by its function, not just its name
Domain 4: Securing the Layers (5%)
The smallest domain by weight, but still testable - covers defense-in-depth across network, application, and endpoint layers.
- Don't skip it just because it's low-weighted; every question counts equally
Domain 5: Data Security (15%)
Tied for the largest domain. Focuses on data classification, encryption concepts, and protecting data at rest and in transit.
- Expect scenario questions on data handling and classification tiers
Domain 6: User Access Control (15%)
Also tied for the largest domain. Covers authentication, authorization models, and identity management principles.
- Know the difference between authentication and authorization cold
Domain 7: Solution Delivery (13%)
Security considerations woven into project and solution delivery lifecycles.
- Connect security requirements to business analysis deliverables
Domain 8: Operations (12%)
Day-to-day security operations, monitoring, and incident response basics.
- Understand the operational handoff from design to running state
For a full narrative explanation of each domain with example question styles, read the CCA Exam Domains 2026 guide.
Exam Mechanics: Format, Fees, and Delivery
The CCA exam is delivered remotely through PSI's online proctoring platform. There's no test-center visit required, but the remote setup has strict requirements: valid identification, a compatible computer, working webcam and microphone, and a secure, private testing environment. No reference materials, no calculator, and no scheduled break are permitted during the 90-minute session.
All 75 questions are knowledge-based multiple-choice - there are no simulations, no case studies requiring written responses, and no adaptive question logic. This single-format consistency is one reason candidates find the exam predictable to prepare for once they understand the domain weighting. For a candid assessment of exam difficulty relative to preparation time, see How Hard Is the CCA Exam?
Key Takeaway
Practice under timed, no-reference conditions before exam day - the remote proctoring rules mean you cannot pause, consult notes, or use a calculator once the clock starts.
Registration and Time Limits
Fee structure matters more than most candidates expect, because it changes based on IIBA membership status:
- Exam only, member: USD 250
- Exam only, non-member: USD 405 (this includes first-year IIBA membership, so it isn't purely a "non-member penalty")
- Retake, member: USD 195
- Retake, non-member: USD 350
- Learning + exam package, member: USD 395
- Learning + exam package, non-member: USD 550
Once you purchase the exam, you have 6 months to schedule and complete it. Miss that window and you'll need to repurchase. This is a hard operational detail worth writing on a calendar the day you register - see the CCA Exam Dates guide for scheduling strategy around this deadline.
Note also that the optional learning program is exactly that - optional. Candidates are not required to complete any course to sit the exam, though they must agree to IIBA's ethics and professional standards as part of registration. For a full eligibility rundown, check CCA Requirements 2026.
Must-Know Topics by Weight
Rather than treating all eight domains equally, allocate review time proportionally. Here's a simplified priority order based purely on official domain weighting:
- Data Security (15%) - classification schemes, encryption concepts, data lifecycle protection
- User Access Control (15%) - authentication vs. authorization, identity management models
- Cybersecurity Overview and Basic Concepts (14%) - core terminology, CIA triad, threat landscape
- Enterprise Risk (14%) - risk assessment methods, organizational risk appetite
- Solution Delivery (13%) - security embedded in delivery lifecycles
- Cybersecurity Risks and Controls (12%) - control types mapped to specific risks
- Operations (12%) - monitoring, incident response fundamentals
- Securing the Layers (5%) - defense-in-depth across technical layers
Notice how tight the top seven domains are - all between 12% and 15%. Only Domain 4 stands apart as clearly lighter. This means a scattergun "study everything equally" approach is close to correct, with one adjustment: don't let Securing the Layers eat disproportionate time relative to its 5% share.
Final-Week Review Schedule
Generic study techniques like spaced repetition or timed drills only matter if they're pointed at the right material. Here's how the final stretch before a CCA attempt should be sequenced, tied directly to domain weight:
Heavyweight Domains
- Deep review of Data Security and User Access Control (30% combined)
- Practice questions focused on classification and authentication scenarios
Foundational and Risk Domains
- Cybersecurity Overview basics and Enterprise Risk frameworks
- Drill terminology until definitions are automatic, not approximate
Delivery, Controls, Operations
- Solution Delivery, Risks and Controls, and Operations review
- Timed practice sets mimicking the 90-minute, no-break format
Light Pass and Logistics
- Quick pass through Securing the Layers
- Confirm webcam, ID, and testing environment for PSI proctoring
For a longer-horizon prep plan spanning weeks rather than days, see the CCA Study Guide 2026. And if you want to gauge realistic pass expectations before you commit to a date, review the CCA Pass Rate data.
Who Hires CCA Holders
The CCA sits at the intersection of business analysis and security practice, which shapes who values it. Because IIBA co-developed it with the IEEE Computer Society, it's positioned for professionals who translate security requirements into business and delivery decisions - not purely technical penetration-testing roles. Business analysts moving into security-adjacent work, risk analysts, and delivery-side professionals responsible for embedding security into projects are the natural audience.
If you're evaluating whether this credential fits your career trajectory, or comparing it against your current role's requirements, the Is the CCA Certification Worth It? ROI Analysis and CCA Salary Guide articles go deeper on positioning. You can also browse CCA Jobs for a sense of how the credential appears in job postings.
Common Mix-Ups to Avoid
Because "CCA" is used by several unrelated credentials across different industries, and because IIBA's own materials reference both "eight domains" and "nine courses," a few mix-ups are worth flagging explicitly:
- Domains vs. courses: The exam blueprint has 8 domains; the optional learning program has 9 courses. They cover overlapping content but aren't a 1:1 map - don't assume course order equals domain order.
- Member vs. non-member fees: The non-member exam fee (USD 405) already bundles first-year membership; it's not simply a markup.
- Pass/fail scoring: There's no numeric score report - only pass/fail. Don't expect a percentile breakdown after the exam.
- Time window: The 6-month completion window starts at purchase, not at your intended test date.
If you've landed here after searching general terms about the acronym itself, our companion explainer pages - What Is CCA?, CCA Meaning, What Does CCA Stand For?, What Is A CCA?, and What Does CCA Mean? - clarify exactly which credential this site covers and why. For the certification itself, see CCA Certification and What Is CCA Certification?.
Once you're confident on scope, you can practice against realistic scenario-style questions on our main CCA practice test platform, which mirrors the domain weighting described above. Structured CCA Training resources and repeated runs through the practice tests are the most direct way to convert this cheat sheet into exam-day readiness.
FAQ
The exam contains 75 knowledge-based multiple-choice questions, and you have 90 minutes to complete it, with no scheduled break.
Data Security and User Access Control are tied as the largest domains, each worth 15% of the exam.
No. The learning program is optional; candidates only need to agree to IIBA's ethics and professional standards to sit the exam.
The purchased exam must be completed within 6 months of purchase. If that window lapses, you'll need to purchase the exam again.
No. The certificate does not expire and requires no recertification or continuing development units (CDUs) once earned.