- The 2026 IIBA-CCA Blueprint at a Glance
- How the Eight Domains Are Weighted
- Domain 1: Cybersecurity Overview and Basic Concepts
- Domain 2: Enterprise Risk
- Domain 3: Cybersecurity Risks and Controls
- Domain 4: Securing the Layers
- Domain 5: Data Security
- Domain 6: User Access Control
- Domain 7: Solution Delivery
- Domain 8: Operations
- Question Style, Format, and Registration Mechanics
- Mapping the Domains to a Study Schedule
- Who Hires for These Domains
- FAQ
- The 2026 IIBA-CCA Handbook defines eight exam domains, not the nine courses in the optional learning program.
- Data Security and User Access Control are the heaviest domains at 15% each.
- Securing the Layers is the lightest domain at just 5% of the 75 questions.
- The exam is 75 knowledge-based multiple-choice questions in 90 minutes, delivered via PSI remote proctoring.
The 2026 IIBA-CCA Blueprint at a Glance
Every question on the Certificate in Cybersecurity Analysis (CCA) exam traces back to a single source document: the 2026 IIBA-CCA Handbook published by the International Institute of Business Analysis (IIBA) in collaboration with the IEEE Computer Society. That handbook breaks the exam content into eight domains, each carrying a specific percentage weight of the 75 knowledge-based multiple-choice questions you'll see on test day.
If you've browsed the optional learning program, you may have noticed it's organized into nine courses. That's a separate structure. The exam blueprint uses eight domains, and it's the domains - not the course numbering - that determine how questions are distributed. Mixing the two up is one of the most common early mistakes candidates make when they start building a study plan, so it's worth bookmarking this distinction before you go any further.
How the Eight Domains Are Weighted
Weighting matters because it tells you where to invest your limited study hours. A domain worth 15% of the exam deserves noticeably more attention than one worth 5%, even if the 5% domain feels more technically interesting. Here's the full breakdown from the handbook:
| Domain | Weight | Approx. Questions (of 75) |
|---|---|---|
| 1. Cybersecurity Overview and Basic Concepts | 14% | ~11 |
| 2. Enterprise Risk | 14% | ~11 |
| 3. Cybersecurity Risks and Controls | 12% | ~9 |
| 4. Securing the Layers | 5% | ~4 |
| 5. Data Security | 15% | ~11 |
| 6. User Access Control | 15% | ~11 |
| 7. Solution Delivery | 13% | ~10 |
| 8. Operations | 12% | ~9 |
Notice that Data Security and User Access Control tie as the two heaviest domains, together accounting for roughly 30% of the exam. Securing the Layers, by contrast, is the smallest domain by a wide margin. For a deeper walkthrough of how these weights translate into study hours, see our CCA Study Guide 2026: How to Pass on Your First Attempt.
Domain 1: Cybersecurity Overview and Basic Concepts (14%)
What this domain covers
This is the foundational domain - vocabulary, core principles, and the mental model everything else builds on. Expect questions on fundamental security concepts, the CIA triad (confidentiality, integrity, availability), threat and vulnerability terminology, and how cybersecurity fits inside broader business analysis and enterprise contexts.
- Core security terminology and definitions used consistently across the other seven domains
- The relationship between cybersecurity work and business analysis practice
- Basic classification of threats, vulnerabilities, and assets
Because this domain underpins the other seven, candidates who rush through it often struggle later with questions that assume fluency in this baseline language.
Domain 2: Enterprise Risk (14%)
What this domain covers
Enterprise Risk tests your ability to think at the organizational level - identifying, assessing, and prioritizing risk across a business rather than at the level of a single system or control.
- Risk identification and assessment frameworks applied to enterprise environments
- Prioritization logic: which risks get addressed first and why
- How risk appetite and business context shape security decisions
Tied with Domain 1 at 14%, Enterprise Risk is one of the four domains that together make up more than half the exam, alongside Data Security, User Access Control, and Cybersecurity Overview.
Domain 3: Cybersecurity Risks and Controls (12%)
What this domain covers
Where Domain 2 stays at the enterprise level, Domain 3 moves into the specific risks organizations face and the controls used to mitigate them.
- Common categories of cybersecurity risk and how they manifest technically
- Matching control types to the risks they're designed to reduce
- Evaluating control effectiveness in a given scenario
Domain 4: Securing the Layers (5%)
What this domain covers
At only 5%, Securing the Layers is the smallest domain on the exam - roughly four questions. It focuses on the layered, defense-in-depth approach to security architecture across network, application, and infrastructure layers.
- The concept of defense in depth and why security is applied in layers
- How different architectural layers (network, application, host) each carry distinct protections
Domain 5: Data Security (15%)
What this domain covers
Tied for the single largest domain on the exam, Data Security deserves top priority in any study plan. It covers protecting data across its lifecycle - at rest, in transit, and in use.
- Data classification and handling requirements
- Encryption concepts and where they apply across the data lifecycle
- Data loss prevention and privacy-related considerations
Key Takeaway
Because Domain 5 and Domain 6 together represent 30% of the exam, candidates who master data security and access control concepts build a strong floor under their overall score before tackling smaller domains.
Domain 6: User Access Control (15%)
What this domain covers
The other largest domain, User Access Control, tests how identity, authentication, and authorization are managed to keep systems and data protected from unauthorized use.
- Authentication mechanisms and identity verification concepts
- Authorization models and the principle of least privilege
- Access provisioning, review, and de-provisioning practices
Given that Data Security and User Access Control combined make up nearly a third of the exam, candidates preparing with our CCA Cheat Sheet 2026: One-Page Review of Must-Know Facts should expect these two domains to dominate their final review pass.
Domain 7: Solution Delivery (13%)
What this domain covers
Solution Delivery examines how security is built into the process of designing, developing, and deploying solutions - a natural fit given the certification's roots in business analysis practice.
- Integrating security requirements into solution design and delivery
- Secure development lifecycle considerations
- Stakeholder and requirements-gathering practices as they relate to security outcomes
Domain 8: Operations (12%)
What this domain covers
The final domain covers the day-to-day operational side of cybersecurity - the ongoing activities that keep systems secure after they've been designed and deployed.
- Monitoring and detection activities in ongoing operations
- Incident response fundamentals
- Operational maintenance of controls established in earlier domains
If you're still deciding whether the certification aligns with your background before diving into domain-level prep, our overview of CCA Requirements 2026: Eligibility, Prerequisites & How to Qualify is a useful starting point.
Question Style, Format, and Registration Mechanics
All 75 questions on the CCA exam are knowledge-based multiple choice, delivered in a 90-minute window through PSI's remote-proctored online platform. There's no case-study essay component and no simulation environment - every question draws directly from the eight domains above, weighted according to the percentages in the table earlier in this guide.
Registration and retake economics are worth understanding before you schedule anything:
- Standard exam fee: USD 250 for IIBA members, USD 405 for non-members (the non-member price includes first-year membership)
- Retake fee: USD 195 for members, USD 350 for non-members
- Optional learning-and-exam bundle: USD 395 for members, USD 550 for non-members
- Once purchased, the exam must be completed within 6 months
- Remote delivery requires ID verification, a compatible computer, webcam, microphone, and a private testing space; no reference materials, calculator, or break is permitted during the 90 minutes
Results are reported strictly as pass/fail, with no numeric score breakdown by domain provided afterward. That makes pre-exam self-assessment against the domain weights especially important - you won't get a post-exam report telling you which domains cost you the most points. For the full pricing picture including the learning package, see our CCA Certification Cost 2026: Complete Pricing Breakdown, and for scheduling logistics check CCA Exam Dates 2026: Testing Windows, Deadlines & Scheduling.
Mapping the Domains to a Study Schedule
Rather than studying all eight domains in the order they appear in the handbook, sequence your review by weight and dependency. Domain 1 builds vocabulary everything else relies on, so it belongs first; the two 15% domains deserve dedicated weeks of their own; and the 5%-weighted Domain 4 can be compressed into a single short session near the end.
Foundations
- Domain 1: Cybersecurity Overview and Basic Concepts
- Domain 2: Enterprise Risk
Risk and Controls
- Domain 3: Cybersecurity Risks and Controls
- Domain 4: Securing the Layers (short session)
The heavyweight domains
- Domain 5: Data Security
- Domain 6: User Access Control
Delivery, operations, and full review
- Domain 7: Solution Delivery
- Domain 8: Operations
- Full-length timed practice run
Whatever pace you use, take at least one full 75-question, 90-minute simulation before test day so the timing feels routine rather than rushed. Our CCA practice tests mirror the domain weighting shown above, which makes them a realistic way to gauge readiness before you spend the registration fee. If you're still weighing how demanding the exam actually is relative to your background, How Hard Is the CCA Exam? Complete Difficulty Guide 2026 walks through that in more depth, and CCA Passing Score 2026: Exactly What You Need to Pass explains how the pass/fail threshold is applied.
Who Hires for These Domains
The domain structure isn't arbitrary - it reflects the blended skill set employers look for when hiring analysts who sit between business requirements and technical security controls. Roles that value this mix typically span security analyst, risk analyst, business analyst with a security focus, and IT governance positions where someone needs to translate Enterprise Risk and Cybersecurity Risks and Controls thinking into Solution Delivery and Operations practices that technical teams can implement.
Because the certification is issued through the IIBA in partnership with the IEEE Computer Society, it tends to resonate most with candidates who already work in or near business analysis and want a credential that formally validates cybersecurity literacy without requiring a purely technical background. For a broader look at how the credential is positioned in the job market, see CCA Jobs and Is the CCA Certification Worth It? Complete ROI Analysis 2026.
Frequently Asked Questions
Eight. The 2026 IIBA-CCA Handbook defines eight exam domains, ranging from 5% to 15% weight each, totaling the 75 questions on the exam.
No. The exam blueprint uses eight weighted domains, while the optional learning-and-exam package is organized into nine courses. They cover related material but are structured differently.
Data Security and User Access Control are tied as the largest domains at 15% each, together representing close to a third of the 75-question exam.
Securing the Layers is the smallest domain at 5%. Don't skip it entirely, but don't let it consume study time better spent on the 15%-weighted domains.
No. Results are reported as pass/fail only, with no domain-level score breakdown, which is why self-assessment against the domain weights before test day matters so much.