- CCA stands for Certificate in Cybersecurity Analysis, issued as IIBA-CCA by IIBA with the IEEE Computer Society.
- The exam has 75 knowledge-based multiple-choice questions in 90 minutes, delivered via PSI remote proctoring.
- Data Security and User Access Control are the heaviest domains, each worth 15% of the exam.
- Members pay USD 250 for the exam; non-members pay USD 405, which includes first-year IIBA membership.
What CCA Means
CCA stands for Certificate in Cybersecurity Analysis, a credential developed by the International Institute of Business Analysis (IIBA) in collaboration with the IEEE Computer Society. Its official designation is IIBA-CCA, which is the label you'll see on the certificate itself, on LinkedIn badges, and inside the IIBA certification directory. If you've landed on this page wondering what the acronym actually unpacks to, the short version is: it's not a job title, it's not a security clearance level, and it's not one of the several other "CCA" credentials floating around other industries. It is a knowledge-based certification aimed at professionals who need to analyze, assess, and communicate cybersecurity risk within a business context.
For a broader introduction to the credential beyond just the acronym, see What Is CCA? and CCA Certification. This article focuses specifically on unpacking the name, the organization behind it, and what earning it actually signals to employers.
Who Issues the CCA and Why It Matters
The meaning of an acronym is only half the story - the other half is who stands behind it. The CCA is issued by IIBA, the same organization known for business analysis certifications, working jointly with the IEEE Computer Society, a technical standards body with deep roots in computing and engineering. That pairing shapes what the certificate actually tests: it isn't a pure penetration-testing or hands-on security-operations exam. It's built for people who sit at the intersection of business analysis and cybersecurity - translating risk, controls, and technical safeguards into decisions the organization can act on.
This lineage explains why the exam blueprint reads the way it does. Rather than deep-diving into a single technical stack, it spans risk, controls, data protection, access management, and delivery - the full analytical picture a business analyst or risk-adjacent professional needs. If you want the full designation history and background, What Does CCA Stand For? covers the naming and organizational details in more depth.
What the Letters Translate To on Exam Day
Understanding what CCA means also means understanding what earning it actually requires. The exam itself is straightforward in structure:
- 75 knowledge-based multiple-choice questions
- 90 minutes total time
- Delivered through PSI as a remote-proctored exam
- Results reported as a simple pass/fail - no scaled score is published
- No calculator, reference materials, or breaks permitted during the session
Because it's remote-proctored, candidates need a compatible computer, a working webcam and microphone, valid identification, and a secure, private testing environment for the full 90 minutes. There's no walking away for a stretch break mid-exam, so treat the session as a single uninterrupted sprint. For the mechanics of scheduling and what to expect logistically, CCA Exam Dates 2026: Testing Windows, Deadlines & Scheduling walks through the scheduling flow in detail.
Once you purchase the exam, you have a six-month window to sit for it - plan your prep timeline around that deadline rather than an open-ended calendar.
Key Takeaway
Book your PSI exam slot only after you have a realistic six-month study runway mapped out - the purchase window doesn't reset, and letting it lapse means paying again.
The Meaning Behind Each Domain
The "Cybersecurity Analysis" part of the name is best understood through the eight domains that make up the 2026 IIBA-CCA Handbook blueprint. These domains are what the exam actually measures - memorizing the acronym is meaningless without knowing what each domain demands.
Domain 1: Cybersecurity Overview and Basic Concepts (14%)
Foundational terminology, the CIA triad, threat actors, and how cybersecurity fits into overall business risk conversations.
- Core vocabulary examiners expect you to use precisely
Domain 2: Enterprise Risk (14%)
How organizations identify, assess, and prioritize cybersecurity risk at a strategic level.
- Risk assessment frameworks and business impact reasoning
Domain 3: Cybersecurity Risks and Controls (12%)
Mapping specific risks to the controls designed to mitigate them.
- Control categories and how they reduce specific attack vectors
Domain 4: Securing the Layers (5%)
The smallest domain, but still testable - covers layered security across network, application, and physical layers.
- Defense-in-depth reasoning across infrastructure layers
Domain 5: Data Security (15%)
One of the two largest domains. Focuses on protecting data at rest, in transit, and in use.
- Encryption concepts, classification, and data lifecycle protections
Domain 6: User Access Control (15%)
The other largest domain, tied with Data Security. Covers identity, authentication, and authorization models.
- Access control models and privilege management principles
Domain 7: Solution Delivery (13%)
Security considerations woven into how solutions are designed, built, and deployed.
- Secure development and delivery lifecycle concepts
Domain 8: Operations (12%)
Day-to-day security operations, monitoring, and incident response fundamentals.
- Operational monitoring and response workflows
Because Data Security and User Access Control together account for 30% of the exam, those two domains deserve outsized attention in your prep. For a full walk-through of every domain with sample question angles, see CCA Exam Domains 2026: Complete Guide to All 8 Content Areas. Note also that these eight exam domains are distinct from the optional learning program's nine courses - don't confuse a course outline with the actual exam blueprint.
| Domain | Weight |
|---|---|
| Data Security | 15% |
| User Access Control | 15% |
| Cybersecurity Overview and Basic Concepts | 14% |
| Enterprise Risk | 14% |
| Solution Delivery | 13% |
| Cybersecurity Risks and Controls | 12% |
| Operations | 12% |
| Securing the Layers | 5% |
Registration, Fees, and Mechanics
Part of what "CCA" means in practice is understanding the cost structure, because IIBA prices it differently for members versus non-members:
- Exam fee: USD 250 for IIBA members, USD 405 for non-members (the non-member price includes first-year membership)
- Retake fee: USD 195 for members, USD 350 for non-members
- Optional learning-and-exam package: USD 395 for members, USD 550 for non-members
The learning program itself is optional - you are not required to take a course to sit the exam, but candidates do agree to IIBA's ethics and professional standards as part of registration. For the complete pricing picture, including how the bundled package compares to buying the exam alone, read CCA Certification Cost 2026: Complete Pricing Breakdown. And for the exact requirements and eligibility questions candidates ask before registering, check CCA Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Who Actually Earns the CCA
Given its business-analysis lineage, the CCA tends to attract people who work adjacent to security teams rather than deep technical security specialists exclusively. That includes business analysts moving into risk and security functions, IT auditors, compliance and governance professionals, project and product managers who need cybersecurity fluency, and early-career security analysts who want a credential that validates broad analytical knowledge rather than a narrow technical skill. Because the exam spans risk, controls, data protection, access management, and operations rather than one specialty, it functions well as a bridge credential for people translating between technical teams and business stakeholders.
If you're evaluating whether this fits your career path, Is the CCA Certification Worth It? Complete ROI Analysis 2026 and CCA Jobs both dig into where the credential shows up in job postings and how it's positioned relative to adjacent roles. For a sense of what the credential can mean for compensation conversations, see CCA Salary Guide 2026: Complete Earnings Analysis.
Turning the Acronym Into a Study Plan
Knowing what CCA stands for is step one; converting the eight domains into a workable prep schedule is step two. A simple way to sequence study time is to weight it against domain percentages rather than splitting effort evenly across all eight areas.
Foundations
- Cybersecurity Overview and Basic Concepts
- Enterprise Risk
Controls and Layers
- Cybersecurity Risks and Controls
- Securing the Layers
Highest-Weight Domains
- Data Security
- User Access Control
Delivery, Operations, and Review
- Solution Delivery
- Operations
- Full-length practice questions under timed conditions
Since Data Security and User Access Control combine for 30% of the exam, they earn a dedicated week rather than being folded into general review. For a more detailed, day-by-day breakdown geared toward passing on the first attempt, see CCA Study Guide 2026: How to Pass on Your First Attempt. If you're unsure how much difficulty to expect from the question style, How Hard Is the CCA Exam? Complete Difficulty Guide 2026 covers that in depth, and CCA Passing Score 2026: Exactly What You Need to Pass explains how pass/fail results are determined.
Running timed practice questions through a full-length practice test platform is one of the most direct ways to simulate the 90-minute, 75-question format before exam day, since the real PSI session won't allow any breaks once the clock starts.
Don't Confuse This CCA With Another One
Because "CCA" is a reused acronym across several unrelated industries, it's worth being explicit: on this site, and in this article, CCA refers exclusively to the IIBA-CCA - Certificate in Cybersecurity Analysis. If you encounter other content online using "CCA" attached to different exam fees, different domain structures, or different certifying bodies, that content is describing a different credential entirely, not this one. Always cross-check details against the official IIBA handbook and fee pages before relying on any secondary source.
For more foundational definitions using slightly different search phrasing, see What Is A CCA?, What Does CCA Mean?, and What Is CCA Certification? - all describing this same Certificate in Cybersecurity Analysis. You can also explore structured coursework options through CCA Training if you're weighing the optional learning package against self-study, and revisit CCA Exam Prep's practice tests as your primary readiness check before booking the PSI session.
Frequently Asked Questions
CCA stands for Certificate in Cybersecurity Analysis, officially designated IIBA-CCA, issued by IIBA in collaboration with the IEEE Computer Society.
No. This CCA refers specifically to IIBA's Certificate in Cybersecurity Analysis. Other industries use the same three letters for unrelated credentials with different exam structures and fees.
It contains 75 knowledge-based multiple-choice questions administered over 90 minutes through PSI's remote-proctored testing platform, with results reported as pass or fail.
No. Once earned, the CCA does not expire and requires no recertification or continuing development units (CDUs).
No. The learning program is optional. Candidates can purchase the exam alone or choose the bundled learning-and-exam package.