CCA logo
Focused certification exam prep
Start practice

CCA Pass Rate 2026: What the Data Shows

TL;DR
  • IIBA does not publish an official CCA pass rate - treat any specific percentage you see online with skepticism.
  • The IIBA-CCA exam reports pass/fail only, with 75 questions in 90 minutes and no partial-credit visibility.
  • Data Security and User Access Control are each weighted at 15%, the two heaviest of the eight domains.
  • A failed attempt costs USD 195 (members) or USD 350 (non-members) to retake - plan your first attempt seriously.

Why There's No Official CCA Pass Rate

Anyone searching for a hard number on the Certificate in Cybersecurity Analysis (CCA) pass rate will run into the same wall: the International Institute of Business Analysis (IIBA), which administers the IIBA-CCA credential in collaboration with the IEEE Computer Society, does not publish pass-rate statistics for this exam. There is no annual report, no percentage breakdown by domain, and no historical trend chart on the official certification pages.

That absence is not an oversight - it is standard practice for many professional certification bodies that want candidates focused on mastering content rather than gaming a target score. If you see a specific pass-rate percentage attached to "CCA" on a third-party site, be cautious. It may be outdated, unverifiable, or worse, pulled from an entirely different certification that happens to share the same three-letter acronym. This article sticks strictly to what is verifiable about the IIBA-CCA exam itself.

Important Distinction: Because no official pass-rate figure exists for the IIBA-CCA exam, the most reliable way to gauge your odds is to study the exam's actual structure - question count, timing, and domain weighting - rather than search for a number that isn't published.

What Pass/Fail Score Reporting Actually Tells You

The CCA exam reports results as a simple pass or fail. You will not receive a scaled score, a percentile ranking, or a domain-by-domain breakdown of where you lost points. This matters for anyone trying to estimate difficulty from outside data, because there is no granular scoring history for researchers or bloggers to analyze in the first place - pass/fail reporting by design limits how much statistical insight can ever be extracted and published.

From a candidate's perspective, this reporting style has a practical implication: you cannot "cushion" a weak domain with points elsewhere and hope to see the tradeoff reflected in a nuanced score. You either demonstrate sufficient knowledge across the 75 knowledge-based multiple-choice questions or you don't. That reality should shape how you approach preparation - evenly across all eight domains rather than optimizing for a handful of favorite topics. The CCA Passing Score guide goes deeper into how the pass/fail threshold is structured.

Key Takeaway

Because scores are pass/fail only, treat every domain as equally "must-pass" in your preparation - there's no visible partial credit to lean on.

How Domain Weighting Shapes Who Passes

While IIBA doesn't publish pass-rate percentages, it does publish something arguably more useful: the exact weighting of each domain in the 2026 IIBA-CCA Handbook. That blueprint is the closest thing candidates have to a map of where the exam concentrates its difficulty and volume of questions.

Domain 5: Data Security (15%)

Tied for the heaviest domain on the exam. Candidates must understand data classification, encryption practices, and protection controls across the data lifecycle.

  • Highest-weighted domain alongside User Access Control
  • Directly tested through scenario-based multiple-choice items

Domain 6: User Access Control (15%)

The other heaviest domain. Expect questions on authentication, authorization models, identity management, and access governance.

  • Equal weight to Data Security - do not under-prepare either
  • Frequently overlaps conceptually with Domain 5 content

Beyond those two, Cybersecurity Overview and Basic Concepts and Enterprise Risk each carry 14%, Solution Delivery carries 13%, Cybersecurity Risks and Controls and Operations each carry 12%, and Securing the Layers is the lightest at 5%. That last figure is worth noting: it's easy to either overinvest or completely neglect a domain worth only 5%, and either mistake wastes study time relative to its weight on the exam. For a full breakdown of what each domain actually covers, see the CCA Exam Domains Guide.

DomainWeightRelative Priority
Data Security15%Highest
User Access Control15%Highest
Cybersecurity Overview and Basic Concepts14%High
Enterprise Risk14%High
Solution Delivery13%Moderate
Cybersecurity Risks and Controls12%Moderate
Operations12%Moderate
Securing the Layers5%Lowest

Exam Format Details That Influence Results

Format constraints shape outcomes just as much as content difficulty does. The CCA exam is delivered as a remote-proctored test through PSI, and the delivery rules are strict: candidates need valid identification, a compatible computer, a working webcam and microphone, and a secure, private testing environment. No reference materials, no calculator, and no break are permitted during the session.

You have 90 minutes to answer 75 knowledge-based multiple-choice questions - roughly 72 seconds per question on average, though knowledge-based items typically move faster than scenario-heavy ones once the material is internalized. There's no scratch-pad advantage, no open-book fallback, and no midway pause to recompose yourself. Candidates who underestimate the no-break, no-materials environment sometimes struggle more with pacing and fatigue than with the content itself. The How Hard Is the CCA Exam guide unpacks these logistics in more detail, and the official CCA Exam Dates guide covers scheduling specifics.

Format Reality Check: A fixed 90-minute window with zero breaks and no reference materials means time management and memorized fluency matter as much as raw knowledge - simulate this exact environment before exam day.

Who Sits the CCA Exam - and Why It Matters

Outcomes on any certification exam are shaped partly by who is taking it. The IIBA-CCA credential sits at the intersection of business analysis and cybersecurity, and it tends to attract business analysts adding security fluency, IT professionals moving toward governance and risk roles, and security-adjacent staff who need to speak the language of both worlds. Employers hiring for these hybrid roles - security analysts, risk and compliance coordinators, and IT governance staff - value candidates who can bridge technical controls with business risk conversations, which is exactly what the eight-domain blueprint tests.

Because candidates arrive with varied backgrounds - some strong on the technical side, others stronger on governance and process - no single "typical candidate profile" determines difficulty. Your personal starting point relative to domains like Data Security, User Access Control, and Enterprise Risk is a better predictor of your outcome than any aggregate statistic could be. If you're unsure whether this credential fits your career trajectory, the Is the CCA Certification Worth It analysis and the CCA Jobs overview are useful starting points, and the CCA Requirements guide confirms there are no rigid prerequisites blocking entry.

The Real Cost of Not Passing the First Time

Since no official pass-rate figure exists, the more actionable number to internalize is the cost of a retake. The standard exam fee is USD 250 for IIBA members and USD 405 for non-members - the non-member price includes first-year IIBA membership. If you don't pass, the retake fee is USD 195 for members and USD 350 for non-members. Candidates who prefer a bundled path can choose the optional learning-and-exam package, priced at USD 395 for members and USD 550 for non-members; note that the accompanying learning program is optional and organized into nine courses, which should not be confused with the exam's eight scored domains.

There's also a firm timeline constraint: once purchased, the exam must be completed within six months. That window is generous but not infinite - it's easy to let a busy quarter erase months of preparation time. For the complete fee structure, including how the retake and package pricing compares, see the CCA Certification Cost breakdown.

Key Takeaway

A failed attempt isn't just a scheduling setback - it's a USD 195-350 expense. Treat your first sitting as the only sitting you plan to need.

A Domain-Weighted Study Timeline

Rather than relying on a generic weekly template, allocate your study time in rough proportion to domain weight, front-loading the heaviest domains while they're freshest in memory before exam day.

Week 1

Data Security & User Access Control

  • Cover both 15%-weighted domains first - they carry the most exam questions
  • Build flashcards for encryption concepts and access-control models
Week 2

Cybersecurity Overview & Enterprise Risk

  • Work through both 14%-weighted domains together since risk concepts recur
  • Practice scenario-based multiple-choice questions, not just definitions
Week 3

Solution Delivery, Risks and Controls, Operations

  • Group the three mid-weighted domains (13%, 12%, 12%)
  • Focus on how controls map to operational and delivery processes
Week 4

Securing the Layers & Full Review

  • Finish the lightest domain (5%) quickly - don't overinvest
  • Run full-length, timed 75-question practice sessions to build 90-minute pacing

This structure is not a rigid formula - adjust it based on your own strengths. But it directly reflects the actual blueprint rather than a generic "review everything equally" approach. For a more detailed week-by-week breakdown, the CCA Study Guide expands on this plan, and our CCA practice test platform lets you simulate the timed, no-break exam environment described above.

How to Read Any "CCA Pass Rate" Claim You Find Online

If you encounter a specific pass-rate percentage attributed to the CCA exam elsewhere, run it through a quick filter before trusting it:

  • Check the source. Is it linked to an official IIBA page, or is it an unsourced blog claim?
  • Check the acronym. "CCA" is used by multiple unrelated certifications in completely different industries - a pass-rate figure could easily belong to one of those instead.
  • Check the date. Certification blueprints and fee structures change; a number from years ago may not reflect the current 2026 handbook.
  • Check for methodology. A credible statistic explains its sample size and timeframe. A number with no context is not verifiable.

Given that IIBA has not published pass-rate data for the IIBA-CCA exam, the most defensible position is to treat the domain blueprint, question format, and fee structure - all verifiable facts - as your planning inputs, rather than an unverified percentage. Reviewing the official CCA Cheat Sheet alongside the handbook is a more reliable way to gauge readiness than chasing a rumored statistic. You can also test your current readiness directly using our CCA practice exams before committing to a scheduled attempt.

Frequently Asked Questions

Does IIBA publish an official CCA pass rate?

No. IIBA has not published pass-rate statistics for the IIBA-CCA exam. Treat any specific percentage found elsewhere online with caution, especially since other certifications also use the "CCA" acronym.

How is the CCA exam scored?

The exam is reported strictly as pass or fail, based on your performance across 75 knowledge-based multiple-choice questions within a 90-minute window. No scaled score or domain breakdown is provided.

What happens if I fail the CCA exam?

You can retake it for USD 195 (IIBA members) or USD 350 (non-members). The purchased exam attempt must be completed within six months of purchase.

Which CCA domains should I prioritize given no published pass rate?

Prioritize Data Security and User Access Control, each weighted at 15% - the highest of the eight domains - followed by Cybersecurity Overview and Basic Concepts and Enterprise Risk at 14% each.

Is the CCA certification permanent once earned?

Yes. The IIBA-CCA certificate does not expire and requires no recertification or continuing development units (CDUs) to maintain.

Ready to pass your CCA exam?

Put this into practice with free CCA questions across every exam domain.