CCA logo
Focused certification exam prep
Start practice

CCA Passing Score 2026: Exactly What You Need to Pass

TL;DR
  • IIBA-CCA results are reported strictly as pass/fail - no numeric score is shown to candidates.
  • The exam has 75 knowledge-based multiple-choice questions in 90 minutes, delivered via PSI remote proctoring.
  • Data Security and User Access Control each carry 15% weight, the two heaviest of eight domains.
  • Securing the Layers is worth only 5%, the lightest domain - don't over-study it at the expense of the big two.

How CCA Results Are Actually Scored

If you're searching for a specific number - "you need 72% to pass the CCA" or similar - that number doesn't exist in any official IIBA documentation. The Certificate in Cybersecurity Analysis (CCA), governed by the International Institute of Business Analysis in collaboration with the IEEE Computer Society, reports results as a simple pass or fail. There is no percentage breakdown shown after the exam, no scaled score displayed on screen, and no domain-by-domain scorecard handed back to you.

This surprises candidates who are used to certifications that publish a fixed cutoff like "70% correct answers required." The IIBA-CCA exam simply tells you whether you met the standard or not. That's it. Understanding this scoring reality changes how you should prepare - instead of chasing an arbitrary percentage, your job is to build broad competence across all eight domains so that no single weak area drags your overall performance down.

What You Actually Receive: After completing the 75-question exam through PSI's remote-proctored platform, you get a pass/fail result. IIBA does not disclose the exact scaled-score threshold used to determine that outcome.

Why IIBA Doesn't Publish a Fixed Cut Score

Many professional certification bodies - including IIBA - use psychometric scoring models rather than a flat "number of correct answers" rule. This is common practice for knowledge-based, multiple-choice exams where question difficulty can vary slightly between exam forms. Rather than counting raw correct answers, these models typically weigh performance against the difficulty of the specific question set a candidate received, then compare it against a pre-established competency standard.

The practical implication for you: don't waste energy hunting for a leaked "passing percentage" on forums. Nothing in the official 2026 IIBA-CCA Handbook specifies one, and IIBA's fee and recertification pages are equally silent on a numeric cutoff. What the handbook does specify - clearly and usefully - is the domain blueprint and the weight each domain carries. That blueprint is your real roadmap to passing, and it's covered in full detail in the CCA Exam Domains 2026: Complete Guide to All 8 Content Areas.

Key Takeaway

Stop looking for a percentage. Focus your energy on mastering all eight domains proportionally to their published weight - that's the closest thing to a "formula" for passing that actually exists.

How the Eight Domains Shape Your Score

Because there's no visible scoring breakdown, the domain weight table becomes the single most reliable signal for where to invest your study hours. Every question on the exam is knowledge-based and multiple choice, and questions are distributed across these eight domains according to the official blueprint:

DomainWeight
Data Security15%
User Access Control15%
Cybersecurity Overview and Basic Concepts14%
Enterprise Risk14%
Solution Delivery13%
Cybersecurity Risks and Controls12%
Operations12%
Securing the Layers5%

Notice the math: Data Security and User Access Control together account for 30% of the exam - nearly a third of all 75 questions. Treat these as non-negotiable mastery zones.

Data Security (15%)

Candidates must understand how information is classified, encrypted, and protected across its lifecycle.

  • Data classification schemes and handling requirements
  • Encryption concepts applied to data at rest and in transit
  • Data loss prevention and retention principles

User Access Control (15%)

This domain tests how identities are verified and how access is granted, limited, and revoked.

  • Authentication vs. authorization concepts
  • Least-privilege and role-based access models
  • Identity lifecycle management practices

At the opposite end, Securing the Layers sits at just 5% - the smallest domain on the blueprint. It still deserves study time, but not at the expense of the two 15% domains. A candidate who spends equal hours on all eight domains is misallocating effort relative to how the exam is actually built. For a domain-by-domain breakdown of what each of the eight areas covers conceptually, the CCA Exam Domains 2026 guide goes deeper than weight percentages alone.

Inside the 75-Question, 90-Minute Format

The CCA exam consists of 75 knowledge-based multiple-choice questions, and you have 90 minutes to complete them - roughly 72 seconds per question on average. It's delivered remotely through PSI's proctoring platform, which means you'll need a valid ID, a compatible computer, a working webcam and microphone, and a secure, private testing environment. No reference materials, no calculator, and no scheduled break are permitted during the session.

Because every question is knowledge-based rather than scenario-heavy case study format, the exam rewards candidates who can recall specific terminology, control types, and process steps quickly rather than those who need extended time to reason through a long narrative. That format detail matters for pacing: if a question is taking you far longer than 72 seconds, it's usually more efficient to mark your best guess and move on rather than let one item consume time you'll need elsewhere.

Remote Proctoring Reality: Since no break is allowed and no materials can be referenced, your working memory on exam day carries the full weight of performance - there's no fallback resource mid-test. Treat your test environment setup as seriously as your content review.

If you're unsure whether your background knowledge is strong enough to handle this pacing and format, the How Hard Is the CCA Exam? Complete Difficulty Guide 2026 breaks down the difficulty profile in more detail, and the CCA Pass Rate 2026 data article discusses what's publicly known about outcomes.

Registration, Fees, and What Happens If You Fail

Understanding the financial mechanics around the exam is part of understanding what "passing" is worth to you. IIBA members pay USD 250 for the exam; non-members pay USD 405, though that higher fee bundles in a first-year IIBA membership. There's also an optional learning-and-exam package priced at USD 395 for members and USD 550 for non-members, which pairs preparation coursework with the exam itself - but that learning program is optional, not required to sit the test.

Once you purchase the exam, you have six months to schedule and complete it. If you don't pass on the first attempt, the retake fee is USD 195 for members and USD 350 for non-members - noticeably less than a fresh full-price registration, but still a real cost that makes first-attempt preparation financially worthwhile. For the complete cost picture across membership tiers and package options, see the CCA Certification Cost 2026: Complete Pricing Breakdown.

One detail worth flagging: candidates agree to IIBA's ethics and professional standards as part of registration, separate from the knowledge tested on the exam itself. And once you do pass, the certificate does not expire - there's no recertification cycle and no continuing development units (CDUs) required to maintain it, which is a meaningfully different maintenance model than many other cybersecurity credentials.

Key Takeaway

Because retakes cost real money and the purchase window is only six months, treat your first attempt as the one that counts - don't register before your domain coverage, especially on the two 15% domains, is solid.

Allocating Study Time to Protect Your Score

Since there's no published percentage to hit, the smartest use of a study calendar is proportional coverage matched to domain weight - heavier domains get more sessions, lighter domains get focused-but-brief review. Here's a sample allocation over a five-week runway:

Week 1

Data Security & User Access Control (30% combined)

  • Build flashcards on classification, encryption, and access-control models
  • Drill authentication vs. authorization scenarios
Week 2

Cybersecurity Overview and Enterprise Risk (28% combined)

  • Review foundational terminology and risk frameworks
  • Practice identifying risk treatment options
Week 3

Solution Delivery and Cybersecurity Risks and Controls (25% combined)

  • Study secure development and control-selection logic
  • Map controls to specific risk types
Week 4

Operations and Securing the Layers (17% combined)

  • Cover monitoring and incident response basics
  • Skim layered-defense concepts without over-investing time
Week 5

Full-Domain Review and Timed Practice

  • Take full-length timed practice sets at ../ to build 90-minute pacing stamina
  • Revisit weakest domain based on practice results

Notice this schedule intentionally gives roughly double the attention to the top two domains compared with the bottom two - that's a direct reflection of the blueprint weighting, not a generic study template. For a fuller walkthrough of preparation strategy beyond scheduling, the CCA Study Guide 2026: How to Pass on Your First Attempt covers material selection and practice-question strategy in depth.

What Actually Counts Toward a Pass

Since the scoring model isn't public, the most useful mental model is this: every one of the 75 questions is drawn from the eight-domain blueprint, weighted according to the percentages above, and your overall performance across that full question set determines pass/fail. There is no minimum score required within any single domain that's been published - so a rough patch on Securing the Layers (5%) is far less damaging than a rough patch on Data Security or User Access Control (15% each).

This is why domain-proportional preparation beats blanket, unfocused review. It's also why candidates who've already met the eligibility expectations outlined in the CCA Requirements 2026: Eligibility, Prerequisites & How to Qualify guide, and who understand the exam's scheduling windows via the CCA Exam Dates 2026 resource, tend to walk in with realistic expectations about both format and standard.

Running full-length timed practice sessions at ../ before exam day is one of the few ways to simulate the pass/fail pressure without a public score to benchmark against - it lets you gauge readiness by consistency across all eight domains rather than chasing a single mystery number.

Frequently Asked Questions

What percentage do I need to pass the CCA exam?

IIBA does not publish a fixed passing percentage for the Certificate in Cybersecurity Analysis. Results are reported only as pass or fail, based on performance across all 75 questions and the eight weighted domains.

Will I see my score if I fail the CCA exam?

No. The result is delivered as pass/fail only, with no numeric score or domain-level breakdown provided to the candidate.

Which domains should I prioritize since there's no published cut score?

Prioritize Data Security and User Access Control, each weighted at 15% - the two heaviest domains on the blueprint - followed by Cybersecurity Overview and Basic Concepts and Enterprise Risk at 14% each.

How much does it cost to retake the CCA exam if I don't pass?

Retakes cost USD 195 for IIBA members and USD 350 for non-members, less than the original registration fee but still a meaningful reason to prepare thoroughly before your first attempt.

Does the CCA certification expire if I pass?

No. Once earned, the Certificate in Cybersecurity Analysis does not expire and requires no recertification or continuing development units (CDUs) to maintain.

Ready to pass your CCA exam?

Put this into practice with free CCA questions across every exam domain.