- How CCA Results Are Actually Scored
- Why IIBA Doesn't Publish a Fixed Cut Score
- How the Eight Domains Shape Your Score
- Inside the 75-Question, 90-Minute Format
- Registration, Fees, and What Happens If You Fail
- Allocating Study Time to Protect Your Score
- What Actually Counts Toward a Pass
- Frequently Asked Questions
- IIBA-CCA results are reported strictly as pass/fail - no numeric score is shown to candidates.
- The exam has 75 knowledge-based multiple-choice questions in 90 minutes, delivered via PSI remote proctoring.
- Data Security and User Access Control each carry 15% weight, the two heaviest of eight domains.
- Securing the Layers is worth only 5%, the lightest domain - don't over-study it at the expense of the big two.
How CCA Results Are Actually Scored
If you're searching for a specific number - "you need 72% to pass the CCA" or similar - that number doesn't exist in any official IIBA documentation. The Certificate in Cybersecurity Analysis (CCA), governed by the International Institute of Business Analysis in collaboration with the IEEE Computer Society, reports results as a simple pass or fail. There is no percentage breakdown shown after the exam, no scaled score displayed on screen, and no domain-by-domain scorecard handed back to you.
This surprises candidates who are used to certifications that publish a fixed cutoff like "70% correct answers required." The IIBA-CCA exam simply tells you whether you met the standard or not. That's it. Understanding this scoring reality changes how you should prepare - instead of chasing an arbitrary percentage, your job is to build broad competence across all eight domains so that no single weak area drags your overall performance down.
Why IIBA Doesn't Publish a Fixed Cut Score
Many professional certification bodies - including IIBA - use psychometric scoring models rather than a flat "number of correct answers" rule. This is common practice for knowledge-based, multiple-choice exams where question difficulty can vary slightly between exam forms. Rather than counting raw correct answers, these models typically weigh performance against the difficulty of the specific question set a candidate received, then compare it against a pre-established competency standard.
The practical implication for you: don't waste energy hunting for a leaked "passing percentage" on forums. Nothing in the official 2026 IIBA-CCA Handbook specifies one, and IIBA's fee and recertification pages are equally silent on a numeric cutoff. What the handbook does specify - clearly and usefully - is the domain blueprint and the weight each domain carries. That blueprint is your real roadmap to passing, and it's covered in full detail in the CCA Exam Domains 2026: Complete Guide to All 8 Content Areas.
Key Takeaway
Stop looking for a percentage. Focus your energy on mastering all eight domains proportionally to their published weight - that's the closest thing to a "formula" for passing that actually exists.
How the Eight Domains Shape Your Score
Because there's no visible scoring breakdown, the domain weight table becomes the single most reliable signal for where to invest your study hours. Every question on the exam is knowledge-based and multiple choice, and questions are distributed across these eight domains according to the official blueprint:
| Domain | Weight |
|---|---|
| Data Security | 15% |
| User Access Control | 15% |
| Cybersecurity Overview and Basic Concepts | 14% |
| Enterprise Risk | 14% |
| Solution Delivery | 13% |
| Cybersecurity Risks and Controls | 12% |
| Operations | 12% |
| Securing the Layers | 5% |
Notice the math: Data Security and User Access Control together account for 30% of the exam - nearly a third of all 75 questions. Treat these as non-negotiable mastery zones.
Data Security (15%)
Candidates must understand how information is classified, encrypted, and protected across its lifecycle.
- Data classification schemes and handling requirements
- Encryption concepts applied to data at rest and in transit
- Data loss prevention and retention principles
User Access Control (15%)
This domain tests how identities are verified and how access is granted, limited, and revoked.
- Authentication vs. authorization concepts
- Least-privilege and role-based access models
- Identity lifecycle management practices
At the opposite end, Securing the Layers sits at just 5% - the smallest domain on the blueprint. It still deserves study time, but not at the expense of the two 15% domains. A candidate who spends equal hours on all eight domains is misallocating effort relative to how the exam is actually built. For a domain-by-domain breakdown of what each of the eight areas covers conceptually, the CCA Exam Domains 2026 guide goes deeper than weight percentages alone.
Inside the 75-Question, 90-Minute Format
The CCA exam consists of 75 knowledge-based multiple-choice questions, and you have 90 minutes to complete them - roughly 72 seconds per question on average. It's delivered remotely through PSI's proctoring platform, which means you'll need a valid ID, a compatible computer, a working webcam and microphone, and a secure, private testing environment. No reference materials, no calculator, and no scheduled break are permitted during the session.
Because every question is knowledge-based rather than scenario-heavy case study format, the exam rewards candidates who can recall specific terminology, control types, and process steps quickly rather than those who need extended time to reason through a long narrative. That format detail matters for pacing: if a question is taking you far longer than 72 seconds, it's usually more efficient to mark your best guess and move on rather than let one item consume time you'll need elsewhere.
If you're unsure whether your background knowledge is strong enough to handle this pacing and format, the How Hard Is the CCA Exam? Complete Difficulty Guide 2026 breaks down the difficulty profile in more detail, and the CCA Pass Rate 2026 data article discusses what's publicly known about outcomes.
Registration, Fees, and What Happens If You Fail
Understanding the financial mechanics around the exam is part of understanding what "passing" is worth to you. IIBA members pay USD 250 for the exam; non-members pay USD 405, though that higher fee bundles in a first-year IIBA membership. There's also an optional learning-and-exam package priced at USD 395 for members and USD 550 for non-members, which pairs preparation coursework with the exam itself - but that learning program is optional, not required to sit the test.
Once you purchase the exam, you have six months to schedule and complete it. If you don't pass on the first attempt, the retake fee is USD 195 for members and USD 350 for non-members - noticeably less than a fresh full-price registration, but still a real cost that makes first-attempt preparation financially worthwhile. For the complete cost picture across membership tiers and package options, see the CCA Certification Cost 2026: Complete Pricing Breakdown.
One detail worth flagging: candidates agree to IIBA's ethics and professional standards as part of registration, separate from the knowledge tested on the exam itself. And once you do pass, the certificate does not expire - there's no recertification cycle and no continuing development units (CDUs) required to maintain it, which is a meaningfully different maintenance model than many other cybersecurity credentials.
Key Takeaway
Because retakes cost real money and the purchase window is only six months, treat your first attempt as the one that counts - don't register before your domain coverage, especially on the two 15% domains, is solid.
Allocating Study Time to Protect Your Score
Since there's no published percentage to hit, the smartest use of a study calendar is proportional coverage matched to domain weight - heavier domains get more sessions, lighter domains get focused-but-brief review. Here's a sample allocation over a five-week runway:
Data Security & User Access Control (30% combined)
- Build flashcards on classification, encryption, and access-control models
- Drill authentication vs. authorization scenarios
Cybersecurity Overview and Enterprise Risk (28% combined)
- Review foundational terminology and risk frameworks
- Practice identifying risk treatment options
Solution Delivery and Cybersecurity Risks and Controls (25% combined)
- Study secure development and control-selection logic
- Map controls to specific risk types
Operations and Securing the Layers (17% combined)
- Cover monitoring and incident response basics
- Skim layered-defense concepts without over-investing time
Full-Domain Review and Timed Practice
- Take full-length timed practice sets at ../ to build 90-minute pacing stamina
- Revisit weakest domain based on practice results
Notice this schedule intentionally gives roughly double the attention to the top two domains compared with the bottom two - that's a direct reflection of the blueprint weighting, not a generic study template. For a fuller walkthrough of preparation strategy beyond scheduling, the CCA Study Guide 2026: How to Pass on Your First Attempt covers material selection and practice-question strategy in depth.
What Actually Counts Toward a Pass
Since the scoring model isn't public, the most useful mental model is this: every one of the 75 questions is drawn from the eight-domain blueprint, weighted according to the percentages above, and your overall performance across that full question set determines pass/fail. There is no minimum score required within any single domain that's been published - so a rough patch on Securing the Layers (5%) is far less damaging than a rough patch on Data Security or User Access Control (15% each).
This is why domain-proportional preparation beats blanket, unfocused review. It's also why candidates who've already met the eligibility expectations outlined in the CCA Requirements 2026: Eligibility, Prerequisites & How to Qualify guide, and who understand the exam's scheduling windows via the CCA Exam Dates 2026 resource, tend to walk in with realistic expectations about both format and standard.
Running full-length timed practice sessions at ../ before exam day is one of the few ways to simulate the pass/fail pressure without a public score to benchmark against - it lets you gauge readiness by consistency across all eight domains rather than chasing a single mystery number.
Frequently Asked Questions
IIBA does not publish a fixed passing percentage for the Certificate in Cybersecurity Analysis. Results are reported only as pass or fail, based on performance across all 75 questions and the eight weighted domains.
No. The result is delivered as pass/fail only, with no numeric score or domain-level breakdown provided to the candidate.
Prioritize Data Security and User Access Control, each weighted at 15% - the two heaviest domains on the blueprint - followed by Cybersecurity Overview and Basic Concepts and Enterprise Risk at 14% each.
Retakes cost USD 195 for IIBA members and USD 350 for non-members, less than the original registration fee but still a meaningful reason to prepare thoroughly before your first attempt.
No. Once earned, the Certificate in Cybersecurity Analysis does not expire and requires no recertification or continuing development units (CDUs) to maintain.