CCA logo
Focused certification exam prep
Start practice

CCA Requirements 2026: Eligibility, Prerequisites & How to Qualify

TL;DR
  • There is no mandatory prerequisite exam, degree, or work-experience minimum for the IIBA-CCA.
  • You "qualify" by registering, paying the fee, and agreeing to IIBA's ethics and professional standards.
  • Non-member exam registration (USD 405) includes first-year IIBA membership automatically.
  • Once purchased, your exam must be completed within 6 months, so timing your registration matters.

Is There a Prerequisite for the CCA Exam?

If you're used to certifications that gate access behind years of documented work experience or a bundle of prerequisite courses, the Certificate in Cybersecurity Analysis (CCA) works differently. The IIBA-CCA - jointly developed by the International Institute of Business Analysis (IIBA) and the IEEE Computer Society - does not require a specific degree, a minimum number of years in a security role, or proof of prior certifications before you register.

That doesn't mean anyone should walk in unprepared. The exam is knowledge-based, and "eligibility" in a practical sense means having enough grounding in the eight exam domains to answer 75 multiple-choice questions in 90 minutes. The real qualification bar isn't administrative - it's competency. For a full breakdown of what's actually tested, see the CCA Exam Domains 2026: Complete Guide to All 8 Content Areas.

No Gatekeeping, But No Shortcuts: Because there's no prerequisite exam or experience requirement, the CCA is genuinely open to career-changers, analysts, and IT professionals moving into security. But the absence of a gate means the exam itself has to do the filtering - so preparation quality matters more, not less.

Who Should Pursue the IIBA-CCA?

Since eligibility isn't restricted by title or tenure, the better question is fit. The credential blends business-analysis thinking with cybersecurity fundamentals, so it tends to suit people sitting at that intersection rather than deep technical specialists alone.

  • Business analysts who now touch security requirements, risk documentation, or compliance projects.
  • IT and security professionals who want a credential that validates knowledge across enterprise risk, data protection, and access control rather than a single tool or platform.
  • Project and product professionals involved in solution delivery where security controls must be baked into requirements and design.
  • Career-changers moving from general business or IT roles into cybersecurity-adjacent positions, using the certificate as a structured entry point.

If you're still deciding whether this credential aligns with your goals, the article Is the CCA Certification Worth It? Complete ROI Analysis 2026 walks through that decision in more depth, and CCA Jobs looks at the types of roles that reference this credential.

Registration, Fees, and Eligibility Mechanics

The practical path to "qualifying" for the CCA runs through IIBA's registration and payment process rather than a document-verification step. Understanding the fee structure helps you plan correctly:

ItemMember PriceNon-Member Price
Standard examUSD 250USD 405 (includes first-year IIBA membership)
Retake examUSD 195USD 350
Learning + exam package (optional)USD 395USD 550

Notice that the non-member price isn't just a penalty for skipping membership - it bundles your first year of IIBA membership into the fee. That's a meaningful detail when comparing options, and it's covered in more granular detail in CCA Certification Cost 2026: Complete Pricing Breakdown.

The optional learning-and-exam package includes preparation coursework alongside the exam itself. It's worth stressing that this package is optional - nothing in the eligibility process forces you to purchase it. Candidates who already have strong domain knowledge can register for the exam alone.

Key Takeaway

Once you purchase your exam, you have 6 months to complete it. Don't register before you're realistically ready to study - the clock starts immediately, and letting it lapse means paying again.

The IIBA Ethics Agreement Requirement

The one non-negotiable "requirement" tied to the CCA isn't academic - it's a professional-conduct agreement. Candidates must agree to IIBA's ethics and professional standards as part of the certification process. This is consistent with how IIBA administers its broader family of business-analysis certifications and signals that the CCA credential carries expectations of professional conduct beyond passing a test.

This agreement doesn't add study burden, but it's worth reading before you register so you understand what you're formally committing to as a certificate holder.

Exam Format You're Qualifying For

Understanding the exact structure you're preparing for helps clarify what "being ready" actually means. The IIBA-CCA exam consists of:

  • 75 knowledge-based multiple-choice questions
  • 90 minutes total testing time
  • Pass/fail result reporting - no scaled score is published
  • Delivery via PSI online remote proctoring

The blueprint governing question distribution comes from the 2026 IIBA-CCA Handbook, which defines eight examination domains. Don't confuse these with the learning program's nine courses - the courses are a study structure, while the eight domains are what's actually scored on exam day.

For a deeper dive into exactly how many questions you need right versus wrong, read CCA Passing Score 2026: Exactly What You Need to Pass. And if you want a realistic sense of exam difficulty before you commit money to registration, How Hard Is the CCA Exam? Complete Difficulty Guide 2026 is a useful companion read.

Domain Readiness Checklist

Because there's no formal prerequisite screening, self-assessment against the domain blueprint is your real eligibility check. Here is the weighting from the 2026 Handbook:

Domain 1: Cybersecurity Overview and Basic Concepts (14%)

Foundational terminology, threat landscape concepts, and how cybersecurity intersects with business analysis work.

  • Core vocabulary and conceptual models used throughout the other seven domains

Domain 2: Enterprise Risk (14%)

How organizations identify, assess, and manage risk at a strategic level.

  • Risk frameworks and their application to business decision-making

Domain 3: Cybersecurity Risks and Controls (12%)

Specific risk categories and the controls designed to mitigate them.

  • Mapping control types to the risks they address

Domain 4: Securing the Layers (5%)

The smallest domain by weight, but still tested - covers layered security architecture concepts.

  • Don't skip it just because it's lightly weighted; a few missed questions here still count

Domain 5: Data Security (15%)

Tied for the largest domain - expect the most questions from this area.

  • Data protection principles, classification, and lifecycle security

Domain 6: User Access Control (15%)

Also tied for largest domain weight - authentication, authorization, and identity concepts.

  • Access management models and their practical application

Domain 7: Solution Delivery (13%)

Embedding security into requirements, design, and delivery processes.

  • Where business-analysis skills and security knowledge directly overlap

Domain 8: Operations (12%)

Ongoing security operations and maintenance concepts.

  • Operational monitoring and response fundamentals

For anchor-point study around each domain, the CCA Exam Domains 2026: Complete Guide to All 8 Content Areas article expands on each area with more detail than fits here.

Technical Requirements for Remote Proctoring

Because the exam is delivered through PSI's remote-proctored platform, "qualifying" to sit for it also means meeting a set of technical and environmental requirements on exam day - these function as practical prerequisites even though they're procedural, not academic.

  • Valid government-issued identification
  • A compatible computer with functioning webcam and microphone
  • A secure, private testing environment free from interruption
  • No reference materials, no calculator, and no scheduled breaks during the 90-minute session
Test Your Setup Early: Technical failures on exam day can cost you time or force a reschedule. Confirm your computer, webcam, and internet connection meet PSI's remote-proctoring standards well before your scheduled date.

Planning Your Qualification Timeline

Since there's no external prerequisite process to navigate, your main planning task is sequencing study time against the domain weights and the 6-month completion window. A simple way to think about pacing:

Weeks 1-2

Foundation Domains

  • Cybersecurity Overview and Basic Concepts
  • Enterprise Risk
Weeks 3-4

Heaviest-Weighted Domains

  • Data Security (15%)
  • User Access Control (15%)
Weeks 5-6

Applied Domains

  • Cybersecurity Risks and Controls
  • Solution Delivery
  • Operations
Week 7

Review and Practice

  • Securing the Layers (lightest weight, quick review)
  • Full-length practice questions across all eight domains

This sequencing front-loads the two 15%-weighted domains so they get repeated review before exam day, while still allocating dedicated time to the lighter-weighted Domain 4 so it isn't neglected entirely. A more detailed study methodology, including how to structure practice sessions, is covered in CCA Study Guide 2026: How to Pass on Your First Attempt.

Running through timed practice questions at CCA Exam Prep's practice tests before you lock in your PSI appointment gives you real signal on which domains still need work - far more useful than guessing based on how comfortable you feel with the material.

What Happens After You Qualify and Pass

One requirement worth knowing before you start: the IIBA-CCA certificate does not expire. There's no recertification cycle and no continuing development units (CDUs) to track afterward. Once you pass, the credential is yours permanently - a meaningful contrast to certifications that demand ongoing renewal fees and CDU submissions.

That permanence is part of why getting the underlying qualification steps right the first time matters. Registering with the correct membership status, understanding the fee structure, and confirming your technical setup all reduce the chance of a wasted attempt. If you haven't yet locked in your exam appointment, check CCA Exam Dates 2026: Testing Windows, Deadlines & Scheduling for scheduling specifics, and browse CCA Exam Prep's question bank to gauge your current readiness against real domain-weighted questions.

For readers still building general familiarity with the credential before diving into logistics, the primer articles What Is CCA? and CCA Certification are useful starting points, and CCA Pass Rate 2026: What the Data Shows offers additional context on what successful candidates typically do differently.

Frequently Asked Questions

Do I need a degree to sit for the CCA exam?

No. The IIBA-CCA has no formal degree requirement. Eligibility is based on registering and paying the exam fee, not on academic credentials.

Is prior work experience required before registering?

No minimum years of experience are required. The exam is open to candidates at different career stages, though solid familiarity with the eight domains is strongly recommended before scheduling.

Do I have to become an IIBA member to take the CCA exam?

No. Non-members can register directly for USD 405, which includes first-year IIBA membership. Members pay USD 250 for the standard exam.

Is the learning program required to qualify for the exam?

No, the learning-and-exam package is optional. Candidates can register for the exam alone without purchasing the accompanying coursework.

How long do I have to take the exam after registering?

Once purchased, the exam must be completed within 6 months. Plan your registration date around your realistic study timeline.

Ready to pass your CCA exam?

Put this into practice with free CCA questions across every exam domain.