CCA logo
Focused certification exam prep
Start practice

What Is A CCA?

TL;DR
  • A CCA is a holder of the IIBA-CCA - Certificate in Cybersecurity Analysis - issued by IIBA with the IEEE Computer Society.
  • The exam has 75 knowledge-based multiple-choice questions in 90 minutes, delivered via PSI remote proctoring.
  • Data Security and User Access Control are the heaviest domains, each worth 15% of the exam.
  • Exam fees run USD 250 (members) or USD 405 (non-members, including first-year membership).

What Is A CCA, Exactly?

A CCA is a professional who holds the Certificate in Cybersecurity Analysis (CCA), formally designated IIBA-CCA. It is a credential - not a job title - that signals someone has demonstrated knowledge-based competency across eight defined domains of cybersecurity analysis, from foundational concepts through operations. The letters "CCA" appear on several unrelated certifications in other industries, so it's worth being precise: on this site, and in this article, CCA always refers to the IIBA-CCA specifically.

The credential sits at the intersection of business analysis and cybersecurity. It was built for people who need to understand security risk, controls, and data protection well enough to work alongside technical teams, translate requirements, and support secure solution delivery - without necessarily being a hands-on penetration tester or network engineer. If you're still deciding whether this designation fits your career path, the deeper breakdown in Is the CCA Certification Worth It? Complete ROI Analysis 2026 walks through the tradeoffs in more depth.

Quick Definition: A CCA is anyone who has passed the IIBA-CCA exam - a 75-question, 90-minute, remote-proctored test covering eight cybersecurity analysis domains, administered by IIBA in collaboration with the IEEE Computer Society.

Who Issues the Credential and Why It Matters

The Certificate in Cybersecurity Analysis is issued by the International Institute of Business Analysis (IIBA), developed in collaboration with the IEEE Computer Society. That pairing is intentional: IIBA brings decades of business-analysis certification infrastructure, while the IEEE Computer Society lends technical credibility on the cybersecurity side. The official designation used after your name is IIBA-CCA.

This matters for anyone evaluating whether the credential carries weight. It's not a vendor badge tied to a single software product, and it's not a general-purpose "cybersecurity 101" certificate - it's specifically scoped around analyzing cybersecurity risk, controls, and data/access protection from a business-analysis lens. For a fuller history and scope explanation, see CCA Certification and the related overview at What Is CCA Certification?.

Exam Format: What You Actually Sit For

Understanding the exam mechanics is part of understanding what a CCA actually is - the format shapes the kind of knowledge being tested. The exam consists of 75 knowledge-based multiple-choice questions, and you have 90 minutes to complete it. That's roughly 72 seconds per question on average, which leaves little room for extended second-guessing on any single item.

Delivery is entirely remote through PSI's online proctoring system. There's no test-center visit required, but the remote environment has strict conditions:

  • Valid identification must be presented before the exam starts
  • A compatible computer with a working webcam and microphone is required
  • You need a secure, private testing environment - no interruptions, no other people in the room
  • No reference materials, no calculator, and no scheduled breaks are permitted during the session

Results come back as a straightforward pass/fail outcome rather than a scaled score report. If you want the exact mechanics of what separates a pass from a fail, CCA Passing Score 2026: Exactly What You Need to Pass covers that in detail, and How Hard Is the CCA Exam? Complete Difficulty Guide 2026 discusses the difficulty profile candidates report.

Key Takeaway

Because the exam is timed at roughly 72 seconds per question with no breaks or reference materials allowed, practicing under realistic timed conditions before exam day matters as much as content review.

The Eight Domains a CCA Must Know

A CCA's knowledge is defined by eight examination domains laid out in the IIBA-CCA Handbook. These eight domains are the exam blueprint - don't confuse them with the nine courses that make up the optional learning program, which is a separate structure entirely.

Domain 1: Cybersecurity Overview and Basic Concepts (14%)

Foundational terminology, principles, and the language used throughout the rest of the exam.

  • Core security concepts and how they interrelate

Domain 2: Enterprise Risk (14%)

How organizations identify, assess, and manage cybersecurity risk at an enterprise level.

  • Risk frameworks and enterprise-level decision-making

Domain 3: Cybersecurity Risks and Controls (12%)

Specific risk types paired with the controls used to mitigate them.

  • Matching control types to risk categories

Domain 4: Securing the Layers (5%)

The smallest domain by weight, covering layered security architecture concepts.

  • Defense-in-depth thinking across system layers

Domain 5: Data Security (15%)

One of the two largest domains - protecting data at rest, in transit, and in use.

  • Data classification, protection mechanisms, and lifecycle considerations

Domain 6: User Access Control (15%)

Tied with Data Security as the heaviest domain - governs who can access what, and how that access is managed.

  • Authentication, authorization, and access governance concepts

Domain 7: Solution Delivery (13%)

Building security considerations into how solutions are delivered.

  • Secure delivery practices within project and solution lifecycles

Domain 8: Operations (12%)

Ongoing operational security once a solution is live.

  • Monitoring, maintenance, and operational security practices

Notice that Data Security and User Access Control together account for 30% of the exam - nearly a third of everything tested. Any serious prep plan has to weight study time accordingly. For a domain-by-domain breakdown with more nuance, see CCA Exam Domains 2026: Complete Guide to All 8 Content Areas.

DomainWeight
Cybersecurity Overview and Basic Concepts14%
Enterprise Risk14%
Cybersecurity Risks and Controls12%
Securing the Layers5%
Data Security15%
User Access Control15%
Solution Delivery13%
Operations12%

Registration, Fees, and Retake Mechanics

Becoming a CCA involves a specific fee structure worth understanding before you register. The standard exam fee is USD 250 for IIBA members and USD 405 for non-members - the non-member price effectively bundles a first-year IIBA membership into the cost. If you'd rather bundle preparation with your exam, IIBA also offers an optional learning-and-exam package priced at USD 395 for members and USD 550 for non-members; the underlying learning program is entirely optional, not a prerequisite.

If your first attempt doesn't go your way, retakes are priced separately at USD 195 for members and USD 350 for non-members. One detail that trips people up: once you purchase your exam, you must complete it within six months, so don't buy access before you're genuinely ready to schedule. A full pricing breakdown, including how the packages compare, is available in CCA Certification Cost 2026: Complete Pricing Breakdown, and eligibility specifics live in CCA Requirements 2026: Eligibility, Prerequisites & How to Qualify.

All candidates agree to IIBA's ethics and professional standards as part of registration, regardless of whether they take the optional learning program. For a look at how testing windows and scheduling actually work in practice, check CCA Exam Dates 2026: Testing Windows, Deadlines & Scheduling.

Fee Snapshot: Members pay USD 250 to sit the exam and USD 195 to retake it. Non-members pay USD 405 initially (with first-year membership included) and USD 350 to retake.

Who Hires People With A CCA

Because the CCA sits between business analysis and technical security, holders are typically found in roles where someone needs to bridge those two worlds - translating security requirements into project deliverables, assessing risk for stakeholders, or supporting governance and access-control initiatives. Organizations building out risk management, data governance, or solution-delivery functions often value a credential that proves someone can speak both languages: business need and security control.

Rather than a single job title, think of the CCA as a signal layered onto existing business-analysis, risk-analyst, or IT-governance roles. If you're mapping out how this credential fits into a broader career trajectory, CCA Jobs and CCA Salary Guide 2026: Complete Earnings Analysis go deeper into how employers position and value the credential.

Preparing for the CCA: A Domain-Aware Approach

Generic study advice only goes so far here - the smarter approach is to let the domain weights drive your schedule. Since Data Security and User Access Control together represent 30% of the exam, they deserve dedicated blocks of study time rather than being folded into a single generic review week.

Week 1

Foundations First

  • Cover Domain 1 (Cybersecurity Overview and Basic Concepts) and Domain 2 (Enterprise Risk) since later domains build on this vocabulary
Week 2

Heaviest-Weight Domains

  • Dedicate concentrated time to Domain 5 (Data Security) and Domain 6 (User Access Control) - 30% of the exam lives here
Week 3

Risk, Controls, and Delivery

  • Work through Domain 3 (Cybersecurity Risks and Controls), Domain 7 (Solution Delivery), and Domain 8 (Operations)
Week 4

Timed Practice and Gaps

  • Run full timed practice sets to build comfort with the 90-minute, 75-question format, and revisit Domain 4 (Securing the Layers) since it's the lightest-weighted but easy to under-prepare

For a structured, week-by-week study plan built specifically around these domain weights, CCA Study Guide 2026: How to Pass on Your First Attempt lays out a fuller roadmap. And once you've reviewed content, running full-length timed sets on our practice test platform is the closest way to simulate real exam pressure before test day.

After You Pass: No Recertification Required

One of the more distinctive facts about being a CCA is what happens after you pass: nothing. The certificate does not expire, and there's no recertification cycle or continuing development units (CDUs) to track over time. Once you earn the IIBA-CCA designation, it's yours indefinitely - a meaningful contrast to certifications that demand ongoing renewal fees and CDU logs every cycle.

That permanence is one reason candidates weigh the CCA carefully against the upfront cost and study effort. If you want the numbers behind how the exam has performed for past candidates, CCA Pass Rate 2026: What the Data Shows covers what's publicly known, and CCA Cheat Sheet 2026: One-Page Review of Must-Know Facts is a handy last-mile reference before exam day. You can also run a quick readiness check anytime using our CCA practice questions to see which domains still need attention.

Frequently Asked Questions

What does CCA stand for in this context?

CCA stands for Certificate in Cybersecurity Analysis, issued by IIBA in collaboration with the IEEE Computer Society, formally designated IIBA-CCA. See What Does CCA Stand For? and CCA Meaning for related explanations.

Is the CCA exam taken in person or online?

The exam is delivered remotely through PSI's online proctoring system. You'll need a compatible computer, webcam, microphone, valid ID, and a secure, private testing space - no reference materials, calculator, or breaks are allowed during the session.

Do I have to take the learning program to become a CCA?

No. The learning program is optional. You can register directly for the exam alone, or choose the combined learning-and-exam package if you want structured preparation bundled in.

Which domains carry the most weight on the exam?

Data Security and User Access Control are the two largest domains, each worth 15% of the exam, together accounting for 30% of total content.

Does the CCA credential ever expire?

No. The certificate does not expire and there is no recertification requirement or continuing development units (CDUs) needed to maintain it.

Ready to pass your CCA exam?

Put this into practice with free CCA questions across every exam domain.