- What Is A CCA, Exactly?
- Who Issues the Credential and Why It Matters
- Exam Format: What You Actually Sit For
- The Eight Domains a CCA Must Know
- Registration, Fees, and Retake Mechanics
- Who Hires People With A CCA
- Preparing for the CCA: A Domain-Aware Approach
- After You Pass: No Recertification Required
- Frequently Asked Questions
- A CCA is a holder of the IIBA-CCA - Certificate in Cybersecurity Analysis - issued by IIBA with the IEEE Computer Society.
- The exam has 75 knowledge-based multiple-choice questions in 90 minutes, delivered via PSI remote proctoring.
- Data Security and User Access Control are the heaviest domains, each worth 15% of the exam.
- Exam fees run USD 250 (members) or USD 405 (non-members, including first-year membership).
What Is A CCA, Exactly?
A CCA is a professional who holds the Certificate in Cybersecurity Analysis (CCA), formally designated IIBA-CCA. It is a credential - not a job title - that signals someone has demonstrated knowledge-based competency across eight defined domains of cybersecurity analysis, from foundational concepts through operations. The letters "CCA" appear on several unrelated certifications in other industries, so it's worth being precise: on this site, and in this article, CCA always refers to the IIBA-CCA specifically.
The credential sits at the intersection of business analysis and cybersecurity. It was built for people who need to understand security risk, controls, and data protection well enough to work alongside technical teams, translate requirements, and support secure solution delivery - without necessarily being a hands-on penetration tester or network engineer. If you're still deciding whether this designation fits your career path, the deeper breakdown in Is the CCA Certification Worth It? Complete ROI Analysis 2026 walks through the tradeoffs in more depth.
Who Issues the Credential and Why It Matters
The Certificate in Cybersecurity Analysis is issued by the International Institute of Business Analysis (IIBA), developed in collaboration with the IEEE Computer Society. That pairing is intentional: IIBA brings decades of business-analysis certification infrastructure, while the IEEE Computer Society lends technical credibility on the cybersecurity side. The official designation used after your name is IIBA-CCA.
This matters for anyone evaluating whether the credential carries weight. It's not a vendor badge tied to a single software product, and it's not a general-purpose "cybersecurity 101" certificate - it's specifically scoped around analyzing cybersecurity risk, controls, and data/access protection from a business-analysis lens. For a fuller history and scope explanation, see CCA Certification and the related overview at What Is CCA Certification?.
Exam Format: What You Actually Sit For
Understanding the exam mechanics is part of understanding what a CCA actually is - the format shapes the kind of knowledge being tested. The exam consists of 75 knowledge-based multiple-choice questions, and you have 90 minutes to complete it. That's roughly 72 seconds per question on average, which leaves little room for extended second-guessing on any single item.
Delivery is entirely remote through PSI's online proctoring system. There's no test-center visit required, but the remote environment has strict conditions:
- Valid identification must be presented before the exam starts
- A compatible computer with a working webcam and microphone is required
- You need a secure, private testing environment - no interruptions, no other people in the room
- No reference materials, no calculator, and no scheduled breaks are permitted during the session
Results come back as a straightforward pass/fail outcome rather than a scaled score report. If you want the exact mechanics of what separates a pass from a fail, CCA Passing Score 2026: Exactly What You Need to Pass covers that in detail, and How Hard Is the CCA Exam? Complete Difficulty Guide 2026 discusses the difficulty profile candidates report.
Key Takeaway
Because the exam is timed at roughly 72 seconds per question with no breaks or reference materials allowed, practicing under realistic timed conditions before exam day matters as much as content review.
The Eight Domains a CCA Must Know
A CCA's knowledge is defined by eight examination domains laid out in the IIBA-CCA Handbook. These eight domains are the exam blueprint - don't confuse them with the nine courses that make up the optional learning program, which is a separate structure entirely.
Domain 1: Cybersecurity Overview and Basic Concepts (14%)
Foundational terminology, principles, and the language used throughout the rest of the exam.
- Core security concepts and how they interrelate
Domain 2: Enterprise Risk (14%)
How organizations identify, assess, and manage cybersecurity risk at an enterprise level.
- Risk frameworks and enterprise-level decision-making
Domain 3: Cybersecurity Risks and Controls (12%)
Specific risk types paired with the controls used to mitigate them.
- Matching control types to risk categories
Domain 4: Securing the Layers (5%)
The smallest domain by weight, covering layered security architecture concepts.
- Defense-in-depth thinking across system layers
Domain 5: Data Security (15%)
One of the two largest domains - protecting data at rest, in transit, and in use.
- Data classification, protection mechanisms, and lifecycle considerations
Domain 6: User Access Control (15%)
Tied with Data Security as the heaviest domain - governs who can access what, and how that access is managed.
- Authentication, authorization, and access governance concepts
Domain 7: Solution Delivery (13%)
Building security considerations into how solutions are delivered.
- Secure delivery practices within project and solution lifecycles
Domain 8: Operations (12%)
Ongoing operational security once a solution is live.
- Monitoring, maintenance, and operational security practices
Notice that Data Security and User Access Control together account for 30% of the exam - nearly a third of everything tested. Any serious prep plan has to weight study time accordingly. For a domain-by-domain breakdown with more nuance, see CCA Exam Domains 2026: Complete Guide to All 8 Content Areas.
| Domain | Weight |
|---|---|
| Cybersecurity Overview and Basic Concepts | 14% |
| Enterprise Risk | 14% |
| Cybersecurity Risks and Controls | 12% |
| Securing the Layers | 5% |
| Data Security | 15% |
| User Access Control | 15% |
| Solution Delivery | 13% |
| Operations | 12% |
Registration, Fees, and Retake Mechanics
Becoming a CCA involves a specific fee structure worth understanding before you register. The standard exam fee is USD 250 for IIBA members and USD 405 for non-members - the non-member price effectively bundles a first-year IIBA membership into the cost. If you'd rather bundle preparation with your exam, IIBA also offers an optional learning-and-exam package priced at USD 395 for members and USD 550 for non-members; the underlying learning program is entirely optional, not a prerequisite.
If your first attempt doesn't go your way, retakes are priced separately at USD 195 for members and USD 350 for non-members. One detail that trips people up: once you purchase your exam, you must complete it within six months, so don't buy access before you're genuinely ready to schedule. A full pricing breakdown, including how the packages compare, is available in CCA Certification Cost 2026: Complete Pricing Breakdown, and eligibility specifics live in CCA Requirements 2026: Eligibility, Prerequisites & How to Qualify.
All candidates agree to IIBA's ethics and professional standards as part of registration, regardless of whether they take the optional learning program. For a look at how testing windows and scheduling actually work in practice, check CCA Exam Dates 2026: Testing Windows, Deadlines & Scheduling.
Who Hires People With A CCA
Because the CCA sits between business analysis and technical security, holders are typically found in roles where someone needs to bridge those two worlds - translating security requirements into project deliverables, assessing risk for stakeholders, or supporting governance and access-control initiatives. Organizations building out risk management, data governance, or solution-delivery functions often value a credential that proves someone can speak both languages: business need and security control.
Rather than a single job title, think of the CCA as a signal layered onto existing business-analysis, risk-analyst, or IT-governance roles. If you're mapping out how this credential fits into a broader career trajectory, CCA Jobs and CCA Salary Guide 2026: Complete Earnings Analysis go deeper into how employers position and value the credential.
Preparing for the CCA: A Domain-Aware Approach
Generic study advice only goes so far here - the smarter approach is to let the domain weights drive your schedule. Since Data Security and User Access Control together represent 30% of the exam, they deserve dedicated blocks of study time rather than being folded into a single generic review week.
Foundations First
- Cover Domain 1 (Cybersecurity Overview and Basic Concepts) and Domain 2 (Enterprise Risk) since later domains build on this vocabulary
Heaviest-Weight Domains
- Dedicate concentrated time to Domain 5 (Data Security) and Domain 6 (User Access Control) - 30% of the exam lives here
Risk, Controls, and Delivery
- Work through Domain 3 (Cybersecurity Risks and Controls), Domain 7 (Solution Delivery), and Domain 8 (Operations)
Timed Practice and Gaps
- Run full timed practice sets to build comfort with the 90-minute, 75-question format, and revisit Domain 4 (Securing the Layers) since it's the lightest-weighted but easy to under-prepare
For a structured, week-by-week study plan built specifically around these domain weights, CCA Study Guide 2026: How to Pass on Your First Attempt lays out a fuller roadmap. And once you've reviewed content, running full-length timed sets on our practice test platform is the closest way to simulate real exam pressure before test day.
After You Pass: No Recertification Required
One of the more distinctive facts about being a CCA is what happens after you pass: nothing. The certificate does not expire, and there's no recertification cycle or continuing development units (CDUs) to track over time. Once you earn the IIBA-CCA designation, it's yours indefinitely - a meaningful contrast to certifications that demand ongoing renewal fees and CDU logs every cycle.
That permanence is one reason candidates weigh the CCA carefully against the upfront cost and study effort. If you want the numbers behind how the exam has performed for past candidates, CCA Pass Rate 2026: What the Data Shows covers what's publicly known, and CCA Cheat Sheet 2026: One-Page Review of Must-Know Facts is a handy last-mile reference before exam day. You can also run a quick readiness check anytime using our CCA practice questions to see which domains still need attention.
Frequently Asked Questions
CCA stands for Certificate in Cybersecurity Analysis, issued by IIBA in collaboration with the IEEE Computer Society, formally designated IIBA-CCA. See What Does CCA Stand For? and CCA Meaning for related explanations.
The exam is delivered remotely through PSI's online proctoring system. You'll need a compatible computer, webcam, microphone, valid ID, and a secure, private testing space - no reference materials, calculator, or breaks are allowed during the session.
No. The learning program is optional. You can register directly for the exam alone, or choose the combined learning-and-exam package if you want structured preparation bundled in.
Data Security and User Access Control are the two largest domains, each worth 15% of the exam, together accounting for 30% of total content.
No. The certificate does not expire and there is no recertification requirement or continuing development units (CDUs) needed to maintain it.