- CCA stands for Certificate in Cybersecurity Analysis, issued as IIBA-CCA by IIBA with the IEEE Computer Society.
- The exam has 75 knowledge-based multiple-choice questions in 90 minutes, delivered via PSI remote proctoring.
- Data Security and User Access Control are the two heaviest domains, each worth 15% of the exam.
- Member exam fee is USD 250; non-members pay USD 405, which includes first-year IIBA membership.
What Is the Certificate in Cybersecurity Analysis?
The Certificate in Cybersecurity Analysis, officially designated IIBA-CCA, is a knowledge-based credential focused on the intersection of business analysis and cybersecurity practice. It's built for professionals who need to understand how security risk, controls, and governance decisions get translated into technical and organizational requirements - not for penetration testers writing exploit code. If you're researching this credential for the first time, this overview pairs well with our more detailed CCA Certification guide and the terminology breakdowns in CCA Meaning and What Does CCA Stand For?.
Unlike hands-on technical certifications that test configuration or scripting skills, the CCA exam is entirely multiple-choice and knowledge-based. Candidates are evaluated on their understanding of frameworks, risk concepts, control types, and secure delivery practices across eight defined domains, which we'll walk through below.
Who Issues the CCA and Why It Exists
The CCA is administered by the International Institute of Business Analysis (IIBA) in collaboration with the IEEE Computer Society. This pairing matters: IIBA brings its established business analysis certification infrastructure, while IEEE Computer Society lends technical credibility on the cybersecurity content itself. The result is a credential that sits deliberately at the seam between analytical/business roles and security operations - rather than duplicating a purely technical security certification.
Candidates who register agree to IIBA's ethics and professional standards as part of the certification process. There's also an optional learning-and-exam package available for those who want structured coursework bundled with their exam attempt, though the learning program itself is not mandatory - you can register for the exam independently if you already have the requisite knowledge. For a full eligibility breakdown, see CCA Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Exam Format, Fees, and Delivery
The CCA exam consists of 75 knowledge-based multiple-choice questions and runs for 90 minutes. It's delivered exclusively through PSI's remote-proctored platform, which means you can test from home or office rather than traveling to a physical test center - provided your setup meets the technical requirements.
Remote Proctoring Requirements
Because the exam is delivered online, candidates must arrive prepared with the right environment and documentation.
- Valid identification for verification before the session starts
- A compatible computer with a working webcam and microphone
- A quiet, secure testing environment free of interruptions
- No reference materials, calculators, or scheduled breaks are permitted during the 90 minutes
On the cost side, IIBA structures pricing around membership status:
| Item | IIBA Member | Non-Member |
|---|---|---|
| Standard exam fee | USD 250 | USD 405 (includes first-year IIBA membership) |
| Retake fee | USD 195 | USD 350 |
| Learning + exam package | USD 395 | USD 550 |
Once purchased, an exam attempt must be completed within six months, so scheduling matters as soon as you register. Results are reported strictly as pass/fail - there is no scaled score released to candidates. For a complete cost walkthrough including the retake math, read CCA Certification Cost 2026: Complete Pricing Breakdown, and for scheduling logistics see CCA Exam Dates 2026: Testing Windows, Deadlines & Scheduling.
Key Takeaway
Because retakes cost less than the original exam but still add up (USD 195-350), it's worth using a full-length practice test on our CCA practice platform before your first attempt rather than treating the exam as a low-stakes trial run.
The Eight CCA Exam Domains
The 2026 IIBA-CCA Handbook defines eight examination domains. It's worth noting these eight domains are distinct from the nine courses offered in the optional learning program - don't confuse the two when planning your study time. For a domain-by-domain deep dive, see CCA Exam Domains 2026: Complete Guide to All 8 Content Areas.
Domain 1: Cybersecurity Overview and Basic Concepts - 14%
Foundational terminology, the CIA triad, threat actors, and how security fits into broader organizational strategy.
Domain 2: Enterprise Risk - 14%
Risk identification, assessment methodologies, risk appetite, and how enterprise risk registers connect to security decisions.
Domain 3: Cybersecurity Risks and Controls - 12%
Mapping specific threats to preventive, detective, and corrective controls, plus control selection rationale.
Domain 4: Securing the Layers - 5%
The smallest domain, covering network, application, and infrastructure layering concepts for defense in depth.
Domain 5: Data Security - 15%
Tied for the largest domain. Covers classification, encryption concepts, data lifecycle protection, and data handling requirements.
- Expect the most questions from this area, so budget study time accordingly
Domain 6: User Access Control - 15%
Also tied for largest. Focuses on authentication, authorization models, identity governance, and least-privilege principles.
- Pair this domain with Data Security - together they represent 30% of the exam
Domain 7: Solution Delivery - 13%
Secure development lifecycle concepts, how security requirements get embedded into delivery and change processes.
Domain 8: Operations - 12%
Ongoing monitoring, incident response fundamentals, and operational security practices after deployment.
Who Should Pursue the CCA
The CCA sits at a specific professional intersection: analysts, requirements specialists, IT auditors, project and product roles, and early-career security professionals who need to speak fluently about risk, controls, and data protection without necessarily being hands-on technical engineers. Organizations hiring for governance, risk, compliance, business analysis with a security focus, and cross-functional security liaison roles often value this credential because it signals structured knowledge across the full breadth of the eight domains rather than deep specialization in one technical niche.
If you're weighing whether this matches your career direction, CCA Jobs outlines the types of roles that reference this certification, and CCA Salary Guide 2026: Complete Earnings Analysis discusses compensation context. For a broader cost-versus-benefit view, Is the CCA Certification Worth It? Complete ROI Analysis 2026 weighs the certification against the registration and study investment.
Preparing for the CCA Exam
Because the CCA tests knowledge across eight weighted domains rather than a single skill, preparation works best when it mirrors the exam's own weighting. Rather than spending equal time on all eight areas, allocate more review sessions to Data Security and User Access Control (15% each), moderate time to Cybersecurity Overview, Enterprise Risk, Solution Delivery, and Operations (12-14% each), and the least time to Securing the Layers (5%).
Foundations
- Cybersecurity Overview and Basic Concepts
- Enterprise Risk
High-Weight Domains
- Data Security (15%)
- User Access Control (15%)
Applied Domains
- Cybersecurity Risks and Controls
- Solution Delivery
- Operations
Review and Practice
- Securing the Layers (light review)
- Full-length timed practice exams
Since the exam allows no reference materials, calculator, or break during the 90-minute session, timed practice under realistic conditions matters more than passive reading. Running full simulations on our practice test platform before exam day helps you build the pacing needed to answer 75 questions without running out of time. For a structured week-by-week plan and specific topic checklists, our CCA Study Guide 2026: How to Pass on Your First Attempt goes deeper than this overview, and How Hard Is the CCA Exam? Complete Difficulty Guide 2026 sets realistic expectations for difficulty. If you want to understand exactly what score threshold you're aiming for, CCA Passing Score 2026: Exactly What You Need to Pass explains how pass/fail results work, and CCA Pass Rate 2026: What the Data Shows covers what's publicly known about outcomes.
A one-page reference like our CCA Cheat Sheet 2026: One-Page Review of Must-Know Facts can be useful in the final days before your test to confirm you haven't overlooked any domain, especially the smaller ones like Securing the Layers that are easy to under-prepare for simply because they carry less weight.
After You Pass: What the Certificate Means
One of the more practical facts about the CCA is what happens after you pass: the certificate does not expire and requires no recertification or continuing development units (CDUs). Once you clear the exam, the credential is yours permanently, without the ongoing renewal cycle that some other certifications impose. This makes the upfront investment - both the fee and the study time - a one-time commitment rather than a recurring obligation.
If your first attempt doesn't succeed, the retake fee (USD 195 for members, USD 350 for non-members) is lower than the original exam cost, but repeated attempts still add up financially and in lost time. That's a strong argument for thorough domain-weighted preparation the first time around, using resources like What Is CCA Certification? and What Is A CCA? to make sure your foundational understanding of the credential itself is solid before you even get to domain content.
Frequently Asked Questions
In this article, CCA refers to the Certificate in Cybersecurity Analysis, officially designated IIBA-CCA, issued by IIBA in collaboration with the IEEE Computer Society. Other industries use the same acronym for unrelated credentials, so always confirm context.
The exam contains 75 knowledge-based multiple-choice questions and must be completed within 90 minutes, with no scheduled breaks.
IIBA members pay USD 250 for the exam; non-members pay USD 405, which includes first-year IIBA membership. Retakes cost USD 195 for members and USD 350 for non-members.
Data Security and User Access Control are the largest domains, each worth 15% of the exam, together accounting for 30% of all questions.
No. The certificate does not expire and there is no recertification requirement or continuing development unit (CDU) obligation once you pass.