- What Is CCA Certification?
- Who Issues the Credential and Why It Matters
- Exam Format: What Actually Happens on Test Day
- The Eight Domains You Must Master
- Registration, Fees, and the Learning Package
- Who Hires CCA-Certified Professionals
- Preparing for the Exam: A Domain-Weighted Approach
- After You Pass: No Recertification Required
- Frequently Asked Questions
- IIBA-CCA is issued by the International Institute of Business Analysis with the IEEE Computer Society.
- The exam has 75 knowledge-based multiple-choice questions in a 90-minute window, delivered via PSI.
- Data Security and User Access Control are the heaviest domains, each worth 15% of the exam.
- Exam fees are USD 250 for members and USD 405 for non-members, with retakes priced separately.
What Is CCA Certification?
The Certificate in Cybersecurity Analysis (CCA) - officially designated IIBA-CCA - is a knowledge-based credential built jointly by the International Institute of Business Analysis (IIBA) and the IEEE Computer Society. It is aimed at business analysts, security-adjacent professionals, and technical staff who need a structured, vendor-neutral way to demonstrate that they understand how cybersecurity concepts intersect with business analysis, risk management, and solution delivery.
Unlike credentials that require years of documented work experience or a portfolio review, CCA is earned entirely by passing a single proctored exam. That makes it accessible to people transitioning into security-adjacent roles, but it also means the exam itself is the whole story - there is no experience waiver and no alternate path. If you want the full picture of how this designation is classified and what "CCA" means in this specific context, our companion piece on CCA Certification lays out the terminology in more depth, and What Is CCA? answers the acronym question directly.
Who Issues the Credential and Why It Matters
IIBA is best known in the business analysis community, and its partnership with the IEEE Computer Society on this certificate reflects the credential's positioning: it is not a purely technical penetration-testing or forensics certification. Instead, CCA sits at the intersection of analysis and security - evaluating risk, translating security requirements into solution design, and understanding operational controls from an analyst's vantage point rather than a pure engineering one.
Candidates who register agree to IIBA's ethics and professional standards as part of the certification process. This is a formal commitment, not a formality - it signals that IIBA treats the credential as part of its broader professional ecosystem rather than a standalone technical badge. For a deeper breakdown of eligibility expectations, see CCA Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Exam Format: What Actually Happens on Test Day
The CCA exam is delivered as a remote-proctored test through PSI. That single detail shapes almost everything about how you should prepare and how you should plan your test day logistics.
- Question count and timing: 75 knowledge-based multiple-choice questions, 90 minutes total - roughly 72 seconds per question if you pace evenly.
- Scoring: Results are reported as pass/fail only. There is no published scaled score breakdown released to candidates, so your prep should focus on domain mastery, not chasing a specific point target. Our article on CCA Passing Score 2026: Exactly What You Need to Pass walks through what pass/fail reporting actually means for how you study.
- Environment requirements: a valid ID, a compatible computer, a working webcam and microphone, and a secure, private testing space. No reference materials, no calculator, and no breaks are permitted during the session.
- Purchase window: once you buy the exam, you have six months to complete it, which affects how you should time your registration relative to your study schedule.
Because there are no breaks and no reference materials allowed, candidates who are used to open-book or paced exams should treat the CCA exam as a closed-book, single-sitting event. If you're unsure whether the format itself will be a challenge, How Hard Is the CCA Exam? Complete Difficulty Guide 2026 breaks down the difficulty profile in more detail, and CCA Exam Dates 2026: Testing Windows, Deadlines & Scheduling covers how the six-month window interacts with scheduling.
Key Takeaway
Practice full 90-minute, 75-question sessions under closed-book conditions before test day. The remote-proctoring rules leave no room for surprises about what you can and can't have on your desk.
The Eight Domains You Must Master
The 2026 IIBA-CCA Handbook defines an eight-domain blueprint for the exam. Note that this is different from the optional learning program, which is organized into nine courses - don't confuse the exam's domain structure with the course structure when you're planning study time. A full domain-by-domain breakdown is available in CCA Exam Domains 2026: Complete Guide to All 8 Content Areas, but here is the weighting you need to know:
| Domain | Weight |
|---|---|
| 1. Cybersecurity Overview and Basic Concepts | 14% |
| 2. Enterprise Risk | 14% |
| 3. Cybersecurity Risks and Controls | 12% |
| 4. Securing the Layers | 5% |
| 5. Data Security | 15% |
| 6. User Access Control | 15% |
| 7. Solution Delivery | 13% |
| 8. Operations | 12% |
Data Security (15%)
This is one of the two heaviest domains, tied with User Access Control. Candidates need a firm grasp of how data is classified, protected in transit and at rest, and governed across its lifecycle.
- Data classification and handling standards
- Encryption concepts and where they apply in a solution
- Data lifecycle governance from creation to disposal
User Access Control (15%)
Also weighted at 15%, this domain covers identity, authentication, and authorization concepts as they relate to enterprise systems and analyst-driven solution design.
- Authentication vs. authorization distinctions
- Access control models and least-privilege principles
- Identity management as it intersects with business requirements
Securing the Layers (5%)
The lightest domain by weight, but still testable. It focuses on layered security concepts across network, application, and infrastructure boundaries.
- Defense-in-depth reasoning
- How layered controls reduce single points of failure
Notice that Domains 5 and 6 together account for 30% of the exam - nearly a third of your score rides on data security and access control alone. That single fact should shape how you allocate review time far more than generic advice ever could.
Registration, Fees, and the Learning Package
CCA pricing follows a member/non-member structure, and understanding it before you register avoids surprises:
- Exam fee: USD 250 for IIBA members, USD 405 for non-members. The non-member price includes a first-year IIBA membership, which is worth factoring into your cost comparison.
- Retake fee: USD 195 for members, USD 350 for non-members, if you don't pass on the first attempt.
- Optional learning-and-exam package: USD 395 for members, USD 550 for non-members. This bundles the exam with IIBA's optional learning program - remember, that program is structured as nine courses, distinct from the exam's eight domains.
For a complete cost comparison, including how the membership bundling affects total spend, see CCA Certification Cost 2026: Complete Pricing Breakdown. And if you're weighing whether the investment is justified relative to your career goals, Is the CCA Certification Worth It? Complete ROI Analysis 2026 covers that question directly.
Who Hires CCA-Certified Professionals
Because CCA blends business analysis with cybersecurity fundamentals, it tends to appeal to a specific slice of the workforce: business analysts moving into security-adjacent roles, IT professionals who need to speak fluently about risk and controls in cross-functional meetings, and project or product roles where security requirements must be translated into deliverable specifications. It's not primarily aimed at penetration testers or incident responders - the domain weighting (heavy on data security, access control, enterprise risk, and solution delivery) reflects an analyst's view of security rather than a hands-on offensive security skill set.
If you're evaluating whether this credential fits your career trajectory, browsing typical CCA Jobs descriptions is a useful sanity check - look for how often "risk," "requirements," and "controls" appear together in the same posting, which is a strong signal that the role rewards the analyst-plus-security blend this certificate represents.
Preparing for the Exam: A Domain-Weighted Approach
Rather than a generic study calendar, the most efficient way to prepare for CCA is to let the domain weights dictate your time allocation. Since Data Security and User Access Control each carry 15%, and Securing the Layers carries only 5%, spending equal time on all eight domains is a mistake.
Foundational Domains
- Cybersecurity Overview and Basic Concepts (14%)
- Enterprise Risk (14%)
Highest-Weight Domains
- Data Security (15%)
- User Access Control (15%)
Mid-Weight Domains
- Cybersecurity Risks and Controls (12%)
- Solution Delivery (13%)
- Operations (12%)
Light Review and Practice Exams
- Securing the Layers (5%)
- Full-length timed practice sessions on the practice test platform
This isn't a generic weekly template - it's ordered specifically around the CCA blueprint, front-loading the domains worth the most points before spending limited time on the 5%-weighted Securing the Layers domain. For a more exhaustive walkthrough of study strategy, see CCA Study Guide 2026: How to Pass on Your First Attempt, and for a compact review resource in the final days before your test, CCA Cheat Sheet 2026: One-Page Review of Must-Know Facts condenses the must-know points by domain.
After You Pass: No Recertification Required
One of the more distinctive features of CCA compared to many other professional certifications is that it does not expire. There's no ongoing CDU (continuing development unit) tracking, no renewal fee, and no periodic recertification exam. Once you pass, the credential is yours permanently under IIBA's current policy.
This changes the math on whether the exam fee and prep time are worth it - you're not signing up for a recurring cost cycle, just a one-time investment. If you want to see how that permanence factors into overall value, our ROI breakdown at Is the CCA Certification Worth It? Complete ROI Analysis 2026 covers it alongside cost and career impact. And if you're still deciding whether the return justifies the exam fee relative to your target roles, the CCA Salary Guide 2026: Complete Earnings Analysis is a useful companion read.
Key Takeaway
Because CCA never expires, there's no benefit to rushing an underprepared attempt just to "get it done early." Take the extra week if you need it - the retake fee costs more than the time.
Frequently Asked Questions
In this article, CCA refers to the Certificate in Cybersecurity Analysis, officially designated IIBA-CCA, issued by the International Institute of Business Analysis in collaboration with the IEEE Computer Society. See What Does CCA Stand For? and CCA Meaning for more on the terminology.
The exam contains 75 knowledge-based multiple-choice questions and must be completed within 90 minutes, delivered remotely through PSI's proctoring platform.
The exam fee is USD 250 for IIBA members and USD 405 for non-members, with the non-member fee including first-year IIBA membership. Retakes are USD 195 for members and USD 350 for non-members.
Data Security and User Access Control are the two largest domains, each worth 15% of the exam, followed by Cybersecurity Overview and Basic Concepts and Enterprise Risk at 14% each.
No. The CCA certificate does not expire and requires no recertification or continuing development units (CDUs) once earned.