Cybersecurity is not only a technical problem, and the IIBA Certificate in Cybersecurity Analysis exists because someone has to connect the security requirements to the business. The CCA certifies exactly that bridge role: the business analyst or practitioner who can translate cyber risk into requirements, controls, and solutions that an organisation can actually deliver.
Developed jointly by IIBA and the IEEE Computer Society, the CCA is unusual in being aimed at analysts rather than engineers, and its eight weighted domains reflect that framing. Data Security and User Access Control lead the weightings, but risk and controls run throughout. This guide breaks down each domain and sets out a plan matched to how the exam distributes its marks.
Table of Contents
- What Does the IIBA CCA Exam Cover?
- Who Should Take the Certificate in Cybersecurity Analysis?
- What Do the Cybersecurity Overview and Enterprise Risk Domains Test?
- How Are Cybersecurity Risks, Controls, and Layered Security Covered?
- Why Do Data Security and User Access Control Carry the Most Weight?
- What Does the Solution Delivery Domain Require?
- How Does the Operations Domain Approach Security?
- What Careers Does the CCA Support?
- How Should You Structure a CCA Study Plan?
- Frequently Asked Questions
- Conclusion
What Does the IIBA CCA Exam Cover?
The IIBA CCA (Certificate in Cybersecurity Analysis) is a 90-minute exam of 75 multiple-choice questions, scored pass or fail, delivered through Prometric. Fees are $250 for IIBA members and $405 for non-members. It validates the ability to apply business analysis practice to cybersecurity across eight weighted domains, from risk through controls to operations.
How Is the Exam Scored?
The CCA uses binary pass or fail scoring rather than a published percentage, so the practical goal is competence across all eight domains. Because the domains are weighted, Data Security and User Access Control at 15 percent each carry the most influence, but the smaller domains still contribute, and the analyst framing means questions test application rather than pure recall.
Domain Weightings at a Glance
| Domain | Weight |
|---|---|
| Data Security | 15% |
| User Access Control | 15% |
| Cybersecurity Overview and Basic Concepts | 14% |
| Enterprise Risk | 14% |
| Solution Delivery | 13% |
| Cybersecurity Risks and Controls | 12% |
| Operations | 12% |
| Securing the Layers | 5% |
The weightings are unusually even, with seven of the eight domains between 12 and 15 percent. That flatness means breadth matters more than depth in any single area, and a balanced study plan beats concentrating on a favourite topic.
Who Should Take the Certificate in Cybersecurity Analysis?
The CCA is aimed at business analysts, systems analysts, and project professionals who need to work fluently with cybersecurity requirements. It suits those moving cybersecurity from a bolt-on afterthought toward a built-in discipline, and it is a strong fit for analysts on projects where security and compliance are central concerns.
What Background Helps
A business analysis foundation makes the CCA far more approachable, since the exam applies familiar analysis techniques to a security context. Candidates without that background can still succeed but face a steeper climb. Those newer to analysis often start with an entry credential, and this guide to the IIBA ECBA certification shows how the foundation connects to the specialisation.
A Different Angle on Security
Unlike engineer-focused security exams, the CCA approaches cybersecurity through the analyst’s lens of requirements, risk, and delivery. For an orientation to the credential and its path, this path to the IIBA CCA certificate sets out what the journey involves. The official framing is available on the IIBA CCA certification page.
Once you know the blueprint, put it to work with a full IIBA CCA practice exam to benchmark your readiness under real conditions.
What Do the Cybersecurity Overview and Enterprise Risk Domains Test?
The Cybersecurity Overview and Basic Concepts domain (14%) and the Enterprise Risk domain (14%) together establish the foundation the rest of the exam builds on. One provides the vocabulary and core concepts of cybersecurity; the other frames security as a matter of managing risk to the enterprise.
Core Concepts and Frameworks
The overview domain covers the fundamental concepts, terminology, and frameworks that structure cybersecurity work. Familiarity with a recognised framework such as the NIST Cybersecurity Framework helps here, because the exam expects you to place controls and activities within a coherent model rather than treat them as isolated facts.
Enterprise Risk
The Enterprise Risk domain applies risk management to security. Understand how threats, vulnerabilities, and impacts combine into risk, how risk is assessed and prioritised, and how an analyst communicates it to stakeholders. This domain is where the business analyst’s instinct for stakeholder needs meets the discipline of security risk.
How Are Cybersecurity Risks, Controls, and Layered Security Covered?
The Cybersecurity Risks and Controls domain (12%) and the Securing the Layers domain (5%) move from understanding risk to doing something about it. Together they cover the controls that mitigate risk and the layered, defence-in-depth thinking that underpins a resilient architecture.
Risks and Controls
This domain expects you to connect specific risks to appropriate controls. Understand the categories of control, preventive, detective, and corrective, and how an analyst helps select and specify them. The exam frames this as a requirements activity: translating a risk into a control requirement the delivery team can implement.
Securing the Layers
Though the smallest domain at 5 percent, Securing the Layers reinforces the defence-in-depth principle: that security is applied across multiple layers rather than at a single perimeter. Understand how controls at the network, host, application, and data layers combine, and why no single layer is sufficient on its own.
Why Do Data Security and User Access Control Carry the Most Weight?
Data Security and User Access Control, each worth 15 percent, are the joint-largest domains because they address what most breaches actually target: the data itself and the access to it. Together they make up nearly a third of the exam, and they deserve proportionate attention.
Data Security
The Data Security domain covers protecting data across its lifecycle: classification, encryption, retention, and the controls that keep sensitive information safe at rest and in transit. The exam expects an analyst to understand how data protection requirements are identified and specified, connecting regulatory and business needs to concrete safeguards.
User Access Control
User Access Control covers who can access what, and how that is governed. Understand authentication, authorisation, the principle of least privilege, and identity and access management concepts. As an analyst, you are expected to translate access requirements into clear specifications, balancing security with the usability the business needs.
“The IIBA Certificate in Cybersecurity Analysis recognizes the ability of business analysis professionals to understand the requirements and value of cybersecurity concepts and apply them in the business context.”
What Does the Solution Delivery Domain Require?
The Solution Delivery domain, worth 13 percent, is where the analyst’s core discipline meets security. It covers how security requirements are built into solutions as they are designed, developed, and delivered, ensuring that cybersecurity is integral to the solution rather than added afterwards.
Building Security In
The domain reflects the CCA’s central philosophy: security is most effective when built in from the start. Understand how security requirements are elicited, specified, and traced through the delivery lifecycle, and how an analyst ensures they are not lost between concept and implementation. This is the analyst competence the certification most distinctively validates.
Working With Delivery Teams
Solution Delivery also covers collaboration with the teams that build and deploy. The exam expects you to understand how security requirements are validated, how they fit into development approaches, and how an analyst supports secure delivery without becoming a bottleneck. It is a practical, requirements-centred view of secure development.
For a related path, see our guide to the path to the IIBA CCA certificate.
How Does the Operations Domain Approach Security?
The Operations domain, worth 12 percent, covers security once a solution is live. It addresses the ongoing operational activities that keep systems secure, from monitoring and incident response to the continuous improvement that mature security programmes rely on.
Monitoring and Response
The domain expects familiarity with how security is maintained operationally: monitoring for threats, responding to incidents, and the processes that support both. From an analyst’s perspective, this means understanding the requirements that operational security imposes and how they feed back into future solutions.
Continuous Improvement
Operations also covers the idea that security is never finished. Understand how lessons from incidents and monitoring drive improvement, and how an analyst contributes by capturing and specifying the changes that result. The domain closes the loop between building security in and keeping it effective over time.
What Careers Does the CCA Support?
The CCA maps most directly to cybersecurity business analyst, security analyst, and requirements roles on security-focused projects. It signals a rare and valuable combination: the analyst’s ability to elicit and specify requirements applied to the domain of cybersecurity, which many organisations struggle to staff.
A Bridge Skill in Demand
The certification’s value lies in bridging two disciplines that often talk past each other. Security teams and business teams frequently misunderstand one another, and a professional who can translate between them is genuinely scarce. The CCA validates exactly that translation skill, which is why it commands attention on hybrid security and analysis roles. IIBA’s cybersecurity program resources describe how the discipline is positioned.
Registration
The exam is delivered through Prometric, and IIBA members pay a reduced fee. Confirm current requirements and any prerequisites through IIBA when you register, since the certification is periodically updated in partnership with the IEEE Computer Society.
“Business analysts have a responsibility to bring good security practices forward in the requirements area. Understanding cybersecurity is essential not just to protect your organization, but to create real business value.”
How Should You Structure a CCA Study Plan?
Six to eight weeks at five to seven hours per week suits most candidates with a business analysis background, and longer for those newer to either analysis or security. Because the domains are evenly weighted, a balanced plan that covers all eight matters more than deep focus on any one, and applying analysis techniques to security scenarios is the most effective preparation.
An Eight-Week Sequence
- Weeks one to two – foundations. Work through the cybersecurity overview and enterprise risk domains to build the conceptual frame.
- Weeks three to four – controls and data. Cover risks and controls, securing the layers, and the heavily weighted Data Security domain.
- Week five – access control. Study User Access Control in depth, given its 15 percent weight and its centrality to real breaches.
- Weeks six to seven – delivery and operations. Work through Solution Delivery and Operations, connecting security requirements to the full lifecycle.
- Week eight – review. Move to timed practice across all eight domains, reinforcing the even coverage the exam rewards.
The Habit That Separates Passes From Retakes
Think like an analyst, not an engineer. The CCA rewards the ability to translate security concepts into requirements and decisions, so practise framing scenarios as an analyst would rather than memorising technical detail. Working through a full IIBA CCA practice exam under timed conditions helps calibrate to the exam’s analyst-oriented question style and reveals which of the eight domains need more work.
Frequently Asked Questions
How many questions are on the IIBA CCA exam?
The exam contains 75 multiple-choice questions to be completed in 90 minutes. That is a comfortable pace, though the eight-domain breadth means preparation must be wide.
What is the passing score for the CCA?
The CCA is scored pass or fail rather than as a published percentage. Because the domains are weighted and fairly even, balanced competence across all eight is the practical requirement.
How much does the IIBA CCA exam cost?
The fee is $250 for IIBA members and $405 for non-members, delivered through Prometric. Retake fees are lower, at $195 for members and $350 for non-members.
Who develops the CCA certification?
The CCA is developed jointly by IIBA and the IEEE Computer Society, combining business analysis practice with cybersecurity expertise. This partnership gives the credential credibility across both disciplines.
Which domains carry the most weight?
Data Security and User Access Control each carry 15 percent, the joint-largest domains. Cybersecurity Overview and Enterprise Risk follow at 14 percent each, so the weightings are relatively even.
Is the CCA a technical exam?
No. It approaches cybersecurity through the business analyst’s lens of requirements, risk, and delivery rather than engineering. It suits analysts who need to work with security, not build it directly.
Do I need a business analysis background?
It helps considerably, since the exam applies analysis techniques to security. Candidates without that background can still pass but should expect to learn both the analysis framing and the security content.
What does building security in mean?
It is the CCA’s central idea that security should be integral to a solution from the start, elicited and specified as requirements, rather than added as an afterthought once the solution is built.
What jobs can the CCA support?
It maps to cybersecurity business analyst, security analyst, and requirements roles on security projects, particularly where translating between security and business teams is valued.
How long does it take to prepare for the CCA?
Six to eight weeks at five to seven hours per week is realistic for candidates with a business analysis background. Those newer to analysis or security should plan for longer.
Conclusion
The IIBA CCA fills a genuine gap by certifying the analyst who can carry cybersecurity requirements from business need to delivered solution. Its eight evenly weighted domains cover the full analyst view of security, from risk and controls through data protection and access to delivery and operations, and its even weighting rewards broad, balanced preparation.
Approach the exam as an analyst rather than an engineer, and lean into the heavily weighted Data Security and User Access Control domains without neglecting the rest. The certification’s distinctive value is the bridge it builds between security and business, so practise framing security as requirements and decisions.
Plan six to eight weeks, cover all eight domains evenly, and think in terms of building security in rather than bolting it on. The CCA validates a scarce and increasingly needed skill, and it opens the hybrid roles where cybersecurity and business analysis meet.
