If you want to lead or take part in official Cybersecurity Maturity Model Certification (CMMC) Level 2 assessments, the ISACA CMMC Certified Assessor (ISACA CCA™) credential makes it possible. The exam is long, detail-heavy, and packed with scoping and evidence scenarios, so it’s normal to feel a little overwhelmed at first. The good news is that the blueprint tells you exactly where the points are, and a plan built around it can get you through on your first try.

In this guide, we’ll walk you through what the CCA is, the exam format, each of the four blueprint domains and their weights, the official resources worth bookmarking, and the questions candidates ask most often.

What Is the ISACA CCA Exam?

The CCA is the assessor-level credential in the CMMC program run by the Department of War (DoW, formerly the Department of Defense). CCAs work for Certified Third-Party Assessment Organizations (C3PAOs) and evaluate whether defense contractors, called Organizations Seeking Certification (OSCs), meet the 110 security requirements of CMMC Level 2, based on NIST Special Publication (SP) 800-171 Revision 2.

The Cyber AB previously managed the credential entirely. In December 2025, ISACA was authorized as the CMMC Assessor and Instructor Certification Organization (CAICO), and by April 2026 it had taken over training oversight, exams, and certification for CCPs and CCAs. The Cyber AB is still the accreditation body and still handles Tier 3 background investigation coordination for assessors.

Most exam questions give you an assessment situation, such as an asset that may or may not be in scope or a piece of evidence that may or may not prove a practice, and ask what the assessor should conclude or do next.

What Is the ISACA CCA Exam Format?

Here’s the exam at a glance, based on the ISACA CCA certification page and the CCA Exam Content Outline:

  • Questions: 150 multiple-choice questions.
  • Time: 4 hours (240 minutes), or about 96 seconds per question.
  • Delivery: Computer-based through PSI, at a test center or as a remotely proctored exam.
  • Registration: Continuous. You can schedule as early as 48 hours after paying, and your registration is valid for six months.
  • Prerequisite before testing: You must complete the mandatory CCA training through a CAICO-approved training provider (ATP).
  • Scoring: Results are reported as a scaled score. Check the ISACA candidate guide for the current cut score and results timeline, since CAICO sets those details.

Ninety-six seconds per question sounds generous, but many CCA stems describe a network, a list of assets, or an evidence set. Practice reading scenarios for the one detail that changes the answer.

What Content Outline Does the ISACA CCA Exam Use?

Pocket Prep’s CCA content aligns with the ISACA CCA Exam Content Outline. Here is how the 150 questions break down. The question counts are approximate and calculated from the percentages.

  • Domain 1, Evaluating OSC Against CMMC Level 2: 15% (about 22 questions)
  • Domain 2, CMMC Level 2 Assessment Scoping: 20% (about 30 questions)
  • Domain 3, CMMC Assessment Process (CAP): 25% (about 37 questions)
  • Domain 4, Assessing CMMC Level 2 Practices: 40% (about 60 questions)

Domain 1: Evaluating OSC Against CMMC Level 2 (15%)

This domain is about understanding the environment you are walking into. Before you can judge a practice, you need to know how the OSC’s locations, facilities, and technology shape what the practice looks like in real life.

  • Logical versus physical locations, and how each affects evidence collection.
  • Professional (office) versus industrial (manufacturing floor) environments.
  • Single-site and multi-site constraints.
  • Cloud, hybrid, and on-premises environments.
  • Environmental exclusions and how they are justified and documented.

What questions look like: An OSC runs its CUI workloads in a cloud tenant but keeps badge-controlled servers at one of three plants. Expect to decide which sites and components the assessment must actually reach.

Domain 2: CMMC Level 2 Assessment Scoping (20%)

Scoping decides what gets assessed and how deeply. The blueprint ties this domain to the CMMC Level 2 Scoping Guide and its five asset categories.

  • Categorize assets as CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, or Out-of-Scope Assets.
  • Analyze scope in scenarios, including logical separation (firewalls, VLANs) and physical separation (locks, badge access, guards).
  • Evaluate whether Federal Contract Information (FCI) and CUI sit in the same or different assessment scopes.
  • Evaluate External Service Providers (ESPs), including customer responsibility matrices and service level agreements.

Study tip: Memorize what each asset category requires. For example, Specialized Assets such as operational technology and government-furnished equipment must be documented in the asset inventory, System Security Plan (SSP), and network diagram, but they are not assessed against every Level 2 practice.

Domain 3: CMMC Assessment Process (CAP) (25%)

This domain tests whether you know how an official assessment runs from start to finish, and which activities belong in which phase.

  • Plan and prepare the assessment: analyze requirements, develop the assessment plan, and verify readiness.
  • Conduct the assessment: collect and examine evidence, score practices, and generate preliminary results.
  • Report results: deliver recommended assessment results through the proper channels.

What questions look like: A question may describe the lead assessor discovering that the SSP doesn’t match the scope in the assessment plan. You’ll need to know what should have happened during readiness review and what the team does now. Note that the current CAP document, released after the 32 CFR Part 170 rule, adds a POA&M close-out phase, so know how conditional status and close-out work too.

Domain 4: Assessing CMMC Level 2 Practices (40%)

This is the largest domain and the heart of the exam. It covers how you gather and judge evidence for all 110 Level 2 practices across the 14 families, from Access Control (AC) to System and Information Integrity (SI).

  • Use the three assessment methods from NIST SP 800-171A: examine, interview, and test.
  • Judge evidence for adequacy and sufficiency.
  • Look for evidence that practices are applied consistently, such as policies, plans, resourcing, communication, and training.
  • Apply the CMMC Assessment Guide’s assessment objectives to decide whether each practice is MET, NOT MET, or NOT APPLICABLE.

Study tip: A practice is MET only when every one of its assessment objectives is satisfied. Questions often show evidence that covers most objectives but misses one.

How Should You Use the CCA Blueprint to Build a Study Plan?

Treat the blueprint as your master checklist. Here’s a practical way to turn it into a plan:

  1. Take a baseline. Answer a mixed set of practice questions before reviewing so you know where you stand.
  2. Weight your time. Domain 4 alone is 40% of the exam, and Domains 3 and 4 together are 65%. Put most of your hours there, but don’t skimp on scoping. Roughly 30 scoping questions can make or break a score.
  3. Map every miss to a domain and practice. Label wrong answers by domain and, for Domain 4, by practice family. Patterns show up quickly.
  4. Read the source documents side by side. The Assessment Guide, Scoping Guide, and CAP answer most “what would an assessor do” questions.
  5. Finish with timed, mixed practice. In the final weeks, practice at exam pace so long scenario stems don’t slow you down.

What Official Resources Should You Use?

Frequently Asked Questions About the ISACA CCA Exam

Do I need to be a CCP first?
Yes. ISACA requires an active CMMC Certified Professional (CCP) certification to earn the CCA, along with the mandatory CCA training, a qualifying DoD 8140 certification, and relevant experience.

How many questions are on the CCA exam, and how long is it?
The exam has 150 multiple-choice questions, and you have 4 hours.

Who administers the CCA exam?
ISACA, as the CAICO, now handles CCA exams and certification. The exam is delivered through PSI. The Cyber AB remains the accreditation body.

What is the passing score?
The CCA uses a scaled score. Because the CAICO sets and publishes the cut score, confirm it in the current ISACA candidate guide rather than relying on third-party figures.

How do I keep the CCA once I earn it?
You earn at least 120 continuing professional education (CPE) hours over each three-year cycle, with at least 20 each year, and follow ISACA’s Code of Professional Ethics.

Start Preparing for the ISACA CCA Exam With Pocket Prep

Pocket Prep’s ISACA CCA™ practice questions give you 500 exam-style questions across all four domains, and every one includes a detailed answer explanation that shows the assessor reasoning behind the best choice. Use Weakest Subject quizzes to zero in on scoping or practice assessment, then build exam stamina with Timed Quiz sessions. Keep at it a little each day, and you’ll be ready to walk into your assessment career with confidence.