- The Short Answer: What CBCA Means
- Who Issues the Credential
- Course, Exam, and Certification Are Three Different Things
- What the Audit Examination Looks Like
- What a CBCA Candidate Must Know
- Fees and Registration Mechanics
- Experience, Essays, and References
- Who Uses the CBCA Credential
- Keeping the Credential Active
- Avoiding Acronym Confusion
- A Domain-Ordered Preparation Sequence
- Frequently Asked Questions
- CBCA stands for Certified Business Continuity Auditor, a credential issued by DRI International.
- Passing the 100-question, 2-hour-30-minute audit exam with at least 75% does not by itself confer certification.
- Certification also requires an experience-based application with five essays and validating references.
- Published pricing is $2,950 for the course with first exam, plus a $400 application fee.
The Short Answer: What CBCA Means
On this site, CBCA means Certified Business Continuity Auditor. It is a professional designation from DRI International (the Disaster Recovery Institute) for practitioners who audit business continuity programs. In practice, a CBCA evaluates whether an organization's continuity management system actually meets a recognized standard, and then communicates findings, recommendations, and an opinion to management.
That auditing focus is what separates the credential from general continuity planning certifications. A planner builds the program. An auditor tests it against a standard, gathers evidence, and reports on conformity and gaps. If you want other angles on the same question, our related explainers cover what CBCA stands for and the broader definition of CBCA certification.
Who Issues the Credential
DRI International is the governing body for the CBCA. It publishes the course content, administers the Audit Examination through its own online examination and account process, and reviews certification applications. No external testing vendor such as Pearson VUE, PSI, or Prometric has been verified for this specific examination, so candidates should expect to manage scheduling through their DRI account rather than a third-party test center portal.
This matters for planning. Because delivery runs through DRI's own system, the authoritative instructions for booking are the ones attached to your specific course registration, not a generic testing-center workflow.
Course, Exam, and Certification Are Three Different Things
The most common misunderstanding about the CBCA is treating "passing the exam" as the finish line. The pathway has distinct stages, and each has its own requirements:
- The course. Candidates complete the Business Continuity Planning for Auditors course, offered by DRI as BCLE AUD in an ISO 22301 version and an NFPA 1600 version. Current US courses run four full instructional days and award 32 Continuing Education Activity Points (CEAPs). The course can be taken without any previous DRI certification.
- The Audit Examination. After the course, candidates sit a 100-question multiple-choice exam. The course descriptions say the exam is taken online at the learner's convenience after the course.
- The certification application. Passing the exam alone does not confer professional certification. DRI separately reviews an experience-based application before awarding the CBCA designation.
For a fuller walk through eligibility, see our guide to CBCA requirements and how to qualify.
What the Audit Examination Looks Like
| Feature | What Is Published |
|---|---|
| Question count | 100 multiple-choice questions |
| Time allowed | 2 hours 30 minutes |
| Passing standard | At least 75% individual score |
| Delivery | Online, via DRI's examination/account process |
| Retake fee | $250 per audit-exam retake |
| Published pass rate | Not publicly disclosed |
| Scored vs. unscored breakdown | Not specified in reviewed official sources |
Two points deserve emphasis. First, the exam is multiple choice. The course includes a hypothetical-company case study and hands-on auditing activities, but those are classroom exercises, not a performance-based or essay exam. The five subject-matter essays belong to the certification application, not the 100-question test.
Second, the 75% figure is the required individual score, not an observed pass rate. DRI does not publish cohort pass statistics in the materials reviewed, so any number you see quoted for the CBCA specifically should be treated skeptically. Our pages on the CBCA passing score and what data exists on pass rates go deeper on both topics.
Details such as open-book or closed-book status, calculator rules, remote-proctoring specifics, and permitted reference materials could not be verified publicly. Confirm those through your DRI course materials rather than assuming they match any other exam you have taken.
What a CBCA Candidate Must Know
The audit course is built around auditing a continuity program against a standard. The ISO 22301 route, which is the focus of this site's preparation material, follows a sequence of topics that mirrors how an audit unfolds. The headings below reflect DRI's current ISO 22301 audit-course outline; they are preparation topics, not an official weighted blueprint, because DRI has not published domain percentages for the exam.
Auditing basics
The foundation: what an audit is, how evidence is gathered and evaluated, and how auditors conduct themselves.
- Audit purpose, scope, and criteria
- Evidence collection techniques such as interviews, document review, and observation
- Auditor independence and professional conduct
Understanding ISO 22301
The standard itself is the audit yardstick. Candidates need fluency in how its clauses fit together and what conformity looks like.
- Structure and intent of the business continuity management system standard
- The difference between requirements ("shall") and supporting guidance
- How the standard references ISO 22301:2019 in the current course
Context of the organization
Auditors verify that the organization understands its internal and external environment and the needs of interested parties.
- Scope definition and its justification
- Interested parties and their requirements
Leadership, planning, support, and operation
This area tests whether management commitment is real and documented, and whether resources, competence, and operational controls exist.
- Policy, roles, and top-management evidence
- Objectives, resources, awareness, and documented information
- Operational planning and control
Risk assessment
Auditors examine how the organization identifies, analyzes, and treats risks to its prioritized activities.
- Risk identification and evaluation methods
- Linkage between risk treatment and continuity strategy
Business impact analysis (BIA)
The BIA drives priorities. Auditors check whether impacts over time, recovery objectives, and dependencies were identified credibly.
- Prioritized activities and impact over time
- Recovery time objectives and dependencies
- Whether results were approved and used downstream
Continuity strategies and solutions
Candidates assess whether chosen strategies are proportionate to BIA and risk results.
- Strategy selection criteria and resource requirements
- Traceability from analysis to chosen solution
Business continuity plans
Plans must be usable, current, and aligned with strategy.
- Incident response structure and activation criteria
- Plan content, roles, and communications
- Document control and version currency
Education and training
Auditors verify that people know their roles and that competence is evidenced.
- Awareness versus role-specific training
- Records that demonstrate completion and effectiveness
Exercise program
Exercising proves the plans work. Auditors evaluate the program's design, frequency, and follow-through.
- Exercise types, objectives, and scope
- Post-exercise reporting and corrective actions
Audit findings, recommendations, and auditor's opinion
The culminating skill: turning evidence into clear findings and a defensible opinion.
- Writing findings that tie to criteria and evidence
- Classifying nonconformities and proposing recommendations
- Framing an overall opinion for management
Notice the logic of the sequence: the organization's context feeds risk and BIA, those feed strategies, which feed plans, which are then trained on and exercised, and finally the auditor reports. Questions often test whether you can follow that chain and spot where an organization broke it. For a topic-by-topic breakdown, see our guide to the 11 CBCA content areas.
Key Takeaway
Think like an auditor, not a planner. Exam scenarios reward the answer that asks "what evidence demonstrates conformity?" rather than "how would I build this?" Practice tracing each requirement to the artifact that would prove it.
Fees and Registration Mechanics
Because the exam is bundled with a mandatory course, CBCA pricing works differently from exams sold separately. The published figures are:
| Item | Published Amount (US) |
|---|---|
| Course plus first exam (BCLE AUD, ISO 22301 or NFPA 1600) | $2,950 |
| Certification application | $400 |
| Training-plus-application subtotal | $3,350 |
| Audit-exam retake | $250 |
| Annual renewal | $225 |
The first exam attempt is included in the course price; it is not an additional charge. The $3,350 subtotal is simply the course fee plus the application fee, calculated before renewal, travel, taxes, or discounts. DRI's Continuity Audit FAQ mentions a 10% discount for NFPA and other professional-organization members, but it does not list every qualifying organization or show a discounted checkout total, so confirm eligibility and the final amount with DRI before budgeting around it. No separate member versus nonmember exam-only price is published for this mandatory-course route.
For the full financial picture, including how to think about total outlay, read our CBCA certification cost breakdown.
Experience, Essays, and References
The application is where the credential becomes a professional designation rather than a course completion. DRI's published requirements include:
- Experience: at least two years of significant practical experience in business continuity, emergency or disaster management, and/or audit within the preceding ten years.
- Essays: five subject-matter essays, with at least two drawn from DRI's specified application areas covering business impact analysis, continuity strategies, plan development and implementation, and exercise/test/assessment/maintenance.
- References: two validating references per subject area, which may be the same two people across all five areas.
No degree requirement and no fixed experience-hour threshold was found in the reviewed materials. Certain existing professional designations may qualify an applicant for waivers in the reference or experience sections, but this is not a blanket waiver of the audit course, the exam, or the CBCA experience requirement.
Who Uses the CBCA Credential
The CBCA fits professionals whose work involves assessing continuity programs rather than only running them. Typical roles include internal auditors who cover resilience and continuity, business continuity managers who prepare for certification audits against ISO 22301, risk and compliance professionals, and consultants who perform continuity program assessments for clients. Organizations in regulated sectors often care most, because resilience and continuity expectations are scrutinized by regulators and customers.
We have deliberately avoided quoting salary ranges here because DRI does not publish them and invented figures would mislead you. For a qualitative look at earning potential and role types, see our CBCA salary guide, our overview of CBCA jobs, and the ROI analysis for the certification.
Keeping the Credential Active
CBCA status is not a one-time achievement. Maintaining it involves two separate obligations that are easy to conflate:
- Annual financial maintenance: a $225 fee each year.
- Continuing education: 80 CEAPs over each two-year period, along with compliance with DRI's code of ethics.
Do not describe the credential as an unconditional two-year certification. The annual fee and the two-year CEAP cycle run on different clocks, and both matter. Note that the 32 CEAPs awarded for completing the audit course can count toward continuing-education needs, though you should confirm how DRI applies them to your cycle.
Avoiding Acronym Confusion
Search results for "CBCA" can mix very different credentials. To stay on the right track, verify three things before trusting any article or training product: the issuing body should be DRI International; the credential name should be Certified Business Continuity Auditor; and the exam should be the audit examination tied to the BCLE AUD course. DRI also runs a general qualifying examination that is a separate assessment and should not be substituted for the audit exam. The same caution applies to the ISO 22301 versus NFPA 1600 routes: they are distinct course-and-exam pairings, and this site's preparation material addresses only the ISO 22301 route.
If you want to see how the terminology varies across searches, our pages on what CBCA is and the meaning of CBCA address the same question from other angles.
A Domain-Ordered Preparation Sequence
Rather than generic advice, sequence your study to follow the audit logic of the course. Because DRI publishes no weighted blueprint, treat the allocation below as an editorial suggestion, not an official weighting.
Standard and audit fundamentals
- Auditing basics and the structure of ISO 22301
- Context of the organization and leadership topics, since later domains assume this vocabulary
The analysis chain
- Risk assessment and business impact analysis
- Practice tracing BIA outputs into strategy selection
Strategies, plans, training, and exercises
- Continuity strategies, plans, education and training, and the exercise program
- Write your own scenario questions about evidence for each
Reporting and timed practice
- Audit findings, recommendations, and the auditor's opinion
- Timed sets of 100 independently written practice questions within 2 hours 30 minutes
Keep in mind that DRI requires candidates to keep course and exam materials confidential, so build practice questions from your own understanding of the standard rather than reproducing course content. For a fuller plan, see our CBCA study guide, and gauge expectations with our look at how difficult the exam is. You can also quiz yourself on realistic scenarios with the CBCA practice tests, and the one-page cheat sheet works well for final review. If you are still deciding whether to enroll, our overview of CBCA training explains the course route in more detail.
Key Takeaway
Schedule risk assessment and BIA before strategies and plans. Those two domains generate the inputs that every later domain depends on, so weakness there compounds throughout the rest of your preparation.
Frequently Asked Questions
CBCA stands for Certified Business Continuity Auditor, a professional designation issued by DRI International for practitioners who audit business continuity management programs.
No. Passing the 100-question Audit Examination with at least 75% is required, but DRI also reviews a separate experience-based application, including five essays and validating references, before conferring the certification.
The Audit Examination has 100 multiple-choice questions and allows 2 hours 30 minutes. The course descriptions say it is taken online after the course, at the learner's convenience.
The published US course-and-exam price is $2,950, which includes the first exam attempt. The certification application is $400, giving a $3,350 subtotal before renewal, travel, taxes, or discounts. Retakes are $250 and annual renewal is $225.
DRI does not publicly disclose a pass rate in the official materials reviewed. The 75% figure is the score you must achieve, not a statistic about how many candidates succeed.