CBCA logo
Focused certification exam prep
Start practice

What Is A CBCA?

TL;DR
  • CBCA means Certified Business Continuity Auditor, a credential issued by DRI International (Disaster Recovery Institute International).
  • Passing the 100-question, 2-hour-30-minute audit exam at 75% or higher does not by itself confer certification.
  • The published training-plus-application subtotal is $3,350: the $2,950 course-and-exam bundle plus the $400 application.
  • Certification also requires two years of experience, five subject-matter essays, and two validating references per subject area.

The Short Answer: What a CBCA Is

A CBCA is a Certified Business Continuity Auditor: a professional who has completed DRI International's audit-focused training, passed its Audit Examination, and had an experience-based application accepted. The credential signals that the holder can evaluate whether an organization's business continuity program is sound, documented, and actually working, rather than simply build one.

That distinction matters. Many continuity credentials focus on writing plans, running recovery teams, or leading a program. The CBCA takes the reviewer's seat. A CBCA candidate learns to examine evidence, test whether a program meets a standard, and issue findings, recommendations, and an auditor's opinion. If you have seen other pages on this site that cover the same ground under slightly different phrasings, such as What Is CBCA? or What Does CBCA Stand For?, this article is the fuller walkthrough of how the credential actually works.

Identity check: Several unrelated credentials share the CBCA acronym. This article covers only the DRI International Certified Business Continuity Auditor. Fees, exam details, and renewal rules described here do not apply to any other credential abbreviated the same way.

Who Issues the Credential and How It Is Earned

The governing body is DRI International. The official designation is Certified Business Continuity Auditor (CBCA). DRI administers the Audit Examination through its own online examination and account process; no external proctoring vendor such as Pearson VUE, PSI, or Prometric was verified for this exam.

The most common misunderstanding is treating the credential as "just an exam." In reality, two separate gates exist:

  1. Course and examination. You complete the Business Continuity Planning for Auditors course (the BCLE AUD route) and then sit the Audit Examination.
  2. Professional certification application. DRI reviews your experience, essays, and references. Passing the exam alone does not confer the CBCA designation.
  3. Because the first gate is accessible to people without prior DRI certification, the course can be taken as a standalone learning investment. The credential itself, however, requires the application to be approved as well. For a deeper look at eligibility, see CBCA Requirements 2026.

    The Two-Part Path: Course and Exam, Then Application

    Part one: the audit course and examination

    Current US courses run four full instructional days and award 32 Continuing Education Activity Points (CEAPs). DRI offers two course variants: BCLE AUD for ISO 22301 and BCLE AUD for NFPA 1600. The course includes a hypothetical-company case study and practical auditing activities. These are classroom learning exercises, not part of the scored exam, so do not expect essay or performance tasks on test day.

    Part two: the certification application

    To obtain the CBCA designation, applicants need:

    • At least two years of significant practical experience in business continuity, emergency/disaster management, and/or audit within the preceding ten years.
    • Five subject-matter essays, at least two of which must come from DRI's specified application areas covering business impact analysis, continuity strategies, plan development and implementation, and exercise, test, assessment, and maintenance.
    • Two validating references per subject area, which may be the same two people across all five areas.

    No degree requirement and no fixed experience-hour threshold were found in the reviewed official materials. Certain existing professional designations can qualify for waivers of the reference or experience sections, but this is not a blanket waiver of the audit course, the exam, or the CBCA experience requirement.

    Don't confuse the essays with the exam: The five written essays belong to the certification application. The Audit Examination itself is a 100-question multiple-choice test. Writing practice for the essays and question practice for the exam are separate workstreams.

    What the Audit Examination Looks Like

    FeatureCBCA Audit Examination
    AdministratorDRI International, via its online examination/account process
    Questions100 multiple-choice
    Time allowed2 hours 30 minutes
    Passing scoreAt least 75%
    Pass rateNot publicly disclosed in official materials reviewed
    Target version (ISO route)Listed as "2023 Audit Exam - ISO 22301"
    Official domain weightsNot publicly verified

    A few points deserve emphasis. First, the 75% figure is the required individual score, not an observed pass rate; DRI does not publish cohort pass statistics for this exam, so any quoted "pass rate" you see elsewhere is not a CBCA figure. Our page on the CBCA pass rate explains what can and cannot be said. Second, the public materials do not specify a scored versus unscored question breakdown, and they do not establish open-book or closed-book status, calculator permissions, or detailed remote-proctoring rules. Confirm those details through your DRI account and course instructions rather than assuming them from other exams. Third, scheduling guidance has shifted: current course descriptions say the exam is taken online after the course at your convenience, while an older FAQ sentence still refers to the final course day. Follow the course-specific booking instructions, and see CBCA Exam Dates for scheduling context.

    For the exact scoring threshold, read CBCA Passing Score. For a realistic view of difficulty, see How Hard Is the CBCA Exam?

    Fees and Registration Mechanics

    The pricing structure is unusual because training and exam are bundled. There is no published separate member or nonmember exam-only price for this mandatory-course route.

    ItemPublished US amount
    Course and first exam (BCLE AUD, ISO 22301 or NFPA 1600)$2,950
    Certification application$400
    Training-plus-application subtotal$3,350
    Audit-exam retake$250
    Annual renewal$225

    The $3,350 subtotal is simply the course-and-exam price plus the application fee, calculated before renewal, travel, taxes, or discounts. The first exam attempt is included in the course price, so you are not adding a separate exam fee on top. DRI's Continuity Audit FAQ advertises a 10% discount for NFPA and other professional-organization members, but it does not identify every qualifying organization or show a discounted checkout total, so treat eligibility and the final amount as something to confirm directly with DRI. A full breakdown lives in CBCA Certification Cost 2026.

    Key Takeaway

    Budget for the whole path, not just the exam. The cost to reach the designation is the course bundle plus the application fee, and the cost to keep it is the recurring annual fee plus continuing-education effort.

    The ISO 22301 Content You Need to Master

    This site's preparation approach targets the DRI Audit Examination - ISO 22301, not the general DRI Qualifying Examination (a separate exam that should not be substituted). The NFPA 1600 route is a different variant, and coverage of it is not established here. The current ISO course references ISO 22301:2019.

    DRI does not publicly verify an official weighted exam blueprint, so the eleven topics below are drawn from the issuer's current ISO 22301 audit-course outline. They are preparation topics, not an official or exhaustive list of exam domains, and any practice-question allocation is editorial rather than a DRI percentage. You can see each one expanded in CBCA Exam Domains: All 11 Content Areas.

    Auditing basics

    The foundations of audit practice as applied to continuity programs.

    • Audit objectives, scope, and criteria
    • Evidence gathering versus assumption
    • The independence and professionalism expected of an auditor

    Understanding ISO 22301

    The structure and intent of the management system standard you will audit against.

    • How the standard frames a continuity management system
    • Mapping requirements to audit questions
    • Note: the course page uses the heading "Understanding ISO 22301" while the linked brochure says "Introduction to ISO22301"; this is a wording difference, not an extra topic

    Context of the organization

    Why the program exists and what shapes it.

    • Internal and external issues affecting the program
    • Interested parties and their expectations
    • Defining the scope of the continuity management system

    Leadership, planning, support, and operation

    How management commitment turns into resourced, operating controls.

    • Evidence of leadership involvement and policy
    • Objectives, competence, awareness, and documented information
    • Operational planning and control

    Risk assessment

    How threats and vulnerabilities to prioritized activities are identified and evaluated.

    • Whether the method is defined and consistently applied
    • Linkage between identified risks and treatment decisions

    Business impact analysis (BIA)

    The analysis that drives priorities and recovery expectations.

    • How impacts over time are assessed
    • How recovery priorities and dependencies are established
    • What an auditor looks for to confirm results are current and approved

    Continuity strategies and solutions

    Whether chosen strategies actually answer the BIA and risk findings.

    • Alignment between recovery needs and selected solutions
    • Resource, dependency, and supplier considerations

    Business continuity plans

    Whether plans are usable by the people who must execute them.

    • Clear activation, roles, and communication content
    • Version control, approval, and accessibility

    Education and training

    Evidence that people know what to do.

    • Training records versus actual competence
    • Awareness programs and role-specific preparation

    Exercise program

    How testing validates the program.

    • Exercise planning, scope, and objectives
    • Capturing lessons learned and tracking corrective actions

    Audit findings, recommendations, and auditor's opinion

    The output of the whole engagement.

    • Classifying and communicating nonconformities
    • Writing recommendations that are specific and defensible
    • Forming an overall opinion supported by evidence

    A useful lens across all eleven: ask not "what does the standard say?" but "what evidence would prove the organization does this?" Questions in an audit exam tend to reward that evidence-minded perspective. For a compact recap, the CBCA cheat sheet condenses the must-know facts.

    Who Uses a CBCA and Where It Fits

    The credential naturally suits people who assess or oversee continuity programs rather than only run them. Typical backgrounds include internal audit, risk and compliance, business continuity management, emergency and disaster management, and consulting engagements where an outside review of a continuity program is needed. Organizations that maintain or pursue alignment with ISO 22301 have a particular reason to value someone trained to audit against it.

    Because no verified salary or hiring data exists in the official sources reviewed for this article, we avoid quoting figures here. If you want to explore the market side, our pages on CBCA jobs, the CBCA salary guide, and whether the certification is worth it discuss career value in context.

    Keeping the Credential Active

    Earning the designation is not the end of the financial or educational commitment. Renewal has two distinct parts, and it is a common mistake to blur them:

    • Annual fee: $225 per year.
    • Continuing education: 80 CEAPs over each two-year period.
    • Ethics: compliance with DRI's code of ethics.

    So the credential should not be described as an unconditional two-year certification. The annual financial maintenance and the two-year CEAP cycle run in parallel. The four-day audit course itself carries 32 CEAPs, which can serve as a meaningful early contribution toward a first cycle, though you should confirm exactly how DRI applies points in your situation.

    A CBCA-Specific Preparation Sequence

    Because the exam is multiple-choice but the thinking is audit-oriented, sequence your study so concepts build on each other. This sample plan assumes you have completed or are completing the DRI course and want to consolidate. Adjust it to your own pace; for a longer treatment see the CBCA study guide and the overview of CBCA training.

    Week 1

    Frame the standard

    • Auditing basics and Understanding ISO 22301 first, since every later topic is judged against the standard
    • Build a one-page map linking each clause area to an audit question
    Week 2

    Organization and management system

    • Context of the organization, then Leadership, planning, support, and operation
    • Practice spotting what evidence would demonstrate each requirement
    Week 3

    The analytical core

    • Risk assessment, Business impact analysis, and Continuity strategies and solutions together
    • Trace how a BIA result should flow into strategy choices, since audit questions often test that linkage
    Week 4

    Execution, testing, and reporting

    • Business continuity plans, Education and training, and Exercise program
    • Finish with Audit findings, recommendations, and auditor's opinion, then run timed sets of independently written practice questions
    Keep practice material original: Candidates are expected to keep DRI course and exam materials confidential. Build or use only independently written practice questions, and avoid anyone offering reproduced exam content. When you are ready to drill, the CBCA practice tests are written independently of DRI's materials.

    Frequently Asked Questions

    Does passing the exam make me a CBCA?

    No. Passing the Audit Examination at 75% or higher is required, but DRI also reviews an experience-based application, including essays and references, before conferring the Certified Business Continuity Auditor designation.

    Do I need a prior DRI certification to take the course?

    No. The audit course may be taken without a previous DRI certification. The experience, essay, and reference requirements apply to the certification application, not to course enrollment. See CBCA requirements for details.

    How many questions are on the exam, and how long do I get?

    The Audit Examination has 100 multiple-choice questions with a 2 hour 30 minute time limit. The public sources reviewed do not break down scored versus unscored items.

    What is the total published cost to get started?

    The published US course-and-exam price is $2,950 and the application is $400, for a $3,350 subtotal before renewal, travel, taxes, or discounts. A retake is $250. Confirm any membership discount directly with DRI.

    Is there a published CBCA pass rate?

    No. DRI does not publicly disclose a pass rate in the official materials reviewed. The 75% figure is the score you need, not the share of candidates who pass. See CBCA pass rate for more.

    In short, a CBCA is both a body of audit knowledge and a verified track record. Treat the course and exam as the learning gate, treat the application as the professional gate, and plan for the ongoing renewal commitments from the start. To begin testing your readiness against ISO 22301 audit topics, head to the main practice site.

Ready to pass your CBCA exam?

Put this into practice with free CBCA questions across every exam domain.