CBCA logo
Focused certification exam prep
Start practice

What Is CBCA?

TL;DR
  • CBCA here means Certified Business Continuity Auditor, a DRI International designation, not any other credential sharing the acronym.
  • Passing the 100-question, 2.5-hour exam at 75% or higher does not by itself confer certification.
  • The certification application adds experience requirements, five subject-matter essays, and two validating references per subject area.
  • Published training-plus-application cost is $3,350: $2,950 for the course with first exam, plus a $400 application fee.

What CBCA Means: Certified Business Continuity Auditor

In this context, CBCA stands for Certified Business Continuity Auditor. It is a professional designation issued by DRI International (the Disaster Recovery Institute International), the organization best known for credentials in business continuity and disaster recovery. The designation recognizes a specific skill set: evaluating whether an organization's business continuity management system actually conforms to a recognized standard, and communicating the result in a defensible auditor's opinion.

If you have searched for the acronym and landed on material about finance, accounting, or business valuation, you were looking at a different credential entirely. This site covers only the DRI designation. For a terminology-focused walkthrough, see our companion explainers on what CBCA stands for and CBCA meaning.

The core idea is simple: a continuity planner builds the program, while a continuity auditor tests the program against criteria and reports on gaps. That shift in perspective, from building to verifying, shapes everything about the exam and the credential.

Who Issues It and How It Differs From Other Credentials

DRI International governs the CBCA. The Audit Examination is administered through DRI's own online examination and account process. No external proctoring vendor has been verified as the delivery channel, so do not assume the exam is booked through a third-party testing center network. Always follow the booking instructions attached to your specific course registration.

Two characteristics set this credential apart from many certifications you may have seen:

  • A mandatory course precedes the exam. You complete the Business Continuity Planning for Auditors course (listed by DRI as BCLE AUD) before sitting the Audit Examination. Current US versions run four full instructional days and award 32 Continuing Education Activity Points (CEAPs).
  • The exam alone is not the credential. DRI separately reviews an experience-based application before conferring the designation.
Don't Confuse the Audit Exam With the General Qualifying Exam: DRI also offers a general qualifying examination. It is a separate instrument with a separate purpose. This article and the preparation approach described here target the DRI Audit Examination for the ISO 22301 route, not the general qualifying exam.

Two Gates: The Audit Examination and the Certification Application

Gate one: course and examination

The course may be taken without any previous DRI certification. After completing it, you sit the Audit Examination online. Current course descriptions say the exam is taken after the course at the learner's convenience, although DRI's FAQ still contains an older sentence tying it to the final course day. When the two conflict, rely on the course-specific booking instructions rather than the general FAQ wording. Our guide to CBCA exam dates and scheduling covers the logistics in more depth.

Gate two: the professional application

To actually earn the designation, applicants must show:

  • At least two years of significant practical experience in business continuity, emergency/disaster management, and/or audit within the preceding ten years.
  • Five subject-matter essays, with at least two drawn from DRI's specified application areas covering business impact analysis, continuity strategies, plan development and implementation, and exercise/test/assessment/maintenance.
  • Two validating references per subject area. These may be the same two people across all five areas.

Some existing professional designations qualify for waivers of the reference or experience sections of the application. These are not blanket waivers: they do not remove the audit course, the exam, or the CBCA experience requirement. No degree requirement and no fixed experience-hour threshold were found in the reviewed materials. For the full eligibility picture, read CBCA requirements: eligibility, prerequisites and how to qualify.

Essays Are Not on the Exam: The five subject-matter essays belong to the certification application. The examination itself is multiple choice. Classroom case studies and practical audit exercises in the course are teaching activities, not an essay or performance-based exam.

Exam Format, Scoring, and Delivery

AttributeWhat DRI Publishes
Question count100 multiple-choice questions
Time allowed2 hours 30 minutes
Passing scoreAt least 75% individual score
DeliveryOnline, through DRI's examination/account process
Standard version (ISO route)Listed as "2023 Audit Exam - ISO 22301"; course references ISO 22301:2019
Scored vs. unscored questionsNot publicly specified
Official domain weightsNot publicly verified
Pass rateNot publicly disclosed

Several things remain unknown from public sources, and it is better to say so than to guess. DRI does not publish open-book or closed-book status, calculator permissions, detailed remote-proctoring rules, or a list of permitted references in the materials reviewed. An ADA-version listing exists for the ISO audit exam, but the public listing does not establish a different time allowance. Check your course confirmation and DRI account for the authoritative rules before exam day.

The 75% threshold is an individual score requirement, not a measure of how many people pass. Anyone quoting a CBCA pass rate is not drawing on published DRI cohort data; see what the data actually shows on CBCA pass rates and exactly what you need to pass for the careful version of that discussion. For a realistic sense of difficulty, how hard the CBCA exam really is separates the format from the folklore.

Fee Mechanics and What They Add Up To

DRI's published US pricing works like this: the course-and-exam package costs $2,950 for either the ISO 22301 version (BCLE AUD ISO 22301) or the NFPA 1600 version. The first exam attempt is included in that price, so there is no additional $750 exam fee on top. The certification application is a separate $400.

ItemPublished Amount
Course plus first exam (ISO 22301 or NFPA 1600)$2,950
Certification application$400
Training-plus-application subtotal$3,350
Audit exam retake$250
Annual renewal$225

The $3,350 subtotal is calculated from the two published fees and excludes renewal, travel, taxes, and any discounts. DRI's Continuity Audit FAQ advertises a 10% discount for NFPA and other professional-organization members, but it does not list every qualifying organization or show a discounted checkout total. Treat eligibility and the final amount as something to confirm directly with DRI before you budget. No separate member and nonmember exam-only price is published for this mandatory-course route.

A fuller breakdown lives in the CBCA certification cost guide, and if you are weighing the spend against career outcomes, the ROI analysis and the salary guide take that up directly.

What a Business Continuity Auditor Actually Examines

The auditing mindset the credential certifies is easiest to understand by following one organization's continuity program through an audit. A competent auditor asks questions like:

  • Has the organization defined its context, interested parties, and scope in a way that matches how it really operates?
  • Can top management show leadership commitment through documented policy, assigned roles, and resourcing, rather than just a signed statement?
  • Does the risk assessment feed the business impact analysis, and does the BIA feed the choice of continuity strategies?
  • Do written plans trace back to those strategies, and do people actually know their roles in them?
  • Is the exercise program planned, executed, and followed by corrective action?

Notice the thread running through those questions: traceability and evidence. An auditor does not merely agree that a plan exists; they test whether it follows from analysis, whether it was exercised, and whether gaps were closed. That evidence-first logic is what separates audit questions from planning questions on the exam.

Key Takeaway

When a practice question describes a situation, ask what evidence an auditor would request and what finding would result, not what a planner would build next. The exam rewards the verifier's viewpoint.

The Eleven Topics You Need to Master

An important caveat: DRI has not publicly verified an official weighted domain blueprint for the Audit Examination. The eleven areas below come from selected substantive headings of DRI's current ISO 22301 audit-course outline. They are preparation topics drawn from the course, not an official exam blueprint, and no topic percentages are claimed. They exclude the course's introduction, exam-preparation session, and the examination event itself. Our complete guide to all 11 CBCA content areas expands on each one.

Domain 1: Auditing basics

The fundamentals of audit practice: how audits are planned, how evidence is gathered, and how objectivity is maintained.

  • Audit purpose, scope, and criteria
  • Evidence collection and sampling concepts
  • Auditor independence and professional conduct

Domain 2: Understanding ISO 22301

The structure and intent of the business continuity management system standard. The current course page uses the heading "Understanding ISO 22301," while the linked brochure says "Introduction to ISO22301"; that is a spelling difference, not an extra topic.

  • How the standard's requirements are organized
  • Terminology the standard relies on
  • What conformity looks like in practice

Domain 3: Context of the organization

Understanding the organization, its interested parties, and the scope of its management system.

  • Internal and external issues
  • Stakeholder requirements
  • Defining and justifying scope

Domain 4: Leadership, planning, support, and operation

How top management commitment, objectives, resources, and operational controls come together in the management system.

  • Policy and assigned responsibilities
  • Resources, competence, and awareness
  • Operational planning and control

Domain 5: Risk assessment

How threats and vulnerabilities are identified and evaluated, and how an auditor judges the adequacy of that process.

  • Risk identification and analysis methods
  • Linkage to treatment decisions
  • Whether the process is repeatable and documented

Domain 6: Business impact analysis (BIA)

Assessing the effect of disruption over time and identifying priorities for recovery.

  • Prioritized activities and dependencies
  • Recovery time and resource requirements
  • Checking BIA results against what the organization actually plans for

Domain 7: Continuity strategies and solutions

The options an organization selects to protect and recover prioritized activities, and whether those choices are justified by the analysis.

  • Matching strategies to BIA outputs
  • Resource and cost considerations
  • Evidence that solutions are implemented, not just chosen

Domain 8: Business continuity plans

The documented procedures for responding to and recovering from disruption.

  • Plan content, structure, and activation criteria
  • Roles and communications
  • Traceability from strategy to procedure

Domain 9: Education and training

How the organization builds competence and awareness so plans can be executed by real people.

  • Training needs and records
  • Awareness programs
  • Evidence of competence

Domain 10: Exercise program

Planned exercising and testing, and whether results drive improvement.

  • Exercise scheduling and objectives
  • Capturing lessons and corrective actions
  • Whether exercises cover prioritized activities

Domain 11: Audit findings, recommendations, and auditor's opinion

Turning evidence into classified findings, practical recommendations, and a supportable opinion.

  • Distinguishing observations from nonconformities
  • Writing clear, evidence-backed findings
  • Forming and communicating the overall opinion

Because the real weighting is unpublished, do not over-invest in one favorite area. Build balanced competence, then use targeted practice to find weak spots. Our one-page CBCA cheat sheet is a handy way to keep the eleven areas straight during revision.

Who Uses This Credential

The CBCA is a niche, specialist designation. It is most relevant to people whose work involves assessing continuity programs rather than just running them. Typical settings include:

  • Internal audit and risk functions that include continuity within their audit universe.
  • Consulting and assurance firms that perform continuity assessments or standard-conformity reviews for clients.
  • Business continuity and resilience teams that run internal assessments or prepare for external certification audits against ISO 22301.
  • Regulated and critical-service organizations that must demonstrate continuity capability to oversight bodies, customers, or partners.

Employer demand varies by industry and region, and this article does not cite salary figures because none are published by DRI for this credential. For a qualitative look at roles, see CBCA jobs, and for broader context on the credential itself, the CBCA certification overview.

Sequencing Your Preparation

Rather than a generic study schedule, sequence your preparation to mirror how the standard itself builds. Each stage feeds the next, so understanding earlier material makes later material easier to audit.

Block 1

Foundations

  • Auditing basics, Understanding ISO 22301, and Context of the organization
  • Goal: learn the standard's vocabulary and the audit process before touching technical content
Block 2

The analysis chain

  • Leadership, planning, support, and operation; Risk assessment; Business impact analysis
  • Goal: be able to trace how analysis outputs should drive later decisions
Block 3

Solutions and readiness

  • Continuity strategies and solutions; Business continuity plans; Education and training; Exercise program
  • Goal: spot breaks in the chain from strategy to plan to proven capability
Block 4

Reporting and rehearsal

  • Audit findings, recommendations, and auditor's opinion, then timed 100-question practice sets
  • Goal: build speed against the 2.5-hour limit (about 90 seconds per question)

Write your own practice questions or use independently produced ones. DRI course and exam materials are confidential, so do not seek out or share reproduced exam content. For a full plan, see the CBCA study guide, the structured options under CBCA training, and our CBCA practice test platform, where you can drill questions by topic and simulate timed conditions.

Preparation Scope Reminder: This preparation approach is limited to the ISO 22301 route. DRI also offers an NFPA 1600 version of the audit course, but coverage of that route is not established here, so do not assume ISO-focused practice fully prepares you for it.

Staying Certified: Annual Fee and Two-Year CEAP Cycle

Earning the designation is not the end of the obligation. Maintenance has two distinct components that are easy to blur together:

  • An annual financial fee of $225.
  • 80 CEAPs over each two-year continuing-education period, along with compliance with DRI's code of ethics.

Because the fee is annual and the CEAP requirement runs on a two-year cycle, the credential should not be described as an unconditional two-year certification. Plan for both. A useful detail: the four-day audit course itself carries 32 CEAPs, so initial training contributes toward continuing-education habits from the start, though how CEAPs are counted across cycles should be confirmed with DRI.

Frequently Asked Questions

What does CBCA stand for in business continuity?

It stands for Certified Business Continuity Auditor, a designation granted by DRI International. It is distinct from other credentials that happen to share the same four letters.

Does passing the exam make me a CBCA?

No. Passing the 100-question Audit Examination with at least 75% is one requirement. DRI also reviews a certification application covering practical experience, five subject-matter essays, and validating references before conferring the designation.

How much does the path to CBCA cost?

DRI's published US pricing is $2,950 for the course with the first exam included, plus a $400 application fee, for a $3,350 subtotal. Renewal ($225 per year), retakes ($250), travel, taxes, and possible discounts are separate. Confirm any discount eligibility with DRI.

What is the CBCA pass rate?

DRI does not publicly disclose one in the materials reviewed. The 75% figure is the score each candidate must achieve, not a percentage of candidates who pass.

Do I need prior DRI certification to take the course?

No. The audit course may be taken without a previous DRI certification. However, earning CBCA itself requires meeting the experience, essay, and reference requirements of the application.

If the credential fits your career direction, the next sensible step is to review the requirements, confirm current fees and scheduling with DRI, and begin structured practice through the CBCA Exam Prep practice tests.

Ready to pass your CBCA exam?

Put this into practice with free CBCA questions across every exam domain.