CCOA — ISACA Certified Cybersecurity Operations Analyst
ISACA's 2025 technical cybersecurity operations certification — their first credential with performance-based questions alongside MCQ. CCOA uses a hybrid 4-hour exam format: traditional multiple-choice plus hands-on lab questions requiring proficiency with open-source tools including Security Onion, KQL/Kibana, Wireshark, and Nmap. Replaces the retired CSX-P as ISACA's technical operations credential. Covers Technology Essentials (25%), Cybersecurity Principles and Risk (20%), Adversarial TTPs (10%), Incident Detection and Response (34%), and Securing Assets (11%). Targets practitioners with 2-3 years of security operations experience. Strong early market traction — LinkedIn listed ~1,970 CCOA-preferred roles within six months of launch. ISACA CISA and CISM holders seeking to add a technical credential, and CySA+ holders seeking an ISACA-branded equivalent, are the primary audience.
| Issuer | ISACA |
| Level | intermediate |
| Domains | Defensive Security / SOC |
| Practical weight | 25% |
| Cost (USD) | 760 |
| Renewal | 3 years (CPE) |
| Skills | threat_detection, incident_response_process, vulnerability_management_process, siem_investigation, network_traffic_analysis, security_operations, mitre_attack_framework, threat_hunting_methodology |
Official certification page
Browse all 426 cybersecurity certifications on EBCertMap