BCA (Certified Architect) is the senior technical level in the BI.ZONE certification program. It confirms that a specialist can design a deployment architecture for a product to fit a complex, distributed customer infrastructure, not just deploy it in a standard configuration. We break down how this level differs from the engineering-level BCE, who it's for, and which BI.ZONE products it is available for in the platform catalog.
What the BCA Level Is
The BI.ZONE certification program is structured by levels: BSC (sales) covers product positioning, BCE (engineer) covers deployment and administration in a standard configuration, and BCA (architect) covers complex, distributed deployments, integrations with the customer's infrastructure, and support for non-standard operational tasks. BCA is the next step after BCE, not an alternative, easier path: it's designed for specialists who already know how to deploy the product and are moving on to designing it for a specific infrastructure.
How an Architect's Job Differs from an Engineer's and an Operator's
Three technical roles in the BI.ZONE ecosystem answer different questions: the engineer (BCE) answers “how do I deploy the product by the book”, the architect (BCA) answers “how do I design a deployment that fits the constraints of a specific infrastructure”, and the product user on the customer's side answers “how do I work confidently in an already deployed system every day”.
| Role | Core question | Typical responsibility |
|---|---|---|
| Engineer (BCE) | how to deploy the product | deployment and administration in a standard configuration |
| Architect (BCA) | how to design for the customer's infrastructure | architecture of complex and non-standard deployments, integrations, fault tolerance |
| User (BCS level) | how to work in the system day to day | incident investigation, rule configuration, day-to-day operation |
The engineer follows a known procedure: the configuration is standard and the deployment steps are described in advance. The architect takes responsibility for making sure the solution as a whole will work in an infrastructure that does not fit the standard scenario — accounting for the customer's existing systems, network topology, load, and fault tolerance requirements. The user, by contrast, neither designs nor deploys the system at all — they work inside an architecture that has already been built, and the certification program has a separate track for this role, covered in the article “The BCS User Track”. Formally, access to BCA-level certification is open to a specialist who holds a valid BCE certificate for the same product — that is, a confirmed engineering level.
Who the Architect Level Is For
BCA is designed for deployment architects and lead engineers who are responsible for:
- designing an architecture that fits a specific customer's requirements and constraints;
- deploying in complex, distributed, and high-load configurations;
- integrating the product with adjacent infrastructure systems and SOC processes;
- fault tolerance, scaling, and support for non-standard operational tasks.
What Architectural Preparation Covers
Architectural preparation covers the entire path from the customer's requirements to stable operation — it is not about “deploying by the book”, but about designing a solution, justifying it, and bringing it through to handover.
- Designing the deployment around requirements and constraints. The architect chooses a configuration for the specific customer's infrastructure — taking its particulars into account rather than following a single template that suits any standard installation.
- Calculating component placement. The system's components have to be distributed across sites, communication links, and load so that the architecture holds up against the customer's real network topology, not a reference diagram from the documentation.
- Integrations with adjacent systems. The product is embedded into the customer's existing IT and security landscape: SIEM, user directories, neighboring security tools, SOC processes — and the architect has to understand how these connections will affect the stability of the whole solution.
- Fault tolerance. The architect determines which components need to be redundant and how to keep the system available if an individual node or communication link fails.
- Migration plan. The path from the customer's current state — including a legacy solution or no protection at all — to the target architecture has to be designed without stopping working processes during the transition.
- Acceptance. The architect has to be able to confirm, both to the customer and to themselves, that the deployed architecture covers the original requirements rather than merely being technically up and answering pings.
What the BCA Certificate Confirms
Upon completion of preparation and a competency check, BI.ZONE issues an electronic BCA-level certificate. It confirms to partners and customers that the specialist can do more than deploy the product by following instructions — they can design an architecture for real infrastructure and bring a complex deployment to stable operation. The competency check takes the form of a lab session with a trainer, by prior appointment. The certificate is confirmed periodically: check the validity period and the renewal procedure when you sign up.
How Practice on the Lab Environment Works
The BCA-level competency check is a lab session with a trainer on an isolated cloud environment, not a presentation of an architecture diagram on slides. The difference matters: a slide confirms that the solution has been thought through on paper, while the lab environment confirms that it actually works.
A slide with an architecture diagram won't show what happens when one of the components fails, an integration with a neighboring system responds differently than expected, or the migration plan runs into a real infrastructure constraint. These are exactly the discrepancies the architect has to identify and resolve during the lab session — on an environment that reproduces a distributed infrastructure, not on a simplified mock-up. The isolation of the environment makes it possible to safely test complex and abnormal scenarios — a node failure, a load profile, a non-standard integration — without risk to the customer's production infrastructure, while the task itself remains essentially the same as in a real deployment project.
Which Products the BCA Level Is Available For
The set of levels depends on the product — the BCA level isn't offered for every product line. Here's the current status:
- BI.ZONE EDR — the BCA level is already available: the “Designing and Deploying BI.ZONE EDR” course.
- BI.ZONE Mail Security — the “Designing and Deploying BI.ZONE Mail Security” course is available in the platform catalog.
- BI.ZONE PAM — the “Designing and Deploying BI.ZONE PAM” course is available in the platform catalog.
- BI.ZONE Secure SD-WAN — the “Designing and Deploying BI.ZONE Secure SD-WAN” course is available in the platform catalog.
For BI.ZONE Secure DNS, GRC, and ZTNA, the architect level isn't part of the program — for these products, BCE remains the senior technical level.
The Growth Path to BCA
A typical path for a partner specialist looks like this: BSC provides product positioning and pilot preparation, BCE covers deployment and administration in a standard configuration, and BCA opens up to specialists who already hold a valid BCE and adds the design of complex deployments and integrations. This is a deliberate sequence: before designing an architecture for non-standard infrastructure, a specialist needs to confidently deploy the product in a standard one.
How a Partner Should Prepare for BCA
Before registering for a BCA-level course, make sure the specialist already handles the engineering level confidently: deploying the product in a standard configuration, connecting basic integrations, and diagnosing operational issues without outside help. Simply wanting to master the architecture of complex deployments doesn't replace confirmed experience — BCA certification is designed to reinforce practical skills the specialist already has, not to build them from scratch.
Partners planning to bring several specialists up to the BCA level should plan the queue in advance: BCE- and BCA-level courses can't be taken in parallel by the same person, and the BCA-level competency check is a separate lab session with a trainer that requires prior sign-up.
Where to Start: Course Order and What to Brush Up On in Advance
A sensible order for a specialist who plans to reach BCA is to first close out the engineering level — the “Deploying and Administering BI.ZONE EDR” course — then build up hands-on experience on at least one or two real deployments, and only after that move on to the architecture course.
Before starting the architecture course, it's worth refreshing the product fundamentals rather than relying on memories of the engineering course alone. The materials “How to Choose an EDR” and “Common EDR Deployment Mistakes” help you look at the product again through the eyes of someone who chooses the architecture and answers for its consequences, rather than someone who simply follows deployment steps. This is also the right place to check how the day-to-day user experience of the product is set up — the article “The BCS User Track” and the “Working with BI.ZONE EDR” course show what the customer's team will end up working with once the architect has handed over the deployment.
How to Tell You're Ready: A Competency Checklist
- You can confidently deploy the product in a standard configuration without outside help and without consulting the documentation at every step.
- You know where to look for the cause of an abnormal situation in operation, not just how to work through a deployment checklist.
- You can explain why each architecture component is needed, not just where to physically place it.
- You are familiar with the common deployment mistakes for the product (see “Common EDR Deployment Mistakes”) and understand how to avoid them in a project, not just how to fix them after the fact.
- You are ready to justify an architectural decision to the customer — including their own architects and security team — and not only to a fellow engineer.
- You have taken part in at least one deployment more complex than a standard configuration, even if not as the architect in charge.
Common Preparation Mistakes
- Registering for BCA right after earning BCE, with no real deployment experience between the levels — theory without practice maps poorly onto an architect's tasks.
- Treating BCA as “a harder exam on the same theory” rather than as a separate design discipline with its own decision-making logic.
- Ignoring adjacent systems and SOC processes during preparation — an architect who doesn't account for the customer's integration context will design a solution in a vacuum, detached from real infrastructure.
- Planning without accounting for the prior sign-up for the lab session with a trainer — the BCA-level competency check doesn't adapt to a schedule at the last moment, and the queue should be planned in advance.
- Counting on the theory part alone being enough — without practice on a lab environment, architectural decisions remain untested assumptions.
What the Track Gives the Team and the Customer
Having a BCA-level specialist on a partner's team signals to the customer that a complex or non-standard product deployment will be designed deliberately, rather than assembled from a standard template in the hope that it will somehow work. This reduces the risk of costly architecture rework after the project has already run into constraints that weren't taken into account at the start.
For the customer, this means more predictable integration of the product with existing infrastructure and SOC processes on the first attempt, rather than after several rounds of rework. For the partner, it means a specialist who can defend an architectural decision to the customer and the customer's own architects, not just to colleagues on the deployment team. And once the deployment is complete and the product has been handed over to day-to-day operation, the gap between “the architect designed everything” and “the customer's team works confidently with the product” is closed by a different certification track — “The BCS User Track”.
Training and Certification Format
Technical levels, including BCA, combine theory on the portal with lab work on isolated cloud environments — practice that's as close to a real deployment as possible, without risk to the customer's production infrastructure. The full training and certification program for a specific product is available on the “BI.ZONE EDR Training and Certification” page and similar hubs for other products. To understand what EDR is and what problems the product solves, see the article “What Is EDR”.