What you’ll learn in this article…
- CISA requires five years of audit or security experience before certification.
- First-time pass rates hover between 45% and 60% in 2026.
- Total three-year cost with ISACA membership runs roughly $1,500 to $3,000.
General cybersecurity certifications and audit credentials often get shelved together, but they solve different problems. CISA is not a broad security cert. It is the gold standard for information systems audit, assurance, and controls work, issued by ISACA and built for professionals who evaluate whether IT environments meet governance, risk, and compliance expectations.
The credential carries a five-year experience requirement, a four-hour exam, and a three-year renewal cycle with mandatory continuing professional education. Those commitments are why most candidates researching CISA already know the name and need specifics on cost, eligibility, difficulty, job fit, and how it stacks against CISSP, CRISC, and CIA before booking a voucher, and whether the credential is ultimately worth the investment, a question many address in our Are Cybersecurity Certifications Worth It? guide.
CISA Credential Snapshot
The Certified Information Systems Auditor (CISA) is a professional credential issued by ISACA that validates your ability to audit, control, monitor, and assess an organization's information technology and business systems. It is one of the most recognized certifications in the IT audit and assurance space, and it has been a benchmark for hiring managers since its introduction in 1978.
Below is a quick-reference table covering everything you need to know at a glance before diving into the details.
Key Exam Details
- Issuing Body: ISACA
- Exam Code: CISA
- Number of Questions: 150 multiple-choice items2
- Exam Duration: 4 hours1
- Score Scale: 200 to 8002
- Passing Score: 4502
- Number of Domains: 52
Cost Overview
- Exam Fee (ISACA Member): $5751
- Exam Fee (Non-Member): $7601
- Certification Application Fee: $50 (one-time, submitted after passing)3
- Annual Maintenance Fee (Member): $454
- Annual Maintenance Fee (Non-Member): $854
Experience and Renewal Requirements
- Work Experience: A minimum of 5 years of professional experience in information systems auditing, control, assurance, or security3. ISACA does allow certain substitutions and waivers of the certification prerequisites, which we cover in a later section.
- CPE Hours: 120 hours over a rolling 3-year cycle, with a minimum of 20 hours each year.4
Why This Snapshot Matters
Understanding the full financial and time commitment upfront helps you plan realistically. Between exam fees, potential training costs, and ongoing maintenance, you are looking at a meaningful investment. The credential is not a weekend project. It is designed for professionals who already have hands-on experience with audit processes and IT governance, or who are actively building that experience and want a clear career target , learning how to choose a cybersecurity certification can help you confirm that CISA aligns with your goals.
We recommend verifying current pricing directly with ISACA before scheduling your exam, as fees can change between testing windows.
What CISA Validates and Why It Matters
As regulatory pressure mounts and boards demand demonstrable audit readiness, the role of the systems auditor has shifted from back-office compliance to a frontline governance function. CISA is the benchmark credential for professionals who evaluate whether information systems are protected, reliable, and aligned with business objectives.
Audit Scope, Not Security Operations
CISA validates expertise in information systems auditing, control assessment, and assurance. It does not certify hands-on security operations skills. Unlike Security+ or CEH, which emphasize configuring firewalls, running penetration tests, or hardening endpoints, CISA confirms the ability to plan an audit, gather and evaluate evidence, assess control design and effectiveness, and communicate findings to stakeholders. You will not be asked to configure a SIEM on the exam; you will be asked to determine whether existing controls sufficiently mitigate a given risk.
The Five Domains at a Glance
The exam organizes audit proficiency into five practice areas, each mirroring real-world job tasks.
- Information System Auditing Process: Covers audit planning, risk assessment, evidence collection, and reporting, aligning with standards like ISACA's IT Audit Framework.
- Governance and Management of IT: Focuses on IT strategy alignment, resource management, and organizational structures, requiring you to evaluate whether governance practices support business goals.
- Information Systems Acquisition, Development, and Implementation: Examines project management, system development lifecycle controls, and post-implementation review.
- Information Systems Operations and Business Resilience: Tests ability to audit operational procedures, service management, and disaster recovery planning.
- Protection of Information Assets: Addresses logical access controls, network security architecture, encryption, and physical security from an auditor's perspective.
Each domain demands that you not only understand technical details but also determine whether controls are appropriately designed, effectively implemented, and operating as intended.
Regulatory and Employer Recognition
CISA is recognized globally by regulatory frameworks including SOX, HIPAA, and GDPR, where independent audit assurance is mandatory. It satisfies DoD Directive 8570/8140 requirements for information assurance audit roles, making it a required or preferred credential for contractors supporting federal agencies. Employers in finance, healthcare, and consulting routinely list CISA alongside CPA or CIA for internal audit and IT risk positions, signaling that the credential holder can bridge the gap between technical systems and business risk.
Who Should Pursue CISA
CISA is a mid-career credential, not an entry point into cybersecurity. ISACA built the exam around the assumption that candidates already understand how enterprise systems, controls, and audit engagements work in practice. That framing should shape whether you sit for it now, later, or at all.
Career Changer With No IT Background
If you are making a cybersecurity career change from finance, accounting, or another field without hands-on IT exposure, CISA is a long-horizon goal rather than a first move. You can pass the exam without meeting the experience requirement, but the certification will not be issued until you accumulate the required audit or security experience (with limited waivers for related education and general IS work). Plan a two to four year runway: build foundational IT knowledge with a certification in cyber security first, then take an audit-adjacent role, and then sit for the exam. Chasing CISA before you understand how a change management ticket or an access review actually functions inside a company tends to end in a failed attempt and a wasted voucher.
Early IT Professional (1 to 3 Years)
This is the sweet spot for exam preparation, though not yet for full certification. If you are working in help desk, sysadmin, junior security, or internal audit support, CISA gives you a concrete target that maps to promotion into an IS auditor or GRC analyst role. Pass the exam early, then let your experience clock catch up. Employers in banking, insurance, and Big Four consulting actively recruit at this level and often reimburse the exam.
Working Cybersecurity or GRC Practitioner
For practitioners already doing SOC 2 readiness, ISO 27001 work, internal control testing, or compliance analysis, CISA formalizes what you already do. It is the credential that unlocks regulated-industry doors: financial services, healthcare, federal contractors, and publicly traded companies almost always list it as preferred or required for senior audit and assurance postings. Expect a clear salary bump after certification.
Experienced Manager or Specialist
At the manager or director level, CISA functions as a governance credibility signal rather than a skills validator. It pairs well with CRISC (risk) or CISM (security management) but does not replace them. If your remit includes audit committee reporting, external auditor coordination, or third-party risk oversight, CISA sharpens your seat at the table.
Related Articles
Eligibility, Prerequisites, and Experience Waivers
ISACA requires five years of professional experience in information systems auditing, control, assurance, or security across the exam's five job practice domains before it will issue the CISA credential.1 That experience bar is the real gatekeeper: passing the exam only gets you halfway there.
The Baseline Five-Year Requirement
All qualifying experience must fall within a 10-year window preceding your certification application, or within five years of the date you passed the exam, whichever ISACA verifies first.1 In practice, that means you cannot pull work from a decade-and-a-half ago to satisfy the requirement, and you cannot indefinitely delay applying after passing. Experience is verified by a supervisor, employer, or other independent professional using ISACA's verification form.
A critical clarification: you can pass the CISA exam before accruing any of the required experience. The credential itself is only awarded once experience is documented and approved, but sitting the exam early is a common and accepted path for career changers. You can map out your entire certification path with our Cybersecurity Certification Roadmaps.
Waivers and Substitutions (Up to 3 Years)
ISACA allows a maximum of three years of the five-year requirement to be waived through substitutions.2 You still need at least two years of direct, hands-on IS audit, control, or security experience that cannot be waived.2 Available substitutions include:3
- Two-year degree (associate): 1 year waived
- Four-year degree (bachelor's): 2 years waived
- Master's degree in IS, IT, or a related field: 1 to 2 years waived depending on program alignment
- ISACA-accredited university program graduate: up to 2 years waived
- Full-time university instructor in a related field: 1 year waived for every 2 years of teaching
- General information systems experience (non-audit IT work): 1 year waived
- Non-IS audit experience (financial or operational audit): 1 year waived
- Approved related certification such as CISM, CGEIT, CRISC, CISSP, or CompTIA Security+ (CompTIA Security+ Certification Guide): 1 year waived
Waivers do not stack past the three-year ceiling. A candidate with a bachelor's degree and a CISSP, for example, gets three years credited and still needs two years of qualifying audit or security work.
Edge Cases: Part-Time Work, Gaps, and Overlapping Roles
Part-time experience is prorated. Two years of half-time audit work counts as one year toward the requirement. Career gaps do not disqualify prior experience as long as the work still falls inside the 10-year window. Overlapping roles (for instance, an IT auditor who also managed security operations) cannot be double-counted; you claim the time once, under whichever domain fits best.
Application Timeline
Once you pass the exam, you have five years to submit a complete certification application with verified experience.1 Missing that window means retaking the exam. ISACA typically processes applications within about eight weeks after receiving all documentation, so build that runway into your career planning, and consider using our Cybersecurity Certification Study Plan for Working Adults to organize your preparation.
Questions to Ask Yourself
Exam Format, Domains, Scoring, and Testing Options
ISACA refreshes the CISA job practice periodically, and the current blueprint reflects a shift toward IT governance, emerging technology risks, and integrated audit approaches rather than pure controls testing. Before you register, verify the live specifications directly from ISACA rather than relying on secondhand summaries, because domain weights and delivery logistics do change between blueprint cycles.
Where to Confirm the Current Exam Blueprint
The authoritative source for exam structure is the ISACA credentialing site at isaca.org. Look specifically for the CISA exam content outline (sometimes called the job practice areas) and the current candidate information guide. Both documents are updated when ISACA revises the exam, and they specify the number of questions, total testing time, domain names, and the percentage weight assigned to each domain. If you buy a prep provider's course, cross-check their outline against ISACA's published version, because third-party materials occasionally lag behind blueprint updates.
Understanding Scoring
CISA uses a scaled scoring system rather than a raw percentage. ISACA publishes the passing threshold and explains how scaled scores are derived in the candidate guide. The scaled model means you should not assume a fixed percentage of correct answers guarantees a pass; instead, rely on ISACA's published guidance and, as outlined in our How to Prepare for a Cybersecurity Certification Exam, use full-length practice exams from reputable providers to gauge readiness. Score reports are typically delivered shortly after the exam, with an official result following once ISACA completes its review.
Testing Options
ISACA offers two primary delivery methods: in-person at authorized PSI test centers and online remote proctoring from a private location. Each has different equipment, environment, and identification requirements. Read the current remote testing policy on the ISACA site, and for practical tips on proctoring rules see our Online Cybersecurity Exams: Proctoring and Retakes, because remote proctoring imposes strict requirements on workspace, secondary devices, and interruptions that some candidates find harder to manage than a test center.
Where Else to Look
For broader context on how employers weight CISA compared to other credentials, including our Compare Cybersecurity Certifications Side by Side tool, professional associations like ISACA chapters, IIA (for internal audit crossover), and (ISC)² publish role guidance. Government workforce data from the U.S. Bureau of Labor Statistics at bls.gov can help you understand demand for information security analysts and auditors in your region, though BLS does not break out data by specific certification.
Full Cost Breakdown: Exam, Training, Retakes, and Renewal Fees
Understanding the total cost of CISA certification over a full three-year cycle helps you budget realistically and decide whether ISACA membership is worth the investment. The comparison below uses the member pricing path, which saves roughly $500 or more over three years when you factor in discounted exam fees, lower maintenance fees, and reduced study material costs. For non-members, expect to add approximately $300-$550 across these same line items, though you skip the membership fee itself.

How Difficult CISA Is and How to Prepare
ISACA has never published official pass rate data for CISA1, which leaves candidates piecing together difficulty estimates from prep providers and community reports. Independent trackers place first-time pass rates in the 45-60% range in 2026.2 The exam itself is 150 questions over 240 minutes, scored on a 200-800 scale with 450 as the passing mark.1 That structure is not the hard part. The hard part is thinking like an auditor.
Difficulty by Background
CISA reads differently depending on where you sit today.
- Career changers without audit exposure: Hardest path. You are learning both the technical vocabulary and the audit-first mindset simultaneously. Expect the steepest curve in Domain 1 (audit process) and Domain 2 (governance).
- Working IT auditors: Moderate. The audit framing is familiar, but the governance, risk, and IS acquisition domains still require deliberate study.
- GRC professionals with several years in the field: Most manageable. The concepts map cleanly to daily work, and preparation is mostly about mastering ISACA's specific phrasing.
- Experienced security practitioners without audit experience: Deceptively tricky. Strong technical knowledge does not translate to correct answers when the question is really asking about control evidence or auditor independence.
Common Failure Patterns
Most candidates who fail share a few habits. They lean on IT knowledge and pick the technically correct answer instead of the audit-correct answer. They underestimate the governance and risk domains, treating them as filler. They practice with generic question banks that do not mirror ISACA's phrasing style. And they sit for the exam before their practice scores are consistent.
Study Plans by Profile
- Experienced auditors or GRC professionals: 3 to 4 months at 10 to 15 hours per week.
- IT or security professionals pivoting into audit: 5 to 6 months at 15 to 20 hours per week.
- Candidates with limited IT background: Plan for 6 months or more and consider foundational coursework before starting CISA-specific prep.
Resources and Benchmarks
The ISACA official Review Manual and the QAE (Questions, Answers, and Explanations) database are the baseline. Third-party providers such as Gleim and HOCK add structured video instruction and larger question pools. Independent study guides and instructor-led boot camps fill in the gaps for candidates who prefer different formats, including Self-Study vs. Instructor-Led Cybersecurity Training.
Before booking your exam, target consistent scores of 80 to 85% on mixed-source practice sets2, 90% on ISACA's own QAE material3, and 80% or better on each of the five domains individually3. Sit for at least one full-length timed simulation under exam conditions3. If any domain is lagging below 80%, delay the exam rather than hope for a lucky test form.
Because audit and compliance work sits at the intersection of regulation and risk, CISA holders in banking, healthcare, and government often out-earn peers in general IT roles. Heavily regulated industries pay a premium for professionals who can prove controls work, not just build them. Here's what that premium actually looks like by role and sector.
CISA Jobs, Salaries, and Industry Demand
CISA holders land roles across audit, compliance, governance, and security management, with compensation that reflects the credential's specialized value. The table below pairs broad federal occupation data from the Bureau of Labor Statistics with CISA-specific salary benchmarks reported across industry salary surveys. Keep in mind that BLS figures cover entire occupation groups, so professionals holding a CISA and working in audit-focused roles often earn toward the upper end of these ranges or above the median.
| Role or Occupation | Median Annual Wage | Typical Salary Range | Total U.S. Employment |
|---|---|---|---|
| Information Security Analysts | $124,910 | $92,160 to $159,600 | 179,430 |
| Computer and Information Systems Managers | $171,200 | $134,350 to $216,220 | 645,970 |
| Accountants and Auditors | $81,680 | $64,660 to $106,450 | 1,448,290 |
| IS Auditor / IT Auditor (CISA-specific) | N/A | $100,000 to $110,000 | N/A |
| IT Audit Manager / Senior IT Audit Lead (CISA-specific) | N/A | $140,000 to $200,000 | N/A |
| CISA-Certified Professionals (all roles, national) | $106,000 | $90,000 to $140,000 | N/A |
| IT Cybersecurity Specialist, Federal | $151,000 | N/A | N/A |
Renewal, CPE Tracking, and Expiration Rules
How do I keep my CISA certification active, and what happens if I fall behind on CPE?
Earning the Certified Information Systems Auditor (CISA) credential is a significant achievement, but maintaining it requires ongoing professional education. ISACA enforces a structured Continuing Professional Education (CPE) policy to ensure that certified professionals stay current with evolving audit, assurance, and information security practices.
CPE Requirements at a Glance
ISACA mandates a minimum of 20 CPE hours annually3 and 120 hours over a rolling three-year reporting cycle4. At least 90 of those 120 hours must align directly with CISA exam domains (such as audit process, governance, or protection of information assets), while the remaining 30 hours can cover broader professional development topics. One CPE hour equals 50 minutes of active participation. Keep in mind, there's a cap: vendor sales and marketing activities can account for no more than 10 CPE hours annually.
Qualifying CPE Activities and Example Hour Values
A wide range of activities count toward your CPE total. The following examples reflect common ways CISA holders earn credits:
- Attending ISACA chapter meetings and events: Typically 1 to 2 CPE hours per meeting, depending on session length.
- Completing online courses or webinars: Many providers offer structured content worth 1 to 3 CPE hours per completed hour of instruction.
- Publishing articles, white papers, or books: Authoring an article for a peer-reviewed or industry publication may earn 5 to 15 CPE hours depending on complexity; a full book can earn significantly more.
- Attending professional conferences: One day of a relevant conference often yields 6 to 8 CPE hours, with documentation required.
- Mentoring or serving on ISACA boards and committees: Active volunteer service can earn CPE hours on an hourly basis, up to reasonable limits.
- Teaching or presenting: Delivering a talk or training session related to audit or information systems can earn CPE at a 1:1 ratio for preparation and presentation time.
You can also carry over up to 20 excess CPE hours into the next year within the same three-year cycle, which provides some flexibility if you exceed the annual minimum.
Tracking, Reporting Deadlines, and Audit Risk
ISACA relies on the MyISACA online portal as the official CPE tracking tool. You must submit your CPE activities annually by the January 15 deadline5 for the prior calendar year. The system automatically tabulates totals and flags any shortfalls. ISACA conducts annual audits4 of a random sample of certificate holders; if selected, you will need to produce verifiable documentation (such as certificates of completion, attendance logs, or publication copies) for each claimed activity. Failure to comply with the audit or meet CPE requirements can lead to immediate revocation of the certification.
What Happens If Certification Lapses
If your CISA goes inactive because you missed CPE requirements or reporting deadlines, you lose the right to use the designation. Reinstatement is not automatic. The only path back is to re-pass the CISA exam in its entirety, just as a new candidate would, and then reapply for certification. There is no grandfathering or grace period that allows you to simply catch up on missed hours. ISACA's updated 2026-2027 CPE policy continues to emphasize that CPE earned for one ISACA credential (such as CRISC or CISM) can be shared with your CISA reporting4, which can reduce the burden if you hold multiple certifications. Staying on top of your tracking each year is a small investment compared to the time and cost of retaking the exam.
CISA vs CISSP, CRISC, and CIA: Choosing the Right Credential
The real question is not which certification is hardest or most prestigious, but which one matches the work you actually want to do. CISA, CISSP, CRISC, and CIA are often lumped together as "senior GRC credentials," but each points toward a distinct career track, and picking the wrong one can mean two years of study for a role you never wanted.
What Each Credential Targets
The cleanest way to separate these four is by primary job function:
- CISA (ISACA): IT audit, IT controls testing, and assurance work. Best for anyone who reviews systems for compliance, evaluates control effectiveness, or issues audit opinions.
- CISSP certification (ISC2): Security engineering, architecture, and security management. Best for practitioners who design and defend systems rather than audit them.
- CRISC (ISACA): IT risk identification, assessment, and response. Best for risk analysts, GRC consultants, and second-line risk functions.
- CIA (IIA): Enterprise internal audit across finance, operations, and governance, not just IT. Best for internal auditors who want breadth beyond technology, as this CIA vs CISA comparison explains.
Exam and Experience Comparison
The structural differences are meaningful when you plan your timeline and budget:
- CISA: 150 questions, 4 hours, passing score of 450, five years of experience, exam fee $575 to $760.1
- CRISC: 150 questions, 4 hours, passing score of 450, three years of experience, exam fee $575 to $760.1
- CISSP: 125 to 175 questions delivered as a computerized adaptive test, 4 hours, passing score of 700, five years of experience, exam fee around $799.2
- CIA: Three separate exam parts totaling 325 questions and 6.5 hours of testing time, one to two years of experience depending on education, exam fees typically $1,000 to $1,500 in total.3
How to Choose
If your day involves testing controls, sampling evidence, and writing audit findings, CISA is the correct answer. If you build, harden, or run security systems, CISSP fits better. If you sit on the risk side of the three-lines model, translating threats into business impact and treatment plans, CRISC is the specialist choice. And if your audit scope reaches beyond IT into financial and operational reviews, CIA is the credential that hiring managers in internal audit departments actually recognize.
Many senior professionals eventually hold two of these, commonly CISA plus CISSP or CISA plus CRISC, but stacking credentials only pays off after you know which discipline anchors your career.
Frequently Asked Questions
These are the questions we hear most often from professionals weighing the CISA credential. Each answer draws on current ISACA policies and exam requirements as of 2026.
Explore More
- AAISM Certification Guide
- Are Cybersecurity Certifications Worth It? ROI Guide
- AWS Certified Security Specialty Guide
- Brain Dumps & Exam Ethics in Cybersecurity Certifications
- BTL1 Certification Guide
- CCSP Certification Guide
- CEH Certification Guide
- Cisco CCNA Cybersecurity Certification Guide
- Cisco CCST Cybersecurity Certification Guide
- CISM Certification Guide
- CISSP Certification Guide
- Compare Cybersecurity Certifications Side by Side
- CompTIA CySA+ Certification Guide
- CompTIA PenTest+ Certification Guide (PT0-003)
- CompTIA SecAI+ Certification Guide
- CompTIA Security+ Certification Guide
- CompTIA SecurityX Certification Guide
- CRISC Certification Guide
- Cybersecurity Certification Finder
- Cybersecurity Certification Methodology
- Cybersecurity Certification Prerequisites Explained
- Cybersecurity Certification Roadmaps by Role & Level
- Cybersecurity Certification Study Plan for Working Adults
- Cybersecurity Certification vs. Certificate vs. Bootcamp
- Cybersecurity Certifications Without a Degree
- Cybersecurity Degree vs. Certification vs. Bootcamp
- eJPT Certification Guide
- GIAC AI Platform Security (GAIPS)
- GIAC GICSP Certification Guide
- GIAC GPEN Certification Guide
- GIAC GSEC Certification Guide
- GIAC GWAPT Certification Guide
- Google Cybersecurity Certificate Guide
- Google Professional Cloud Security Engineer Guide
- How to Choose a Cybersecurity Certification
- How to Prepare for a Cybersecurity Certification Exam
- HTB CPTS Certification Guide
- ISACA CCOA Certification Guide
- ISC2 Certified in Cybersecurity (CC) Guide
- ISC2 CGRC Certification Guide
- ISC2 CSSLP Certification Guide
- ISC2 SSCP Certification Guide
- Microsoft SC-100 Certification Guide
- Microsoft SC-200 Certification Guide
- Microsoft SC-900 Certification Guide
- Online Cybersecurity Exams
- OSCP & OSCP+ Certification Guide
- OSWE Certification Guide
- PNPT Certification Guide
- Self-Study vs. Instructor-Led vs. Bootcamp Cyber Training
- Vendor-Neutral vs. Vendor-Specific Cybersecurity Certs






