CISA in 2026: Why the Exam Wants the Auditor’s Answer

By Donald Korinchak, MBA, PMP, CISSP, SecurityX, ITILv3   Published: 09/26/26   Updated: 09/26/26   9 min read

Last updated September 2026

This page is about ISACA’s CISA certification, not the U.S. Cybersecurity and Infrastructure Security Agency.

CISA is the credential internal audit teams, Big Four firms, regulators and compliance groups use to sort IT auditors from everyone else. ISACA’s Certified Information Systems Auditor proves you can plan and run an audit of information systems, judge whether IT governance and controls actually work, and report findings management can act on. ISACA says more than 151,000 professionals hold it.

Nothing is changing on the exam itself right now. It still follows the content outline ISACA introduced in August 2024, and no new one has been announced. The change to plan for is on the maintenance side: a new CPE policy from January 1, 2027 (details below, and on ISACA’s CPE page).

Think like an auditor, or the exam will beat you

CISA questions are written from the auditor’s chair. The right answer usually gives the most reliable evidence, protects independence or best serves the audit objective. It is rarely what a sysadmin would do to fix the problem. The common ways candidates go wrong:

From Donald: From my PMP and ITIL background, PMP adds the most value.

Who hires CISAs, and why

For those employers, CISA is a screening credential: it tells them you speak audit as well as IT. ISACA’s CISA page advertises an average salary of “US$149K+” for holders. That’s ISACA’s own figure, not an independent survey (ISACA).

The U.S. Bureau of Labor Statistics doesn’t break out IT auditors. It groups them with accountants and auditors and reports a median pay of $83,680 in May 2025 and 5% projected growth from 2025 to 2035. That group is broad, and the top 10% earned more than $144,090 (BLS). IT audit roles that combine CISA with security knowledge often pay well above the overall median, and many CISA holders move into security governance roles, where BLS lists information security analysts at a median of $129,180 (BLS).

Format, scoring and scheduling

ItemDetails
Exam content outlineEffective August 2024 (current)
Number of questions150 multiple-choice
Time limit4 hours (240 minutes)
Scoring450 on a scaled range of 200 to 800
Where you testIn person at a PSI test center, or online with a remote proctor
RegistrationContinuous; schedule as early as 48 hours after paying; eligibility lasts six months
Exam priceUS$575 (ISACA member) or US$760 (non-member)
Application feeUS$50, paid once when you apply
ExperienceFive years of IS/IT audit, control, assurance or security experience; waivers available for up to three years
Annual maintenance feeUS$45 a year (member) or US$85 a year (non-member)
CPE20 hours minimum every year; 120 hours over each three-year cycle

Sources: ISACA’s CISA exam page, certification requirements, maintenance requirements, exam content outline and the ISACA Exam Candidate Guide.

Five domains, weighted toward operations and protection

DomainWeightWhat it covers
1. Information Systems Auditing Process18%Audit standards and codes of ethics, types of audits, risk-based audit planning, types of controls, audit project management, testing and sampling, evidence collection, audit data analytics, reporting and audit quality assurance
2. Governance and Management of IT18%Laws and standards, IT governance and strategy, policies and procedures, enterprise architecture, enterprise risk management, privacy, data governance and classification, IT resource and vendor management, and performance monitoring
3. Information Systems Acquisition, Development and Implementation12%Project governance, business cases and feasibility, system development methodologies, control design, implementation testing, configuration and release management, migration and data conversion, and post-implementation review
4. Information Systems Operations and Business Resilience26%IT components and asset management, job scheduling, shadow IT, availability and capacity, problem and incident management, change, configuration and patch management, log management, business impact analysis, resilience, backup and restoration, BCP and DRP
5. Protection of Information Assets26%Security policies and frameworks, physical controls, identity and access management, network and endpoint security, DLP, encryption and PKI, cloud, mobile and IoT, awareness training, attack methods, security testing, monitoring, incident response and forensics

Weights and topics: ISACA CISA exam content outline (effective August 2024). Domains 4 and 5 make up more than half the exam.

After you pass: the experience rule

Passing the exam doesn’t make you a CISA. You apply for certification afterwards, with verified experience (ISACA):

Early-career auditors often pass first, then apply when they hit the five years. That works as long as you apply within five years of your pass date.

Fees at a glance

FeeISACA memberNon-member
Exam registrationUS$575US$760
Application processing (once, when you apply)US$50US$50
Annual maintenance (due January 1)US$45US$85

Membership carries its own annual dues, so compare the exam saving with the dues in your region before you join. For prep, ISACA sells the CISA Review Manual (28th edition), a questions-and-answers database with more than 1,000 questions, and an online review course. Third-party courses and books are common too.

A 12-week plan, domain by domain

Budget about eight hours a week. Some audit, control or security experience helps; if you have none, add time to weeks 1 and 2.

Keeping CISA: the 2027 CPE rules

You need at least 20 CPE hours a year and 120 over each three-year period, plus the annual maintenance fee. From January 1, 2027, the 120-hour requirement stays, but only 90 of those hours must align with CISA content. Up to 30 can come from broader professional development such as leadership, soft skills or mentoring.

CISA or CISM (and other pairings)

Planning the GRC track? Our certification roadmap shows how CISA and CISM fit by goal.

How CISA ranks against security certs: Best Cybersecurity Certifications in 2026.

Every breach report is a control that failed. Read them like an auditor. The CyberExperts Daily Brief gives you the week’s incidents in five minutes, weekday mornings. Get tomorrow’s brief.

Questions about the CISA certification

Is this the CISA certification or the CISA agency?

This page covers ISACA’s Certified Information Systems Auditor certification, not the U.S. Cybersecurity and Infrastructure Security Agency.

What is the CISA exam like?

Four hours for 150 multiple-choice questions. You pass with a scaled score of 450 on a range of 200 to 800.

How much does CISA cost?

US$575 for ISACA members and US$760 for non-members, plus a one-time US$50 application fee. Maintaining it costs US$45 a year for members or US$85 for non-members.

Do I need five years of audit experience before the exam?

No. Anyone can take the exam. You need five years of information systems auditing, control, assurance or security experience, gained within the 10 years before you apply, when you apply for certification. You have five years after passing to apply, and ISACA allows waivers for a maximum of three years.

Is the CISA exam changing?

ISACA hasn’t announced a new content outline; the current one took effect in August 2024. The CPE rules change on January 1, 2027: at least 90 of the 120 three-year CPE hours must align with CISA content, and up to 30 can cover broader professional development.

Why do security people struggle with CISA?

Because the exam wants the auditor’s answer: reliable evidence, independence and reporting to the right people. Security professionals tend to pick the technical fix instead.

CISA or CISM first?

If you work in audit, assurance or compliance, CISA first. If you manage a security program, CISM first. Many GRC professionals eventually hold both.

Sources

Donald Korinchak, MBA, PMP, CISSP, SecurityX, ITILv3

Donald Korinchak is a Cybersecurity Professional in the Washington DC area. Donald holds an MBA from the University of Pittsburgh Katz School of Business. Donald is considered a thought leader in business, leadership, and cybersecurity issues.