CISA Certification in 2026: Exam Guide, Cost and Requirements

By Donald Korinchak, MBA, PMP, CISSP, SecurityX, ITILv3   Published: 09/26/26   9 min read

Updated September 2026: The CISA exam still follows the content outline ISACA introduced in August 2024, and ISACA hasn’t announced a new one. The change to plan for is ISACA’s new CPE policy from January 1, 2027: you still need 120 CPE hours every three years, but only 90 must align with the CISA content, and up to 30 can come from broader professional development such as leadership, soft skills or mentoring (ISACA).

ISACA’s Certified Information Systems Auditor (CISA) is the best-known certification for IT auditors. It proves you can plan and run an audit of information systems, judge whether IT governance and controls actually work, and report findings that management can act on. Internal audit teams, Big Four firms, regulators and compliance groups all use CISA as a hiring filter, and ISACA says more than 151,000 professionals hold it.

This guide covers who CISA is for, the exam facts, the five-year experience rule and waivers, the five domains, the full cost including annual fees, a study plan, career value, and how CISA compares with CISM, CISSP and Security+. For the wider picture, see Best Cybersecurity Certifications in 2026. (Looking for the U.S. Cybersecurity and Infrastructure Security Agency instead? This page is about the ISACA certification.)

Who CISA is for

CISA questions are written from the auditor’s point of view. The right answer is usually the one that gives the most reliable evidence, stays independent, or best serves the audit objective, not the one a system administrator would choose to fix the problem.

CISA exam facts (2026)

ItemDetails
Exam content outlineEffective August 2024 (current)
Number of questions150 multiple-choice
Time limit4 hours (240 minutes)
ScoringScaled 200 to 800; 450 or higher to pass
Where you testPSI test centers or online with remote proctoring
RegistrationContinuous; schedule as early as 48 hours after paying; eligibility lasts six months
Exam priceUS$575 for ISACA members, US$760 for non-members
Application feeUS$50 (one time, after you pass)
ExperienceFive years of IS/IT audit, control, assurance or security experience; waivers available for up to three years
Annual maintenance feeUS$45 for members, US$85 for non-members
CPEAt least 20 hours a year and 120 hours per three-year period

Sources: ISACA’s CISA exam page, certification requirements, maintenance requirements, exam content outline and the ISACA Exam Candidate Guide.

The CISA experience requirement

Anyone can take the CISA exam. To become certified after you pass, you need verified work experience (ISACA):

Many people pass the exam early in their audit career and apply once they reach the experience requirement, as long as they stay inside the five-year window.

The five CISA domains and their weights

DomainWeightWhat it covers
1. Information Systems Auditing Process18%Audit standards and codes of ethics, types of audits, risk-based audit planning, types of controls, audit project management, testing and sampling, evidence collection, audit data analytics, reporting and audit quality assurance
2. Governance and Management of IT18%Laws and standards, IT governance and strategy, policies and procedures, enterprise architecture, enterprise risk management, privacy, data governance and classification, IT resource and vendor management, and performance monitoring
3. Information Systems Acquisition, Development and Implementation12%Project governance, business cases and feasibility, system development methodologies, control design, implementation testing, configuration and release management, migration and data conversion, and post-implementation review
4. Information Systems Operations and Business Resilience26%IT components and asset management, job scheduling, shadow IT, availability and capacity, problem and incident management, change, configuration and patch management, log management, business impact analysis, resilience, backup and restoration, BCP and DRP
5. Protection of Information Assets26%Security policies and frameworks, physical controls, identity and access management, network and endpoint security, DLP, encryption and PKI, cloud, mobile and IoT, awareness training, attack methods, security testing, monitoring, incident response and forensics

Weights and topics: ISACA CISA exam content outline (effective August 2024). Domains 4 and 5 make up more than half the exam.

What CISA costs in 2026

A non-member who studies on their own pays US$760 plus US$50 to get certified, then US$85 a year. A member pays US$575 plus US$50, then US$45 a year, plus dues.

A 12-week CISA study plan

This assumes about eight hours a week and some audit, control or security experience.

Is CISA worth it? Jobs and salary

ISACA’s CISA page advertises an average annual salary of “US$149K+” for holders; that’s ISACA’s own figure for its certification, not an independent survey (ISACA).

For an independent benchmark, the U.S. Bureau of Labor Statistics groups IT auditors with accountants and auditors, reporting a median pay of $83,680 in May 2025 and 5% projected growth from 2025 to 2035. That group is broad, and the top 10% earned more than $144,090 (BLS). IT audit roles that combine CISA with security knowledge often pay well above the overall median, and many CISA holders move into security governance roles, where BLS lists information security analysts at a median of $129,180 (BLS).

CISA vs CISM, CISSP and Security+

Planning your next certification? See the full certification roadmap for the order to take them by career goal.

What I would tell a friend starting CISA

Learn to answer as an auditor, not as a fixer. When two answers both sound right, pick the one that gives independent, reliable evidence or reports the issue to the right people. And follow real breaches: the most useful audit findings come from asking whether the control that failed somewhere else would hold up in your own organization.

Every breach report is a control that failed. Read them like an auditor. The CyberExperts Daily Brief covers what changed in security and why it matters, in five minutes, weekday mornings. Get tomorrow’s brief.

Frequently asked questions

How many questions are on the CISA exam?

150 multiple-choice questions in four hours (240 minutes).

What is the passing score for CISA?

450 on ISACA’s scaled score range of 200 to 800.

How much does the CISA exam cost?

US$575 for ISACA members and US$760 for non-members, plus a one-time US$50 application fee after you pass. Keeping CISA costs US$45 a year for members or US$85 for non-members.

What are the CISA experience requirements?

Five years of information systems auditing, control, assurance or security experience, gained within the 10 years before you apply. You have five years after passing to apply, and ISACA allows experience waivers for a maximum of three years.

Can I take CISA without experience?

Yes. Anyone can take the exam. You need the experience only when you apply for certification, within five years of passing.

Is the CISA exam changing in 2026 or 2027?

ISACA hasn’t announced a new CISA exam content outline; the current one took effect in August 2024. The CPE rules change on January 1, 2027: at least 90 of the 120 three-year CPE hours must align with CISA content, and up to 30 can cover broader professional development.

Should I get CISA or CISM first?

If you work in audit, assurance or compliance, CISA first. If you manage a security program, CISM first. Many GRC professionals eventually hold both.

Sources

Donald Korinchak, MBA, PMP, CISSP, SecurityX, ITILv3

Donald Korinchak is a Cybersecurity Professional in the Washington DC area. Donald holds an MBA from the University of Pittsburgh Katz School of Business. Donald is considered a thought leader in business, leadership, and cybersecurity issues.