Updated September 2026: The CISA exam still follows the content outline ISACA introduced in August 2024, and ISACA hasn’t announced a new one. The change to plan for is ISACA’s new CPE policy from January 1, 2027: you still need 120 CPE hours every three years, but only 90 must align with the CISA content, and up to 30 can come from broader professional development such as leadership, soft skills or mentoring (ISACA).
ISACA’s Certified Information Systems Auditor (CISA) is the best-known certification for IT auditors. It proves you can plan and run an audit of information systems, judge whether IT governance and controls actually work, and report findings that management can act on. Internal audit teams, Big Four firms, regulators and compliance groups all use CISA as a hiring filter, and ISACA says more than 151,000 professionals hold it.
This guide covers who CISA is for, the exam facts, the five-year experience rule and waivers, the five domains, the full cost including annual fees, a study plan, career value, and how CISA compares with CISM, CISSP and Security+. For the wider picture, see Best Cybersecurity Certifications in 2026. (Looking for the U.S. Cybersecurity and Infrastructure Security Agency instead? This page is about the ISACA certification.)
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Who CISA is for
- IT auditors and internal auditors who review systems, controls and IT processes
- External auditors and consultants at audit and advisory firms
- Compliance, risk and GRC professionals who test controls against frameworks and regulations
- Security professionals who want to move into assurance, audit or governance roles
CISA questions are written from the auditor’s point of view. The right answer is usually the one that gives the most reliable evidence, stays independent, or best serves the audit objective, not the one a system administrator would choose to fix the problem.
CISA exam facts (2026)
| Item | Details |
|---|---|
| Exam content outline | Effective August 2024 (current) |
| Number of questions | 150 multiple-choice |
| Time limit | 4 hours (240 minutes) |
| Scoring | Scaled 200 to 800; 450 or higher to pass |
| Where you test | PSI test centers or online with remote proctoring |
| Registration | Continuous; schedule as early as 48 hours after paying; eligibility lasts six months |
| Exam price | US$575 for ISACA members, US$760 for non-members |
| Application fee | US$50 (one time, after you pass) |
| Experience | Five years of IS/IT audit, control, assurance or security experience; waivers available for up to three years |
| Annual maintenance fee | US$45 for members, US$85 for non-members |
| CPE | At least 20 hours a year and 120 hours per three-year period |
Sources: ISACA’s CISA exam page, certification requirements, maintenance requirements, exam content outline and the ISACA Exam Candidate Guide.
The CISA experience requirement
Anyone can take the CISA exam. To become certified after you pass, you need verified work experience (ISACA):
- Five years of professional information systems auditing, control or security work experience, as described in the CISA job practice areas.
- Timing: The experience must fall within the 10 years before you apply, and you have five years from the date you pass the exam to apply.
- Verification: A supervisor or manager verifies your experience.
- Waivers: ISACA’s Exam Candidate Guide says experience waivers are available for a maximum of three years (ISACA). Check the current CISA application in MyISACA for which education or other substitutions qualify before you count on one.
Many people pass the exam early in their audit career and apply once they reach the experience requirement, as long as they stay inside the five-year window.
The five CISA domains and their weights
| Domain | Weight | What it covers |
|---|---|---|
| 1. Information Systems Auditing Process | 18% | Audit standards and codes of ethics, types of audits, risk-based audit planning, types of controls, audit project management, testing and sampling, evidence collection, audit data analytics, reporting and audit quality assurance |
| 2. Governance and Management of IT | 18% | Laws and standards, IT governance and strategy, policies and procedures, enterprise architecture, enterprise risk management, privacy, data governance and classification, IT resource and vendor management, and performance monitoring |
| 3. Information Systems Acquisition, Development and Implementation | 12% | Project governance, business cases and feasibility, system development methodologies, control design, implementation testing, configuration and release management, migration and data conversion, and post-implementation review |
| 4. Information Systems Operations and Business Resilience | 26% | IT components and asset management, job scheduling, shadow IT, availability and capacity, problem and incident management, change, configuration and patch management, log management, business impact analysis, resilience, backup and restoration, BCP and DRP |
| 5. Protection of Information Assets | 26% | Security policies and frameworks, physical controls, identity and access management, network and endpoint security, DLP, encryption and PKI, cloud, mobile and IoT, awareness training, attack methods, security testing, monitoring, incident response and forensics |
Weights and topics: ISACA CISA exam content outline (effective August 2024). Domains 4 and 5 make up more than half the exam.
What CISA costs in 2026
- Exam: US$575 for ISACA members or US$760 for non-members. Membership has its own annual dues, so compare the saving with the dues in your region.
- Application processing fee: US$50, paid once when you apply for certification.
- Annual maintenance fee: US$45 a year for members or US$85 for non-members, due by January 1 each year.
- Prep: ISACA sells the CISA Review Manual (28th edition), a questions-and-answers database with more than 1,000 questions, and an online review course. Third-party courses and books are common too.
A non-member who studies on their own pays US$760 plus US$50 to get certified, then US$85 a year. A member pays US$575 plus US$50, then US$45 a year, plus dues.
A 12-week CISA study plan
This assumes about eight hours a week and some audit, control or security experience.
- Weeks 1 to 2: the audit process (18%). Standards, audit planning, sampling, evidence and reporting. This domain teaches the auditor’s mindset the whole exam depends on.
- Weeks 3 to 4: governance and management of IT (18%). Governance vs management, frameworks, policies, enterprise architecture, risk management, privacy, data governance and vendor oversight.
- Week 5: acquisition, development and implementation (12%). Project controls, business cases, SDLC, testing, release management and post-implementation reviews.
- Weeks 6 to 8: operations and business resilience (26%). IT operations, change and patch management, BIA, RTO and RPO, backup strategies, BCP and DRP testing.
- Weeks 9 to 10: protection of information assets (26%). Identity and access management, network and endpoint security, encryption and PKI, cloud and mobile, security testing, incident response and forensics, all from the auditor’s view.
- Weeks 11 to 12: practice. Work through a large question bank in timed blocks. Read every explanation, especially for questions where you picked the “technical fix” instead of the auditor’s answer.
Is CISA worth it? Jobs and salary
ISACA’s CISA page advertises an average annual salary of “US$149K+” for holders; that’s ISACA’s own figure for its certification, not an independent survey (ISACA).
For an independent benchmark, the U.S. Bureau of Labor Statistics groups IT auditors with accountants and auditors, reporting a median pay of $83,680 in May 2025 and 5% projected growth from 2025 to 2035. That group is broad, and the top 10% earned more than $144,090 (BLS). IT audit roles that combine CISA with security knowledge often pay well above the overall median, and many CISA holders move into security governance roles, where BLS lists information security analysts at a median of $129,180 (BLS).
CISA vs CISM, CISSP and Security+
- CISA vs CISM: Both come from ISACA. CISA is for people who audit and assure; CISM is for people who manage security programs. Many GRC professionals earn both, usually CISA first.
- CISA vs CISSP: CISSP is broader security knowledge for practitioners and leaders. CISA is audit-specific. Security teams hire CISSPs; audit teams hire CISAs.
- CISA vs Security+: Security+ is entry-level technical security. It’s a useful base for a new IT auditor who lacks a security background.
- Cloud audit: If you audit cloud environments, CCSP or a cloud provider certification such as the AWS Certified Security – Specialty exam adds depth that CISA doesn’t cover in detail.
Planning your next certification? See the full certification roadmap for the order to take them by career goal.
What I would tell a friend starting CISA
Learn to answer as an auditor, not as a fixer. When two answers both sound right, pick the one that gives independent, reliable evidence or reports the issue to the right people. And follow real breaches: the most useful audit findings come from asking whether the control that failed somewhere else would hold up in your own organization.
Every breach report is a control that failed. Read them like an auditor. The CyberExperts Daily Brief covers what changed in security and why it matters, in five minutes, weekday mornings. Get tomorrow’s brief.
Frequently asked questions
How many questions are on the CISA exam?
150 multiple-choice questions in four hours (240 minutes).
What is the passing score for CISA?
450 on ISACA’s scaled score range of 200 to 800.
How much does the CISA exam cost?
US$575 for ISACA members and US$760 for non-members, plus a one-time US$50 application fee after you pass. Keeping CISA costs US$45 a year for members or US$85 for non-members.
What are the CISA experience requirements?
Five years of information systems auditing, control, assurance or security experience, gained within the 10 years before you apply. You have five years after passing to apply, and ISACA allows experience waivers for a maximum of three years.
Can I take CISA without experience?
Yes. Anyone can take the exam. You need the experience only when you apply for certification, within five years of passing.
Is the CISA exam changing in 2026 or 2027?
ISACA hasn’t announced a new CISA exam content outline; the current one took effect in August 2024. The CPE rules change on January 1, 2027: at least 90 of the 120 three-year CPE hours must align with CISA content, and up to 30 can cover broader professional development.
Should I get CISA or CISM first?
If you work in audit, assurance or compliance, CISA first. If you manage a security program, CISM first. Many GRC professionals eventually hold both.
Sources
- ISACA, CISA certification: isaca.org
- ISACA, CISA exam (pricing, registration, certification steps): isaca.org
- ISACA, CISA exam content outline: isaca.org
- ISACA, Get CISA certified (experience requirements): isaca.org
- ISACA, Maintain CISA certification (CPE and fees): isaca.org
- ISACA, CPE policy changes effective January 1, 2027: isaca.org
- ISACA, Exam Candidate Guide (format, scoring, waivers): isaca.org
- BLS, Accountants and auditors (includes IT auditors): bls.gov
- BLS, Information security analysts: bls.gov
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.