Last updated September 2026
This page is about ISACA’s CISA certification, not the U.S. Cybersecurity and Infrastructure Security Agency.
CISA is the credential internal audit teams, Big Four firms, regulators and compliance groups use to sort IT auditors from everyone else. ISACA’s Certified Information Systems Auditor proves you can plan and run an audit of information systems, judge whether IT governance and controls actually work, and report findings management can act on. ISACA says more than 151,000 professionals hold it.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Nothing is changing on the exam itself right now. It still follows the content outline ISACA introduced in August 2024, and no new one has been announced. The change to plan for is on the maintenance side: a new CPE policy from January 1, 2027 (details below, and on ISACA’s CPE page).
Think like an auditor, or the exam will beat you
CISA questions are written from the auditor’s chair. The right answer usually gives the most reliable evidence, protects independence or best serves the audit objective. It is rarely what a sysadmin would do to fix the problem. The common ways candidates go wrong:
- Choosing the fix. Auditors report and recommend. If an answer has the auditor implementing a control, be suspicious.
- Weak evidence. An interview is weaker than a document, and a document is weaker than evidence the auditor gathers directly. Questions often hinge on that ranking.
- Independence slips. Anything that has the auditor auditing their own work, or designing the control they later test, is a red flag.
- Under-studying the big domains. Domains 4 and 5 together are more than half the exam. Technical people coast on domain 5 and then get surprised by operations and resilience.
From Donald: From my PMP and ITIL background, PMP adds the most value.
Who hires CISAs, and why
- Internal audit departments reviewing systems, controls and IT processes
- External audit and advisory firms
- Compliance, risk and GRC teams that test controls against frameworks and regulations
- Security teams whose people want to move into assurance, audit or governance
For those employers, CISA is a screening credential: it tells them you speak audit as well as IT. ISACA’s CISA page advertises an average salary of “US$149K+” for holders. That’s ISACA’s own figure, not an independent survey (ISACA).
The U.S. Bureau of Labor Statistics doesn’t break out IT auditors. It groups them with accountants and auditors and reports a median pay of $83,680 in May 2025 and 5% projected growth from 2025 to 2035. That group is broad, and the top 10% earned more than $144,090 (BLS). IT audit roles that combine CISA with security knowledge often pay well above the overall median, and many CISA holders move into security governance roles, where BLS lists information security analysts at a median of $129,180 (BLS).
Format, scoring and scheduling
| Item | Details |
|---|---|
| Exam content outline | Effective August 2024 (current) |
| Number of questions | 150 multiple-choice |
| Time limit | 4 hours (240 minutes) |
| Scoring | 450 on a scaled range of 200 to 800 |
| Where you test | In person at a PSI test center, or online with a remote proctor |
| Registration | Continuous; schedule as early as 48 hours after paying; eligibility lasts six months |
| Exam price | US$575 (ISACA member) or US$760 (non-member) |
| Application fee | US$50, paid once when you apply |
| Experience | Five years of IS/IT audit, control, assurance or security experience; waivers available for up to three years |
| Annual maintenance fee | US$45 a year (member) or US$85 a year (non-member) |
| CPE | 20 hours minimum every year; 120 hours over each three-year cycle |
Sources: ISACA’s CISA exam page, certification requirements, maintenance requirements, exam content outline and the ISACA Exam Candidate Guide.
Five domains, weighted toward operations and protection
| Domain | Weight | What it covers |
|---|---|---|
| 1. Information Systems Auditing Process | 18% | Audit standards and codes of ethics, types of audits, risk-based audit planning, types of controls, audit project management, testing and sampling, evidence collection, audit data analytics, reporting and audit quality assurance |
| 2. Governance and Management of IT | 18% | Laws and standards, IT governance and strategy, policies and procedures, enterprise architecture, enterprise risk management, privacy, data governance and classification, IT resource and vendor management, and performance monitoring |
| 3. Information Systems Acquisition, Development and Implementation | 12% | Project governance, business cases and feasibility, system development methodologies, control design, implementation testing, configuration and release management, migration and data conversion, and post-implementation review |
| 4. Information Systems Operations and Business Resilience | 26% | IT components and asset management, job scheduling, shadow IT, availability and capacity, problem and incident management, change, configuration and patch management, log management, business impact analysis, resilience, backup and restoration, BCP and DRP |
| 5. Protection of Information Assets | 26% | Security policies and frameworks, physical controls, identity and access management, network and endpoint security, DLP, encryption and PKI, cloud, mobile and IoT, awareness training, attack methods, security testing, monitoring, incident response and forensics |
Weights and topics: ISACA CISA exam content outline (effective August 2024). Domains 4 and 5 make up more than half the exam.
After you pass: the experience rule
Passing the exam doesn’t make you a CISA. You apply for certification afterwards, with verified experience (ISACA):
- Five years of professional information systems auditing, control or security work experience, as described in the CISA job practice areas.
- Timing: The experience must fall within the 10 years before you apply, and you have five years from the date you pass the exam to apply.
- Verification: A supervisor or manager verifies your experience.
- Waivers: ISACA’s Exam Candidate Guide says experience waivers are available for a maximum of three years (ISACA). Check the current CISA application in MyISACA for which education or other substitutions qualify before you count on one.
Early-career auditors often pass first, then apply when they hit the five years. That works as long as you apply within five years of your pass date.
Fees at a glance
| Fee | ISACA member | Non-member |
|---|---|---|
| Exam registration | US$575 | US$760 |
| Application processing (once, when you apply) | US$50 | US$50 |
| Annual maintenance (due January 1) | US$45 | US$85 |
Membership carries its own annual dues, so compare the exam saving with the dues in your region before you join. For prep, ISACA sells the CISA Review Manual (28th edition), a questions-and-answers database with more than 1,000 questions, and an online review course. Third-party courses and books are common too.
A 12-week plan, domain by domain
Budget about eight hours a week. Some audit, control or security experience helps; if you have none, add time to weeks 1 and 2.
- Weeks 1 to 2: the audit process (18%). Standards, audit planning, sampling, evidence and reporting. This domain teaches the auditor’s mindset the whole exam depends on.
- Weeks 3 to 4: governance and management of IT (18%). Governance vs management, frameworks, policies, enterprise architecture, risk management, privacy, data governance and vendor oversight.
- Week 5: acquisition, development and implementation (12%). Project controls, business cases, SDLC, testing, release management and post-implementation reviews.
- Weeks 6 to 8: operations and business resilience (26%). IT operations, change and patch management, BIA, RTO and RPO, backup strategies, BCP and DRP testing.
- Weeks 9 to 10: protection of information assets (26%). Identity and access management, network and endpoint security, encryption and PKI, cloud and mobile, security testing, incident response and forensics, all from the auditor’s view.
- Weeks 11 to 12: practice. Work through a large question bank in timed blocks. Read every explanation, especially for questions where you picked the “technical fix” instead of the auditor’s answer.
Keeping CISA: the 2027 CPE rules
You need at least 20 CPE hours a year and 120 over each three-year period, plus the annual maintenance fee. From January 1, 2027, the 120-hour requirement stays, but only 90 of those hours must align with CISA content. Up to 30 can come from broader professional development such as leadership, soft skills or mentoring.
CISA or CISM (and other pairings)
- CISA vs CISM: Both come from ISACA. CISA is for people who audit and assure; CISM is for people who manage security programs. Many GRC professionals earn both, usually CISA first.
- CISA vs CISSP: CISSP is broader security knowledge for practitioners and leaders. CISA is audit-specific. Security teams hire CISSPs; audit teams hire CISAs.
- CISA vs Security+: Security+ is entry-level technical security. It’s a useful base for a new IT auditor who lacks a security background.
- Cloud audit: If you audit cloud environments, CCSP or a cloud provider certification such as the AWS Certified Security – Specialty exam adds depth that CISA doesn’t cover in detail.
Planning the GRC track? Our certification roadmap shows how CISA and CISM fit by goal.
How CISA ranks against security certs: Best Cybersecurity Certifications in 2026.
Every breach report is a control that failed. Read them like an auditor. The CyberExperts Daily Brief gives you the week’s incidents in five minutes, weekday mornings. Get tomorrow’s brief.
Questions about the CISA certification
Is this the CISA certification or the CISA agency?
This page covers ISACA’s Certified Information Systems Auditor certification, not the U.S. Cybersecurity and Infrastructure Security Agency.
What is the CISA exam like?
Four hours for 150 multiple-choice questions. You pass with a scaled score of 450 on a range of 200 to 800.
How much does CISA cost?
US$575 for ISACA members and US$760 for non-members, plus a one-time US$50 application fee. Maintaining it costs US$45 a year for members or US$85 for non-members.
Do I need five years of audit experience before the exam?
No. Anyone can take the exam. You need five years of information systems auditing, control, assurance or security experience, gained within the 10 years before you apply, when you apply for certification. You have five years after passing to apply, and ISACA allows waivers for a maximum of three years.
Is the CISA exam changing?
ISACA hasn’t announced a new content outline; the current one took effect in August 2024. The CPE rules change on January 1, 2027: at least 90 of the 120 three-year CPE hours must align with CISA content, and up to 30 can cover broader professional development.
Why do security people struggle with CISA?
Because the exam wants the auditor’s answer: reliable evidence, independence and reporting to the right people. Security professionals tend to pick the technical fix instead.
CISA or CISM first?
If you work in audit, assurance or compliance, CISA first. If you manage a security program, CISM first. Many GRC professionals eventually hold both.
Sources
- ISACA, CISA certification: isaca.org
- ISACA, CISA exam (pricing, registration, certification steps): isaca.org
- ISACA, CISA exam content outline: isaca.org
- ISACA, Get CISA certified (experience requirements): isaca.org
- ISACA, Maintain CISA certification (CPE and fees): isaca.org
- ISACA, CPE policy changes effective January 1, 2027: isaca.org
- ISACA, Exam Candidate Guide (format, scoring, waivers): isaca.org
- BLS, Accountants and auditors (includes IT auditors): bls.gov
- BLS, Information security analysts: bls.gov
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.