Three or four years into an IT audit career, most Certified Information Systems Auditor (CISA) holders notice the same thing: the interesting decisions happen on the other side of the table. You assess the controls; someone else designs the risk programme, runs the security function or owns the governance framework. Your next certification is really a decision about which side of that table you want to sit on.
Short answer: if you want to move from assessing risk to managing it, take CRISC. If you want to run an information security programme, take CISM. If you want hands-on security depth or broader technical credibility, take CISSP. If you intend to stay in audit and go deeper, look at ISACA's AAIA (AI audit) or the IIA's CIA. There is no single "level 2" after CISA — CISM is a different discipline, not a promotion.
This article maps those routes so you can pick one deliberately. It assumes you already hold CISA; if you are still weighing up the audit credential itself, start with the official ISACA CISA page instead.
First, decide the destination role — not the exam
Certifications after CISA sort cleanly by the job they point at. Before comparing exam fees or domains, answer one question honestly: in five years, do you want to be an audit leader, a risk manager, a security manager, or a security practitioner? Each answer has a different best-fit credential, and picking by exam difficulty or salary headline instead of destination is the most common sequencing mistake we see auditors make.
A useful test: read your last three audit reports. If the findings you enjoyed writing were about risk appetite, ownership and treatment, you are leaning CRISC. If they were about programme structure, budgets and incident readiness, that is CISM territory. If you kept wanting to get into the technical weeds of the control itself, CISSP will suit you better than either.
CRISC: from finding risks to managing them
Certified in Risk and Information Systems Control (CRISC) is ISACA's risk-management credential, and it is the most natural continuation of audit work because you already spend your days identifying and evaluating risk — CRISC certifies your ability to own the response side.
The exam covers four domains: Governance (26%), Risk Assessment (22%), Risk Response and Reporting (32%), and Technology and Security (20%). As a CISA holder you will recognise most of the governance and assessment material; the risk-response and reporting domain, the heaviest at 32%, is where the perspective genuinely shifts from auditor to risk owner.
Practical details, as of 2026: the exam is 150 multiple-choice questions over 4 hours, scored on ISACA's 200–800 scale with 450 to pass, and costs US$575 for ISACA members or US$760 for non-members, plus a US$50 application fee after you pass (confirm current fees on isaca.org). Certification requires 3 or more years of experience in IT risk management and IS control — and unlike CISA, CRISC allows no experience waivers. Audit experience alone does not automatically qualify; check how ISACA counts your control-related work before you register.
CRISC suits the auditor who wants to move into a second-line risk function, an IT risk manager role, or a GRC leadership track without leaving the governance world ISACA credentials are built around.
CISM: crossing over into security management
Certified Information Security Manager (CISM) takes you out of assurance altogether and into running the information security programme — strategy, budget, team, incidents. It is the right pick when your goal is "security manager", "head of information security" or eventually a CISO track.
The current exam mirrors CISA's mechanics — 150 questions, 4 hours, 450/800 to pass, US$575/US$760 plus the US$50 application fee — but the content is a different world: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%) and Incident Management (30%). Certification requires five or more years of information security management experience, with waivers available for a maximum of 2 years; like all core ISACA exams, you can sit it before you have the experience and apply within 5 years of passing.
One timing note that matters in 2026: ISACA has announced that the CISM exam content outline changes on 3 November 2026. If CISM is your next step, decide whether you are testing against the current outline or the new one, and match your study materials accordingly — ISACA had not published the new domain weights as of August 2026.
Because the exam format feels familiar, many auditors underestimate the mindset change. CISM questions reward the manager's answer — what protects the business — where audit habits push you towards the reviewer's answer. Timed practice is the cheapest way to expose that habit before exam day: a full run through CISM practice questions will show whether you are answering as a manager or still marking someone else's homework. What comes after CISM — governance, cloud or CISO-track credentials — is its own decision, mapped in our guide to certifications after CISM.
CISSP: technical breadth beyond the audit lens
Certified Information Systems Security Professional (CISSP), from ISC2, is the odd one out here: it is a practitioner's credential, not a governance one, and that is exactly why some auditors choose it. If your findings keep getting challenged by engineers, or you want the option of security architecture and operations roles, CISSP adds the technical breadth CISA never claimed to cover.
Know what you are signing up for. The exam has used Computerized Adaptive Testing in all languages since April 2024 — 100 to 150 items in a maximum of 3 hours, with no going back to previous questions — and costs US$749 in the Americas as of 2026 (regional prices vary). Certification requires 5 years of cumulative paid experience across at least 2 of its 8 domains; a degree or an approved credential can waive one year, and audit work that maps to domains such as Security and Risk Management or Security Assessment and Testing may count. Fall short and you can still pass the exam as an Associate of ISC2, then earn the experience within 6 years.
Choose CISSP over CRISC or CISM when your gap is technical credibility rather than management standing. Where it leads afterwards — concentrations, cloud, leadership — is covered in our companion piece on what to take after CISSP.
Staying in audit: AAIA and the CIA
Progression does not have to mean leaving audit. Two credentials deepen the path you are already on.
ISACA Advanced in AI Audit (AAIA). Launched in May 2025, AAIA is an add-on credential for which every CISA holder automatically qualifies. It covers AI Governance and Risk (33%), AI Operations (46%) and AI Auditing Tools and Techniques (21%) across a shorter exam — 90 questions in 2.5 hours — and costs less than the core certs at US$459 member / US$599 non-member plus the US$50 application fee. With ISACA reporting in 2025 that 85% of digital trust professionals expect to need stronger AI skills within two years, AAIA is the clearest way for an auditor to specialise ahead of demand rather than behind it.
IIA Certified Internal Auditor (CIA). If your ambition is chief audit executive rather than IT audit specialist, the Institute of Internal Auditors' CIA broadens you from IS audit into the full internal audit profession — governance, engagement planning and business auditing beyond technology. Working through CIA Part 1 practice questions is a quick way to gauge how much of the syllabus your IT audit experience already covers. Confirm current CIA fees and eligibility on the IIA's site — they differ from ISACA's structure.
A third ISACA option, Certified in the Governance of Enterprise IT (CGEIT), suits auditors heading towards board-level IT governance advisory; it requires 5 years of governance-support experience with no waivers, so it typically comes later in a career than the options above.
How the main options compare
Factor
CRISC
CISM
CISSP
AAIA
Provider
ISACA
ISACA
ISC2
ISACA
Target role
IT risk manager / GRC
Security manager / CISO track
Security practitioner / architect
AI-focused auditor
Experience for certification
3 yrs, no waivers
5 yrs, up to 2 waived
5 yrs, 1 waivable (Associate route exists)
Active CISA (or listed audit/accountancy credential)
Exam (2026)
150 Qs, 4 hrs
150 Qs, 4 hrs
100–150 Qs CAT, max 3 hrs
90 Qs, 2.5 hrs
Cost (2026, confirm on provider site)
$575/$760 + $50
$575/$760 + $50
$749 (Americas)
$459/$599 + $50
Distance from audit
Short step
Career change
Career change + technical depth
Stays in audit
Salary claims deserve caution here: figures vary widely by country, experience and role. For context, ISACA's own page cites a US$149K+ average annual salary for CISA holders (as of August 2026), and Skillsoft's 2025 salary data reports CISM holders averaging US$111,346 in Asia-Pacific and US$134,025 in Latin America — survey averages for credential holders, not a payout any certificate delivers on its own.
A sequencing plan for the next 24 months
Months 1–2: pick the destination role using the report-reading test above, and verify your experience actually qualifies — CRISC's no-waiver rule and CISM's management-experience requirement disqualify more candidates than the exams do.
Months 2–3: if you choose an ISACA exam, price membership before registering; the member discount on exam fees is substantial (verify current dues on isaca.org). Registration is continuous, with a six-month eligibility window once you pay.
Months 3–6: study against the current official outline — especially for CISM, given the 3 November 2026 outline change — and benchmark with timed practice before booking. ExamPractice offers free sample questions across the ISACA exam range, with fuller question sets and a timed simulation mode for subscribers.
Months 6–24: after passing, submit your certification application (ISACA gives you 5 years), then plan CPE deliberately — ISACA certifications need a minimum of 20 CPE hours a year and 120 per 3-year cycle, and choosing CPE in your destination discipline compounds the career move you just made.
Whichever branch you take, the credential is the paperwork for a transition you drive through the work itself: volunteer for the risk committee before you hold CRISC, take incident post-mortems seriously before you hold CISM. The auditors who progress fastest are the ones whose next certification confirms a move already underway.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
A five-step decision process for choosing a professional certification: goals, market demand, true cost, prerequisites and renewal — with a comparison worksheet.
The strongest professional certifications for 2026, ranked on demand, recognition and cost of ownership — with the year's retirements and AI-driven changes factored in.