Exampractice
Cybersecurity

CISA Certification Guide

What CISA is, its five exam domains, eligibility rules, full costs and the step-by-step path from registration to certified — verified against ISACA sources.

Alexander Novak · 11 min read
Circular dashboard divided into five segments representing the CISA exam domains and their weightings, with a magnifying glass on top.

The Certified Information Systems Auditor (CISA) is ISACA's flagship credential for professionals who audit, control and assess an organisation's information systems. To earn it, you pass a 150-question exam covering five domains, then apply for certification with evidence of five years of relevant experience (waivers can reduce this by up to three years). As of 2026, the exam costs US$575 for ISACA members and US$760 for non-members, plus a US$50 application fee once you pass.

This guide covers everything you need to decide whether to pursue CISA and to navigate the process: what the certification actually attests to, the five domains and their weightings, the exam format, eligibility and experience requirements, the full cost picture, and the step-by-step route from registration to holding the credential. It deliberately stays out of three areas covered elsewhere: how difficult the exam is, how to study for it, and what it does for your salary — links to those are provided where relevant.

What is the CISA certification?

CISA — Certified Information Systems Auditor — is a professional certification issued by ISACA, the global association for IT governance, risk, audit and security professionals. It validates your ability to plan and execute information systems audits, evaluate IT governance, and assess the controls that protect an organisation's information assets. According to ISACA's own figures, more than 151,000 professionals hold the credential worldwide as of 2026.

Unlike vendor certifications tied to a specific product, CISA is vendor-neutral and role-based. It certifies a way of working — the audit process, evidence gathering, control evaluation, reporting — rather than proficiency in any single technology. That is why it appears in job descriptions for IT auditors, internal audit teams, compliance functions and consulting practices across industries and countries.

The current exam is built on the 2024 job practice (exam content outline), which took effect on 1 August 2024. The domain names carried over from the 2019 version, but the weightings shifted towards operations, resilience and protection of information assets — a signal of where ISACA sees the modern IT audit role heading.

Who is CISA designed for?

CISA is aimed at people who audit or assess information systems for a living, or who are moving into that work: IT auditors, internal auditors expanding into technology audits, IT risk and compliance analysts, security professionals whose role includes control assessment, and consultants who deliver audit or assurance engagements. It is a mid-career credential in practice — the experience requirement (covered below) assumes several years in the field — but there is nothing stopping an early-career professional from passing the exam first and completing the experience later.

If your interest is security management rather than audit, ISACA's CISM is usually the better fit; the two credentials serve different roles, as our CISA vs CISM comparison explains. And if you want a verdict on whether the investment pays off for your specific situation, that question has its own dedicated analysis in Is CISA Worth It?

The five CISA exam domains

The CISA exam tests five domains, each with a fixed weighting that determines how many of the 150 questions it contributes. Under the 2024 outline, the weightings are:

DomainTitleWeighting
1Information Systems Auditing Process18%
2Governance and Management of IT18%
3Information Systems Acquisition, Development and Implementation12%
4Information Systems Operations and Business Resilience26%
5Protection of Information Assets26%

Two things stand out in this table. First, Domains 4 and 5 together account for more than half the exam — operations, business resilience and information protection dominate. Second, Domain 3 (acquisition and development) is the smallest at 12%, which matters when you allocate study time. The 2024 update moved weight in exactly this direction: Domain 1 dropped from 21% to 18%, while Domain 4 rose from 23% to 26%.

In brief, Domain 1 covers audit planning, execution, evidence and reporting — the craft of auditing itself. Domain 2 covers how organisations govern and manage IT: strategy, policies, organisational structures and performance monitoring. Domain 3 deals with how systems are acquired, developed, tested and implemented, including project governance. Domain 4 covers day-to-day IT operations, service management, incident handling and business resilience. Domain 5 covers information asset security: access controls, network security, encryption and security event management.

A full breakdown of what each domain tests, topic by topic, is a study-planning exercise in its own right — see CISA Exam Domains Explained for that level of detail.

CISA exam format: what you sit on the day

The CISA exam is a computer-based test of 150 multiple-choice questions with a four-hour (240-minute) time limit. There are no essays, no labs and no simulations — every question is multiple choice. You can take it at a PSI testing centre or from home via online remote proctoring.

Key format facts, verified against ISACA's Certification Exam Candidate Guide (version 1.26):

  • Questions: 150, all multiple choice
  • Time: 4 hours (an average of 96 seconds per question)
  • Delivery: PSI test centres or remote proctoring
  • Languages: English, Spanish, Chinese-Simplified, French, German, Korean and Japanese
  • Breaks: up to two breaks of no more than 10 minutes each, with proctor permission
  • Results: a preliminary pass/fail appears on screen immediately; the official score arrives by email and online within 10 working days

Scoring uses a scaled 200–800 range, and 450 or above is a pass; a score of 800 means every question was answered correctly. Because the scale is not a raw percentage, ISACA publishes no percent-correct equivalent, and any figure you see quoted online is unofficial. What that scoring model means for how hard the exam actually is — and why candidates fail — is the subject of our companion piece, How Hard Is the CISA Exam?

One logistical rule worth flagging early: arrive on time. Candidates who are more than 15 minutes late forfeit their appointment and their fee.

CISA certification requirements: eligibility and experience

CISA's requirements trip up more people at the reading stage than at the application stage, because the exam and the certification have different rules. Here is the distinction that matters:

There are no prerequisites to sit the exam. Anyone can register and take it — no degree, no experience, no prior certification required.

Certification requires experience. To actually be awarded the CISA credential after passing, you must apply and provide evidence of a minimum of five years of professional experience in information systems audit, control, assurance or security. That experience must have been gained within the ten years preceding your application. You then have five years from your passing date to submit the application, so the exam result does not expire the moment you walk out of the test centre.

Experience waivers: reducing the five years

ISACA allows waivers and substitutions for a maximum of three years of the five-year requirement. In other words, at least two years of hands-on experience is always required, but education and certain other qualifications can substitute for the rest. The precise substitution rules (which degrees and qualifications count, and for how much) are detailed in ISACA's candidate guide and on the CISA pages at isaca.org — check the current terms there before assuming a specific waiver applies to you, as the categories are specific.

A realistic eligibility scenario

Consider an internal auditor with three years in a financial-services audit team, two of them spent on IT-focused engagements, plus a relevant degree. She can sit the exam today with no barrier. After passing, she applies the education waiver against part of the five-year requirement and counts her qualifying audit experience towards the rest; anything still outstanding she can complete within the five-year application window while the pass remains valid. The practical takeaway: do not wait until you are "fully eligible" to take the exam — the design of the programme explicitly accommodates passing first and certifying later.

How much does CISA certification cost?

The exam fee is the headline number, but the true cost of becoming and staying certified has several components. As of 2026, the verified figures are:

Cost itemISACA memberNon-member
Exam registrationUS$575US$760
Application processing fee (after passing)US$50US$50
Annual maintenance feeUS$45US$85
Eligibility extension (optional, one-time)US$75US$75

Fees are in US dollars; local taxes may apply depending on your country. The exam fee is non-refundable and non-transferable, and your membership status at the time of registration determines which rate you pay. Note the US$185 gap between member and non-member exam pricing — many candidates join ISACA before registering because the discount offsets much of the membership cost, though you should verify current membership dues on isaca.org before deciding.

On top of ISACA's fees, budget for study materials — ISACA's aligned resources for the 2024 outline are the CISA Review Manual (28th Edition), the CISA Online Review Course and the CISA Questions, Answers and Explanations (QAE) Database, each priced separately on isaca.org. Which materials are actually worth buying, and how to use them, is covered in our CISA exam preparation guide.

How to get CISA certified: the process step by step

The route from decision to credential follows a fixed sequence. Registration is continuous — the old system of fixed exam windows was retired years ago — so you control the timeline.

  1. Decide on ISACA membership. Compare current membership dues against the US$185 member discount on the exam fee. Membership status at registration is what counts.
  2. Register and pay. Register for the CISA exam via isaca.org. Payment starts a six-month eligibility period in which you must take the exam.
  3. Schedule your appointment. Book a slot at a PSI test centre or a remote-proctored session — as early as 48 hours after payment, and up to 90 days in advance. You can reschedule free of charge if you do so at least 48 hours before the appointment, within your eligibility window.
  4. Prepare. Most candidates study over a period of months; realistic timelines by background are covered in How Long Does CISA Preparation Take?
  5. Sit the exam. 150 questions, four hours, preliminary result on screen at the end.
  6. Receive your official score. Within 10 working days, by email and in your ISACA account.
  7. Apply for certification. Once you pass and meet the experience requirement (with any waivers), submit the application with the US$50 processing fee. You have five years from your pass date to do this.
  8. Maintain the credential. Report continuing professional education (CPE) annually and pay the maintenance fee (see below).

Two timing rules deserve emphasis because they cost real money when missed. If you do not take the exam within your six-month eligibility period, your fee is forfeited — a single US$75 extension is available, once. And if you fail, retakes are permitted but rationed: a maximum of four attempts within a rolling twelve-month period, with a 30-day wait after the first attempt and 90-day waits after the second and third, each at the full registration fee.

Keeping CISA: CPE and renewal

CISA is not a pass-once-hold-forever credential. To maintain it, you must earn and report a minimum of 20 CPE hours every year and at least 120 CPE hours across each three-year reporting cycle, and pay the annual maintenance fee (US$45 for members, US$85 for non-members, due by 1 January). CPE can come from training, conferences, teaching, professional contributions and other categories ISACA defines on its CISA maintenance pages.

When you weigh up CISA, treat maintenance as part of the deal: roughly a week's worth of learning activity per year, plus a small fee, for as long as you hold the credential. Professionals already working in audit or security typically absorb this through work they would do anyway.

Frequently asked questions

Can I take the CISA exam with no work experience?

Yes. There are no prerequisites to sit the exam. Experience is only required at the certification-application stage, and you have five years from passing to accumulate and document it (with waivers available for up to three of the five years).

How long is the CISA exam valid if I pass but don't apply?

Five years from your passing date. If you have not applied for certification within that window, the pass lapses and you would need to retake the exam.

Does CISA expire?

The certification continues as long as you meet the maintenance requirements: 20 CPE hours per year, 120 per three-year cycle, and the annual fee. Fail to maintain it and the credential can be revoked.

Can I take the CISA exam from home?

Yes. ISACA delivers the exam through PSI both at physical test centres and via online remote proctoring, so you can sit it at home provided your setup meets the proctoring requirements published in the candidate guide.

Is the exam offered in my language?

The CISA exam is available in English, Spanish, Chinese-Simplified, French, German, Korean and Japanese, per ISACA's candidate guide (v1.26).

Deciding whether CISA is your next step

If your work touches IT audit, assurance or control assessment — or you want it to — CISA is the credential that maps most directly onto that career, backed by a large global holder base and a clearly documented path: a five-domain, 150-question exam with no entry barriers, followed by an experience-verified application. The costs are knowable in advance (US$575–760 to sit, US$50 to apply, US$45–85 a year to keep), the timeline is in your control thanks to continuous registration, and the experience requirement is more flexible than it first appears once waivers and the five-year application window are factored in.

Your next moves depend on where you are. If you are still weighing the decision, read the cost-benefit analysis in Is CISA Worth It? and gauge the challenge in How Hard Is the CISA Exam? If you have decided, register, book a date and move on to preparation. A good early step is to try a handful of CISA practice questions to see the question style for yourself before you commit study time — the multiple-choice format is more judgement-based than most people expect.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like