Certification Exam Costs Explained
·13 min read
What certification exams actually cost across CompTIA, AWS, Cisco, Microsoft, ISC2 and PMI, why prices differ so much, and how pricing tiers work.
Continue readingHow to renew your CISA: the 20-hour annual and 120-hour cycle CPE requirements, ISACA maintenance fees, reporting deadlines and what to do if you lapse.

Certified Information Systems Auditors spend their working lives checking other people's compliance, yet the credential itself imposes a compliance regime of its own — and ISACA audits it. Keeping a Certified Information Systems Auditor (CISA) certification active comes down to three obligations that never change: report at least 20 Continuing Professional Education (CPE) hours every year, accumulate at least 120 CPE hours across each three-year cycle, and pay the annual maintenance fee on time. Miss any of the three and the credential is at risk.
This guide is for people who already hold the CISA. It covers the requirements, the money, the reporting mechanics and what to do about a lapse — nothing about earning the certification in the first place.
| Obligation | Requirement | When |
|---|---|---|
| Annual CPE minimum | 20 CPE hours | Every year, reported annually |
| Cycle CPE total | 120 CPE hours | Per three-year reporting cycle |
| Annual maintenance fee | US$45 members / US$85 non-members (reported figures — confirm at isaca.org) | Due by 1 January |
| Reporting | CPE hours declared through your ISACA account | Annually, by 31 December |
Two structural points trip people up. First, the 20-hour annual minimum means you cannot cram all 120 hours into the cycle's final year — a quiet year with zero reported hours breaches the policy even if your three-year total ends up fine. Second, the fee and the hours are independent obligations: paying the fee does not excuse a CPE shortfall, and vice versa.
ISACA accepts a broad set of professional-development activities, several of them free. CPE-eligible categories include:
Some categories are capped — activities like mentoring and self-study can only contribute up to category limits, so a renewal plan built entirely on one activity type may not qualify in full. Check the current CPE policy on isaca.org before assuming a single category will carry your whole 120 hours.
A workable rhythm for a practising IS auditor: one ISACA chapter event per quarter, one substantial course or conference per cycle, and logging the eligible professional-education elements of normal work. That pattern clears 20 hours a year without a December scramble — the cross-provider tactics in how to keep your certifications current apply here too.
The direct cash cost is the annual maintenance fee — reported by secondary sources at US$45 for ISACA members and US$85 for non-members, due by 1 January (verify the current figure on ISACA's CISA maintenance page, as ISACA fees change over time). Over a three-year cycle that is roughly US$135–255 depending on membership status, before any spending on the CPE activities themselves.
Whether ISACA membership pays for itself at renewal time depends on how you earn CPE: members get access to chapter events and member-priced training that can lower the credit-earning cost well below the dues. For how CISA maintenance compares with other bodies' fee structures, see the broader breakdown of certification renewal costs.
If you hold several ISACA credentials or certifications from multiple bodies, a single tracking system beats per-cert memory — see how to keep all your certifications organised for a portfolio-level approach.
If you fall short on CPE hours or miss the fee, the certification can be revoked — and ISACA's precise grace and reinstatement mechanics are not something we can state as settled fact here, because they are policy details ISACA can change; treat isaca.org and ISACA support as the authority on your specific situation. What we can say:
The consequences side — what an expired credential means for your CV and current role — is covered in what happens when a certification expires.
Often, yes — a security conference or training course that satisfies another body's continuing-education programme can also be CPE-eligible under ISACA's rules, provided the activity itself meets ISACA's criteria and category caps. Log it once, claim it wherever it legitimately qualifies, and keep the evidence for both bodies.
Each ISACA credential has its own maintenance obligations, but a single relevant activity can frequently serve more than one where the subject matter fits. Check each credential's maintenance page on isaca.org before assuming a single 120-hour pool covers everything.
No — ISACA's maintenance model is CPE-based. Unlike providers that let you re-test to renew, an active CISA is maintained through reported hours and fees, which is why annual tracking matters so much.
CPE hours are reported annually with the reporting year ending 31 December, and the maintenance fee is due by 1 January. Treat mid-December as your personal cut-off so nothing depends on holiday-week admin.
Renewal is easiest when it stops being an event: a quarterly CPE habit, receipts filed as they arrive, hours reported in early December, and the fee paid before the new year. Do that, and the three-year cycle becomes background noise rather than a deadline. If your development plan for the coming cycle includes adding a neighbouring credential — many CISA holders look at security-management or risk certifications next — the certification exams directory is a reasonable place to scan the options, and ExamPractice offers free sample questions on its exam pages if you want to gauge a new exam's style before committing study hours to it.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·13 min read
What certification exams actually cost across CompTIA, AWS, Cisco, Microsoft, ISC2 and PMI, why prices differ so much, and how pricing tiers work.
Continue reading·7 min read
The real end-to-end cost of earning a professional certification — exam fees, training, materials and the extras most first-time candidates forget.
Continue reading·5 min read
When paid certification training earns its price and when self-study wins — a decision framework comparing courses, bootcamps and self-study by candidate situation.
Continue reading