Exampractice
Costs & Renewal

CISA Certification Renewal Guide

How to renew your CISA: the 20-hour annual and 120-hour cycle CPE requirements, ISACA maintenance fees, reporting deadlines and what to do if you lapse.

Aisha Rahman · 6 min read
Clipboard checklist of CISA renewal obligations with CPE hours ticked and the annual fee item pending

Certified Information Systems Auditors spend their working lives checking other people's compliance, yet the credential itself imposes a compliance regime of its own — and ISACA audits it. Keeping a Certified Information Systems Auditor (CISA) certification active comes down to three obligations that never change: report at least 20 Continuing Professional Education (CPE) hours every year, accumulate at least 120 CPE hours across each three-year cycle, and pay the annual maintenance fee on time. Miss any of the three and the credential is at risk.

This guide is for people who already hold the CISA. It covers the requirements, the money, the reporting mechanics and what to do about a lapse — nothing about earning the certification in the first place.

The CISA renewal requirements in one view

ObligationRequirementWhen
Annual CPE minimum20 CPE hoursEvery year, reported annually
Cycle CPE total120 CPE hoursPer three-year reporting cycle
Annual maintenance feeUS$45 members / US$85 non-members (reported figures — confirm at isaca.org)Due by 1 January
ReportingCPE hours declared through your ISACA accountAnnually, by 31 December

Two structural points trip people up. First, the 20-hour annual minimum means you cannot cram all 120 hours into the cycle's final year — a quiet year with zero reported hours breaches the policy even if your three-year total ends up fine. Second, the fee and the hours are independent obligations: paying the fee does not excuse a CPE shortfall, and vice versa.

What counts as CPE for CISA?

ISACA accepts a broad set of professional-development activities, several of them free. CPE-eligible categories include:

  • Conferences and chapter events
  • Training courses and university study
  • Self-study programmes
  • Teaching, lecturing and publishing
  • Mentoring

Some categories are capped — activities like mentoring and self-study can only contribute up to category limits, so a renewal plan built entirely on one activity type may not qualify in full. Check the current CPE policy on isaca.org before assuming a single category will carry your whole 120 hours.

A workable rhythm for a practising IS auditor: one ISACA chapter event per quarter, one substantial course or conference per cycle, and logging the eligible professional-education elements of normal work. That pattern clears 20 hours a year without a December scramble — the cross-provider tactics in how to keep your certifications current apply here too.

What does maintaining the CISA cost?

The direct cash cost is the annual maintenance fee — reported by secondary sources at US$45 for ISACA members and US$85 for non-members, due by 1 January (verify the current figure on ISACA's CISA maintenance page, as ISACA fees change over time). Over a three-year cycle that is roughly US$135–255 depending on membership status, before any spending on the CPE activities themselves.

Whether ISACA membership pays for itself at renewal time depends on how you earn CPE: members get access to chapter events and member-priced training that can lower the credit-earning cost well below the dues. For how CISA maintenance compares with other bodies' fee structures, see the broader breakdown of certification renewal costs.

How to report your CPE hours

  1. Log activities as you complete them. Record the date, provider, activity type and hours; keep certificates of attendance or completion. ISACA can audit reported hours, and an auditor's own records should survive an audit.
  2. Report annually through your ISACA account. Hours are declared each year, with the reporting year closing on 31 December.
  3. Pay the maintenance fee by 1 January. The fee is invoiced through the same account.
  4. Watch your cycle position. Know which year of your three-year cycle you are in, and whether your running total is on pace for 120.

If you hold several ISACA credentials or certifications from multiple bodies, a single tracking system beats per-cert memory — see how to keep all your certifications organised for a portfolio-level approach.

What happens if your CISA lapses?

If you fall short on CPE hours or miss the fee, the certification can be revoked — and ISACA's precise grace and reinstatement mechanics are not something we can state as settled fact here, because they are policy details ISACA can change; treat isaca.org and ISACA support as the authority on your specific situation. What we can say:

  • Act before 31 December, not after. A shortfall you spot in November is a scheduling problem; one you spot in February is a policy problem.
  • A lapse is not always terminal. Certification bodies commonly offer reinstatement routes; the general landscape of options for a fully lapsed credential is covered in how to reinstate an expired certification.
  • Losing the credential means losing the right to use it. You cannot present yourself as a CISA while revoked — a serious matter in audit engagements where the credential is contractually cited.

The consequences side — what an expired credential means for your CV and current role — is covered in what happens when a certification expires.

Common CISA renewal mistakes

  • Treating 120 hours as the only target and ignoring the 20-hour annual minimum.
  • Reporting hours without evidence. Unsupported hours can fail an ISACA audit; keep certificates for the full cycle.
  • Assuming the fee auto-renews. The maintenance fee is a deliberate annual payment with a 1 January due date.
  • Double-counting ineligible activities. Capped categories (self-study, mentoring) have limits; routine work that involves no learning does not count.
  • Leaving everything to year three. Even where the totals could work, the annual minimum makes back-loading a rule breach.

Frequently asked questions

Do CPE hours from other certifications count toward CISA renewal?

Often, yes — a security conference or training course that satisfies another body's continuing-education programme can also be CPE-eligible under ISACA's rules, provided the activity itself meets ISACA's criteria and category caps. Log it once, claim it wherever it legitimately qualifies, and keep the evidence for both bodies.

Does holding multiple ISACA certifications multiply the CPE burden?

Each ISACA credential has its own maintenance obligations, but a single relevant activity can frequently serve more than one where the subject matter fits. Check each credential's maintenance page on isaca.org before assuming a single 120-hour pool covers everything.

Can I renew the CISA by retaking the exam instead of earning CPE?

No — ISACA's maintenance model is CPE-based. Unlike providers that let you re-test to renew, an active CISA is maintained through reported hours and fees, which is why annual tracking matters so much.

When exactly is my reporting deadline?

CPE hours are reported annually with the reporting year ending 31 December, and the maintenance fee is due by 1 January. Treat mid-December as your personal cut-off so nothing depends on holiday-week admin.

Keeping your CISA renewal on autopilot

Renewal is easiest when it stops being an event: a quarterly CPE habit, receipts filed as they arrive, hours reported in early December, and the fee paid before the new year. Do that, and the three-year cycle becomes background noise rather than a deadline. If your development plan for the coming cycle includes adding a neighbouring credential — many CISA holders look at security-management or risk certifications next — the certification exams directory is a reasonable place to scan the options, and ExamPractice offers free sample questions on its exam pages if you want to gauge a new exam's style before committing study hours to it.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like