Exampractice
Cybersecurity

CISA Salary Guide

What CISA holders earn in 2026 — the verified figures, how pay shifts with role, region and experience, and how to benchmark your own market rate.

Alexander Novak · 8 min read
Magnifying glass examining a salary bar chart annotated with source, year and region labels

Short answer: ISACA itself advertises an average annual salary of US$149K+ for Certified Information Systems Auditor (CISA) holders on its official certification page (as of August 2026). That is a self-reported headline for a global, experience-heavy population — most people researching the certification will earn less than it early on and some will earn well beyond it later. This guide explains what that figure does and does not mean, what other verifiable benchmarks exist, and how role, region and experience move the number for a specific person: you.

A quick scope note. Whether the pay uplift justifies the exam's cost and effort is a separate question answered in Is CISA Worth It?, and the roles behind these pay packets are mapped in the CISA Career Path Explained article. Here, we stay on the money.

The verified numbers, and exactly where they come from

Honest salary writing starts with an uncomfortable admission: there are very few CISA pay figures that can be traced to a named source, a year and a geography. Here is what clears that bar as of August 2026:

  • US$149K+ average annual salary — ISACA's own figure, published on the official CISA page alongside its count of 151,000+ certification holders worldwide. ISACA does not break this down by country or seniority on that page.
  • Around US$155K average for CISM holders (US) — from Skillsoft's IT Skills and Salary research (2025), for ISACA's security-management certification rather than CISA itself. It is included here because CISM is the credential CISA holders most often weigh against it; the CISM Salary Guide covers that side fully. Verify the current figure on Skillsoft's site before relying on it — salary-survey numbers are revised annually.

Skillsoft's surveys have also historically reported CISA-specific averages, but we could not verify the exact current figure and year at the time of fact-checking, so we will not print one. That restraint is deliberate, and it leads to the most useful skill this guide can teach you.

How to read any CISA salary claim (a four-question test)

Search results for "cisa salary" serve up numbers ranging so widely they cannot all describe the same job. Before believing any of them — including ours — run four checks:

  1. Whose data is it? Certification bodies report on their own members (a senior-skewed, motivated population). Job boards average advertised ranges (which skew to roles that are hard to fill). Salary-survey firms sample their own customers. Each lens inflates or deflates differently.
  2. Which year and currency? A 2022 figure quoted in 2026 has quietly absorbed four years of inflation and market change. A "$" that turns out to be Singapore dollars changes everything.
  3. Which population? "Average CISA salary" mixes a 26-year-old audit analyst in Manila with a 55-year-old audit director in New York. Averages over that mix describe nobody.
  4. Salary or total compensation? Consulting and banking roles often carry bonuses worth 10–30% of base pay; a base-only figure understates them, while a total-comp figure flatters employers who pay low bases.

ISACA's US$149K+ passes checks 1 and 2 (named source, current year) but not 3 — it is a global average across all holders — which is why it belongs at the top of your reading as a ceiling-ish reference point, not a personal expectation.

What actually moves a CISA holder's pay

Role type

The certification feeds several job families, and they pay differently for structural reasons:

  • Internal IT audit sits in the middle of the range at analyst and senior levels, with strong upside once you reach audit management, because leadership roles are paid against the whole audit function rather than a technical specialism.
  • External audit and advisory (professional-services firms) starts lower at junior grades but compounds fastest — the consulting ladder repriced roughly every promotion, with manager and director grades leaping ahead of in-house equivalents.
  • GRC and technology risk roles in-house often out-pay equivalent-seniority audit roles, particularly in financial services, because they compete for talent with security teams.
  • Regulated-industry specialists — IT auditors fluent in banking, insurance or healthcare compliance regimes — command premiums over generalists at the same grade.

Experience and the certification clock

CISA's own design tells you when the pay effect kicks in. You can sit the exam with no experience, but certification requires five years of qualifying IS audit, control, assurance or security experience (with waivers of up to three years). The result is that "CISA salary" statistics largely describe people at five-plus years of experience — the point where the credential, the experience and the pay rise arrive together. Broadly:

  • Pre-certification (exam passed, experience accruing): the exam pass is a hiring signal more than a pay lever; the salary benefit shows up as access to better-paying employers.
  • Newly certified (around 5–8 years in): the title "senior IT auditor" and the credential tend to land close together, and this is where holders report the clearest step-up.
  • Certified plus leadership (8+ years): pay decouples from the certification and attaches to scope — team size, audit-universe size, committee exposure. The letters become table stakes.

Treat these as mechanics, not multipliers: no source in our research supports a precise "CISA adds X%" claim, and you should distrust anyone who prints one without a named study behind it.

Region: the UK-versus-US question

Candidates comparing markets should expect US salaries for equivalent IT-audit roles to look higher on paper than UK ones, as they do across most technology and finance occupations — but no source we could verify publishes a current, like-for-like CISA split between the two countries, so this guide will not manufacture one. What we can tell you is how to make the comparison honestly:

  • Compare roles, not averages — a senior IT auditor in London against a senior IT auditor in a comparable US financial centre, using live job advertisements with posted ranges.
  • Adjust for total employment cost: US figures come with healthcare deductions and typically thinner leave and pension provision; UK figures embed employer pension contributions and statutory benefits.
  • Note that pay-transparency laws in several US states and in UK public-sector postings now put real ranges in job ads — these beat any survey average because they are offers, not summaries.
  • Remember ISACA prices globally: the exam costs US$575 for members and US$760 for non-members wherever you sit it (plus a US$50 application fee), so the certification's cost-to-salary ratio is far better in high-wage markets. That asymmetry, not the exam itself, is why the credential is often described as especially good value in the US, the UK, the Gulf and Singapore.

Employer size and sector

Large, regulated organisations pay more for the same audit title than small ones, for a blunt reason: their audit findings carry regulatory and market consequences. A CISA holder auditing a systemically important bank is priced against that risk. Public-sector and not-for-profit audit roles typically sit below private-sector equivalents but often compensate with pension value and stability — worth pricing in rather than dismissing.

Does CISA increase your salary, or do higher earners simply get CISA?

Both, and it matters which is operating in your case. The certification's population is senior-skewed by construction (the five-year experience rule), so headline averages partly reflect who holds it rather than what it adds. The uplift is most real in three situations:

  1. Crossing a screening threshold. Many IT-audit vacancies list CISA as required or strongly preferred. Where the credential is the difference between being shortlisted and not, its effect on your pay is the whole difference between the new job and your current one.
  2. Switching employers. Pay research consistently frames external moves as the moment credentials get repriced; internally, your salary history anchors you.
  3. Entering from an adjacent field. For a sysadmin or financial auditor moving into IT audit, CISA substitutes for a track record they do not yet have — that is the strongest version of the "increase" story.

Conversely, if you are already a well-paid audit manager, adding CISA late mainly protects mobility rather than raising pay. Stacking a further specialism can reopen the gap: ISACA's Advanced in AI Audit (AAIA) credential, for which all CISA holders qualify, targets AI assurance — a skill ISACA's 2025 research suggests 85% of digital trust professionals expect to need more of within two years. Scarce skills, not extra letters, are what employers ultimately pay for.

Benchmarking your own number: a 30-minute method

Skip the generic averages and build a personal benchmark:

  1. Collect 8–10 live job adverts for your target title, seniority and city (or remote policy), keeping only those with posted ranges.
  2. Record the midpoints, discard the single highest and lowest, and average the rest — that is your working market rate.
  3. Adjust ±10–15% for your specifics: regulated-industry expertise, scarce system knowledge, people-management scope.
  4. Cross-check against ISACA's official figure and any current salary survey — as sanity bounds, not targets.
  5. Re-run the exercise every six months; this market reprices quickly.

This method also tells you when the certification is worth accelerating: if the adverts in your stack keep listing CISA as essential, every month before you hold it has a measurable price.

Frequently asked questions

What does ISACA's "US$149K+ average" really represent?

It is ISACA's own published figure on the CISA certification page (August 2026) for the certified population globally. ISACA does not publish its methodology, country split or seniority split alongside it, so treat it as an indicator of the credential's senior-market standing rather than a salary you should quote in negotiation.

Is a CISA salary higher than a CISM salary?

The only verifiable comparison points are ISACA's US$149K+ CISA figure and Skillsoft's roughly US$155K US average for CISM (2025) — different sources, populations and methods, so the honest answer is that they sit in the same band and the role, not the credential, decides. The two certifications also serve different careers; CISA vs CISM covers that choice.

Do I need to add the certification cost into my salary maths?

Yes, but it is small against the stakes: US$575–760 for the exam, US$50 to apply after passing, and ongoing annual maintenance (US$45 for members, US$85 for non-members, per ISACA's CISA maintenance page) plus continuing-education time. Confirm current fees on isaca.org before budgeting, as they change.

Where can I find trustworthy salary data beyond this guide?

ISACA's certification pages, Skillsoft's annual IT Skills and Salary report, national statistics bodies' occupation data, and — best of all — posted ranges in live job advertisements for your exact market.

Turning research into a pay rise

A salary guide earns its keep only if it changes what you do next. If the benchmark exercise shows CISA gating the roles you want, the cheapest way to shorten the gap is to find out how close to exam-ready you already are: work through some free CISA sample questions to see how the five domains are examined, then plan your preparation around what the results reveal.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like