Exampractice
Cybersecurity

CRISC Certification Guide

What CRISC covers, who qualifies, what the exam looks like and what it costs — a complete guide to ISACA's IT risk certification, verified for 2026.

Alexander Novak · 8 min read
Ring chart of the four CRISC exam domains with their official percentage weights

Certified in Risk and Information Systems Control (CRISC) is ISACA's certification for professionals who identify, assess and manage IT risk and design the controls that keep it within appetite. The exam has 150 multiple-choice questions across four domains, costs US$575 for ISACA members or US$760 for non-members, and certification requires three years of relevant experience — with no waivers. This guide covers what the credential actually certifies, the domains, eligibility rules, exam logistics, full cost and the step-by-step route to getting certified.

What is the CRISC certification?

CRISC (pronounced "see-risk") is awarded by ISACA, the professional association behind CISA, CISM and CGEIT. Where CISA certifies auditors and CISM certifies security managers, CRISC sits in the risk lane: it validates that you can build and run an IT risk management programme — identifying risk, assessing its likelihood and impact, choosing and reporting on responses, and monitoring the information systems controls that treat it.

That makes it the natural credential for people whose job is governance, risk and compliance (GRC) rather than hands-on security engineering. Typical holders work as IT risk managers, risk analysts, control owners, second-line risk officers and consultants who translate technical exposure into business language for boards and regulators.

Two things distinguish CRISC within ISACA's portfolio. First, it is the only one of the association's five core certifications with a three-year experience requirement rather than five. Second, it allows no experience waivers at all — more on both below.

The four CRISC domains

The exam follows ISACA's 2021 exam content outline, which as of August 2026 remains current with no announced changes. The official CRISC Review Manual is in its 8th edition. The four domains, with their official weights from ISACA's certification exam candidate guide, are:

Domain 1: Governance (26%)

Roughly a quarter of the exam. This domain covers the organisational context risk management operates in: organisational strategy, structure and culture, policies and standards, risk appetite and tolerance, ownership and accountability, and the ethics and professional standards that underpin the role. ISACA's own site phrases this domain as "Corporate IT Governance". The practical thrust is that risk decisions belong to the business — your job is to enable and inform them, not to make them unilaterally.

Domain 2: IT Risk Assessment (22%)

Identifying and analysing risk: threat and vulnerability analysis, risk scenario development, likelihood and impact assessment, and building and maintaining a risk register. Expect questions that test whether you can distinguish inherent from residual risk and choose the right assessment approach for a given situation.

Domain 3: Risk Response and Reporting (32%)

The heaviest domain. It covers selecting risk responses (accept, mitigate, transfer, avoid), designing and implementing controls, defining ownership of risk and controls, and the reporting layer — key risk indicators (KRIs), key performance indicators (KPIs) and key control indicators (KCIs) that tell management whether treatment is working. Because nearly a third of your score comes from here, it deserves a matching share of study time.

Domain 4: Information Technology and Security (20%)

The most technical domain: enterprise architecture, IT operations, project and change management, business continuity and disaster recovery, and information security principles. It exists so risk professionals can hold credible conversations with the technologists whose systems carry the risk. Candidates from non-technical GRC backgrounds often find this the least familiar territory — a point covered properly in how hard the CRISC exam really is.

CRISC requirements: who is eligible?

The eligibility model trips people up because it separates the exam from the certification.

To sit the exam: nothing. There are no prerequisites to register and take the CRISC exam. A student or career-changer can book it tomorrow.

To become certified: three or more years of experience in IT risk management and information systems control. Crucially, CRISC permits no experience waivers or substitutions — unlike CISA (up to three years waivable) or CISM (up to two). A degree or another certification does not shorten the requirement.

The sequencing is flexible: you can pass first and accumulate experience afterwards, because ISACA gives you five years from your passing date to apply for certification. Passing early is therefore a legitimate strategy for someone moving into risk from an adjacent field — the exam result waits while the CV catches up.

Once you apply, ISACA charges a one-time US$50 application processing fee.

CRISC exam format and logistics

As of 2026, the exam runs on the same machinery as ISACA's other core certifications:

  • Questions: 150 multiple-choice
  • Time: 4 hours (240 minutes)
  • Scoring: scaled 200–800; 450 or above passes. An 800 means every question correct. The scale is not a percentage — ISACA does not publish a raw percent-correct equivalent, so ignore any source claiming you "need 56%".
  • Delivery: computer-based at PSI testing centres or via online remote proctoring from home
  • Scheduling: registration is continuous year-round. You can book as early as 48 hours after payment, up to 90 days ahead, and you get a six-month eligibility window from registration to sit the exam. One US$75 extension is available — once. Miss the window (or arrive more than 15 minutes late) and the fee is forfeited.
  • Breaks: two breaks of up to 10 minutes each, with proctor permission.
  • Results: a preliminary pass/fail appears on screen immediately; the official score follows within 10 working days.

If you fail, ISACA allows four attempts within a rolling 12-month period: a 30-day wait after the first attempt, then 90 days after the second and third. Each retake costs the full registration fee, which is a strong argument for not booking until practice results say you are ready.

How much does CRISC cost?

The headline exam fee is only part of the picture. As of 2026 (fees are set in US dollars; confirm current figures on ISACA's site before booking):

Cost itemAmount (USD)
Exam fee — ISACA member$575
Exam fee — non-member$760
Application processing fee (after passing)$50
Eligibility extension (optional, once)$75
Annual maintenance feesee note below
Study materials (review manual, question database, courses)varies

Two budgeting notes. First, the $185 member discount on the exam typically makes ISACA membership worth pricing up before you register — check current dues on isaca.org and do the arithmetic for your chapter. Second, ISACA verifies its annual maintenance fee figures per certification; the association publishes US$45 member / US$85 non-member on its CISA maintenance page and applies the same CPE structure across its credentials, but confirm the CRISC-specific figure on the official CRISC maintenance page before budgeting.

Whether the total outlay pays back is a separate question with its own trade-offs — weighed properly in Is CRISC worth it?, while the earnings side of the equation lives in our CRISC salary guide.

How to get CRISC certified, step by step

  1. Confirm the credential fits your direction. If your ambitions lean towards security leadership rather than risk, compare the tracks in CRISC vs CISM before spending anything.
  2. Decide on membership. Price ISACA membership against the $185 exam discount and any study-material discounts.
  3. Register with ISACA and pay. Your six-month eligibility clock starts here — do not register before you intend to study.
  4. Study the 2021 exam content outline. The CRISC Review Manual (8th edition) and ISACA's official question database are the aligned materials; weight your plan towards Domain 3's 32%.
  5. Benchmark with timed practice. A full-length, four-hour simulation tells you whether your pacing and domain coverage hold up before you commit to a date. ExamPractice offers free sample CRISC practice questions, with fuller question sets and a timed simulation mode for subscribers — use results to find weak domains, not to memorise answers.
  6. Book your slot at a PSI centre or for remote proctoring, at least 48 hours ahead.
  7. Sit the exam and read your preliminary result on screen.
  8. Apply for certification once you have the three years of experience — within five years of passing — and pay the $50 application fee.
  9. Maintain the credential with continuing professional education (CPE): a minimum of 20 CPE hours reported annually and at least 120 hours over each three-year cycle, plus the annual maintenance fee.

The study methodology itself — resources, timelines, domain tactics — is a topic of its own, covered in how to prepare for CRISC.

Who should pursue CRISC — and who should look elsewhere?

A realistic picture helps here. Consider three profiles:

The second-line risk analyst. Two years into a GRC role at a bank, maintaining the IT risk register and chasing control owners for attestations. CRISC is close to purpose-built for this person: the domains mirror the day job, the three-year experience mark is within reach, and the credential signals readiness for risk-manager openings. Passing now and applying at the three-year mark is a sensible sequence.

The security engineer eyeing management. Hands-on with vulnerability management and keen to move up. CRISC would formalise the risk vocabulary, but if the target role is running a security programme rather than a risk function, CISM is usually the better-aligned ISACA credential — see the CISM certification guide for that track.

The complete newcomer. No IT or risk experience yet. Nothing stops this person sitting the exam, but with no waivers available the certification itself sits at least three years away, and the exam's scenario style rewards judgement built on real exposure. An entry-level security or audit foundation first is normally the smarter order.

CRISC also lives in a wider ecosystem: ISACA's own portfolio is mapped in ISACA certifications explained, and adjacent risk credentials exist outside it — such as PECB's ISO 31000 Risk Manager for framework-based enterprise risk roles.

Frequently asked questions

Can I take the CRISC exam with no experience?

Yes. There are no prerequisites to sit the exam. You only need the three years of IT risk and IS control experience when you apply for certification, and you have five years from passing to do so.

Does CRISC expire?

The certification continues as long as you maintain it: at least 20 CPE hours a year, 120 over each three-year cycle, and the annual maintenance fee. Lapse on either and the credential can be revoked.

What is the CRISC pass rate?

ISACA does not publish pass rates for any of its exams, so any percentage you see online is unofficial. Judge your own readiness with timed practice scores instead.

Can I take CRISC online?

Yes — ISACA delivers the exam through PSI either at physical testing centres or via online remote proctoring, year-round.

Is CRISC harder than CISM?

They are difficult in different ways — CRISC leans on risk-scenario judgement, CISM on management judgement — and neither has an official pass rate to compare. The difficulty question gets a full treatment in our dedicated article below.

Is CRISC your next credential?

If your work already involves risk registers, control design or reporting risk to management — or you want it to — CRISC is the most directly aligned certification ISACA offers, with a lower experience bar than CISA or CISM and a genuinely portable, vendor-neutral scope. The strict no-waiver policy means career-changers should plan the experience path before the exam path. Verify current fees and policies on ISACA's official CRISC page, since these change, then decide your sequence: study, pass, and let the five-year application window absorb any experience gap.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like