CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingWhat CRISC covers, who qualifies, what the exam looks like and what it costs — a complete guide to ISACA's IT risk certification, verified for 2026.

Certified in Risk and Information Systems Control (CRISC) is ISACA's certification for professionals who identify, assess and manage IT risk and design the controls that keep it within appetite. The exam has 150 multiple-choice questions across four domains, costs US$575 for ISACA members or US$760 for non-members, and certification requires three years of relevant experience — with no waivers. This guide covers what the credential actually certifies, the domains, eligibility rules, exam logistics, full cost and the step-by-step route to getting certified.
CRISC (pronounced "see-risk") is awarded by ISACA, the professional association behind CISA, CISM and CGEIT. Where CISA certifies auditors and CISM certifies security managers, CRISC sits in the risk lane: it validates that you can build and run an IT risk management programme — identifying risk, assessing its likelihood and impact, choosing and reporting on responses, and monitoring the information systems controls that treat it.
That makes it the natural credential for people whose job is governance, risk and compliance (GRC) rather than hands-on security engineering. Typical holders work as IT risk managers, risk analysts, control owners, second-line risk officers and consultants who translate technical exposure into business language for boards and regulators.
Two things distinguish CRISC within ISACA's portfolio. First, it is the only one of the association's five core certifications with a three-year experience requirement rather than five. Second, it allows no experience waivers at all — more on both below.
The exam follows ISACA's 2021 exam content outline, which as of August 2026 remains current with no announced changes. The official CRISC Review Manual is in its 8th edition. The four domains, with their official weights from ISACA's certification exam candidate guide, are:
Roughly a quarter of the exam. This domain covers the organisational context risk management operates in: organisational strategy, structure and culture, policies and standards, risk appetite and tolerance, ownership and accountability, and the ethics and professional standards that underpin the role. ISACA's own site phrases this domain as "Corporate IT Governance". The practical thrust is that risk decisions belong to the business — your job is to enable and inform them, not to make them unilaterally.
Identifying and analysing risk: threat and vulnerability analysis, risk scenario development, likelihood and impact assessment, and building and maintaining a risk register. Expect questions that test whether you can distinguish inherent from residual risk and choose the right assessment approach for a given situation.
The heaviest domain. It covers selecting risk responses (accept, mitigate, transfer, avoid), designing and implementing controls, defining ownership of risk and controls, and the reporting layer — key risk indicators (KRIs), key performance indicators (KPIs) and key control indicators (KCIs) that tell management whether treatment is working. Because nearly a third of your score comes from here, it deserves a matching share of study time.
The most technical domain: enterprise architecture, IT operations, project and change management, business continuity and disaster recovery, and information security principles. It exists so risk professionals can hold credible conversations with the technologists whose systems carry the risk. Candidates from non-technical GRC backgrounds often find this the least familiar territory — a point covered properly in how hard the CRISC exam really is.
The eligibility model trips people up because it separates the exam from the certification.
To sit the exam: nothing. There are no prerequisites to register and take the CRISC exam. A student or career-changer can book it tomorrow.
To become certified: three or more years of experience in IT risk management and information systems control. Crucially, CRISC permits no experience waivers or substitutions — unlike CISA (up to three years waivable) or CISM (up to two). A degree or another certification does not shorten the requirement.
The sequencing is flexible: you can pass first and accumulate experience afterwards, because ISACA gives you five years from your passing date to apply for certification. Passing early is therefore a legitimate strategy for someone moving into risk from an adjacent field — the exam result waits while the CV catches up.
Once you apply, ISACA charges a one-time US$50 application processing fee.
As of 2026, the exam runs on the same machinery as ISACA's other core certifications:
If you fail, ISACA allows four attempts within a rolling 12-month period: a 30-day wait after the first attempt, then 90 days after the second and third. Each retake costs the full registration fee, which is a strong argument for not booking until practice results say you are ready.
The headline exam fee is only part of the picture. As of 2026 (fees are set in US dollars; confirm current figures on ISACA's site before booking):
| Cost item | Amount (USD) |
|---|---|
| Exam fee — ISACA member | $575 |
| Exam fee — non-member | $760 |
| Application processing fee (after passing) | $50 |
| Eligibility extension (optional, once) | $75 |
| Annual maintenance fee | see note below |
| Study materials (review manual, question database, courses) | varies |
Two budgeting notes. First, the $185 member discount on the exam typically makes ISACA membership worth pricing up before you register — check current dues on isaca.org and do the arithmetic for your chapter. Second, ISACA verifies its annual maintenance fee figures per certification; the association publishes US$45 member / US$85 non-member on its CISA maintenance page and applies the same CPE structure across its credentials, but confirm the CRISC-specific figure on the official CRISC maintenance page before budgeting.
Whether the total outlay pays back is a separate question with its own trade-offs — weighed properly in Is CRISC worth it?, while the earnings side of the equation lives in our CRISC salary guide.
The study methodology itself — resources, timelines, domain tactics — is a topic of its own, covered in how to prepare for CRISC.
A realistic picture helps here. Consider three profiles:
The second-line risk analyst. Two years into a GRC role at a bank, maintaining the IT risk register and chasing control owners for attestations. CRISC is close to purpose-built for this person: the domains mirror the day job, the three-year experience mark is within reach, and the credential signals readiness for risk-manager openings. Passing now and applying at the three-year mark is a sensible sequence.
The security engineer eyeing management. Hands-on with vulnerability management and keen to move up. CRISC would formalise the risk vocabulary, but if the target role is running a security programme rather than a risk function, CISM is usually the better-aligned ISACA credential — see the CISM certification guide for that track.
The complete newcomer. No IT or risk experience yet. Nothing stops this person sitting the exam, but with no waivers available the certification itself sits at least three years away, and the exam's scenario style rewards judgement built on real exposure. An entry-level security or audit foundation first is normally the smarter order.
CRISC also lives in a wider ecosystem: ISACA's own portfolio is mapped in ISACA certifications explained, and adjacent risk credentials exist outside it — such as PECB's ISO 31000 Risk Manager for framework-based enterprise risk roles.
Can I take the CRISC exam with no experience?
Yes. There are no prerequisites to sit the exam. You only need the three years of IT risk and IS control experience when you apply for certification, and you have five years from passing to do so.
Does CRISC expire?
The certification continues as long as you maintain it: at least 20 CPE hours a year, 120 over each three-year cycle, and the annual maintenance fee. Lapse on either and the credential can be revoked.
What is the CRISC pass rate?
ISACA does not publish pass rates for any of its exams, so any percentage you see online is unofficial. Judge your own readiness with timed practice scores instead.
Can I take CRISC online?
Yes — ISACA delivers the exam through PSI either at physical testing centres or via online remote proctoring, year-round.
Is CRISC harder than CISM?
They are difficult in different ways — CRISC leans on risk-scenario judgement, CISM on management judgement — and neither has an official pass rate to compare. The difficulty question gets a full treatment in our dedicated article below.
If your work already involves risk registers, control design or reporting risk to management — or you want it to — CRISC is the most directly aligned certification ISACA offers, with a lower experience bar than CISA or CISM and a genuinely portable, vendor-neutral scope. The strict no-waiver policy means career-changers should plan the experience path before the exam path. Verify current fees and policies on ISACA's official CRISC page, since these change, then decide your sequence: study, pass, and let the five-year application window absorb any experience gap.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading