Exampractice
Cybersecurity

How Long Does CISA Preparation Take?

Realistic CISA preparation timelines by background and weekly study hours — from 8 weeks for experienced auditors to 6 months for career changers.

Alexander Novak · 6 min read
Timeline showing three different CISA preparation durations depending on candidate background

Most candidates preparing for ISACA's Certified Information Systems Auditor (CISA) exam spend somewhere between two and four months studying part-time — that range appears consistently across prep literature, and ISACA itself publishes no official study-hours figure. The honest answer, though, depends far more on what you already do for a living than on any universal number. An IT auditor with three years on the job is revising vocabulary they use daily; a network engineer is learning an auditor's way of thinking from scratch, and that difference can double the timeline.

Short answer: plan for roughly 2–4 months of part-time study. Experienced IS auditors can be ready in 6–8 weeks; IT professionals without audit exposure typically need 3–4 months; career changers from outside IT should budget 4–6 months. Adjust up or down based on your weekly study capacity.

One practical constraint shapes everything: as of 2026, ISACA gives you a six-month eligibility period from the date you register, and you can schedule your exam as soon as 48 hours after payment. A single US$75 extension is available if you run out of road, but only once. Your preparation window therefore needs to fit inside six months from registration — which is one reason many candidates study first and register once they are perhaps eight weeks out.

What actually determines your CISA preparation time

Three variables matter more than anything else: your professional background, your weekly study availability, and how familiar you are with multiple-choice exams that test judgement rather than recall.

The exam itself is 150 multiple-choice questions in four hours, covering five domains. The two heaviest — Information Systems Operations and Business Resilience, and Protection of Information Assets — carry 26% each under the 2024 exam content outline, so how quickly those topics come to you disproportionately affects your total prep time. (What each domain actually covers is a separate question — see the breakdown in CISA Exam Domains Explained.)

Note also that CISA's difficulty is scaled, not percentage-based: you need 450 on a 200–800 scale, and ISACA publishes no percent-correct equivalent. That means you cannot shortcut planning by aiming for "just enough" — your practice results, not a percentage target, tell you when you are ready. How hard the exam actually is deserves its own discussion, which we cover in How Hard Is the CISA Exam?.

Timelines by professional background

Experienced IS auditors: 6–10 weeks

If you have been performing information systems audits for two or more years, most of Domain 1 (Information Systems Auditing Process) and much of Domain 2 (Governance and Management of IT) will read as a formalised description of your job. Your study time goes into ISACA's specific terminology, the domains you touch less often — typically systems acquisition and development — and calibrating to how ISACA frames "best" answers.

A realistic scenario: an internal auditor with three years of IT audit fieldwork, studying 8–10 hours a week, is commonly exam-ready in about eight weeks. The bottleneck is rarely knowledge; it is learning to pick ISACA's preferred answer when two options both look defensible.

IT professionals without audit experience: 3–4 months

Systems administrators, security analysts, network engineers and developers usually know the technology in Domains 4 and 5 well but have never thought like an auditor. The audit process, evidence, sampling, control objectives and governance frameworks in Domains 1 and 2 are genuinely new material, and they anchor how ISACA words nearly every question.

At 8–10 hours a week, budget 12–16 weeks. The temptation for this group is to skim the technical domains and race through; resist it, because CISA questions test the auditor's perspective on that technology, not the practitioner's.

Finance and non-IT audit professionals: 3–5 months

Financial auditors and compliance professionals have the opposite gap: the audit mindset is second nature, but the technology in Domains 3, 4 and 5 — resilience, operations, information asset protection — needs building from foundations. At a similar weekly commitment, 14–20 weeks is a sensible range, weighted heavily towards the technical domains.

Career changers new to both IT and audit: 4–6 months

Coming from outside both disciplines, you are learning two vocabularies at once. That is entirely feasible — there are no prerequisites to sit the exam, and experience is only required later, when you apply for certification (you get five years after passing to do so) — but compressing it below four months at part-time pace tends to produce shallow coverage. Six months at 8–10 hours a week is a defensible plan; a structured schedule helps most here, and the CISA Study Plan for Beginners provides one.

How weekly hours change the calendar

The same preparation stretches or compresses depending on your week. As a rough planning grid for an IT professional without audit experience:

  • 5 hours/week — around 5–6 months. Workable, but long enough that early material fades; build in revision.
  • 8–10 hours/week — around 3–4 months. The most common and most sustainable cadence for people in full-time jobs. If this is you, the CISA study schedule for working professionals maps it week by week.
  • 15+ hours/week — around 8–10 weeks. Feasible between jobs or with employer study leave; fatigue becomes the risk.

Experienced auditors can shift each of those bands down a notch; career changers should shift them up.

Is a 3-month CISA study plan feasible?

For most candidates, yes — three months at 8–10 hours a week is the mainstream path, and it is why the 2–4 month guidance recurs in prep literature. It becomes risky in two situations: when you are new to both IT and audit, or when your real weekly availability is closer to three hours than eight. Be honest about the second one; a three-month calendar with 4 hours a week is really a six-month plan wearing a shorter label.

It also helps that ISACA no longer runs fixed exam windows. Registration is continuous, exams are delivered year-round at PSI test centres or via remote proctoring, and appointments can be booked up to 90 days ahead. You can therefore let your readiness set the date rather than the reverse — schedule when your practice results say you are close, not when a calendar deadline forces your hand.

How to tell you are ready rather than just "out of time"

Because the pass mark is a scaled 450/800 with no published percentage equivalent, the most reliable readiness signal is performance on full-length, timed practice. Working through 150 questions in a four-hour sitting tells you two things a textbook cannot: whether your accuracy holds across all five domains, and whether your pacing survives hour three. Analyse results by domain, and treat a persistent weak domain as a reason to extend your timeline by a couple of weeks rather than hoping it averages out. ExamPractice offers free sample CISA practice questions, with fuller question sets and a timed simulation mode for subscribers — useful for exactly this benchmarking step. How to sequence and score those tests is its own craft, covered in CISA Practice Test Strategy.

One planning footnote: if the exam does not go your way, ISACA's retake rules impose a 30-day wait after a first attempt (and 90 days after the second and third), with the full fee each time — so a timeline with two or three spare weeks of buffer before any hard deadline is worth building in from the start.

Setting your own timeline

Work backwards from your profile: pick the background band above that matches you, multiply by your honest weekly hours, then add two weeks of buffer for a final review-and-practice phase. Register once you are six to eight weeks out so the six-month eligibility clock works for you rather than against you. And remember the timeline question is only about whenhow to fill those weeks with the right resources and tactics belongs to the CISA Exam Preparation Guide.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like