CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingA clear-eyed look at what CRISC really costs in money and time, what it returns for IT risk and GRC professionals, and who should skip it.

Short answer: Certified in Risk and Information Systems Control (CRISC) is worth it if you already work in — or are actively moving into — IT risk, governance, risk and compliance (GRC), or IS control roles, and you can meet ISACA's three-year experience requirement. The all-in first-year cost typically lands between roughly US$800 and US$1,000 before study materials, and the credential's value is concentrated in one place: it is the recognised, dedicated IT risk certification from ISACA, the body whose frameworks much of the GRC world already runs on. If your work only brushes against risk, or you cannot evidence the experience, that money and study time are better pointed elsewhere.
The rest of this article earns that verdict: the full cost in money and time, what you actually receive, the counter-arguments, and a straight list of who should and should not pursue it.
The sticker price is only part of the bill. As of 2026, here is the realistic ledger (fees are in US dollars and can change — confirm current figures on ISACA's CRISC page before budgeting):
| Cost item | Amount (as of 2026) | Notes |
|---|---|---|
| Exam registration | $575 member / $760 non-member | Non-refundable, non-transferable |
| Application processing fee | $50 | One-time, paid after passing |
| ISACA membership (optional) | Varies | Members save $185 on the exam — check current dues on isaca.org to see whether joining nets out cheaper |
| Study materials | Varies | ISACA's CRISC Review Manual (8th edition) and question databases, or third-party resources |
| Annual maintenance fee | Modest annual fee | ISACA charges certification maintenance annually; confirm the current CRISC amount on isaca.org |
| Retake, if needed | Full exam fee again | Up to 4 attempts in a rolling 12 months; 30-day wait after the first attempt, 90 days after the second and third |
Two cost details deserve emphasis because they change the risk profile of the purchase:
There is no official study-hours figure, and anyone quoting one as a guarantee is guessing. What is fixed: the exam itself is 150 multiple-choice questions in 4 hours, scored on a 200–800 scale with 450 needed to pass, covering four domains — Governance (26%), Risk Assessment (22%), Risk Response and Reporting (32%), and Technology and Security (20%). For experienced risk practitioners, much of the material formalises what you already do; for those newer to the field, the time investment grows accordingly. How demanding the exam feels, and to whom, is its own question — see how hard is the CRISC exam.
You can sit the CRISC exam with no experience at all, but the certificate itself requires three or more years of experience in IT risk management and IS control — with no waivers or substitutions. This is stricter than its ISACA siblings: CISA allows up to three years of waivers and CISM up to two, but CRISC allows none. You have five years after passing to apply, so passing early and certifying later is a legitimate path — but if you are more than a couple of years away from qualifying experience, factor in that the letters stay out of reach until the experience exists.
Stripped of marketing, CRISC buys you four things.
1. The recognised specialist credential for IT risk. ISACA sits at the centre of the audit, governance and risk profession, and CRISC is its dedicated risk-and-controls certification. In GRC hiring, where screening is often done by keyword and framework familiarity, holding the field's flagship risk credential is a legible signal in a way that a strong CV paragraph is not.
2. A vetted, current body of knowledge. The 2021 exam content outline is the current version as of 2026, and the domain structure maps closely onto real risk work: governance context, assessing risk, responding and reporting on it, and the technology and security substrate underneath. Studying it forces breadth — the governance and reporting material in particular tends to stretch technically-rooted candidates in useful directions.
3. Verified experience, not just a passed exam. Because ISACA certifies the combination of exam plus three years of evidenced practice, CRISC communicates something an exam-only credential cannot: that a third party checked you have actually done the work.
4. A maintenance structure that keeps it current. Continuing professional education requirements (ISACA's standard structure is a minimum of 20 CPE hours a year and 120 across each three-year cycle — confirm the CRISC-specific terms on isaca.org) mean the credential decays if you leave the field, which is precisely why employers trust that an active CRISC is a practising risk professional.
What CRISC opens up in terms of specific roles and progression is a bigger topic than this verdict piece — the CRISC career path maps the ladder in detail — and for pay evidence by role and region, see the CRISC salary guide rather than trusting any single headline number.
A fair verdict needs the counter-arguments at full strength.
Rather than a universal verdict, run your own situation through these four questions.
Worth it for:
Skip it (or defer it) if:
CRISC clears the cost-benefit bar for one clearly defined group: practitioners genuinely working in IT risk and controls who can satisfy the experience requirement. For them, roughly $800–$1,000 plus focused study time buys the field's standard credential, a disciplined pass through a current body of knowledge, and a durable market signal — with the caveat that it must be maintained to stay alive. For everyone else, the honest answer is not "no" but "not this one, or not yet": pick the credential that matches the work you actually do, and come back to CRISC when the risk experience is real.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading