CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingEvery ISACA certification mapped — CISA, CISM, CRISC, CGEIT, CDPSE and the new AI credentials — with who each serves, costs, formats and experience rules.

ISACA is a professional association for people who work in IT audit, information security, IT risk, IT governance and data privacy — the disciplines it collectively calls digital trust. Its certification portfolio, as of 2026, contains five core credentials — CISA (audit), CISM (security management), CRISC (risk), CGEIT (governance) and CDPSE (privacy engineering) — plus two newer AI-focused add-on credentials, AAIA and AAISM, and one retired credential, CSX-P, that existing holders can still maintain. This article is the neutral map: what each credential means, who it serves, what it costs and requires, and how the pieces relate. It deliberately doesn't crown a best one — rankings by career value for security roles live in a separate guide to the best ISACA certifications for cybersecurity — and it doesn't go deep on any single exam, because each has its own dedicated guide linked below.
Two framing points make the rest of the map easier to read. First, ISACA credentials are management- and practice-level, not tool-level: they certify judgement in a discipline (auditing systems, running a security programme, governing IT) rather than skill with a product. Second, they are experience-gated in an unusual way — anyone may sit any exam, but the certification itself is only awarded once you can evidence several years of relevant work, which shapes who each credential realistically serves.
Before the individual credentials, it's worth learning the machinery once, because ISACA runs its five core certifications on a common chassis (all figures as of 2026 — confirm current details on isaca.org):
With the chassis understood, each credential below is mostly a question of discipline: which slice of digital trust it certifies and for whom.
Discipline: IT audit and assurance. CISA is ISACA's oldest and most widely held flagship — ISACA reports over 151,000 holders — and it certifies the ability to audit, control and assure information systems: planning audits, evaluating IT governance, and assessing how systems are built, operated and protected. Its current exam reflects the 2024 job practice, effective 1 August 2024, spread over five domains: Information Systems Auditing Process (18%), Governance and Management of IT (18%), Information Systems Acquisition, Development and Implementation (12%), Information Systems Operations and Business Resilience (26%), and Protection of Information Assets (26%).
Certification requires five years of professional experience in IS/IT audit, control, assurance or security, gained within the ten years before applying, with waivers and substitutions available for up to three of those years. ISACA's own page cites a "US$149K+ average annual salary" for holders (ISACA's figure, as of August 2026; pay varies widely by country, role and seniority).
Who it's for: internal and external IT auditors, assurance professionals, and control-minded people in compliance or security who want the audit profession's standard credential. The full picture — eligibility, application, process — is in the CISA certification guide.
Discipline: information security management. CISM certifies the running of a security function rather than hands-on defence: governing the programme, managing information risk, building and operating the security programme, and managing incidents. The current outline weights four domains — Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%) and Incident Management (30%) — though note that ISACA has announced an updated CISM exam content outline effective 3 November 2026; candidates testing before then sit the current outline, and the new weights should be checked on isaca.org once published.
Certification requires five or more years of experience in information security management, with waivers available for up to two years. A common misreading worth correcting: CISM is not "the level above CISA" — audit and security management are parallel disciplines, not rungs of one ladder.
Who it's for: security team leads, security managers and aspiring CISOs — people accountable for security rather than only skilled at it. Details live in the CISM certification guide.
Discipline: IT risk management. CRISC (Certified in Risk and Information Systems Control) certifies the enterprise risk craft: identifying and assessing IT risk, choosing and implementing responses and controls, and monitoring and reporting risk to the business. Its 2021 outline spans four domains — Governance (26%), Risk Assessment (22%), Risk Response and Reporting (32%), and Technology and Security (20%).
Its experience bar is the portfolio's most distinctive: only three years — the lowest of the core five — but in IT risk management and IS control, and with no waivers or substitutions whatsoever.
Who it's for: risk analysts, GRC professionals, control specialists and consultants building a risk-management career. The one-sentence version of the perennial follow-up: choosing between CRISC and CISM is a choice between the risk track and the security-management track, unpacked properly in CRISC vs CISM. The credential itself is covered in the CRISC certification guide.
Discipline: enterprise IT governance. CGEIT sits furthest from the keyboard of the five. It certifies the ability to align IT with enterprise strategy at board and executive level: its 2020 outline covers Governance of Enterprise IT (40%), IT Resources (15%), Benefits Realization (26%) and Risk Optimization (19%). Where CISA asks "were the controls effective?" and CRISC asks "what could hurt us?", CGEIT asks "is the enterprise getting the value it should from IT, and who is accountable for that?"
Certification requires five or more years of experience in an advisory or oversight role supporting the governance of IT's contribution to the enterprise, with no waivers or substitutions. That framing is the honest filter: CGEIT presumes you already operate near the top of the IT decision-making structure.
Who it's for: CIOs and their deputies, IT directors, senior governance advisers and consultants who work on how enterprises direct and control IT — not a first certification for practitioners.
Discipline: privacy engineering. CDPSE is ISACA's technical privacy credential, certifying the ability to build privacy into systems and data lifecycles rather than merely document it. It's also the structural outlier of the core five: 120 questions in 3.5 hours (English only, per the current candidate guide), across four domains — Privacy Governance (20%), Privacy Risk Management & Compliance (18%), Data Lifecycle Management (23%) and Privacy Engineering (39%). Older descriptions of CDPSE as a three-domain exam are out of date; use the current four-domain outline.
Certification requires three or more years of experience across privacy governance, privacy risk and compliance, privacy engineering or data lifecycle work, with no waivers. ISACA reports 16,000+ holders and cites a "US$150K+ average annual salary" (again, ISACA's own figure as of August 2026, with the usual location-and-role caveats).
Who it's for: privacy engineers, architects and technically minded privacy officers — the people who translate regulation into system design.
In 2025 ISACA extended the portfolio with two advanced AI credentials. They behave differently from the core five in one crucial way: you cannot start with them, because each requires an existing qualifying certification. Both are also cheaper — US$459 for members and US$599 for non-members, plus the standard US$50 application fee — with the same six-month eligibility window.
Launched in May 2025 as an audit-specific AI certification, AAIA stacks on an existing credential: all CISA holders qualify, as do holders of certain audit and accountancy credentials (CIA, US CPA, ACCA/FCCA and several national equivalents) with an IT audit or advisory focus, following an eligibility expansion in July 2025. The exam is 90 multiple-choice questions in 2.5 hours across three domains: AI Governance and Risk (33%), AI Operations (46%), and AI Auditing Tools and Techniques (21%). It answers a demand signal ISACA itself has measured — in its May 2025 announcement, ISACA reported that 85% of digital trust professionals say they'll need to increase their AI skills within two years.
Who it's for: certified auditors whose engagements now include AI systems and who want that competence evidenced.
AAISM is the security-management counterpart, positioned by ISACA as the first AI security management certification. Its prerequisite is strict and short: candidates must hold an active CISM or CISSP. ISACA's page lists three domains — AI Governance and Program Management, AI Risk Management, and AI Technologies and Controls — and delivery follows the usual PSI test-centre or remote-proctored model; check ISACA's AAISM candidate guide for the current exam format and weights before preparing, as ISACA's main page doesn't publish full details.
Who it's for: security leaders already credentialed at CISM/CISSP level who are being handed accountability for AI risk and security.
The CSX Cybersecurity Practitioner (CSX-P), ISACA's hands-on performance-based cybersecurity certification, is retired: ISACA states the certification "is retired, but maintenance is available for existing holders." No new candidates can pursue it, and ISACA has named no successor. If you hold it, you can keep it alive through the standard CPE route; if you were considering it, you'll need to look elsewhere in (or beyond) the portfolio for hands-on cyber skills validation.
| Credential | Discipline | Exam (as of 2026) | Experience to certify | Waivers |
|---|---|---|---|---|
| CISA | IT audit and assurance | 150 Qs / 4 hrs | 5 years | Up to 3 years |
| CISM | Information security management | 150 Qs / 4 hrs (outline changes 3 Nov 2026) | 5 years | Up to 2 years |
| CRISC | IT risk management | 150 Qs / 4 hrs | 3 years | None |
| CGEIT | Enterprise IT governance | 150 Qs / 4 hrs | 5 years (advisory/oversight) | None |
| CDPSE | Privacy engineering | 120 Qs / 3.5 hrs | 3 years | None |
| AAIA | AI audit (add-on) | 90 Qs / 2.5 hrs | Active CISA or listed audit/accountancy credential | — |
| AAISM | AI security management (add-on) | See ISACA candidate guide | Active CISM or CISSP | — |
| CSX-P | Hands-on cybersecurity | Retired — maintenance only | — | — |
All core-five exams pass at 450 on the 200–800 scale; fees are US$575/US$760 for the core five and US$459/US$599 for the AI credentials, each plus US$50 on application.
Three relationships organise the portfolio better than any ranking:
Historically, Information Systems Audit and Control Association — but the organisation now goes by ISACA alone, reflecting a remit that has broadened well beyond audit into security, risk, governance and privacy.
Yes. Every ISACA exam is open to anyone; the experience requirements gate the certification, not the test. Pass first and you have five years to accumulate the required experience and apply — a route students and career-changers use deliberately.
No. Membership's practical relevance is financial: members pay US$185 less per exam and receive discounts on official study materials, which for most candidates is worth pricing against the current membership dues on isaca.org before registering.
They occupy a different altitude: ISACA certifies discipline-level professional judgement with experience requirements, where much of the wider certification market certifies technical knowledge or tool skills. Cross-provider comparisons deserve their own treatment; within this library, each ISACA exam's dedicated guide notes its nearest external neighbours where relevant.
Working a handful of practice questions is an underrated way to choose a certification, not just prepare for one — the question style tells you what the discipline actually values. ExamPractice's ISACA exams hub hosts free sample questions for CISA, CISM and CRISC, with fuller sets and timed practice-test simulation available to subscribers.
A neutral map still has a use: locate yourself on it. Ask which question you most want to be paid to answer — were the controls effective? (CISA), is the security programme sound? (CISM), what could hurt us and what should we do? (CRISC), is IT delivering enterprise value? (CGEIT), or is personal data engineered responsibly? (CDPSE) — and follow that credential's dedicated guide for the depth this overview deliberately withholds. If your interest is specifically which ISACA credentials repay security professionals best, that ranking is made — with recommendations this article won't — in best ISACA certifications for cybersecurity. And whichever station on the map you choose, verify the live details — fees, outlines, dates — on isaca.org, because portfolios move and this map is dated 2026.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading