Exampractice
Cybersecurity

ISACA Certifications Explained

Every ISACA certification mapped — CISA, CISM, CRISC, CGEIT, CDPSE and the new AI credentials — with who each serves, costs, formats and experience rules.

Alexander Novak · 11 min read
Metro-style map showing ISACA certifications as stations on audit, security, risk, governance and privacy lines

ISACA is a professional association for people who work in IT audit, information security, IT risk, IT governance and data privacy — the disciplines it collectively calls digital trust. Its certification portfolio, as of 2026, contains five core credentials — CISA (audit), CISM (security management), CRISC (risk), CGEIT (governance) and CDPSE (privacy engineering) — plus two newer AI-focused add-on credentials, AAIA and AAISM, and one retired credential, CSX-P, that existing holders can still maintain. This article is the neutral map: what each credential means, who it serves, what it costs and requires, and how the pieces relate. It deliberately doesn't crown a best one — rankings by career value for security roles live in a separate guide to the best ISACA certifications for cybersecurity — and it doesn't go deep on any single exam, because each has its own dedicated guide linked below.

Two framing points make the rest of the map easier to read. First, ISACA credentials are management- and practice-level, not tool-level: they certify judgement in a discipline (auditing systems, running a security programme, governing IT) rather than skill with a product. Second, they are experience-gated in an unusual way — anyone may sit any exam, but the certification itself is only awarded once you can evidence several years of relevant work, which shapes who each credential realistically serves.

The machinery every ISACA certification shares

Before the individual credentials, it's worth learning the machinery once, because ISACA runs its five core certifications on a common chassis (all figures as of 2026 — confirm current details on isaca.org):

  • Exam fee: US$575 for ISACA members, US$760 for non-members, set by your membership status at registration. Passing later adds a one-time US$50 application processing fee.
  • Registration and scheduling: continuous, year-round. You get a six-month eligibility window from registration, can book a slot as soon as 48 hours after payment, and sit the exam at a PSI test centre or by online remote proctoring. A single US$75 extension of the window is available; miss the window and the fee is forfeited.
  • Format and scoring (core five): 150 multiple-choice questions in four hours for CISA, CISM, CRISC and CGEIT; CDPSE differs at 120 questions in 3.5 hours. All are scored on a 200–800 scale with 450 to pass — a scaled score, not a percentage, and ISACA publishes no percent-correct equivalent and no pass rates. A preliminary pass/fail appears on screen immediately; official scores follow within ten working days.
  • Retakes: up to four attempts in a rolling twelve-month period — a 30-day wait after the first attempt, 90 days after the second and third — at full fee each time.
  • Experience and the five-year rule: each certification requires evidenced professional experience (detailed per credential below), and you have five years from passing the exam to apply.
  • Maintenance: certifications are maintained through continuing professional education — a minimum of 20 CPE hours a year and 120 across each three-year cycle, per ISACA's published CISA maintenance requirements, which reflect the CPE structure ISACA applies across its certifications — plus an annual maintenance fee (US$45 members / US$85 non-members on the CISA page; confirm per credential on isaca.org).

With the chassis understood, each credential below is mostly a question of discipline: which slice of digital trust it certifies and for whom.

The five core certifications

CISA — Certified Information Systems Auditor

Discipline: IT audit and assurance. CISA is ISACA's oldest and most widely held flagship — ISACA reports over 151,000 holders — and it certifies the ability to audit, control and assure information systems: planning audits, evaluating IT governance, and assessing how systems are built, operated and protected. Its current exam reflects the 2024 job practice, effective 1 August 2024, spread over five domains: Information Systems Auditing Process (18%), Governance and Management of IT (18%), Information Systems Acquisition, Development and Implementation (12%), Information Systems Operations and Business Resilience (26%), and Protection of Information Assets (26%).

Certification requires five years of professional experience in IS/IT audit, control, assurance or security, gained within the ten years before applying, with waivers and substitutions available for up to three of those years. ISACA's own page cites a "US$149K+ average annual salary" for holders (ISACA's figure, as of August 2026; pay varies widely by country, role and seniority).

Who it's for: internal and external IT auditors, assurance professionals, and control-minded people in compliance or security who want the audit profession's standard credential. The full picture — eligibility, application, process — is in the CISA certification guide.

CISM — Certified Information Security Manager

Discipline: information security management. CISM certifies the running of a security function rather than hands-on defence: governing the programme, managing information risk, building and operating the security programme, and managing incidents. The current outline weights four domains — Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%) and Incident Management (30%) — though note that ISACA has announced an updated CISM exam content outline effective 3 November 2026; candidates testing before then sit the current outline, and the new weights should be checked on isaca.org once published.

Certification requires five or more years of experience in information security management, with waivers available for up to two years. A common misreading worth correcting: CISM is not "the level above CISA" — audit and security management are parallel disciplines, not rungs of one ladder.

Who it's for: security team leads, security managers and aspiring CISOs — people accountable for security rather than only skilled at it. Details live in the CISM certification guide.

CRISC — Certified in Risk and Information Systems Control

Discipline: IT risk management. CRISC (Certified in Risk and Information Systems Control) certifies the enterprise risk craft: identifying and assessing IT risk, choosing and implementing responses and controls, and monitoring and reporting risk to the business. Its 2021 outline spans four domains — Governance (26%), Risk Assessment (22%), Risk Response and Reporting (32%), and Technology and Security (20%).

Its experience bar is the portfolio's most distinctive: only three years — the lowest of the core five — but in IT risk management and IS control, and with no waivers or substitutions whatsoever.

Who it's for: risk analysts, GRC professionals, control specialists and consultants building a risk-management career. The one-sentence version of the perennial follow-up: choosing between CRISC and CISM is a choice between the risk track and the security-management track, unpacked properly in CRISC vs CISM. The credential itself is covered in the CRISC certification guide.

CGEIT — Certified in the Governance of Enterprise IT

Discipline: enterprise IT governance. CGEIT sits furthest from the keyboard of the five. It certifies the ability to align IT with enterprise strategy at board and executive level: its 2020 outline covers Governance of Enterprise IT (40%), IT Resources (15%), Benefits Realization (26%) and Risk Optimization (19%). Where CISA asks "were the controls effective?" and CRISC asks "what could hurt us?", CGEIT asks "is the enterprise getting the value it should from IT, and who is accountable for that?"

Certification requires five or more years of experience in an advisory or oversight role supporting the governance of IT's contribution to the enterprise, with no waivers or substitutions. That framing is the honest filter: CGEIT presumes you already operate near the top of the IT decision-making structure.

Who it's for: CIOs and their deputies, IT directors, senior governance advisers and consultants who work on how enterprises direct and control IT — not a first certification for practitioners.

CDPSE — Certified Data Privacy Solutions Engineer

Discipline: privacy engineering. CDPSE is ISACA's technical privacy credential, certifying the ability to build privacy into systems and data lifecycles rather than merely document it. It's also the structural outlier of the core five: 120 questions in 3.5 hours (English only, per the current candidate guide), across four domains — Privacy Governance (20%), Privacy Risk Management & Compliance (18%), Data Lifecycle Management (23%) and Privacy Engineering (39%). Older descriptions of CDPSE as a three-domain exam are out of date; use the current four-domain outline.

Certification requires three or more years of experience across privacy governance, privacy risk and compliance, privacy engineering or data lifecycle work, with no waivers. ISACA reports 16,000+ holders and cites a "US$150K+ average annual salary" (again, ISACA's own figure as of August 2026, with the usual location-and-role caveats).

Who it's for: privacy engineers, architects and technically minded privacy officers — the people who translate regulation into system design.

The AI add-on credentials

In 2025 ISACA extended the portfolio with two advanced AI credentials. They behave differently from the core five in one crucial way: you cannot start with them, because each requires an existing qualifying certification. Both are also cheaper — US$459 for members and US$599 for non-members, plus the standard US$50 application fee — with the same six-month eligibility window.

AAIA — Advanced in AI Audit

Launched in May 2025 as an audit-specific AI certification, AAIA stacks on an existing credential: all CISA holders qualify, as do holders of certain audit and accountancy credentials (CIA, US CPA, ACCA/FCCA and several national equivalents) with an IT audit or advisory focus, following an eligibility expansion in July 2025. The exam is 90 multiple-choice questions in 2.5 hours across three domains: AI Governance and Risk (33%), AI Operations (46%), and AI Auditing Tools and Techniques (21%). It answers a demand signal ISACA itself has measured — in its May 2025 announcement, ISACA reported that 85% of digital trust professionals say they'll need to increase their AI skills within two years.

Who it's for: certified auditors whose engagements now include AI systems and who want that competence evidenced.

AAISM — Advanced in AI Security Management

AAISM is the security-management counterpart, positioned by ISACA as the first AI security management certification. Its prerequisite is strict and short: candidates must hold an active CISM or CISSP. ISACA's page lists three domains — AI Governance and Program Management, AI Risk Management, and AI Technologies and Controls — and delivery follows the usual PSI test-centre or remote-proctored model; check ISACA's AAISM candidate guide for the current exam format and weights before preparing, as ISACA's main page doesn't publish full details.

Who it's for: security leaders already credentialed at CISM/CISSP level who are being handed accountability for AI risk and security.

The retired one: CSX-P

The CSX Cybersecurity Practitioner (CSX-P), ISACA's hands-on performance-based cybersecurity certification, is retired: ISACA states the certification "is retired, but maintenance is available for existing holders." No new candidates can pursue it, and ISACA has named no successor. If you hold it, you can keep it alive through the standard CPE route; if you were considering it, you'll need to look elsewhere in (or beyond) the portfolio for hands-on cyber skills validation.

The portfolio at a glance

CredentialDisciplineExam (as of 2026)Experience to certifyWaivers
CISAIT audit and assurance150 Qs / 4 hrs5 yearsUp to 3 years
CISMInformation security management150 Qs / 4 hrs (outline changes 3 Nov 2026)5 yearsUp to 2 years
CRISCIT risk management150 Qs / 4 hrs3 yearsNone
CGEITEnterprise IT governance150 Qs / 4 hrs5 years (advisory/oversight)None
CDPSEPrivacy engineering120 Qs / 3.5 hrs3 yearsNone
AAIAAI audit (add-on)90 Qs / 2.5 hrsActive CISA or listed audit/accountancy credential
AAISMAI security management (add-on)See ISACA candidate guideActive CISM or CISSP
CSX-PHands-on cybersecurityRetired — maintenance only

All core-five exams pass at 450 on the 200–800 scale; fees are US$575/US$760 for the core five and US$459/US$599 for the AI credentials, each plus US$50 on application.

How the credentials relate to each other

Three relationships organise the portfolio better than any ranking:

  1. The core five are parallel, not sequential. CISA, CISM, CRISC, CGEIT and CDPSE certify five different disciplines at comparable professional altitude. Nothing in ISACA's rules sequences them, and treating one as the prerequisite or "next level" of another misreads the map. People hold several because their careers span disciplines, not because the certs form a ladder.
  2. The AI credentials are vertical extensions. AAIA extends audit (via CISA or equivalent accountancy credentials); AAISM extends security management (via CISM or CISSP). They express seniority within a discipline rather than opening a new one.
  3. The disciplines interlock in practice. Auditors assess the controls that risk professionals designed; risk professionals quantify what security managers must treat; governance professionals decide what the enterprise will fund; privacy engineers build what all of the above demand of personal data. That interlock is why the credentials share vocabulary and why multi-cert holders are common in senior digital-trust roles.

Frequently asked questions

What does ISACA stand for?

Historically, Information Systems Audit and Control Association — but the organisation now goes by ISACA alone, reflecting a remit that has broadened well beyond audit into security, risk, governance and privacy.

Can I take an ISACA exam with no work experience?

Yes. Every ISACA exam is open to anyone; the experience requirements gate the certification, not the test. Pass first and you have five years to accumulate the required experience and apply — a route students and career-changers use deliberately.

Is ISACA membership required for certification?

No. Membership's practical relevance is financial: members pay US$185 less per exam and receive discounts on official study materials, which for most candidates is worth pricing against the current membership dues on isaca.org before registering.

How do ISACA certifications compare with CompTIA or (ISC)² credentials?

They occupy a different altitude: ISACA certifies discipline-level professional judgement with experience requirements, where much of the wider certification market certifies technical knowledge or tool skills. Cross-provider comparisons deserve their own treatment; within this library, each ISACA exam's dedicated guide notes its nearest external neighbours where relevant.

Where can I practise before choosing an exam?

Working a handful of practice questions is an underrated way to choose a certification, not just prepare for one — the question style tells you what the discipline actually values. ExamPractice's ISACA exams hub hosts free sample questions for CISA, CISM and CRISC, with fuller sets and timed practice-test simulation available to subscribers.

Reading the map for your own career

A neutral map still has a use: locate yourself on it. Ask which question you most want to be paid to answer — were the controls effective? (CISA), is the security programme sound? (CISM), what could hurt us and what should we do? (CRISC), is IT delivering enterprise value? (CGEIT), or is personal data engineered responsibly? (CDPSE) — and follow that credential's dedicated guide for the depth this overview deliberately withholds. If your interest is specifically which ISACA credentials repay security professionals best, that ranking is made — with recommendations this article won't — in best ISACA certifications for cybersecurity. And whichever station on the map you choose, verify the live details — fees, outlines, dates — on isaca.org, because portfolios move and this map is dated 2026.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like