Skip to content
Getting Digital
All certifications

ISACA certifications

ISACA sits at the governance end of the security profession, and its two exams on this site are misread more often than anything else here. Neither is a technical certificate. CISA certifies auditors, CISM certifies managers, both at expert tier, both valid for three years, and both written for people who already have a working history behind them.

Exam delivery: PSI (test centre or online proctored) in exam windows; registration on isaca.org, the certificate follows an application with an experience record

People come looking for a harder version of a security certificate and find something with a different purpose. CISA is an audit qualification. It asks whether you can plan an engagement, collect evidence, decide whether a control actually operates, and write the finding up so it survives review. CISM is a management qualification. It asks how a security programme gets governed, funded, measured and reported, and how an incident is handled from the seat that briefs the board rather than the seat that pulls the cable. Deep configuration knowledge earns you very little in either exam. There is a second trap: passing does not make you certified. ISACA issues the credential only against a documented record of relevant professional practice, verified on application, with partial waivers available for degrees and adjacent work. You may sit either exam before that record exists, and a pass stays convertible for a fixed number of years, but until the application clears you hold a result rather than a credential.

Most people who ask about CISA should not book it yet

  • Early in your career, wait. One or two years in, treat ISACA's published domain outline as a map of what your job ought to be teaching you, and chase the rotations that fill the gaps. Sitting early buys a result you cannot yet convert, and the conversion window, while generous, is not open indefinitely.
  • Changing into security from outside it: start elsewhere. Security+ covers the vocabulary an ISACA exam assumes you already own, and CySA+ takes you into analysis work that later counts towards the experience record. Come back to CISA once the record exists.
  • Engineers who want technical depth are in the wrong queue. That is CISSP territory, which spreads wider and considerably deeper across technical ground. Plenty of senior people eventually hold both, and the usual order is technical first, ISACA second.
  • Auditors and assurance staff without a deep IT background are the natural fit for CISA, which is the unusual case here: the audit discipline transfers, the systems knowledge gets built from the domain outline, and the certificate names the specialisation your team already practises.
  • Aspiring security managers should check the calendar before committing to CISM. ISACA has announced a revised content outline taking effect on 3 November 2026, so preparation finishing before then matches the material on the market, and anything later should wait for updated study guides rather than drilling an outline the exam has moved past.
  • What a CISA signals that a technical certificate cannot. A hiring manager reading a platform or security badge learns that you can operate systems competently. Reading CISA, they learn you can be put in a room with a regulator, an external auditor or an anxious board and produce evidence that holds up under challenge. It speaks to judgement, independence and documentation, which is why audit teams ask for it by name and why it outlives whichever technology stack you happen to know.

The cost that arrives after the certificate

Both credentials run on a three-year cycle, and that cycle is where ISACA's long-term price sits. You owe continuing-education credits across the three years, with a minimum to be met annually rather than crammed at the end, logged by you against the categories ISACA accepts. Separately, a maintenance fee falls due every year, owed in a year when you learned nothing at all, and charged at a lower rate to members. Plan for the full cycle rather than the first sitting; the current figures, each with the date it was read, sit on the CISA and CISM pages.

Expert

Choosing within ISACA

Each verdict is written from the first exam's page; the reverse view, where one exists, is written from the other's.

CISA against CISM
The management counterpart from the same body, with the same fee structure and upkeep. Audit assesses; management owns. People hold both, and rarely for the same job.
CISM against CISA
The audit counterpart from the same body, identically priced and maintained. Assess against decide: people hold both and use them in different rooms.

Frequently asked

Can I sit a CISA or CISM exam before I qualify for the certificate?
Yes. Registration is open to anyone, and many candidates pass well before their experience record is complete. The application is a separate step with its own evidence requirements, and the credential only exists once ISACA has approved it.
Which comes first if I want both?
Usually CISA, because audit and assurance work tends to come earlier in a career than running a security programme. CISM then builds on ground you have already covered from the other side of the table. Both are maintained on the same three-year renewal model, so holding two means one combined obligation rather than two separate routines.
Do these certificates expire if I stop paying?
Effectively yes. The three-year validity assumes both halves of the bargain are kept: the credits logged and the maintenance fee paid. Miss either and the credential stops being current, which is why it belongs in a budget as a standing commitment rather than a single purchase.

Official certification portal: www.isaca.org/credentialing

Other vendors

Last reviewed 12 September 2026 · Getting Digital