Certified Information Systems Auditor (CISA)
CISA certifies the information systems auditor: assessing whether controls exist, work, and can be evidenced to somebody who will not take your word for it.
Four hours, 150 questions, and an experience requirement separate from the exam.
Exam facts
- Exam code
- CISA
- Level
- Expert
- Field
- Cybersecurity
- Duration
- 240 minutes
- Questions
- 150 multiple-choice questions
- Passing score
- 450 on a scaled range of 200 to 800
- Languages
- English, German, Chinese, French, Hebrew, Italian, Japanese, Korean, Spanish, TurkishLanguage list per ISACA's candidate guide as mirrored by its chapters; ISACA schedules some translations only in certain testing windows — confirm the language when you register.
- Price
- 760 USD (read 12 September 2026)
- Validity
- 3 years, renewable
- Exam delivery
- PSI (test centre or online proctored) in exam windows; registration on isaca.org, the certificate follows an application with an experience record
Prerequisites: Five years of professional IS audit, control or security work for the certificate (waivers of up to three years for degrees and related experience); the exam itself can be taken first, with five years to apply afterwards.
Renewal: 120 CPE hours per three-year cycle with at least 20 a year, plus the annual maintenance fee of 45 USD (members) or 85 USD (non-members)
Source: exam page at ISACA · Price: Non-member exam fee; ISACA members pay 575 USD (isaca.org, read 2026-09-12); plus 50 USD application fee after passing and 45/85 USD annual maintenance
How to prepare
1. The vendor's free learning path
ISACA publishes the exam objectives and a learning path free of charge — the authoritative source for scope and weighting. Open the learning path (opens in a new tab)
2. Online courses
Courses and practice questions from the directory that target exactly this exam — details, price and the provider link (affiliate) are on the course page.
3. A practice test in the exam format
MeasureUp sells a practice test for CISA with questions in the exam format, an explanation for every answer and a timed mode; the price shows in your currency on the shop page. Affiliate link.
Practice test for CISA at MeasureUp (opens in a new tab)Book the exam
Delivered by PSI (test centre or online proctored) in exam windows; registration on isaca.org, the certificate follows an application with an experience record. Schedule with ISACA (opens in a new tab)
Affiliate disclosure: the course and practice-test links above are affiliate links — buying through them may earn us a commission at no extra cost to you. The vendor's learning path and booking links carry no commission.
Readers mistake this for a technical certificate
| Question a role asks | Whose certificate |
|---|---|
| Is this system configured securely? | A technical security certificate |
| Can we prove the control operated all year? | CISA |
| Who is accountable, and to what standard? | CISM |
| How do we detect and respond? | An analyst certificate |
The table is the whole argument. An auditor is not paid to make a system secure and is not paid to say whether it is. An auditor is paid to say whether the organisation can demonstrate, to somebody outside the room, that a control existed, operated throughout the period, and left evidence behind. That stance runs through all 150 questions, and it is why engineers with years of hands-on security sometimes score below compliance officers who have never opened a firewall console. The engineer knows what a good configuration looks like. The exam wants to know whether the configuration change was approved, logged, reviewed and reconciled, and whether the reviewer was somebody other than the person who made it.
Five domains, weighted toward operations and protection
ISACA's outline splits the syllabus into five domains: the audit process itself, governance and management of IT, the acquisition and development of systems, operations and business resilience, and the protection of information assets. The last two carry the largest share at roughly a quarter each, and they are where candidates from a pure audit background lose the most marks, because they demand a working grasp of backups, incident handling, access control and encryption at the level of knowing what evidence each one should produce. The first three domains reward audit reasoning and can be learned from the outline and a good question set. The last two reward having sat next to the people who run systems.
- Four hours for 150 questions works out at a little over a minute and a half each, which is comfortable until a scenario runs to a paragraph and every option sounds defensible.
- Scores are scaled from 200 to 800 and 450 passes. The scale means a raw percentage tells you nothing; treat practice scores as directional only.
- PSI centres or remote proctoring, and remote sitting changes nothing about the paper. It does change how you handle scratch notes, so read the rules before the day.
- Ten exam languages, and some translations appear only in certain windows. If you want to sit in German or Japanese, check availability before you plan the date.
The exam is the middle of the process, not the end
Certification requires five years of professional audit, control or security work, with waivers of up to three years for degrees and related experience, and it can be claimed up to five years after passing. Passing first and applying later is common and sensible for anyone a year or two short. Once certified, upkeep is a minimum of 20 continuing-education hours every year and 120 across each three-year reporting cycle, plus an annual maintenance fee, discounted for members. None of that is onerous for somebody working in the field, and all of it is invisible in a comparison that stops at the sitting fee.
Passing the exam is not the whole process
There is an application separate from the exam, with its own processing fee, and the certification requires five years of relevant professional experience with some substitutions available. You have several years after passing in which to apply, which helps candidates who sit it early, and it also means a pass on its own is not a credential. Budget for the application as well as the sitting.
What a question looks like
Written by us in the exam's style. It is not a real question from any question bank, and we do not publish those.
During an audit you find that a required approval step is being performed consistently and correctly, but the system records only the final outcome and not who approved it. Management points to the consistent results. How should this be reported?
The control is working and the evidence does not exist, and those are different findings. Technical candidates see a process functioning correctly and conclude there is nothing to report. The auditor's answer is that an unevidenced control cannot be relied upon, the distinction on which this whole certificate rests, and it feels pedantic right up until your signature is on the opinion.
What it costs to get and to keep
| Item | Amount | Note |
|---|---|---|
| Exam fee, non-member | 760 USD | ISACA's published non-member price (read 12 September 2026) |
| Exam fee, member | 575 USD | membership costs money of its own, so work out whether the saving across exam, renewal and maintenance covers it before joining (read 12 September 2026) |
| Application processing fee | 50 USD | separate from the exam and required before the certification is issued (read 12 September 2026) |
| Annual maintenance, member | 45 USD | payable each year the certification is held; non-members pay a higher annual figure (read 12 September 2026) |
| Continuing education | not published | at least 20 hours a year and at least 120 across a three-year reporting period, which is a sustained commitment rather than a burst (read 12 September 2026) |
How much preparation, from where you are
- You audit systems already
- The exam is your working vocabulary formalised. The gaps are usually the technical domains, particularly operations and resilience, where auditors rely on specialists.
- You are technical and moving toward assurance
- The content will feel familiar and the perspective will not. Practise answering as somebody who must evidence a conclusion to a regulator rather than as somebody who can simply check the system.
- You work in risk or compliance without IT depth
- The realistic candidate ISACA describes. The audit reasoning is yours; budget the time for the technical domains, which is where non-IT candidates lose most of their marks.
What passing this does not prove
- Whether you can configure or secure anything yourself.
- Whether an organisation will act on the finding you raised.
- The negotiation that turns a draft finding into an agreed one.
- Current attack techniques, which are not what an auditor is for.
Against the alternatives
- CISM — Certified Information Security Manager (CISM)
- The management counterpart from the same body, with the same fee structure and upkeep. Audit assesses; management owns. People hold both, and rarely for the same job.
- CISSP — Certified Information Systems Security Professional (CISSP)
- Broader, more technical and better known outside audit circles. If your career is heading toward security leadership rather than assurance, that is the more portable credential.
- SY0-701 — CompTIA Security+
- The technical grounding this assumes you already have. Worth holding first if your background is compliance rather than IT.
CISA — quick answers
Is membership worth it?
Do the arithmetic rather than assuming. Members pay less for the exam and less for annual maintenance, and membership costs money every year. Across a first cycle it often pays for itself; across a career it depends on how long you hold the certification and whether you use anything else the body provides.
Do I need five years of audit experience?
For the certification, yes, with some substitutions available. You may sit the exam before meeting it and apply later, within a window of several years after passing, which is why plenty of candidates sit it early and file the application once the experience arrives.
Is it useful outside audit?
In regulated industries, considerably. Anyone who has to demonstrate compliance rather than merely achieve it benefits from thinking in evidence, and that habit transfers into risk, governance and vendor management. It will not make you better at securing a system, which is a different certificate and a different job.
Which domain should a technical candidate study hardest?
The audit process domain, and it is the smallest. Engineers arrive knowing how systems work and not knowing how an audit is planned, sampled, evidenced and reported, so the questions that feel most alien are the ones about the auditor's own method. The protection and operations domains will feel like home; do not let that comfort set the study plan.
Can I sit it remotely?
Yes, ISACA offers remote proctoring alongside PSI test centres, and the paper is identical. What changes is the environment: a four-hour exam at home with a camera on you and rules about your desk is a different experience from a centre, and candidates who have never done a proctored remote sitting should rehearse the setup rather than meet it on the day.
What comes next
Concepts this exam draws on
Glossary entries with the reason each one matters for CISA.
- Uptime & SLA
Operations and business resilience: service levels, continuity and recovery are a quarter of the exam.
- Security Risk Assessment
Audit planning is risk-based, and the exam asks how an auditor decides where to look.
- Change Control
Whether changes to systems were authorised, tested and evidenced is a recurring audit question.
- IAM
Access provisioning, review and removal are the controls an IS auditor tests most often.
- Least Privilege
Excessive access is among the commonest audit findings, and the exam expects you to recognise it.
- Incident Response
The operations and resilience domain covers whether an organisation can detect, respond and evidence that it did.
Last reviewed 12 September 2026 · Getting Digital
