CISA (Certified Information Systems Auditor)
ISACA
Complete guide to passing the CISA (Certified Information Systems Auditor) exam on your first attempt.
$575-$760
~50%
3 years (40 CPE/year)
Global
ISACA
$110k-$165k
Are you ready for CISA (Certified Information Systems Auditor)?
Loading quiz...
Complete Overview
CISA, the Certified Information Systems Auditor, is ISACA's certification for professionals who audit, monitor, and assess an organization's information systems and IT controls. It is taken by IT auditors, internal and external audit staff, compliance and assurance professionals, and security staff who work alongside audit functions, and ISACA charges US$575 for members and US$760 for non-members to register for the exam.
The exam is 150 multiple-choice questions in 240 minutes. Every question has a stem and four options with one best answer, and some appear as scenarios where several questions draw on the same described situation. Scores are reported on a scaled range of 200 to 800, and 450 passes. ISACA includes unscored pretest items in every form, does not disclose which items those are, and reports domain-level results for information only, since the score is based on total items answered correctly regardless of domain. There is no penalty for a wrong answer, so leaving anything blank costs you outright.
The current exam content outline took effect in August 2024 and covers five domains: Information Systems Auditing Process at 18 percent, Governance and Management of IT at 18 percent, Information Systems Acquisition, Development and Implementation at 12 percent, Information Systems Operations and Business Resilience at 26 percent, and Protection of Information Assets at 26 percent. The two largest domains cover operations, resilience, and security controls, which is where candidates from a pure financial audit background usually need the most work.
Passing the exam and becoming certified are separate steps. To hold the CISA designation you must also pay a one-time US$50 application processing fee, demonstrate five or more years of professional information systems auditing, control, assurance, or security work experience gained within the ten years before you apply, agree to ISACA's Code of Professional Ethics and Continuing Professional Education policy, and comply with the Information Systems Auditing Standards. ISACA allows experience waivers for a maximum of three of those five years. You have five years from your passing date to submit the application.
Exams are delivered at authorized PSI testing centres worldwide or as remotely proctored sessions. Registration is continuous with no fixed exam windows, you can schedule as early as 48 hours after payment, and your eligibility lasts six months from registration. If six months is not enough, ISACA sells one six-month extension for US$75. The exam is available in English, Spanish, Chinese Simplified, French, German, Korean, and Japanese.
Once certified, you keep the credential by earning a minimum of 20 CPE hours each year and 120 hours across a three-year reporting period, and by paying an annual maintenance fee of US$45 for ISACA members or US$85 for non-members, due each 1 January. CISA is accredited by ANSI under ISO/IEC 17024, and ISACA states that more than 200,000 people have earned it since the program began in 1978.
Why Get CISA (Certified Information Systems Auditor) Certified?
CISA is the credential most commonly named in IT audit job descriptions, and ISACA reports that more than 200,000 people have earned it since 1978 with more than 151,000 currently holding it.
The salary band associated with CISA holders runs $110k to $165k. ISACA's own CISA page cites an average annual salary above US$149,000 for holders.
The certification is accredited by ANSI under ISO/IEC 17024, which is what allows regulated employers and government agencies to accept it as evidence of competence rather than as a training certificate.
The 2024 content outline added audit data analytics including audit algorithms, plus evaluation of automation and decision-making systems, so the credential covers the analytics shift that has changed how audit fieldwork is actually performed.
You can sit the exam before meeting the five-year experience requirement and then apply for certification any time within five years of passing, which lets you clear the hardest step while the material is fresh and accumulate experience afterwards.
CPE hours earned for CISA can also count towards other ISACA certifications where the activity is relevant, so stacking CISA with CISM or CRISC does not multiply your annual continuing education burden.
Once you hold more than two ISACA certifications the annual maintenance fee for the third and subsequent ones drops to US$25 for members and US$50 for non-members, which makes CISA a cheap anchor for a multi-credential portfolio.
Exam Format & Structure
Duration
4 hours (240 minutes)
Questions
150 questions
Passing Score
450 on a scaled range of 200 to 800
Question Types
- Multiple-choice with one best answer, each item having a stem and four options
- Scenario-based sets where a described situation supports two or more linked questions
- Unscored pretest items mixed in and not identified to the candidate
Delivery Method
Computer-based at an authorized PSI testing centre or as a remotely proctored online exam. Registration is continuous and appointments can be scheduled as early as 48 hours after payment.
Exam Domains & Topics
Covers how an audit is planned and executed: the standards and codes of ethics that govern it, the types of audits and reviews available, risk-based planning, and the execution mechanics of project management, testing, sampling, evidence collection, analytics, and reporting. Also covers quality assurance of the audit process itself.
Key Topics to Master:
- IS audit standards, guidelines, functions, and codes of ethics
- Types of audits, assessments, and reviews and when each applies
- Risk-based audit planning and scope determination
- Types of controls: preventive, detective, corrective, and compensating
- Audit project management and resource allocation
- Audit testing and statistical versus non-statistical sampling methodology
- Audit evidence collection techniques and evidence sufficiency
- Audit data analytics including audit algorithms
- Reporting, communication techniques, and quality assurance of the audit process
Splits into IT governance and IT management. Governance covers the laws, standards, structures, policies, and enterprise architecture that set direction, plus enterprise risk management, privacy programmes, and data governance. Management covers how resources, vendors, performance, and quality are actually run day to day.
Key Topics to Master:
- Laws, regulations, and industry standards affecting IT
- Organizational structure, IT governance frameworks, and IT strategy alignment
- IT policies, standards, procedures, and practices
- Enterprise architecture and architectural considerations
- Enterprise risk management programmes
- Privacy programme and privacy principles
- Data governance and data classification
- IT resource management and IT vendor management
- IT performance monitoring, reporting, and quality management
The smallest domain. Covers the controls an auditor evaluates while a system is being bought or built and while it is being put into production: project governance, business case and feasibility, development methodologies, control design, readiness testing, release management, migration, and post-implementation review.
Key Topics to Master:
- Project governance and project management for system delivery
- Business case development and feasibility analysis
- System development methodologies including waterfall and agile approaches
- Control identification and control design during development
- System readiness and implementation testing
- Implementation configuration and release management
- System migration, infrastructure deployment, and data conversion
- Post-implementation review and benefits realization
One of the two heaviest domains. Covers the running estate, from IT components and asset management through job scheduling, interfaces, shadow IT, capacity, incident and problem management, change and patch management, log management, service levels, and databases. The resilience half covers business impact analysis, backup and restoration, business continuity, and disaster recovery.
Key Topics to Master:
- IT components and IT asset life cycle management
- Job scheduling and production process automation
- System interfaces and integration controls
- Shadow IT and end-user computing risk
- Systems availability and capacity management
- Problem and incident management
- IT change, configuration, and patch management
- Operational log management, IT service level management, and database management
- Business impact analysis, data backup and restoration, business continuity and disaster recovery plans
The other heaviest domain, and the one that has grown as cybersecurity has spread into every information systems role. Covers the security control set an auditor evaluates, from frameworks and physical controls through identity, network and endpoint security, data loss prevention, encryption, PKI, cloud, mobile, and IoT, plus the security event management side.
Key Topics to Master:
- Information asset security policies, frameworks, standards, and guidelines
- Physical and environmental controls
- Identity and access management
- Network and endpoint security
- Data loss prevention and data encryption
- Public key infrastructure
- Cloud, virtualized, mobile, wireless, and internet-of-things environments
- Security awareness training, attack methods and techniques
- Security testing and monitoring tools, incident response management, evidence collection and forensics
Recommended Study Plan
- 1Read the CISA Exam Content Outline on isaca.org and record the five domain weights where you will see them daily
- 2Take the free ten-question CISA practice quiz on ISACA's site to calibrate the question style before buying anything
- 3Register for the exam so your six-month eligibility clock starts against a real deadline rather than an intention
- 4Buy the CISA Review Manual, 28th Edition and the CISA Questions, Answers and Explanations database, which carries a 1,070-question pool on a six-month subscription
- 5Confirm your ISACA account name matches your government-issued ID exactly, because a mismatch on exam day forfeits the fee
- 1Work through the planning half of Domain 1 in the Review Manual: standards, guidelines, codes of ethics, and audit types
- 2Learn the ITAF structure and how ISACA's standards differ from guidelines in obligation
- 3Build a one-page table of control types with a worked example of each: preventive, detective, corrective, compensating
- 4Practise risk-based audit planning by scoping a hypothetical audit of a payroll system
- 5Answer 60 QAE questions restricted to Domain 1 and log every wrong answer with the reason
- 1Study audit project management, testing, and the difference between statistical and non-statistical sampling
- 2Learn the evidence hierarchy and which evidence types an auditor treats as most reliable
- 3Cover audit data analytics including audit algorithms, which the 2024 outline added
- 4Practise writing an audit finding with condition, criteria, cause, effect, and recommendation
- 5Answer 60 more Domain 1 questions and confirm your accuracy has moved
- 1Study organizational structure, IT strategy alignment, and how governance differs from management in ISACA's framing
- 2Map COBIT governance and management objectives against the Domain 2 subtopics
- 3Cover enterprise risk management, risk appetite, and how an auditor evaluates an ERM programme
- 4Study privacy programme principles and data governance and classification
- 5Answer 60 QAE questions on Domain 2 governance subtopics
- 1Cover IT resource management, vendor management, and contract controls
- 2Study IT performance monitoring, KPIs, KRIs, and the reporting an auditor tests
- 3Learn quality assurance and quality management of IT as ISACA defines them
- 4Draft the evaluation steps you would perform for a third-party vendor assurance review
- 5Take a mixed Domain 1 and 2 quiz of 75 questions under time pressure
- 1Study project governance, business case, and feasibility analysis as audit subjects rather than as project management theory
- 2Compare waterfall, iterative, and agile development and the control implications of each
- 3Learn control identification and design during development, and where an auditor should be involved
- 4Cover readiness testing, release management, migration, data conversion, and post-implementation review
- 5Answer 50 Domain 3 questions, remembering this domain is only 12 percent so time here has a lower return
- 1Work through IT components, asset management, job scheduling, and system interfaces
- 2Study shadow IT and end-user computing risk and what compensating controls look like
- 3Cover problem and incident management and how they differ in ITIL terms
- 4Study change, configuration, release, and patch management, which generate a high share of questions
- 5Answer 75 Domain 4 questions on the operations subtopics
- 1Learn business impact analysis and be able to calculate and distinguish RTO, RPO, MTD, and MTO
- 2Study backup strategies, offsite storage, and restoration testing
- 3Compare business continuity plans against disaster recovery plans and know which questions target which
- 4Study recovery site options from hot to cold and the cost and recovery time trade-offs
- 5Answer 50 resilience questions and check that the recovery objective definitions are automatic
- 1Study security frameworks, physical and environmental controls, and identity and access management
- 2Cover network and endpoint security controls from an auditor's evaluation perspective, not an engineer's
- 3Learn data loss prevention, encryption, and public key infrastructure to the depth of what an auditor tests
- 4Study cloud, virtualization, mobile, wireless, and IoT control considerations
- 5Answer 75 questions on the Domain 5 security and control subtopics
- 1Study security awareness training programmes and how their effectiveness is measured
- 2Cover attack methods and techniques at the level of recognition and control mapping
- 3Study security testing and monitoring tools and what audit evidence each produces
- 4Cover incident response management, evidence collection, and forensics handling
- 5Take a full 150-question timed practice exam and record domain-level performance
- 1Rework the two weakest domains from your practice exam using the Review Manual rather than question banks
- 2Drill the qualifier words ISACA uses: BEST, MOST, FIRST, and GREATEST change the correct answer
- 3Practise the ISACA answer hierarchy where governance and risk answers usually beat technical fixes
- 4Answer 150 mixed questions and read the explanation for every item, including the ones you got right
- 5Join an ISACA Engage CISA study group if you are a member and post the questions you keep missing
- 1Sit two full 150-question 240-minute exams on separate days with no breaks, matching real conditions
- 2Pace-check against 96 seconds per question and practise flagging rather than stalling
- 3Reread the exam content outline in full and confirm you can define every subtopic in one sentence
- 4Run the PSI compatibility check if testing remotely, and prepare a mirror or phone for the mandatory mirror check
- 5Plan to arrive at least 30 minutes early if testing at a centre, since arriving more than 15 minutes late forfeits the fee
Ready to pass CISA (Certified Information Systems Auditor)?
Get 500+ practice questions, video walkthroughs, and a pass guarantee.
Best Study Resources
CISA Exam Content Outline
Official blueprintISACA's authoritative list of the five domains, their weights, every subtopic, and the 43 supporting tasks. The 2024 outline is the one currently examined. Read the supporting tasks list, because it tells you the verbs ISACA expects.
Free
CISA Review Manual, 28th Edition
Official textbookISACA's own reference covering all five domains and the role of the IS auditor. This is the source the exam is written against, and its phrasing matches how questions are worded.
Paid, print or digital, member discount available
CISA Questions, Answers and Explanations database
Official question bankA 1,070-question pool with a personalized dashboard, custom study plans, and progress tracking. The explanations matter more than the scores, because they teach ISACA's answer logic.
Paid, six-month subscription
CISA Online Review Course
Official self-paced courseISACA's on-demand course covering all five CISA domains across more than 40 modules with video, text, and interactive elements. Useful if you learn better from structured instruction than from the manual.
Paid
Free CISA practice quiz
Official sample questionsTen free questions on ISACA's site testing IT auditing, control, and information security. Worth taking before you buy anything, purely to see how ISACA phrases a question and how often the best answer is not the technical one.
Free
ISACA Engage CISA study groups
Community forumA member-only global study forum where candidates work practice questions and get answers from certified professionals. Useful for the specific ISACA reasoning that trips up candidates with an engineering background.
Free to ISACA members
ITAF: Information Technology Assurance Framework
Official standards documentThe standards, guidelines, and tools framework CISA holders agree to comply with. Domain 1 tests the distinction between mandatory standards and advisory guidelines directly.
Free download from ISACA
COBIT 2019
Governance frameworkISACA's governance framework, which underpins much of the Domain 2 governance and management content. You are not examined on COBIT component names line by line, but the governance versus management split maps directly onto the domain structure.
Some publications free to members
ISACA interactive glossary
ReferenceISACA's own definitions for terms used in exam questions. Where a commercial study guide and ISACA disagree on a definition, the glossary is the version that gets examined.
Free
CISA All-in-One Exam Guide (McGraw Hill)
Third-party bookPeter Gregory's independent guide, widely used as a second pass over the material with different phrasing from the Review Manual. Useful when an ISACA explanation is not landing.
Around $60 print
Common Mistakes to Avoid
Answering as a practitioner instead of an auditor. Candidates from engineering and security backgrounds pick the answer that fixes the technical problem, when CISA questions usually want the auditor action: assess, evaluate, review, report, or recommend.
Before choosing, ask what an independent auditor is permitted to do. Auditors do not implement controls or remediate findings. If an option has you configuring something, it is almost certainly wrong.
Missing the qualifier. ISACA writes stems with BEST, MOST, FIRST, and GREATEST, and several options will be defensible. Reading past the qualifier turns a question you know into a coin flip.
Read the last line of the stem twice and note the qualifier before looking at the options. On FIRST questions, sequence matters: risk assessment usually precedes control selection, and scoping precedes fieldwork.
Treating the 12 percent Domain 3 as equal in effort to the 26 percent Domain 4 and Domain 5. Roughly 78 items on a 150-question form come from operations, resilience, and protection of information assets combined.
Allocate study hours in proportion to the published weights. Domains 4 and 5 together are 52 percent of the exam, which justifies more than half your preparation time before you look at anything else.
Leaving questions blank or dwelling on one item. There is no penalty for a wrong answer, and 240 minutes across 150 questions leaves 96 seconds each with no slack for a five-minute standoff.
Answer everything, even a guess. Flag and move on at the two-minute mark, then use the remaining time on flagged items. ISACA scores only the total number of items answered correctly.
Assuming a pass makes you certified. Passing the exam is one of six requirements, and the certification does not exist until you pay the US$50 application fee and get five years of experience verified by a supervisor or manager.
Line up your experience verification before you sit the exam. Confirm which supervisors will sign, and check that the work falls within the ten-year window before the application date. You have five years from passing to apply, but chasing signatures from former employers gets harder every year.
Letting the six-month exam eligibility lapse. Eligibility starts at registration, not at scheduling, and ISACA forfeits both the eligibility and the registration fee if you do not sit within the window.
Schedule a date as soon as you register even if you plan to move it. Rescheduling is free more than 48 hours out. If you genuinely need longer, buy the one available six-month extension for US$75 before eligibility expires, and cancel any scheduled appointment at least 48 hours ahead first.
Learning recovery objectives loosely. Domain 4 questions distinguish RTO, RPO, MTD, and service delivery objectives precisely, and a vague grasp turns several straightforward items into guesses.
Write the definitions and then work numeric scenarios. Given a four-hour RTO and a one-hour RPO, be able to say exactly what backup frequency and recovery site type the organization needs, and what the auditor should test.
Preparing entirely from a question bank. High scores on repeated QAE questions reflect memory of those items rather than command of the domain, and the real exam rephrases everything.
Use the Review Manual as the primary source and the QAE database as diagnostic. Read the explanation for every question, including ones you answered correctly, because the reasoning is what transfers.
Arriving without the right identification. ISACA requires a single current, valid, original government-issued ID showing name, signature, and photograph, with the name matching your registration exactly. Digital IDs and photocopies are rejected.
Check your ISACA profile name against your passport or licence weeks in advance and update it in MyISACA if it differs. Being turned away counts as a no-show, forfeits the fee, and means paying full price again.
Exam Day Tips
- 1
Bring one current, valid, original government-issued ID that shows your name, your signature, and your photograph, and make sure the first and last name match your ISACA registration exactly. Photocopies, handwritten documents, and digital IDs are not accepted.
- 2
At a PSI testing centre, plan to arrive at least 30 minutes early. Arriving more than 15 minutes late for the appointment means you forfeit the registration fee entirely.
- 3
No calculator is permitted. Neither are reference materials, notes, paper, language dictionaries, or multiple monitors, so every recovery objective calculation and sampling estimate has to be done in your head.
- 4
No food or drink is allowed, and ISACA specifies that this includes water, at test centres and in remotely proctored sessions alike. Hydrate before check-in and expect four hours without a drink at your desk.
- 5
You may take two breaks of no more than ten minutes each with proctor permission. The exam pauses, but the timer does not stop, so a full break costs you real minutes against the 240.
- 6
If you test remotely, expect a 360 degree room scan, a desk scan including under your laptop or keyboard, a floor to ceiling scan, and a mirror check that shows the screen, keyboard, and all four edges of your monitor. Have a portable mirror or a phone ready, and remove the phone from the room afterwards.
- 7
Remote proctor communication is in English only through a live chat tool, regardless of which of the seven exam languages you selected for the questions.
- 8
Pace at roughly 96 seconds per question. Answer every item because there is no penalty for wrong answers, and flag anything that is taking more than two minutes.
- 9
Do not photograph or screenshot any part of the exam, including the preliminary results screen. ISACA operates a zero-tolerance policy on fraudulent test-taking and can nullify scores or revoke certifications.
- 10
If something goes wrong with the administration itself, such as site conditions or a technical fault, report it to ISACA support within 48 hours of finishing. Complaints filed later cannot be reviewed before scores are released.
Career Paths & Salary Ranges
IT auditor
Plans and executes audits of applications, infrastructure, and IT processes, gathers evidence, and writes findings. The role the exam is built around, and the one the five-year experience requirement is written to describe.
Lower to middle of the $110k-$165k CISA band
IT audit manager
Owns the audit plan, allocates staff across engagements, reviews workpapers, and presents results to audit committees. Domain 1 audit project management and Domain 2 governance content map directly onto the role.
Middle to upper part of the $110k-$165k CISA band
IT compliance manager
Runs the control framework against regulatory obligations such as SOX, PCI DSS, or sector-specific rules, coordinates evidence collection, and manages external auditor relationships. Draws on Domain 2 legal and regulatory content and Domain 5 control evaluation.
Middle of the $110k-$165k CISA band
Internal control or SOX analyst
Tests IT general controls over change management, access, and operations on a recurring cycle. Domain 4 change, configuration, and access control content covers most of the daily work.
Lower part of the $110k-$165k CISA band
IT risk and assurance consultant
Delivers assurance and advisory engagements for external clients, often at an audit or consulting firm, where CISA is frequently a promotion requirement rather than a preference.
Upper part of the $110k-$165k CISA band
Head of internal audit or audit director
Sets audit strategy, reports to the audit committee, and owns the relationship with regulators and external auditors. CISA plus CRISC or CISM is the common credential combination at this level.
Top of the $110k-$165k CISA band and above
Prerequisites & Requirements
- There are no prerequisites to sit the exam. ISACA states the CISA exam is open to anyone with an interest in information security, and you can take it before meeting the experience requirement.
- To become certified you need five or more years of professional information systems auditing, control, assurance, or security work experience as described in the CISA job practice areas.
- That experience must have been gained within the ten-year period preceding your certification application date.
- ISACA allows experience waivers for a maximum of three of the five years. The accepted substitutions are listed on the CISA application form.
- You must pay a one-time US$50 application processing fee and submit the application within five years of your passing date.
- You must agree to ISACA's Code of Professional Ethics, the Continuing Professional Education policy, and the Information Systems Auditing Standards.
Frequently Asked Questions
How much does the CISA exam cost?
ISACA charges US$575 to register if you are an ISACA member and US$760 if you are not, and the fee is based on your membership status at the time you register. Fees are nonrefundable and nontransferable. Separately, becoming certified requires a one-time US$50 application processing fee after you pass. If your six-month eligibility runs out you can buy one six-month extension for US$75. Because ISACA membership brings the exam fee down by US$185 and also discounts study materials and CPE, joining before registering usually costs less overall than registering as a non-member.
What happens if I fail the CISA exam?
You may attempt the exam up to four times within a rolling 12-month period, and you pay the full registration fee for every attempt. After failing the first attempt you must wait 30 days from the date of that attempt before the second. After the second attempt you must wait 90 days before the third, and another 90 days before the fourth. Your official score report includes domain-level results, which ISACA provides for information only, but those are still the best guide to where to concentrate before the next attempt.
How is the CISA exam scored?
ISACA converts your raw score to a scaled score on a common range of 200 to 800, and 450 or higher passes. A score of 800 means every question was answered correctly and 200 is the lowest possible. Scaling exists so that different versions of the exam are comparable, which means 450 is not a fixed percentage of items correct. Each form includes unscored pretest items that do not count towards your result, and ISACA does not identify them. Domain percentages describe how much of the exam covers each domain and are not used to calculate your score.
How long does it take to get CISA results?
Your preliminary pass or fail status appears on screen immediately after you finish. The official score is emailed and made available online within 10 working days, on the MyISACA Certifications and CPE Management page. ISACA does not give scores over the telephone or by fax and does not provide question-level results. If you did not pass and believe the score is wrong, you can request a rescore in writing through ISACA support within 30 days of results being released, with a US$75 fee per request. Rescores are performed by PSI.
What identification do I need on exam day?
One current, valid, original government-issued ID that shows your name, your signature, and your photograph. All three elements must appear on a single document. The first and last name must match the name you used to register. Acceptable forms include a driver's licence, a state or national ID card, a passport, a passport card, a green card, an alien registration document, or a permanent resident card. Copies, handwritten documents, and digital IDs are refused. Driver's licences issued in Japan without a signature are the one stated exception. If you cannot present acceptable ID you are turned away, the sitting counts as a no-show, and the fee is forfeited.
Can I use a calculator or reference materials during the CISA exam?
No. ISACA prohibits calculators outright, along with reference materials, study materials, paper, notes, notepads, and language dictionaries. Also prohibited are multiple monitors, phones, tablets, smart watches, smart glasses, headphones, baggage, weapons, tobacco or vaping products, and any food or beverage including water. Your workspace must be completely clear, and you must face the screen throughout so proctors can monitor the session.
Can I take breaks during the four-hour exam?
Yes, two breaks of no more than ten minutes each, and only with your proctor's permission. The exam pauses during an approved break, but the timer does not stop, so any break comes out of your 240 minutes. You must check out and check back in to use the facilities, and no extra time is granted. Leaving the testing area without authorization can result in your exam being terminated and can mean you are not allowed back into the testing room.
How does remote proctoring work for CISA?
ISACA delivers remotely proctored exams through PSI. Run the device compatibility check before exam day, and get IT approval first if you are using a company machine, since the secure browser has to be installed. Check-in requires a 360 degree scan of all four walls, a desk scan including under your laptop or keyboard, and a floor to ceiling scan of your test space. ISACA also requires a mirror check on every exam, where you hold a portable mirror or a phone up to the webcam to show the screen, keyboard, and all four edges of the monitor. If you use a phone for that, it must be removed from the testing room afterwards. Proctor communication is by live chat in English only.
Are special accommodations available for the CISA exam?
Yes. You must flag the special accommodation requirement field during exam registration, then complete ISACA's Special Accommodation Request Form together with your health care professional and submit it through ISACA support. Requests are not considered until registration fees are paid in full, must be submitted no later than four weeks before your preferred exam date, and are valid for that one exam administration only. A subsequent attempt requires a fresh request.
What are the CISA experience requirements and can they be waived?
Certification requires five or more years of professional information systems auditing, control, assurance, or security work experience as described in the CISA job practice areas, gained within the ten-year period before your application date. Your experience must be verified by a supervisor or manager. ISACA allows experience waivers for a maximum of three of those five years, and the accepted substitutions are set out on the CISA application form. You can sit and pass the exam before meeting the requirement, and you then have five years from your passing date to apply.
How do I maintain CISA once I am certified?
You report a minimum of 20 CPE hours each year and a minimum of 120 CPE hours across a three-year reporting period, and you pay the annual maintenance fee of US$45 for ISACA members or US$85 for non-members, due each 1 January. You must also comply with the annual CPE audit if selected, adhere to the Code of Professional Ethics, and abide by ISACA's IT auditing standards. If you hold more than two ISACA certifications, the maintenance fee for the third and any subsequent certification drops to US$25 for members and US$50 for non-members. CPE hours can count towards more than one ISACA certification where the activity is relevant to each.
What happens if I miss the CPE requirement?
ISACA revokes the CISA designation for non-compliance with the CPE policy, and revoked holders may no longer present themselves as certified. You can appeal for reinstatement in writing to the CISA Working Group with a detailed explanation and the CPE documentation covering the period from revocation to the current year. If the appeal is approved you pay any outstanding maintenance fees plus a US$50 reinstatement fee per certification. If it is not approved, returning to active status means retaking and repassing the exam and reapplying with the appropriate experience. Keep CPE documentation for 12 months after the end of each three-year cycle in case you are selected for audit.
How long is my exam eligibility valid after I register?
Six months from the date you register, and the registration fee must be paid in full before you can schedule. You can book an appointment as early as 48 hours after payment, though appointments are only released 90 days in advance. You forfeit both the eligibility and the fee if you do not sit within the window, miss the appointment, or arrive more than 15 minutes late. One six-month extension is available for US$75, and the option appears on your dashboard from 30 days before to 30 days after expiry. If an exam is already scheduled it must be cancelled at least 48 hours ahead before you can extend.
Can I reschedule my CISA exam?
Yes, without penalty, at any point during your eligibility period as long as you do it at least 48 hours before the scheduled appointment. Inside 48 hours you must sit the exam or forfeit the fee. If you miss an appointment because of a documented personal hardship such as illness, the death of an immediate family member, or a traffic accident, contact PSI within 72 hours of the appointment with supporting documentation. A doctor's note must be signed by a licensed doctor, include the visit date and the doctor's contact information, and indicate that you should not sit the exam. If a hardship request is denied you must register and pay in full again.
How does CISA compare with CRISC?
Both are ISACA certifications with the same exam mechanics: 150 questions, 240 minutes, a scaled score of 200 to 800 with 450 passing, the same US$575 member and US$760 non-member fee, the same US$50 application fee, and the same 20 CPE per year and 120 per three years maintenance. The difference is subject and entry bar. CISA covers the audit process and IT control evaluation across five domains and requires five years of experience with waivers available for up to three. CRISC covers IT risk identification, assessment, response, and monitoring across four domains and requires three years of experience with no waivers or substitutions at all. Auditors typically take CISA first; risk and control practitioners often go straight to CRISC.
How does CISA compare with CISM?
CISA is for people who assess and audit information systems; CISM is for people who manage an information security programme. The exam mechanics are identical at 150 questions in 240 minutes with 450 passing on a 200 to 800 scale, and the fees are the same. CISM requires five years of information security management experience with waivers available for a maximum of two years, against CISA's five years of audit, control, assurance, or security experience with waivers up to three. Many professionals hold both, and because CPE hours can be applied to multiple ISACA certifications where relevant, the ongoing burden of the second one is mostly the reduced maintenance fee.
Does ISACA publish a CISA pass rate?
No. ISACA does not publish pass rates for CISA or for its other certification exams, and it does not release question-level results to candidates either. Any pass rate figure you see quoted comes from third-party estimates or from surveys of candidates, not from ISACA. What ISACA does publish is the passing standard itself: a scaled score of 450 out of 200 to 800, which it describes as representing the minimum standard of knowledge, applied consistently across every version of the exam.
In which languages is the CISA exam available?
Seven: English, Spanish, Chinese Simplified, French, German, Korean, and Japanese. That is the widest language coverage of any ISACA certification exam. You choose your preferred language when scheduling, and changing it afterwards requires rescheduling the appointment, which must be done at least 48 hours before the booked time. ISACA also publishes translated CISA terminology lists in Chinese Simplified, French, German, Japanese, Korean, and Spanish, which is worth using if you are testing in a second language, since exam wording turns on precise terms.
Pass CISA (Certified Information Systems Auditor), Guaranteed
94% pass rate on first attempt
One-time • Lifetime access