CRISC (Certified in Risk and Information Systems Control)
ISACA
Complete guide to passing the CRISC (Certified in Risk and Information Systems Control) exam on your first attempt.
$575-$760
~55%
3 years (40 CPE/year)
Global
ISACA
$120k-$170k
Are you ready for CRISC (Certified in Risk and Information Systems Control)?
Loading quiz...
Complete Overview
CRISC, Certified in Risk and Information Systems Control, is ISACA's certification for professionals who identify, assess, respond to, and report on IT risk, and who design and monitor the controls that treat it. It is taken by IT risk managers, risk analysts, control owners, second-line risk functions, and security managers whose work is measured in risk registers rather than incidents, and ISACA charges US$575 for members and US$760 for non-members to register for the exam.
The exam is 150 multiple-choice questions in 240 minutes. Every item has a stem and four options with one best answer, and some questions come in scenario sets where several items draw on the same described situation. Scores are scaled to a range of 200 to 800 and 450 passes. Each form includes unscored pretest items that ISACA does not identify, domain-level results are reported for information only, and the score depends on the total number of items answered correctly regardless of domain. Wrong answers carry no penalty, so a blank is strictly worse than a guess.
CRISC has four domains. Risk Response and Reporting is the heaviest at 32 percent, followed by Governance at 26 percent, Risk Assessment at 22 percent, and Technology and Security at 20 percent. That distribution matters for planning: more than half the exam sits in Governance and Risk Response and Reporting, which are the two domains furthest from hands-on technical work. Candidates arriving from a security engineering background usually find Domain 4 the easiest and Domain 1 the hardest, and their study time should reflect the opposite.
Becoming certified takes more than passing. You must pay a one-time US$50 application processing fee and demonstrate three or more years of professional work experience across at least two of the four CRISC domains, gained within the ten-year period before your application date and verified by a supervisor or manager. ISACA allows no experience waivers or substitutions for CRISC at all, which distinguishes it from CISA and CISM where waivers exist. You have five years from your passing date to apply, and you may sit the exam before you meet the experience requirement.
Exams run at authorized PSI testing centres worldwide or as remotely proctored sessions. Registration is continuous with no fixed windows, you can schedule as early as 48 hours after payment, and eligibility lasts six months from registration with one six-month extension available for US$75. The exam is offered in English, Spanish, and Japanese.
Maintenance requires a minimum of 20 CPE hours annually and 120 hours across a three-year reporting period, plus an annual maintenance fee of US$45 for ISACA members or US$85 for non-members, due each 1 January. CRISC is accredited by ANSI under ISO/IEC 17024. ISACA states that more than 46,000 people have earned CRISC since the programme began in 2010 and that more than 30,000 currently hold it, making it a smaller population than CISA by a wide margin.
Why Get CRISC (Certified in Risk and Information Systems Control) Certified?
CRISC is one of the few certifications built entirely around IT risk rather than security operations, and its four domains map onto how a second-line risk function is actually organized: governance, assessment, response and reporting, and the technology underneath.
The salary band associated with CRISC holders runs $120k to $170k, above the CISA band. ISACA's own CRISC page cites an average annual salary above US$151,000 and ranks the certification fourth among top-paying certifications worldwide.
The experience bar is three years rather than five, which makes CRISC reachable earlier in a career than CISA or CISM. The trade-off is that ISACA grants no waivers or substitutions for CRISC, so all three years have to be real.
CRISC is accredited by ANSI under ISO/IEC 17024, which is why regulated employers and government agencies accept it as evidence of competence in the same way they accept CISA and CISM.
With around 30,000 current holders against more than 151,000 for CISA, CRISC is a comparatively scarce credential, which matters in hiring for dedicated IT risk roles where the candidate pool is thin.
CPE hours earned for CRISC can also count towards other ISACA certifications where the activity is relevant, and once you hold more than two ISACA certifications the annual maintenance fee for the third and beyond drops to US$25 for members and US$50 for non-members.
The Domain 4 content now includes emerging technologies and AI risk considerations, so the certification covers the risk questions boards started asking about generative AI rather than only classical IT risk.
Exam Format & Structure
Duration
4 hours (240 minutes)
Questions
150 questions
Passing Score
450 on a scaled range of 200 to 800
Question Types
- Multiple-choice with one best answer, each item having a stem and four options
- Scenario-based sets where one described situation supports two or more linked questions
- Unscored pretest items mixed into every form and not identified to the candidate
Delivery Method
Computer-based at an authorized PSI testing centre or as a remotely proctored online exam. Registration is continuous and appointments can be scheduled as early as 48 hours after payment.
Exam Domains & Topics
Splits into organizational governance and risk governance. The first half covers strategy, structure, roles, culture, ethics, policies, business process resilience, and asset management. The second half covers enterprise risk management, the three lines of defence model, the risk profile, risk appetite and tolerance, and the frameworks and legal, regulatory, and contractual requirements the risk programme has to satisfy.
Key Topics to Master:
- Organizational strategy, goals, and objectives and how IT risk connects to them
- Organizational structure, roles, and responsibilities for risk
- Organizational culture and ethics as risk factors
- Policies and standards and the difference in obligation between them
- Business processes and resilience including disaster recovery and business continuity planning
- Organizational asset management
- Enterprise risk management and the three lines of defence
- Risk profile, risk appetite, and risk tolerance
- Risk frameworks and legal, regulatory, and contractual requirements
Covers risk identification and risk analysis. Identification deals with risk events, threat modelling, the threat landscape, vulnerability management, and building and evaluating risk scenarios. Analysis deals with assessment concepts and standards, business impact analysis, the risk register, analysis methodologies, and the distinction between inherent and residual risk.
Key Topics to Master:
- Risk events and how they are captured and classified
- Threat modelling and understanding the current threat landscape
- Vulnerability management as an input to risk assessment
- Risk scenario development and evaluation
- Risk assessment concepts and standards
- Business impact analysis and its outputs
- Risk register structure, ownership, and upkeep
- Qualitative and quantitative risk analysis methodologies
- Inherent risk, residual risk, and current risk
The heaviest domain, covering three linked areas. Risk response covers the response options, risk and control ownership, vendor and supply chain risk, and the management of issues, findings, exceptions, and exemptions. Control design and implementation covers frameworks, control types, selection, analysis, and testing methodologies. Risk monitoring and reporting covers action plans, data aggregation and validation, metrics, monitoring techniques, and reporting formats.
Key Topics to Master:
- Risk response options: accept, mitigate, transfer, and avoid
- Risk ownership and control ownership and why they differ
- Vendor and supply chain risk management
- Issues, findings, exceptions, and exemptions management
- Control frameworks, control types, and control standards
- Control design, selection, implementation, and analysis
- Control testing methodologies and evidence of effectiveness
- Risk action plans and data collection, aggregation, analysis, and validation
- Risk and control metrics including KRIs, KCIs, and KPIs, and reporting through heat maps, scorecards, and dashboards
The technical foundation a risk practitioner needs in order to have credible conversations with engineering. Covers technology principles, roadmaps and enterprise architecture, operations management, the system development life cycle, data life cycle management, portfolio and project management, technology resilience, and emerging technologies. The second half covers information security concepts, frameworks, awareness training, and data privacy and protection principles.
Key Topics to Master:
- Technology principles and enterprise architecture
- Technology roadmaps and their risk implications
- Operations management including change management, assets, DevOps, problems, and incidents
- System development life cycle and where controls are embedded
- Data life cycle management
- Portfolio and project management including agile delivery
- Technology resilience and disaster response and recovery
- Emerging technologies and their risk profile
- Security concepts, frameworks, and standards, security and risk awareness training, and data privacy and protection principles
Recommended Study Plan
- 1Read the CRISC Exam Content Outline on isaca.org and write the four domain weights somewhere you will see them daily
- 2Take the free ten-question CRISC practice quiz on ISACA's site to see how ISACA phrases a risk question
- 3Register for the exam so the six-month eligibility clock gives you a real deadline
- 4Buy the CRISC Review Manual and the CRISC Questions, Answers and Explanations database, which carries an 833-question pool on a six-month subscription
- 5Check that your ISACA account name matches your government-issued ID exactly, because a mismatch at check-in forfeits the fee
- 1Study strategy, goals, and objectives and practise tracing an IT risk up to a business objective it threatens
- 2Learn organizational structures and who owns risk in each model
- 3Cover organizational culture and ethics as risk factors, which candidates from technical backgrounds routinely skip
- 4Study the difference between policies, standards, procedures, and guidelines in obligation and in who approves each
- 5Answer 50 QAE questions restricted to Domain 1 and log the reasoning behind every wrong answer
- 1Learn enterprise risk management structure and how IT risk rolls up into it
- 2Study the three lines of defence and be able to say which line performs which activity
- 3Distinguish risk appetite from risk tolerance with a worked numeric example
- 4Study risk frameworks and the legal, regulatory, and contractual requirements that constrain risk decisions
- 5Cover business process resilience, DRP, and BCP as they appear in Domain 1 rather than in a technical context
- 1Study risk events, threat modelling, and the current threat landscape as inputs to identification
- 2Practise writing five complete risk scenarios with threat, asset, event, and business consequence
- 3Learn how vulnerability management output becomes a risk input rather than a finding list
- 4Study risk scenario evaluation and how scenarios are pruned before they reach the register
- 5Answer 50 Domain 2 identification questions
- 1Learn qualitative and quantitative analysis methodologies and where each is defensible
- 2Work numeric examples of single loss expectancy, annualized rate of occurrence, and annualized loss expectancy
- 3Distinguish inherent, residual, and current risk and be able to say which controls move which
- 4Study business impact analysis outputs and how they feed the register
- 5Build a five-row risk register with owner, inherent rating, controls, residual rating, and treatment
- 1Learn the four response options and practise choosing between them against appetite and cost
- 2Study risk ownership versus control ownership and why the same person is often the wrong choice for both
- 3Cover vendor and supply chain risk management including fourth-party exposure
- 4Study issues, findings, exceptions, and exemptions management and the approval path each requires
- 5Answer 60 Domain 3 questions on the response subtopics
- 1Study control frameworks and control types including preventive, detective, corrective, and compensating
- 2Practise selecting a control for a given risk and justifying it against cost and appetite
- 3Learn control testing methodologies and what constitutes evidence of operating effectiveness
- 4Distinguish control design effectiveness from control operating effectiveness with examples of each failing
- 5Answer 60 more Domain 3 questions on control subtopics
- 1Learn the definitions of KRI, KCI, and KPI cold and be able to write one of each for the same risk
- 2Study leading versus lagging indicators and which the exam prefers for early warning
- 3Practise data collection, aggregation, analysis, and validation and where aggregation distorts a picture
- 4Study reporting formats: heat maps, scorecards, and dashboards, and which audience gets which
- 5Cover the monitoring and reporting of emerging risks, then take a full Domain 3 quiz, since this domain is 32 percent of the exam
- 1Study technology principles, enterprise architecture, and technology roadmaps from a risk perspective
- 2Cover operations management including change management, asset management, DevOps, problems, and incidents
- 3Study the system development life cycle and where risk practitioners insert control requirements
- 4Cover data life cycle management and portfolio and project management including agile delivery
- 5Study technology resilience and disaster response and recovery, plus emerging technologies and their risk profile
- 1Study security concepts, frameworks, and standards to the depth a risk practitioner needs, not an engineer
- 2Cover security and risk awareness training design and how its effectiveness is measured
- 3Study data privacy and data protection principles and their regulatory drivers
- 4Practise translating a technical security control into a risk statement a board would read
- 5Take a full 150-question timed practice exam and record domain-level results
- 1Rework your two weakest domains from the Review Manual rather than from more questions
- 2Drill the qualifiers ISACA uses: BEST, MOST, FIRST, and GREATEST change which option is correct
- 3Practise the CRISC answer hierarchy, where the answer that establishes ownership or aligns to appetite usually beats the answer that adds a technical control
- 4Answer 150 mixed questions and read the explanation on every item, including those answered correctly
- 5Join an ISACA Engage CRISC study group if you are a member and post the reasoning you keep getting wrong
- 1Sit two full 150-question 240-minute exams on separate days under real conditions with no drink at the desk
- 2Pace-check against 96 seconds per question and practise flagging rather than stalling
- 3Reread the exam content outline and the 24 supporting tasks, which show the verbs ISACA expects of a CRISC holder
- 4Run the PSI compatibility check if testing remotely and get a portable mirror or phone ready for the mandatory mirror check
- 5Plan to arrive at least 30 minutes early at a test centre, because arriving more than 15 minutes late forfeits the fee
Ready to pass CRISC (Certified in Risk and Information Systems Control)?
Get 500+ practice questions, video walkthroughs, and a pass guarantee.
Best Study Resources
CRISC Exam Content Outline
Official blueprintISACA's authoritative list of the four domains, their weights, every subtopic, and the 24 supporting tasks. The supporting tasks list is the most useful part, because it states the actions ISACA expects a CRISC holder to perform.
Free
CRISC Review Manual
Official textbookISACA's own reference covering all four domains. The exam is written against this material, and its phrasing matches the way questions define risk appetite, residual risk, and control ownership.
Paid, print or digital, member discount available
CRISC Questions, Answers and Explanations database
Official question bankAn 833-question pool with a personalized dashboard, custom study plans, and progress tracking. Smaller than the CISA pool, so treat it as diagnostic rather than as your main source of coverage.
Paid, six-month subscription
CRISC Online Review Course
Official self-paced courseISACA's self-paced course covering governance, IT risk assessment, risk response and reporting, and information technology and security. Useful if you need structured instruction rather than a reference manual.
Paid
Free CRISC practice quiz
Official sample questionsTen free questions on ISACA's site testing risk and information systems control. Take it before you spend anything, because it reveals whether you naturally pick the risk answer or the engineering answer.
Free
ISACA Engage CRISC study groups
Community forumA member-only forum acting as a global virtual study group where candidates work practice questions and get help from certified professionals. Useful for checking your reasoning on scenario questions against someone who has already sat the exam.
Free to ISACA members
NIST SP 800-30, Guide for Conducting Risk Assessments
Free standardA free, detailed treatment of risk assessment methodology, threat and vulnerability identification, and likelihood and impact determination. Maps closely onto Domain 2 without costing anything.
Free
NIST SP 800-37, Risk Management Framework
Free standardThe full risk management life cycle from categorization through control selection, implementation, assessment, authorization, and monitoring. Useful background for Domains 1 and 3 and free to download.
Free
COBIT 2019
Governance frameworkISACA's governance framework. The governance versus management distinction it draws is the same one Domain 1 tests, and the framework language appears throughout ISACA's own materials.
Some publications free to ISACA members
ISACA interactive glossary
ReferenceISACA's own definitions of the terms used in exam items. Where a third-party guide and ISACA define residual risk or risk tolerance differently, the glossary is the version the exam uses.
Free
Common Mistakes to Avoid
Answering as an engineer instead of a risk practitioner. Presented with a risk, technical candidates reach for the strongest control, when CRISC usually wants the answer that assigns ownership, checks the decision against risk appetite, or escalates to the risk owner.
Before picking, ask who owns this decision. If an option has you unilaterally implementing a control that the business has not accepted the cost of, it is probably wrong even when it is technically correct.
Confusing risk owner with control owner. CRISC treats these as separate accountabilities, and questions build on that separation. The business unit head owns the risk; the IT manager may own the control that treats it.
Write out five real risks from your own organization and name both owners for each. If you find yourself naming the same person twice, you have not understood the split the exam is testing.
Blurring risk appetite and risk tolerance. They are related but not interchangeable, and questions turn on the difference between the amount of risk an organization is willing to pursue and the acceptable variation around it.
Anchor both to a number. If appetite is stated as no more than four hours of unplanned downtime per quarter, tolerance is the band around that figure the organization will live with before escalating. Practise until the distinction is automatic.
Mixing up KRIs, KCIs, and KPIs. Domain 3 is 32 percent of the exam and metrics run through all of it, so getting these confused costs more points on CRISC than on any other ISACA exam.
For a single risk, write one key risk indicator that gives early warning, one key control indicator that shows the control is operating, and one key performance indicator that shows the process is achieving its objective. Repeat for five risks.
Underweighting Domain 1 because it feels like corporate theory. Governance is 26 percent, and combined with Risk Response and Reporting at 32 percent, more than half the exam sits away from technical content.
Allocate study hours in proportion to the published weights. Domains 1 and 3 together are 58 percent of the exam. Domain 4, the most comfortable one for technical candidates, is only 20 percent.
Assuming a pass leads directly to certification. CRISC requires three or more years of professional experience across at least two of the four domains, and ISACA allows no waivers or substitutions of any kind, unlike CISA and CISM.
Before booking, map your work history to the four domains and confirm at least two are genuinely covered. Identify the supervisor or manager who will verify it, and check the experience falls inside the ten-year window before your application date.
Choosing residual risk answers without checking what the controls actually do. Questions present inherent risk, a control set, and ask about residual exposure, and candidates apply a control that reduces likelihood to a question about impact.
For every control you study, note whether it reduces likelihood, reduces impact, or does both. Then work scenarios where the residual figure barely moves, because the control addressed the wrong variable.
Studying only from the 833-question QAE database. That pool is smaller than the CISA equivalent, so repeated passes produce recall of specific items rather than command of the domains, and the real exam rephrases everything.
Use the Review Manual as the primary source and the question bank as a diagnostic tool. Read the explanation on every item, including the ones you answered correctly, because CRISC scoring turns on reasoning rather than recall.
Letting the six-month eligibility expire. Eligibility begins at registration rather than at scheduling, and ISACA forfeits both eligibility and the registration fee if you do not sit within the window.
Schedule an appointment as soon as you register, even if you later move it, since rescheduling more than 48 hours out is free. If you need longer, buy the single available six-month extension for US$75 before eligibility expires, cancelling any booked appointment at least 48 hours ahead first.
Exam Day Tips
- 1
Bring one current, valid, original government-issued ID showing your name, your signature, and your photograph, with the first and last name matching your ISACA registration exactly. Photocopies, handwritten documents, and digital IDs are refused.
- 2
At a PSI testing centre, plan to arrive at least 30 minutes early. Arriving more than 15 minutes late for the appointment forfeits the registration fee outright.
- 3
No calculator is permitted. Every annualized loss expectancy and every risk rating calculation has to be done mentally, so drill the arithmetic before exam day rather than relying on a tool you will not have.
- 4
No reference materials, notes, paper, notepads, or language dictionaries. Your workspace must be completely clear, and you must face the screen throughout so the proctor can monitor the session.
- 5
No food or drink, and ISACA specifies that this includes water, at test centres and in remote sessions alike. Hydrate before check-in and plan for four hours without a drink at your desk.
- 6
You may take two breaks of ten minutes or less with proctor permission. The exam pauses but the timer keeps running, so each break costs real minutes out of the 240.
- 7
For remote sessions, expect a 360 degree wall scan, a desk scan including under your laptop or keyboard, a floor to ceiling scan, and a mandatory mirror check showing the screen, keyboard, and all four edges of the monitor. Have a portable mirror or a phone ready, then remove the phone from the room.
- 8
Remote proctor communication is by live chat in English only, even if you selected Spanish or Japanese for the exam questions themselves.
- 9
Pace at roughly 96 seconds per question and answer every item, because there is no penalty for wrong answers and ISACA scores only the total answered correctly.
- 10
Do not photograph or screenshot any part of the exam, including the preliminary result screen. ISACA has a zero-tolerance policy for fraudulent test-taking and can nullify scores or revoke certifications.
Career Paths & Salary Ranges
IT risk analyst
Builds and maintains risk scenarios and the risk register, runs assessments, and tracks treatment plans. The three-year experience requirement is written to describe roughly this level of work across at least two CRISC domains.
Lower part of the $120k-$170k CRISC band
IT risk manager
Owns the IT risk programme, sets the assessment cadence, negotiates treatment with control owners, and reports exposure against appetite. Domains 1 and 3, which together are 58 percent of the exam, map directly onto this role.
Middle of the $120k-$170k CRISC band
Information security risk manager
Runs risk management inside a security function, connecting technical findings to business exposure. Draws on Domain 4 information security principles alongside the response and reporting content in Domain 3.
Middle to upper part of the $120k-$170k CRISC band
Third-party and supply chain risk manager
Assesses vendor and supply chain exposure, sets contractual control requirements, and monitors ongoing performance. Vendor and supply chain risk management is named explicitly in the Domain 3 risk response subtopics.
Middle of the $120k-$170k CRISC band
Internal control or GRC manager
Owns the control framework, coordinates control testing, and manages issues, findings, exceptions, and exemptions. The control design, implementation, and testing subtopics in Domain 3 cover most of the day-to-day work.
Middle of the $120k-$170k CRISC band
Head of technology risk or deputy CISO
Sets risk strategy, presents to executive committees and boards, and owns the relationship between IT risk and enterprise risk management. CRISC combined with CISM or CISA is the usual credential pairing at this level.
Top of the $120k-$170k CRISC band and above
Prerequisites & Requirements
- There are no prerequisites to sit the exam. ISACA states the CRISC exam is open to anyone with an interest in information security, and you may take it before meeting the experience requirement.
- To become certified you need three or more years of professional work experience across at least two of the four CRISC domains.
- That experience must have been gained within the ten-year period preceding your certification application date and must be verified by a supervisor or manager.
- ISACA allows no experience waivers or substitutions for CRISC. This differs from CISA, where up to three years may be waived, and CISM, where up to two years may be waived.
- You must pay a one-time US$50 application processing fee and submit the application within five years of your passing date.
- You must agree to ISACA's Code of Professional Ethics and the Continuing Professional Education policy.
Frequently Asked Questions
How much does the CRISC exam cost?
ISACA charges US$575 to register if you are an ISACA member and US$760 if you are not, based on your membership status at the time you register. The fee is nonrefundable and nontransferable. Becoming certified after you pass requires an additional one-time US$50 application processing fee. If your six-month eligibility period expires you can buy one six-month extension for US$75. Because membership reduces the exam fee by US$185 and also discounts the Review Manual, question database, and CPE, joining before registering is usually cheaper overall than registering as a non-member.
What happens if I fail the CRISC exam?
You may attempt the exam up to four times within a rolling 12-month period, paying the full registration fee for every attempt. After failing the first attempt you must wait 30 days from that attempt date before the second. After the second attempt you must wait 90 days before the third, and a further 90 days before the fourth. Your official score report includes domain-level results, which ISACA supplies for information only but which still tell you where the gap is. Given that Risk Response and Reporting is 32 percent of the exam, a fail concentrated there needs different remediation from a fail spread evenly.
How is the CRISC exam scored?
ISACA converts your raw score to a scaled score on a common range of 200 to 800, with 450 or higher required to pass. A score of 800 means every question was answered correctly and 200 is the lowest possible. Scaling makes different exam forms comparable, so 450 does not correspond to a fixed percentage of items correct. Every form contains unscored pretest items that ISACA does not identify and that do not affect your result. Domain percentages describe how much of the exam covers each domain and are not used to calculate your score, which depends only on total items answered correctly.
How long does it take to get CRISC results?
A preliminary pass or fail appears on screen immediately after you finish. The official score is emailed and posted online within 10 working days, on the MyISACA Certifications and CPE Management page. ISACA does not provide scores by telephone or fax and does not release question-level results. If you did not pass and want the score checked, you can request a rescore in writing through ISACA support within 30 days of results being released, with a US$75 fee per request, and PSI performs the rescore.
What identification do I need on exam day?
One current, valid, original government-issued ID that carries your name, your signature, and your photograph, with all three on a single document. The first and last name must match the name used to register. Acceptable documents include a driver's licence, a state or national ID card, a passport, a passport card, a green card, an alien registration document, or a permanent resident card. Copies, handwritten documents, and digital IDs are refused, with driver's licences issued in Japan without a signature the one stated exception. Failing to present acceptable ID counts as a no-show and forfeits the fee.
Can I use a calculator during the CRISC exam?
No. ISACA prohibits calculators outright, along with reference materials, study materials, paper, notes, notepads, and language dictionaries. This matters on CRISC because Domain 2 covers quantitative risk analysis, so any single loss expectancy, annualized rate of occurrence, or annualized loss expectancy calculation has to be performed mentally. Practise the arithmetic during preparation rather than assuming a tool will be available.
Can I take breaks during the four-hour exam?
Yes, two breaks of no more than ten minutes each, with your proctor's permission. The exam pauses during an approved break but the timer does not stop, so any break comes out of your 240 minutes and no extra time is granted. You must check out and check back in to use the facilities. Leaving the testing area without authorization can result in the exam being terminated, and candidates who leave without authorization are not permitted to return to the testing room.
How does remote proctoring work for CRISC?
ISACA delivers remotely proctored exams through PSI. Complete the device compatibility check in advance, and get IT approval first if you are using a company machine, because the secure browser must be installed. Check-in requires a 360 degree scan of all four walls, a desk scan that includes under your laptop or keyboard, and a floor to ceiling scan of your test space. ISACA also requires a mirror check on every exam, where you hold a portable mirror or phone to the webcam to show the screen, keyboard, and all four edges of the monitor. A phone used for that must then be removed from the testing room. Proctor communication is by live chat in English only.
Are special accommodations available for CRISC?
Yes. Check the special accommodation requirement field during exam registration, then complete ISACA's Special Accommodation Request Form with your health care professional and submit it through ISACA support. Requests are not considered until registration fees are paid in full, must reach ISACA no later than four weeks before your preferred exam date, and are valid only for that single exam administration. A later attempt requires a new request.
What are the CRISC experience requirements?
Three or more years of professional work experience across at least two of the four CRISC domains, gained within the ten-year period preceding your application date and verified by a supervisor or manager. ISACA grants no experience waivers or substitutions for CRISC, which sets it apart from CISA where up to three years may be waived and CISM where up to two may be waived. You can sit and pass the exam before meeting the requirement, and you then have five years from your passing date to submit the application with the US$50 processing fee.
How do I maintain CRISC once I am certified?
Report a minimum of 20 CPE hours each year and a minimum of 120 CPE hours across a three-year reporting period, and pay the annual maintenance fee of US$45 for ISACA members or US$85 for non-members, due each 1 January. You must also comply with the annual CPE audit if selected and adhere to ISACA's Code of Professional Ethics. If you hold more than two ISACA certifications, the fee for the third and any subsequent one drops to US$25 for members and US$50 for non-members. CPE hours can count towards multiple ISACA certifications where the activity is relevant to each.
What happens if I miss the CPE requirement?
ISACA revokes the CRISC designation for non-compliance with the CPE policy, and a revoked holder may no longer present themselves as certified. You may appeal for reinstatement in writing with a detailed explanation and the CPE documentation covering the period from revocation to the current year. If the appeal succeeds you pay any outstanding maintenance fees plus a US$50 reinstatement fee per certification. If it fails, returning to active status means retaking and repassing the exam and reapplying with the appropriate experience. Retain CPE documentation for 12 months after the end of each three-year cycle in case you are selected for audit.
How long is my exam eligibility valid after registering?
Six months from your registration date, and the registration fee must be paid in full before you can schedule. Appointments can be booked as early as 48 hours after payment but are only released 90 days in advance. You forfeit both eligibility and fee if you do not sit within the window, miss the appointment, or arrive more than 15 minutes late. One six-month extension is available for US$75, and the option appears on your dashboard from 30 days before to 30 days after expiry. If an exam is already scheduled, cancel it at least 48 hours ahead before extending.
Can I reschedule my CRISC exam?
Yes, without penalty, at any time during your eligibility period provided you do it at least 48 hours before the scheduled appointment. Inside 48 hours you must sit the exam or forfeit the fee. If you miss an appointment through a documented personal hardship such as illness, the death of an immediate family member, or a traffic accident, contact PSI within 72 hours with supporting documentation. A doctor's note must be signed by a licensed doctor, carry the visit date and the doctor's contact details, and indicate you should not sit the exam. Denied hardship requests mean registering and paying in full again.
How does CRISC compare with CISA?
The mechanics are identical: 150 questions, 240 minutes, a 200 to 800 scaled score with 450 passing, US$575 member and US$760 non-member registration, a US$50 application fee, and the same 20 CPE per year and 120 per three-year maintenance. The subject and the entry bar differ. CISA covers the IT audit process and control evaluation across five domains and requires five years of experience with up to three waivable. CRISC covers IT risk identification, assessment, response, and monitoring across four domains and requires only three years, but with no waivers at all. CISA is also offered in seven languages against three for CRISC, and has far more holders.
How does CRISC compare with CISM?
CRISC is about managing IT risk; CISM is about managing an information security programme. Exam mechanics, fees, and maintenance requirements are the same across both. CISM requires five years of information security management experience with waivers available for up to two years, against CRISC's three years with no waivers. The domain structures diverge: CISM weights Information Security Program at 33 percent and Incident Management at 30 percent, while CRISC weights Risk Response and Reporting at 32 percent and Governance at 26 percent. Holding both is common, and because CPE hours can be applied across ISACA certifications where relevant, the ongoing cost of the second is largely the reduced maintenance fee.
Does ISACA publish a CRISC pass rate?
No. ISACA does not publish pass rates for CRISC or for any of its certification exams, and it does not release question-level results either. Any pass rate figure quoted elsewhere comes from third-party estimates or candidate surveys rather than from ISACA. What ISACA does publish is the standard: a scaled score of 450 on a 200 to 800 range, described as the minimum standard of knowledge and applied consistently across every version of the exam.
In which languages is the CRISC exam offered?
Three: English, Spanish, and Japanese. That is narrower than CISA, which is offered in seven. You choose your preferred language when scheduling, and changing it afterwards requires rescheduling the appointment, which must happen at least 48 hours before the booked time. ISACA also publishes translated CRISC terminology lists in Chinese Simplified, Korean, and Spanish, which helps if you are testing in a second language, since CRISC questions turn on precise definitions of terms such as appetite, tolerance, inherent risk, and residual risk.
Pass CRISC (Certified in Risk and Information Systems Control), Guaranteed
94% pass rate on first attempt
One-time • Lifetime access
CRISC (Certified in Risk and Information Systems Control) Pass Rate
How hard is it? (~55%)
Failed CRISC (Certified in Risk and Information Systems Control)?
Recovery plan & retake policy
Study Timeline
Week-by-week study plan
Requirements
Prerequisites & registration
Compare Certifications
Side-by-side comparisons