CISA vs CRISC
CISA is ISACA's audit certification for assessing IT systems and controls. CRISC covers identifying and managing IT risk through IS controls. The exams share a format and fee, but the experience requirements differ.
Side by Side
| CISA | CRISC | |
|---|---|---|
| Full name | Certified Information Systems Auditor | Certified in Risk and Information Systems Control |
| Issuer | ISACA | ISACA |
| Level | Advanced | Intermediate |
| Exam type | Multiple choice | Multiple choice |
| Questions | 150 | 150 |
| Duration | 4 hours (240 minutes) | 4 hours (240 minutes) |
| Passing score | 450 on a scale of 200-800 | 450 on a scale of 200-800 |
| Exam fee | $760 | $760 |
| Prerequisites | Five or more years of professional IS auditing, control or security experience, gained within the 10 years before applying. Waivers can cover up to three years, and candidates can take the exam before the experience is complete. | Three or more years of IT risk management and IS control experience across at least two of the four CRISC domains, gained within the 10 years before applying. ISACA allows no waivers or substitutions. |
| Validity | 3 years | 3 years |
| Renewal | 20 CPE hours each year and 120 CPE hours per three-year period, plus an annual maintenance fee of US$45 (members) or US$85 (non-members), reduced to US$25/US$50 for a third or later ISACA certification. | 20 CPE hours each year and 120 CPE hours per three-year period, plus an annual maintenance fee of US$45 (members) or US$85 (non-members), reduced to US$25/US$50 for a third or later ISACA certification. |
| Exam domains | Information Systems Auditing Process; Governance and Management of IT; Information Systems Acquisition, Development and Implementation; Information Systems Operations and Business Resilience; Protection of Information Assets | Governance; Risk Assessment; Risk Response and Reporting; Technology and Security |
Main Differences
- +Focus: CISA is built around the audit process and assurance. CRISC is built around governance, risk assessment, risk response and reporting, and technology and security controls.
- +Experience: CISA needs five years of IS auditing, control, or security experience, with waivers of up to three years. CRISC needs three years of IT risk management and IS control experience across two of its four domains, with no waivers.
- +Level: with three years required, CRISC asks for less experience than CISA.
- +Exam and cost: both have 150 questions in 4 hours, pass at 450, and cost $575 for members or $760 for non-members.
Certification Details
Frequently Asked Questions
Does CRISC allow experience waivers?→
No. ISACA allows no waivers or substitutions for the three-year CRISC experience requirement. CISA allows waivers of up to three years.
How many domains do CISA and CRISC have?→
CISA has five domains and CRISC has four.
Sources
- Get CISA Certified
- CISA Exam Content Outline
- Maintain CISA Certification
- Get CRISC Certified
- CRISC Exam Content Outline
- Maintain CRISC Certification
- ISACA Certification Exams Candidate Guide 2026
- ISACA: CISA certification
- ISACA CPE Policy
- ISACA press release: CISA exam updated (2024)
- ISACA press release: ISACA Introduces the CISA Associate
- ISACA: CISA Associate
- ISACA: CRISC certification
- ISACA press release: ISACA Updates CDPSE and CRISC Exams (2025)
Exam details come from official issuer pages and are listed in the sources above. Fees and exam versions change; confirm with the issuer before registering.