CISA (Certified Information Systems Auditor)
CISA covers auditing, monitoring and assessing IT and business systems with a risk-based approach to audit engagements. ISACA designs it for IT and IS auditors and for control, assurance and information security professionals with five or more years of experience.
Exam Details
Computer-based exam with scaled scoring, taken at PSI test centers or through remote proctoring.
Non-member price. ISACA members pay US$575. A one-time US$50 application processing fee is due after passing. The full fee is paid for each attempt, with up to four attempts in a rolling 12-month period.
Requirements and Renewal
Prerequisites
Five or more years of professional IS auditing, control or security experience, gained within the 10 years before applying. Waivers can cover up to three years, and candidates can take the exam before the experience is complete.
Renewal
20 CPE hours each year and 120 CPE hours per three-year period, plus an annual maintenance fee of US$45 (members) or US$85 (non-members), reduced to US$25/US$50 for a third or later ISACA certification.
Current Version
CISA 2024 exam content outline, in effect since Aug 1, 2024.
Exam Domains
5 domains| Domain | Weight |
|---|---|
| Information Systems Auditing Process | 18% |
| Governance and Management of IT | 18% |
| Information Systems Acquisition, Development and Implementation | 12% |
| Information Systems Operations and Business Resilience | 26% |
| Protection of Information Assets | 26% |
DoD 8140 Work Roles
6 work rolesThe DoD 8140 Qualification Matrix V2.1 lists CISA as a foundational qualification option for these DoD Cyber Workforce Framework work roles, up to the proficiency level shown. Lower levels of the same work role are also covered.
Comparisons
Certification Lists
Related Tool Categories
Frequently Asked Questions
What does CISA stand for?→
CISA stands for Certified Information Systems Auditor. ISACA issues it for professionals who audit, monitor and assess IT and business systems.
Can the CISA exam be taken without five years of experience?→
Yes. The exam is open before the experience requirement is met, and candidates have five years from the pass date to apply. Students without the required work experience can earn the CISA Associate designation by participating in an ISACA partner program and passing the exam; it requires active ISACA membership and a one-time US$25 application fee.
Which is better, CISA or CRISC?→
They test different job practices. CISA covers IS audit across five domains and requires five years of audit, control or security experience, while CRISC covers IT risk and IS control and requires three years of experience.
How many times can the CISA exam be retaken?→
ISACA allows four attempts within a rolling 12-month period. The first retake requires a 30-day wait, and each attempt needs a new registration fee.
Sources
- ISACA: CISA certification
- ISACA: CISA exam content outline
- ISACA: Get CISA certified
- ISACA: Maintain CISA certification
- ISACA Certification Exams Candidate Guide (2026)
- ISACA CPE Policy
- ISACA press release: CISA exam updated (2024)
- ISACA press release: ISACA Introduces the CISA Associate
- ISACA: CISA Associate
Exam details are checked against official ISACA pages. Fees, exam versions, and renewal rules change; confirm with ISACA before registering. CISA is a trademark of its owner. This site is not affiliated with or endorsed by ISACA.