CISSP vs CISA
CISSP covers designing and managing an organization's security across eight domains. CISA covers auditing and assessing IT and business systems and their controls. Both require five years of experience.
Side by Side
| CISSP | CISA | |
|---|---|---|
| Full name | Certified Information Systems Security Professional | Certified Information Systems Auditor |
| Issuer | ISC2 | ISACA |
| Level | Advanced | Advanced |
| Exam type | Computerized adaptive | Multiple choice |
| Questions | 100-150 | 150 |
| Duration | 3 hours | 4 hours (240 minutes) |
| Passing score | 700 out of 1000 points | 450 on a scale of 200-800 |
| Exam fee | $749 | $760 |
| Prerequisites | Five years of cumulative, full-time work experience in two or more of the eight CISSP domains. A relevant degree or one credential from the ISC2 approved list can waive one year, and only one waiver applies. Candidates without the experience can pass the exam and become an Associate of ISC2, with six years to earn the five years of experience. | Five or more years of professional IS auditing, control or security experience, gained within the 10 years before applying. Waivers can cover up to three years, and candidates can take the exam before the experience is complete. |
| Validity | 3 years | 3 years |
| Renewal | 120 CPE credits per three-year cycle (at least 90 Group A, the rest Group A or B) plus a U.S. $135 annual maintenance fee. | 20 CPE hours each year and 120 CPE hours per three-year period, plus an annual maintenance fee of US$45 (members) or US$85 (non-members), reduced to US$25/US$50 for a third or later ISACA certification. |
| Exam domains | Security and Risk Management; Asset Security; Security Architecture and Engineering; Communication and Network Security; Identity and Access Management (IAM); Security Assessment and Testing; Security Operations; Software Development Security | Information Systems Auditing Process; Governance and Management of IT; Information Systems Acquisition, Development and Implementation; Information Systems Operations and Business Resilience; Protection of Information Assets |
Main Differences
- +Focus: CISSP is a broad security practitioner and management certification. CISA is an audit and assurance certification.
- +Exam: CISSP is a computerized adaptive test with 100 to 150 questions in 3 hours. CISA has 150 questions in 4 hours.
- +Cost: ISC2 lists the CISSP exam at U.S. $749 for standard registration in the Americas. The CISA exam costs $575 for ISACA members and $760 for non-members.
- +Experience waivers: CISSP allows one year to be waived through a degree or an approved credential. CISA allows waivers of up to three years.
Certification Details
Frequently Asked Questions
Do CISSP and CISA both require five years of experience?→
Yes. CISSP needs five years in two or more of its eight domains, and CISA needs five years of IS auditing, control, or security experience within the last 10 years.
How often must CISSP and CISA be renewed?→
Both run on three-year cycles with 120 CPE credits. CISA also requires at least 20 CPE hours each year.
Sources
- CISSP Certification Exam Outline
- ISC2 Exam Pricing
- ISC2 Member Policies (CPE requirements)
- Get CISA Certified
- CISA Exam Content Outline
- Maintain CISA Certification
- ISACA Certification Exams Candidate Guide 2026
- CISSP - Certified Information Systems Security Professional
- CISSP Experience Requirements
- CISSP Experience Waiver Updates
- CISSP Exam Refresh FAQ
- ISC2 Annual Maintenance Fees (AMF)
- Become an Associate of ISC2
- ISC2 Certification Maintenance Handbook
- ISACA: CISA certification
- ISACA CPE Policy
- ISACA press release: CISA exam updated (2024)
- ISACA press release: ISACA Introduces the CISA Associate
- ISACA: CISA Associate
Exam details come from official issuer pages and are listed in the sources above. Fees and exam versions change; confirm with the issuer before registering.