ISACA CISA
An information-systems audit credential focused on audit processes, governance, systems acquisition and operations, information protection, and evaluating organizational controls.
Last verified: 2026-09-01
Overview
ISACA CISA is an advanced, vendor-neutral certification for professionals who audit, assess, monitor, and help improve information systems and technology controls. It covers the information systems auditing process, governance and management of IT, systems acquisition and implementation, operations and business resilience, and protection of information assets.\n\nCISA is commonly pursued by IT auditors, technology risk professionals, compliance specialists, and security or governance professionals who evaluate whether information systems support business objectives while meeting control, risk, and regulatory requirements.
- Recommended experience
- The CISA exam is open to anyone, but full certification requires at least five years of professional information systems auditing, control, or security work experience. Candidates must meet ISACA's current experience rules and apply for certification within five years of passing the exam.
- Estimated study time
- 120–200 hours
- Target job roles
- IT AuditorInformation Systems AuditorTechnology Risk AnalystIT Compliance ManagerGRC AnalystInternal AuditorIT Controls Specialist
Exam Details
ISACA CISA Exam
- Exam code
- CISA
- Number of exams
- 1
- Duration
- 240 minutes
- Question count
- 150 questions
- Delivery method
- PSI testing center or remote-proctored exam
- Price
- $575 USD member / $760 USD nonmember
Skills and Domains
Information System Auditing Process
18%Planning and executing risk-based information-system audits, evidence collection, reporting, analytics, and audit quality.
Governance and Management of IT
18%IT governance, strategy, policies, enterprise risk, privacy, data governance, resource management, and performance.
Information Systems Acquisition, Development, and Implementation
12%Project governance, system-development methods, controls, implementation testing, migration, and post-implementation review.
Information Systems Operations and Business Resilience
26%IT operations, service management, assets, availability, databases, backup, business continuity, and disaster recovery.
Protection of Information Assets
26%Security controls, identity, network and endpoint security, encryption, cloud, monitoring, incident response, and forensics.
Study Resources
ISACA CISA Certification
Official resourceDocumentation · Free
Official ISACA CISA certification overview, exam, application, and credential information.
View resourceISACA CISA Exam Content Outline
Official resourceOfficial Guide · Free
Official current CISA exam domains and job-practice outline.
View resourceMaintain CISA Certification
Official resourceDocumentation · Free
Official ISACA CPE, maintenance-fee, and renewal requirements.
View resourceRenewal
- Validity period
- 3-year CPE reporting cycle
- Renewal method
- Earn at least 20 CPE hours each year and 120 CPE hours over three years, pay the annual maintenance fee, and comply with ISACA professional and audit standards.
- Notes
- Current annual maintenance fee is U.S. $45 for ISACA members and U.S. $85 for non-members.
Related Certifications
Recommended Before
Verify with official provider.
Recommended After
Verify with official provider.
Alternatives
Verify with official provider.
Specializations
Verify with official provider.
Keep exploring on ThirdBadge
Connect this certification to its broader technology area, career roadmaps, training, and study resources.
Explore certification categories
Browse focused certification guides by technology and career domain.