Skip to main content
← Back to certifications
ISACAGRC and AuditAdvancedVendor-neutralActive

ISACA CISA

An information-systems audit credential focused on audit processes, governance, systems acquisition and operations, information protection, and evaluating organizational controls.

Last verified: 2026-09-01

Overview

ISACA CISA is an advanced, vendor-neutral certification for professionals who audit, assess, monitor, and help improve information systems and technology controls. It covers the information systems auditing process, governance and management of IT, systems acquisition and implementation, operations and business resilience, and protection of information assets.\n\nCISA is commonly pursued by IT auditors, technology risk professionals, compliance specialists, and security or governance professionals who evaluate whether information systems support business objectives while meeting control, risk, and regulatory requirements.

Recommended experience
The CISA exam is open to anyone, but full certification requires at least five years of professional information systems auditing, control, or security work experience. Candidates must meet ISACA's current experience rules and apply for certification within five years of passing the exam.
Estimated study time
120–200 hours
Target job roles
IT AuditorInformation Systems AuditorTechnology Risk AnalystIT Compliance ManagerGRC AnalystInternal AuditorIT Controls Specialist

Exam Details

ISACA CISA Exam

Exam code
CISA
Number of exams
1
Duration
240 minutes
Question count
150 questions
Delivery method
PSI testing center or remote-proctored exam
Price
$575 USD member / $760 USD nonmember

Skills and Domains

Information System Auditing Process

18%

Planning and executing risk-based information-system audits, evidence collection, reporting, analytics, and audit quality.

Governance and Management of IT

18%

IT governance, strategy, policies, enterprise risk, privacy, data governance, resource management, and performance.

Information Systems Acquisition, Development, and Implementation

12%

Project governance, system-development methods, controls, implementation testing, migration, and post-implementation review.

Information Systems Operations and Business Resilience

26%

IT operations, service management, assets, availability, databases, backup, business continuity, and disaster recovery.

Protection of Information Assets

26%

Security controls, identity, network and endpoint security, encryption, cloud, monitoring, incident response, and forensics.

Study Resources

ISACA CISA Certification

Official resource

Documentation · Free

Official ISACA CISA certification overview, exam, application, and credential information.

View resource

ISACA CISA Exam Content Outline

Official resource

Official Guide · Free

Official current CISA exam domains and job-practice outline.

View resource

Maintain CISA Certification

Official resource

Documentation · Free

Official ISACA CPE, maintenance-fee, and renewal requirements.

View resource

Renewal

Validity period
3-year CPE reporting cycle
Renewal method
Earn at least 20 CPE hours each year and 120 CPE hours over three years, pay the annual maintenance fee, and comply with ISACA professional and audit standards.
Notes
Current annual maintenance fee is U.S. $45 for ISACA members and U.S. $85 for non-members.

Recommended Before

Verify with official provider.

Recommended After

Verify with official provider.

Alternatives

Verify with official provider.

Specializations

Verify with official provider.

Keep exploring on ThirdBadge

Connect this certification to its broader technology area, career roadmaps, training, and study resources.

Explore certification categories

Browse focused certification guides by technology and career domain.