ISACA CRISC
A risk-focused credential covering IT risk identification, assessment, response, monitoring, and the design and evaluation of information-system controls.
Last verified: 2026-09-01
Overview
ISACA CRISC is an advanced, vendor-neutral certification focused on enterprise information systems risk and control. It validates the ability to support governance, identify and assess risk, design and evaluate risk responses and controls, report risk information, and understand the technology and security context in which risk decisions are made.\n\nCRISC is suited to IT risk professionals, GRC practitioners, security and controls specialists, and technology leaders who help organizations connect business objectives with practical risk management and information-system controls.
- Recommended experience
- The CRISC exam is open to anyone, but full certification requires at least three years of professional experience across at least two of the four CRISC domains. Candidates must satisfy ISACA's current experience requirements and apply within five years of passing the exam.
- Estimated study time
- 100–160 hours
- Target job roles
- IT Risk ManagerGRC AnalystTechnology Risk ConsultantInformation Security Risk AnalystIT Controls ManagerRisk and Compliance Manager
Exam Details
ISACA CRISC Exam
- Exam code
- CRISC
- Number of exams
- 1
- Duration
- 240 minutes
- Question count
- 150 questions
- Delivery method
- PSI testing center or remote-proctored exam
- Price
- $575 USD member / $760 USD nonmember
Skills and Domains
Governance
26%Organizational and risk governance, policies, roles, risk appetite, enterprise risk management, resilience, and standards.
Risk Assessment
22%Risk identification, threat and vulnerability analysis, business impact, risk scenarios, registers, and assessment methods.
Risk Response and Reporting
32%Risk treatment, control design and testing, third-party risk, action plans, metrics, monitoring, and stakeholder reporting.
Technology and Security
20%Technology architecture, operations, SDLC, data lifecycle, resilience, emerging technologies, security, privacy, and awareness.
Study Resources
ISACA CRISC Certification
Official resourceDocumentation · Free
Official ISACA CRISC certification overview, exam, application, and credential information.
View resourceISACA CRISC Exam Content Outline
Official resourceOfficial Guide · Free
Official current CRISC exam domains and job-practice outline.
View resourceMaintain CRISC Certification
Official resourceDocumentation · Free
Official ISACA CPE, maintenance-fee, and renewal requirements.
View resourceRenewal
- Validity period
- 3-year CPE reporting cycle
- Renewal method
- Earn at least 20 CPE hours each year and 120 CPE hours over three years, pay the annual maintenance fee, and comply with ISACA certification requirements.
- Notes
- Current annual maintenance fee is U.S. $45 for ISACA members and U.S. $85 for non-members.
Related Certifications
Recommended Before
Verify with official provider.
Recommended After
Verify with official provider.
Alternatives
Verify with official provider.
Specializations
Verify with official provider.
Keep exploring on ThirdBadge
Connect this certification to its broader technology area, career roadmaps, training, and study resources.
Explore certification categories
Browse focused certification guides by technology and career domain.