TCL Portal

CISA Certification: The Complete 2026 Guide

By: Sekiko Jo (pen name, TCL Security Editorial Desk) Published:
  • #CISA
  • #ISACA
  • #Security Certification
  • #IT Audit
  • #Career

If your work involves auditing IT systems, assessing internal controls, or proving to regulators and stakeholders that an organization’s technology is governed the way it claims to be, CISA is the credential that signals you can do that job credibly.

In this guide, I’ll cover what CISA certification is, who it’s for, what the exam actually tests, the experience requirements, and how it compares to CISM — a certification professionals frequently confuse with CISA because both come from ISACA and both have three-letter acronyms starting with “CIS.”

What CISA Certification Covers

CISA stands for Certified Information Systems Auditor. It’s issued by ISACA (previously known as the Information Systems Audit and Control Association), a global professional association focused on IT governance, audit, risk, and security.

CISA is the leading credential for professionals who audit, control, monitor, and assess an organization’s information technology and business systems. Unlike certifications aimed at building or defending systems, CISA validates the ability to independently evaluate whether systems, controls, and processes are working as intended — and to report findings that stakeholders, auditors, and regulators can trust.

Typical roles held by CISA-certified professionals include:

If your target role is running or building a security program rather than auditing one, our CISA vs CISM comparison further down this guide will help you decide which credential fits your direction better.

The CISA Exam Domains

The CISA exam consists of 150 questions covering five job practice domains, updated by ISACA effective August 1, 2024 to reflect current audit practice:

DomainExam WeightFocus
1. Information System Auditing Process18%Audit planning, standards, risk-based audit strategy, evidence collection, reporting
2. Governance and Management of IT18%IT governance frameworks, strategy, organizational structure, policies, enterprise risk management
3. Information Systems Acquisition, Development and Implementation12%Project governance, system development lifecycle, testing, change management
4. Information Systems Operations and Business Resilience26%IT operations, service management, business continuity, disaster recovery
5. Protection of Information Assets26%Security controls, identity and access management, network security, data protection

Domains 4 and 5 carry the most weight — a reflection of how much CISA emphasizes operational resilience and information protection alongside classic audit process knowledge. This is not a purely audit-methodology exam; a working knowledge of security controls and IT operations is required to pass.

The exam runs 3 hours, is computer-based, and is delivered through PSI testing centers worldwide or as a remotely proctored exam. Scores are reported on a scaled range of 200–800, with 450 required to pass.

For candidates who want a domain-by-domain study breakdown, our CISSP Domains Overview covers the equivalent structure for the security-management track, which is useful context if you’re weighing CISA against a broader security certification path.

Experience Requirements

To become CISA certified, you need a minimum of five years of professional work experience in information systems auditing, control, assurance, or security — earned within the ten years preceding your certification application, or within five years of passing the exam.

The experience must fall within at least one of the five CISA job practice domain areas listed above.

Experience waivers: ISACA allows up to three years of the five-year requirement to be waived through substitutions such as:

Waivers apply only to the experience requirement — you still need to pass the exam itself regardless of prior education or credentials.

If you pass the exam before meeting the experience requirement, ISACA allows up to five years from your exam pass date to accumulate and submit the required experience. This mirrors how our CISSP experience requirements guide describes the equivalent (ISC)² path — pass first, then formalize the credential once your work history catches up.

What CISA Certification Costs

ItemISACA MemberNonmember
Exam registration feeUS$575US$760
Application processing fee (one-time, after passing)US$50US$50
Annual maintenance feeUS$45US$85

Once you register for the exam, you have a six-month eligibility window to sit for it. Many employers with internal audit or IT governance functions cover the exam fee as part of professional development, particularly at firms where CISA is a stated requirement for senior audit roles.

CISA vs CISM: IT Audit vs Security Management

CISA and CISM are both ISACA certifications, both require five years of relevant experience, and both are frequently pursued by the same population of mid-career security and governance professionals — which is exactly why they get confused.

FactorCISACISM
Core focusAuditing, assessing, and reporting on IT controls and governanceBuilding and managing an information security program
Domains5 domains (audit process, governance, systems development, operations/resilience, asset protection)4 domains (security governance, risk management, security program, incident management)
Best fit forIT auditors, assurance professionals, compliance analystsSecurity managers, CISOs, security program leads
Experience required5 years in audit/control/assurance/security (up to 3 years waivable)5 years in information security management across 3+ domains
Exam length3 hours, 150 questions150 questions
Mindset tested”Does this control actually work, and can I prove it?""How do I run a security program that manages risk to the business?”

The practical distinction: CISA asks you to independently verify and report on whether systems and controls are working as designed. CISM asks you to design, run, and be accountable for the program those controls belong to. If you enjoy investigating, testing, and documenting evidence, CISA fits. If you’d rather set security strategy and manage the people and budget behind it, CISM fits.

It’s also common to hold both. Auditors who move into security leadership roles — or security managers who want stronger credibility on the controls-testing side — frequently add the second credential a few years after the first. See our CISA vs CISM: which to take first guide for a decision framework based on your current role and target direction, and our CISSP vs CISM comparison if you’re also weighing the broader (ISC)² security-architecture track against ISACA’s management-focused credential.

Career Paths for CISA Holders

CISA opens a fairly linear career track, since the certification maps closely to job titles in audit and assurance functions:

In markets with strengthening financial and data-protection regulation, demand for CISA-credentialed auditors tends to track closely with regulatory enforcement activity — organizations need people who can independently confirm their controls hold up under scrutiny, not just people who built the controls in the first place.

Sources

Fees, domain weights, and requirements reflect ISACA’s published guidance as of September 2026. ISACA updates certification requirements periodically — verify current figures on isaca.org before registering.

FAQ

Q: What does CISA stand for?

Certified Information Systems Auditor, issued by ISACA. It certifies the ability to audit, control, monitor, and assess an organization’s information systems and business processes.

Q: How many questions are on the CISA exam, and how long is it?

150 questions over 3 hours, computer-based, delivered at PSI testing centers or via remote proctoring. A scaled score of 450 out of 800 is required to pass.

Q: What are the CISA experience requirements?

Five years of professional experience in information systems auditing, control, assurance, or security, earned within the ten years before your application. Up to three years can be waived through qualifying education or other credentials.

Q: Can I take the CISA exam before I have five years of experience?

Yes. You can pass the exam first and have up to five years from your pass date to accumulate and submit the required experience for full certification.

Q: How much does CISA cost?

Exam registration is US$575 for ISACA members and US$760 for nonmembers, plus a one-time US$50 application processing fee after passing, and an annual maintenance fee of US$45 (members) or US$85 (nonmembers).

Q: Should I get CISA or CISM first?

Depends on direction. CISA fits IT audit, assurance, and controls-testing work. CISM fits security program management and leadership. Many professionals eventually hold both — see our CISA vs CISM guide for a fuller breakdown.

Conclusion

CISA remains the standard credential for professionals who verify — rather than build — an organization’s IT controls and governance. The path requires five years of qualifying experience (partially waivable), a focused pass through five exam domains weighted heavily toward operations, resilience, and information protection, and ongoing maintenance once certified.

If your career is heading toward audit leadership, risk and assurance consulting, or IT governance, CISA is the more direct credential than a security-management certification like CISM. If you’re still deciding between the audit track and the security-leadership track, our CISA vs CISM: which to take first guide walks through the decision in more detail, and our CISSP Certification Complete Guide covers the broader security-architecture credential if you’re weighing all three paths against each other.


@jo_sekiko

FAQ

What does CISA stand for?

CISA stands for Certified Information Systems Auditor, a certification issued by ISACA for professionals who audit, control, monitor, and assess an organization's information systems and business processes.

How many domains does the CISA exam cover?

The CISA exam covers five domains: Information System Auditing Process (18%), Governance and Management of IT (18%), Information Systems Acquisition, Development and Implementation (12%), Information Systems Operations and Business Resilience (26%), and Protection of Information Assets (26%).

What are the CISA experience requirements?

You need a minimum of five years of professional work experience in information systems auditing, control, assurance, or security, gained within the ten years preceding your certification application. Up to three years can be waived with qualifying education or other ISACA certifications.

Is CISA or CISM better for my career?

CISA is built for IT audit, assurance, and control work — verifying that systems and processes are governed correctly. CISM is built for security management — leading and running a security program. Choose based on whether you want to audit and assess, or build and manage.

About the authors