CISA Certification: The Complete 2026 Guide
- #CISA
- #ISACA
- #Security Certification
- #IT Audit
- #Career
If your work involves auditing IT systems, assessing internal controls, or proving to regulators and stakeholders that an organization’s technology is governed the way it claims to be, CISA is the credential that signals you can do that job credibly.
In this guide, I’ll cover what CISA certification is, who it’s for, what the exam actually tests, the experience requirements, and how it compares to CISM — a certification professionals frequently confuse with CISA because both come from ISACA and both have three-letter acronyms starting with “CIS.”
What CISA Certification Covers
CISA stands for Certified Information Systems Auditor. It’s issued by ISACA (previously known as the Information Systems Audit and Control Association), a global professional association focused on IT governance, audit, risk, and security.
CISA is the leading credential for professionals who audit, control, monitor, and assess an organization’s information technology and business systems. Unlike certifications aimed at building or defending systems, CISA validates the ability to independently evaluate whether systems, controls, and processes are working as intended — and to report findings that stakeholders, auditors, and regulators can trust.
Typical roles held by CISA-certified professionals include:
- IT Auditor / Internal Auditor
- IT Audit Manager or Director
- IS Risk and Assurance Consultant
- Compliance and Controls Analyst
- Information Security Auditor
- IT Governance Analyst
If your target role is running or building a security program rather than auditing one, our CISA vs CISM comparison further down this guide will help you decide which credential fits your direction better.
The CISA Exam Domains
The CISA exam consists of 150 questions covering five job practice domains, updated by ISACA effective August 1, 2024 to reflect current audit practice:
| Domain | Exam Weight | Focus |
|---|---|---|
| 1. Information System Auditing Process | 18% | Audit planning, standards, risk-based audit strategy, evidence collection, reporting |
| 2. Governance and Management of IT | 18% | IT governance frameworks, strategy, organizational structure, policies, enterprise risk management |
| 3. Information Systems Acquisition, Development and Implementation | 12% | Project governance, system development lifecycle, testing, change management |
| 4. Information Systems Operations and Business Resilience | 26% | IT operations, service management, business continuity, disaster recovery |
| 5. Protection of Information Assets | 26% | Security controls, identity and access management, network security, data protection |
Domains 4 and 5 carry the most weight — a reflection of how much CISA emphasizes operational resilience and information protection alongside classic audit process knowledge. This is not a purely audit-methodology exam; a working knowledge of security controls and IT operations is required to pass.
The exam runs 3 hours, is computer-based, and is delivered through PSI testing centers worldwide or as a remotely proctored exam. Scores are reported on a scaled range of 200–800, with 450 required to pass.
For candidates who want a domain-by-domain study breakdown, our CISSP Domains Overview covers the equivalent structure for the security-management track, which is useful context if you’re weighing CISA against a broader security certification path.
Experience Requirements
To become CISA certified, you need a minimum of five years of professional work experience in information systems auditing, control, assurance, or security — earned within the ten years preceding your certification application, or within five years of passing the exam.
The experience must fall within at least one of the five CISA job practice domain areas listed above.
Experience waivers: ISACA allows up to three years of the five-year requirement to be waived through substitutions such as:
- One year waived for a completed university degree
- Up to two additional years waived for other qualifying credentials or a master’s degree in a related field (information security, IT, business)
Waivers apply only to the experience requirement — you still need to pass the exam itself regardless of prior education or credentials.
If you pass the exam before meeting the experience requirement, ISACA allows up to five years from your exam pass date to accumulate and submit the required experience. This mirrors how our CISSP experience requirements guide describes the equivalent (ISC)² path — pass first, then formalize the credential once your work history catches up.
What CISA Certification Costs
| Item | ISACA Member | Nonmember |
|---|---|---|
| Exam registration fee | US$575 | US$760 |
| Application processing fee (one-time, after passing) | US$50 | US$50 |
| Annual maintenance fee | US$45 | US$85 |
Once you register for the exam, you have a six-month eligibility window to sit for it. Many employers with internal audit or IT governance functions cover the exam fee as part of professional development, particularly at firms where CISA is a stated requirement for senior audit roles.
CISA vs CISM: IT Audit vs Security Management
CISA and CISM are both ISACA certifications, both require five years of relevant experience, and both are frequently pursued by the same population of mid-career security and governance professionals — which is exactly why they get confused.
| Factor | CISA | CISM |
|---|---|---|
| Core focus | Auditing, assessing, and reporting on IT controls and governance | Building and managing an information security program |
| Domains | 5 domains (audit process, governance, systems development, operations/resilience, asset protection) | 4 domains (security governance, risk management, security program, incident management) |
| Best fit for | IT auditors, assurance professionals, compliance analysts | Security managers, CISOs, security program leads |
| Experience required | 5 years in audit/control/assurance/security (up to 3 years waivable) | 5 years in information security management across 3+ domains |
| Exam length | 3 hours, 150 questions | 150 questions |
| Mindset tested | ”Does this control actually work, and can I prove it?" | "How do I run a security program that manages risk to the business?” |
The practical distinction: CISA asks you to independently verify and report on whether systems and controls are working as designed. CISM asks you to design, run, and be accountable for the program those controls belong to. If you enjoy investigating, testing, and documenting evidence, CISA fits. If you’d rather set security strategy and manage the people and budget behind it, CISM fits.
It’s also common to hold both. Auditors who move into security leadership roles — or security managers who want stronger credibility on the controls-testing side — frequently add the second credential a few years after the first. See our CISA vs CISM: which to take first guide for a decision framework based on your current role and target direction, and our CISSP vs CISM comparison if you’re also weighing the broader (ISC)² security-architecture track against ISACA’s management-focused credential.
Career Paths for CISA Holders
CISA opens a fairly linear career track, since the certification maps closely to job titles in audit and assurance functions:
- IT Auditor → Senior IT Auditor → IT Audit Manager, typically within internal audit departments at enterprises or through Big 4 and mid-tier consulting firms
- IS Risk and Assurance Consultant, advising clients on control design and regulatory compliance (SOX, ISO 27001, industry-specific frameworks)
- IT Governance / Compliance Analyst, working alongside legal and risk teams on policy and framework alignment
- Director of IT Audit or Chief Audit Executive (CAE) track, for professionals who stay on the audit leadership path long-term
In markets with strengthening financial and data-protection regulation, demand for CISA-credentialed auditors tends to track closely with regulatory enforcement activity — organizations need people who can independently confirm their controls hold up under scrutiny, not just people who built the controls in the first place.
Sources
- ISACA — CISA Certification
- ISACA — CISA Exam Content Outline
- ISACA — Earn a CISA Certification
- ISACA Support — CISA certification requirements
- ISACA Support — Costs associated with ISACA certification
- ISACA — CISA Exam Updated to Reflect Innovations and Evolving Technologies Impacting IT Audit (2024)
Fees, domain weights, and requirements reflect ISACA’s published guidance as of September 2026. ISACA updates certification requirements periodically — verify current figures on isaca.org before registering.
FAQ
Q: What does CISA stand for?
Certified Information Systems Auditor, issued by ISACA. It certifies the ability to audit, control, monitor, and assess an organization’s information systems and business processes.
Q: How many questions are on the CISA exam, and how long is it?
150 questions over 3 hours, computer-based, delivered at PSI testing centers or via remote proctoring. A scaled score of 450 out of 800 is required to pass.
Q: What are the CISA experience requirements?
Five years of professional experience in information systems auditing, control, assurance, or security, earned within the ten years before your application. Up to three years can be waived through qualifying education or other credentials.
Q: Can I take the CISA exam before I have five years of experience?
Yes. You can pass the exam first and have up to five years from your pass date to accumulate and submit the required experience for full certification.
Q: How much does CISA cost?
Exam registration is US$575 for ISACA members and US$760 for nonmembers, plus a one-time US$50 application processing fee after passing, and an annual maintenance fee of US$45 (members) or US$85 (nonmembers).
Q: Should I get CISA or CISM first?
Depends on direction. CISA fits IT audit, assurance, and controls-testing work. CISM fits security program management and leadership. Many professionals eventually hold both — see our CISA vs CISM guide for a fuller breakdown.
Conclusion
CISA remains the standard credential for professionals who verify — rather than build — an organization’s IT controls and governance. The path requires five years of qualifying experience (partially waivable), a focused pass through five exam domains weighted heavily toward operations, resilience, and information protection, and ongoing maintenance once certified.
If your career is heading toward audit leadership, risk and assurance consulting, or IT governance, CISA is the more direct credential than a security-management certification like CISM. If you’re still deciding between the audit track and the security-leadership track, our CISA vs CISM: which to take first guide walks through the decision in more detail, and our CISSP Certification Complete Guide covers the broader security-architecture credential if you’re weighing all three paths against each other.
FAQ
What does CISA stand for?
CISA stands for Certified Information Systems Auditor, a certification issued by ISACA for professionals who audit, control, monitor, and assess an organization's information systems and business processes.
How many domains does the CISA exam cover?
The CISA exam covers five domains: Information System Auditing Process (18%), Governance and Management of IT (18%), Information Systems Acquisition, Development and Implementation (12%), Information Systems Operations and Business Resilience (26%), and Protection of Information Assets (26%).
What are the CISA experience requirements?
You need a minimum of five years of professional work experience in information systems auditing, control, assurance, or security, gained within the ten years preceding your certification application. Up to three years can be waived with qualifying education or other ISACA certifications.
Is CISA or CISM better for my career?
CISA is built for IT audit, assurance, and control work — verifying that systems and processes are governed correctly. CISM is built for security management — leading and running a security program. Choose based on whether you want to audit and assess, or build and manage.
About the authors
Sekiko Jo
"Sekiko Jo" is the pen name used by Team Creative Lab’s security editorial desk. Articles are written and reviewed by an editor-in-chief who holds CISSP, CCSP and the Registered Information Security Specialist (情報処理安全確保支援士) credential, with a focus on cloud threat modeling and security governance.
Registered Information Security Specialist (情報処理安全確保支援士), Japan