Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Careers

CISA Salary in 2026: What IT Auditors Actually Earn

K
Ken Sahs Training Camp
Published
Read Time 14 min read
CISA Salary in 2026: What IT Auditors Actually Earn

ISACA puts the average CISA salary above $149,000. ZipRecruiter says $109,713. Glassdoor’s base pay figure lands closer to $93,000. Three credible sources, one credential, and a spread wide enough to buy a car with.

Every one of those numbers is defensible. They measure different populations and different kinds of pay, and one of them leans on a job classification that doesn’t cleanly exist in federal data. Which figure applies to you depends on where you sit now and where you’re trying to go next, and that is the part most salary pages skip entirely. So here is the honest version, with the reasons the numbers fight each other and a realistic read on what the Certified Information Systems Auditor credential is actually worth to your paycheck.

A realistic range for a working CISA holder in the United States in 2026 is $95,000 to $140,000, with audit managers and directors clearing that ceiling and first-year auditors sitting below the floor.


What Is the Average CISA Salary in 2026?

The average CISA salary in the United States sits somewhere between $109,000 and $123,000 depending on which aggregator you trust, with ISACA’s own member survey reporting a much higher figure above $149,000. Pull all four major sources together and the picture gets clearer, because the disagreement itself is informative.

Source Reported Figure What It Actually Measures
ISACA $149,000+ Self-reported total pay from ISACA’s own certified population, which skews senior and global
Payscale (March 2026) $123,000 average base Base salary only, no bonus, from about 1,255 self-reported US profiles
ZipRecruiter (June 2026) $109,713 average Advertised pay on job postings mentioning CISA, including roles where it is only preferred
Glassdoor (May 2026) $93,000 average base Base pay only, weighted toward individual contributors earlier in their careers

ZipRecruiter’s percentile spread is the most useful single view of the market. The 25th percentile lands at $94,000, the 75th at $123,500, and the top ten percent of postings reach $140,500. That maps almost exactly to the range I quoted at the top, and it is the band most people should plan against.


Why Do CISA Salary Estimates Disagree So Much?

Three things drive the fifty thousand dollar gap, and none of them mean anybody is lying to you.

Who answers the survey. ISACA collects pay data from people who are already certified, already members, already engaged enough to fill out a questionnaire. That population runs older, more senior, and more likely to hold a second or third credential. Nobody with two years of experience and a fresh CISA is padding out that sample. A number gathered from established practitioners is a fine number, it just is not a starting salary.

Base pay versus everything else. Glassdoor and Payscale report base salary. ISACA reports what people say they earn, which in banking and consulting quietly includes bonus. In financial services an audit manager’s bonus can run twenty to thirty percent, so the same person shows up as a $115,000 employee on one site and a $145,000 earner on another. Both are accurate. They are answering different questions.

The federal data has no box to put you in. This one is the real culprit and almost nobody mentions it. The Bureau of Labor Statistics does not track “IT auditor” as an occupation. CISA holders get scattered across two codes with wildly different pay. Some land under Information Security Analysts, where the median wage was $124,910 in May 2024. Others get counted under Accountants and Auditors, where the median was $81,680. Same credential, same skill set, a $43,000 difference depending on which department signs your paycheck. Every aggregator scraping government and posting data inherits that split, which is why their averages drift so far apart.

The practical takeaway from that classification split is worth acting on. If your CISA sits inside a security or technology organization, you are on the higher pay scale. Sit inside internal audit reporting up through finance and you are on the lower one. Same certification, different org chart, and the org chart is doing most of the work. Most people looking to raise a CISA salary reach for another credential. Moving the role does more, and it does it faster.


What Do CISA Holders Earn by Job Title?

Job title moves the number more than any other single factor, including geography. Here is roughly where the common CISA roles land in 2026, drawn from aggregated posting and reported-pay data rather than any one source.

💼 CISA Pay by Role, 2026
IT AUDITOR

$75,000 to $105,000. The entry point for most CISA holders. Pay here is heavily shaped by whether you sit in a Big Four practice, a corporate internal audit team, or a regional firm.

SENIOR IT AUDITOR

$100,000 to $130,000. Where the CISA starts paying for itself. At this level the credential is frequently a posted requirement rather than a nice extra.

IT AUDIT MANAGER

$120,000 to $155,000. Add a bonus on top in banking and insurance. Managing audit staff and owning the annual plan is what unlocks this tier.

GRC MANAGER

$125,000 to $160,000. The lateral move a lot of auditors make and rarely regret. Sitting on the security side of the house rather than the finance side tends to carry a premium.

IT AUDIT DIRECTOR

$150,000 to $200,000+. Reporting to the audit committee. By this point the CISA is table stakes and your track record is doing the negotiating.

Notice the shape of that ladder. The jump from auditor to senior auditor is worth roughly $25,000, and the jump from senior to manager is worth about the same again. Neither of those jumps has much to do with the letters after your name. What earns them is running engagements, writing findings that hold up when the business pushes back, and eventually owning an audit plan and the people executing it.


Which Industries Pay CISA Holders the Most?

Banking and financial services pay the most, and it is not close. Regulatory examination cycles, Sarbanes-Oxley IT general controls, and PCI DSS obligations create a permanent internal demand for people who can audit systems and defend the workpapers. Insurance runs a close second for the same reasons. If one industry choice moves your number more than any other, that is it, and I have written more about which ISACA certifications actually carry weight in banking if you want to go deeper on that.

Public accounting and consulting pay competitively but extract it in hours. A Big Four IT audit senior making $105,000 and working sixty-hour weeks during busy season is earning less per hour than a corporate internal auditor at $95,000 who goes home at six. Run that math before you take the offer, because the headline number is not the whole trade.

Federal contracting and defense sit in an interesting middle. Base salaries tend to run slightly below commercial banking, but clearance-adjacent audit roles are sticky, the work is steady, and the demand does not evaporate when the economy turns. Healthcare pays a bit below both, though HIPAA-driven audit demand keeps it reliable. Retail and manufacturing usually sit at the bottom of the range unless the company is large enough to have a real audit function.


Does CISA Actually Raise Your Salary?

ISACA reports that 22 percent of CISA holders received a pay boost tied to the certification. Read that number carefully, because it cuts both ways. Roughly one in five got a raise out of it. Which means four in five did not, at least not immediately.

That is the honest framing I give people before they spend the money. The CISA is a gate, not a raise. It does not make your current employer hand you fifteen thousand dollars because you passed a test in March. What it does is get your resume past the filter on jobs that list it as required, and there are a lot of those. Search any major job board for IT audit roles at the senior level and up, and you will find the credential named in the requirements section far more often than it is named in the nice-to-have section. That is the whole mechanism. The certification buys you access to the roles that pay more, and after that you still have to interview well and do the job.

Where it moves the needle fastest is at the transition points. Somebody sitting at $85,000 as a systems administrator who wants into IT audit, or a financial auditor who keeps getting pushed off the technology engagements, gets far more out of the CISA than a person already running an audit team. A manager who already holds the seat is using the credential to defend ground. Somebody trying to get into audit from a systems background is using it to cross the line in the first place, which is a far more valuable job for it to do.


What Does CISA Cost, and How Long Until It Pays Back?

The exam registration runs $575 for ISACA members and $760 for non-members, with a one-time $50 application processing fee once you pass. Membership costs around $135 a year plus local chapter dues, so joining before you register generally pays for itself on the exam discount alone. After you certify, the annual maintenance fee is $45 for members or $85 for non-members, and you owe 120 continuing professional education hours over each three-year cycle with a minimum of 20 hours annually.

Preparation is the variable. Self-study with the official review manual and a question bank might run $400 to $600. Structured boot camp training typically lands between $2,500 and $4,500. Most candidates end up somewhere in the middle, all in for $1,000 to $3,000 counting the exam.

The payback math: if the CISA is what moves you from an $85,000 role into a $105,000 role, a $2,500 total investment clears in about six weeks of the new salary. That is a real return and it is why the certification keeps its reputation. The thing that catches people is not the price. Between studying, sitting the exam, waiting on the application, and actually landing the new job, you are realistically eight to fourteen months from spending the money to seeing the raise. Budget your patience accordingly.

One structural detail catches people off guard. You can sit the exam before you have the experience, and you then have five years from your passing date to submit the application. The requirement is five years of professional information systems auditing, control, assurance, or security experience earned within the ten years before you apply, with up to three years waivable. An associate’s degree waives one year, a bachelor’s waives two, and a master’s in information systems or a related field waives three. A lot of candidates take the exam early, bank the pass, and file the paperwork when they qualify. If you want the full picture of what the exam covers, that is a separate conversation and I have laid out the domain-by-domain breakdown here.


Who Should Skip the CISA?

Plenty of people, and I would rather tell you now than after you have spent the money.

If you are a hands-on engineer with no interest in the assurance side of the business, the CISA will not pay you. It tests whether you can evaluate a control, not whether you can build one, and the day job it qualifies you for involves a lot of documentation, evidence sampling, and meetings with people who do not want to be audited. Some engineers discover they love that work. Most find out the hard way that they don’t, and they finish with a credential they never use.

If your target is security management rather than audit, the CISM is the better spend, and the comparison between the two is worth an honest read before you commit. Enterprise risk points you toward CRISC instead. And somebody two years into their career with no audit exposure at all should wait a while. The credential still makes sense for them eventually, just not yet. Get the experience started, then certify into the seniority you are already approaching. Broader options across the governance and compliance track are covered in our rundown of the best certifications for GRC careers.

🎯 What the Numbers Actually Tell You

Plan against $95,000 to $140,000 and treat ISACA’s $149,000 figure as a picture of where the credential can take you, not where it starts you. The certification’s real value is access, since it clears the requirements filter on senior audit roles that pay $25,000 to $40,000 more than the ones you can reach without it. Where you sit in the org chart matters more than most people realize, and a CISA inside a security organization outearns the identical CISA inside internal audit by a wide margin. Before you register for the exam, get clear on which of those two chairs you want, because that decision is worth more to your salary than the credential is.


Frequently Asked Questions About CISA Salary

How much does a CISA make in 2026?

A working CISA holder in the United States typically earns $95,000 to $140,000, with ZipRecruiter reporting an average of $109,713 and Payscale reporting an average base of about $123,000 as of 2026. ISACA’s own member data reports an average above $149,000, which reflects a more senior and self-selected population. Audit directors and CISOs regularly clear $150,000, while first-year IT auditors commonly start in the $75,000 to $90,000 range.

Is CISA worth it for the salary alone?

For someone moving into IT audit or up into senior audit roles, yes, because the credential is a posted requirement on a large share of those jobs and a $2,500 investment clears quickly against a $20,000 salary jump. Somebody already established as an audit manager has a weaker case, since experience is doing most of the work at that point. ISACA reports that 22 percent of holders received a pay boost tied to the certification, so treat it as an access credential rather than an automatic raise.

Does CISA or CISM pay more?

CISM generally reports higher average pay because it maps to security management roles, which sit closer to the CISO track and carry larger bonus components. The gap is a function of the job, not the difficulty of the exam. An IT audit director with a CISA will outearn a security analyst with a CISM, so the more useful question is which career track you want rather than which credential has a bigger headline number.

What is the entry-level CISA salary?

Entry-level IT auditors with a CISA generally start between $75,000 and $90,000, with public accounting firms and large banks at the upper end of that band and smaller regional employers at the lower end. Because ISACA requires five years of experience for full certification, a true entry-level CISA holder is uncommon. Most people passing the exam early hold the pass and apply once they qualify, which means the certified population skews toward mid-career pay.

Which industry pays CISA holders the most?

Banking and financial services pay CISA holders the most, driven by regulatory examination cycles, Sarbanes-Oxley IT general controls testing, and PCI DSS obligations that create permanent internal audit demand. Insurance follows closely. Consulting and public accounting pay competitively but require significantly longer hours, so the effective hourly rate is often lower than a corporate internal audit role at a similar salary.

How much does the CISA certification cost?

The CISA exam costs $575 for ISACA members and $760 for non-members, plus a one-time $50 application processing fee after you pass. ISACA membership runs about $135 annually plus chapter dues, and the annual maintenance fee once certified is $45 for members or $85 for non-members. Adding preparation materials or training, most candidates spend $1,000 to $3,000 in total.

Do you need five years of experience to earn a CISA?

You need five years of professional information systems auditing, control, assurance, or security experience earned within the ten years before you apply, though up to three years can be waived. An associate’s degree waives one year, a bachelor’s waives two, and a master’s in information systems or a related field waives three. You can sit the exam before meeting the requirement and have five years from your passing date to submit the application, which is what most early-career candidates do.

Ken Sahs

Vice President of Sales. Training Camp

Ken Sahs is the Director of Sales at Training Camp, where he leads the company's sales team and oversees all ISACA certification programs. He helps organizations navigate the world of IT governance and risk management certifications – including CISA, CISM, and CRISC. He works directly with enterprise clients to create training programs that not only get their teams certified but also solve real business challenges.