Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about ISACA's flagship IT audit certification as of 2026, covering the five domains, exam format, experience requirements, career paths, DoD 8140 status, and how CISA compares to CISM and CISSP. A complete reference guide for anyone weighing the CISA or trying to understand what it covers.
Audit planning, evidence, sampling, and reporting. 18% of the exam.
IT governance, strategy, policy, and regulatory alignment. 18% of the exam.
Controls across how systems are built and deployed. 12% of the exam.
IT operations, continuity, and recovery. One of the two heaviest at 26%.
Security controls, access, and data protection. The other heavyweight at 26%.
CISA is ISACA's flagship IT audit certification, first administered in 1978 and held by more than 200,000 professionals worldwide today.
It validates the ability to audit, assess, and report on an organization's information systems and controls across five domains. The job is to answer one question with evidence behind it: are these systems and controls working the way they're supposed to? CISA is built entirely around that audit and assurance function.
The credential is ANAB-accredited under ISO/IEC 17024, approved under DoD 8140 at the Advanced level, and gated behind a five-year experience requirement. As one of the oldest IT certifications still in active use, it has long been the standard credential for the IT audit field. CISA is issued and maintained by ISACA, which has administered the program since 1978.
Four things that have made CISA the credential most often named when employers describe an IT audit hire.
In audit and compliance, CISA isn't one option among several. It's the credential. As one of the oldest IT certifications still in use, it has decades of employer recognition behind it, which is why job postings for IT audit roles so often name it by acronym.
CISA tests how you plan an audit, gather evidence, test controls, and report findings the right way. That focus on independent, evidence-based assurance is exactly what regulators, boards, and clients want to see behind an audit opinion.
In banking and other regulated sectors, CISA is often treated as table stakes for senior audit roles. Our look at which ISACA certifications matter in banking digs into why.
CISA is an approved foundational qualification under DoD Manual 8140.03 at the Advanced proficiency level, mapped to six work roles in the DoD Cyber Workforce Framework (DCWF) across the Cybersecurity, IT, and Cyberspace Enabler elements.
With element-level qualification now mandatory across the department, an approved credential like CISA is what lets people fill those audit and assessment roles. Current qualification matrices are published at the DoD Cyber Exchange.
Everything you need to know about the certification, the exam structure, and how to maintain CISA as of 2026.
CISA proves you can evaluate whether controls work. From there, professionals tend to broaden into risk, management, or enterprise governance. These ISACA credentials most often come next.
ISACA's Certified in Risk and Information Systems Control pairs naturally with CISA: where CISA evaluates whether controls work, CRISC is about managing the risk behind them. It requires three years of related experience.
The Certified Information Security Manager moves you from auditing programs to running them. CISA and CISM combine well for people who oversee audit functions and security management. It requires five years of experience.
ISACA's Certified in the Governance of Enterprise IT goes deep on IT governance at the enterprise level. It suits CISA holders moving toward board-level governance work and requires five years of related experience.
CISA is the anchor credential for an IT audit career. It builds on general IT and security literacy and leads into risk, management, and enterprise governance paths as you take on more senior work.
Build the baseline
The anchor
Two questions to answer before you commit: can you certify, and should you pursue CISA specifically. Here's a straight answer to both.
You can certify in full.
You have five years of professional information systems auditing, control, or security work experience. Up to three years can be substituted with education or related experience. Pass the exam, submit your application, and you hold the full CISA.
You can still pass now.
Sit the exam before you meet the full requirement. Once you pass, you have up to five years to submit your application as you finish earning the experience, so the exam never has to wait on your resume. Experience can count if it falls within the ten years before you apply.
CISA maps to audit, assurance, and assessment roles across the private sector and the federal cyber workforce. Several of these are DCWF work roles where CISA qualifies at the Advanced level.
Reviews how IT programs are governed, funded, and run against policy. DCWF work role 805, where CISA qualifies at the Advanced proficiency level. The role CISA was practically built for.
Examines systems and controls to answer one question: are they working as intended? The core CISA career, spanning internal audit, external audit, and assurance work.
Evaluates whether security controls are implemented correctly and operating as intended. DCWF work role 612, where CISA qualifies at the Advanced level.
Owns the audit function and the people who run it, setting scope and reporting findings to leadership. A senior path CISA holders move into with experience.
Governs delivery of IT projects against scope, budget, and control requirements. DCWF work role 802, mapped to CISA at the Advanced level.
Identifies and assesses weaknesses across systems and applications. DCWF work role 541, where CISA qualifies at the Advanced level.
All three are senior credentials, but they aim at different work: audit, management, and broad security. Here's how they line up.
| CISA | CISM | CISSP | |
|---|---|---|---|
| Issuer | ISACA | ISACA | ISC2 |
| Focus | Information systems audit | Security management and governance | Broad security across 8 domains |
| Exam Format | 150 questions, 4 hours | 150 questions, 4 hours | Adaptive, 100 to 150 items, 3 hrs |
| Experience | 5 yrs in IS audit, control, or security | 5 yrs infosec, 3 in management | 5 yrs in 2+ domains |
| Passing Score | 450 / 800 | 450 / 800 | 700 / 1000 |
| Renewal | 120 CPEs over 3 years | 120 CPEs over 3 years | 120 CPEs over 3 years |
| DoD 8140 Approved | Yes (Advanced) | Yes (Advanced) | Yes (Advanced) |
| Best For | IT auditors and assurance pros | Security managers and governance leads | Architects and senior generalists |
Pricing and renewal details vary by region and membership status. Many practitioners eventually hold more than one of these credentials.
Our official ISACA CISA boot camp covers all five domains over four days, with your exam voucher, official courseware, and a free retake guarantee included, so experienced practitioners leave exam-ready.
Certification decisions, the ISACA family, GRC careers, and where CISA fits across industries.
A straight read on the two ISACA flagships: CISA is built around examining and evaluating systems, CISM around building and managing them. Which one fits the career you actually want.
How CISA fits alongside CISM, CRISC, and CGEIT in the ISACA family, what each one validates, and the order most professionals work through them as their careers grow.
Governance, risk, and compliance hiring is a maze of overlapping credentials. Why CISA is the gold standard when your work centers on auditing systems and evaluating controls.
A look at how banks treat ISACA credentials in hiring and pay, and why CISA is considered table stakes for senior audit roles across the financial sector.
Where CISA shows up in federal contracting, from Inspector General support to compliance reviews and authorization-to-operate work, and how it sits alongside DoD 8140 requirements.
A guide to the credentials that open the first door, including where audit and GRC-focused paths like CISA fit for people starting out in the field.
CISA and CRISC complement each other: one proves you can evaluate whether controls work, the other that you can manage the risk behind them. A look at when the pairing pays off.
The CISA job practice is organized into five domains, each carrying its own weight on the exam. Click any domain for what it covers.
The core of the credential: audit standards and ethics, risk-based audit planning, evidence collection, sampling, data analytics, and how to report and communicate findings.
IT governance and strategy, laws and regulations, organizational structure, policies and frameworks, and how IT management decisions support and protect the business.
Evaluating how systems are acquired, built, and deployed: project governance, controls in the development lifecycle, testing, and readiness for production.
One of the two heaviest domains. IT operations, asset and configuration management, incident and problem handling, business continuity, and disaster recovery.
The other heavyweight domain. Security controls, network and endpoint protection, identity and access, data classification, and physical and environmental safeguards.
Domains and weights reflect the ISACA CISA Exam Content Outline effective August 2024. ISACA updates the outline on a regular cycle.
The questions candidates ask most often when researching the Certified Information Systems Auditor certification.
CISA is ISACA's flagship IT audit certification. It validates the ability to audit, assess, and report on an organization's information systems and controls across five domains, and it's built for professionals working in IT audit, assurance, and compliance.
CISA fits professionals who audit information systems, evaluate controls, or assess compliance, including IT auditors, assurance specialists, and compliance and governance staff. It isn't a hands-on technical certification. If you're starting out, Security+ or SSCP is usually the better first step.
As of 2026 the CISA exam costs $575 for ISACA members and $760 for non-members. There's also a separate certification application fee. Many candidates join ISACA before registering, since the membership fee is often less than the exam discount it unlocks.
The CISA exam is 150 multiple-choice questions over a four-hour window. The questions test how you'd plan an audit, gather evidence, and evaluate controls the ISACA way, so the best answer is often a matter of judgment. You need a scaled score of 450 out of 800 to pass.
CISA requires five years of professional information systems auditing, control, or security work experience. Up to three of those years can be substituted with education or related experience. Experience must fall within the ten years before applying or within five years after passing.
Yes. You can sit and pass the exam before you have the required experience, then submit your certification application once you meet it. You have up to five years after passing to complete the application, so the exam never has to wait on your work history.
The five CISA domains are Information Systems Auditing Process, Governance and Management of IT, Information Systems Acquisition, Development and Implementation, Information Systems Operations and Business Resilience, and Protection of Information Assets. The last two are the heaviest, at 26 percent each.
CISA is maintained on a three-year cycle. You earn 120 Continuing Professional Education (CPE) credits across the cycle, with a minimum of 20 credits each year, and pay an annual maintenance fee to ISACA. You also agree to follow the ISACA Code of Professional Ethics.
Yes. CISA appears on the DoD 8140 Approved Qualifications Matrix V2.1 at the Advanced proficiency level, mapped to six DCWF work roles including Security Control Assessor, IT Program Auditor, and IT Project Manager. See the full DoD 8140 work role paths.
CISA from ISACA focuses on information systems audit and assurance, CISM from ISACA focuses on security management and governance, and CISSP from ISC2 is a broad security credential spanning eight domains. Many professionals hold more than one and pick their first based on whether they're heading toward audit, management, or broad security.
Yes. ISACA updated the CISA Exam Content Outline effective August 2024, keeping the same five domains but shifting the weights toward operations, business resilience, and protection of information assets. That outline is the one in force for 2026, with no new public refresh announced.
For professionals in or moving into IT audit, assurance, or compliance, CISA remains one of the strongest credentials available in 2026. It carries broad employer recognition, satisfies DoD 8140 at the Advanced level, and is treated as table stakes for senior audit roles in regulated industries. It's less useful for those on a purely hands-on technical track.
Whether you're weighing the certification, working out funding, or planning training for a team, tell us where you are and we'll help you map out the right path.