Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Certification Guide

The Certified Information Systems Auditor
Certification Explained.

Everything you need to know about ISACA's flagship IT audit certification as of 2026, covering the five domains, exam format, experience requirements, career paths, DoD 8140 status, and how CISA compares to CISM and CISSP. A complete reference guide for anyone weighing the CISA or trying to understand what it covers.

CISA_FAST_FACTS
Issuer: ISACA
Exam: 150 questions, 4 hours
Passing Score: 450 / 800
Experience: 5 years in IS audit
DoD 8140 Approved (Advanced)
5 CISA Domains 5 YRS Experience Required 150 Exam Questions 4-HOUR Exam SINCE 1978 ISACA Issued
UPDATED 2026
The CISA Domains

Five Domains of Practice

01

Information Systems Auditing Process

Audit planning, evidence, sampling, and reporting. 18% of the exam.

02

Governance and Management of IT

IT governance, strategy, policy, and regulatory alignment. 18% of the exam.

03

Acquisition, Development and Implementation

Controls across how systems are built and deployed. 12% of the exam.

04

Operations and Business Resilience

IT operations, continuity, and recovery. One of the two heaviest at 26%.

05

Protection of Information Assets

Security controls, access, and data protection. The other heavyweight at 26%.

Overview

What Is the Certified Information Systems Auditor?

CISA is ISACA's flagship IT audit certification, first administered in 1978 and held by more than 200,000 professionals worldwide today.

It validates the ability to audit, assess, and report on an organization's information systems and controls across five domains. The job is to answer one question with evidence behind it: are these systems and controls working the way they're supposed to? CISA is built entirely around that audit and assurance function.

The credential is ANAB-accredited under ISO/IEC 17024, approved under DoD 8140 at the Advanced level, and gated behind a five-year experience requirement. As one of the oldest IT certifications still in active use, it has long been the standard credential for the IT audit field. CISA is issued and maintained by ISACA, which has administered the program since 1978.

1978 First Administered
5 Domains
5 Yr Experience
Why CISA Matters

Why Is CISA So Widely Recognized?

Four things that have made CISA the credential most often named when employers describe an IT audit hire.

The Standard for IT Audit

In audit and compliance, CISA isn't one option among several. It's the credential. As one of the oldest IT certifications still in use, it has decades of employer recognition behind it, which is why job postings for IT audit roles so often name it by acronym.

Built on Evidence and Independence

CISA tests how you plan an audit, gather evidence, test controls, and report findings the right way. That focus on independent, evidence-based assurance is exactly what regulators, boards, and clients want to see behind an audit opinion.

Valued Across Regulated Industries

In banking and other regulated sectors, CISA is often treated as table stakes for senior audit roles. Our look at which ISACA certifications matter in banking digs into why.

DoD 8140 Approved

CISA is an approved foundational qualification under DoD Manual 8140.03 at the Advanced proficiency level, mapped to six work roles in the DoD Cyber Workforce Framework (DCWF) across the Cybersecurity, IT, and Cyberspace Enabler elements.

With element-level qualification now mandatory across the department, an approved credential like CISA is what lets people fill those audit and assessment roles. Current qualification matrices are published at the DoD Cyber Exchange.

Advanced Proficiency 6 DCWF Roles 3 Workforce Elements
Fast Facts

What Are the Key Facts About CISA?

Everything you need to know about the certification, the exam structure, and how to maintain CISA as of 2026.

01

The Certification

Certification Name
Certified Information Systems Auditor (CISA)
Issued By
ISACA
Exam Outline
Effective August 2024
First Administered
1978
Prerequisites
5 yrs IS audit, control, or security
Experience Waiver
Up to 3 years (education or experience)
Test-First Path
Pass exam, apply within 5 years
Accreditation
ANAB-accredited (ISO/IEC 17024)
DoD 8140 Status
Approved at Advanced (6 DCWF roles)
02

Exam & Maintenance

Exam Format
Multiple choice
Number of Items
150 questions
Exam Duration
4 hours
Passing Score
450 out of 800
Exam Cost
$575 member / $760 non-member
Registration
Continuous, 365-day eligibility
Validity
3 years
CPE Requirement
120 CPEs over 3 years (20 min/yr)
Maintenance
Annual maintenance fee to ISACA
Going Deeper

What Comes After the CISA?

CISA proves you can evaluate whether controls work. From there, professionals tend to broaden into risk, management, or enterprise governance. These ISACA credentials most often come next.

CRISC (Risk)

ISACA's Certified in Risk and Information Systems Control pairs naturally with CISA: where CISA evaluates whether controls work, CRISC is about managing the risk behind them. It requires three years of related experience.

CISM (Management)

The Certified Information Security Manager moves you from auditing programs to running them. CISA and CISM combine well for people who oversee audit functions and security management. It requires five years of experience.

CGEIT (Governance)

ISACA's Certified in the Governance of Enterprise IT goes deep on IT governance at the enterprise level. It suits CISA holders moving toward board-level governance work and requires five years of related experience.

Certification Roadmap

Where Does CISA Fit in Your Career?

CISA is the anchor credential for an IT audit career. It builds on general IT and security literacy and leads into risk, management, and enterprise governance paths as you take on more senior work.

STAGE 02 You Are Here

Audit Credential

The anchor

PRIMARY
CISA
ISACA · Certified Information Systems Auditor
Test-First Path
ISACA · Pass first, apply within 5 years
STAGE 03

Specialize

Pick your path

Risk & Governance
Management
Broad Security
Decision Point

Is CISA Right For You?

Two questions to answer before you commit: can you certify, and should you pursue CISA specifically. Here's a straight answer to both.

Q1

Do You Qualify for CISA?

Path A

5+ Years in Audit, Control, or Security

You can certify in full.

You have five years of professional information systems auditing, control, or security work experience. Up to three years can be substituted with education or related experience. Pass the exam, submit your application, and you hold the full CISA.

Path B

Not Quite at the Experience Bar

You can still pass now.

Sit the exam before you meet the full requirement. Once you pass, you have up to five years to submit your application as you finish earning the experience, so the exam never has to wait on your resume. Experience can count if it falls within the ten years before you apply.

Q2

Is CISA the Right Certification for Your Goals?

CISA Is a Strong Fit If...

  • Your work involves auditing information systems, evaluating controls, or assessing compliance with policy and regulation
  • You're building a career in IT audit, assurance, or compliance and want the credential employers expect
  • You need a DoD 8140 approved credential at the Advanced level for audit or assessment work in federal or contractor settings
  • You work in a regulated industry such as banking, where CISA is treated as table stakes for senior audit roles
  • You keep seeing CISA listed as required or preferred for the roles you want
  • You want a globally recognized credential with decades of standing behind it

Consider Alternatives If...

  • You're early in your career without IT or security fundamentals yet, start with Security+ or SSCP first
  • You want to run a security program rather than audit one, where CISM is the management fit
  • Your focus is enterprise IT risk specifically, where CRISC is purpose built
  • You want broad technical depth across the whole security field, where CISSP is the wider credential
  • You want a deeply hands-on technical track and prefer performance-based exams, look at PenTest+ or CySA+
  • You don't work in or near audit, control, or assurance and the questions would feel abstract
Career Paths

What Jobs Can You Get With CISA?

CISA maps to audit, assurance, and assessment roles across the private sector and the federal cyber workforce. Several of these are DCWF work roles where CISA qualifies at the Advanced level.

Audit

IT Program Auditor

Reviews how IT programs are governed, funded, and run against policy. DCWF work role 805, where CISA qualifies at the Advanced proficiency level. The role CISA was practically built for.

Audit and Assurance

Information Systems Auditor

Examines systems and controls to answer one question: are they working as intended? The core CISA career, spanning internal audit, external audit, and assurance work.

Assessment

Security Control Assessor

Evaluates whether security controls are implemented correctly and operating as intended. DCWF work role 612, where CISA qualifies at the Advanced level.

Audit Leadership

IT Audit Manager

Owns the audit function and the people who run it, setting scope and reporting findings to leadership. A senior path CISA holders move into with experience.

Program Delivery

IT Project Manager

Governs delivery of IT projects against scope, budget, and control requirements. DCWF work role 802, mapped to CISA at the Advanced level.

Assessment

Vulnerability Assessment Analyst

Identifies and assesses weaknesses across systems and applications. DCWF work role 541, where CISA qualifies at the Advanced level.

Comparison

How Does CISA Compare to CISM and CISSP?

All three are senior credentials, but they aim at different work: audit, management, and broad security. Here's how they line up.

  CISA CISM CISSP
Issuer ISACA ISACA ISC2
Focus Information systems audit Security management and governance Broad security across 8 domains
Exam Format 150 questions, 4 hours 150 questions, 4 hours Adaptive, 100 to 150 items, 3 hrs
Experience 5 yrs in IS audit, control, or security 5 yrs infosec, 3 in management 5 yrs in 2+ domains
Passing Score 450 / 800 450 / 800 700 / 1000
Renewal 120 CPEs over 3 years 120 CPEs over 3 years 120 CPEs over 3 years
DoD 8140 Approved Yes (Advanced) Yes (Advanced) Yes (Advanced)
Best For IT auditors and assurance pros Security managers and governance leads Architects and senior generalists

Pricing and renewal details vary by region and membership status. Many practitioners eventually hold more than one of these credentials.

Ready to Get Certified?

Train for CISA with Training Camp.

Our official ISACA CISA boot camp covers all five domains over four days, with your exam voucher, official courseware, and a free retake guarantee included, so experienced practitioners leave exam-ready.

View Boot Camp
Dive Deeper

CISA Articles and Guides.

Certification decisions, the ISACA family, GRC careers, and where CISA fits across industries.

Featured Decision Guide

CISA vs CISM: Which ISACA Cert Should You Pursue First?

A straight read on the two ISACA flagships: CISA is built around examining and evaluating systems, CISM around building and managing them. Which one fits the career you actually want.

Read Article →
ISACA Family

The Complete Guide to ISACA Certifications

How CISA fits alongside CISM, CRISC, and CGEIT in the ISACA family, what each one validates, and the order most professionals work through them as their careers grow.

Read Article →
GRC Careers

Best Certifications for GRC Careers

Governance, risk, and compliance hiring is a maze of overlapping credentials. Why CISA is the gold standard when your work centers on auditing systems and evaluating controls.

Read Article →
Industry Demand

Which ISACA Certifications Actually Matter in Banking?

A look at how banks treat ISACA credentials in hiring and pay, and why CISA is considered table stakes for senior audit roles across the financial sector.

Read Article →
Federal Contracting

What Cybersecurity Certifications Do Government Contractors Actually Require?

Where CISA shows up in federal contracting, from Inspector General support to compliance reviews and authorization-to-operate work, and how it sits alongside DoD 8140 requirements.

Read Article →
Getting Started

Entry-Level Cybersecurity Certifications for Beginners

A guide to the credentials that open the first door, including where audit and GRC-focused paths like CISA fit for people starting out in the field.

Read Article →
Risk and Compliance

Is CRISC Worth It? Breaking Down the ROI for Risk Professionals

CISA and CRISC complement each other: one proves you can evaluate whether controls work, the other that you can manage the risk behind them. A look at when the pairing pays off.

Read Article →
Curriculum

Inside the Five CISA Domains.

The CISA job practice is organized into five domains, each carrying its own weight on the exam. Click any domain for what it covers.

Domains 01-03

Audit to Development
01 Information Systems Auditing Process 18%

The core of the credential: audit standards and ethics, risk-based audit planning, evidence collection, sampling, data analytics, and how to report and communicate findings.

02 Governance and Management of IT 18%

IT governance and strategy, laws and regulations, organizational structure, policies and frameworks, and how IT management decisions support and protect the business.

03 Information Systems Acquisition, Development and Implementation 12%

Evaluating how systems are acquired, built, and deployed: project governance, controls in the development lifecycle, testing, and readiness for production.

Domains 04-05

Operations to Protection
04 Information Systems Operations and Business Resilience 26%

One of the two heaviest domains. IT operations, asset and configuration management, incident and problem handling, business continuity, and disaster recovery.

05 Protection of Information Assets 26%

The other heavyweight domain. Security controls, network and endpoint protection, identity and access, data classification, and physical and environmental safeguards.

Domains and weights reflect the ISACA CISA Exam Content Outline effective August 2024. ISACA updates the outline on a regular cycle.

Frequently Asked Questions

Common Questions About CISA.

The questions candidates ask most often when researching the Certified Information Systems Auditor certification.

What is the CISA certification?

CISA is ISACA's flagship IT audit certification. It validates the ability to audit, assess, and report on an organization's information systems and controls across five domains, and it's built for professionals working in IT audit, assurance, and compliance.

Who should get the CISA?

CISA fits professionals who audit information systems, evaluate controls, or assess compliance, including IT auditors, assurance specialists, and compliance and governance staff. It isn't a hands-on technical certification. If you're starting out, Security+ or SSCP is usually the better first step.

How much does the CISA exam cost in 2026?

As of 2026 the CISA exam costs $575 for ISACA members and $760 for non-members. There's also a separate certification application fee. Many candidates join ISACA before registering, since the membership fee is often less than the exam discount it unlocks.

What is the CISA exam like?

The CISA exam is 150 multiple-choice questions over a four-hour window. The questions test how you'd plan an audit, gather evidence, and evaluate controls the ISACA way, so the best answer is often a matter of judgment. You need a scaled score of 450 out of 800 to pass.

What experience do you need for the CISA?

CISA requires five years of professional information systems auditing, control, or security work experience. Up to three of those years can be substituted with education or related experience. Experience must fall within the ten years before applying or within five years after passing.

Can you take the CISA exam without the experience?

Yes. You can sit and pass the exam before you have the required experience, then submit your certification application once you meet it. You have up to five years after passing to complete the application, so the exam never has to wait on your work history.

What are the five CISA domains?

The five CISA domains are Information Systems Auditing Process, Governance and Management of IT, Information Systems Acquisition, Development and Implementation, Information Systems Operations and Business Resilience, and Protection of Information Assets. The last two are the heaviest, at 26 percent each.

How do I maintain my CISA certification?

CISA is maintained on a three-year cycle. You earn 120 Continuing Professional Education (CPE) credits across the cycle, with a minimum of 20 credits each year, and pay an annual maintenance fee to ISACA. You also agree to follow the ISACA Code of Professional Ethics.

Is CISA approved for DoD 8140?

Yes. CISA appears on the DoD 8140 Approved Qualifications Matrix V2.1 at the Advanced proficiency level, mapped to six DCWF work roles including Security Control Assessor, IT Program Auditor, and IT Project Manager. See the full DoD 8140 work role paths.

What is the difference between CISA, CISM, and CISSP?

CISA from ISACA focuses on information systems audit and assurance, CISM from ISACA focuses on security management and governance, and CISSP from ISC2 is a broad security credential spanning eight domains. Many professionals hold more than one and pick their first based on whether they're heading toward audit, management, or broad security.

Did the CISA exam change recently?

Yes. ISACA updated the CISA Exam Content Outline effective August 2024, keeping the same five domains but shifting the weights toward operations, business resilience, and protection of information assets. That outline is the one in force for 2026, with no new public refresh announced.

Is CISA worth it in 2026?

For professionals in or moving into IT audit, assurance, or compliance, CISA remains one of the strongest credentials available in 2026. It carries broad employer recognition, satisfies DoD 8140 at the Advanced level, and is treated as table stakes for senior audit roles in regulated industries. It's less useful for those on a purely hands-on technical track.

Get In Touch

Have Questions About CISA?

Whether you're weighing the certification, working out funding, or planning training for a team, tell us where you are and we'll help you map out the right path.

+1
    100% Secure. NDA Compliant.
    ISACA CISA Boot Camp 4-Day Boot Camp · Exam Voucher Included
    View Boot Camp