Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Certification Guide

The Certified in Risk and Information Systems Control (CRISC)
Certification Explained.

Everything you need to know about ISACA's IT risk management certification as of 2026, covering the four domains of the exam content outline that took effect November 3, 2025, the exam format, the three-year experience requirement, career paths, DoD 8140 status, and how CRISC compares to CISM, CISA, and CGRC. A complete reference for anyone weighing the CRISC or trying to understand what it covers.

CRISC_FAST_FACTS
Issuer: ISACA
Exam: 150 questions, 4 hours
Passing Score: 450 / 800
Experience: 3 years across 2+ domains
On the DoD 8140 Approved Qualifications Matrix
4 CRISC Domains 3 YRS Experience Required 150 Exam Questions 4-HOUR Exam 30K+ CRISC Holders
UPDATED 2026
Overview

What Is the Certified in Risk and Information Systems Control (CRISC)?

CRISC is ISACA's certification for IT and enterprise risk management. ISACA reports that more than 30,000 professionals hold it.

It validates the ability to identify and assess IT risk, choose and own a response, design and test the controls that keep risk inside tolerance, and report on all of it in language the business understands. The exam isn't asking whether you can run a vulnerability scan. It asks what the scan result means for the organization, which response fits the agreed risk appetite, and how you'll know the control is still working a year from now.

The credential requires three years of risk and control experience with no waivers, which keeps it in mid-career and senior territory. It is listed on the DoD 8140 Approved Qualifications Matrix, and it is issued and maintained by ISACA, the same association behind CISA and CISM.

30K+ Holders (ISACA)
4 Domains
3 Yr Experience
The CRISC Domains

Four Domains of Practice

01

Governance

Organizational governance and risk governance: frameworks, three lines of defense, appetite and tolerance. 26% of the exam.

02

Risk Assessment

Identifying risk events, threats, and scenarios, then analyzing likelihood, impact, and control gaps. 22% of the exam.

03

Risk Response and Reporting

Response options, control design and testing, KRIs and KCIs, and reporting. The heaviest domain at 32%.

04

Technology and Security

Enterprise architecture, IT operations, SDLC, security frameworks, continuity, and privacy. 20% of the exam.

Why CRISC Matters

Why Is CRISC So Widely Recognized?

Four things that have made CRISC the credential most often named when an employer describes an IT risk hire.

Built for the Risk Practitioner, Not the Auditor or the Engineer

An auditor asks whether the control was followed. An engineer asks whether it was configured. CRISC sits between them and asks something different: does this risk matter to the business, what should be done about it, and how will anyone know it worked. The exam is scenario based and rewards judgment about appetite, ownership, and response over technical recall.

A Shared Language With the Business

Risk appetite, tolerance, KRIs, and the three lines of defense are the vocabulary boards and executives already use. CRISC certifies that you speak it, which is why it appears in postings for risk managers, GRC leads, and control owners in finance, healthcare, government, and technology alike.

Pay Follows the Role

CRISC holders tend to sit in risk management and GRC roles rather than practitioner roles, and pay follows the role rather than the badge. Our look at the highest paying IT certifications explains how to read the salary surveys without being misled by them.

On the DoD 8140 Approved Qualifications Matrix

CRISC is listed on the DoD 8140 Approved Qualifications Matrix, the list of certifications that count toward foundational qualification under DoD Manual 8140.03. The matrix maps each credential to specific DoD Cyber Workforce Framework (DCWF) work roles and proficiency levels, and those mappings change as the matrix is revised.

Before relying on CRISC for a specific position, check the current matrix for the work role and proficiency level you are being hired against. The current version is published at the DoD Cyber Exchange.

Listed on the Matrix DCWF Role Mapped Verify Current Version
Fast Facts

What Are the Key Facts About CRISC?

Everything you need to know about the certification, the exam structure, and how to maintain CRISC as of September 2026.

01

The Certification

Certification Name
Certified in Risk and Information Systems Control (CRISC)
Issued By
ISACA
Exam Outline
Effective November 3, 2025
Domains
4
Prerequisites
3 yrs across 2+ domains (one in Domain 1 or 2)
Experience Waiver
None offered by ISACA
Experience Window
10 yrs before applying or 5 yrs after passing
Test-First Path
Pass exam, apply within 5 years
DoD 8140 Status
On the Approved Qualifications Matrix
02

Exam & Maintenance

Exam Format
Multiple choice, scenario based
Number of Items
150 questions
Exam Duration
4 hours (240 minutes)
Passing Score
450 on a 200 to 800 scale
Exam Cost
$575 member / $760 non-member
Delivery
PSI test centers or online proctored, year-round
Validity
3 years
CPE Requirement
120 CPE hours over 3 years (20 min/yr)
Maintenance
Annual maintenance fee to ISACA
Going Deeper

What Comes After the CRISC?

CRISC puts you at the center of the risk program. From there, people tend to move toward running the security program, governing IT at the enterprise level, or auditing it. These are the credentials that most often come next, and CISM and CISA share the CRISC exam format.

CISM (Security Management)

ISACA's Certified Information Security Manager moves from owning risk to owning the whole security program: governance, risk, program management, and incident management. It requires five years of information security experience, three of them in management. See our CISM guide.

CGEIT (Governance)

ISACA's Certified in the Governance of Enterprise IT goes deep on IT governance at the enterprise level. It suits risk professionals moving toward board-level governance.

CISA (Audit)

ISACA's Certified Information Systems Auditor covers information systems audit and assurance across five domains. It requires five years of IS audit, control, or security experience and is the natural next step for CRISC holders who spend their time evidencing controls. See our CISA guide.

Certification Roadmap

Where Does CRISC Fit in Your Career?

CRISC is rarely a first certification. It sits at the point where a security, audit, or IT career turns toward risk ownership, building on foundational credentials and leading into management, governance, audit, and federal authorization paths.

STAGE 02 You Are Here

Risk Credential

The pivot point

PRIMARY
CRISC
ISACA · Certified in Risk and Information Systems Control
Test-First Path
ISACA · Pass first, apply within 5 years
STAGE 03

Specialize

Pick your path

Management
Governance & Audit
Federal Authorization
Decision Point

Is CRISC Right For You?

Two questions to answer before you commit: can you certify, and should you pursue CRISC specifically. Here's a straight answer to both.

Q1

Do You Qualify for CRISC?

Path A

3+ Years Across Two Domains

You can certify in full.

You have at least three years of cumulative work experience performing CRISC tasks across two or more of the four domains, and one of those two is Governance or Risk Assessment. The work falls within the ten years before you apply. ISACA offers no waivers for CRISC, so the three years have to be real experience. Pass the exam, submit your application, and you hold the full CRISC.

Path B

Not Quite at the Experience Bar

You can still pass now.

Sit the exam before you meet the full requirement. Once you pass, you have five years to submit your application as you finish earning the experience, and work done in those five years counts. The exam never has to wait on your resume, and a passed exam on a resume tends to open the risk roles that produce the experience.

Q2

Is CRISC the Right Certification for Your Goals?

CRISC Is a Strong Fit If...

  • You already own or want to own the IT risk register, the assessment cycle, or the controls that keep risk in tolerance
  • You work in GRC, third-party risk, or compliance and want the credential that names that work directly
  • You keep seeing CRISC listed as required or preferred for the risk manager and GRC roles you want
  • You spend your days translating technical findings into likelihood, impact, and decisions for people who don't read scan output
  • You need a credential on the DoD 8140 Approved Qualifications Matrix and your work is risk rather than operations
  • You want an ISACA credential that asks for three years of experience instead of the five that CISM and CISA require

Consider Alternatives If...

  • You're early in your career without security fundamentals yet, start with Security+ or CC first
  • You want to run the security program as a manager, where CISM is the direct credential
  • Your work centers on IT audit and assurance, where CISA is the tighter fit
  • Your job is building and defending federal authorization packages, where CGRC is purpose built
  • You want a deeply hands-on technical track and prefer performance-based exams, look at CySA+ or PenTest+
  • You don't yet work in or near risk management and the scenario questions would feel abstract
Career Paths

What Jobs Can You Get With CRISC?

CRISC maps to risk, governance, and controls roles across the private sector and government. These are the six titles where the credential shows up most often in postings and on the resumes of the people who hold them.

Risk Management

IT Risk Manager

Owns the IT risk register, runs the assessment cycle, and reports risk against appetite to leadership. The role CRISC was written for, and the one where postings most often list it as required or preferred.

Risk Assessment

Cyber Risk Analyst

Identifies threats and vulnerabilities, builds risk scenarios, and turns technical findings into likelihood and impact the business can act on. Domains 1 and 2 of the outline are this job description.

Governance

GRC Analyst / GRC Manager

Keeps policies, controls, and regulatory obligations lined up across the organization. CRISC covers the governance frameworks, three lines of defense, and control testing that fill a GRC calendar.

Vendor Risk

Third-Party Risk Manager

Assesses and monitors the risk that vendors, cloud providers, and partners bring inside the perimeter. Third-party risk is called out by name in Domain 3 of the CRISC outline.

Controls

IT Controls and Compliance Manager

Designs, implements, and tests the controls that keep risk inside tolerance, then evidences that for auditors and regulators. Control ownership and KCIs sit at the center of the exam's heaviest domain.

Leadership

Head of Enterprise Risk / CRO

Sets risk appetite with the board and answers for the enterprise risk program. CRISC is one of the credentials risk leaders hold when technology risk is a large share of what they oversee.

Comparison

How Does CRISC Compare to CISM, CISA, and CGRC?

Four governance, risk, and compliance credentials that get shortlisted together. Three share an issuer and an exam format; the fourth comes from ISC2 and aims at federal authorization work. Here's how they line up.

  CRISC CISM CISA CGRC
Issuer ISACA ISACA ISACA ISC2
Focus IT and enterprise risk, controls Security management and governance Information systems audit System authorization and compliance
Domains 4 4 5 7
Exam Format 150 questions, 4 hours 150 questions, 4 hours 150 questions, 4 hours Linear, 125 items, 3 hrs
Experience 3 yrs across 2+ domains 5 yrs infosec, 3 in management 5 yrs IS audit, control, or security 2 yrs in 1 or more domains
Passing Score 450 / 800 450 / 800 450 / 800 700 / 1000
Exam Cost $575 member / $760 non-member $575 member / $760 non-member $575 member / $760 non-member ~$599
Renewal 120 CPEs over 3 years 120 CPEs over 3 years 120 CPEs over 3 years 60 CPEs over 3 years
DoD 8140 Approved Yes (check current matrix for roles) Yes (Advanced) Yes (Advanced) Yes (Intermediate)
Best For IT risk managers, GRC and controls professionals Security managers and governance leads IT auditors and assurance pros Assessors, ISSOs, GRC practitioners

Pricing and renewal details vary by region and membership status. Many practitioners eventually hold more than one of these credentials, and CRISC plus CISA or CISM is a common pairing.

Ready to Get Certified

Train for CRISC with Training Camp.

Training Camp is an award-winning ISACA Elite+ Training Partner. Our official ISACA CRISC boot camp covers all four domains of the November 2025 outline over three days, with your exam voucher, official ISACA courseware, and a free retake included. To see the question style before you commit, take the CRISC practice test.

View Boot Camp
Dive Deeper

CRISC Articles and Guides.

DoD 8140 mapping, CPE rules, neighboring GRC credentials, salary context, and exam-day logistics for CRISC candidates.

Featured DoD 8140

Which Certifications Qualify for DoD 8140 Work Roles? A DCWF Map

How the DoD 8140 Approved Qualifications Matrix maps certifications to DCWF work roles and proficiency levels, and where ISACA credentials like CRISC land. Read this before assuming a credential qualifies you for a specific position.

Read Article →
Maintenance

CPE Requirements by Certification Body: A Complete Comparison

ISACA wants 120 CPE hours every three years with a 20-hour annual floor. Here is how that stacks up against ISC2, CompTIA, and the other bodies, and how to earn the hours without paying for them twice.

Read Article →
Comparison

CGRC Certification: The ISC2 Credential for ATO and Authorization Work

CGRC is the credential people compare against CRISC most often when the work is federal. What it covers, who it is for, and why the two are complements more often than rivals.

Read Article →
Salary

CISA Salary in 2026: What IT Auditors Actually Earn

CRISC and CISA holders often work side by side. A sober look at what the audit side of the house earns, where the figures come from, and how to read salary surveys without being misled.

Read Article →
Decision Guide

Is the CDPSE Worth It? Who the Certification Is Actually For

ISACA's privacy engineering credential overlaps with the data privacy content in CRISC Domain 4. When it makes sense to add it, and when CRISC already covers what you need.

Read Article →
Career Value

The Highest Paying IT Certifications in 2026 (And What Those Numbers Actually Mean)

Risk and governance credentials show up near the top of most salary lists. What those rankings measure, what they leave out, and how to use them when deciding whether CRISC is your next move.

Read Article →
Exam Day

Certification Exam Day Rules: ID, Breaks, Proctoring, and Retakes Compared Across Vendors

What to expect at a PSI test center or in an online proctored session for an ISACA exam, from ID checks to break rules, and how the retake policies differ from ISC2 and CompTIA.

Read Article →
Curriculum

Inside the Four CRISC Domains.

The CRISC exam content outline is organized into four domains, each carrying its own weight on the exam. Click any domain for what it covers.

Domains 01-02

Governance to Assessment
01 Governance 26%

How the organization is set up to own risk: strategy, structure, culture, policies, business processes, and the assets that carry value. It also covers risk governance itself, including enterprise risk management frameworks, the three lines of defense, risk appetite and tolerance, legal and regulatory requirements, and professional ethics.

02 Risk Assessment 22%

Finding and sizing the risk. Risk identification covers events, threats, vulnerabilities, scenarios, and the risk register, while risk analysis and evaluation covers assessment methodologies, likelihood and impact, inherent and residual risk, and spotting control gaps.

Domains 03-04

Response to Technology
03 Risk Response and Reporting 32%

The heaviest domain on the exam. Choosing a risk response and assigning ownership, third-party risk, issue and exception management, designing, implementing, and testing controls, and the KRIs, KPIs, and KCIs that feed risk reporting and ongoing monitoring.

04 Technology and Security 20%

The technical context a risk practitioner has to understand without being the engineer: enterprise architecture, IT operations, project and change management, the SDLC, and emerging technologies. It also covers information security concepts, frameworks and standards, awareness training, business continuity, and data privacy principles.

Domains and weights reflect the ISACA CRISC Exam Content Outline effective November 3, 2025, which is the outline in use as of September 2026. To see how these domains feel in question form, try the free CRISC practice test.

Frequently Asked Questions

Common Questions About CRISC.

The questions candidates ask most often when researching the Certified in Risk and Information Systems Control certification.

What is the CRISC certification?

CRISC is ISACA's certification for IT and enterprise risk management. It validates the ability to identify and assess IT risk, choose and own a response, design and test the controls that keep risk inside tolerance, and report on all of it to the business. It's built for mid-career and senior professionals in risk, GRC, and controls roles.

Who should get the CRISC?

CRISC fits people who already work in or next to IT risk: risk managers and analysts, GRC staff, control owners, third-party risk managers, and security or audit professionals moving toward risk management. It isn't an entry-level certification. If you're starting out, Security+ or ISC2's CC is usually the better first step.

How much does the CRISC exam cost in 2026?

As of September 2026 the CRISC exam costs $575 for ISACA members and $760 for non-members. Many candidates join ISACA before registering, since the membership fee is often less than the exam discount that comes with it. Certification application fees are separate.

What is the CRISC exam like?

The CRISC exam is 150 multiple-choice questions over four hours (240 minutes). The questions are scenario based and ask for the most appropriate risk decision rather than a technical fact, so several answers often look reasonable. Scores are scaled from 200 to 800 and you need 450 to pass. It's delivered at PSI test centers or online with a remote proctor, year-round.

What experience do you need for CRISC?

CRISC requires a minimum of three years of cumulative work experience performing the tasks of a CRISC professional across at least two of the four domains, and one of those two must be Governance (Domain 1) or Risk Assessment (Domain 2). The experience has to fall within the ten years before you apply or within five years of passing the exam. ISACA offers no experience waivers for CRISC.

Can you take the CRISC exam before you have the experience?

Yes. You can sit and pass the exam first, then submit your certification application once you meet the experience requirement. ISACA gives you five years from your pass date to apply, so the exam never has to wait on your work history.

What are the four CRISC domains?

The four CRISC domains are Governance at 26 percent, Risk Assessment at 22 percent, Risk Response and Reporting at 32 percent, and Technology and Security at 20 percent. Risk Response and Reporting is the heaviest, and together with Governance the two make up more than half of the exam.

How do I maintain my CRISC certification?

CRISC is maintained on a three-year cycle. You earn 120 Continuing Professional Education (CPE) hours across the cycle, with a minimum of 20 hours each year, pay an annual maintenance fee to ISACA, and agree to follow the ISACA Code of Professional Ethics.

Is CRISC approved for DoD 8140?

Yes. CRISC is listed on the DoD 8140 Approved Qualifications Matrix (Version 2.1, effective September 19, 2025), which maps certifications to specific DoD Cyber Workforce Framework (DCWF) work roles and proficiency levels. Those mappings change as the matrix is revised, so check the current matrix at the DoD Cyber Exchange for the work role and level you're being hired against. See our DoD 8140 work role paths.

What is the difference between CRISC, CISM, and CISA?

All three come from ISACA and share the same exam format: 150 questions, four hours, 450 out of 800 to pass. CRISC focuses on IT risk and controls, CISM on running the security program as a manager, and CISA on information systems audit and assurance. CRISC asks for three years of experience while CISM and CISA ask for five. Many professionals hold two of the three.

How does CRISC compare to CGRC?

CGRC from ISC2 centers on system authorization and compliance, the assessment and authorization work common in federal environments, with 125 questions over three hours and a two-year experience requirement. CRISC is broader enterprise IT risk management with a three-year requirement. If your work is authorization packages, CGRC is the closer fit; if it's the organization's risk program, CRISC is.

Did the CRISC exam change in 2025?

Yes. ISACA's current CRISC Exam Content Outline took effect on November 3, 2025. It keeps four domains, Governance, Risk Assessment, Risk Response and Reporting, and Technology and Security, with Risk Response and Reporting carrying the most weight at 32 percent. This page describes that outline, and exams taken today test it.

Is CRISC worth it in 2026?

For professionals who own or want to own IT risk, CRISC remains the credential most directly tied to that work in 2026. It is recognized across industries, appears on the DoD 8140 Approved Qualifications Matrix, and carries the ISACA name that hiring managers in GRC already trust. It's less useful for people early in their careers or committed to a purely hands-on technical role.

Get In Touch

Have Questions About CRISC?

Tell us where you are, from weighing the certification to working out funding or planning training for a risk team, and we'll help you map out the right path.

+1
    100% Secure. NDA Compliant.
    ISACA CRISC Boot Camp 3-Day Boot Camp · Exam Voucher Included
    View Boot Camp