Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about ISACA's IT risk management certification as of 2026, covering the four domains of the exam content outline that took effect November 3, 2025, the exam format, the three-year experience requirement, career paths, DoD 8140 status, and how CRISC compares to CISM, CISA, and CGRC. A complete reference for anyone weighing the CRISC or trying to understand what it covers.
CRISC is ISACA's certification for IT and enterprise risk management. ISACA reports that more than 30,000 professionals hold it.
It validates the ability to identify and assess IT risk, choose and own a response, design and test the controls that keep risk inside tolerance, and report on all of it in language the business understands. The exam isn't asking whether you can run a vulnerability scan. It asks what the scan result means for the organization, which response fits the agreed risk appetite, and how you'll know the control is still working a year from now.
The credential requires three years of risk and control experience with no waivers, which keeps it in mid-career and senior territory. It is listed on the DoD 8140 Approved Qualifications Matrix, and it is issued and maintained by ISACA, the same association behind CISA and CISM.
Organizational governance and risk governance: frameworks, three lines of defense, appetite and tolerance. 26% of the exam.
Identifying risk events, threats, and scenarios, then analyzing likelihood, impact, and control gaps. 22% of the exam.
Response options, control design and testing, KRIs and KCIs, and reporting. The heaviest domain at 32%.
Enterprise architecture, IT operations, SDLC, security frameworks, continuity, and privacy. 20% of the exam.
Four things that have made CRISC the credential most often named when an employer describes an IT risk hire.
An auditor asks whether the control was followed. An engineer asks whether it was configured. CRISC sits between them and asks something different: does this risk matter to the business, what should be done about it, and how will anyone know it worked. The exam is scenario based and rewards judgment about appetite, ownership, and response over technical recall.
Risk appetite, tolerance, KRIs, and the three lines of defense are the vocabulary boards and executives already use. CRISC certifies that you speak it, which is why it appears in postings for risk managers, GRC leads, and control owners in finance, healthcare, government, and technology alike.
CRISC holders tend to sit in risk management and GRC roles rather than practitioner roles, and pay follows the role rather than the badge. Our look at the highest paying IT certifications explains how to read the salary surveys without being misled by them.
CRISC is listed on the DoD 8140 Approved Qualifications Matrix, the list of certifications that count toward foundational qualification under DoD Manual 8140.03. The matrix maps each credential to specific DoD Cyber Workforce Framework (DCWF) work roles and proficiency levels, and those mappings change as the matrix is revised.
Before relying on CRISC for a specific position, check the current matrix for the work role and proficiency level you are being hired against. The current version is published at the DoD Cyber Exchange.
Everything you need to know about the certification, the exam structure, and how to maintain CRISC as of September 2026.
CRISC puts you at the center of the risk program. From there, people tend to move toward running the security program, governing IT at the enterprise level, or auditing it. These are the credentials that most often come next, and CISM and CISA share the CRISC exam format.
ISACA's Certified Information Security Manager moves from owning risk to owning the whole security program: governance, risk, program management, and incident management. It requires five years of information security experience, three of them in management. See our CISM guide.
ISACA's Certified in the Governance of Enterprise IT goes deep on IT governance at the enterprise level. It suits risk professionals moving toward board-level governance.
ISACA's Certified Information Systems Auditor covers information systems audit and assurance across five domains. It requires five years of IS audit, control, or security experience and is the natural next step for CRISC holders who spend their time evidencing controls. See our CISA guide.
CRISC is rarely a first certification. It sits at the point where a security, audit, or IT career turns toward risk ownership, building on foundational credentials and leading into management, governance, audit, and federal authorization paths.
Build the baseline
The pivot point
Two questions to answer before you commit: can you certify, and should you pursue CRISC specifically. Here's a straight answer to both.
You can certify in full.
You have at least three years of cumulative work experience performing CRISC tasks across two or more of the four domains, and one of those two is Governance or Risk Assessment. The work falls within the ten years before you apply. ISACA offers no waivers for CRISC, so the three years have to be real experience. Pass the exam, submit your application, and you hold the full CRISC.
You can still pass now.
Sit the exam before you meet the full requirement. Once you pass, you have five years to submit your application as you finish earning the experience, and work done in those five years counts. The exam never has to wait on your resume, and a passed exam on a resume tends to open the risk roles that produce the experience.
CRISC maps to risk, governance, and controls roles across the private sector and government. These are the six titles where the credential shows up most often in postings and on the resumes of the people who hold them.
Owns the IT risk register, runs the assessment cycle, and reports risk against appetite to leadership. The role CRISC was written for, and the one where postings most often list it as required or preferred.
Identifies threats and vulnerabilities, builds risk scenarios, and turns technical findings into likelihood and impact the business can act on. Domains 1 and 2 of the outline are this job description.
Keeps policies, controls, and regulatory obligations lined up across the organization. CRISC covers the governance frameworks, three lines of defense, and control testing that fill a GRC calendar.
Assesses and monitors the risk that vendors, cloud providers, and partners bring inside the perimeter. Third-party risk is called out by name in Domain 3 of the CRISC outline.
Designs, implements, and tests the controls that keep risk inside tolerance, then evidences that for auditors and regulators. Control ownership and KCIs sit at the center of the exam's heaviest domain.
Sets risk appetite with the board and answers for the enterprise risk program. CRISC is one of the credentials risk leaders hold when technology risk is a large share of what they oversee.
Four governance, risk, and compliance credentials that get shortlisted together. Three share an issuer and an exam format; the fourth comes from ISC2 and aims at federal authorization work. Here's how they line up.
| CRISC | CISM | CISA | CGRC | |
|---|---|---|---|---|
| Issuer | ISACA | ISACA | ISACA | ISC2 |
| Focus | IT and enterprise risk, controls | Security management and governance | Information systems audit | System authorization and compliance |
| Domains | 4 | 4 | 5 | 7 |
| Exam Format | 150 questions, 4 hours | 150 questions, 4 hours | 150 questions, 4 hours | Linear, 125 items, 3 hrs |
| Experience | 3 yrs across 2+ domains | 5 yrs infosec, 3 in management | 5 yrs IS audit, control, or security | 2 yrs in 1 or more domains |
| Passing Score | 450 / 800 | 450 / 800 | 450 / 800 | 700 / 1000 |
| Exam Cost | $575 member / $760 non-member | $575 member / $760 non-member | $575 member / $760 non-member | ~$599 |
| Renewal | 120 CPEs over 3 years | 120 CPEs over 3 years | 120 CPEs over 3 years | 60 CPEs over 3 years |
| DoD 8140 Approved | Yes (check current matrix for roles) | Yes (Advanced) | Yes (Advanced) | Yes (Intermediate) |
| Best For | IT risk managers, GRC and controls professionals | Security managers and governance leads | IT auditors and assurance pros | Assessors, ISSOs, GRC practitioners |
Pricing and renewal details vary by region and membership status. Many practitioners eventually hold more than one of these credentials, and CRISC plus CISA or CISM is a common pairing.
Training Camp is an award-winning ISACA Elite+ Training Partner. Our official ISACA CRISC boot camp covers all four domains of the November 2025 outline over three days, with your exam voucher, official ISACA courseware, and a free retake included. To see the question style before you commit, take the CRISC practice test.
DoD 8140 mapping, CPE rules, neighboring GRC credentials, salary context, and exam-day logistics for CRISC candidates.
How the DoD 8140 Approved Qualifications Matrix maps certifications to DCWF work roles and proficiency levels, and where ISACA credentials like CRISC land. Read this before assuming a credential qualifies you for a specific position.
ISACA wants 120 CPE hours every three years with a 20-hour annual floor. Here is how that stacks up against ISC2, CompTIA, and the other bodies, and how to earn the hours without paying for them twice.
CGRC is the credential people compare against CRISC most often when the work is federal. What it covers, who it is for, and why the two are complements more often than rivals.
CRISC and CISA holders often work side by side. A sober look at what the audit side of the house earns, where the figures come from, and how to read salary surveys without being misled.
ISACA's privacy engineering credential overlaps with the data privacy content in CRISC Domain 4. When it makes sense to add it, and when CRISC already covers what you need.
Risk and governance credentials show up near the top of most salary lists. What those rankings measure, what they leave out, and how to use them when deciding whether CRISC is your next move.
What to expect at a PSI test center or in an online proctored session for an ISACA exam, from ID checks to break rules, and how the retake policies differ from ISC2 and CompTIA.
The CRISC exam content outline is organized into four domains, each carrying its own weight on the exam. Click any domain for what it covers.
How the organization is set up to own risk: strategy, structure, culture, policies, business processes, and the assets that carry value. It also covers risk governance itself, including enterprise risk management frameworks, the three lines of defense, risk appetite and tolerance, legal and regulatory requirements, and professional ethics.
Finding and sizing the risk. Risk identification covers events, threats, vulnerabilities, scenarios, and the risk register, while risk analysis and evaluation covers assessment methodologies, likelihood and impact, inherent and residual risk, and spotting control gaps.
The heaviest domain on the exam. Choosing a risk response and assigning ownership, third-party risk, issue and exception management, designing, implementing, and testing controls, and the KRIs, KPIs, and KCIs that feed risk reporting and ongoing monitoring.
The technical context a risk practitioner has to understand without being the engineer: enterprise architecture, IT operations, project and change management, the SDLC, and emerging technologies. It also covers information security concepts, frameworks and standards, awareness training, business continuity, and data privacy principles.
Domains and weights reflect the ISACA CRISC Exam Content Outline effective November 3, 2025, which is the outline in use as of September 2026. To see how these domains feel in question form, try the free CRISC practice test.
The questions candidates ask most often when researching the Certified in Risk and Information Systems Control certification.
CRISC is ISACA's certification for IT and enterprise risk management. It validates the ability to identify and assess IT risk, choose and own a response, design and test the controls that keep risk inside tolerance, and report on all of it to the business. It's built for mid-career and senior professionals in risk, GRC, and controls roles.
CRISC fits people who already work in or next to IT risk: risk managers and analysts, GRC staff, control owners, third-party risk managers, and security or audit professionals moving toward risk management. It isn't an entry-level certification. If you're starting out, Security+ or ISC2's CC is usually the better first step.
As of September 2026 the CRISC exam costs $575 for ISACA members and $760 for non-members. Many candidates join ISACA before registering, since the membership fee is often less than the exam discount that comes with it. Certification application fees are separate.
The CRISC exam is 150 multiple-choice questions over four hours (240 minutes). The questions are scenario based and ask for the most appropriate risk decision rather than a technical fact, so several answers often look reasonable. Scores are scaled from 200 to 800 and you need 450 to pass. It's delivered at PSI test centers or online with a remote proctor, year-round.
CRISC requires a minimum of three years of cumulative work experience performing the tasks of a CRISC professional across at least two of the four domains, and one of those two must be Governance (Domain 1) or Risk Assessment (Domain 2). The experience has to fall within the ten years before you apply or within five years of passing the exam. ISACA offers no experience waivers for CRISC.
Yes. You can sit and pass the exam first, then submit your certification application once you meet the experience requirement. ISACA gives you five years from your pass date to apply, so the exam never has to wait on your work history.
The four CRISC domains are Governance at 26 percent, Risk Assessment at 22 percent, Risk Response and Reporting at 32 percent, and Technology and Security at 20 percent. Risk Response and Reporting is the heaviest, and together with Governance the two make up more than half of the exam.
CRISC is maintained on a three-year cycle. You earn 120 Continuing Professional Education (CPE) hours across the cycle, with a minimum of 20 hours each year, pay an annual maintenance fee to ISACA, and agree to follow the ISACA Code of Professional Ethics.
Yes. CRISC is listed on the DoD 8140 Approved Qualifications Matrix (Version 2.1, effective September 19, 2025), which maps certifications to specific DoD Cyber Workforce Framework (DCWF) work roles and proficiency levels. Those mappings change as the matrix is revised, so check the current matrix at the DoD Cyber Exchange for the work role and level you're being hired against. See our DoD 8140 work role paths.
All three come from ISACA and share the same exam format: 150 questions, four hours, 450 out of 800 to pass. CRISC focuses on IT risk and controls, CISM on running the security program as a manager, and CISA on information systems audit and assurance. CRISC asks for three years of experience while CISM and CISA ask for five. Many professionals hold two of the three.
CGRC from ISC2 centers on system authorization and compliance, the assessment and authorization work common in federal environments, with 125 questions over three hours and a two-year experience requirement. CRISC is broader enterprise IT risk management with a three-year requirement. If your work is authorization packages, CGRC is the closer fit; if it's the organization's risk program, CRISC is.
Yes. ISACA's current CRISC Exam Content Outline took effect on November 3, 2025. It keeps four domains, Governance, Risk Assessment, Risk Response and Reporting, and Technology and Security, with Risk Response and Reporting carrying the most weight at 32 percent. This page describes that outline, and exams taken today test it.
For professionals who own or want to own IT risk, CRISC remains the credential most directly tied to that work in 2026. It is recognized across industries, appears on the DoD 8140 Approved Qualifications Matrix, and carries the ISACA name that hiring managers in GRC already trust. It's less useful for people early in their careers or committed to a purely hands-on technical role.
Tell us where you are, from weighing the certification to working out funding or planning training for a risk team, and we'll help you map out the right path.