IT, Cloud & Cybersecurity • Certification
Certified Information Systems Auditor
The world’s most-recognised IT audit credential.
Researched and maintained by TestPrepPilot Editorial BoardCloud, IT & cybersecurity certifications desk · Figures last verified August 2026
The short version
What is the Certified Information Systems Auditor and is it worth it?
CISA is a 150-question, 4-hour exam scored 450/800, costing $575 for members and $760 for non-members (plus a $50 application fee in some cases). Five years of audit experience is required, with substitutions allowed. It is valid three years with 120 CPE credits.
- Global standard for IT audit and assurance
- Often required for senior audit and SOX roles
- Five domains aligned to the audit lifecycle
- Experience substitutions available
What is it?
What exactly is the Certified Information Systems Auditor?
The world’s most-recognised IT audit credential.
The Certified Information Systems Auditor (CISA) is ISACA’s flagship for IT auditors, assurance and risk-and-controls professionals. It covers the audit process, IT governance, systems acquisition, operations and protection of information assets. A common requirement for senior internal audit and SOX compliance roles.
The path in brief
- Join ISACA (save on fee)
- Study the 5 domains
- Schedule via PSI
- Pass at 450/800
- Maintain 120 CPE/3yr
Before you book
Who is eligible to sit the Certified Information Systems Auditor?
Who it is for: IT auditors, assurance and controls professionals.
The test itself
What is the format of the Certified Information Systems Auditor?
The Certified Information Systems Auditor is administered by PSI test centre or remote proctoring and runs 4 hours, contains 150 multiple choice questions and requires 450 / 800 scaled to pass.
| Administered by | PSI test centre or remote proctoring |
|---|---|
| Questions | 150 multiple choice |
| Time limit | 4 hours |
| Pass mark | 450 / 800 scaled |
| Exam fee | $575 member / $760 non-member |
| Format | Multiple choice |
Content outline
What topics are on the Certified Information Systems Auditor?
The Certified Information Systems Auditor is weighted across 5 domains; the largest are Information Systems Auditing Process (18%), Governance and Management of IT (18%), Information Systems Acquisition, Development and Implementation (12%).
Weightings come from the official exam outline. Study time is best allocated in roughly these proportions rather than evenly across domains.
- Information Systems Auditing Process 18%
Planning and evidence
- Governance and Management of IT 18%
Alignment and frameworks
- Information Systems Acquisition, Development and Implementation 12%
Build and deploy
- Information Systems Operations and Business Resilience 26%
Ops and continuity
- Protection of Information Assets 26%
Logical and physical controls
Money & time
How much does the Certified Information Systems Auditor cost?
For the Certified Information Systems Auditor, the exam fee is $575 member / $760 non-member; the all-in cost is typically $725-$1,210; most candidates spend 3-6 months preparing.
Cost breakdown
| Exam fee | $575-$760 |
|---|---|
| Application fee | $50 |
| Review manual/QAE | $100-$400 |
| Typical total | $725-$1,210 |
ISACA membership ($135/yr) lowers the exam fee and study discounts.
Timeline
- Study 3-6 months
Typical prep: 3-6 months
The path
How do you register for the Certified Information Systems Auditor?
- 1
Register with ISACA10 minutes
Create an account; membership lowers the exam fee and unlocks study discounts.
- 2
Pay the exam fee
Members pay $575, non-members $760. A $50 application fee may apply for some credentials.
- Members: $575
- Non-members: $760
- 3
Schedule via PSI
Book a slot at a PSI test centre or choose remote proctoring.
- Test centre
- Remote proctored
- 4
Take the exam
Complete the 150-question exam and receive a scaled score.
The fine print
What are the retake and renewal rules for the Certified Information Systems Auditor?
- Proctoring & delivery
- ISACA exams are delivered by PSI at authorised test centres or through PSI remote proctoring, with a live proctor and secure-room requirements.
- Retake policy
- Candidates may attempt an exam up to four times in a rolling 12-month period: a 30-day wait before attempt 2, then 90-day waits before attempts 3 and 4. Each attempt requires a new registration fee.
- Score reporting
- Exams are scored on a 200–800 scale; 450 is the passing mark. Candidates see a preliminary pass/fail at the centre, with the official score following.
- Recertification
- Certifications are valid for three years. Holders must earn 120 CPE credits over the cycle (minimum 20 per year) and pay the annual maintenance fee ($45 members / $85 non-members).
What it pays
How much does this credential pay?
$94,060 median for accountants and auditors — with information security analysts ($124,910) as the adjacent security benchmark (BLS, May 2024)
There is no Bureau of Labor Statistics occupation called "CISA" — the Certified Information Systems Auditor credential validates IT audit, control and assurance skill, and the wage question belongs to the role you perform with it. The closest official BLS occupations are Accountants and Auditors, SOC 13-2011, which had a May 2024 median wage of $94,060, and Information Security Analysts, SOC 15-1212, at a May 2024 median of $124,910. The fit is deliberate: CISA holders work as IT auditors, information-systems auditors, security auditors and compliance professionals, and the role sits between the audit and security series in the labour market. BLS counted 1,631,900 accountant and auditor jobs in 2024 and projects a 6 percent decline from 2024 to 2034 (driven by automation of traditional accounting work), while the information-security series projects a striking 30 percent growth with about 17,500 openings a year — and the IT-audit niche the CISA serves tracks the security side of that market. The limitation to state plainly: the BLS figures cover the whole occupations at all levels, credentialed or not, and the CISA's value is as a recognised IT-audit and security-governance signal that employers use for audit, compliance and security-assurance roles. Read the numbers as the market for the roles the credential serves.
| Measure | Figure | Source / note |
|---|---|---|
| Median annual wage, accountants and auditors | $94,060 | BLS OOH, SOC 13-2011, May 2024 |
| Median, information security analysts (adjacent security benchmark) | $124,910 | BLS OOH, SOC 15-1212, May 2024 |
| Lowest 10 percent, accountants and auditors | Under $55,290 | BLS OOH, SOC 13-2011, May 2024 |
| Highest 10 percent, accountants and auditors | Above $169,150 | BLS OOH, SOC 13-2011, May 2024 |
Job growth.BLS projects a 6 percent decline for accountants and auditors from 2024 to 2034, while the adjacent information-security series projects 30 percent growth.
Source: BLS Occupational Outlook Handbook - Accountants and Auditors
Your odds
What are the pass rates?
ISACA publishes pass rates — the reported CISA pass rate is around 50% in recent published data
ISACA publishes pass-rate information for its certification exams, and the reported CISA pass rate has historically clustered around 50 percent in recent published cycles; we present it as the body's own reporting, noting the figure varies by exam window and candidate pool. What ISACA also publishes is the format: the CISA exam has 150 multiple-choice questions with a 4-hour time limit, delivered by computer at ISACA-approved test centres or through remote proctoring, and the result is reported as pass/fail. The exam content follows the published CISA job practice areas: the process of auditing information systems; governance and management of IT; information systems acquisition, development and implementation; information systems operations and business resilience; and protection of information assets. The practical reading: the published pass rate reflects a demanding professional exam, and the strongest predictor of success is structured preparation — candidates who complete the review course, work the question database and meet the experience requirement (5 years of relevant work, with waivers) pass at higher rates than the overall cohort.
Read this before quoting the number.ISACA publishes pass-rate data that varies by window; the figure above is the recent reported range, not a fixed number.
Source: ISACA - Certified Information Systems Auditor (CISA)
Your schedule
How long should I study for it?
150-250 hours over 3-6 months (plus the 5-year experience requirement) of focused study
The CISA exam is a 150-question, 4-hour exam built on the five job practice areas: auditing information systems, governance and management of IT, acquisition and implementation, operations and business resilience, and protection of information assets. A defensible plan runs 150 to 250 hours over 3 to 6 months, built around the ISACA review materials and the 5-year experience requirement. Months 1-2: the audit domain and governance — the IS audit process, standards and risk-based auditing, then IT governance, the frameworks and the organisational roles. Months 3-4: acquisition and implementation, and operations and resilience — the SDLC and the acquisition process, then operations management, business continuity and disaster recovery. Months 5: protection of information assets — security standards, access controls, cryptography and the protection frameworks. Month 6: the question database and full timed practice exams at the real 150-question, 4-hour format. The plan is domain-driven because the exam covers all five areas; candidates who study only the security domain fail the audit and governance items.
- Months 1-270
Audit process and governance
- The IS audit process and standards
- Risk-based auditing
- IT governance, frameworks and roles
- Months 3-470
Acquisition, operations, resilience
- The SDLC and acquisition process
- Operations management and service delivery
- Business continuity and DR
- Month 545
Protection of information assets
- Security standards and access controls
- Cryptography and network security
- Physical and environmental controls
- Month 640
Database and mocks
- The ISACA question database
- Two full timed practice exams
- Review weak domains
Adjusting the pace
IT auditor in practice.The audit domain accelerates; spend extra time on acquisition, governance and the exam format.
Security professional adding audit.The protection domain is familiar; the audit-process and governance material is the new content.
How to study
How do I prepare most effectively?
The CISA rewards breadth across all five job practice areas, so the dominant strategy is domain-driven coverage with the ISACA review materials as the scope map: the exam draws from every area, and candidates who study only the security domain fail the audit and governance items. Second, master the audit process domain first — the IS audit standards, the risk-based audit approach and the audit lifecycle — because it anchors the credential's identity. Third, use the ISACA QAE (Questions and Answers Database) as the primary practice resource; it is the closest thing to the real item style and includes the answer rationales that build the reasoning the exam rewards. Fourth, confirm the experience requirement early: the CISA requires 5 years of relevant work experience (with education waivers), and certification cannot proceed without it. Finally, take at least two full timed practice exams at the real 150-question, 4-hour format; the length and stamina are part of the test.
Cover all five domains
The exam draws from every area; audit and governance cannot be skipped.
Master the audit process first
The IS audit standards and lifecycle anchor the credential.
Use the ISACA QAE
The closest item style, with the rationales that build the reasoning.
Confirm the experience requirement
5 years of relevant work (with waivers) gates certification.
Run two full timed mocks
150 questions in 4 hours; the stamina is part of the test.
What to buy
Which study resources are worth paying for?
CISA prep is dominated by ISACA's official materials. The ISACA CISA Review Manual ($100-$150) and the QAE database (about $200-$250, or included in the review course) are the standard stack; the review course runs roughly $500-$2,500 depending on format (self-paced, virtual or in-person). Third-party books ($40-$100) and question banks ($50-$200) add alternatives. Free resources include the job practice areas outline and ISACA's sample questions. A realistic total budget is $600 to $3,000 including the exam fee (about $575 for ISACA members, $760 for non-members). Prices below are list prices as of mid-2026 and change frequently; we rank nothing by commission.
| Resource | Price | Format | Best for |
|---|---|---|---|
| CISA Review Manual | $100-$150 | Printed or digital book | The authoritative domain coverage |
| ISACA QAE database | $200-$250 | Online question database | The closest item style and rationales |
| ISACA review course | $500-$2,500 | Self-paced, virtual or in-person | Structured preparation |
| Third-party books and banks | $40-$200 | Books and practice items | Alternatives and extra volume |
| CISA exam | ~$575 member / ~$760 non-member | Computer-based exam | The certification itself |
List prices as of mid-2026, subject to change; ISACA fees vary by membership; no commission or affiliate ranking is implied.
Avoid these
What mistakes do candidates most often make?
The most common CISA mistake is studying only the technical security domain: candidates with a security background focus on the protection-of-information-assets material and fail the audit-process and governance items, which are a large share of the exam. The fix is full five-domain coverage. The second mistake is relying on practice questions without the review manual's domain depth; the QAE is essential, but it works best after the manual. Third, candidates under-prepare the acquisition-and-implementation and operations-and-resilience domains, treating them as minor when they are distinct tested areas. Fourth, some candidates ignore the experience requirement until after passing and then wait years for certification; confirm it early. Finally, candidates who never run a full timed exam underestimate the 150-question, 4-hour stamina.
✕Studying security only
✓Cover all five domains; audit and governance are a large share.
✕Using questions without the manual
✓The QAE works best after the review manual's domain depth.
✕Under-preparing acquisition and operations
✓Distinct tested areas; cover them fully.
✕Ignoring the experience requirement
✓Confirm the 5-year requirement early; it gates certification.
✕Skipping full timed mocks
✓150 questions in 4 hours; run two full timed practice exams.
What you'll face
What question types will I see?
The CISA exam is a 150-question multiple-choice exam in 4 hours. The items span the five job practice areas with a heavy concentration on the audit process, governance, and the reasoning behind audit and control decisions — many items present an audit or control situation and ask for the best practice or the correct conclusion. Samples below are editor-written illustrations of the published job practice areas, not live exam items; they show the audit-reasoning style of the real items.
Audit standards, risk-based auditing and the audit lifecycle.
IT governance, frameworks, roles and responsibilities.
Protection of assets, access controls, BC and DR.
Try these
Q1An IS auditor is planning an audit of a critical financial system. The most appropriate first step is to:
Answer:A
Risk-based auditing begins with a risk assessment that drives the scope and objectives — the IS audit standard approach. Uniform testing, premature reporting or skipped documentation each violate the audit process.
Q2Which control is most appropriate to detect unauthorised changes to application code?
Answer:A
Detecting unauthorised code changes requires change-management controls — segregation of duties, approvals and code review. Firewalls, password policy and training address different risks and do not detect code changes.
Q3A business continuity plan must specify the maximum acceptable downtime for a system. This requirement is the:
Answer:A
The RTO is the maximum acceptable downtime — how quickly systems must be restored. The RPO is data-loss tolerance, the SLA is the service contract, and the BIA is the analysis that informs the objectives.
Samples are editor-written illustrations of the published job practice areas, not live exam items.
The big day
What should I expect on exam day?
The CISA exam is a 150-question, 4-hour computer-based exam at an ISACA-approved test centre or through remote proctoring. Bring the required identification matching your registration and your exam confirmation; personal items go in the locker. Arrive early — late arrivals may forfeit the appointment and fee. Pace at about 1.6 minutes per item, flag uncertain items for review, and budget time for the reading-heavy scenario items. Your result is reported as pass/fail after the exam, with the official report following. If you do not pass, the retake policy and fee apply. On a pass, the CISA is valid for three years and is renewed by earning 120 continuing professional education (CPE) hours every three years. The afterwards matters: log your CPEs as you earn them, because ISACA audits renewals, and submit the certification application if you have not already completed it.
Bring
- Required identification matching your registration
- Exam confirmation
Leave at home
- Phone, smartwatch and all electronics
- Notes and study materials
- Personal bags beyond what the centre allows
How the day runs
Rules in the room
- The exam is computer-based and timed
- 4 hours for 150 questions; the clock does not pause
- The certification renews every 3 years with 120 CPEs
Afterwards.On a pass, complete the certification application and log 120 CPEs every three years. On a fail, retake per the ISACA policy after additional domain study.
Reference
What are the key facts about the Certified Information Systems Auditor?
Certified Information Systems Auditor is a certification credential; awarded by ISACA; the exam fee is $575 member / $760 non-member; typical preparation is 3-6 months; holders typically earn $95,000-$140,000.
| Credential | Certified Information Systems Auditor |
|---|---|
| Abbreviation | CISA |
| Type | Certification |
| Profession | IT, Cloud & Cybersecurity |
| Specialty | Cybersecurity (Vendor-Neutral) |
| Awarded by | ISACA |
| Difficulty | Hard |
| Typical prep time | 3-6 months |
| All-in cost | $725-$1,210 |
| Typical salary range | $95,000-$140,000 |
| Delivery | PSI test centre or remote proctoring |
| Retake | Up to 4 attempts/12mo; 30 then 90-day waits |
| Validity | 3 years; 120 CPE + $45/$85 annual fee |
| Scope | National / Multi-state |
| Also known as | CISA |
Real questions
Frequently asked questions about the Certified Information Systems Auditor
What is the CISA pass mark?
A scaled 450 out of 800. ISACA uses scenario-based items, so the raw percentage is not directly equivalent.
What experience do I need?
Five years of IS audit, control or security experience, with degree and certification substitutions allowed. You can pass first and submit experience within five years.
How is CISA delivered?
150 multiple-choice questions over four hours via PSI test centres or remote proctoring.
How do I maintain CISA?
Earn 120 CPE credits over three years and pay the annual maintenance fee ($45 members / $85 non-members).
Why is the ISACA passing score 450?
ISACA uses a scaled 200–800 range; 450 is the fixed threshold, not a raw percentage. Scenario-based items are weighted by difficulty.
Can I sit the exam without the experience?
Yes for most credentials. You can pass first and have five years afterward to submit verified experience.
In short
Is the Certified Information Systems Auditor worth it?
- CISA is ISACA’s IT audit flagship
- 150 questions, 4 hours, 450/800, $575-$760
- Five domains; 5yr audit experience
- 3-year validity; 120 CPE
Trust
Where does this information come from?
Everything above is taken from the awarding body's own published material. Fees, question counts and domain weights are revised regularly — check the official page before you pay.
- ISACA Awarding body
- Official Certified Information Systems Auditor exam page Exam page
- ISACA certification programme Programme rules
Research confidence: high · Last reviewed 2026-08