TestPrepPilot
Certified Information Systems Auditor — quick facts at a glance: requirements, exam format, fees and timeline
Certified Information Systems Auditor — verified snapshot

The short version

What is the Certified Information Systems Auditor and is it worth it?

CISA is a 150-question, 4-hour exam scored 450/800, costing $575 for members and $760 for non-members (plus a $50 application fee in some cases). Five years of audit experience is required, with substitutions allowed. It is valid three years with 120 CPE credits.

  • Global standard for IT audit and assurance
  • Often required for senior audit and SOX roles
  • Five domains aligned to the audit lifecycle
  • Experience substitutions available

What is it?

What exactly is the Certified Information Systems Auditor?

The world’s most-recognised IT audit credential.

The Certified Information Systems Auditor (CISA) is ISACA’s flagship for IT auditors, assurance and risk-and-controls professionals. It covers the audit process, IT governance, systems acquisition, operations and protection of information assets. A common requirement for senior internal audit and SOX compliance roles.

About ISACA: ISACA is a global professional association focused on IT governance, risk, audit, assurance and security. Its credentials — CISA, CISM, CRISC, CGEIT, CDPSE and newer AI certificates — are staples for GRC, audit and security-management roles.

The path in brief

  1. Join ISACA (save on fee)
  2. Study the 5 domains
  3. Schedule via PSI
  4. Pass at 450/800
  5. Maintain 120 CPE/3yr

Before you book

Who is eligible to sit the Certified Information Systems Auditor?

Prerequisites: Five years of professional IS auditing, control or security experience. Substitutions (degree, other certs) reduce the requirement; you may pass first and submit experience within five years.

Who it is for: IT auditors, assurance and controls professionals.

The test itself

What is the format of the Certified Information Systems Auditor?

The Certified Information Systems Auditor is administered by PSI test centre or remote proctoring and runs 4 hours, contains 150 multiple choice questions and requires 450 / 800 scaled to pass.

Administered byPSI test centre or remote proctoring
Questions150 multiple choice
Time limit4 hours
Pass mark450 / 800 scaled
Exam fee$575 member / $760 non-member
FormatMultiple choice

Content outline

What topics are on the Certified Information Systems Auditor?

The Certified Information Systems Auditor is weighted across 5 domains; the largest are Information Systems Auditing Process (18%), Governance and Management of IT (18%), Information Systems Acquisition, Development and Implementation (12%).

Weightings come from the official exam outline. Study time is best allocated in roughly these proportions rather than evenly across domains.

  • Information Systems Auditing Process 18%

    Planning and evidence

  • Governance and Management of IT 18%

    Alignment and frameworks

  • Information Systems Acquisition, Development and Implementation 12%

    Build and deploy

  • Information Systems Operations and Business Resilience 26%

    Ops and continuity

  • Protection of Information Assets 26%

    Logical and physical controls

Money & time

How much does the Certified Information Systems Auditor cost?

For the Certified Information Systems Auditor, the exam fee is $575 member / $760 non-member; the all-in cost is typically $725-$1,210; most candidates spend 3-6 months preparing.

Cost breakdown

Exam fee$575-$760
Application fee$50
Review manual/QAE$100-$400
Typical total$725-$1,210

ISACA membership ($135/yr) lowers the exam fee and study discounts.

Timeline

  1. Study 3-6 months

Typical prep: 3-6 months

The path

How do you register for the Certified Information Systems Auditor?

  1. 1

    Register with ISACA10 minutes

    Create an account; membership lowers the exam fee and unlocks study discounts.

  2. 2

    Pay the exam fee

    Members pay $575, non-members $760. A $50 application fee may apply for some credentials.

    • Members: $575
    • Non-members: $760
  3. 3

    Schedule via PSI

    Book a slot at a PSI test centre or choose remote proctoring.

    • Test centre
    • Remote proctored
  4. 4

    Take the exam

    Complete the 150-question exam and receive a scaled score.

Preparing for it: The official ISACA Review Manuals and QAE (Question, Answer, Explanation) databases are the most exam-aligned resources. The ISACA "way of thinking" about audit and risk is essential.

The fine print

What are the retake and renewal rules for the Certified Information Systems Auditor?

Proctoring & delivery
ISACA exams are delivered by PSI at authorised test centres or through PSI remote proctoring, with a live proctor and secure-room requirements.
Retake policy
Candidates may attempt an exam up to four times in a rolling 12-month period: a 30-day wait before attempt 2, then 90-day waits before attempts 3 and 4. Each attempt requires a new registration fee.
Score reporting
Exams are scored on a 200–800 scale; 450 is the passing mark. Candidates see a preliminary pass/fail at the centre, with the official score following.
Recertification
Certifications are valid for three years. Holders must earn 120 CPE credits over the cycle (minimum 20 per year) and pay the annual maintenance fee ($45 members / $85 non-members).

What it pays

How much does this credential pay?

$94,060 median for accountants and auditors — with information security analysts ($124,910) as the adjacent security benchmark (BLS, May 2024)

There is no Bureau of Labor Statistics occupation called "CISA" — the Certified Information Systems Auditor credential validates IT audit, control and assurance skill, and the wage question belongs to the role you perform with it. The closest official BLS occupations are Accountants and Auditors, SOC 13-2011, which had a May 2024 median wage of $94,060, and Information Security Analysts, SOC 15-1212, at a May 2024 median of $124,910. The fit is deliberate: CISA holders work as IT auditors, information-systems auditors, security auditors and compliance professionals, and the role sits between the audit and security series in the labour market. BLS counted 1,631,900 accountant and auditor jobs in 2024 and projects a 6 percent decline from 2024 to 2034 (driven by automation of traditional accounting work), while the information-security series projects a striking 30 percent growth with about 17,500 openings a year — and the IT-audit niche the CISA serves tracks the security side of that market. The limitation to state plainly: the BLS figures cover the whole occupations at all levels, credentialed or not, and the CISA's value is as a recognised IT-audit and security-governance signal that employers use for audit, compliance and security-assurance roles. Read the numbers as the market for the roles the credential serves.

MeasureFigureSource / note
Median annual wage, accountants and auditors$94,060BLS OOH, SOC 13-2011, May 2024
Median, information security analysts (adjacent security benchmark)$124,910BLS OOH, SOC 15-1212, May 2024
Lowest 10 percent, accountants and auditorsUnder $55,290BLS OOH, SOC 13-2011, May 2024
Highest 10 percent, accountants and auditorsAbove $169,150BLS OOH, SOC 13-2011, May 2024

Job growth.BLS projects a 6 percent decline for accountants and auditors from 2024 to 2034, while the adjacent information-security series projects 30 percent growth.

Source: BLS Occupational Outlook Handbook - Accountants and Auditors

Your odds

What are the pass rates?

ISACA publishes pass rates — the reported CISA pass rate is around 50% in recent published data

ISACA publishes pass-rate information for its certification exams, and the reported CISA pass rate has historically clustered around 50 percent in recent published cycles; we present it as the body's own reporting, noting the figure varies by exam window and candidate pool. What ISACA also publishes is the format: the CISA exam has 150 multiple-choice questions with a 4-hour time limit, delivered by computer at ISACA-approved test centres or through remote proctoring, and the result is reported as pass/fail. The exam content follows the published CISA job practice areas: the process of auditing information systems; governance and management of IT; information systems acquisition, development and implementation; information systems operations and business resilience; and protection of information assets. The practical reading: the published pass rate reflects a demanding professional exam, and the strongest predictor of success is structured preparation — candidates who complete the review course, work the question database and meet the experience requirement (5 years of relevant work, with waivers) pass at higher rates than the overall cohort.

Read this before quoting the number.ISACA publishes pass-rate data that varies by window; the figure above is the recent reported range, not a fixed number.

Source: ISACA - Certified Information Systems Auditor (CISA)

Your schedule

How long should I study for it?

150-250 hours over 3-6 months (plus the 5-year experience requirement) of focused study

The CISA exam is a 150-question, 4-hour exam built on the five job practice areas: auditing information systems, governance and management of IT, acquisition and implementation, operations and business resilience, and protection of information assets. A defensible plan runs 150 to 250 hours over 3 to 6 months, built around the ISACA review materials and the 5-year experience requirement. Months 1-2: the audit domain and governance — the IS audit process, standards and risk-based auditing, then IT governance, the frameworks and the organisational roles. Months 3-4: acquisition and implementation, and operations and resilience — the SDLC and the acquisition process, then operations management, business continuity and disaster recovery. Months 5: protection of information assets — security standards, access controls, cryptography and the protection frameworks. Month 6: the question database and full timed practice exams at the real 150-question, 4-hour format. The plan is domain-driven because the exam covers all five areas; candidates who study only the security domain fail the audit and governance items.

  1. Months 1-270

    Audit process and governance

    • The IS audit process and standards
    • Risk-based auditing
    • IT governance, frameworks and roles
  2. Months 3-470

    Acquisition, operations, resilience

    • The SDLC and acquisition process
    • Operations management and service delivery
    • Business continuity and DR
  3. Month 545

    Protection of information assets

    • Security standards and access controls
    • Cryptography and network security
    • Physical and environmental controls
  4. Month 640

    Database and mocks

    • The ISACA question database
    • Two full timed practice exams
    • Review weak domains

Adjusting the pace

IT auditor in practice.The audit domain accelerates; spend extra time on acquisition, governance and the exam format.

Security professional adding audit.The protection domain is familiar; the audit-process and governance material is the new content.

How to study

How do I prepare most effectively?

The CISA rewards breadth across all five job practice areas, so the dominant strategy is domain-driven coverage with the ISACA review materials as the scope map: the exam draws from every area, and candidates who study only the security domain fail the audit and governance items. Second, master the audit process domain first — the IS audit standards, the risk-based audit approach and the audit lifecycle — because it anchors the credential's identity. Third, use the ISACA QAE (Questions and Answers Database) as the primary practice resource; it is the closest thing to the real item style and includes the answer rationales that build the reasoning the exam rewards. Fourth, confirm the experience requirement early: the CISA requires 5 years of relevant work experience (with education waivers), and certification cannot proceed without it. Finally, take at least two full timed practice exams at the real 150-question, 4-hour format; the length and stamina are part of the test.

Cover all five domains

The exam draws from every area; audit and governance cannot be skipped.

Master the audit process first

The IS audit standards and lifecycle anchor the credential.

Use the ISACA QAE

The closest item style, with the rationales that build the reasoning.

Confirm the experience requirement

5 years of relevant work (with waivers) gates certification.

Run two full timed mocks

150 questions in 4 hours; the stamina is part of the test.

What to buy

Which study resources are worth paying for?

CISA prep is dominated by ISACA's official materials. The ISACA CISA Review Manual ($100-$150) and the QAE database (about $200-$250, or included in the review course) are the standard stack; the review course runs roughly $500-$2,500 depending on format (self-paced, virtual or in-person). Third-party books ($40-$100) and question banks ($50-$200) add alternatives. Free resources include the job practice areas outline and ISACA's sample questions. A realistic total budget is $600 to $3,000 including the exam fee (about $575 for ISACA members, $760 for non-members). Prices below are list prices as of mid-2026 and change frequently; we rank nothing by commission.

ResourcePriceFormatBest for
CISA Review Manual$100-$150Printed or digital bookThe authoritative domain coverage
ISACA QAE database$200-$250Online question databaseThe closest item style and rationales
ISACA review course$500-$2,500Self-paced, virtual or in-personStructured preparation
Third-party books and banks$40-$200Books and practice itemsAlternatives and extra volume
CISA exam~$575 member / ~$760 non-memberComputer-based examThe certification itself

List prices as of mid-2026, subject to change; ISACA fees vary by membership; no commission or affiliate ranking is implied.

Avoid these

What mistakes do candidates most often make?

The most common CISA mistake is studying only the technical security domain: candidates with a security background focus on the protection-of-information-assets material and fail the audit-process and governance items, which are a large share of the exam. The fix is full five-domain coverage. The second mistake is relying on practice questions without the review manual's domain depth; the QAE is essential, but it works best after the manual. Third, candidates under-prepare the acquisition-and-implementation and operations-and-resilience domains, treating them as minor when they are distinct tested areas. Fourth, some candidates ignore the experience requirement until after passing and then wait years for certification; confirm it early. Finally, candidates who never run a full timed exam underestimate the 150-question, 4-hour stamina.

Studying security only

Cover all five domains; audit and governance are a large share.

Using questions without the manual

The QAE works best after the review manual's domain depth.

Under-preparing acquisition and operations

Distinct tested areas; cover them fully.

Ignoring the experience requirement

Confirm the 5-year requirement early; it gates certification.

Skipping full timed mocks

150 questions in 4 hours; run two full timed practice exams.

What you'll face

What question types will I see?

The CISA exam is a 150-question multiple-choice exam in 4 hours. The items span the five job practice areas with a heavy concentration on the audit process, governance, and the reasoning behind audit and control decisions — many items present an audit or control situation and ask for the best practice or the correct conclusion. Samples below are editor-written illustrations of the published job practice areas, not live exam items; they show the audit-reasoning style of the real items.

Audit process itemsLargest block

Audit standards, risk-based auditing and the audit lifecycle.

Governance and management itemsLarge block

IT governance, frameworks, roles and responsibilities.

Security and resilience itemsLarge block

Protection of assets, access controls, BC and DR.

Try these

Q1An IS auditor is planning an audit of a critical financial system. The most appropriate first step is to:
  • A. Perform a risk assessment to prioritise the audit scope and objectives
  • B. Test all controls equally
  • C. Report findings before the fieldwork
  • D. Skip documentation to save time

Answer:A

Risk-based auditing begins with a risk assessment that drives the scope and objectives — the IS audit standard approach. Uniform testing, premature reporting or skipped documentation each violate the audit process.

Q2Which control is most appropriate to detect unauthorised changes to application code?
  • A. Change-management controls with segregation of duties and code review
  • B. A strong firewall rule
  • C. Password complexity alone
  • D. Annual training

Answer:A

Detecting unauthorised code changes requires change-management controls — segregation of duties, approvals and code review. Firewalls, password policy and training address different risks and do not detect code changes.

Q3A business continuity plan must specify the maximum acceptable downtime for a system. This requirement is the:
  • A. Recovery time objective (RTO)
  • B. Recovery point objective (RPO)
  • C. Service level agreement (SLA)
  • D. Business impact analysis (BIA)

Answer:A

The RTO is the maximum acceptable downtime — how quickly systems must be restored. The RPO is data-loss tolerance, the SLA is the service contract, and the BIA is the analysis that informs the objectives.

Samples are editor-written illustrations of the published job practice areas, not live exam items.

The big day

What should I expect on exam day?

The CISA exam is a 150-question, 4-hour computer-based exam at an ISACA-approved test centre or through remote proctoring. Bring the required identification matching your registration and your exam confirmation; personal items go in the locker. Arrive early — late arrivals may forfeit the appointment and fee. Pace at about 1.6 minutes per item, flag uncertain items for review, and budget time for the reading-heavy scenario items. Your result is reported as pass/fail after the exam, with the official report following. If you do not pass, the retake policy and fee apply. On a pass, the CISA is valid for three years and is renewed by earning 120 continuing professional education (CPE) hours every three years. The afterwards matters: log your CPEs as you earn them, because ISACA audits renewals, and submit the certification application if you have not already completed it.

Bring

  • Required identification matching your registration
  • Exam confirmation

Leave at home

  • Phone, smartwatch and all electronics
  • Notes and study materials
  • Personal bags beyond what the centre allows

How the day runs

Before the examConfirm the appointment, ID requirements and delivery mode.
Exam150 questions in 4 hours; pace ~1.6 minutes per item, flag and review.
After submitPass/fail is reported; the official report follows.
NextComplete the certification application and start the CPE log.

Rules in the room

  • The exam is computer-based and timed
  • 4 hours for 150 questions; the clock does not pause
  • The certification renews every 3 years with 120 CPEs

Afterwards.On a pass, complete the certification application and log 120 CPEs every three years. On a fail, retake per the ISACA policy after additional domain study.

Reference

What are the key facts about the Certified Information Systems Auditor?

Certified Information Systems Auditor is a certification credential; awarded by ISACA; the exam fee is $575 member / $760 non-member; typical preparation is 3-6 months; holders typically earn $95,000-$140,000.

CredentialCertified Information Systems Auditor
AbbreviationCISA
TypeCertification
ProfessionIT, Cloud & Cybersecurity
SpecialtyCybersecurity (Vendor-Neutral)
Awarded byISACA
DifficultyHard
Typical prep time3-6 months
All-in cost$725-$1,210
Typical salary range$95,000-$140,000
DeliveryPSI test centre or remote proctoring
RetakeUp to 4 attempts/12mo; 30 then 90-day waits
Validity3 years; 120 CPE + $45/$85 annual fee
ScopeNational / Multi-state
Also known asCISA

Real questions

Frequently asked questions about the Certified Information Systems Auditor

What is the CISA pass mark?

A scaled 450 out of 800. ISACA uses scenario-based items, so the raw percentage is not directly equivalent.

What experience do I need?

Five years of IS audit, control or security experience, with degree and certification substitutions allowed. You can pass first and submit experience within five years.

How is CISA delivered?

150 multiple-choice questions over four hours via PSI test centres or remote proctoring.

How do I maintain CISA?

Earn 120 CPE credits over three years and pay the annual maintenance fee ($45 members / $85 non-members).

Why is the ISACA passing score 450?

ISACA uses a scaled 200–800 range; 450 is the fixed threshold, not a raw percentage. Scenario-based items are weighted by difficulty.

Can I sit the exam without the experience?

Yes for most credentials. You can pass first and have five years afterward to submit verified experience.

In short

Is the Certified Information Systems Auditor worth it?

  • CISA is ISACA’s IT audit flagship
  • 150 questions, 4 hours, 450/800, $575-$760
  • Five domains; 5yr audit experience
  • 3-year validity; 120 CPE

Trust

Where does this information come from?

Everything above is taken from the awarding body's own published material. Fees, question counts and domain weights are revised regularly — check the official page before you pay.

Research confidence: high · Last reviewed 2026-08

How this guide is maintained

Cloud, IT & cybersecurity certifications desk

This desk covers ISACA and other IT certifications. Exam structure, fees and rules come from the certifying body's official pages (ISACA), which are revised regularly; wage figures come from the Bureau of Labor Statistics Occupational Outlook Handbook series named by SOC code. When a figure is not published, we say so plainly rather than guessing.

Verified against ISACA's CISA program pages and BLS OOH Auditors (SOC 13-2011) and Information Security Analysts (SOC 15-1212), May 2024 data. Every fee, score and deadline on this page was checked against the primary sources cited above in August 2026. Exam boards change these without notice — confirm anything you are about to pay for on the official site.