CISA resources
CISA exam resources
The hub for Certuvo's CISA content: what the Certified Information Systems Auditor credential is, how the 150-question exam is structured, the five official domains and their weights under the job practice effective August 2024, what the experience requirement really involves, and how registration, fees and retakes work. Every factual claim on this page is maintained against the official ISACA publications linked below. Certuvo is an independent study resource and is not affiliated with or endorsed by ISACA.
- Author
- Certuvo Editorial Team
- Reviewed by
- Certuvo Editorial Board
- Published
- Last reviewed
- Next review
- Reading time
- 5 min
What the CISA is — and who it's for
The Certified Information Systems Auditor (CISA) is ISACA's credential for professionals who audit, monitor and assess information technology and business systems. ISACA describes it as the standard of achievement for the IS audit profession, and the credential has real institutional weight behind that claim: it dates from 1978, has been earned by more than 200,000 professionals, is accredited by ANSI under ISO/IEC 17024:2012, and is approved for use under the U.S. Department of Defense's cyberspace workforce program (DoD Manual 8140.03).
It is the natural credential for IT auditors, and it also serves people moving between audit and adjacent disciplines: internal auditors taking on systems-heavy work, security and risk professionals who need audit fluency, and controls specialists in regulated industries. Where the CIA is built around the internal audit function as a whole, the CISA is built around auditing the technology that runs the business — the two overlap in governance and risk territory but test genuinely different bodies of knowledge.
How the exam works: 150 questions, four hours, scaled scoring
Per ISACA's official exam pages, the CISA exam is a computer-based test of 150 multiple-choice questions in 4 hours. Each question presents a stem with four options and one correct answer. The exam mixes scored items with unscored pretest items, and your result is based on the scored items regardless of which domains they come from.
Scoring uses a scaled score from 200 to 800, with 450 required to pass. A scaled score is a conversion of your raw performance onto a common scale so that results are comparable across exam forms — it is not a percentage, and ISACA does not publish a "percent correct" passing threshold, so treat any such figure you see elsewhere as estimation rather than fact.
The five domains and their official weights
The current exam content outline — the job practice effective for exams from 1 August 2024 — organises the CISA exam into five domains with these official weights:
| Domain | Official weight |
|---|---|
| 1. Information System Auditing Process | 18% |
| 2. Governance and Management of IT | 18% |
| 3. Information Systems Acquisition, Development and Implementation | 12% |
| 4. Information Systems Operations and Business Resilience | 26% |
| 5. Protection of Information Assets | 26% |
The weighting tells you where the exam's centre of gravity sits: Domains 4 and 5 — operations, resilience and information-asset protection — together account for over half of the exam. Candidates from a pure audit background often underestimate the depth of the technology content those two domains carry; candidates from a security background often underestimate Domain 1's audit-process discipline. Study materials written before the August 2024 job practice may allocate emphasis differently — our blueprint update policy explains how we track official changes like that update.
Passing the exam is not certification: the experience requirement
CISA certification requires three things per ISACA's official requirements: passing the exam, meeting the experience requirement, and applying for certification (with a US$50 processing fee). The experience requirement is five years of professional information systems auditing, control or security work, gained within the ten years preceding your application — and you must apply within five years of passing the exam.
Up to three of the five years can be satisfied through substitutions — for example, ISACA's published waivers allow one year for an associate's degree, two years for a bachelor's degree, or three years for a master's degree in information systems or a related field, and one year for general IS or audit experience. The combination rules have detail to them, so before planning around a waiver, confirm your specific situation against ISACA's official requirements page. You can sit the exam before the experience is complete — many candidates do — but the certification itself waits for the application to be approved.
Registration, scheduling and retakes
ISACA runs continuous testing: there are no exam windows, and you can register at any time. Registration gives you a 365-day eligibility period in which to schedule and take the exam, at an authorised PSI test centre or via remote online proctoring. Appointments can be scheduled up to 90 days ahead, and rescheduling is free until 48 hours before your appointment.
If you don't pass, ISACA's retake policy allows up to four attempts within a rolling twelve-month period — with a 30-day wait after a first attempt and 90-day waits after the second and third. Each attempt requires the full exam fee, which makes a genuinely honest self-assessment of readiness worth real money.
What it costs
As of our August 2026 review, ISACA lists the exam registration fee at US$575 for ISACA members and US$760 for non-members — nonrefundable, nontransferable, and payable in full before scheduling. After certification, maintaining the credential costs an annual maintenance fee (US$45 members / US$85 non-members) plus continuing education: at least 20 CPE hours every year and 120 hours over each three-year cycle.
Fees change; always confirm the current amounts on ISACA's exam candidate guide pages before budgeting. Whether ISACA membership pays for itself depends on your situation — the exam-fee discount alone covers a substantial share of a typical membership, which is worth checking rather than assuming in either direction.
How Certuvo's CISA coverage works
This hub is the start of Certuvo's CISA library: domain-by-domain deep guides are in the pipeline and will publish only after passing the same three-stage editorial review as our CPA, CMA and CIA guides — never before. Our free study-plan generator and cost calculator now model CISA, with the hour estimates and fee categories researched to the same standard as this page — including continuous testing and the member/ non-member exam pricing above. Everything factual here is dated, reviewed on a schedule, and correctable through our public corrections policy.
Frequently asked questions
Can I take the CISA exam before I have five years of experience?
Yes. The exam and the experience requirement are separate steps: you can sit and pass the exam first, then apply for certification once the experience is in place — as long as you apply within five years of passing, using experience gained within the ten years before the application. Waivers can substitute up to three of the five years; confirm your specific case on ISACA's requirements page.
What score do I need to pass?
A scaled score of 450 on ISACA's 200–800 scale. Because it's a scaled score, there is no official "percentage correct" equivalent — figures like "about 70%" that circulate online are estimates, not ISACA policy.
How often can I retake the exam?
ISACA allows up to four attempts within a rolling twelve-month period: after a first unsuccessful attempt you wait 30 days, and after the second and third attempts you wait 90 days each. Every attempt requires the full exam fee.
Which domains should I weight most heavily in my study plan?
Let the official weights lead: Domains 4 (Information Systems Operations and Business Resilience) and 5 (Protection of Information Assets) are 26% each — together more than half the exam — while Domain 3 is the smallest at 12%. Then adjust for your background: auditors typically need more time on the Domain 4–5 technology depth, and security professionals more time on Domain 1's audit-process discipline.
Official sources and references
Factual claims on this page are maintained against the primary sources below, per our editorial standards.
- CISA — Certified Information Systems Auditor — ISACASupports: ISACA administers the CISA credential; positioning as the standard for IS audit; credential established 1978 with 200,000+ holders.
- CISA Exam Content Outline — ISACASupports: The five domains and official weights (18/18/12/26/26%) effective for exams from 1 August 2024; 150 multiple-choice questions in 4 hours.
- How to Get CISA Certified — ISACASupports: Certification requirements: pass the exam plus five years of IS audit/control/security experience within the preceding ten years; waivers substitute up to three years; application within five years of passing.
- ISACA Exam Candidate Guides — ISACASupports: Exam fees (US$575 member / US$760 non-member), continuous testing, 365-day eligibility period, PSI test centres and remote proctoring, scheduling and retake policies (four attempts per rolling year; 30/90/90-day waits).
- Maintain CISA Certification — ISACASupports: Annual maintenance fee (US$45 member / US$85 non-member) and CPE requirements (20 hours annually, 120 hours per three-year cycle).
- Exam scoring — scaled scores — ISACA SupportSupports: Scaled scoring from 200 to 800 with 450 required to pass; scored plus unscored pretest items.
Editorial disclosure
This page was produced by the Certuvo Editorial Team and reviewed through the technical, subject-matter and claims stages described in our content review process. Named individual author attribution with verified credentials is added as our contributor verification programme completes. Certuvo sells exam-preparation courses; editorial content is produced separately from commercial decisions under our editorial standards.
Independent provider
Certuvo is an independent provider. It is not affiliated with, endorsed by, or approved by any certification body referenced on this page. Always confirm eligibility rules, fees and exam policies with the relevant certification body.
Content change history
- — Study-plan generator and cost calculator extended to CISA, including continuous testing and ISACA's member/non-member exam pricing.
- — Initial publication: exam format, domains and weights (August 2024 job practice), certification requirements, fees and retake rules verified against ISACA's official pages.
Site-wide changes are recorded in the content changelog.
Related Certuvo resources
Resource library
All certification hubs and guides, with review dates and official sources.
CIA resources
The internal-audit counterpart: three-part exam, IIA syllabus and deep guides.
Blueprint update policy
How we track official job-practice and syllabus changes like the August 2024 update.
Authority Center
How this content is governed, reviewed and corrected.
Know exactly where you stand.
Free planning tools built on the official exam blueprints — a week-by-week study plan and an honest, itemised cost estimate. No sign-up, no stored data.