The CGEIT Certification, formally Certified in the Governance of Enterprise IT, is ISACA’s advanced credential for professionals responsible for enterprise IT governance, strategic alignment, value delivery, resources, and risk. The CGEIT exam has 150 multiple-choice questions, lasts 4 hours, and requires a scaled score of 450 or higher. To earn the certification, candidates need five years of qualifying governance experience, including experience across at least three CGEIT domains and at least one year in Domain 1.
The CGEIT Certification is an executive-level IT governance credential offered by ISACA. CGEIT stands for Certified in the Governance of Enterprise IT and is designed for experienced professionals who help organizations align technology investments, governance structures, business objectives, resources, value realization, and risk.
Unlike certifications focused mainly on technical implementation, cybersecurity operations, or IT auditing, ISACA CGEIT concentrates on how technology is governed at the enterprise level.
That distinction matters.
A technical manager may know how to operate infrastructure securely, while a governance professional needs to answer broader questions: Are technology investments aligned with business strategy? Are decision rights clear? Are benefits being realized? Are resources optimized? Is technology risk being managed within enterprise risk appetite?
CGEIT is a framework-agnostic credential focused on enterprise IT governance, resources, benefits realization, and risk optimization.
The current CGEIT exam contains 150 multiple-choice questions and provides 4 hours, or 240 minutes, for completion. ISACA uses a scaled scoring model from 200 to 800, with 450 as the minimum passing score.
CGEIT Exam Detail
Current Information
Certification
Certified in the Governance of Enterprise IT
Provider
ISACA
Questions
150
Exam Duration
4 hours / 240 minutes
Question Type
Multiple choice
Passing Score
450 on a 200–800 scale
Delivery
Testing center or remote proctoring
Member Exam Fee
US$575
Nonmember Exam Fee
US$760
Application Fee
US$50
The examination is computer-based and may be available through authorized testing centers or eligible remote proctoring options.
The CGEIT Certification ISACA exam is organized into four domains.
Domain
Weight
Governance of Enterprise IT
40%
IT Resources
15%
Benefits Realization
26%
Risk Optimization
19%
The weighting immediately shows where candidates should focus. Governance of Enterprise IT alone represents 40%, while Governance plus Benefits Realization account for nearly two-thirds of the examination.
This is the largest CGEIT domain and the foundation of the credential.
Candidates should understand governance frameworks, organizational structures, decision rights, accountability, strategic planning, enterprise objectives, stakeholder engagement, policies, standards, enterprise architecture, information governance, regulatory obligations, ethics, and organizational culture.
This domain tests more than whether you recognize governance terminology.
A strong candidate should be able to evaluate whether governance mechanisms support enterprise objectives.
For example, imagine a company investing heavily in AI, cloud infrastructure, and cybersecurity tools. The governance question is not merely whether those technologies work. CGEIT-level thinking asks whether decision-making authority is clear, investments support strategic priorities, risks are understood, benefits are measured, and accountability exists.
That is the mindset a good CGEIT course should develop.
The IT Resources domain addresses how organizations plan, acquire, develop, manage, and optimize technology-related resources.
Resources include more than servers and software. They also include people, skills, services, vendors, information, applications, infrastructure, and sourcing arrangements.
Candidates should understand resource planning, capacity, talent management, sourcing strategy, vendor relationships, and how resources support strategic objectives.
A governance professional should be able to recognize situations where technical capability exists but resources are poorly allocated.
For instance, an organization may have a large technology budget but still struggle because skilled staff are concentrated in low-priority initiatives while strategic programs remain understaffed.
That is a governance problem, not simply an operational problem.
Benefits Realization represents 26% of the CGEIT exam and focuses on whether technology investments actually produce the value promised when they were approved.
Candidates should understand portfolio management, investment evaluation, performance measurement, benefits tracking, value delivery, business cases, metrics, and stakeholder expectations.
Consider a cloud migration project.
Completing the migration on schedule does not automatically mean the investment delivered value.
The organization may have expected reduced infrastructure costs, improved resilience, faster deployment, or better customer experience. CGEIT-level governance evaluates whether those expected benefits were actually achieved.
This makes Benefits Realization particularly relevant for CIOs, IT directors, governance professionals, PMO leaders, enterprise architects, and senior technology managers.
Risk Optimization represents 19% of the exam.
Candidates need to understand risk appetite, risk tolerance, enterprise risk management, technology risk, controls, monitoring, communication, and how risk decisions support organizational objectives.
CGEIT does not approach risk as simply something to eliminate.
Every organization takes risk when investing in technology, entering new markets, adopting AI, moving workloads to the cloud, or changing operating models.
The governance objective is to ensure that risk is understood, evaluated, communicated, and kept within acceptable limits while still allowing the organization to pursue opportunities.
This is why CGEIT training should teach candidates to think from a business-governance perspective rather than only from a control perspective.
The ISACA CGEIT certification requirements are significantly more demanding than simply passing the examination.
Candidates must have at least five years of professional experience managing, advising, overseeing, or otherwise supporting governance of the IT-related contribution to an enterprise.
That experience must cover at least three of the four CGEIT domains, with at least one year related to Domain 1: Governance of Enterprise IT.
The qualifying experience must generally fall within the required experience window before the certification application.
Passing the exam does not automatically make someone CGEIT certified.
Candidates must also submit the certification application and demonstrate that the professional experience requirements have been satisfied.
This makes CGEIT very different from an entry-level IT credential.
The current CGEIT certification cost begins with the examination fee.
ISACA typically charges different exam fees for members and nonmembers. The member rate is lower, while nonmembers generally pay a higher registration fee.
Additional costs may include:
CGEIT training
Review manuals
Practice-question databases
Instructor-led classes
ISACA membership
Retake fees
Certification application fee
Annual certification maintenance
When evaluating the total CGEIT certification cost, candidates should therefore look beyond the exam fee alone.
Training format, study resources, membership status, and retake requirements can significantly affect the final amount.
Effective CGEIT certification training should not be based on memorizing governance terminology.
The exam is designed for experienced professionals and often requires candidates to choose the BEST, MOST appropriate, or governance-level response to a business scenario.
A strong CGEIT training program should cover governance frameworks, stakeholder alignment, enterprise architecture, strategic planning, resource optimization, benefits management, investment governance, risk optimization, performance measurement, and executive decision-making.
Candidates should also practice distinguishing governance responsibilities from management responsibilities.
That difference is critical.
Management is generally responsible for planning, building, running, and monitoring activities.
Governance provides direction, evaluates stakeholder needs, establishes decision structures, and monitors whether objectives are being achieved.
Confusing these perspectives can lead to incorrect answers even when several options appear technically reasonable.
Start by using the official four-domain structure as your study map.
A practical preparation process is:
Study Governance of Enterprise IT first because it carries the highest exam weighting.
Review IT Resources, Benefits Realization, and Risk Optimization systematically.
Complete scenario-based practice questions instead of relying only on definitions.
Review every incorrect answer and identify why the governance perspective differs from your first choice.
Take full-length timed practice exams once your domain knowledge becomes stronger.
Practice pacing for 150 questions in 240 minutes.
Candidates should also review current governance scenarios involving cybersecurity, cloud adoption, AI, digital transformation, third-party risk, privacy, enterprise architecture, and investment management.
CGEIT is not simply a terminology exam.
Questions may describe a board concern, technology investment, governance weakness, resource problem, strategic initiative, or risk issue and ask what should happen first or what action would be most appropriate.
Several responses may appear reasonable.
The challenge is identifying the answer that best reflects enterprise governance.
For example, a technical response may solve an immediate operational problem, but the CGEIT perspective may require governance oversight, stakeholder alignment, risk evaluation, or strategic review before implementation.
This is why scenario-based practice is more valuable than memorizing definitions alone.
The CGEIT ISACA Certification is best suited to experienced professionals already working close to technology governance and enterprise decision-making.
Typical candidates may include:
CIOs
IT directors
IT governance managers
Enterprise architects
Senior risk professionals
IT strategy leaders
Senior consultants
Program leaders
Compliance executives
Digital transformation leaders
Technology governance professionals
It is usually not the right first certification for someone just entering IT.
A beginner may learn useful governance concepts from a CGEIT course, but the credential itself is designed around senior-level professional experience.
Professionals considering CGEIT often compare it with other ISACA certifications.
CISA primarily focuses on information systems auditing.
CISM focuses on information security management.
CRISC centers on IT risk management and information systems controls.
CGEIT focuses more broadly on governance of enterprise technology, including strategic alignment, value delivery, resources, and risk.
The best fit depends on the responsibilities you currently perform or want to develop.
For example, a security manager may naturally lean toward CISM, while a senior technology governance leader may find CGEIT more aligned with executive-level responsibilities.
Earning CGEIT is not the end of the certification process.
Credential holders must continue professional education, report qualifying CPE activities, pay required maintenance fees, follow professional ethics requirements, and comply with audit requirements when selected.
Continuing professional development is especially important in enterprise governance because technology changes rapidly.
Governance teams increasingly need to understand areas such as:
Artificial intelligence governance
Cloud transformation
Cybersecurity risk
Digital resilience
Privacy
Third-party risk
Data governance
Technology regulation
Enterprise architecture
Digital investment oversight
Keeping knowledge current helps CGEIT professionals remain effective as organizational technology strategies evolve.
The value of CGEIT Certification is strongest for professionals whose responsibilities already include technology governance, strategic alignment, investment oversight, enterprise risk, or value realization. It is less about proving that you can operate technology and more about demonstrating that you understand how enterprises should govern technology. For someone moving toward CIO, IT governance leadership, technology strategy, enterprise architecture, digital risk, or senior advisory responsibilities, that distinction can be valuable. A practical next step is to review the four CGEIT domains against your current responsibilities. If your work already spans governance, resources, value, and risk—and you meet or are approaching the professional experience requirements—begin with current CGEIT certification training, scenario-based practice, and the latest exam objectives. The goal is not merely to pass the CGEIT exam, but to develop the enterprise-level judgment expected from a Certified in the Governance of Enterprise IT professional.