CISA Certification is ISACA’s globally recognized credential for professionals who audit, control, monitor, and assess information systems. The 2026 exam contains 150 multiple-choice questions, lasts 4 hours, and covers five domains. Current exam fees are US$575 for ISACA members and US$760 for nonmembers, plus a US$50 certification application fee after passing. Candidates may register year-round, schedule through PSI, and must meet ISACA’s experience requirements before receiving the full CISA designation. Scaled score of 450 or higher is required to pass.
CISA stands for Certified Information Systems Auditor. It is issued by ISACA and focuses on IT audit, governance, systems acquisition, operations, resilience, and protection of information assets. The credential is designed for professionals who evaluate whether technology controls support business objectives, protect data, manage risk, and meet governance requirements.
Unlike a general cybersecurity credential, the ISACA CISA certification is strongly audit-oriented. A CISA professional must understand how to collect evidence, assess control effectiveness, report findings, evaluate business impact, and apply a risk-based audit approach. That makes CISA IT audit knowledge useful across assurance, compliance, governance, and cybersecurity review roles.
The current CISA syllabus 2026 follows the exam content outline effective from August 2024. ISACA divides the exam into five job-practice domains. The two largest domains are Information Systems Operations and Business Resilience and Protection of Information Assets, each carrying 26% of the exam.
CISA Exam Domain
Weight
Information System Auditing Process
18%
Governance and Management of IT
18%
Information Systems Acquisition, Development and Implementation
12%
Information Systems Operations and Business Resilience
26%
Protection of Information Assets
26%
This part of the CISA exam syllabus covers risk-based audit planning, audit standards, control types, evidence, sampling, testing, data analytics, reporting, communication, and quality assurance.
This domain examines IT governance, organizational structures, policies, enterprise architecture, risk management, resource management, performance monitoring, and alignment of technology with business objectives.
Candidates are tested on project governance, business cases, system development, implementation controls, testing, data conversion, change management, and post-implementation review.
This domain covers IT operations, asset management, incident and problem management, change management, backups, disaster recovery, business continuity, capacity, monitoring, and service management.
This section focuses on logical and physical access, security architecture, network security, encryption, data protection, privacy, vulnerability management, security monitoring, and incident response.
The CISA exam pattern includes 150 multiple-choice questions and provides 4 hours, or 240 minutes, to complete them. ISACA reports scores on a 200–800 scale, and 450 is the minimum passing score.
CISA questions frequently ask for the BEST, MOST appropriate, or FIRST action. Two choices may look technically correct, but only one may match audit priority, independence, evidence requirements, governance responsibility, or risk-based decision-making.
Good preparation should include scenario-based CISA practice tests that train you to choose the most defensible audit response.
If you are asking how much is CISA or how much is the CISA exam fee, the official 2026 pricing is:
ISACA member CISA exam fee: US$575
Nonmember CISA exam fee: US$760
Certification application processing fee after passing: US$50
ISACA states that exam registration fees are nonrefundable and nontransferable.
The CISA certification cost can include more than the exam itself. Total spending may also include membership, training, official review materials, question databases, and retake fees. Training providers set their own CISA course fees, so these should not be confused with official CISA examination fees.
For candidates comparing the CISA certification price or CISA test cost, separate official ISACA charges from optional preparation expenses so the budget remains accurate.
There is no single fixed CISA exam schedule 2026. Registration is continuous, so candidates can register throughout the year. After registration, the exam eligibility period lasts six months. Testing is offered at authorized PSI test centers and through remote proctoring, subject to availability.
Candidates can schedule as early as 48 hours after payment, while appointments are generally displayed up to 90 days in advance.
The scheduling process is:
Sign in to your MyISACA account.
Purchase the ISACA CISA exam registration.
Open Certification & CPE Management.
Select Schedule Your Exam.
Continue to PSI and choose an available appointment.
This flexible schedule allows candidates to choose an exam date based on preparation level rather than waiting for a fixed annual testing window.
You can take the exam before completing the experience requirement, but passing alone does not automatically give you the full CISA certificate.
To understand how to get CISA, follow this path:
Pass the CISA exam.
Pay the US$50 application fee.
Document the required professional experience.
Submit the certification application within five years of passing.
Agree to ISACA’s ethics, auditing, and maintenance requirements.
For full certification, ISACA CISA requirements include at least five years of professional information systems auditing, control, or security experience, earned within the 10 years before the application. Candidates have five years after passing the exam to apply.
After certification, CISA holders must report at least 20 CPE hours each year and 120 CPE hours over three years to maintain the credential.
The phrase CISA CISM certification often appears when professionals compare ISACA credentials, but they serve different career goals.
CISA is best aligned with IT audit, assurance, compliance, control testing, and risk-based assessment. CISM focuses more on information security governance, risk management, security program development, and incident management.
If your role asks, “Are controls designed and operating effectively?” CISA is usually the stronger first choice. If it asks, “How should the organization build and manage its security program?” CISM may be more aligned.
For professionals moving between audit, security leadership, risk, and governance, the two certifications can also complement each other.
A strong study plan should follow the exam weights rather than divide time equally. Domains 4 and 5 together represent 52% of the exam, so weak performance in operations, resilience, and information-asset protection can create a major preparation gap.
Use this approach:
Learn the audit mindset before memorizing technology terms.
Map every topic to risk, control objective, evidence, and business impact.
Spend more time on higher-weight domains.
Use timed CISA practice tests after each domain.
Review why incorrect options are wrong.
Practice identifying control owners, operators, and independent reviewers.
Effective ISACA CISA training should teach decision-making, not simply provide slides or definitions. A technically strong candidate can still lose marks by choosing an operational fix when the question expects an auditor to evaluate evidence, escalate risk, maintain independence, or recommend the appropriate control response.
One useful technique is to ask four questions while solving scenarios: What is the risk? Who owns the risk? What evidence should the auditor obtain? What action should come first? This helps separate technically possible answers from audit-focused answers.
CISA certification is particularly valuable for professionals working in:
IT auditing
Internal audit
Cybersecurity assurance
IT governance
Information security
Technology risk
Regulatory compliance
Controls testing
Third-party risk
Information systems management
Beginners can also take the exam before meeting the full experience requirement. ISACA allows candidates to pass first and complete the certification requirements afterward, provided the application is submitted within the permitted five-year period.
The strongest route to CISA Certification combines the official syllabus, disciplined domain study, scenario-based practice, and familiarity with ISACA’s audit logic. Before booking the exam, confirm that you understand the five-domain CISA syllabus, can manage 150 questions within four hours, and perform consistently on realistic practice exams.
For structured ISACA CISA training, exam-focused preparation, and guided practice, explore the CISA training options available through NYTCC and build your study plan around your target exam date.