The CRISC certification from ISACA validates professional capability in IT risk management, governance, risk assessment, risk response, reporting, and information systems controls. The current CRISC exam contains 150 questions, allows four hours, and covers four domains weighted from 20% to 32%. Candidates need a scaled score of 450 or higher to pass. Certification also requires at least three years of relevant professional experience across two or more CRISC domains and completion of ISACA’s certification application process.
CRISC, short for Certified in Risk and Information Systems Control, is an ISACA credential built for professionals responsible for identifying, assessing, responding to, monitoring, and reporting technology-related business risk.
Unlike certifications focused mainly on technical security configuration, the ISACA CRISC certification sits at the intersection of technology, governance, business objectives, risk ownership, and controls.
That makes it particularly relevant for professionals working in:
IT risk management
Cybersecurity governance
Governance, Risk and Compliance (GRC)
Information security
IT audit and assurance
Enterprise risk management
Internal controls
Compliance
Technology management
Third-party and supply-chain risk
A useful way to understand CRISC is this: a security engineer may ask, “How do we technically secure this system?” A CRISC-focused professional must also ask, “What business risk does this system create, how significant is that risk, who owns it, which controls are justified, and how should management monitor it?”
That business-to-technology connection is central to the credential.
ISACA updated the CRISC exam content in November 2025, and the revised structure is the relevant framework for candidates preparing in 2026. The examination continues to cover four major job-practice domains, with revised weighting across Risk Assessment and Technology and Security.
CRISC Exam Detail
Current Information
Certification
Certified in Risk and Information Systems Control
Provider
ISACA
Exam Questions
150
Exam Duration
4 hours
Passing Score
450 out of 800 scaled score
Exam Domains
4
Testing Method
PSI testing center or remote proctoring
Registration
Continuous
Certification Application Fee
US$50
ISACA uses a scaled scoring system ranging from 200 to 800. A score of 450 or higher is required to pass. Domain-level results can help candidates understand their performance, but the final pass/fail result is based on the total exam score rather than requiring candidates to pass every domain separately.
Understanding domain weighting is one of the most important parts of CRISC exam preparation.
Domain
Weight
Domain 1: Governance
26%
Domain 2: Risk Assessment
22%
Domain 3: Risk Response and Reporting
32%
Domain 4: Technology and Security
20%
These percentages are based on ISACA’s current CRISC Exam Content Outline.
Governance tests whether you can connect technology risk with organizational strategy and decision-making.
Important areas include organizational goals, governance structures, roles and responsibilities, policies, business resilience, enterprise risk management, risk appetite, risk tolerance, risk profiles, legal requirements, and regulatory obligations.
Candidates often underestimate this domain because it does not feel as technical as cybersecurity. That can be a mistake. CRISC expects candidates to understand why risk decisions exist within a business context.
Risk Assessment focuses on identifying threats, vulnerabilities, risk events, and possible business impact.
You should understand concepts such as threat modeling, risk scenarios, business impact analysis, risk registers, inherent risk, residual risk, qualitative assessment, and quantitative assessment.
Strong candidates do more than calculate or classify risk. They understand how risk information affects business decisions.
At 32%, this is the largest CRISC exam domain.
Topics include risk-response options, control ownership, vendor risk, control frameworks, control design, implementation, testing, risk action plans, Key Risk Indicators, Key Performance Indicators, Key Control Indicators, dashboards, scorecards, and emerging-risk reporting.
Because almost one-third of the exam is associated with this domain, your CRISC training should devote significant attention to risk treatment and control-management scenarios.
A common exam-style distinction is between recognizing a risk and deciding what should happen after that risk has been analyzed. Candidates should understand when organizations accept, mitigate, transfer, or avoid risk and who should authorize those decisions.
This section connects risk management with practical technology operations.
Areas include enterprise architecture, change management, DevOps, incident management, system development, data lifecycle management, projects, technology resilience, disaster recovery, emerging technologies, security frameworks, awareness programs, privacy, and data protection.
You do not need to approach this section as a hands-on engineering examination. The important skill is understanding technology from a risk-and-control perspective.
One important distinction is that the requirements for taking the CRISC exam and becoming CRISC certified are different.
ISACA states that candidates can take the examination before meeting the professional experience requirement. However, passing the exam alone does not immediately make someone CRISC certified.
To earn the certification, candidates must:
Pass the CRISC exam.
Have at least three years of relevant professional experience.
Have experience across at least two of the four CRISC domains.
Ensure the qualifying experience falls within the 10 years preceding the certification application.
Apply for certification within five years of passing the exam.
Pay the US$50 certification application fee.
Agree to comply with ISACA's professional and certification requirements.
This structure benefits professionals who are still building experience. You may complete the examination first and then satisfy the remaining experience requirement within the allowed certification application period.
The CRISC certification cost has several components. Candidates should distinguish the exam registration price from certification application and ongoing maintenance costs.
According to ISACA's current pricing, the CRISC exam cost is:
ISACA Member: US$575
Non-Member: US$760
After passing and meeting the requirements, candidates pay a separate US$50 certification application processing fee.
Certification holders must also pay annual maintenance fees. Current annual CRISC maintenance fees are US$45 for ISACA members and US$85 for non-members.
CRISC courses, books, question banks, and instructor-led CRISC certification training may create additional preparation costs depending on the learning method selected.
The difficulty of the CRISC exam comes less from memorizing terminology and more from choosing the best risk-management decision within a scenario.
A candidate may understand what a vulnerability is but still struggle when asked what management should do first after discovering it.
CRISC questions frequently require you to think about:
business objectives → risk → ownership → assessment → controls → monitoring → reporting
This sequence is more valuable than trying to memorize isolated facts.
For example, imagine a business discovers a major vulnerability in a third-party platform. A purely technical response might be to immediately implement additional security controls.
A risk-management response asks additional questions. What business process is affected? What is the likelihood and impact? Who owns the risk? Does the current exposure exceed risk tolerance? What contractual controls exist? What treatment decision should be recommended?
That mindset is essential for CRISC.
A strong CRISC course should follow the current ISACA Exam Content Outline rather than an outdated syllabus.
Your CRISC certification training should combine conceptual learning with scenario-based practice.
Look for preparation covering:
Governance and business objectives
Enterprise risk management
Risk appetite and tolerance
Risk identification
Threats and vulnerabilities
Risk scenario development
Business impact analysis
Risk registers
Inherent and residual risk
Risk-response strategies
Control selection and design
Control testing
Vendor and supply-chain risk
KRIs, KPIs, and KCIs
Risk reporting
Technology resilience
Information security frameworks
Emerging technology risk
ISACA currently offers several official preparation options, including a CRISC Online Review Course, review manuals, practice resources, study groups, and a Questions, Answers & Explanations database. Its current question database contains a pool of 833 practice items.
A practical study process can be divided into five stages.
Step 1: Study the latest exam outline.
Before buying a course or starting a study plan, compare the material with the current four CRISC domains.
Step 2: Build your risk-management foundation.
Make sure you clearly understand risk appetite, tolerance, ownership, inherent risk, residual risk, controls, KRIs, and governance.
Step 3: Practice scenario-based questions.
CRISC preparation should teach decision-making rather than simple vocabulary recall.
Step 4: Review every incorrect answer.
Do not only track your score. Understand why another response was more appropriate.
Step 5: Complete timed mock exams.
With 150 questions and four hours available, candidates have an average of about 96 seconds per question. Practice should therefore include both accuracy and pacing.
One useful exam technique comes directly from ISACA's candidate guidance: pay close attention to qualifiers such as MOST, BEST, and similar wording, eliminate clearly incorrect options, and answer every question because incorrect responses do not carry a separate penalty.
CRISC is particularly relevant when your responsibilities extend beyond cybersecurity technology into decisions about business risk.
A network engineer who mainly configures infrastructure may not use CRISC concepts every day. A security professional who regularly speaks with management, evaluates risk, recommends controls, handles compliance requirements, works with vendors, manages risk registers, or reports security exposure to stakeholders is much closer to the certification's intended skill set.
This distinction matters when comparing CRISC with purely technical certifications.
CRISC asks whether you can help an organization make defensible risk-based decisions, not simply whether you know how a security technology works.
Passing the exam is not the end of the certification lifecycle.
CRISC holders must earn at least 20 Continuing Professional Education hours each year and at least 120 CPE hours during every three-year reporting period. They must also pay annual maintenance fees and comply with ISACA's Code of Professional Ethics and applicable audit requirements.
These requirements are designed to keep the credential connected to current professional practice rather than treating certification as a one-time achievement.
Start your CRISC certification preparation with the current ISACA exam outline, not an old study plan. Give particular attention to Risk Response and Reporting, which now represents 32% of the exam, but do not ignore governance and business-oriented questions.
Choose CRISC training that teaches you how to analyze risk scenarios, identify ownership, evaluate controls, understand residual risk, and communicate risk to decision-makers. Use practice questions to improve judgment rather than memorize answers, then move into timed mock examinations as your test date approaches.
The strongest CRISC candidates learn to think beyond “What is the technical problem?” and consistently ask the more important question: “What should the organization do about the risk, and why?”