The ISACA CISA Certification is the world's leading credential for IT audit, information systems control, and cybersecurity governance professionals. The CISA exam 2026 covers five domains, includes 150 multiple-choice questions, lasts 4 hours, and requires a scaled score of 450/800 to pass. Candidates also need relevant professional experience to earn the certification. This guide explains the CISA syllabus 2026, exam pattern, fees, requirements, certification cost, and the step-by-step process to become a Certified Information Systems Auditor.
CISA (Certified Information Systems Auditor) is a globally recognized certification offered by ISACA for professionals who audit, assess, monitor, and secure enterprise information systems.
Unlike general cybersecurity certifications, CISA focuses on IT auditing, governance, risk management, compliance, and internal controls. Organizations worldwide use CISA-certified professionals to evaluate whether technology systems are secure, reliable, and compliant with business and regulatory requirements.
IT Auditors
Information Security Analysts
Risk & Compliance Professionals
Internal Auditors
Cybersecurity Consultants
Governance & GRC Specialists
IT Managers handling audit or compliance
Feature
Details
Certification
ISACA Certified Information Systems Auditor (CISA)
Exam Questions
150 Multiple Choice Questions
Exam Duration
4 Hours
Passing Score
450 (Scaled Score)
Exam Format
Computer-Based Testing
Testing Window
Year-round scheduling
Certification Validity
Annual maintenance with CPE requirements
Skill Level
Intermediate to Advanced
The CISA exam syllabus 2026 is divided into five weighted domains that reflect real-world IT audit responsibilities.
This domain measures your ability to plan, conduct, and report IT audits.
Key topics include:
Audit standards and ethics
Risk-based audit planning
Evidence collection
Audit documentation
Reporting audit findings
Real-world example: Evaluating whether an organization's cloud infrastructure follows established audit controls.
Focuses on aligning technology with business objectives.
Topics include:
IT governance frameworks
Organizational structure
Enterprise architecture
Vendor management
Performance measurement
Professionals working with COBIT, governance policies, or enterprise IT strategy often find this section familiar.
This section evaluates project and system lifecycle knowledge.
Important areas:
SDLC
Agile and DevOps controls
Change management
System testing
Implementation reviews
The largest operational domain covers:
Incident management
Disaster recovery
Business continuity
IT service management
Database and infrastructure operations
Cloud operational controls
This domain carries significant weight and often determines overall performance.
The cybersecurity-heavy section includes:
Identity & Access Management
Network security
Encryption
Vulnerability management
Security monitoring
Data protection
Privacy controls
Candidates with security experience often perform strongly here, making it highly valuable alongside CISA CISM certification career paths.
Understanding the CISA exam pattern is just as important as studying the syllabus.
Component
Details
Questions
150
Question Type
Multiple Choice
Duration
240 Minutes
Passing Score
450/800
Negative Marking
No
Delivery
Computer-Based Exam
ISACA uses a scaled scoring model instead of raw marks.
Score range: 200–800
Passing score: 450
Every question is not equally weighted in difficulty.
Candidates receive performance feedback by domain after the exam.
One of the most searched questions is "How much is CISA?" or "How much is the CISA exam fee?"
The CISA certification cost depends primarily on whether you're an ISACA member.
Fee Type
ISACA Member
Non-Member
CISA Exam Fee
Lower member rate
Higher standard rate
ISACA Membership
Optional
Optional
Application Fee
Additional
Additional
Annual Maintenance
Required
Required
The total CISA certification fees typically include:
Exam registration
Certification application
Annual maintenance fee
Continuing Professional Education (CPE)
Joining ISACA before registering often reduces the overall CISA examination fees, especially if you plan to maintain the credential long term.
Many candidates confuse passing the exam with earning the certification. They're different.
You can take the exam before completing the experience requirement.
Create a structured study plan covering all five domains.
Schedule your preferred testing date through ISACA's authorized exam system.
Achieve the required 450 scaled score.
Submit your professional experience and agree to ISACA's Code of Professional Ethics.
Earn annual CPE credits and renew your certification each year.
To officially become certified, candidates generally need professional experience in information systems auditing, control, security, or assurance.
The experience requirement can often be reduced through approved educational substitutions, making CISA accessible to professionals with relevant academic backgrounds.
Typical qualifying experience areas include:
IT Audit
Security Operations
Risk Management
Compliance
Internal Controls
Information Assurance
Many professionals compare CISA CISM certification when planning their careers.
Feature
CISA
CISM
Primary Focus
IT Audit
Information Security Management
Ideal Role
Auditor
Security Manager
Core Skill
Assurance & Controls
Security Governance
Best For
Compliance, Audit
Leadership, Cybersecurity Strategy
Offered By
ISACA
ISACA
Choose CISA if your work revolves around auditing systems, evaluating controls, or regulatory compliance. CISM is better aligned with managing enterprise security programs.
Many senior professionals eventually hold both certifications.
The CISA IT audit framework builds practical skills beyond exam knowledge.
You'll learn to:
Identify weaknesses in enterprise controls
Evaluate cloud security governance
Assess cybersecurity risks
Audit ERP and business applications
Review access management policies
Perform evidence-based compliance assessments
Recommend risk mitigation strategies
These capabilities are highly relevant in banking, healthcare, government, consulting, and multinational enterprises.
The CISA exam schedule 2026 follows a year-round testing model rather than fixed exam dates.
Candidates can typically:
Register online.
Select a nearby testing center.
Choose an available date.
Reschedule within permitted policies if needed.
This flexible scheduling allows professionals to prepare at their own pace instead of waiting for quarterly exam windows.
Yes—but only if they're used strategically.
A strong preparation approach includes:
Domain-wise practice questions
Full-length timed mock exams
Performance analysis by domain
Reviewing explanations instead of memorizing answers
Aim to consistently score 80% or higher on realistic mock exams before attempting the actual CISA exam.
Week
Focus
1–2
Domain 1
3–4
Domain 2
5
Domain 3
6–8
Domain 4
9–10
Domain 5
11
Full Practice Tests
12
Revision & Weak Areas
A balanced schedule is more effective than trying to master every domain equally. Prioritize Domains 4 and 5 because together they represent 52% of the exam.
CISA opens opportunities across audit, governance, and cybersecurity.
Common job roles include:
IT Auditor
Senior Information Systems Auditor
Internal Audit Consultant
Cyber Risk Analyst
Governance, Risk & Compliance (GRC) Specialist
Information Security Auditor
Technology Risk Consultant
Compliance Manager
Industries hiring CISA professionals include financial services, consulting firms, healthcare, telecommunications, government, manufacturing, and cloud service providers.
CISA certification is ISACA's globally recognized credential validating expertise in information systems auditing, governance, risk, and security controls.
The CISA exam fee varies for ISACA members and non-members. The total certification cost also includes application and annual maintenance fees.
The CISA syllabus 2026 includes five domains: IT Auditing Process, Governance & Management, System Acquisition & Development, Operations & Resilience, and Protection of Information Assets.
The exam contains 150 multiple-choice questions, lasts 4 hours, and requires a 450 scaled score to pass.
Pass the ISACA CISA exam, meet the professional experience requirement, submit your certification application, and maintain annual CPE compliance.
Yes. Beginners can take the exam, although professional experience is required before ISACA awards the certification.
شهادة CISA is the Arabic term for the Certified Information Systems Auditor certification issued by ISACA.
If your goal is to build a career in IT audit, cybersecurity governance, risk, or compliance, start with the CISA syllabus 2026 and create a structured 12-week study plan. Focus on mastering the five domains, practice under timed conditions, and understand control-based thinking rather than memorizing questions. Passing the exam is only one milestone—the real value of ISACA CISA certification comes from applying audit principles to secure and improve enterprise information systems.
The ISACA CISA Certification is the world's leading credential for IT audit, information systems control, and cybersecurity governance professionals. The CISA exam 2026 covers five domains, includes 150 multiple-choice questions, lasts 4 hours, and requires a scaled score of 450/800 to pass. Candidates also need relevant professional experience to earn the certification. This guide explains the CISA syllabus 2026, exam pattern, fees, requirements, certification cost, and the step-by-step process to become a Certified Information Systems Auditor.
CISA (Certified Information Systems Auditor) is a globally recognized certification offered by ISACA for professionals who audit, assess, monitor, and secure enterprise information systems.
Unlike general cybersecurity certifications, CISA focuses on IT auditing, governance, risk management, compliance, and internal controls. Organizations worldwide use CISA-certified professionals to evaluate whether technology systems are secure, reliable, and compliant with business and regulatory requirements.
IT Auditors
Information Security Analysts
Risk & Compliance Professionals
Internal Auditors
Cybersecurity Consultants
Governance & GRC Specialists
IT Managers handling audit or compliance
Feature
Details
Certification
ISACA Certified Information Systems Auditor (CISA)
Exam Questions
150 Multiple Choice Questions
Exam Duration
4 Hours
Passing Score
450 (Scaled Score)
Exam Format
Computer-Based Testing
Testing Window
Year-round scheduling
Certification Validity
Annual maintenance with CPE requirements
Skill Level
Intermediate to Advanced
The CISA exam syllabus 2026 is divided into five weighted domains that reflect real-world IT audit responsibilities.
This domain measures your ability to plan, conduct, and report IT audits.
Key topics include:
Audit standards and ethics
Risk-based audit planning
Evidence collection
Audit documentation
Reporting audit findings
Real-world example: Evaluating whether an organization's cloud infrastructure follows established audit controls.
Focuses on aligning technology with business objectives.
Topics include:
IT governance frameworks
Organizational structure
Enterprise architecture
Vendor management
Performance measurement
Professionals working with COBIT, governance policies, or enterprise IT strategy often find this section familiar.
This section evaluates project and system lifecycle knowledge.
Important areas:
SDLC
Agile and DevOps controls
Change management
System testing
Implementation reviews
The largest operational domain covers:
Incident management
Disaster recovery
Business continuity
IT service management
Database and infrastructure operations
Cloud operational controls
This domain carries significant weight and often determines overall performance.
The cybersecurity-heavy section includes:
Identity & Access Management
Network security
Encryption
Vulnerability management
Security monitoring
Data protection
Privacy controls
Candidates with security experience often perform strongly here, making it highly valuable alongside CISA CISM certification career paths.
Understanding the CISA exam pattern is just as important as studying the syllabus.
Component
Details
Questions
150
Question Type
Multiple Choice
Duration
240 Minutes
Passing Score
450/800
Negative Marking
No
Delivery
Computer-Based Exam
ISACA uses a scaled scoring model instead of raw marks.
Score range: 200–800
Passing score: 450
Every question is not equally weighted in difficulty.
Candidates receive performance feedback by domain after the exam.
One of the most searched questions is "How much is CISA?" or "How much is the CISA exam fee?"
The CISA certification cost depends primarily on whether you're an ISACA member.
Fee Type
ISACA Member
Non-Member
CISA Exam Fee
Lower member rate
Higher standard rate
ISACA Membership
Optional
Optional
Application Fee
Additional
Additional
Annual Maintenance
Required
Required
The total CISA certification fees typically include:
Exam registration
Certification application
Annual maintenance fee
Continuing Professional Education (CPE)
Joining ISACA before registering often reduces the overall CISA examination fees, especially if you plan to maintain the credential long term.
Many candidates confuse passing the exam with earning the certification. They're different.
You can take the exam before completing the experience requirement.
Create a structured study plan covering all five domains.
Schedule your preferred testing date through ISACA's authorized exam system.
Achieve the required 450 scaled score.
Submit your professional experience and agree to ISACA's Code of Professional Ethics.
Earn annual CPE credits and renew your certification each year.
To officially become certified, candidates generally need professional experience in information systems auditing, control, security, or assurance.
The experience requirement can often be reduced through approved educational substitutions, making CISA accessible to professionals with relevant academic backgrounds.
Typical qualifying experience areas include:
IT Audit
Security Operations
Risk Management
Compliance
Internal Controls
Information Assurance
Many professionals compare CISA CISM certification when planning their careers.
Feature
CISA
CISM
Primary Focus
IT Audit
Information Security Management
Ideal Role
Auditor
Security Manager
Core Skill
Assurance & Controls
Security Governance
Best For
Compliance, Audit
Leadership, Cybersecurity Strategy
Offered By
ISACA
ISACA
Choose CISA if your work revolves around auditing systems, evaluating controls, or regulatory compliance. CISM is better aligned with managing enterprise security programs.
Many senior professionals eventually hold both certifications.
The CISA IT audit framework builds practical skills beyond exam knowledge.
You'll learn to:
Identify weaknesses in enterprise controls
Evaluate cloud security governance
Assess cybersecurity risks
Audit ERP and business applications
Review access management policies
Perform evidence-based compliance assessments
Recommend risk mitigation strategies
These capabilities are highly relevant in banking, healthcare, government, consulting, and multinational enterprises.
The CISA exam schedule 2026 follows a year-round testing model rather than fixed exam dates.
Candidates can typically:
Register online.
Select a nearby testing center.
Choose an available date.
Reschedule within permitted policies if needed.
This flexible scheduling allows professionals to prepare at their own pace instead of waiting for quarterly exam windows.
Yes—but only if they're used strategically.
A strong preparation approach includes:
Domain-wise practice questions
Full-length timed mock exams
Performance analysis by domain
Reviewing explanations instead of memorizing answers
Aim to consistently score 80% or higher on realistic mock exams before attempting the actual CISA exam.
Week
Focus
1–2
Domain 1
3–4
Domain 2
5
Domain 3
6–8
Domain 4
9–10
Domain 5
11
Full Practice Tests
12
Revision & Weak Areas
A balanced schedule is more effective than trying to master every domain equally. Prioritize Domains 4 and 5 because together they represent 52% of the exam.
CISA opens opportunities across audit, governance, and cybersecurity.
Common job roles include:
IT Auditor
Senior Information Systems Auditor
Internal Audit Consultant
Cyber Risk Analyst
Governance, Risk & Compliance (GRC) Specialist
Information Security Auditor
Technology Risk Consultant
Compliance Manager
Industries hiring CISA professionals include financial services, consulting firms, healthcare, telecommunications, government, manufacturing, and cloud service providers.
If your goal is to build a career in IT audit, cybersecurity governance, risk, or compliance, start with the CISA syllabus 2026 and create a structured 12-week study plan. Focus on mastering the five domains, practice under timed conditions, and understand control-based thinking rather than memorizing questions. Passing the exam is only one milestone—the real value of ISACA CISA certification comes from applying audit principles to secure and improve enterprise information systems.