Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA

Certified Information Systems Auditor

The Certified Information Systems Auditor (CISA) certification is the global standard for professionals who audit, control, monitor, and assess an organization's information technology and business systems. It validates your ability to apply a risk-based approach to audit engagements, covering everything from IS auditing processes to the protection of information assets. Earning CISA demonstrates your expertise in IT audit and positions you for career growth in a field where professionals earn an average salary of US$149,000+.

Exam formatComputer-based, multiple choice
DeliveryPSI
Free questions782

Content last reviewed 30 July 2026 · Up to date

The certification

What Certified Information Systems Auditor proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

5domains
24objectives
204concepts
US $575.00exam fee
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The Certified Information Systems Auditor (CISA) certification, offered by ISACA, is world-renowned as the standard of achievement for those who audit, control, monitor, and assess an organization's information technology and business systems. It affirms your ability to apply a risk-based approach to audit engagements, ensuring that IT and business systems are protected, controlled, and provide value to the organization. With a focus on emerging technologies like AI and blockchain, CISA ensures IT audit professionals stay current on the latest technology trends and advancements.

Achieving CISA certification showcases your expertise and asserts your ability to handle the challenges and responsibilities of a modern IT auditor. The certification covers five key domains: Information Systems Auditing Process, Governance and Management of IT, Information Systems Acquisition, Development & Implementation, Information Systems Operations and Business Resilience, and Protection of Information Assets. CISA is globally accepted and recognized, required by many organizations and government agencies, and proves to employers that you are ready to add value to their enterprise.

Who it’s for

The CISA certification is designed for IT professionals who are responsible for auditing, controlling, monitoring, and assessing an organization's information technology and business systems. It is ideal for mid to advanced-career IT professionals looking for leverage in career growth, including IT auditors, IS auditors, IT consultants, and security professionals. Candidates typically have experience in IT audit, control, security, or governance and are seeking to validate their expertise and advance their careers. The certification is also valuable for professionals who want to demonstrate their ability to apply a risk-based approach to audit engagements and stay current with emerging technologies.

Recommended experience

ISACA recommends that candidates have experience in IT audit, control, security, or governance. While there is no formal prerequisite, a minimum of five years of professional work experience in information systems auditing, control, or security is required for certification. Experience in information systems auditing, control, or security; Knowledge of IT governance and management; Understanding of information systems acquisition, development, and implementation; Familiarity with information systems operations and business resilience; Awareness of protection of information assets and cybersecurity principles

The syllabus

What you’ll learn

Every domain and objective ISACA measures, with the weight they carry on the exam.

The official ISACA exam outline · checked 30 July 2026 · See the source

Information Systems Auditing Process
  • Audit Frameworks and Standards
  • Audit Planning and Risk Assessment
  • Audit Execution and Evidence
  • Audit Reporting and Quality
4 objectives · 135 free questions · 29 pages
Governance and Management of IT
  • IT Governance and Strategy
  • Risk and Compliance Management
  • Resource and Vendor Management
  • Performance and Quality Management
4 objectives · 132 free questions · 28 pages
Information Systems Acquisition, Development and Implementation
  • Project Governance and Management
  • Business Case and Feasibility Analysis
  • System Development Methodologies
  • Control Identification and Design
  • System Readiness and Implementation Testing
  • Implementation Configuration and Release Management
  • System Migration, Infrastructure Deployment, and Data Conversion
  • Post-implementation Review
8 objectives · 275 free questions · 58 pages
Information Systems Operations and Business Resilience
  • IT Operations Management
  • Business Resilience and Continuity
2 objectives · 74 free questions · 16 pages
Protection of Information Assets
  • Security Frameworks and Governance
  • Physical and Environmental Security
  • Identity and Access Management
  • Network, Endpoint, and Data Security
  • Security Operations and Monitoring
  • Incident Response and Forensics
6 objectives · 166 free questions · 35 pages
On the day

The exam itself

Everything ISACA publishes about sitting it, and nothing we inferred.

Prerequisites

Pass the CISA certification exam.

CertificationCertified Information Systems Auditor
Exam formatComputer-based, multiple choice
Questions150 questions
DeliveryPSI
LanguagesEnglish, Chinese Simplified, French, German, Japanese, Korean, Spanish
PricingUS $575.00
After you pass

Where this credential goes next

The path ISACA lays out, how the credential is kept, and where to book.

Step-by-step path to Certified Information Systems Auditor

PrerequisitePass the CISA certification exam.
Certified Information Systems Auditor badgeCredential earnedCertified Information Systems Auditor Certification
Renewal and maintenance

CISA certification requires renewal through earning Continuing Professional Education (CPE) credits. Certification holders must adhere to the Continuing Professional Education Policy to maintain their credential. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. ISACA maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by ISACA

Exam registration

Register for the exam through PSI, ISACA’s authorized testing partner.

Schedule your exam

Visit the official ISACA certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does the CISA exam relate to the AAIA certification?

The AAIA (Advanced in AI Audit) certification is designed for professionals who hold a CISA certification or another qualified designation. It builds on the expertise validated by CISA and focuses on AI-specific audit skills.

Do I need to hold a lower-level ISACA certification before taking the CISA exam?

No, there is no prerequisite certification required to take the CISA exam. However, to earn the CISA credential, you must meet the experience and ethical requirements.

Can I reschedule my CISA exam appointment?

Yes, you can reschedule your CISA exam anytime without penalty during your eligibility period if done a minimum of 48 hours prior to your scheduled testing appointment.

What are the identification requirements for the CISA exam?

You must present a government-issued identification that matches the name on your ISACA account. If you are creating an account, ensure your name matches what appears on your government-issued ID.

Is there a hands-on or lab component in the CISA exam?

No, the CISA exam consists of 150 multiple-choice questions. There is no hands-on or lab component.

What is the retake policy for the CISA exam?

ISACA does not specify a retake policy on the official page. Candidates should refer to the exam candidate guide or contact ISACA for details.

Are there any discounts or vouchers available for the CISA exam?

ISACA members receive a discounted exam fee of US$575.00 compared to the non-member fee of US$760.00. No other discounts or vouchers are mentioned on the official page.

How soon will I receive my CISA exam results?

The official page does not specify the exact timing for score release. Candidates should refer to the exam candidate guide or contact ISACA for details.

What job roles does the CISA credential map to?

CISA is designed for IT professionals who audit, control, monitor, and assess an organization's information technology and business systems. It is a must-have for mid to advanced-career IT professionals looking for leverage in career growth.

Can I recertify by passing a different ISACA exam?

ISACA certifications require renewal through earning CPE credits. Passing a different exam may contribute to CPE credits, but the official page does not specify that passing another exam automatically renews CISA.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 782 questions, free, no account needed.