CGEIT · ● Active · Expert · ISACA
Enterprise IT governance is the discipline of directing and controlling IT to align with organizational strategy. CGEIT validates mastery of governance frameworks, risk optimization, benefits realization, and IT resource management at the executive level.
Exam facts
| Field | Value |
|---|---|
| Cost | $575 ISACA members / $760 non-members |
| Duration | 4 hours (240 minutes) |
| Questions | 150 multiple-choice |
| Passing | 450/800 scaled score |
| Format | Computer-based (CBT) |
| Delivery | PSI testing centers (in-person & remote proctored); OnVUE |
| Languages | English, Simplified Chinese |
| Valid | 3 years |
| Renewal | 120 CPE hours per 3-year cycle (minimum 20/year); $45 members / $85 non-members annual maintenance |
| Prerequisites | 5 years IT governance experience (across ≥3 of 4 domains, minimum 1 year Domain 1); must apply within 5 years of passing |
| Released | Not specified (established certification) |
| Retiring | N/A |
Vendor source — ISACA CGEIT Certification Page ↗
Official exam guide — CGEIT Exam Content Outline ↗
Maintenance requirements — CGEIT Maintenance ↗
About
CGEIT is ISACA's expert-level certification in enterprise IT governance. Launched to address the critical need for governance professionals in large organizations, it validates competency in directing IT strategy, managing governance frameworks, optimizing risk, and aligning IT investments with business objectives. Unlike entry-level certifications, CGEIT requires 5 years of hands-on governance experience and tests deep architectural and strategic knowledge.
The certification represents mastery across all four domains of IT governance: the framework itself (COBIT, ITIL), resource allocation and management, tangible business value delivery, and enterprise risk optimization. Candidates must demonstrate not only technical knowledge of governance models but strategic insight into how IT governance enables or constrains business transformation.
CGEIT is the primary credential for IT governance officers, enterprise architects in governance roles, CIOs, compliance/GRC leaders, and risk managers in IT-heavy organizations. The 5-year experience requirement ensures holders have lived through real governance challenges and can speak to implementation complexity, organizational resistance, and pragmatic trade-offs.
Exam difficulty: CGEIT is positioned as an expert-level certification with a reported pass rate of approximately 55-60%. Success requires not just memorization of frameworks but ability to apply governance principles to real-world scenarios and trade-off decisions.
Domain context — Governance
IT governance is the strategic alignment of IT investments, risk management, and business value realization. It encompasses frameworks (COBIT, ITIL), compliance regimes (SOX, GDPR, HIPAA), board-level oversight, and the institutional structures that ensure IT serves enterprise objectives rather than operating in isolation.
Key domains within IT governance include:
- Strategic alignment — ensuring IT priorities map to business strategy, CIO reports to the CFO or CEO, IT strategy is reviewed by the board
- Value delivery — managing IT investments and benefits tracking, post-implementation reviews, portfolio management
- Risk and compliance — enterprise-wide risk management, regulatory obligations, audit readiness, third-party oversight
- Resource management — hiring, budgeting, vendor relationships, capability development, capacity planning
- Performance management — KPIs, SLAs, service quality metrics, IT scorecard development
- Organizational structure — roles, accountability, reporting lines, governance committees, decision rights frameworks
ISACA Governance & Audit Ecosystem Overview ↗
Topics covered
The CGEIT exam blueprint is divided into four domains with the following weight distribution:
Domain 1: Governance of Enterprise IT (40% — ~60 questions)
- IT governance frameworks and standards (COBIT 2019, ITIL 4, ISO 38500, ISO 27001)
- Enterprise architecture, strategic IT planning, and IT strategy roadmaps
- Governance structures, roles, accountability, and board-level IT oversight
- Governance committee composition and decision-making frameworks
- C-suite responsibilities and board reporting on IT matters
- Information classification, data governance, and stewardship models
- Regulatory compliance frameworks (SOX, GDPR, HIPAA, PCI-DSS)
- Strategy alignment and IT investment decision-making
- IT governance maturity models and continuous improvement
- Organizational change management for governance adoption
- IT policies and standards development and enforcement
- Stakeholder communication and governance education
- Enterprise architecture governance and technology selection
Domain 2: IT Resources (15% — ~22 questions)
- IT resource planning, forecasting, and allocation
- Human capital management (skills development, hiring, retention strategies)
- IT workforce planning and competency frameworks
- Infrastructure and technology asset management and lifecycle
- Vendor management and third-party risk assessment
- Sourcing strategies (insourcing, outsourcing, hybrid models)
- IT service contracts and SLA management
- Capacity planning and resource optimization
- Financial management of IT resources (budgeting, cost allocation, ROI)
- IT workforce retention and succession planning
- Skills inventory and capability assessments
- Cloud resource governance and cost optimization
- Make-vs-buy decisions and technology refresh cycles
Domain 3: Benefits Realization (26% — ~39 questions)
- IT investment management and portfolio governance frameworks
- Portfolio prioritization and decision-making processes
- Business case development and financial justification
- Performance measurement, KPI definition, and IT scorecard development
- Benefits tracking and realization monitoring
- Post-implementation reviews and benefits validation
- IT-enabled business transformation oversight
- Cost-benefit analysis and ROI measurement methodologies
- Value realization governance and monitoring
- IT service quality management and user satisfaction
- Portfolio risk management and optimization
- Strategic alignment of IT investments with business objectives
- Business continuity of IT-enabled services
- Benefits ownership and accountability frameworks
Domain 4: Risk Optimization (19% — ~28 questions)
- Enterprise risk management integration with IT strategy
- Risk assessment methodologies and tools
- Risk mitigation planning and monitoring
- Business continuity planning and disaster recovery
- IT resilience and availability requirements
- Security risk framework integration (ISO 27001, NIST)
- Compliance risk management and regulatory adherence
- IT risk appetite and tolerance definition
- Crisis management and incident response governance
- Third-party and supply-chain risk management
- Risk reporting to the board and executive leadership
- Insurance and financial hedging for IT risks
- IT audit coordination and control effectiveness monitoring
- Risk committee structures and escalation procedures
Source: CGEIT Exam Content Outline ↗
Common skills at Governance · Expert
Shared competencies expected of expert-level governance professionals — not specific to CGEIT but core to the domain:
- Board-level communication, executive presentation, and business case articulation
- Strategic IT planning and business alignment methodologies
- Organizational change management and stakeholder engagement
- Enterprise architecture principles and IT strategy development
- Risk assessment, quantification, and mitigation at scale
- Regulatory compliance, audit coordination, and control design
- IT portfolio and investment management frameworks
- Vendor negotiation, contract development, and relationship management
- Cross-functional leadership and executive decision-making
- Financial acumen, IT budgeting, and cost management
- Metrics definition, KPI development, and performance tracking
- Governance framework implementation and organizational adoption
- Policy development, enforcement, and stakeholder communication
- Enterprise-wide decision rights and governance structures
Recommended courses at Governance · Expert
| Provider | Title | Cost | URL |
|---|---|---|---|
| ISACA Official | CGEIT Self-Paced Learning (Online) | $799 (members) / $999 (non-members) | ↗ |
| Infosec Institute | CGEIT Certification Training | $399–$599 | ↗ |
| Learning Tree | CGEIT Certification Training (Instructor-Led) | Contact for pricing | ↗ |
| Udemy | CGEIT Certification Exam Prep | $13–$49 | ↗ |
| CBT Nuggets | IT Governance and CGEIT | $299–$399/year | ↗ |
Course-selection note: CGEIT is less saturated with third-party training than entry-level certifications. ISACA's official self-paced learning is widely recommended for detailed domain coverage. Many candidates supplement with COBIT 2019 frameworks training (separate) and general IT governance books rather than dedicated CGEIT courses. Instructor-led bootcamps are increasingly available through learning providers as demand grows. Most candidates study for 3-6 months part-time before attempting the exam.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| ISACA Official | CGEIT Sample Questions | Free (registered candidates) | ↗ |
| Boson ExSim-Max | CGEIT Practice Exam | $99 | ↗ |
| Whizlabs | CGEIT Practice Tests | $39–$59 | ↗ |
Practice exam note: Official ISACA sample questions are limited but critical to review. Third-party options focus on domain-heavy scenarios and multi-domain integration questions. Practice exams typically emphasize Domain 1 (40%) and Domain 3 (26%) weight, as these represent two-thirds of the exam. Candidates should expect scenario-based questions requiring judgment across competing priorities (cost vs. risk, speed vs. governance). Multiple practice exam attempts are recommended; many candidates report their first attempt score around 50-60%, then improve with study.
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| CGEIT Study Guide | ISACA (official) | ISACA | 2021 | 978-1604202167 | ↗ |
| Governance of Enterprise IT: What Every CIO Needs to Know | Michael Gentile & Cori Stackpole | Wiley | 2020 | 978-1119559467 | ↗ |
| COBIT 2019 Framework | ISACA | ISACA | 2019 | 978-1604202588 | ↗ |
| The IT Governance Body of Knowledge | Alan W. Ward | Technics Publications | 2019 | 978-1634620215 | ↗ |
| IT Governance: How Top Performers Manage IT Decision Rights | Peter Weill & Jeanne Ross | Harvard Business Review Press | 2004 | 978-1591397373 | ↗ |
Book note: CGEIT does not have as extensive a third-party publishing ecosystem as CISA. The ISACA official study guide is considered essential and covers all four domains comprehensively. Many candidates also study COBIT 2019 and ISO 38500 frameworks, which form the backbone of Domain 1. The Gentile & Stackpole text is the most frequently cited third-party governance reference. The Weill & Ross book, while older, remains influential for understanding governance decision frameworks and is often referenced in exam scenarios.
Typical job titles at Governance · Expert
IT Governance Officer · Chief Information Officer (CIO) · Enterprise Architect (Governance) · IT Director · GRC (Governance, Risk & Compliance) Manager · Chief Risk Officer (IT focus) · Audit Manager (IT) · Chief Technology Officer (CTO) · VP of IT Operations · Head of IT Service Delivery · IT Compliance Officer · IT Portfolio Manager · IT Steering Committee Chair
(Job titles drawn from ISACA member data and enterprise job postings listing CGEIT as required or preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $134,000–$141,000 | ZipRecruiter ↗ · PayScale ↗ · Coursera ↗ |
| ZAR | R2,233,780–R2,350,470 | Derived from USD at 16.67 ZAR/USD (May 2026) |
| GBP | No region-specific data available — use ISACA member salary survey | |
| EUR | No region-specific data available — use ISACA member salary survey | |
| AUD | No region-specific data available — use ISACA member salary survey |
Salary context: CGEIT holders typically occupy executive or senior management roles with salaries 25% higher than non-certified peers. Entry-level governance roles (risk management officer, IT control specialist) earn $88,000–$110,000; senior roles (CIO, GRC director) reach $140,000–$207,000. Salary growth averages 14% year-over-year for certified professionals. Salary uplift is most significant in regulated industries (financial services, healthcare, energy) where governance maturity is a competitive differentiator. Fortune 500 companies and large enterprises are the primary employers of CGEIT-certified professionals.
Salary source note: Detailed regional (GBP, EUR, AUD) salary surveys for CGEIT specifically are not publicly available. ISACA member surveys provide more granular regional data but require membership access. US-based salary data is most reliable; international data should be inferred from general IT leadership compensation benchmarks.
Skills validated
Concrete competencies tested by this exam:
- Enterprise IT governance framework design and implementation (COBIT, ITIL, ISO 38500)
- IT strategy alignment and C-suite communication
- IT portfolio management and investment optimization
- Risk management and compliance integration (SOX, GDPR, HIPAA, NIST frameworks)
- Business continuity, disaster recovery, and resilience planning
- IT service level management and vendor governance
- Organizational change and stakeholder management
- Board and audit committee reporting structures
- Metrics, KPI definition, and IT performance measurement
- Benefits realization planning and tracking
- IT budgeting and financial resource allocation
- IT governance maturity assessment and improvement
- Third-party risk management and vendor relationships
- Enterprise architecture alignment with governance
- Regulatory compliance frameworks (industry-specific)
- IT decision rights frameworks and organizational structures
- Strategic IT planning and scenario analysis
- Stakeholder engagement and communication strategies
Related certifications
- Stacks with: ISACA CISA ↗ (Certified Information Systems Auditor — foundational audit complement)
- Prerequisite for: ISACA CISM ↗ (CISM focuses on security governance; CGEIT is broader IT governance)
- Replaces: None (original credential, no renamed predecessor)
- Equivalents at this level: ITIL Expert ↗ (framework-specific alternative)
- Vendor overview: ISACA Overview ↗
Sources
- ISACA CGEIT Certification Page
- CGEIT Exam Content Outline
- CGEIT Maintenance Requirements
- How to Get CGEIT Certified
- Infosec Institute — CGEIT Certification
- Learning Tree — CGEIT Training
- ZipRecruiter — CGEIT Salary
- PayScale — CGEIT Salary
- Coursera — What Is CGEIT Certification
- FlashGenius — Ultimate Guide to CGEIT
- CBT Nuggets — Is the CGEIT Worth It?
- X-Rates — USD to ZAR Exchange Rate (May 2026)
Last verified: 2026-05-01 Parent ecosystem: ISACA Governance & Audit Ecosystem Parent domain: IT Governance Vendor overview: ISACA
Exam preparation strategy
Timeline: Most candidates allocate 4-6 months of part-time study (10-15 hours per week) before attempting CGEIT. Those with recent hands-on governance experience may prepare faster; those further from the work should allow additional time.
Study approach:
- Read the official CGEIT study guide (8-10 weeks) while reviewing the exam content outline to identify weak areas
- Study COBIT 2019 framework documentation and ISO 38500 (2-3 weeks) — these underpin Domain 1
- Work through practice exams weekly; aim for 70%+ on multiple attempts before scheduling the live exam
- Join ISACA study groups or forums to discuss governance scenarios and exam strategies
- Schedule the exam once you consistently score 650+ on practice exams (indicating strong foundation)
Weak areas for candidates:
- Domain 3 (Benefits Realization) specifics — candidates often treat it as generic project management rather than governance-level benefits tracking
- Domain 4 (Risk Optimization) quantitative methods — risk quantification, heat maps, and risk scoring require careful study
- Multi-domain scenario questions — the exam integrates across domains; single-domain memorization is insufficient
Strength areas for experienced candidates:
- Domain 1 (Governance frameworks) — those with audit or compliance background often score highest here
- Domain 2 (IT Resources) — candidates with hiring, budgeting, or vendor experience typically perform well
Exam day tips:
- Read each question fully before answering; multi-domain scenario questions can be misread under time pressure
- Flag difficult questions and return to them if time permits (unlikely with 150 questions in 240 minutes)
- Watch for questions that ask "what is FIRST" or "what should happen BEFORE" — governance has logical sequencing
- Scenario-based questions reward understanding trade-offs, not just textbook answers
Eligibility & application
Experience requirement verification:
- Must document 5 years of IT governance experience within 10 years preceding the application
- Experience must span at least 3 of 4 CGEIT domains; minimum 1 year in Domain 1
- Work experience must be verified by a supervisor or manager
- ISACA may request additional documentation or clarification on claimed experience
Application timeline:
- Must apply for certification within 5 years of passing the exam
- Application review typically takes 2-4 weeks
- After approval, you earn the CGEIT credential and can list it publicly
- Annual maintenance must be paid to retain the credential (non-optional)
Renewal process:
- Every 3 years, renew by submitting 120 CPE hours and paying annual maintenance fee
- CPE can come from training, conferences, publications, or teaching
- At least 20 CPE per year (60 per 3-year period) must come from formal activities
- CPE hours are tracked through the ISACA portal; documentation must be retained for 12 months post-renewal
CGEIT vs. related certifications
CGEIT vs. CISA: CISA (Certified Information Systems Auditor) is the audit-focused sibling. CISA candidates need 5 years of information systems auditing, security, or control experience. CGEIT is broader (governance, risk, benefits, resources) and appeals to practitioners in IT leadership rather than audit. Many professionals hold both; they are complementary rather than competitive.
CGEIT vs. CISM: CISM (Certified Information Security Manager) focuses on security governance. CGEIT is IT-wide governance. CISM is appropriate for Chief Security Officers or IT security directors; CGEIT for CIOs and IT governance officers. The two certifications validate different domains but share some governance principles.
CGEIT vs. ITIL Expert: ITIL Expert is framework-specific (IT Service Management). CGEIT is broader governance. ITIL Expert candidates need ITIL foundation and intermediate certifications before attempting expert level. CGEIT candidates come directly to the expert level. ITIL Expert is relevant for IT service managers; CGEIT for IT governance professionals.
Final exam tips for success
Content mastery focus: The exam rewards understanding governance principles and frameworks over isolated facts. Memorize COBIT 2019 governance objectives and ISO 38500 principles; understand how they apply to real organizations.
Scenario interpretation: Expect questions like: "An organization is evaluating a major IT investment. The board has set IT risk appetite at 'moderate.' Which governance structure would BEST support this decision?" Success requires knowing decision rights, risk frameworks, and governance committee roles.
Time management: 150 questions in 240 minutes = 1.6 minutes per question. Scenario-based questions (the harder ones) will consume 3-4 minutes. Shorter knowledge questions should take 30-45 seconds. Budget accordingly.
Confidence factors: Candidates who scored 70%+ on official ISACA sample questions and 75%+ on third-party practice exams reported 90%+ pass rates. Scoring below 65% on practice exams suggests more study time is needed.
What CGEIT does NOT cover
CGEIT is not a technical certification and does not test:
- Specific technologies (cloud platforms, database systems, programming languages)
- IT operations or infrastructure management (covered by other certifications)
- IT project management specifics (covered by PMP or PRINCE2)
- Cybersecurity technical controls (covered by CISSP or Security+)
- Service management operations (covered by ITIL)
CGEIT is strategic and governance-focused, not tactical or technical.