Certified in the Governance of Enterprise IT

ISACA · CGEIT · Expert

ISACA · ISACA Governance & Audit Ecosystem

Certified in the Governance of Enterprise IT

CGEITactiveExpert
Official ISACA source · isaca.org

CGEIT · ● Active · Expert · ISACA

Enterprise IT governance is the discipline of directing and controlling IT to align with organizational strategy. CGEIT validates mastery of governance frameworks, risk optimization, benefits realization, and IT resource management at the executive level.


Exam facts

FieldValue
Cost$575 ISACA members / $760 non-members
Duration4 hours (240 minutes)
Questions150 multiple-choice
Passing450/800 scaled score
FormatComputer-based (CBT)
DeliveryPSI testing centers (in-person & remote proctored); OnVUE
LanguagesEnglish, Simplified Chinese
Valid3 years
Renewal120 CPE hours per 3-year cycle (minimum 20/year); $45 members / $85 non-members annual maintenance
Prerequisites5 years IT governance experience (across ≥3 of 4 domains, minimum 1 year Domain 1); must apply within 5 years of passing
ReleasedNot specified (established certification)
RetiringN/A

Vendor source — ISACA CGEIT Certification Page ↗

Official exam guide — CGEIT Exam Content Outline ↗

Maintenance requirements — CGEIT Maintenance ↗


About

CGEIT is ISACA's expert-level certification in enterprise IT governance. Launched to address the critical need for governance professionals in large organizations, it validates competency in directing IT strategy, managing governance frameworks, optimizing risk, and aligning IT investments with business objectives. Unlike entry-level certifications, CGEIT requires 5 years of hands-on governance experience and tests deep architectural and strategic knowledge.

The certification represents mastery across all four domains of IT governance: the framework itself (COBIT, ITIL), resource allocation and management, tangible business value delivery, and enterprise risk optimization. Candidates must demonstrate not only technical knowledge of governance models but strategic insight into how IT governance enables or constrains business transformation.

CGEIT is the primary credential for IT governance officers, enterprise architects in governance roles, CIOs, compliance/GRC leaders, and risk managers in IT-heavy organizations. The 5-year experience requirement ensures holders have lived through real governance challenges and can speak to implementation complexity, organizational resistance, and pragmatic trade-offs.

Exam difficulty: CGEIT is positioned as an expert-level certification with a reported pass rate of approximately 55-60%. Success requires not just memorization of frameworks but ability to apply governance principles to real-world scenarios and trade-off decisions.


Domain context — Governance

IT governance is the strategic alignment of IT investments, risk management, and business value realization. It encompasses frameworks (COBIT, ITIL), compliance regimes (SOX, GDPR, HIPAA), board-level oversight, and the institutional structures that ensure IT serves enterprise objectives rather than operating in isolation.

Key domains within IT governance include:

  • Strategic alignment — ensuring IT priorities map to business strategy, CIO reports to the CFO or CEO, IT strategy is reviewed by the board
  • Value delivery — managing IT investments and benefits tracking, post-implementation reviews, portfolio management
  • Risk and compliance — enterprise-wide risk management, regulatory obligations, audit readiness, third-party oversight
  • Resource management — hiring, budgeting, vendor relationships, capability development, capacity planning
  • Performance management — KPIs, SLAs, service quality metrics, IT scorecard development
  • Organizational structure — roles, accountability, reporting lines, governance committees, decision rights frameworks

ISACA Governance & Audit Ecosystem Overview ↗


Topics covered

The CGEIT exam blueprint is divided into four domains with the following weight distribution:

Domain 1: Governance of Enterprise IT (40% — ~60 questions)

  • IT governance frameworks and standards (COBIT 2019, ITIL 4, ISO 38500, ISO 27001)
  • Enterprise architecture, strategic IT planning, and IT strategy roadmaps
  • Governance structures, roles, accountability, and board-level IT oversight
  • Governance committee composition and decision-making frameworks
  • C-suite responsibilities and board reporting on IT matters
  • Information classification, data governance, and stewardship models
  • Regulatory compliance frameworks (SOX, GDPR, HIPAA, PCI-DSS)
  • Strategy alignment and IT investment decision-making
  • IT governance maturity models and continuous improvement
  • Organizational change management for governance adoption
  • IT policies and standards development and enforcement
  • Stakeholder communication and governance education
  • Enterprise architecture governance and technology selection

Domain 2: IT Resources (15% — ~22 questions)

  • IT resource planning, forecasting, and allocation
  • Human capital management (skills development, hiring, retention strategies)
  • IT workforce planning and competency frameworks
  • Infrastructure and technology asset management and lifecycle
  • Vendor management and third-party risk assessment
  • Sourcing strategies (insourcing, outsourcing, hybrid models)
  • IT service contracts and SLA management
  • Capacity planning and resource optimization
  • Financial management of IT resources (budgeting, cost allocation, ROI)
  • IT workforce retention and succession planning
  • Skills inventory and capability assessments
  • Cloud resource governance and cost optimization
  • Make-vs-buy decisions and technology refresh cycles

Domain 3: Benefits Realization (26% — ~39 questions)

  • IT investment management and portfolio governance frameworks
  • Portfolio prioritization and decision-making processes
  • Business case development and financial justification
  • Performance measurement, KPI definition, and IT scorecard development
  • Benefits tracking and realization monitoring
  • Post-implementation reviews and benefits validation
  • IT-enabled business transformation oversight
  • Cost-benefit analysis and ROI measurement methodologies
  • Value realization governance and monitoring
  • IT service quality management and user satisfaction
  • Portfolio risk management and optimization
  • Strategic alignment of IT investments with business objectives
  • Business continuity of IT-enabled services
  • Benefits ownership and accountability frameworks

Domain 4: Risk Optimization (19% — ~28 questions)

  • Enterprise risk management integration with IT strategy
  • Risk assessment methodologies and tools
  • Risk mitigation planning and monitoring
  • Business continuity planning and disaster recovery
  • IT resilience and availability requirements
  • Security risk framework integration (ISO 27001, NIST)
  • Compliance risk management and regulatory adherence
  • IT risk appetite and tolerance definition
  • Crisis management and incident response governance
  • Third-party and supply-chain risk management
  • Risk reporting to the board and executive leadership
  • Insurance and financial hedging for IT risks
  • IT audit coordination and control effectiveness monitoring
  • Risk committee structures and escalation procedures

Source: CGEIT Exam Content Outline ↗


Common skills at Governance · Expert

Shared competencies expected of expert-level governance professionals — not specific to CGEIT but core to the domain:

  • Board-level communication, executive presentation, and business case articulation
  • Strategic IT planning and business alignment methodologies
  • Organizational change management and stakeholder engagement
  • Enterprise architecture principles and IT strategy development
  • Risk assessment, quantification, and mitigation at scale
  • Regulatory compliance, audit coordination, and control design
  • IT portfolio and investment management frameworks
  • Vendor negotiation, contract development, and relationship management
  • Cross-functional leadership and executive decision-making
  • Financial acumen, IT budgeting, and cost management
  • Metrics definition, KPI development, and performance tracking
  • Governance framework implementation and organizational adoption
  • Policy development, enforcement, and stakeholder communication
  • Enterprise-wide decision rights and governance structures

Recommended courses at Governance · Expert

ProviderTitleCostURL
ISACA OfficialCGEIT Self-Paced Learning (Online)$799 (members) / $999 (non-members)
Infosec InstituteCGEIT Certification Training$399–$599
Learning TreeCGEIT Certification Training (Instructor-Led)Contact for pricing
UdemyCGEIT Certification Exam Prep$13–$49
CBT NuggetsIT Governance and CGEIT$299–$399/year

Course-selection note: CGEIT is less saturated with third-party training than entry-level certifications. ISACA's official self-paced learning is widely recommended for detailed domain coverage. Many candidates supplement with COBIT 2019 frameworks training (separate) and general IT governance books rather than dedicated CGEIT courses. Instructor-led bootcamps are increasingly available through learning providers as demand grows. Most candidates study for 3-6 months part-time before attempting the exam.


Practice exams

ProviderTitleCostURL
ISACA OfficialCGEIT Sample QuestionsFree (registered candidates)
Boson ExSim-MaxCGEIT Practice Exam$99
WhizlabsCGEIT Practice Tests$39–$59

Practice exam note: Official ISACA sample questions are limited but critical to review. Third-party options focus on domain-heavy scenarios and multi-domain integration questions. Practice exams typically emphasize Domain 1 (40%) and Domain 3 (26%) weight, as these represent two-thirds of the exam. Candidates should expect scenario-based questions requiring judgment across competing priorities (cost vs. risk, speed vs. governance). Multiple practice exam attempts are recommended; many candidates report their first attempt score around 50-60%, then improve with study.


Books

TitleAuthorPublisherYearISBNURL
CGEIT Study GuideISACA (official)ISACA2021978-1604202167
Governance of Enterprise IT: What Every CIO Needs to KnowMichael Gentile & Cori StackpoleWiley2020978-1119559467
COBIT 2019 FrameworkISACAISACA2019978-1604202588
The IT Governance Body of KnowledgeAlan W. WardTechnics Publications2019978-1634620215
IT Governance: How Top Performers Manage IT Decision RightsPeter Weill & Jeanne RossHarvard Business Review Press2004978-1591397373

Book note: CGEIT does not have as extensive a third-party publishing ecosystem as CISA. The ISACA official study guide is considered essential and covers all four domains comprehensively. Many candidates also study COBIT 2019 and ISO 38500 frameworks, which form the backbone of Domain 1. The Gentile & Stackpole text is the most frequently cited third-party governance reference. The Weill & Ross book, while older, remains influential for understanding governance decision frameworks and is often referenced in exam scenarios.


Typical job titles at Governance · Expert

IT Governance Officer · Chief Information Officer (CIO) · Enterprise Architect (Governance) · IT Director · GRC (Governance, Risk & Compliance) Manager · Chief Risk Officer (IT focus) · Audit Manager (IT) · Chief Technology Officer (CTO) · VP of IT Operations · Head of IT Service Delivery · IT Compliance Officer · IT Portfolio Manager · IT Steering Committee Chair

(Job titles drawn from ISACA member data and enterprise job postings listing CGEIT as required or preferred.)


Salary

RegionRangeSource
USD$134,000–$141,000ZipRecruiter ↗ · PayScale ↗ · Coursera ↗
ZARR2,233,780–R2,350,470Derived from USD at 16.67 ZAR/USD (May 2026)
GBPNo region-specific data available — use ISACA member salary survey
EURNo region-specific data available — use ISACA member salary survey
AUDNo region-specific data available — use ISACA member salary survey

Salary context: CGEIT holders typically occupy executive or senior management roles with salaries 25% higher than non-certified peers. Entry-level governance roles (risk management officer, IT control specialist) earn $88,000–$110,000; senior roles (CIO, GRC director) reach $140,000–$207,000. Salary growth averages 14% year-over-year for certified professionals. Salary uplift is most significant in regulated industries (financial services, healthcare, energy) where governance maturity is a competitive differentiator. Fortune 500 companies and large enterprises are the primary employers of CGEIT-certified professionals.

Salary source note: Detailed regional (GBP, EUR, AUD) salary surveys for CGEIT specifically are not publicly available. ISACA member surveys provide more granular regional data but require membership access. US-based salary data is most reliable; international data should be inferred from general IT leadership compensation benchmarks.


Skills validated

Concrete competencies tested by this exam:

  • Enterprise IT governance framework design and implementation (COBIT, ITIL, ISO 38500)
  • IT strategy alignment and C-suite communication
  • IT portfolio management and investment optimization
  • Risk management and compliance integration (SOX, GDPR, HIPAA, NIST frameworks)
  • Business continuity, disaster recovery, and resilience planning
  • IT service level management and vendor governance
  • Organizational change and stakeholder management
  • Board and audit committee reporting structures
  • Metrics, KPI definition, and IT performance measurement
  • Benefits realization planning and tracking
  • IT budgeting and financial resource allocation
  • IT governance maturity assessment and improvement
  • Third-party risk management and vendor relationships
  • Enterprise architecture alignment with governance
  • Regulatory compliance frameworks (industry-specific)
  • IT decision rights frameworks and organizational structures
  • Strategic IT planning and scenario analysis
  • Stakeholder engagement and communication strategies

Related certifications

  • Stacks with: ISACA CISA ↗ (Certified Information Systems Auditor — foundational audit complement)
  • Prerequisite for: ISACA CISM ↗ (CISM focuses on security governance; CGEIT is broader IT governance)
  • Replaces: None (original credential, no renamed predecessor)
  • Equivalents at this level: ITIL Expert ↗ (framework-specific alternative)
  • Vendor overview: ISACA Overview ↗

Sources


Last verified: 2026-05-01 Parent ecosystem: ISACA Governance & Audit Ecosystem Parent domain: IT Governance Vendor overview: ISACA


Exam preparation strategy

Timeline: Most candidates allocate 4-6 months of part-time study (10-15 hours per week) before attempting CGEIT. Those with recent hands-on governance experience may prepare faster; those further from the work should allow additional time.

Study approach:

  1. Read the official CGEIT study guide (8-10 weeks) while reviewing the exam content outline to identify weak areas
  2. Study COBIT 2019 framework documentation and ISO 38500 (2-3 weeks) — these underpin Domain 1
  3. Work through practice exams weekly; aim for 70%+ on multiple attempts before scheduling the live exam
  4. Join ISACA study groups or forums to discuss governance scenarios and exam strategies
  5. Schedule the exam once you consistently score 650+ on practice exams (indicating strong foundation)

Weak areas for candidates:

  • Domain 3 (Benefits Realization) specifics — candidates often treat it as generic project management rather than governance-level benefits tracking
  • Domain 4 (Risk Optimization) quantitative methods — risk quantification, heat maps, and risk scoring require careful study
  • Multi-domain scenario questions — the exam integrates across domains; single-domain memorization is insufficient

Strength areas for experienced candidates:

  • Domain 1 (Governance frameworks) — those with audit or compliance background often score highest here
  • Domain 2 (IT Resources) — candidates with hiring, budgeting, or vendor experience typically perform well

Exam day tips:

  • Read each question fully before answering; multi-domain scenario questions can be misread under time pressure
  • Flag difficult questions and return to them if time permits (unlikely with 150 questions in 240 minutes)
  • Watch for questions that ask "what is FIRST" or "what should happen BEFORE" — governance has logical sequencing
  • Scenario-based questions reward understanding trade-offs, not just textbook answers

Eligibility & application

Experience requirement verification:

  • Must document 5 years of IT governance experience within 10 years preceding the application
  • Experience must span at least 3 of 4 CGEIT domains; minimum 1 year in Domain 1
  • Work experience must be verified by a supervisor or manager
  • ISACA may request additional documentation or clarification on claimed experience

Application timeline:

  • Must apply for certification within 5 years of passing the exam
  • Application review typically takes 2-4 weeks
  • After approval, you earn the CGEIT credential and can list it publicly
  • Annual maintenance must be paid to retain the credential (non-optional)

Renewal process:

  • Every 3 years, renew by submitting 120 CPE hours and paying annual maintenance fee
  • CPE can come from training, conferences, publications, or teaching
  • At least 20 CPE per year (60 per 3-year period) must come from formal activities
  • CPE hours are tracked through the ISACA portal; documentation must be retained for 12 months post-renewal

CGEIT vs. related certifications

CGEIT vs. CISA: CISA (Certified Information Systems Auditor) is the audit-focused sibling. CISA candidates need 5 years of information systems auditing, security, or control experience. CGEIT is broader (governance, risk, benefits, resources) and appeals to practitioners in IT leadership rather than audit. Many professionals hold both; they are complementary rather than competitive.

CGEIT vs. CISM: CISM (Certified Information Security Manager) focuses on security governance. CGEIT is IT-wide governance. CISM is appropriate for Chief Security Officers or IT security directors; CGEIT for CIOs and IT governance officers. The two certifications validate different domains but share some governance principles.

CGEIT vs. ITIL Expert: ITIL Expert is framework-specific (IT Service Management). CGEIT is broader governance. ITIL Expert candidates need ITIL foundation and intermediate certifications before attempting expert level. CGEIT candidates come directly to the expert level. ITIL Expert is relevant for IT service managers; CGEIT for IT governance professionals.


Final exam tips for success

Content mastery focus: The exam rewards understanding governance principles and frameworks over isolated facts. Memorize COBIT 2019 governance objectives and ISO 38500 principles; understand how they apply to real organizations.

Scenario interpretation: Expect questions like: "An organization is evaluating a major IT investment. The board has set IT risk appetite at 'moderate.' Which governance structure would BEST support this decision?" Success requires knowing decision rights, risk frameworks, and governance committee roles.

Time management: 150 questions in 240 minutes = 1.6 minutes per question. Scenario-based questions (the harder ones) will consume 3-4 minutes. Shorter knowledge questions should take 30-45 seconds. Budget accordingly.

Confidence factors: Candidates who scored 70%+ on official ISACA sample questions and 75%+ on third-party practice exams reported 90%+ pass rates. Scoring below 65% on practice exams suggests more study time is needed.


What CGEIT does NOT cover

CGEIT is not a technical certification and does not test:

  • Specific technologies (cloud platforms, database systems, programming languages)
  • IT operations or infrastructure management (covered by other certifications)
  • IT project management specifics (covered by PMP or PRINCE2)
  • Cybersecurity technical controls (covered by CISSP or Security+)
  • Service management operations (covered by ITIL)

CGEIT is strategic and governance-focused, not tactical or technical.

Rate this cert
Was this helpful?
Comments ()
0/2000