CISA · ● Active · Expert · ISACA
Exam facts
| Field | Value |
|---|---|
| Cost | USD $575 (ISACA member) / $760 (non-member) |
| Duration | 4 hours (240 minutes) |
| Questions | 150 multiple choice |
| Passing | 450 / 800 scaled score |
| Format | Multiple choice |
| Delivery | Pearson VUE testing centers and OnVUE (remote proctored) |
| Languages | English (primary); regional language versions available |
| Valid | 3 years |
| Renewal | 120 Continuing Professional Education (CPE) credits within 3-year cycle; minimum 20 CPE per year |
| Prerequisites | 5 years cumulative information systems audit, control, security, or assurance experience. Substitutions allowed: relevant advanced degree (bachelor's or higher) reduces requirement by 1 year; relevant ISACA certification reduces requirement by up to 2 years. Minimum 1 year if degree + additional cert held. |
| Released | 1994 (original); continuous updates per ISACA exam content evolution |
| Retiring | N/A |
Vendor source — ISACA CISA Credentialing ↗ Official exam guide — CISA Candidate Guide & Handbook ↗ Exam objectives — CISA Exam Content Outline ↗
About
The Certified Information Systems Auditor (CISA) is ISACA's foundational-to-expert certification for IT audit, control, and governance professionals. Originally launched in 1994, CISA validates the ability to assess organizational IT infrastructure, design and evaluate controls, identify vulnerabilities, and ensure compliance with governance frameworks. Unlike technical security certs (CISSP, CEH), CISA focuses on audit methodology, control assessment, and risk-based auditing — making it the standard credential for internal auditors, external auditors, compliance officers, and risk managers in regulated industries. CISA holders typically manage audit programs, evaluate IT governance, and report control efficacy to boards and regulators.
Domain context — Audit / GRC
Governance, Risk, Compliance (GRC) and IT audit — assessing control design and operating effectiveness, evaluating IT governance maturity, managing audit programs, and ensuring organizational alignment with regulatory frameworks and industry standards.
Read full deep dive — ISACA Ecosystem →
Topics covered
CISA covers five knowledge domains, weighted by exam emphasis (total 150 questions):
- Information Systems Auditing Process (18%) — Audit planning, scope definition, risk-based audit methodology, audit execution, evidence gathering, control evaluation, reporting, follow-up and compliance.
- Governance and Management of IT (18%) — Organizational structure & IT governance frameworks (COBIT, ITIL, ISO 20000), IT strategy alignment, portfolio management, resource allocation, quality assurance, maturity models.
- Information Systems Acquisition, Development, and Implementation (12%) — Systems development lifecycle (SDLC) control evaluation, application security design & testing, configuration management, change control, system acceptance & deployment.
- Information Systems Operations and Business Resilience (26%) — IT operations management, incident management & problem resolution, availability & continuity planning (BC/DR), capacity & performance management, operational resilience, service management.
- Protection of Information Assets (26%) — Physical & logical security controls, data classification & protection, access control design, encryption & key management, network security, endpoint protection, data loss prevention, privacy & data handling.
Source: ISACA CISA Exam Content Outline ↗
Common skills at Audit / GRC · Expert
Shared competencies for IT audit and GRC roles at expert level — not specific to CISA.
- Control design & evaluation against COSO, COBIT, ISO 27001, NIST frameworks
- Risk assessment & mitigation planning
- Audit planning, execution, and evidence documentation
- IT governance frameworks (COBIT, ITIL, ISO standards)
- Regulatory compliance mapping (GDPR, HIPAA, SOC 2, PCI-DSS, ISO 27001)
- Business continuity & disaster recovery program oversight
- Incident investigation & root cause analysis
- Audit reporting & stakeholder communication
- IT maturity assessments & continuous improvement
Recommended courses at Audit / GRC · Expert
| Provider | Title | Cost | URL |
|---|---|---|---|
| ISACA Official | CISA Online Review Course | $600–$800 (member) / $900–$1,100 (non-member) | ↗ |
| Hemang Doshi | Masterclass - CISA Exam (Updated 2026) (Udemy) | $15–$100 | ↗ |
| Pocket Prep | CISA Exam Prep App & Web | $50–$100 | ↗ |
| CBT Nuggets | CISA Certification Course | $300–$600/yr | ↗ |
| Pluralsight | CISA Study Path | $300–$500/yr | ↗ |
| INE | CISA Certification Training | $200–$400/yr | ↗ |
| KodeKloud | CISA Preparation Course | $150–$300 | ↗ |
Course-selection rule: CISA courses should emphasize audit methodology, control assessment, and governance frameworks (COBIT, COSO, ISO 27001) — avoid purely technical security content.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| ISACA Official | CISA Official Practice Questions Database (QAE) | $100–$150 (1,000+ questions) | ↗ |
| Pocket Prep | CISA Practice Exam Bank | $50–$100 | ↗ |
| Hemang Doshi | CISA Practice Exam Questions (Udemy) | $15–$100 | ↗ |
| Whizlabs | CISA Practice Exams | $50–$80 | ↗ |
Practice rule: The ISACA Official Questions and Explanations (QAE) database is the most accurate predictor of exam performance and should be prioritized.
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| CISA - Certified Information Systems Auditor Study Guide (3rd Edition) | Hemang Doshi | Self-published / Udemy | 2024 | 978-1835882863 | ↗ |
| CISA Certified Information Systems Auditor Study Guide | Hemang Doshi | Packt Publishing | 2024 | 978-1838989583 | ↗ |
| CISA Review Manual (28th Edition) | ISACA | ISACA | 2024 | 978-1-604-20246-8 | ↗ |
| CISA Exam-Study Guide | Hemang Doshi | Self-published | 2023 | 978-1983328343 | ↗ |
Book rule: The official ISACA CISA Review Manual (28th Edition) is the canonical reference; Hemang Doshi's Study Guides are widely recommended as practical, exam-focused supplements with 1,000+ practice questions.
Typical job titles at Audit / GRC · Expert
IT Auditor · Senior IT Auditor · Information Systems Auditor · Internal Audit Manager (IT focus) · External Auditor (Big 4 / audit firm) · Chief Audit Executive (CAE) with IT emphasis · Compliance Officer · Risk Manager (IT/technology focus) · GRC Manager
(Job titles drawn from current job-board postings that list CISA as required or preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $90,000 – $150,000+ for IT Auditor / Senior Auditor / Audit Manager roles | PayScale ↗ · ZipRecruiter ↗ · InfoSec Institute ↗ |
| ZAR | R700,000 – R1,200,000+ annually (IT audit / compliance roles in South Africa) | Pnet ↗ · PayScale ZA ↗ · CareerJunction ↗ |
| GBP | £60,000 – £100,000+ for IT Auditor / compliance roles in UK | IT Jobs Watch ↗ · Hays ↗ |
| EUR | €70,000 – €120,000+ (Germany/Netherlands IT audit & compliance) | LinkedIn Salary EU ↗ · PayScale EU ↗ |
| AUD | A$100,000 – A$160,000+ for IT Auditor roles in Australia | Seek ↗ · PayScale AU ↗ |
Salary note: CISA compensation is position-dependent; entry-level IT Auditors start lower, while Senior Auditors and Audit Managers (especially in regulated sectors: finance, healthcare, government) command premium salaries. Big 4 audit firms typically pay higher than corporate internal audit teams.
Skills validated
Cert-specific — what CISA actually tests, distinct from the shared "Common skills" above.
- Audit methodology & planning (scoping, risk assessment, evidence collection)
- IT control design & evaluation (preventive, detective, corrective controls)
- IT governance frameworks (COBIT, COSO, ITIL, ISO 20000, ISO 27001)
- Compliance assessment (GDPR, HIPAA, SOC 2, PCI-DSS, CMMC, CIS Controls)
- IT security & physical controls evaluation
- Business continuity & disaster recovery assessment
- Incident investigation & root cause analysis
- IT operations & service management evaluation
- Risk management & mitigation planning
- Audit reporting & stakeholder communication
Related certifications
- Stacks with: ISACA CISM ↗ (security management focus) · [ISACA CRISC ↗]({file not yet created}) (risk & compliance focus)
- Prerequisite for: [ISACA CAP ↗]({file not yet created}) (control & audit professional, builds on CISA)
- Alternatives at this level: [CIA - Certified Internal Auditor ↗]({file not yet created}) (IIA; broader internal audit scope) · [CCSK - Cloud Security Knowledge ↗]({file not yet created}) (cloud-specific controls)
- Vendor overview: ISACA Overview ↗
Sources
- ISACA CISA Credentialing Page ↗
- ISACA CISA Exam Content Outline ↗
- ISACA CISA Candidate Guide ↗
- CISA Exam Scoring Information ↗
- PayScale CISA Salary Data ↗
- ZipRecruiter CISA Salary 2026 ↗
- InfoSec Institute CISA Salary Guide ↗
- Hemang Doshi Udemy CISA Course ↗
- Hemang Doshi CISA Study Materials ↗
- ISACA Official Practice Questions (QAE) ↗
- Pocket Prep CISA Exam Prep ↗
Last verified: 2026-05-01 Parent ecosystem: ISACA Ecosystem Parent domain: Audit / GRC Domain Vendor overview: ISACA Overview