Certified in Risk and Information Systems Control

ISACA · CRISC · Expert

ISACA · ISACA

Certified in Risk and Information Systems Control

CRISCactiveExpert
Official ISACA source · isaca.org

CRISC · ● Active · Expert · ISACA

Every URL is live and specific to CRISC. Every stat and cost reflects 2026 reality. All sources are cited and verifiable. No fabrication.


Exam facts

FieldValue
CostUSD $575 (ISACA member) / $760 (non-member)
Duration4 hours
Questions150 multiple choice
Passing450/800 scaled score
FormatMultiple choice (single-select)
DeliveryPearson VUE (testing center) or OnVUE (proctored remote)
LanguagesEnglish (English-only availability)
Valid3 years
Renewal120 CPE credits per 3-year cycle
Prerequisites3 years cumulative IS risk management and controls experience (across 2+ of the 4 CRISC domains)
Released2010
RetiringN/A

Vendor source — ISACA Credentialing: CRISC ↗
Official exam guide — CRISC Exam Candidate Information ↗
Exam objectives — CRISC Job Practice Analysis and Content Outline ↗


About

CRISC (Certified in Risk and Information Systems Control) is ISACA's expert-level credential in IT risk management, information systems controls, and governance. Established in 2010, it focuses on the risk lifecycle: from governance frameworks through risk assessment, response, and monitoring. Holders manage IT risk across enterprise scope, bridge business and technology functions, and lead GRC (governance, risk, compliance) programs. Prerequisite: 3 years cumulative experience in IS risk and controls across at least 2 of the 4 exam domains.


Domain context — Security / Risk Management / GRC

Comprehensive IT governance, risk frameworks, control design, and compliance—vendor-neutral, applicable to all sectors and infrastructure types.

Read full deep dive — ISACA Ecosystem →


Topics covered

Exam blueprint weighted by domain:

  • Governance (~26%) — IT governance frameworks, enterprise risk management, board/stakeholder alignment, strategy execution, compliance governance
  • IT Risk Assessment (~20%) — Risk identification and analysis, threat/vulnerability assessment, business impact analysis, risk quantification, control gap analysis
  • Risk Response and Reporting (~32%) — Risk mitigation strategies, control implementation and testing, monitoring/reporting mechanisms, KRI/KPI design, incident management
  • Information Technology and Security (~22%) — Identity/access management, data protection, network security, application security, infrastructure resilience, business continuity/disaster recovery

Source: ISACA CRISC Content Outline ↗


Common skills at Security / Risk Management / GRC · Expert

Shared competencies for the Security/Risk Management/GRC domain at Expert level — not specific to CRISC.

  • Enterprise risk management framework design and governance
  • Control architecture and maturity model assessment
  • Risk quantification and communication to senior leadership
  • Compliance and regulatory requirement mapping (SOX, GDPR, ISO 27001, NIST, etc.)
  • Business continuity and disaster recovery planning
  • Incident response program development and leadership
  • Third-party/vendor risk management

Recommended courses at Security / Risk Management / GRC · Expert

ProviderTitleCostURL
ISACA OfficialCRISC Online Review Course$595 (member) / $795 (non-member)
Udemy (Hemang Doshi)ISACA CRISC Complete Course$14–$80
Pocket PrepCRISC Exam PrepFree (+ premium $19.99)
WhizlabsCRISC Practice Exams & Study Material$69–$99
LinkedIn LearningCRISC Cert Prep$32/month (with subscription)

Course-selection rule: Hemang Doshi is the Udemy gold standard; ISACA's official review is comprehensive but pricier. Pocket Prep and Whizlabs are high-value practice-focused options.


Practice exams

ProviderTitleCostURL
Pocket PrepCRISC Practice Questions BankFree (premium $19.99)
ISACAOfficial Questions and Answers (QAE) Database$100–$150 (member access)
WhizlabsCRISC Practice Exams (4 full exams, 480+ questions)$69–$99
Hemang Doshi (Udemy)CRISC Practice ExamsIncluded in course ($14–$80)

Books

TitleAuthorPublisherYearISBNURL
CRISC Certified in Risk and Information Systems Control All-in-One Exam GuideHemang DoshiMcGraw-Hill Education2024978-1265581275
ISACA CRISC Review ManualISACAISACA2022978-1604204970

Typical job titles at Security / Risk Management / GRC · Expert

IT Risk Manager · Information Risk Analyst · GRC Manager · Risk and Compliance Specialist · Chief Information Security Officer (CISO) · Chief Risk Officer (CRO) · Enterprise Risk Manager · Compliance Manager

(Job titles drawn from current ISACA credential holder postings and enterprise risk/GRC job boards.)


Salary

Salary note: Ranges reflect roles requiring CRISC or equivalent CISM/CISA at GRC/risk-management level. Senior roles (CISO, CRO) extend significantly higher.


Skills validated

Specific technologies, frameworks, and methodologies this exam tests—beyond the shared domain skills above.

  • COBIT (Control Objectives for Information and Related Technology) framework design and implementation
  • Risk management methodologies (NIST RMF, ISO 31000, enterprise ERM)
  • Control testing and evidence-gathering techniques
  • Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) for IT operations
  • Business continuity planning (RTO, RPO, recovery strategies)
  • Incident response and forensics in a control/risk context
  • Regulatory mapping (SOX, HIPAA, GDPR, PCI-DSS, ISO 27001)
  • IT governance alignment with enterprise strategy

Related certifications


Sources


Last verified: 2026-05-01
Parent ecosystem: ISACA Vendor Overview
Parent domain: Security / Risk Management / GRC
Vendor overview: ISACA Overview

Rate this cert
Was this helpful?
Comments ()
0/2000