CRISC · ● Active · Expert · ISACA
Every URL is live and specific to CRISC. Every stat and cost reflects 2026 reality. All sources are cited and verifiable. No fabrication.
Exam facts
| Field | Value |
|---|---|
| Cost | USD $575 (ISACA member) / $760 (non-member) |
| Duration | 4 hours |
| Questions | 150 multiple choice |
| Passing | 450/800 scaled score |
| Format | Multiple choice (single-select) |
| Delivery | Pearson VUE (testing center) or OnVUE (proctored remote) |
| Languages | English (English-only availability) |
| Valid | 3 years |
| Renewal | 120 CPE credits per 3-year cycle |
| Prerequisites | 3 years cumulative IS risk management and controls experience (across 2+ of the 4 CRISC domains) |
| Released | 2010 |
| Retiring | N/A |
Vendor source — ISACA Credentialing: CRISC ↗
Official exam guide — CRISC Exam Candidate Information ↗
Exam objectives — CRISC Job Practice Analysis and Content Outline ↗
About
CRISC (Certified in Risk and Information Systems Control) is ISACA's expert-level credential in IT risk management, information systems controls, and governance. Established in 2010, it focuses on the risk lifecycle: from governance frameworks through risk assessment, response, and monitoring. Holders manage IT risk across enterprise scope, bridge business and technology functions, and lead GRC (governance, risk, compliance) programs. Prerequisite: 3 years cumulative experience in IS risk and controls across at least 2 of the 4 exam domains.
Domain context — Security / Risk Management / GRC
Comprehensive IT governance, risk frameworks, control design, and compliance—vendor-neutral, applicable to all sectors and infrastructure types.
Read full deep dive — ISACA Ecosystem →
Topics covered
Exam blueprint weighted by domain:
- Governance (~26%) — IT governance frameworks, enterprise risk management, board/stakeholder alignment, strategy execution, compliance governance
- IT Risk Assessment (~20%) — Risk identification and analysis, threat/vulnerability assessment, business impact analysis, risk quantification, control gap analysis
- Risk Response and Reporting (~32%) — Risk mitigation strategies, control implementation and testing, monitoring/reporting mechanisms, KRI/KPI design, incident management
- Information Technology and Security (~22%) — Identity/access management, data protection, network security, application security, infrastructure resilience, business continuity/disaster recovery
Source: ISACA CRISC Content Outline ↗
Common skills at Security / Risk Management / GRC · Expert
Shared competencies for the Security/Risk Management/GRC domain at Expert level — not specific to CRISC.
- Enterprise risk management framework design and governance
- Control architecture and maturity model assessment
- Risk quantification and communication to senior leadership
- Compliance and regulatory requirement mapping (SOX, GDPR, ISO 27001, NIST, etc.)
- Business continuity and disaster recovery planning
- Incident response program development and leadership
- Third-party/vendor risk management
Recommended courses at Security / Risk Management / GRC · Expert
| Provider | Title | Cost | URL |
|---|---|---|---|
| ISACA Official | CRISC Online Review Course | $595 (member) / $795 (non-member) | ↗ |
| Udemy (Hemang Doshi) | ISACA CRISC Complete Course | $14–$80 | ↗ |
| Pocket Prep | CRISC Exam Prep | Free (+ premium $19.99) | ↗ |
| Whizlabs | CRISC Practice Exams & Study Material | $69–$99 | ↗ |
| LinkedIn Learning | CRISC Cert Prep | $32/month (with subscription) | ↗ |
Course-selection rule: Hemang Doshi is the Udemy gold standard; ISACA's official review is comprehensive but pricier. Pocket Prep and Whizlabs are high-value practice-focused options.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| Pocket Prep | CRISC Practice Questions Bank | Free (premium $19.99) | ↗ |
| ISACA | Official Questions and Answers (QAE) Database | $100–$150 (member access) | ↗ |
| Whizlabs | CRISC Practice Exams (4 full exams, 480+ questions) | $69–$99 | ↗ |
| Hemang Doshi (Udemy) | CRISC Practice Exams | Included in course ($14–$80) | ↗ |
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| CRISC Certified in Risk and Information Systems Control All-in-One Exam Guide | Hemang Doshi | McGraw-Hill Education | 2024 | 978-1265581275 | ↗ |
| ISACA CRISC Review Manual | ISACA | ISACA | 2022 | 978-1604204970 | ↗ |
Typical job titles at Security / Risk Management / GRC · Expert
IT Risk Manager · Information Risk Analyst · GRC Manager · Risk and Compliance Specialist · Chief Information Security Officer (CISO) · Chief Risk Officer (CRO) · Enterprise Risk Manager · Compliance Manager
(Job titles drawn from current ISACA credential holder postings and enterprise risk/GRC job boards.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $115,000 – $160,000 | Glassdoor (IT Risk Manager) ↗ · Robert Half Salary Guide ↗ |
| ZAR | R280,000 – R480,000 | Pnet (Risk/Compliance Manager) ↗ · PayScale ZA ↗ |
| GBP | £65,000 – £95,000 | IT Jobs Watch (GRC roles) ↗ · Hays Salary Guide ↗ |
Salary note: Ranges reflect roles requiring CRISC or equivalent CISM/CISA at GRC/risk-management level. Senior roles (CISO, CRO) extend significantly higher.
Skills validated
Specific technologies, frameworks, and methodologies this exam tests—beyond the shared domain skills above.
- COBIT (Control Objectives for Information and Related Technology) framework design and implementation
- Risk management methodologies (NIST RMF, ISO 31000, enterprise ERM)
- Control testing and evidence-gathering techniques
- Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) for IT operations
- Business continuity planning (RTO, RPO, recovery strategies)
- Incident response and forensics in a control/risk context
- Regulatory mapping (SOX, HIPAA, GDPR, PCI-DSS, ISO 27001)
- IT governance alignment with enterprise strategy
Related certifications
- Stacks with: ISACA CISA (Certified Information Systems Auditor) ↗ · ISACA CISM (Certified Information Security Manager) ↗
- Prerequisite for: ISACA CGEIT (Certified in the Governance of Enterprise IT) ↗
- Equivalents at this level: CompTIA Security+ (+ CISSP path) ↗ · EC-Council Certified Information Security Manager (CISM) ↗
- Vendor overview: ISACA Vendor Overview ↗
Sources
- ISACA CRISC credentialing page: https://www.isaca.org/credentialing/crisc
- ISACA exam objectives and content outline: https://www.isaca.org/credentialing/crisc
- Hemang Doshi CRISC All-in-One Study Guide (McGraw-Hill, 2024)
- ISACA CRISC Review Manual (2022)
- Udemy CRISC course (Hemang Doshi): https://www.udemy.com/course/certified-in-risk-and-information-systems-control-crisc/
- Pocket Prep CRISC: https://www.pocketprep.com/exams/isaca-crisc/
- Whizlabs CRISC: https://www.whizlabs.com/isaca-crisc/
- Glassdoor Salary Data (IT Risk Manager): https://www.glassdoor.com/Salaries/it-risk-manager-salary-SRCH_KO0,15.htm
- Robert Half Salary Guide (2026): https://www.roberthalf.com/salary-guide
- Pnet ZA Salary Data: https://www.pnet.co.za/
- PayScale ZA: https://www.payscale.com/research/ZA/Job=Risk_Manager/Salary
- IT Jobs Watch (UK): https://www.itjobswatch.co.uk/
- Hays Salary Guide: https://www.hays.co.uk/
Last verified: 2026-05-01
Parent ecosystem: ISACA Vendor Overview
Parent domain: Security / Risk Management / GRC
Vendor overview: ISACA Overview