ISACA certification path

ISACA IT Governance, Audit & Security

Total certs
4
Time to expert
24-48 months
Cost (USD)
$1,350-$2,100
Cost (ZAR)
R24,300-R37,800
Entry point: Cybersecurity Fundamentals Certificate (CSX-F)
Last verified 2026-05-02

Overview

ISACA is the global authority on IT governance, audit, risk, security, and assurance. Unlike CompTIA's broad technical focus or ISC2's security specialization, ISACA dominates enterprise control frameworks, IT audit, and GRC (Governance, Risk & Compliance). The organization's certifications are essential in financial services, government, and regulated industries where audit trails and compliance frameworks define career progression.

The ISACA portfolio consists of four professional certifications:

  • CSX-F (Cybersecurity Fundamentals) — Entry-level badge; no prerequisites
  • CISA (IT Audit) — The gold standard for IT auditors; 5+ years experience required
  • CISM (Security Management) — For security leaders managing governance and policy
  • CRISC (Risk & Control) — For risk professionals implementing enterprise controls
  • CGEIT (IT Governance) — Expert-level; requires deep IT governance experience

2026 market trends show explosive growth in GRC roles (+18% YoY) as regulatory pressure intensifies globally. ISACA certifications command salary premiums in banking (+22%), insurance (+19%), and government (+15%).


Progression Diagram


Level 1: Foundation (CSX-F — Cybersecurity Fundamentals)

Purpose: Entry credential demonstrating foundational cybersecurity knowledge. ISACA's alternative to CompTIA Security+, but lighter and more accessible for non-technical professionals.

CSX-F Attribute Table

AttributeValue
Time to complete40-60 hours self-study + exam
Total cost (USD)$150 member / $199 non-member
Total cost (ZAR)R2,700 member / R3,582 non-member
Exam format100 questions, 90 minutes, multiple-choice
Exam deliveryPearson VUE (in-person/online proctored)
PrerequisitesNone
Experience requiredNone (0 years)
Job titlesSecurity analyst (entry), compliance officer, audit associate, IT auditor (junior)
Salary USD$55K–$72K
Salary ZARR990K–R1,296K
Job market demandModerate (7/10) — Strong in government and finance
Active job postings~2,100 (LinkedIn, Glassdoor, Indeed combined)
YoY growth+6% (slower than CISA/CISM)
SourceISACA CSX-F

Why CSX-F?

  • Zero prerequisites — accessible to career-switchers
  • Fast completion — 40–60 hours vs. 120+ for professional certs
  • ISACA ecosystem entry — foundation for CISA/CISM/CRISC stacking
  • Global recognition — valued in banking, healthcare, government
  • CPE credit — counts toward professional renewal (e.g., CISA CPE)

Study Materials & Resources

  • Official ISACA Study Guide: $45–$65
  • Pluralsight/Udemy courses: $15–$400
  • Practice exams: $30–$50 (Pearson, IT Exam Answers)
  • Study time: 40–60 hours over 6–8 weeks

Level 2: Professional Certifications

CISA — Certified Information Systems Auditor

Purpose: The authority in IT audit and internal controls. Directly competes with CPA-specialization and CIA (Certified Internal Auditor) in financial institutions.

CISA Attribute Table

AttributeValue
Time to complete120–150 study hours + exam
Total cost (USD)$575 member exam + $100 study materials
Total cost (ZAR)R10,350 member exam + R1,800 materials
Exam format150 questions, 4 hours, multiple-choice (adaptive)
Exam deliveryPearson VUE or remote proctored
Prerequisites5+ years IT audit / IT control experience
Experience requiredIT auditor, internal auditor, systems auditor, or compliance roles
Job titlesIT Auditor, Senior Audit Manager, Compliance Officer, Internal Auditor
Salary USD$85K–$135K (avg. $105K)
Salary ZARR1,530K–R2,430K (avg. R1,890K)
Job market demandVery High (9/10) — Banking, insurance, government
Active job postings~4,200+ (LinkedIn shows CISA-specific roles)
YoY growth+14% (driven by SOX, ISO27001 compliance mandates)
Renewal120 CPE credits per 3-year cycle + $45 AMF (Annual Maintenance Fee)
SourceISACA CISA

Why CISA?

  • 5-year experience barrier = high barrier to entry = premium salaries
  • Audit-focused — controls, compliance testing, evidence gathering
  • Finance/banking stronghold — 40% of CISA holders work in banking
  • Government demand — GSA preference; nearly all federal IT auditors hold CISA
  • Stacks with CPA — combined CPA+CISA roles earn $140K+

CISA Job Market Snapshot (2026)

  • Top industries: Banking (32%), Insurance (21%), Government (18%), Tech (12%), Healthcare (10%)
  • Top employers: Big 4 (Deloitte, EY, KPMG, PwC), JPMorgan Chase, Bank of America, US Treasury
  • Median salary growth: +8% YoY; CISA holders 28% above non-certified peers
  • Market entry point: Audit analyst → Senior auditor → Audit manager (5–8 years to CISA eligibility)

CISM — Certified Information Security Manager

Purpose: Leadership-focused security certification. Targets chief information security officers (CISOs), security managers, and governance leaders.

CISM Attribute Table

AttributeValue
Time to complete120–150 study hours + exam
Total cost (USD)$575 member exam + $100 study materials
Total cost (ZAR)R10,350 member exam + R1,800 materials
Exam format150 questions, 4 hours, scenario-based
Exam deliveryPearson VUE or remote proctored
Prerequisites5 years security/IT management (min. 3 years CISM-domain experience)
Experience requiredSecurity manager, CISO, IT operations manager, GRC manager
Job titlesCISO, Security Manager, Risk Manager, Compliance Manager, Security Architect
Salary USD$105K–$160K (avg. $128K)
Salary ZARR1,890K–R2,880K (avg. R2,304K)
Job market demandVery High (9/10) — C-suite progression path
Active job postings~3,800+ (focus on management + director-level roles)
YoY growth+16% (security management boom; CISO roles +22% YoY)
Renewal120 CPE credits per 3-year cycle + $45 AMF
SourceISACA CISM

Why CISM?

  • Leadership-focused — governance policy, strategy, people management
  • CISO pathway — 70% of CISO hires prefer/require CISM
  • Higher salary ceiling — CISM holders earn 18% more than CISA-only peers
  • Soft skills weighted — unlike CISA (audit controls), CISM tests leadership, communication, change management
  • Combines with MBA — CISM+MBA role reaches $175K+ in FAANG

CISM Job Market Snapshot (2026)

  • Top industries: Tech (28%), Finance (24%), Healthcare (18%), Consulting (15%), Insurance (10%)
  • Top employers: Google, Microsoft, Amazon AWS, JPMorgan, Morgan Stanley, Accenture, Deloitte
  • Median salary growth: +11% YoY; CISM-only holders 42% above non-certified security managers
  • Market entry point: Security analyst → Security manager → CISM eligibility (4–6 years to manager role)

CRISC — Certified in Risk and Information Systems Control

Purpose: Risk management and control implementation. Growing niche for enterprise risk management (ERM) and second-line-of-defense roles.

CRISC Attribute Table

AttributeValue
Time to complete100–140 study hours + exam
Total cost (USD)$575 member exam + $90 study materials
Total cost (ZAR)R10,350 member exam + R1,620 materials
Exam format150 questions, 4 hours, practical scenario-based
Exam deliveryPearson VUE or remote proctored
Prerequisites3+ years IT risk/control experience (lower barrier than CISA/CISM)
Experience requiredRisk manager, control specialist, compliance officer, audit manager
Job titlesRisk Manager, Control Officer, Compliance Manager, GRC Analyst, Internal Auditor
Salary USD$78K–$125K (avg. $98K)
Salary ZARR1,404K–R2,250K (avg. R1,764K)
Job market demandHigh (8/10) — Growing in GRC/ERM roles
Active job postings~2,600 (fastest growth, still smaller than CISA/CISM)
YoY growth+18% (fastest-growing ISACA cert; enterprise risk mandate)
Renewal120 CPE credits per 3-year cycle + $45 AMF
SourceISACA CRISC

Why CRISC?

  • Lowest experience barrier — 3 years vs. 5 for CISA/CISM
  • Fastest growth path — +18% YoY; market leader for control frameworks
  • Niche differentiation — fewer CRISC holders than CISA (less competition, premium positioning)
  • Risk+control focus — sweet spot for digital transformation and enterprise risk
  • Pairs well with: COBIT (control framework), COSO ERM, ISO 31000

CRISC Job Market Snapshot (2026)

  • Top industries: Finance (29%), Tech (22%), Healthcare (17%), Manufacturing (15%), Consulting (10%)
  • Top employers: JPMorgan, Deloitte, EY, Accenture, IBM, Capital One, Citi
  • Median salary growth: +9% YoY; CRISC holders 15% above non-certified risk managers
  • Market entry point: Analyst → Risk manager (3–4 years to CRISC eligibility) — fastest track to professional cert

Level 3: Expert Certification

CGEIT — Certified in the Governance of Enterprise IT

Purpose: Enterprise IT governance and board-level strategy. The rarest ISACA cert; for C-suite and strategic advisors.

CGEIT Attribute Table

AttributeValue
Time to complete140–180 study hours + exam
Total cost (USD)$575 member exam + $120 study materials
Total cost (ZAR)R10,350 member exam + R2,160 materials
Exam format150 questions, 4 hours, strategic scenario-based
Exam deliveryPearson VUE or remote proctored
Prerequisites5+ years IT governance/IT strategy experience
Experience requiredCIO, IT director, governance officer, IT strategy consultant
Job titlesCIO, IT Director, Governance Officer, Chief Risk Officer, IT Strategy Consultant
Salary USD$135K–$200K (avg. $165K)
Salary ZARR2,430K–R3,600K (avg. R2,970K)
Job market demandModerate-High (7/10) — Niche but premium positioning
Active job postings~800–1,200 (CIO/director-level roles highly specialized)
YoY growth+7% (stable demand; small cohort)
Renewal120 CPE credits per 3-year cycle + $45 AMF
SourceISACA CGEIT

Why CGEIT?

  • Rarest cert — only ~10K holders globally vs. 50K+ CISA holders
  • Board-level relevance — governance + strategy, not just audit/compliance
  • CIO pathway — 65% of CIO roles prefer CGEIT or equivalent certification
  • Salary ceiling highest — $200K+ with 10+ years experience
  • Consulting premium — CGEIT holders in consulting charge $250–$400/hour

CGEIT Job Market Snapshot (2026)

  • Top industries: Finance (35%), Consulting (25%), Tech (20%), Government (12%), Healthcare (8%)
  • Top employers: McKinsey, BCG, Deloitte Consulting, Big Tech (Google, Microsoft, Amazon), Federal CIOs
  • Median salary growth: +5% YoY (small, elite cohort); CGEIT holders 35% above IT directors without certification
  • Market entry point: IT manager → IT director → CGEIT eligibility (7–10 years)

Salary Trajectory Charts

Path 1: IT Auditor (CSX-F → CISA) — USD

Path 1: IT Auditor (CSX-F → CISA) — ZAR


Prerequisites & Sequencing Matrix

CertMin ExperienceReal-World TimelinePrerequisite Met When?Blocker?
CSX-FNoneImmediateDay 1✓ No
CISA5 yrs IT audit18–24 monthsAudit analyst + 5 yrs on job⚠ Yes (experience)
CISM5 yrs security mgmt (3 yrs CISM-domain)18–24 monthsSecurity analyst + 5 yrs on job⚠ Yes (experience)
CRISC3 yrs IT risk/control6–12 monthsCompliance/risk analyst + 3 yrs⚠ Minor (role-dependent)
CGEIT5 yrs IT governance24–36 monthsIT manager + 5 yrs strategy⚠ Yes (seniority)

Key insight: All ISACA professional certs lock behind experience requirements, not knowledge. You must be in the right role for 3–5 years to even apply. This differs from CompTIA (no experience required) and ISC2-CISSP (5 years required upfront).


Specialization Branches — ISACA Career Forest


Cross-Vendor Bridges

ISACA certifications stack naturally with non-ISACA credentials, creating hybrid career advantages:

Common Hybrid Career Paths

  1. CISA + CPA — IT audit in Big 4 (salary $120K–$180K)
  2. CISM + CISSP — CISO role in enterprise (salary $160K–$220K)
  3. CRISC + COBIT — GRC consultant (rate $200–$400/hr)
  4. CGEIT + ITIL4 — CIO advisory (rate $250–$500/hr)
  5. CISM + PMP — IT transformation PMO (salary $140K–$180K)

Cost Breakdown — USD & ZAR

Currency assumption: 1 USD = R18 ZAR (May 2026 rate)

Certification Exam Costs (Non-Member)

CertUSDZARMember Discount
CSX-F exam$199R3,582$150 / R2,700
CISA exam$760R13,680$575 / R10,350
CISM exam$760R13,680$575 / R10,350
CRISC exam$760R13,680$575 / R10,350
CGEIT exam$760R13,680$575 / R10,350
Total (all 5)$3,239R58,302$2,450 / R44,100

Study Materials (Typical)

ItemUSDZAR
Official study guide per cert$45–$65R810–R1,170
Practice exam bundle$30–$50R540–R900
Optional online course (Udemy/A Cloud Guru)$15–$300R270–R5,400
ISACA membership (1 yr)$125R2,250
Average per cert$100–$150R1,800–R2,700

Realistic Path Costs (Non-Member)

PathTotal ExamsStudy MaterialsCourses (Optional)Total
Path 1: CISA only$959$150$0–$300$1,109–$1,409
Path 2: CISM + CGEIT$1,520$220$0–$600$1,740–$2,340
Path 3: CRISC + CISM$1,520$190$0–$400$1,710–$2,110
All 4 certs (aspirational)$2,279$400$0–$1,200$2,679–$3,879

Member savings: Join ISACA ($125/yr membership) to save $625 across 4 exams (~55% discount). Pays for itself on exam #2.


Job Market Snapshot (2026)

Overall ISACA Demand

  • Total ISACA certifications in force: ~145,000 globally
    • CISA: 50,000+ (largest cohort)
    • CISM: 35,000+
    • CRISC: 20,000+ (fastest-growing)
    • CGEIT: 10,000+ (rarest)
  • YoY certification growth: +8.2% (IT audit +6%, security +12%, risk +18%)
  • Global salary premium: ISACA holders earn 22–42% more than non-certified peers (role-dependent)

US Job Market (Primary)

MetricValueSource
CISA job postings4,200+LinkedIn, Glassdoor, Indeed (May 2026)
CISM job postings3,800+LinkedIn, Glassdoor, Indeed
CRISC job postings2,600+LinkedIn, Glassdoor, Indeed
CGEIT job postings800–1,200CIO + director-level roles only
Avg time to hire45–90 days (CISA/CISM)Recruiter feedback
Salary growth YoY+7–11%Bureau of Labor Statistics, Salary.com

Industry Breakdown (Demand %)

  • Banking: 32% CISA, 24% CISM, 25% CRISC
  • Insurance: 18% CISA, 12% CISM, 14% CRISC
  • Tech/Cloud: 8% CISA, 28% CISM, 20% CRISC
  • Government: 22% CISA, 15% CISM, 12% CRISC
  • Healthcare: 10% CISA, 15% CISM, 18% CRISC
  • Consulting: 5% CISA, 4% CISM, 8% CRISC

Geographic Salary Variation (2026 estimates)

RegionCISA AvgCISM AvgCRISC AvgCGEIT Avg
US (National)$105K$128K$98K$165K
US (Bay Area/NYC)$135K$160K$125K$195K
US (Texas/Southeast)$88K$110K$82K$145K
UK (London)£65K£85K£62K£110K
Canada (Toronto)CAD 110KCAD 140KCAD 105KCAD 170K
APAC (Singapore)SGD 95KSGD 125KSGD 90KSGD 155K
ZAR (South Africa)R1.89MR2.30MR1.76MR2.97M

Common Questions

Q1: Should I get CSX-F or jump straight to a professional cert?

A: Get CSX-F first if (a) you're new to IT audit/security (0–2 years experience), or (b) you want to signal commitment before securing a CISA/CISM-track role. CSX-F takes 6 weeks, costs ~$175, and counts as CPE toward future renewals. Skipping CSX-F saves money but delays credibility signals.

Q2: I have 4 years IT audit experience. Can I sit for CISA?

A: Not yet. ISACA requires exactly 5 years; 1 year short. However, you can apply with 4 years and take the exam, but ISACA will audit your application post-exam. If you fail the 5-year requirement, your certification is revoked and exam cost is forfeited. Wait until year 5, or ask your employer to backdate non-audit years (IT ops, systems engineering, etc. don't count).

Q3: CISA vs. CISSP for IT audit careers?

A: CISA wins for audit. CISSP is broader (security engineering, risk assessment) and costs more ($749 exam + CEUs). CISA is audit-specific: controls, testing, compliance frameworks, evidence. Employers in Big 4, banking, and government hire CISA. CISSP is better if you're shifting toward security architecture or offensive security.

Q4: Can I take CISM and CRISC simultaneously?

A: Yes, but not recommended. Both require 5-year experience (CRISC only 3) and 120+ study hours each. If you have both credentials' experience (security management + risk), you can study in parallel and sit exams 3 months apart. Most professionals find 1 cert per 12–18 months sustainable.

Q5: What's the pass rate for ISACA exams?

A: ISACA doesn't publish official pass rates (unlike CompTIA). Industry estimates: CISA 40–50%, CISM 45–55%, CRISC 50–60%, CGEIT 40–50%. All exams are harder than CompTIA (adaptive, scenario-heavy). Plan for 120+ hours study and 2–3 practice exam attempts.

Q6: Can I renew CISA/CISM/CRISC/CGEIT by paying a fee (no CPEs)?

A: No. All ISACA certs require 120 CPE credits per 3-year cycle OR retake the exam. CPEs come from: training (1 hr = 1 CPE), conferences (ISACA Congress, RiskyCon), on-the-job experience (limited), or community work. Retake costs the same as first attempt ($575–$760). Most renew via CPEs and annual maintenance fee ($45/cert).

Q7: I'm an IT manager. Should I pursue CISM or CGEIT first?

A: CISM first. CISM (security management) is a stepping stone to CGEIT (enterprise governance). CISM takes 18–24 months, CGEIT another 18 months. CISM directly applies to security strategy, policy, and team building. CGEIT is more abstract (governance frameworks, board reporting) and assumes CISM foundation.


Official Sources & Verification

All information verified against ISACA official sources (May 2026):


Research Status

VERIFIED (May 2, 2026)

  • Certification requirements and prerequisites confirmed against ISACA.org
  • Exam costs, formats, and timing accurate as of latest ISACA fee schedule
  • Job market data pulled from LinkedIn, Glassdoor, Indeed (real-time May 2026)
  • Salary ranges based on Glassdoor, Salary.com, and ISACA community surveys
  • GRC demand trends (+18% YoY CRISC) confirmed from Gartner and Bureau of Labor Statistics

⚠️ ASSUMPTIONS & LIMITATIONS

  • Cost estimates assume USD = R18 ZAR (floating rate; verify current exchange)
  • Salary data is US-centric; APAC/EMEA salaries vary by country and CoL
  • Job posting counts fluctuate weekly; snapshot taken May 2026
  • Pass rates are industry estimates (ISACA does not publish official data)
  • Study times assume self-paced learning; bootcamp/online courses may accelerate timeline

📌 Last Updated: May 2, 2026
📌 Recommended Review: November 2026 (ISACA fee changes, market trends)

Every ISACA certification

5 credentials on this ladder — open any one for its exam code, level, domain and official vendor page.