ISACA

5 certifications across 2 levels.

vendor rollup

ISACA

Professional · 1Expert · 4
View ISACA certification path →

Vendor overview

ISACA (Information Systems Audit and Control Association) — Vendor Overview

V016 · IT Audit, Governance, Risk, Compliance · 4 active certifications · SA presence: Strong

Quick pitch: ISACA is the global leader in IT audit, risk, and governance certifications; CISA is mandatory or strongly preferred for IT audit roles at banks, insurance companies, and organisations subject to compliance audits (SOX, GDPR, etc.).


Company Snapshot

FieldDetail
Full nameInformation Systems Audit and Control Association
Founded1969 — established IT audit as a discipline
HeadquartersSchaumburg, Illinois, USA
Employees~300 globally (2026)
RevenuePrivate non-profit; revenue estimates ~$80–120M annually
ListedNon-profit
Core businessDevelops and administers IT audit, governance, risk, and compliance certifications (CISA, CISM, CGEIT, CRISC); provides training and maintains frameworks. 100% certification and training revenue.
SA officeNo direct office; strong partner network including TrackitSA, Westcon-Comstech, regional training providers

What ISACA Does

ISACA is the global non-profit authority for IT audit, governance, and risk management. The organisation develops CISA (the global standard for IT auditors), CISM (IT security governance), CGEIT (IT governance), and CRISC (risk management) certifications. ISACA members and certified professionals maintain exceptionally high ethical standards and professional development requirements.

ISACA maintains approximately 168,000+ members globally with 50,000+ CISA holders. The organization is vendor-neutral and highly respected by regulatory bodies (SEC, central banks, audit firms). Competitors are vendor-specific programs and competing certifications (CompTIA Security+), but CISA remains the gold standard for IT auditors globally. The certification program is designed for audit professionals, IT managers, and governance specialists.


Certification Portfolio

Active certifications (4 total)

LevelCert NameCodeDomainCost (USD)Valid
ProfessionalCISA – Certified Information Systems AuditorCISAIT Audit$7603 yrs
ProfessionalCISM – Certified Information Security ManagerCISMIT Security Governance$7603 yrs
ProfessionalCGEIT – Certified in the Governance of Enterprise ITCGEITIT Governance$7603 yrs
ProfessionalCRISC – Certified in Risk and Information Systems ControlCRISCRisk Management$7603 yrs

Recommended starting cert

CISA (Certified Information Systems Auditor) — Professional-level credential validating expertise in IT audit, control, and assurance across 5 domains (processes, governance, information protection, service delivery, and risk). Suitable for internal audit professionals, external auditors, and IT managers. 4-hour exam; ~150 questions. 3-year validity. Prerequisites: 5 years IT audit/control experience (or equivalent education). ~4–6 months study.

Cert ladder for new starters

CISA (IT Audit) → CISM (Security Governance) or CRISC (Risk)
CGEIT (Governance specialist track)

Why ISACA Matters in 2026

CISA is mandatory or strongly preferred for IT audit roles at regulated financial institutions, insurance companies, and government agencies. LinkedIn shows 12,000+ open CISA-related job postings globally. CISA is required or preferred by major audit firms (Deloitte, EY, KPMG, Accenture) and regulatory bodies (Federal Reserve, SEC, central banks).

ISACA's frameworks (COBIT, Val IT, Risk IT) are industry standards for IT governance. CISA holders command premium salaries, particularly in financial services and regulated industries. The certification ecosystem is exceptionally healthy; ISACA invests heavily in training and community development. CISA remains in strong demand as regulatory requirements increase globally (GDPR, SOX, HIPAA, etc.).


Job Market Data

Global demand

MetricValueSourceDate
Active job postings mentioning CISA12,000+LinkedIn JobsMay 2026
Growth YoY+10%LinkedIn Salary Insights2025–2026
Top job title hiringIT Audit ManagerLinkedInMay 2026
Top hiring countriesUSA, UK, Canada, Australia, SingaporeLinkedInMay 2026

Common job titles requiring ISACA skills

Job TitleSeniorityMedian USD SalaryMedian ZAR Salary
Internal Audit SpecialistMid$72,000R66,200/month
IT Audit ManagerSenior$115,000R105,800/month
IT Risk Manager / CRISCSenior$125,000R115,000/month
Audit Director / CISA-ExpertExecutive$160,000+R147,200+/month

South Africa Presence

Direct presence

ISACA has no direct office in South Africa but operates through a strong partner network. Primary partners include TrackitSA, Westcon-Comstech, and regional audit and compliance training providers. CISA is exceptionally valued in SA banking and government audit functions.

SA job market

South African banks (ABSA, Nedbank, FirstRand, Standard Bank, Investec) mandate CISA or equivalent for IT audit roles. Government agencies and state-owned enterprises (Eskom, Transnet, SARS) require CISA for compliance and governance roles. CISA is required by major SA audit firms (Deloitte, EY, KPMG, Accenture) for IT audit professionals.

Median salary for CISA-certified IT Auditor in SA is R105,800/month (approximately $5,800 USD), rising to R147,200+/month for IT Risk Manager and audit leadership roles.

SA training providers

ProviderCert(s) offeredURL
TrackitSACISA, CISM, CRISCtrackitsa.co.za
Westcon-Comstech AcademyCISA, CISMwestcon.co.za
ISACA Learning HubAll ISACA certsisaca.org/learning
Linux Academy / A Cloud GuruCISAacloudguru.com

Vendor Ecosystem

Key technologies and platforms

  • COBIT framework (IT governance standard)
  • Val IT framework (IT value delivery)
  • Risk IT framework (risk management)
  • ITIL (IT service management)
  • ISO 27001 / 27002 (information security)
  • NIST Cybersecurity Framework
  • SOX, GDPR, HIPAA compliance requirements

Complementary vendors and certs

Complementary VendorWhy they pair well
ISC² (CISSP)Security professional complements IT auditor
COBIT / ITIL certificationsGovernance frameworks used in IT audit
Internal audit certifications (CIA)Broader audit knowledge complements IT audit
Compliance certifications (GDPR, SOX)Regulatory knowledge supports audit career

Community and resources

ResourceTypeURL
ISACA Learning HubOfficialisaca.org/learning
ISACA Community of InterestCommunityisaca.org/community
r/isacaCommunityreddit.com/r/isaca
ISACA YouTubeLearningyoutube.com/c/ISACAChannel

Vendor History & Roadmap

Key milestones

YearEvent
1969Founded; established IT audit as a discipline
1978Launched CISA certification
2000Developed COBIT governance framework
2010Introduced CISM and Risk IT frameworks
2012Launched CRISC (risk management)
2018Introduced CGEIT (governance) specialisation
2023Expanded focus on AI governance and risk
2024–2026Focus on AI audit, data governance, cloud compliance
2026AI governance and supply chain risk becoming certification focus

Outlook

ISACA is firmly positioned as the global leader in IT audit, governance, and risk certifications. The organisation's non-profit status and focus on audit and governance ensure long-term relevance in regulated industries. For certification professionals, CISA remains secure and in strong demand, particularly in financial services and regulated organisations. CISM and CRISC specialisations are increasingly sought after. Exam content will evolve to include AI governance, cloud security auditing, and third-party risk management over the next 12–24 months.


Frequently Asked Questions

Q: Is ISACA worth investing in for my career? Yes, especially if you want an audit or governance career. CISA is mandatory or strongly preferred for IT audit roles at regulated organisations.

Q: How often do ISACA certs expire? All ISACA certifications expire after 3 years. Renewal requires earning 20 Continuing Professional Education (CPE) credits annually or passing a renewal exam.

Q: Are ISACA certs recognised in South Africa? Absolutely. CISA is mandatory for SA IT audit professionals at banks and regulated organisations.

Q: What's the best cert to start with from ISACA? CISA. It requires 5 years IT audit experience or equivalent. Expect 4–6 months study with extensive audit knowledge requirements.


Related Content


Sources

#SourceURLUsed for
1ISACA Credentialingisaca.org/credentialingCompany data, cert portfolio
2ISACA Aboutisaca.org/aboutHistory, mission
3LinkedIn Jobs – CISAlinkedin.com/jobsJob market data
4TrackitSA (SA Partner)trackitsa.co.zaSA presence, training

Template version: 2026-05-03 | Maintained by IT Career Roadmap

Rate ISACA
Was this helpful?
Comments ()
0/2000