CISA study guide

ISACA's Certified Information Systems Auditor (CISA) is the leading credential for IT audit, assurance, and control professionals. Questions reward thinking like an independent auditor: evidence, risk-based planning, and objectivity.

Details below were checked in October 2026 against official and widely cited sources. Exams, prices, and requirements change, so confirm with the certifying body before you register.

Eligibility

Exam format & cost

Length150 multiple-choice questions, 4 hours
Passing score450 on a 200–800 scale
Exam fee$575 ISACA members / $760 non-members
Application fee$50 (one-time, after passing)
MaintenanceAt least 20 CPE hours per year and 120 per three-year cycle, plus an annual fee

Domains

DomainWeight
1. Information System Auditing Process18%
2. Governance and Management of IT18%
3. Information Systems Acquisition, Development and Implementation12%
4. Information Systems Operations and Business Resilience26%
5. Protection of Information Assets26%

Weights are from ISACA's 2024 exam content outline, effective August 1, 2024.

How to study

Ready to test yourself on CISA?

Start CISA practice