CISA study guide
ISACA's Certified Information Systems Auditor (CISA) is the leading credential for IT audit, assurance, and control professionals. Questions reward thinking like an independent auditor: evidence, risk-based planning, and objectivity.
Details below were checked in October 2026 against official and widely cited sources. Exams, prices, and requirements change, so confirm with the certifying body before you register.
Eligibility
- Five years of professional experience in information systems audit, control, assurance, or security.
- Certain education and experience substitutions can waive up to three years. Check ISACA's current waiver list.
- Experience must be gained within the 10 years before applying, or within five years after passing.
- You can sit the exam first and apply for certification once you meet the experience requirement.
Exam format & cost
| Length | 150 multiple-choice questions, 4 hours |
|---|---|
| Passing score | 450 on a 200–800 scale |
| Exam fee | $575 ISACA members / $760 non-members |
| Application fee | $50 (one-time, after passing) |
| Maintenance | At least 20 CPE hours per year and 120 per three-year cycle, plus an annual fee |
Domains
| Domain | Weight |
|---|---|
| 1. Information System Auditing Process | 18% |
| 2. Governance and Management of IT | 18% |
| 3. Information Systems Acquisition, Development and Implementation | 12% |
| 4. Information Systems Operations and Business Resilience | 26% |
| 5. Protection of Information Assets | 26% |
Weights are from ISACA's 2024 exam content outline, effective August 1, 2024.
How to study
- Think like an auditor: independence, evidence quality, and risk-based scoping beat technical fixes.
- Domains 4 and 5 make up more than half the exam, so weight your study time accordingly.
- Learn the difference between preventive, detective, and corrective controls, and when compensating controls are acceptable.
- Use ISACA's official review manual and question database for the exam's wording style.
Ready to test yourself on CISA?
Start CISA practice