Certified Information Systems Auditor Exam Guide
At a glance
- Questions
- 150
- Time limit
- 4h
- Passing score
- 450 on a scale of 200-800
- Exam fee
- $575
- Governing body
- ISACA
Quick answers
How much does the CISA cost?
The CISA exam fee is $575 (ISACA members; $760 non-members).
What is the passing score for the CISA?
The passing score for the CISA is 450 on a scale of 200-800.
How many questions is the CISA?
The CISA has 150 questions with a time limit of 4 hours.
CISA (Certified Information Systems Auditor) is a globally recognized credential for IT audit, security, and risk professionals. With over 207,000 certified holders since 1978, CISA validates expertise in assessing and controlling enterprise technology environments—essential for careers in internal audit, compliance, and governance roles.
Overview
The CISA exam spans 5 core domains: Information Systems Auditing Process (18%), Governance and Management of IT (18%), Information Systems Acquisition, Development and Implementation (12%), Information Systems Operations and Business Resilience (26%), and Protection of Information Assets (26%). The current content outline, effective August 2024, emphasizes risk, security, and controls for disruptive technologies and emerging IT audit practices.
Cost and registration
The CISA exam registration fee is US$575.00 for ISACA members and US$760.00 for non-members. ISACA membership is optional but can offset exam cost over time through member pricing.
Exam format
The CISA exam consists of 150 questions administered over 240 minutes (4 hours) and requires a scaled score of 450 or higher to pass. ISACA delivers the exam through PSI, with more than 1,300 testing locations worldwide offering both in-person test center and remote online proctoring options.
Verified facts about the CISA
24 statements, each bound to the official document it was taken from. The source link beside every line opens that document.
Requirements and rules
- Certification application window
- Candidates have 5 years from passing the exam to apply for CISA certification
- ISACA
- Cpe requirement
- Certified professionals must adhere to ISACA's Continuing Professional Education (CPE) Policy to retain the credential
- ISACA
- Testing vendor
- ISACA delivers the CISA exam through PSI, offering in-person test center appointments and remote online proctoring
- ISACA
Fees
Numbers
- Domain count exam page
- The CISA Exam Content Outline details tasks and knowledge statements within each of the 5 domains
- ISACA
- Domain count press release
- The revised CISA exam retains its structure of 5 job practice domains
- ISACA
- Psi test locations
- PSI operates more than 1,300 testing locations across the world for the CISA exam
- ISACA
What is tested
- 2024 update emphasis
- The revised CISA exam emphasizes risk, security and controls related to disruptive technologies and emerging IT audit practices
- ISACA
- Domain 1 information systems auditing process
- Domain 1 - Information Systems Auditing Process is weighted at 18%
- ISACA
- Domain 2 governance and management of it
- Domain 2 - Governance and Management of IT is weighted at 18%
- ISACA
- Domain 3 is acquisition development implementation
- Domain 3 - Information Systems Acquisition, Development and Implementation is weighted at 12%
- ISACA
- Domain 4 is operations and business resilience
- Domain 4 - Information Systems Operations and Business Resilience is weighted at 26%
- ISACA
- Domain 5 protection of information assets
- Domain 5 - Protection of Information Assets is weighted at 26%
- ISACA
- Domains list
- The five CISA content domains are Information Systems Auditing Process, Governance and Management of Information Technology, Information Systems Acquisition, Development and Implementation, Information Systems Operations and Business Resilience, and Protection of Information Assets
- ISACA
How hard is the CISA?
How Hard Is the CISA Exam?
The Certified Information Systems Auditor (CISA) exam is one of the most rigorous information security credentials in the industry. More than 207,000 professionals have earned the CISA credential since 1978, reflecting its established reputation and continued relevance. If you are considering pursuing this certification, understanding its difficulty, scope, and structure will help you assess whether you are ready and what to expect on test day.
Understanding the Exam Structure and Scope
The CISA exam is built around 5 job practice domains, each representing critical areas of information systems auditing and security. The updated exam became available on 1 August 2024, with a revised focus that emphasizes risk, security and controls related to disruptive technologies and emerging IT audit practices. This shift means candidates today face questions that reflect modern security landscapes and evolving organizational threats.
The exam consists of 150 questions that must be completed in 240 minutes (4 hours). This timing structure demands efficiency and confident decision-making. You cannot afford to dwell too long on any single item without risking incomplete coverage of the full exam.
Domain Breakdown and Content Weighting
Success on the CISA exam requires balanced preparation across five domains, though not all carry equal weight. Domain 1—Information Systems Auditing Process—is weighted at 18% of the exam, covering foundational audit methodologies and practices. Domain 2—Governance and Management of IT—is weighted at 18%, focusing on organizational oversight and IT direction.
Domain 3—Information Systems Acquisition, Development and Implementation—is weighted at 12%, making it the lightest domain. However, the remaining two domains carry significantly greater emphasis. Domain 4—Information Systems Operations and Business Resilience—is weighted at 26%, and Domain 5—Protection of Information Assets—is weighted at 26%, meaning a large share of the exam tests your grasp of operational security, incident response, and asset protection.
This distribution signals where exam-takers typically struggle most. If you have extensive hands-on experience in security operations, vulnerability management, or business continuity, you hold an advantage. If your background is lighter in these areas, expect to invest significant effort building competency here.
Passing Requirements and Credentialing Path
A scaled score of 450 or higher is required to pass the CISA exam. The scaled scoring means raw question counts do not directly map to your final score; ISACA adjusts for item difficulty and other statistical factors. This transparency around the passing threshold is useful, but it also underscores that the exam is designed to discriminate between candidates who truly understand audit and security principles and those who do not.
Passing the exam is not the end of the credentialing journey. Candidates have 5 years from passing the exam to apply for CISA certification. This window accounts for post-exam experience requirements; most candidates must accumulate a defined period of paid IT audit work or a combination of IT experience and education before they can formally claim the CISA credential. Additionally, certified professionals must adhere to ISACA's Continuing Professional Education (CPE) Policy to retain the credential, meaning ongoing learning commitments extend well beyond passing the exam.
Test Logistics and Accessibility
| Exam Element | Detail |
|---|---|
| Total Questions | 150 |
| Testing Duration | 240 minutes (4 hours) |
| Passing Score | 450 (scaled) |
| Member Exam Fee | US$575.00 |
| Non-Member Exam Fee | US$760.00 |
| Testing Vendor | PSI (in-person and remote proctoring) |
| Test Locations | More than 1,300 worldwide |
| Exam Eligibility Period | 6 months from registration |
ISACA delivers the CISA exam through PSI, offering both in-person test center appointments and remote online proctoring. PSI operates more than 1,300 testing locations across the world for the CISA exam, providing flexibility in how and where you take the test. Whether you prefer the structure of a testing center or the convenience of home-based remote proctoring, options are widely available.
Assessing Your Readiness
The difficulty of the CISA exam depends heavily on your background. If you have extensive hands-on IT audit, security, or governance experience, you already possess domain knowledge that will accelerate your study. The exam will still challenge you—it tests depth and nuance, not surface-level familiarity—but your foundational understanding is in place.
If your experience is lighter or concentrated in only one or two domains, the exam becomes considerably harder. You will need to build competency across all five domains, especially in operations and asset protection, where the test places the greatest emphasis. This is not insurmountable, but it requires disciplined, comprehensive study that targets your weak areas repeatedly.
What Makes the CISA Exam Hard
The primary difficulty stems from breadth. The CISA exam does not specialize in a single technology or platform; instead, it measures your ability to think strategically about audit, governance, and security across enterprise environments. You must understand cloud security, data protection, incident response, compliance, risk management, and organizational change—often in the same exam sitting.
A secondary challenge is the question quality. ISACA invests in rigorous psychometric development of its exam items. Questions are designed to test applied reasoning, not rote memorization. You may encounter scenarios where multiple answers seem partially correct, forcing you to choose the best response based on audit principles and risk judgment. This level of cognitive demand separates passing scores from merely attempting the exam.
The structured approach to study should reflect your gaps. Begin by reviewing the five domains and identifying which are strongest and which need development. Tackle heavy-weighted domains (4 and 5) with special attention, but do not neglect lighter domains—they still contribute meaningful percentage points to your score. Engage with official ISACA study materials, practice questions, and hands-on audit scenarios. You are ready when you consistently score well on full-length practice tests and can defend your answer choices with reference to audit principles.
The CISA exam is genuinely challenging, but it is not unattainable. Thousands of professionals earn the credential every year by committing to comprehensive study and leveraging their experience. Your success depends on honest assessment of your current knowledge, disciplined focus on weak areas, and willingness to engage deeply with the material.
Ways to prepare for the CISA
Each of these is a side-by-side on what the provider does better than we do, what it charges today, and where the free path here is enough.
Frequently asked questions
How much does the CISA exam cost?
The CISA exam registration fee is US$575.00 for ISACA members and US$760.00 for non-members. If you plan to sit for the exam, it's worth comparing the cost of an ISACA membership against the US$185 fee difference — for many candidates the member discount effectively offsets a large portion of joining.
How many questions are on the CISA exam and how long do I have?
The CISA exam consists of 150 questions and gives you a total testing time of 240 minutes (4 hours). That works out to an average of roughly 1.6 minutes per question, so pace yourself and avoid getting stuck on any single item.
What score do I need to pass, and how is the exam structured?
You need a scaled score of 450 or higher to pass the CISA exam. The exam is built around 5 job practice domains, and questions are weighted by domain: Domain 4 - Information Systems Operations and Business Resilience and Domain 5 - Protection of Information Assets are each weighted at 26%, together accounting for 52% of the exam content. Because these two domains dominate the exam, prioritizing them in your study plan gives you the best return on effort.
After I register, how long do I have to take the exam and then get certified?
Your exam eligibility period is 6 months from the date of registration, so you'll want to schedule and sit for the exam within that window. Once you pass, you then have 5 years from the date of passing to apply for CISA certification. In practical terms, register only when you're confident you can be ready to test within about half a year, then use the generous post-exam window to complete the experience requirements before applying.
Is the CISA exam hard?
The CISA exam is demanding mainly because of its breadth and length: ISACA gives candidates 240 minutes (4 hours) to answer 150 questions spread across 5 job practice domains. The difficulty is less about trick questions and more about sustaining auditor-style judgment for four straight hours across governance, operations, and security material. Candidates who come from a narrow technical background usually find the governance and audit-process content harder than the technical content, since the exam rewards the auditor's perspective over the engineer's.
What is the passing score for the CISA exam?
ISACA requires a scaled score of 450 or higher to pass the CISA exam. Because the score is scaled rather than a raw percentage of the 150 questions answered correctly, you cannot simply translate "450" into a fixed number of correct answers. The practical takeaway is to aim comfortably above a bare pass on practice material rather than trying to reverse-engineer a question count.
How long do I have to take the exam after I register — and to get certified after I pass?
ISACA sets the exam eligibility period at 6 months from the date of registration, and once you pass you have 5 years from the exam date to apply for CISA certification. Those two windows work very differently: the first is a tight scheduling deadline, while the second gives you room to accumulate the experience your application needs. ISACA delivers the exam through PSI, which offers both in-person test center appointments and remote online proctoring, so scheduling inside the six months is usually the easy part.
How should I study for the CISA exam?
Study by domain weight, because the five domains are not equal: ISACA weights Information Systems Operations and Business Resilience at 26% and Protection of Information Assets at 26%, so together Domains 4 and 5 account for 52% of the exam content. Domains 1 and 2 sit at 18% each and Domain 3 — Information Systems Acquisition, Development and Implementation — at just 12%, which makes it the lowest-yield place to spend extra weeks. A sensible plan front-loads Domains 4 and 5, then uses timed practice sets to build the endurance the four-hour format demands.
Is my old CISA study material still current?
Check the edition date first: ISACA's updated CISA exam became available on 1 August 2024, and the current exam content outline took effect the same day. The revised exam retains its structure of 5 job practice domains but emphasizes risk, security and controls related to disruptive technologies and emerging IT audit practices, so pre-2024 material can leave gaps in exactly those areas. Also note that passing is only the start of the commitment — certified professionals must adhere to ISACA's Continuing Professional Education (CPE) Policy to retain the credential, which more than 207,000 professionals have earned since 1978.
Sources
- 1.CISA Exam Content Outline — ISACA (accessed Jul 18, 2026)
- 2.CISA Certification Overview — ISACA (accessed Jul 18, 2026)
- 3.Certification Exam Candidate Guides — ISACA (accessed Jul 18, 2026)
- 4.ISACA's CISA Exam Updated to Reflect Innovations and Evolving Technologies (Press Release, 2024) — ISACA (accessed Jul 18, 2026)
- 5.ISACA Credentials — ISACA
Official sources
Primary documents used to verify the exam details shown on this page.
- CISA Exam Content OutlineISACAisaca.org
- CISA Certification OverviewISACAisaca.org
- ISACA's CISA Exam Updated to Reflect Innovations and Evolving Technologies (Press Release, 2024)ISACAisaca.org
- Certification Exam Candidate GuidesISACAisaca.org
- CISA ExamISACAisaca.org
Last verified against the official exam content outline: