Certified Information Systems Auditor Exam Guide
At a glance
- Questions
- 150
- Time limit
- 4h
- Passing score
- 450 on a scale of 200-800
- Exam fee
- $575
- Governing body
- ISACA
CISA (Certified Information Systems Auditor) is a globally recognized credential for IT audit, security, and risk professionals. With over 207,000 certified holders since 1978, CISA validates expertise in assessing and controlling enterprise technology environments—essential for careers in internal audit, compliance, and governance roles.
The CISA exam spans 5 core domains: Information Systems Auditing Process (18%), Governance and Management of IT (18%), Information Systems Acquisition, Development and Implementation (12%), Information Systems Operations and Business Resilience (26%), and Protection of Information Assets (26%). The current content outline, effective August 2024, emphasizes risk, security, and controls for disruptive technologies and emerging IT audit practices.
The CISA exam registration fee is US$575.00 for ISACA members and US$760.00 for non-members. ISACA membership is optional but can offset exam cost over time through member pricing.
The CISA exam consists of 150 questions administered over 240 minutes (4 hours) and requires a scaled score of 450 or higher to pass. ISACA delivers the exam through PSI, with more than 1,300 testing locations worldwide offering both in-person test center and remote online proctoring options.
Frequently asked questions
How much does the CISA exam cost?
The CISA exam registration fee is US$575.00 for ISACA members and US$760.00 for non-members. If you plan to sit for the exam, it's worth comparing the cost of an ISACA membership against the US$185 fee difference — for many candidates the member discount effectively offsets a large portion of joining.
How many questions are on the CISA exam and how long do I have?
The CISA exam consists of 150 questions and gives you a total testing time of 240 minutes (4 hours). That works out to an average of roughly 1.6 minutes per question, so pace yourself and avoid getting stuck on any single item.
What score do I need to pass, and how is the exam structured?
You need a scaled score of 450 or higher to pass the CISA exam. The exam is built around 5 job practice domains, and questions are weighted by domain: Domain 4 - Information Systems Operations and Business Resilience and Domain 5 - Protection of Information Assets are each weighted at 26%, together accounting for 52% of the exam content. Because these two domains dominate the exam, prioritizing them in your study plan gives you the best return on effort.
After I register, how long do I have to take the exam and then get certified?
Your exam eligibility period is 6 months from the date of registration, so you'll want to schedule and sit for the exam within that window. Once you pass, you then have 5 years from the date of passing to apply for CISA certification. In practical terms, register only when you're confident you can be ready to test within about half a year, then use the generous post-exam window to complete the experience requirements before applying.