Every Exam PrepFREE EXAM PREP
Ask AI
EXAM GUIDE · CISA

Certified Information Systems Auditor Exam Guide

Administered by ISACAVerified against the official content outline
Written by Every Exam Prep Editorial TeamSource and review policyPublished July 18, 2026Updated July 23, 2026

At a glance

Questions
150
Time limit
4h
Passing score
450 on a scale of 200-800
Exam fee
$575
Governing body
ISACA

Quick answers

How much does the CISA cost?

The CISA exam fee is $575 (ISACA members; $760 non-members).

What is the passing score for the CISA?

The passing score for the CISA is 450 on a scale of 200-800.

How many questions is the CISA?

The CISA has 150 questions with a time limit of 4 hours.

CISA (Certified Information Systems Auditor) is a globally recognized credential for IT audit, security, and risk professionals. With over 207,000 certified holders since 1978, CISA validates expertise in assessing and controlling enterprise technology environments—essential for careers in internal audit, compliance, and governance roles.

Overview

The CISA exam spans 5 core domains: Information Systems Auditing Process (18%), Governance and Management of IT (18%), Information Systems Acquisition, Development and Implementation (12%), Information Systems Operations and Business Resilience (26%), and Protection of Information Assets (26%). The current content outline, effective August 2024, emphasizes risk, security, and controls for disruptive technologies and emerging IT audit practices.

Cost and registration

The CISA exam registration fee is US$575.00 for ISACA members and US$760.00 for non-members. ISACA membership is optional but can offset exam cost over time through member pricing.

Exam format

The CISA exam consists of 150 questions administered over 240 minutes (4 hours) and requires a scaled score of 450 or higher to pass. ISACA delivers the exam through PSI, with more than 1,300 testing locations worldwide offering both in-person test center and remote online proctoring options.

Verified facts about the CISA

24 statements, each bound to the official document it was taken from. The source link beside every line opens that document.

Requirements and rules

Certification application window
Candidates have 5 years from passing the exam to apply for CISA certification
ISACA
Cpe requirement
Certified professionals must adhere to ISACA's Continuing Professional Education (CPE) Policy to retain the credential
ISACA
Exam eligibility period
The exam eligibility period is 6 months from the date of registration
ISACA
Testing vendor
ISACA delivers the CISA exam through PSI, offering in-person test center appointments and remote online proctoring
ISACA

Fees

Exam fee member
$The CISA exam registration fee is US$575.00 for ISACA members
ISACA
Exam fee nonmember
$The CISA exam registration fee is US$760.00 for non-members
ISACA

Numbers

Credential holders
More than 207,000 professionals have earned the CISA credential since 1978
ISACA
Domain count
The CISA exam is built around 5 job practice domains
ISACA
Domain count exam page
The CISA Exam Content Outline details tasks and knowledge statements within each of the 5 domains
ISACA
Domain count press release
The revised CISA exam retains its structure of 5 job practice domains
ISACA
Domains 4 5 combined weight
Domains 4 and 5 together account for 52% of the exam content%
ISACA
Exam duration
The CISA exam has a total testing time of 240 minutes (4 hours)
ISACA
Passing score
A scaled score of 450 or higher is required to pass the CISA exam
ISACA
Psi test locations
PSI operates more than 1,300 testing locations across the world for the CISA exam
ISACA
Question count
The CISA exam consists of 150 questions
ISACA

What is tested

2024 update emphasis
The revised CISA exam emphasizes risk, security and controls related to disruptive technologies and emerging IT audit practices
ISACA
Domain 1 information systems auditing process
Domain 1 - Information Systems Auditing Process is weighted at 18%
ISACA
Domain 2 governance and management of it
Domain 2 - Governance and Management of IT is weighted at 18%
ISACA
Domain 3 is acquisition development implementation
Domain 3 - Information Systems Acquisition, Development and Implementation is weighted at 12%
ISACA
Domain 4 is operations and business resilience
Domain 4 - Information Systems Operations and Business Resilience is weighted at 26%
ISACA
Domain 5 protection of information assets
Domain 5 - Protection of Information Assets is weighted at 26%
ISACA
Domains list
The five CISA content domains are Information Systems Auditing Process, Governance and Management of Information Technology, Information Systems Acquisition, Development and Implementation, Information Systems Operations and Business Resilience, and Protection of Information Assets
ISACA

Dates

Content outline effective date
The current CISA exam content outline became effective 1 August 2024
ISACA
Updated exam available date
The updated CISA exam became available on 1 August 2024
ISACA

How hard is the CISA?

How Hard Is the CISA Exam?

The Certified Information Systems Auditor (CISA) exam is one of the most rigorous information security credentials in the industry. More than 207,000 professionals have earned the CISA credential since 1978, reflecting its established reputation and continued relevance. If you are considering pursuing this certification, understanding its difficulty, scope, and structure will help you assess whether you are ready and what to expect on test day.

Understanding the Exam Structure and Scope

The CISA exam is built around 5 job practice domains, each representing critical areas of information systems auditing and security. The updated exam became available on 1 August 2024, with a revised focus that emphasizes risk, security and controls related to disruptive technologies and emerging IT audit practices. This shift means candidates today face questions that reflect modern security landscapes and evolving organizational threats.

The exam consists of 150 questions that must be completed in 240 minutes (4 hours). This timing structure demands efficiency and confident decision-making. You cannot afford to dwell too long on any single item without risking incomplete coverage of the full exam.

Domain Breakdown and Content Weighting

Success on the CISA exam requires balanced preparation across five domains, though not all carry equal weight. Domain 1—Information Systems Auditing Process—is weighted at 18% of the exam, covering foundational audit methodologies and practices. Domain 2—Governance and Management of IT—is weighted at 18%, focusing on organizational oversight and IT direction.

Domain 3—Information Systems Acquisition, Development and Implementation—is weighted at 12%, making it the lightest domain. However, the remaining two domains carry significantly greater emphasis. Domain 4—Information Systems Operations and Business Resilience—is weighted at 26%, and Domain 5—Protection of Information Assets—is weighted at 26%, meaning a large share of the exam tests your grasp of operational security, incident response, and asset protection.

This distribution signals where exam-takers typically struggle most. If you have extensive hands-on experience in security operations, vulnerability management, or business continuity, you hold an advantage. If your background is lighter in these areas, expect to invest significant effort building competency here.

Passing Requirements and Credentialing Path

A scaled score of 450 or higher is required to pass the CISA exam. The scaled scoring means raw question counts do not directly map to your final score; ISACA adjusts for item difficulty and other statistical factors. This transparency around the passing threshold is useful, but it also underscores that the exam is designed to discriminate between candidates who truly understand audit and security principles and those who do not.

Passing the exam is not the end of the credentialing journey. Candidates have 5 years from passing the exam to apply for CISA certification. This window accounts for post-exam experience requirements; most candidates must accumulate a defined period of paid IT audit work or a combination of IT experience and education before they can formally claim the CISA credential. Additionally, certified professionals must adhere to ISACA's Continuing Professional Education (CPE) Policy to retain the credential, meaning ongoing learning commitments extend well beyond passing the exam.

Test Logistics and Accessibility

Exam Element Detail
Total Questions 150
Testing Duration 240 minutes (4 hours)
Passing Score 450 (scaled)
Member Exam Fee US$575.00
Non-Member Exam Fee US$760.00
Testing Vendor PSI (in-person and remote proctoring)
Test Locations More than 1,300 worldwide
Exam Eligibility Period 6 months from registration

ISACA delivers the CISA exam through PSI, offering both in-person test center appointments and remote online proctoring. PSI operates more than 1,300 testing locations across the world for the CISA exam, providing flexibility in how and where you take the test. Whether you prefer the structure of a testing center or the convenience of home-based remote proctoring, options are widely available.

Assessing Your Readiness

The difficulty of the CISA exam depends heavily on your background. If you have extensive hands-on IT audit, security, or governance experience, you already possess domain knowledge that will accelerate your study. The exam will still challenge you—it tests depth and nuance, not surface-level familiarity—but your foundational understanding is in place.

If your experience is lighter or concentrated in only one or two domains, the exam becomes considerably harder. You will need to build competency across all five domains, especially in operations and asset protection, where the test places the greatest emphasis. This is not insurmountable, but it requires disciplined, comprehensive study that targets your weak areas repeatedly.

What Makes the CISA Exam Hard

The primary difficulty stems from breadth. The CISA exam does not specialize in a single technology or platform; instead, it measures your ability to think strategically about audit, governance, and security across enterprise environments. You must understand cloud security, data protection, incident response, compliance, risk management, and organizational change—often in the same exam sitting.

A secondary challenge is the question quality. ISACA invests in rigorous psychometric development of its exam items. Questions are designed to test applied reasoning, not rote memorization. You may encounter scenarios where multiple answers seem partially correct, forcing you to choose the best response based on audit principles and risk judgment. This level of cognitive demand separates passing scores from merely attempting the exam.

The structured approach to study should reflect your gaps. Begin by reviewing the five domains and identifying which are strongest and which need development. Tackle heavy-weighted domains (4 and 5) with special attention, but do not neglect lighter domains—they still contribute meaningful percentage points to your score. Engage with official ISACA study materials, practice questions, and hands-on audit scenarios. You are ready when you consistently score well on full-length practice tests and can defend your answer choices with reference to audit principles.

The CISA exam is genuinely challenging, but it is not unattainable. Thousands of professionals earn the credential every year by committing to comprehensive study and leveraging their experience. Your success depends on honest assessment of your current knowledge, disciplined focus on weak areas, and willingness to engage deeply with the material.

Ways to prepare for the CISA

Weighing a paid course

Each of these is a side-by-side on what the provider does better than we do, what it charges today, and where the free path here is enough.

Frequently asked questions

How much does the CISA exam cost?

The CISA exam registration fee is US$575.00 for ISACA members and US$760.00 for non-members. If you plan to sit for the exam, it's worth comparing the cost of an ISACA membership against the US$185 fee difference — for many candidates the member discount effectively offsets a large portion of joining.

How many questions are on the CISA exam and how long do I have?

The CISA exam consists of 150 questions and gives you a total testing time of 240 minutes (4 hours). That works out to an average of roughly 1.6 minutes per question, so pace yourself and avoid getting stuck on any single item.

What score do I need to pass, and how is the exam structured?

You need a scaled score of 450 or higher to pass the CISA exam. The exam is built around 5 job practice domains, and questions are weighted by domain: Domain 4 - Information Systems Operations and Business Resilience and Domain 5 - Protection of Information Assets are each weighted at 26%, together accounting for 52% of the exam content. Because these two domains dominate the exam, prioritizing them in your study plan gives you the best return on effort.

After I register, how long do I have to take the exam and then get certified?

Your exam eligibility period is 6 months from the date of registration, so you'll want to schedule and sit for the exam within that window. Once you pass, you then have 5 years from the date of passing to apply for CISA certification. In practical terms, register only when you're confident you can be ready to test within about half a year, then use the generous post-exam window to complete the experience requirements before applying.

Is the CISA exam hard?

The CISA exam is demanding mainly because of its breadth and length: ISACA gives candidates 240 minutes (4 hours) to answer 150 questions spread across 5 job practice domains. The difficulty is less about trick questions and more about sustaining auditor-style judgment for four straight hours across governance, operations, and security material. Candidates who come from a narrow technical background usually find the governance and audit-process content harder than the technical content, since the exam rewards the auditor's perspective over the engineer's.

What is the passing score for the CISA exam?

ISACA requires a scaled score of 450 or higher to pass the CISA exam. Because the score is scaled rather than a raw percentage of the 150 questions answered correctly, you cannot simply translate "450" into a fixed number of correct answers. The practical takeaway is to aim comfortably above a bare pass on practice material rather than trying to reverse-engineer a question count.

How long do I have to take the exam after I register — and to get certified after I pass?

ISACA sets the exam eligibility period at 6 months from the date of registration, and once you pass you have 5 years from the exam date to apply for CISA certification. Those two windows work very differently: the first is a tight scheduling deadline, while the second gives you room to accumulate the experience your application needs. ISACA delivers the exam through PSI, which offers both in-person test center appointments and remote online proctoring, so scheduling inside the six months is usually the easy part.

How should I study for the CISA exam?

Study by domain weight, because the five domains are not equal: ISACA weights Information Systems Operations and Business Resilience at 26% and Protection of Information Assets at 26%, so together Domains 4 and 5 account for 52% of the exam content. Domains 1 and 2 sit at 18% each and Domain 3 — Information Systems Acquisition, Development and Implementation — at just 12%, which makes it the lowest-yield place to spend extra weeks. A sensible plan front-loads Domains 4 and 5, then uses timed practice sets to build the endurance the four-hour format demands.

Is my old CISA study material still current?

Check the edition date first: ISACA's updated CISA exam became available on 1 August 2024, and the current exam content outline took effect the same day. The revised exam retains its structure of 5 job practice domains but emphasizes risk, security and controls related to disruptive technologies and emerging IT audit practices, so pre-2024 material can leave gaps in exactly those areas. Also note that passing is only the start of the commitment — certified professionals must adhere to ISACA's Continuing Professional Education (CPE) Policy to retain the credential, which more than 207,000 professionals have earned since 1978.

Sources

  1. 1.CISA Exam Content OutlineISACA (accessed Jul 18, 2026)
  2. 2.CISA Certification OverviewISACA (accessed Jul 18, 2026)
  3. 3.Certification Exam Candidate GuidesISACA (accessed Jul 18, 2026)
  4. 4.ISACA's CISA Exam Updated to Reflect Innovations and Evolving Technologies (Press Release, 2024)ISACA (accessed Jul 18, 2026)
  5. 5.ISACA CredentialsISACA

Official sources

Primary documents used to verify the exam details shown on this page.

Last verified against the official exam content outline: