CISA CPE Requirements: What It Takes to Keep the Certification

CISA CPE requirements: 20 hours per year and 120 hours per three-year cycle

The CISA CPE requirements come to this: a minimum of 20 CPE hours every year, a total of 120 CPE hours across each three-year reporting cycle, and an annual maintenance fee paid to ISACA. That is the whole obligation in one sentence. The two hour figures run at the same time, and this is the part people misread: clearing 120 across three years does not excuse you from the 20 in any single year inside that cycle.

The maintenance fee is USD 45 for ISACA members and USD 85 for non-members, due annually by 1 January to renew through the coming calendar year. If you hold more than two ISACA certifications, the third and every one after it renews at a reduced rate, currently USD 25 for members and USD 50 for non-members. Fees and policies change, so confirm the current figures on ISACA's Maintain CISA page before you budget for the year.

What are the CISA CPE requirements each year and each cycle?

Twenty a year. One hundred twenty over three. Both conditions have to be true, every cycle, for as long as you hold the credential.

Think of it as a floor and a total. The floor stops you from disappearing for two years and cramming in year three. The total stops you from coasting at the bare minimum forever, because 20 a year for three years is only 60, which is half of what the cycle demands. In practice the arithmetic means an average of 40 hours a year, with 20 as the hard bottom in any one of them.

If you are still deciding whether the credential earns its keep, that ongoing obligation belongs in the calculation. We work through the wider math in is the CISA worth it, and the one-time costs in CISA exam cost and fees.

What counts as CPE for a CISA?

ISACA's CPE policy recognizes technical and managerial training that applies to the certification's job practice areas. That is a wider door than most people assume. The qualifying categories cover ISACA professional education such as conferences, seminars, workshops and chapter programs, non-ISACA professional education including corporate training and university courses, structured self-study courses, vendor presentations, teaching and presenting, publishing articles or books, developing or reviewing certification exam questions, passing other related professional exams, ISACA board or chapter officer work, professional contributions like research and peer review, and mentoring.

Several of those categories carry annual caps. Vendor presentations and mentoring are limited to 10 hours a year each. Board or committee work and professional contributions are limited to 20 hours a year each. The caps exist so nobody builds an entire cycle out of one activity type, and they are the detail most likely to bite you if you planned your year around a single source.

Credit is one CPE hour for each 50 minutes of active participation, excluding lunches and breaks, and hours can be reported in quarter-hour increments. That detail is worth knowing, because a full-day session with breaks stripped out often earns more than the round number you would have claimed. University coursework is more generous, at 15 CPE hours per semester credit hour and 10 per quarter credit hour. Teaching pays a multiple: five times the presentation time for the first delivery of new material, then actual presentation time for a second delivery of the same content. If you have ever built a training session for your team, you have earned more than you probably claimed.

What does not count?

Basic office software training is explicitly excluded. So, by implication, is anything with no real link to the CISA job practice: audit process, IT governance and management, systems acquisition and development, operations and resilience, and protection of information assets. Time spent on the job is not CPE either. Doing an audit is your work; learning something structured about how to audit is education.

The honest test is whether you could describe the activity to an auditor and have them nod. If you cannot name the provider, the date, the subject and the hours, it is not going to survive scrutiny.

How do you earn and document hours?

Earning is the easy half. Documenting is where people get careless.

Report hours through your ISACA account. Activities that ISACA tracks itself, such as its own courses and events, are pre-loaded onto your certification dashboard. Everything else, including chapter programs and outside training, you enter yourself. Self-study courses need a certificate of completion from the provider showing the hours earned.

Keep evidence for every activity. ISACA asks for records covering the participant name, the sponsoring organization, the activity title, the date, and the number of CPE hours awarded, retained for 12 months after the end of each three-year reporting cycle. The practical version of this advice: make a folder now, drop every certificate, agenda and confirmation email into it the day you receive it, and add a one-line entry to a spreadsheet with those five fields. Ten minutes a year of discipline replaces a miserable weekend of reconstruction later.

What is the CPE audit, and how likely is it?

ISACA randomly selects certification holders each year and asks them to document the hours they reported. It is a paperwork exercise, and it is entirely survivable if you kept records.

The stakes are real, though. Holders who do not comply with the audit have their CISA revoked. Note the wording carefully. What triggers revocation is failure to comply with the audit. Someone who reported 42 hours and can produce evidence for 38 is in a very different position from someone who reported 42 hours and produces nothing at all. Records are the whole defense.

What happens if you fall short?

If you miss the annual minimum, miss the cycle total, or let the maintenance fee lapse, your certification is at risk. ISACA handles shortfalls and reinstatement under its current CPE policy, and the specifics of any grace period or reinstatement route are the kind of detail that gets updated, so check the current rules on ISACA's Maintain CISA page or in the CPE policy document rather than trusting a forum post from three years ago.

What you should not do is go quiet. A shortfall you flag and ask about is an administrative problem. A shortfall you hide until the audit letter arrives is a different conversation entirely.

How do you get 20 hours a year without an expensive conference?

This is the question behind most CPE anxiety, and the answer is that conferences are the most expensive way to do it and rarely the best one.

Start with your ISACA chapter. Local chapter meetings and events are among the cheapest qualifying education available, often free or close to it with membership, and they tend to run monthly. Two or three chapter evenings can cover a meaningful slice of your annual floor.

Then look at what your employer already pays for. Corporate training, vendor-neutral platform subscriptions, internal technical sessions with an actual curriculum, and formal courses your security or IT team runs all fall under non-ISACA professional education. Most people under-claim here because they think of training as something that happens at a venue.

Teach something. The multiplier on first-delivery teaching is the highest-value line in the whole policy. Building and delivering a two-hour session on control testing for your junior auditors earns considerably more than sitting through two hours of someone else's. You were going to do the knowledge transfer anyway.

Write something. Articles and published pieces qualify. So does exam question development and review, which has the added advantage of counting across every ISACA certification you hold.

And take a university or structured self-study course if one fits your year. The credit conversion for academic coursework is favorable, and structured self-study with a completion certificate is the most schedule-friendly category on the list.

What changes if you hold more than one ISACA certification?

Two things work in your favor. The renewal fee drops for your third certification and beyond, and certain qualifying activities can be multi-counted across all your ISACA certifications rather than split between them. Exam question development and board or committee work are named explicitly in the policy as multi-countable.

Do not assume every hour is automatically portable, though. The rules on which activities can be applied to which certifications live in ISACA's current CPE policy, and that is where you should check before you plan a cycle around double-counting. If you are weighing a second ISACA credential, CISA vs CISM covers what each one is actually for.

What is changing in the CPE policy on 1 January 2027?

One thing you should know before you plan a cycle: ISACA has announced a CPE policy change effective 1 January 2027, and it changes what counts rather than how much.

The headline numbers survive. It is still 120 CPE hours across a three-year cycle. What ISACA is adding is a split between two categories. Certification-aligned hours, meaning education tied directly to your certification's exam content outline and domains, must make up at least 90 of the 120. The remaining 30 are optional and can come from a new professional-aligned category, described as skills that support professional growth without being aligned to exam content.

The examples ISACA gives are the useful part, because they tell you which bucket your usual activities land in. Certification-aligned covers a cybersecurity class, ISACA conferences and virtual summits, exam item writing, review manual development, publishing on emerging technologies, and teaching content aligned to your certification. Professional-aligned covers a communications skills class, mentoring a young professional, serving as an ISACA chapter officer or board member, leadership conferences, and chapter presentations that are not tied to exam content.

Read that second list carefully if you have been leaning on chapter officer work or mentoring to fill your year. Those hours still count, but from 2027 they compete for a capped 30 across three years rather than counting freely. The practical adjustment is to make sure the bulk of your hours are demonstrably tied to the CISA domains, and to treat the softer activities as the top-up rather than the base. ISACA publishes the revised policy as a PDF on its CPE Policy Changes for 2027 page, and that is the document to read before your next cycle rather than any summary, including this one.

The opinion: the annual minimum is the trap

The 120-hour cycle total is the number everyone quotes, and it is the wrong number to worry about. Twenty hours a year is the one that ends certifications.

Here is the pattern. Year one, you have just passed the exam and you feel current, so you do a little and bank nothing. Year two, work gets busy, and the cycle deadline still looks far away. Year three, you finally sit down with the dashboard and discover two problems at once: you owe roughly 100 hours in twelve months, and you have already missed the annual minimum in years one and two. The cycle total you can still theoretically rescue with a brutal year. The annual minimums you cannot. Those years are closed.

So treat 20 as a monthly-ish obligation, not an annual one. Two hours a month clears the floor with room to spare and gets you most of the way to the cycle average without ever feeling like a scramble. The people who find CPE painless are not the ones with the biggest training budgets. They are the ones who log an hour when they earn it.

If you have not passed the exam yet and this is all forward planning, the sequence matters: experience first, then the exam, then maintenance. We cover the eligibility side in CISA experience requirements, the exam itself in what is the CISA exam, and if you want the five domains in plain English with four full-length practice exams and every answer explained, that is our CISA study guide.

FAQ

How many CPE hours does a CISA need per year?

A minimum of 20 CPE hours annually, plus a total of 120 CPE hours across each three-year reporting cycle. Both requirements apply at once, so meeting the three-year total does not cover you if you fell below 20 in any individual year of that cycle.

How much is the CISA annual maintenance fee?

USD 45 for ISACA members and USD 85 for non-members, due by 1 January each year for the coming calendar year. If you hold more than two ISACA certifications, the third and each additional one renews at a reduced rate, currently USD 25 for members and USD 50 for non-members. Confirm the current amounts on ISACA's Maintain CISA page before you plan around them.

Does my day job count toward CISA CPE?

No. Performing audits is your work, not continuing education. What counts is structured technical or managerial training tied to the CISA job practice areas, along with teaching, publishing, exam question development, chapter and committee work, and related professional exams. Basic office software training is specifically excluded.

What happens if I get selected for a CPE audit?

ISACA asks you to document the activities you reported, with the participant name, sponsoring organization, activity title, date and hours for each one. Keep those records for 12 months after the end of each three-year cycle. Certification holders who do not comply with the audit have their CISA revoked, so the records are what protect you.

Can one activity count toward more than one ISACA certification?

Some can. ISACA's policy names exam question development and board or committee work as activities that can be multi-counted across all your ISACA certifications. The rules vary by activity type, so check ISACA's current CPE policy rather than assuming every hour is portable.


Looking for a plain-English CISA guide? ISACA CISA: Certified Information Systems Auditor Study Guide covers all five domains with four full-length practice exams, every answer explained.

Simply Certified is an independent publisher. CISA and ISACA are trademarks of ISACA. Our books are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.