The CISA passing score is 450. Scores are reported on a scale that runs from 200 to 800, and 450 is the line: at or above it you pass, below it you do not. That number applies to every candidate on every version of the exam, and it does not shift with your test date, your test center, or the particular set of 150 questions you happen to draw.
That is the complete answer. The rest of this post exists because the number gets misread constantly. A score of 450 out of 800 looks like a percentage, so people treat it as one and conclude they need about 56% of the questions right. They do not. A scaled score is a conversion of your performance onto a shared yardstick, and the conversion table is not published by ISACA or anyone else.
Is the CISA passing score of 450 the same as 56 percent?
No, and the arithmetic behind that 56% is measuring something the scale does not contain. Start with the obvious problem: the scale does not begin at zero. The floor is 200. A candidate who answers nothing correctly does not receive a 0, and the usable band is the 600 points between 200 and 800, not the full 800.
Run the naive math the other way and you get a different answer. If you treat 450 as a position within the 200 to 800 band, it sits roughly 42% of the way up. So the same score yields 56% under one framing and 42% under another, and neither figure tells you anything about how many questions you need. That contradiction is the tell. When two reasonable-looking calculations on the same number disagree, the calculation is the wrong tool.
The scaled score is a report of where your performance landed against a fixed standard. It is not a count of anything, and it does not convert to a count in any way you can do on the back of an envelope.
What is a scaled score, and why does ISACA use one?
Every administration of the CISA draws from a large item bank, so different candidates see different questions. Those question sets cannot be made perfectly identical in difficulty. One form might land a slightly harder run of Domain 5 items; another might be marginally gentler on governance.
If raw correct answers were reported directly, that variation would be unfair in both directions. A candidate on a hard form would be penalized for the luck of the draw, and a candidate on an easy form would be flattered by it. Scaled scoring exists to remove that luck from the result.
The mechanism is called equating. Before a form goes live, its items have known statistical properties, and the raw-to-scaled conversion for that form is built so that a given scaled score reflects the same demonstrated ability no matter which form produced it. A 450 earned on a slightly harder form and a 450 earned on a slightly easier form represent the same standard. That is the entire point, and it is a genuinely good design.
The consequence follows directly. Because the conversion is built per form, the raw performance that produces a 450 is not a constant. It moves, by design, in the opposite direction to form difficulty.
How many questions do you need to answer correctly to pass?
Nobody outside ISACA can tell you, and that is not evasion, it is the structural fact of how the exam is scored. The conversion tables are not public. They differ by form. Even ISACA cannot hand you one number that holds for every candidate, because a single number would defeat the purpose of equating.
This matters because plenty of sites will give you a number anyway. You will see confident claims that you need a specific count out of 150, or a specific percentage, sometimes stated to a decimal place. Those figures are guesses dressed up as data. The people writing them do not have access to the conversion, and if they did, publishing it would tell you about one retired form rather than the one you will sit.
Treat a precise raw-correct claim as a reliability signal about the source. A site willing to invent that number is willing to invent other things, and CISA candidates already have enough trouble with sources that fabricate figures. It is the same reason we never quote a pass rate.
What does the CISA score report show?
Two things worth your attention. First, a total scaled score on the 200 to 800 range, which is the number that decides pass or fail. Second, a breakdown of your performance by domain area, so you can see how you did across the five sections of the exam rather than only in aggregate.
That domain-level detail is the part candidates skim past and should not. The total tells you the outcome. The subscores tell you why, and they are the only diagnostic information you get about your own exam.
The five domains carry fixed weights, which is the context you need to interpret those subscores:
| Domain | Weight |
|---|---|
| 1. Information Systems Auditing Process | 18% |
| 2. Governance and Management of IT | 18% |
| 3. IS Acquisition, Development, and Implementation | 12% |
| 4. IS Operations and Business Resilience | 26% |
| 5. Protection of Information Assets | 26% |
Domains 4 and 5 are 26% each, so together they carry 52% of the exam. A weak subscore in Domain 5 costs you far more than the same weakness in Domain 3, which is 12% of the questions. Our full breakdown of each domain is in CISA domains explained, and it is worth reading with your subscores open next to it.
How do you read a failed score report and plan a retake?
Start with the gap. A 430 and a 310 call for different responses, and treating them the same wastes weeks. If you landed close to 450, you are looking at refinement: tighten the two weakest domains, do more explained practice on the qualifier-style questions, rehearse the full 4-hour sitting. If you landed well below, the honest read is that coverage was thin somewhere substantial, and another pass through the material is a better use of time than more practice questions.
Then read the subscores as a shape, not a list. What you want to know is whether your performance was flat across all five domains or spiky. Flat and slightly short is the easier problem. Spiky, with one or two domains far below the rest, tells you exactly where the hours go.
Weight the repair by the blueprint, not by how uncomfortable a domain feels. A soft Domain 4 or 5 result deserves the bulk of your retake study because those two domains decide half the exam. A soft Domain 3 result is worth a targeted week and not much more.
Finally, factor in the cost of the attempt. At USD 575 for ISACA members and USD 760 for nonmembers, a rushed retake is an expensive way to confirm you were not ready. We break the numbers down in CISA exam cost and fees. Book the date when the subscores say the gap is closed, not when the disappointment is freshest.
What should you target on practice exams instead?
Since the raw cutoff is unknowable, chasing a percentage target is chasing a number that does not correspond to anything. Here is what to use instead.
Judge readiness on three signals instead of a number. Your results hold steady across several full-length timed runs rather than swinging twenty points between them. Your weakest domain sits near your average rather than dragging behind it. And on the items you answered correctly, you can say out loud why the credited option beat the runner-up. That last signal is the one people skip, and it is the one that catches lucky guessing, which inflates a practice score and does nothing for you on exam day.
An evenly strong profile beats a lopsided one, even at the same overall score. Two candidates can average the same and face very different odds, because the lopsided one is exposed to the luck of the draw. If your Domain 5 knowledge is thin and your form happens to lean into the harder end of Domain 5 items, you have no cushion, and Domain 5 is a quarter of the exam. The candidate with no weak domain absorbs a bad run of questions anywhere. That is the profile to build.
If you want to see what working through explained questions looks like in practice, we walk through several in CISA practice questions explained. Our CISA study guide is built around the same idea: plain-English coverage of all five domains plus four full-length practice exams where every option, credited and not, is explained.
Why does the CISA pass rate question hit the same wall?
Because there is no published pass rate either. ISACA does not release one, no percentage-of-candidates figure exists in any official source, and every number you have seen quoted online was estimated, extrapolated from a forum poll, or made up outright.
The pass rate question and the cut score question come from one instinct: the wish to know your odds before you commit. The instinct is understandable and the information does not exist. What does exist is published and verifiable: 150 multiple-choice questions, 4 hours, five domains with fixed weights, scaled scores from 200 to 800, and 450 to pass. Build your preparation on the parts that are real.
The opinion: stop reverse-engineering the cut score
Of everything a CISA candidate can spend attention on, working out how many questions equal 450 is the least useful. It is unknowable, it varies by form, and knowing it would change nothing about how you study. The exam does not become easier because you have a target count, and no realistic study plan looks different at 100 correct than at 105.
What the reverse-engineering actually does is give you a way to feel productive while avoiding the work. It has the texture of preparation. It is arithmetic, it involves the exam, it feels like planning. But you cannot practice it, and it does not move a single subscore.
The useful version of the same energy is this: identify your weakest domain, weight it by the blueprint, and close the gap with explained practice. Do that until no domain trails the others and your full-length runs are steady. Then sit the exam. For the wider picture of what you are preparing for, start with what the CISA exam is, and for an honest read on the difficulty, see how hard the CISA exam is.
The score takes care of itself when the preparation is even. That reads like a slogan, but it is the one strategy the scoring model actually rewards.
FAQ
What is the passing score for the CISA exam?
450 on a scaled range of 200 to 800. The mark is fixed and applies to every candidate on every form of the exam. Your score report gives you the total scaled score plus a breakdown of how you performed across the five domain areas.
Is 450 out of 800 equal to 56 percent?
No. The scale does not start at zero, so a percentage read of the number is not meaningful, and the scaled score is a conversion of your performance rather than a count of correct answers. Treating it as a percentage produces different answers depending on how you set up the fraction, which is a good sign the calculation does not apply.
How many CISA questions do I need to answer correctly?
Nobody outside ISACA can say, and the count is not fixed anyway. Equating builds a separate raw-to-scaled conversion for each form, so the raw performance sitting behind a 450 moves with how hard that form turned out to be. The conversion tables are not published. Any site quoting an exact figure, especially one carried to a decimal place, is guessing.
Why can nobody tell me the CISA pass rate?
Because ISACA does not release one. The figures circulating on forums and prep sites were estimated from self-selected samples or invented outright, and there is no official source to check them against. Treat a confident pass-rate claim the same way you treat a confident raw-cutoff claim: as evidence about the site, not about the exam.
How should I use my domain subscores after failing?
Read them as a shape rather than a list of numbers. If one or two domains trail the rest, that is where your retake study goes, weighted by the blueprint so Domains 4 and 5 get priority given they are 26% each. If everything sits evenly just below the line, you need refinement across the board rather than a rescue mission in one domain.
Looking for a plain-English CISA guide? ISACA CISA: Certified Information Systems Auditor Study Guide covers all five domains with four full-length practice exams, every answer explained.
Simply Certified is an independent publisher. CISA and ISACA are trademarks of ISACA. Our books are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.