CISA Requirements: The 5-Year Experience Rule, Explained

CISA requirements: 5 years of IS/IT audit experience, waivers up to 3 years

The CISA requirements confuse more people than the exam content does. Here is the short version: anyone can register for and sit the CISA exam. There is no experience gate, no degree check, no prerequisite certification. The experience requirement, five years of professional work in IS/IT audit, control, assurance, or security, only applies when you apply for the certification itself, and that application can come up to five years after you pass.

So the 5-year rule is real, but it sits at the certification step, not the exam step. ISACA also allows waivers and substitutions that can cover up to three of those five years, which means some candidates certify with as little as two years of qualifying work. The rest of this post walks through each requirement in order: sitting the exam, the experience rule, what can substitute for it, the application timeline, the fees, and what it costs you in effort every year to keep the credential.

Who can take the CISA exam?

Anyone. ISACA's exam registration is open and continuous: you register whenever you like, pay the fee, and you can schedule a testing appointment as early as 48 hours after payment. There is no application to sit the exam, no employer sign-off, and no minimum experience check at registration.

Once you register, you have a six-month eligibility period to take the exam. If life gets in the way, you can buy one six-month extension for USD 75, but only one, and the fee itself is nonrefundable and nontransferable. The exam runs 150 multiple-choice questions over 4 hours, delivered at a PSI test center or through online remote proctoring, and is scored on a 200 to 800 scale with 450 to pass. If you want the full picture of the exam itself, the pillar post on what the CISA exam is covers format, domains, and scoring in detail.

This open-registration model trips people up because other credentials do gate the exam. CISA does not. The gate comes later.

What is the 5-year experience requirement?

To become certified, ISACA requires five or more years of experience in IS/IT audit, control, assurance, or security. Note the breadth of that list. You do not need five years with "IT auditor" in your job title. Control work, assurance work, and security work all count, which covers a lot of people in compliance, risk, internal audit support, and security operations who never thought of themselves as auditors.

The experience is verified, not just claimed. When you apply for certification, you submit an application that demonstrates the experience requirements, and it must be independently confirmed. That verification step is why the requirement has teeth: passing the exam proves knowledge, the application proves you have done the work.

What waivers and substitutions are available?

ISACA allows experience waivers and substitutions for a maximum of three years of the five. That cap is the number that matters: no combination of education or alternative experience gets you below two years of verified professional work.

The Candidate Guide states the three-year maximum but leaves the itemized substitution list to ISACA's CISA application requirements page, so check the current list there before counting on a specific credit. Broadly, substitutions credit university education and certain related experience against the requirement, with each category worth a defined amount and the total capped at three years.

Two practical notes. First, the waiver is not automatic; you claim it in your application and it gets reviewed like everything else. Second, the three-year cap is generous compared with ISACA's other credentials. CISM caps waivers at two years, CRISC allows none, and CGEIT allows at most one year. If you are early in your career, CISA is the ISACA credential with the most forgiving path.

Can I take the CISA with no experience?

Yes, you can sit the exam with zero experience. You cannot be certified until the experience is verified.

This is the most common misconception about CISA requirements, so it is worth being precise. Nothing stops a student or a career changer from registering, passing, and holding a passing score. What they hold at that point is a pass, not a certification. They cannot call themselves a CISA, and the credential does not appear anywhere until the application is approved.

What makes this genuinely useful rather than a technicality is the timeline: candidates have five years from passing the exam to apply for certification. Pass the exam in your final year of university or your first year in a GRC role, and the clock gives you five full years to accumulate the two to five years of qualifying experience you need. For a lot of people, passing early is the smart play. The material is fresh, study time is easier to find before the job gets demanding, and a passing score on your resume signals commitment even before the letters are official.

The one risk is letting the window lapse. If five years pass without an approved application, the pass expires and you would need to retake the exam. Put the deadline in your calendar the day your score arrives.

What does the CISA exam cost?

The exam registration fee is USD 575 for ISACA members and USD 760 for nonmembers. The fee is nonrefundable and nontransferable, and it must be paid in full before you can schedule.

There are a few other numbers worth knowing before you budget:

Item Cost
Exam registration (ISACA member) USD 575
Exam registration (nonmember) USD 760
Six-month eligibility extension (max one) USD 75
Certification application processing fee USD 50
Rescore request (within 30 days of results) USD 75

Retakes cost the full registration fee each time. You get four attempts within a rolling 12-month period: a 30-day wait before attempt two, then 90-day waits before attempts three and four. At USD 575 to 760 per sitting, the cheapest exam is the one you pass once, which is a fair argument for an honest read on how hard the CISA exam is before you book a date.

What are the steps to become certified?

Once you pass, certification is a five-part checklist:

  1. Pass the certification exam.
  2. Pay the USD 50 application processing fee.
  3. Submit the application demonstrating your experience.
  4. Adhere to ISACA's Code of Professional Ethics.
  5. Adhere to the Continuing Professional Education policy.

CISA holders also agree to comply with ISACA's Information Systems Auditing Standards, a requirement specific to this credential among ISACA's certifications. It fits the job: the certification exists to assure audit quality, so holders commit to the standards that define it.

What are the ongoing CPE requirements?

Certification is not a one-time event. To maintain the CISA, you complete continuing professional education: 20 CPE hours every year and 120 hours across each three-year cycle. There is also an annual maintenance fee paid to ISACA; check the current figure on ISACA's CISA maintenance page, since it changes and we would rather point you at the live number than print a stale one.

Twenty hours a year is manageable for anyone working in the field. Conference sessions, ISACA chapter meetings, webinars, and structured training all typically qualify. The 120-hour cycle total means you cannot coast on the annual minimum every year; 20 times three is 60, so plan for heavier years somewhere in the cycle.

How should you sequence the CISA requirements?

If you are experienced, the order is simple: study, pass, apply immediately, done. If you are short of the experience bar, pass first and let the five-year window work for you while your qualifying years accrue.

Either way, the exam is the step you control the timing of, so control it. A structured run at the five domains beats open-ended reading; our 12-week CISA study plan lays out one workable schedule. And if you want the material itself in plain English, the ISACA CISA: Certified Information Systems Auditor Study Guide covers all five domains with four full-length practice exams, every answer explained.

The requirements are less scary than they first look. The exam is open to everyone, the experience rule bends by up to three years, and the clock after passing is long. What ISACA is really asking for is proof you know the work and proof you have done it, in whichever order suits your career.

FAQ

Can I take the CISA exam as a student?

Yes. Exam registration has no experience prerequisite, so students can register, sit, and pass. You then have five years from your pass date to apply for certification, which gives you time to build the qualifying experience after graduation.

How many years of experience do I need for CISA certification?

Five years of experience in IS/IT audit, control, assurance, or security. Waivers and substitutions can cover a maximum of three of those years, so the practical minimum of verified professional experience is two years.

How long is my CISA exam pass valid?

Five years. You must submit and complete your certification application within five years of passing the exam. If the window lapses, the pass expires and the exam must be retaken.

What does the CISA certification application cost?

The application processing fee is USD 50, paid on top of the exam registration fee of USD 575 for members or USD 760 for nonmembers.

What are the CPE requirements to keep the CISA?

20 CPE hours per year and 120 hours per three-year reporting cycle, plus adherence to ISACA's Code of Professional Ethics and, for CISA specifically, the Information Systems Auditing Standards. An annual maintenance fee also applies; check ISACA's maintenance page for the current amount.


Looking for a plain-English CISA guide? ISACA CISA: Certified Information Systems Auditor Study Guide covers all five domains with four full-length practice exams, every answer explained.

Simply Certified is an independent publisher. CISA and ISACA are trademarks of ISACA. Our books are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.