How Long to Study for the CISA? A 12-Week Plan That Matches the Weights

How long to study for the CISA: a 12-week plan weighted to the five domains

How long to study for the CISA? For most working professionals, a sensible planning assumption is roughly 2 to 3 months at 8 to 10 hours a week. That works out to somewhere between 95 and 120 hours of study, spread thin enough to hold a job at the same time. Treat that as a planning number, not a prediction. Nobody can tell you your number in advance, because the honest answer depends on how much of the exam you already do for a living.

The CISA is a big exam by any measure: 150 multiple-choice questions in 4 hours, scored on a scale of 200 to 800 with 450 to pass, covering five domains that ISACA weights at 18, 18, 12, 26, and 26 percent. The exam also expects five years of IS audit, control, assurance, or security experience, with waivers and substitutions up to three years. So most candidates arrive already knowing a real chunk of the material. The job of a study plan is not to teach you everything from zero. It is to close the gap between what you do at work and what the exam actually asks, and to spend your hours where the weights say the points are.

Why "it depends" is the honest answer

If you are a practicing IT auditor, Domains 1 and 2 describe your working week: audit planning, evidence, sampling, reporting, governance, vendor management. You will read those chapters nodding. Your gap is more likely Domains 4 and 5, the operations, resilience, and security content, which together carry 52 percent of the exam.

If you come from security or infrastructure, it flips. You already know backup schemes, IAM, encryption, and incident response. Your gap is the auditor's half: audit standards, risk-based planning, sampling methodology, and the discipline of forming an opinion from evidence rather than fixing what you find.

Either way, the exam tests everything from the auditor's seat. Domains 4 and 5 are technical content, but the questions ask you to assess and assure controls, not to build or configure them. That reframing takes time to absorb even for strong technologists, and it is the main reason we suggest a full 12 weeks rather than a sprint. If you want the domain-by-domain detail before committing to a schedule, start with what the CISA exam actually covers.

How should study time map to the domain weights?

The weights are published, so use them. Domain 3 is the smallest at 12 percent and the worst place to spend your first study week. Domains 4 and 5 are 26 percent each, and together they are more than half the exam. A plan that gives every domain equal time is quietly overweighting the small domains and underweighting the two that decide the result.

The plan below follows that logic. Domains 1 and 2 get two weeks each, Domain 3 gets one, and Domains 4 and 5 get the most time: two weeks each plus a shared second-pass week, five weeks combined for the 52 percent that earns it. The final three weeks belong to full-length practice exams and, more importantly, to reviewing every wrong answer. We walk through each domain's content in CISA domains explained if you want to preview what each block covers.

The 12-week CISA study plan

Assume 8 to 10 hours a week. Weekday evenings for reading, one longer weekend block for practice questions on what you just covered.

Week Focus What you cover
1 Domain 1, part 1 (18%) Audit standards and ethics, types of audits, risk-based planning, types of controls
2 Domain 1, part 2 Audit execution: project management, testing and sampling, evidence, analytics, reporting
3 Domain 2, part 1 (18%) IT governance: laws and standards, org structure and strategy, policies, EA, ERM, privacy, data governance
4 Domain 2, part 2 IT management: resources, vendor management, performance monitoring, quality
5 Domain 3 (12%) The full life cycle: project governance, business case, SDLC methods, control design, testing, release, migration, post-implementation review
6 Domain 4, part 1 (26%) IS operations: asset management, scheduling, interfaces, shadow IT, availability, incident and problem management, change and patch, logs, SLAs, databases
7 Domain 4, part 2 Business resilience: BIA, RTO and RPO, backup and restoration, BCP, DRP
8 Domain 5, part 1 (26%) Asset security: frameworks, physical controls, IAM, network and endpoint, DLP, encryption, PKI, cloud, mobile and IoT
9 Domain 5, part 2 Security event management: awareness, attack methods, security testing, monitoring, incident response, forensics
10 Domains 4 and 5 second pass Targeted review of the 52 percent block, then your first full-length practice exam at the end of the week
11 Practice exams Two more full-length 150-question exams under the 4-hour clock, with a full review of every wrong answer
12 Final exam and review Last full-length exam, then review weak areas surfaced across all four exams

Three scheduling notes. First, the second pass in week 10 is not optional padding. Domains 4 and 5 are wide, and a week 6 memory of log management will have faded by exam day without a refresh. Second, take practice exams under real conditions: 150 questions, 4 hours, no pauses. Stamina is part of what the exam tests. Third, the review of wrong answers is where the score moves. An exam you take and never review is half wasted.

Practice the answer patterns from week 1, not week 10

Two habits should run through the entire plan, not just the practice-exam weeks, because they are habits, and habits need repetition.

The first is the qualifier pattern. CISA stems constantly ask for the MOST important, the BEST course of action, or the FIRST step. Several options will be true; only one is most, best, or first. Every time you answer a practice question, from week 1 onward, ask which qualifier the stem used and why the runner-up options fail it.

The second is the assurance-over-remediation habit. The auditor evaluates and assures; the auditor does not build or fix. When an answer option has you implementing the control, redesigning the process, or remediating the finding yourself, be suspicious. The credited answer usually has you assessing, verifying, reporting, or recommending. Security and ops people find this the hardest habit to build, which is exactly why it needs twelve weeks of small doses rather than a cram at the end. We work through both patterns on real question structures in our CISA practice questions walkthrough.

Ten to fifteen practice questions on the current week's domain, every week, is enough to build both habits. This is also the strongest argument for study material with explained answers: knowing that B was right is worth little if you never learn why A, C, and D were wrong. The ISACA CISA Study Guide is built around exactly this, with four full-length practice exams and an explanation for every wrong option, not just the credited one.

The 8-week variant for experienced auditors

If you have several years in IS audit, Domains 1 and 2 are your day job and you can compress them hard. Keep the full weight on Domains 4 and 5 and on practice.

Week Focus
1 Domains 1 and 2 at review pace: skim for terminology and the ITAF framing, question drills to confirm
2 Domain 3
3 Domain 4, part 1: IS operations
4 Domain 4, part 2: resilience, BIA, backup, BCP, DRP
5 Domain 5, part 1: asset security and control
6 Domain 5, part 2: security event management
7 Two full-length practice exams with full wrong-answer review
8 Two more full-length exams, final weak-area review

The trap for experienced auditors is overconfidence on Domains 1 and 2. You know the work, but the exam wants ISACA's vocabulary and ISACA's framing: the audit risk model, sampling terminology, the exact taxonomy of controls. Run enough questions in week 1 to prove you can score there, and if you cannot, borrow a week back from the schedule.

What if you miss a week?

Life happens across three months. If you fall behind, cut from Domain 3 review time and from the second-pass week before you cut a single practice exam. The full-length exams and the wrong-answer reviews are the highest-value hours in the whole plan. A candidate who read every chapter once and took four reviewed practice exams is in better shape than one who read everything twice and never sat a timed 150.

FAQ

How many hours does the CISA take in total?

Using the planning assumption above, roughly 95 to 120 hours: 8 to 10 hours a week for about 12 weeks. Candidates with deep audit or security experience can land under that; career changers may need more. There is no official figure, so build a schedule and adjust after your first practice exam.

Can I pass the CISA in 4 weeks?

It is a bad bet for most people. The exam is 150 questions across five domains, and the auditor's answer pattern takes repetition to internalize. If your timeline is short, the 8-week variant is the sensible floor, and only if audit is already your day job.

Do I need work experience before taking the exam?

You can sit the exam first. Certification requires five years of IS audit, control, assurance, or security experience, with waivers and substitutions up to a maximum of three years, but you can pass the exam and bank it while you finish the experience requirement.

What score do I need to pass?

450 on a scaled range of 200 to 800. The score is scaled across the whole exam, not per domain, which is another reason to weight your study time toward Domains 4 and 5: at 26 percent each, they carry the most questions.

Should I study the domains in order?

Order 1 through 5 works well because Domain 1 teaches the auditor's lens that every later domain is tested through. If you are from a security background, resist the urge to start with Domain 5. Learning the assurance framing first changes how you read everything after it.


Looking for a plain-English CISA guide? ISACA CISA: Certified Information Systems Auditor Study Guide covers all five domains with four full-length practice exams, every answer explained.

Simply Certified is an independent publisher. CISA and ISACA are trademarks of ISACA. Our books are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.