The CRISC requirements come down to one sentence with a sting in the tail: you need three or more years of professional experience in IT risk management and information systems control, earned within the ten years before you apply, and there are no experience waivers or substitutions of any kind. Not for a degree. Not for teaching. Not for a related certification. Three years of the actual work, verified, or no certificate.
That is what separates CRISC from the rest of ISACA's line, and it is the detail most candidates find out too late. CISA lets waivers and substitutions cover up to three of its five years. CRISC allows none. The good news sits in the order of operations: the exam and the certification are two separate gates, and the first is open to anybody. What follows is each requirement in sequence, including one point where ISACA's own pages currently say different things and you will need an answer straight from ISACA.
Who can register for the CRISC exam?
Anyone. There is no application to sit, no employer sign-off, no prerequisite credential, and no experience check at registration. You pay the exam fee, USD 575 as an ISACA member or USD 760 as a nonmember, and schedule your appointment.
Registration opens a six-month eligibility window. Sit inside that window or the registration is spent. ISACA does sell one extension of it for USD 75, with conditions worth reading before you plan around them: one extension per registration and no more, and if you already have a sitting on the calendar, that appointment has to be canceled at least 48 hours before the exam date for the extension to apply.
You also get four attempts in any rolling 12-month period, which caps how quickly you can grind at it if the first sitting goes badly. For the format and scoring, see what the CRISC exam is.
What counts as CRISC experience?
Three or more years of professional work in IT risk management and IS control. Two qualifiers sit around that number, and both catch people out.
The first is subject matter. ISACA is asking for IT risk management and information systems control work, not general IT, not general audit, not general project delivery. Time spent building and running systems is a different thing from time spent assessing, responding to, and reporting on risk in them.
The second is recency. Your experience has to be gained within the ten years preceding the application date. Anything older does not count toward the three years, so a career break or a risk role you left a decade ago can quietly put you back below the line. If your qualifying work is aging, that window is a reason to file sooner.
The four CRISC domains are Governance at 26%, Risk Assessment at 22%, Risk Response and Reporting at 32%, and Technology and Security at 20%, and the CRISC domains explained walks through what each one contains. How your three years have to be distributed across those four domains is the one requirement on this page that cannot be stated cleanly right now. The next section is why.
How should you document your experience across the domains?
Start with the work, not the rule. Whatever domain requirement applies to you, the application asks you to describe your experience domain by domain, and the candidates who struggle are the ones writing that description from memory in the week they apply.
Job titles are the wrong unit of measurement here, because "Risk Analyst" and "IT Compliance Specialist" describe wildly different work at different companies. Start from artifacts. List, year by year, what you actually produced: risk assessments you authored, scenarios you built, control tests you designed, findings you tracked to closure, KRIs you defined. Then tag each artifact with the domain it belongs to, and keep going across all four domains instead of stopping once two look populated. Titles are noise. Deliverables are evidence.
Most people find Domain 3, Risk Response and Reporting, is their strongest column by a distance, since it is where the visible output of risk work lives, and it is also the largest domain at 32% of the exam. Domain 4, Technology and Security, is usually the thinnest, largely because engineers who do that work rarely write it up as risk work. A complete four-domain map lets you answer whichever version of the requirement turns out to apply.
Then write to each domain plainly: name the domain, name what you did, name who could verify it. An application line that reads "designed and tested access controls for the ERP migration and reported residual risk to the steering committee" tells a reviewer more than three paragraphs copied out of a job description. If you cannot name a concrete deliverable for a year, that year is going to be hard to defend.
Where ISACA's own pages disagree
Here is the part you should not take on trust from this page or any other page. As of 2 September 2026, ISACA describes the domain requirement two different ways in two different places, and both are published by ISACA.
ISACA's Get CRISC Certified page says the experience must be earned across at least two of the four CRISC domains.
ISACA's support knowledge base article on the requirements to become CRISC certified, updated 5 March 2026, says that candidates who passed the exam after November 2025 must have experience in both Domain 2, Risk Assessment, and Domain 3, Risk Response and Reporting. That same article describes the two-of-four wording as the rule that applied from August 2021 to November 2025.
Those cannot both be the live rule for the same candidate, and the gap between them is not cosmetic. Someone whose three years sit in Domain 1 and Domain 3 satisfies one version and falls short of the other. We are not going to choose one for you and present it as settled, because we do not know which page the reviewer handling your application is working from.
So do this before you pay the USD 50 application processing fee. Contact ISACA certification support, quote both pages, give them your exam date, and ask which requirement applies to you. Get the answer in writing and keep it with your application file. That is a short email set against a fee that is not refunded and an application review you would rather go through once.
Why are there no CRISC waivers?
ISACA does not publish its reasoning, so treat what follows as an argument rather than a quotation. The rule itself is confirmed: no waivers, no substitutions, no partial offsets.
It fits the credential. CRISC is a practitioner certification about judgment under uncertainty, and there is no classroom version of having recommended a risk response that the business then had to live with. Whether or not you buy that, the effect is the same: three years is a floor and there is no ladder under it.
If you are early in your career and the no-waiver rule is a problem, change the order rather than the destination. The CISA requirements allow substitutions of up to three years, so the audit credential can be reachable first while your risk years accumulate. Weighing CRISC against the management credential instead? CRISC vs CISM sets the two side by side.
Can you take the CRISC exam without the experience?
Yes, and for a lot of people it is the right move.
Sitting the exam and holding the certification are separate events with separate gates. Nothing stops you from registering, passing, and banking a passing score while you are still short of three years. What you hold at that point is a pass, and you cannot put the letters after your name until your application is approved.
Passing early has real advantages. Study time is easier to find before a senior role eats your evenings, the material is fresh while you are doing the work it describes, and a passing score on a resume signals intent well before certification. A 12-week CRISC study plan is a realistic shape for that run.
The deadline you have to respect is five years. You must apply for CRISC certification within five years of passing the exam. Let that window close and the pass stops being usable, which means paying the full registration fee and sitting the exam again. Put the date in your calendar the week your results arrive, then work backward: if the three years will not be complete inside five, think harder about the exam-first sequence.
What does the certification itself cost?
Certification carries a one-time USD 50 application processing fee, paid on top of whatever you spent on the exam. It is separate from exam registration and separate from ISACA membership, and it pays for the review of your experience evidence. If the application comes up short, the fee does not come back.
Retakes cost the full registration fee each time, which is the strongest financial argument for an honest read on how hard the CRISC exam is before you book. The full bill is laid out in CRISC exam costs and fees.
What does it take to keep the CRISC?
Certification is a subscription to a standard of practice. Three obligations keep it live.
The first is continuing professional education: 20 CPE hours every year, and 120 hours across each three-year reporting cycle. Notice that those numbers do not multiply out. Twenty hours a year for three years is 60, half of what the cycle demands, so treat the annual figure as a floor and plan well above it. Chapter meetings, conference sessions, webinars, and structured training typically qualify.
The second is the annual maintenance fee, charged for every year you hold the credential: USD 45 for ISACA members and USD 85 for nonmembers, per ISACA's CRISC maintenance page. If CRISC is your third or later ISACA certification, it renews at a reduced rate. Fees move, so confirm the current amount before you budget.
The third is adherence to ISACA's Code of Professional Ethics and its CPE policy, which includes being willing to have your hours audited.
Miss the CPE hours or the fee and the certification stops being maintained, which eventually means losing it and sitting the exam again. That is a bad trade for roughly seven hours a quarter. Log CPE as you earn it, because reconstructing a year in December is where people quietly give up on a credential they already paid for.
Does the CRISC accreditation matter?
For some employers, yes, and it is worth knowing you have it. CRISC is accredited under ISO/IEC 17024:2012 and is ANSI accredited under Personnel Certification #0694.
This matters most in government contracting, defense-adjacent work, and any procurement process where a role description names an accredited certification rather than a specific brand. Accreditation says an independent body has assessed how the certification is designed and administered, which is the box a compliance-driven hiring process wants ticked. It rarely comes up in commercial hiring. If you are aiming at a role that lists accredited credentials, though, this is the sentence to have ready.
Putting the CRISC requirements in order
If you already have three qualifying years inside the last ten, the sequence is short: get ISACA's answer on the domain question in writing, study, pass, apply straight away, then start logging CPE. If you are short of the experience, invert it. Sit the exam while the study time exists, mark your five-year application deadline, and let the qualifying years accrue against a pass you already hold.
Either way, the exam is the piece you control. That is where preparation actually pays, and it is what our CRISC study guide is built for: all four domains taught at their real weights, in plain English, with explained practice.
Most of these requirements are strict and simple. Three years of real risk and control work inside the last ten, verified, applied for within five years of your pass, with no substitutes for the years themselves. One of them, the domain spread, needs an email to ISACA before you file.
FAQ
Can I take the CRISC exam without any experience?
Yes. Exam registration has no experience prerequisite, so anyone can register, sit, and pass. Certification is the separate gate, and that is where the three-year experience requirement applies. You then have five years from passing the exam to apply for certification, so note that deadline the week your results arrive.
Are there any CRISC experience waivers or substitutions?
No. Unlike CISA, which allows substitutions covering up to three of its five years, CRISC allows no waivers or substitutions at all. A degree, a teaching post, or another certification does not offset any part of the three-year requirement.
How many CRISC domains does my experience have to cover?
Confirm this one with ISACA before you apply, because ISACA's own pages currently describe it two ways. The Get CRISC Certified page says experience across at least two of the four domains. The support knowledge base article on CRISC requirements, updated 5 March 2026, says candidates who passed after November 2025 need experience in both Domain 2, Risk Assessment, and Domain 3, Risk Response and Reporting, and calls the two-of-four wording the August 2021 to November 2025 rule. Map your work against all four domains, then ask ISACA certification support which version applies to your exam date and keep the reply.
How recent does my CRISC experience have to be?
It has to fall within the ten years preceding your application date. Qualifying work older than that window does not count toward the three years, which matters most after a career break or a move into an unrelated function.
How many CPE hours does CRISC require?
20 hours a year and 120 hours across each three-year cycle, alongside adherence to ISACA's Code of Professional Ethics and its CPE policy. The annual minimum on its own does not reach the cycle total, so plan for at least one heavier year in every three.
Looking for a plain-English CRISC guide? ISACA CRISC: Simply Certified Study Guide covers all four domains at their 26/22/32/20 weights, with four full-length practice exams, every answer explained.
Simply Certified is an independent publisher. CRISC and ISACA are trademarks of ISACA. Our books are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.