The CISA, short for Certified Information Systems Auditor, is ISACA's certification for people who audit, control, and assure information systems. The exam behind it is 150 multiple-choice questions in 4 hours, covering five domains, scored on a scale of 200 to 800 with 450 required to pass. It costs USD 575 for ISACA members and USD 760 for nonmembers, and you can sit it at a PSI test center or online with a remote proctor.
That is the short answer. The longer answer, and the part most first-time candidates miss, is that the CISA is not a technical exam wearing an audit badge. It tests whether you can think like an auditor: someone whose job is to assess and assure controls, not to build or fix them. The rest of this post walks through who holds the credential, what the five domains cover, how the exam is scored and delivered, what it costs, and the experience requirement that turns a passed exam into an actual certification.
What is the CISA certification, and who holds it?
CISA is the flagship IT audit credential, and it is the one the audit profession asks for by name. More than 207,000 people have earned it since its launch in 1978, and ISACA counts over 151,000 current holders, which makes it ISACA's highest-volume certification, well ahead of siblings like CISM. Typical holders are internal and external IT auditors, IT audit managers, security and risk professionals moving into audit, and consultants who assess client environments for a living.
If you are weighing CISA against ISACA's management-track credential, the split is straightforward: CISA is for people who evaluate controls, CISM is for people who run security programs. We compare the two properly in CISA vs CISM.
The exam is written to the CISA Exam Content Outline effective August 2024. That outline is current and stable, with no announced change on the horizon, so a candidate preparing in 2026 is studying the same five domains as everyone who has sat the exam since mid-2024.
What are the five CISA domains?
Every question on the exam maps to one of five domains, and the weights are published, so you know exactly where the marks are before you open a book.
| Domain | Weight |
|---|---|
| 1. Information Systems Auditing Process | 18% |
| 2. Governance and Management of IT | 18% |
| 3. Information Systems Acquisition, Development, and Implementation | 12% |
| 4. Information Systems Operations and Business Resilience | 26% |
| 5. Protection of Information Assets | 26% |
A few things jump out of that table. Domains 4 and 5 together are 52% of the exam, so over half your marks sit in operations, resilience, and security content. Domain 3 is the smallest weight at 12%, and it is the worst place to spend your first study week.
In plain terms: Domain 1 is how to plan and execute an audit, from risk-based planning through evidence, sampling, and reporting. Domain 2 is IT governance and management, covering policies, enterprise architecture, risk management, and vendor oversight. Domain 3 follows systems from business case through development, testing, and post-implementation review. Domain 4 covers IT operations plus business continuity and disaster recovery. Domain 5 is information security: identity and access management, network and endpoint security, encryption, PKI, cloud, and mobile.
That is the one-paragraph version. Each domain has its own sub-areas and its own traps, and we break all five down in CISA domains explained.
What is the CISA exam format?
The exam is 150 multiple-choice questions with a 4-hour time limit, which works out to about 96 seconds per question. Every question has four options and one correct answer. There are no simulations, no essays, and no lab component. It is multiple choice from the first question to the last.
Scoring is scaled. Your raw performance is converted to a score between 200 and 800, and you need 450 to pass. The scaled score means you cannot translate the pass mark into a simple percentage of questions answered correctly, and ISACA does not publish a conversion table. ISACA also does not publish pass rates for the CISA, so treat any specific pass-rate figure you see online as a guess.
Delivery is through PSI, not Pearson VUE, which surprises candidates coming from other certification families. You can test in person at a PSI test center or online from home with a remote proctor. The online option has the usual remote-proctoring requirements: a webcam, a stable connection, and a room you can clear of notes and second screens.
Is 150 questions in 4 hours hard? Time is rarely the problem; the questions are. Many stems ask for the MOST likely, BEST, or FIRST answer, meaning two or three options are defensible and you are choosing between degrees of right. We give an honest assessment of the difficulty in how hard is the CISA exam, and walk through real question mechanics in our CISA practice questions walkthrough.
How much does the CISA exam cost?
The exam fee is USD 575 for ISACA members and USD 760 for nonmembers. That is the exam registration only. Study materials, ISACA membership itself if you choose it, and any retake are on top.
The member discount of USD 185 is worth doing the arithmetic on before you register, since an ISACA membership can pay for a real portion of itself through the reduced exam fee alone. Whether it nets out in your favor depends on your local chapter dues, so check the current membership pricing against the USD 185 saving rather than assuming.
Budget beyond the fee is mostly a time question, not a money question. A structured 12-week plan is enough runway for most working candidates, and we lay out exactly what those weeks look like, domain by domain, in the 12-week CISA study plan.
What is the CISA experience requirement?
Passing the exam does not make you a CISA. Certification requires 5 years of professional experience in information systems audit, control, assurance, or security. This is the part of the process people discover late, sometimes after they have already passed.
There is flexibility built in. Waivers and substitutions, for things like relevant university education, can reduce the requirement by up to a maximum of 3 years. However the waivers stack, at least 2 years must come from actual work experience.
The practical upshot: you can sit the exam before you have the full 5 years. Many candidates pass early in their audit careers and complete the experience requirement afterward. The exam result and the certification application are separate steps, and the details of what counts, what can be waived, and how to sequence it deserve their own post: see CISA requirements and experience.
What does the CISA exam actually test?
Here is the thesis that should shape your entire preparation: the CISA rewards the auditor's judgment, not the engineer's fix.
Domains 4 and 5 look technical on paper. Patch management, backups, encryption, IAM, network security. An engineer reads that list and starts thinking about how to configure things. The exam does not ask you to configure anything. It asks whether the control exists, whether it is designed properly, whether it operates as intended, and what the auditor should do about it when it does not. Assess and assure, not build and repair.
This is why technically strong candidates get burned. Faced with a scenario where a control has failed, the engineer's instinct is to pick the answer that fixes the problem. The exam's answer is usually the one that evaluates, evidences, or reports the problem, because fixing it is management's job, and an auditor who fixes what they audit has just destroyed their own independence. Once you see that pattern, whole families of questions open up.
It also means your study material should teach from the auditor's seat, not the administrator's. A reference written for practitioners will teach you how backups work; you need to know how to audit a backup regime. The ISACA CISA: Certified Information Systems Auditor Study Guide is written from that lens throughout: seven chapters mapped to the five domains, with four full-length practice exams, 600 questions in total, and a written explanation for every answer, including why the wrong options are wrong.
Is the CISA worth it in 2026?
If your work touches IT audit, assurance, or controls testing, the CISA is the credential the job listings name, and its 151,000-plus current holders make it the recognized common language of the field. The outline effective August 2024 is current with no imminent revision, so material and effort invested now are not about to be obsoleted by a version change.
The honest caveat is the experience requirement. If you are 5 or more years away from qualifying even with waivers, the certification itself is a long play, though the exam pass can still be banked earlier. And if your ambitions are on the security management side rather than assurance, read the CISA vs CISM comparison before you commit the fee.
FAQ
How many questions is the CISA exam?
150 multiple-choice questions in a single 4-hour session. There are no simulations or written components. That averages out to roughly 96 seconds per question.
What score do you need to pass the CISA?
450 on a scaled range of 200 to 800. Because the score is scaled, there is no official percentage equivalent, and ISACA does not publish pass rates.
Can I take the CISA exam online?
Yes. Delivery is through PSI, either at a test center or online with remote proctoring. Both formats use the same 150-question, 4-hour exam.
Can I take the exam before I have 5 years of experience?
Yes. The exam and the certification are separate steps. You can pass first and complete the experience requirement afterward, and waivers can reduce the 5 years by up to 3.
Which CISA domain should I study most?
Domains 4 and 5 carry 26% each, 52% combined, so operations, resilience, and protection of information assets deserve the largest share of your time. Domain 3, at 12%, is the smallest.
Looking for a plain-English CISA guide? ISACA CISA: Certified Information Systems Auditor Study Guide covers all five domains with four full-length practice exams, every answer explained.
Simply Certified is an independent publisher. CISA and ISACA are trademarks of ISACA. Our books are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.