What is the CRISC certification? It is ISACA's credential for the person who identifies, assesses, responds to, and reports on enterprise IT risk. CRISC stands for Certified in Risk and Information Systems Control. The exam is 150 multiple-choice questions in 4 hours across four domains, scored on a scale of 200 to 800 with 450 required to pass. It costs USD 575 for ISACA members and USD 760 for nonmembers, and you sit it either at a PSI test center or at home with a remote proctor.
That is the short answer. The part candidates underestimate sits outside the exam room. Certification requires three or more years of IT risk management and IS control experience, gained within the ten years before you apply, and CRISC allows no experience waivers and no substitutions of any kind. You can sit the exam whenever you want. The experience is not negotiable, and that single rule shapes who should be pursuing this credential and when.
What is the CRISC certification for?
CRISC is aimed at people who already work with IT risk as a named part of the job. IT risk analysts, risk and control analysts, GRC and compliance staff, second-line risk functions, and the security, audit, or business people moving into a risk seat.
The shape of the role is visible in the domain weights. A CRISC holder is expected to build risk scenarios, rate them, argue for a response against a stated risk appetite, own or assign the controls that deliver that response, and then report the result upward in a form a board can act on. Those are practitioner verbs with a governance frame around them. What is missing is telling: the exam does not ask you to configure anything, and it rarely asks you to remember a definition for its own sake.
What are the four CRISC domains?
Every question maps to one of four domains. Under the CRISC Exam Content Outline effective 2025, the published weights are:
| Domain | Weight |
|---|---|
| 1. Governance | 26% |
| 2. Risk Assessment | 22% |
| 3. Risk Response and Reporting | 32% |
| 4. Technology and Security | 20% |
In plain terms, Domain 1 sets the frame the other three work inside: strategy, roles, culture, policy, resilience, and the risk appetite and tolerance thresholds every later decision is measured against. Domain 2 is finding risk and sizing it. Domain 3 is deciding what to do about it and reporting the result upward. Domain 4 is the technology and security literacy the other three assume you already have.
Domain 3 is a third of the paper on its own, roughly 48 of the 150 questions. Domain 1 is second at 26%. Those two carry 58% between them, which tells you where to spend your first study weeks. We take each domain apart section by section in CRISC domains explained.
Which CRISC outline is current?
The CRISC Exam Content Outline effective 2025 has been live since November 3, 2025, and it is the outline your exam is written against today. There is no pending change hanging over the credential, which is a genuine advantage over booking around a cutover date.
The move from the prior outline was small. Domain 2 rose from 20% to 22% and Domain 4 fell from 22% to 20%. Domains 1 and 3 did not move, and nothing about the format or the pass mark changed. Two domains were renamed: Domain 2 became Risk Assessment, previously IT Risk Assessment, and Domain 4 became Technology and Security, previously Information Technology and Security. If you have older study material in hand, it is mistuned by two percentage points in two places rather than wrong, but check the domain names before you trust it.
What is the CRISC exam format and how is it scored?
The exam is 150 multiple-choice questions with a 4-hour limit, which is about 96 seconds per question. Every item has one stem and four options, and you pick the single best answer. Some items are scenario-based, where a situation is followed by more than one question. There are no labs, no simulations, and nothing to write.
Unscored pretest items are mixed in with the scored ones and you cannot tell them apart. Nothing is deducted for a wrong answer, so a blank is strictly worse than a guess.
Scoring is scaled. Your raw performance is converted to a number between 200 and 800, and 450 is the minimum passing score. Because the scale is applied to a mix of items of varying difficulty, there is no published percentage of questions you need to get right and no conversion table. Your domain-level results come back as information only and play no part in the pass or fail decision.
ISACA does not publish CRISC pass rates. Any percentage you find quoted online was estimated by someone with no access to the data, so judge your readiness against the published parts of the exam instead. Our honest read on the difficulty is in how hard is the CRISC exam.
What does it cost, and how do you book it?
The exam fee is USD 575 for ISACA members and USD 760 for nonmembers. Certification after you pass costs a further USD 50 as a one-time application processing fee.
Registration opens a six-month eligibility window, and you have to schedule and sit inside it. If you are the kind of person who books first and plans later, treat that window as the real deadline. You are also limited to four attempts in any rolling 12-month period, which is generous in principle and expensive in practice at these fees.
Delivery is through PSI, either at a test center or online with a remote proctor, and the exam is offered in English, Spanish, and Japanese. The membership arithmetic, the annual maintenance fee, what a retake actually costs, and what the remote proctoring setup demands of your room are all worked through in CRISC exam cost and fees.
The experience rule with no way around it
This is the sharpest difference between CRISC and the rest of ISACA's line, and it deserves reading slowly.
To be certified you need three or more years of IT risk management and IS control experience, gained within the ten years before your application date. There are no experience waivers and no substitutions. A degree does not count. A related certification does not count. Teaching the subject does not count. Compare that with CISA, where the five-year requirement can be reduced by waivers of up to three years. CRISC asks for less time but takes the time literally, which is the point: ISACA is protecting the meaning of a risk credential by insisting its holders have actually done risk work.
Passing the exam and applying for certification are still separate steps, so sitting the exam while the experience accrues is a normal and sensible path. Just be clear with yourself about which one you are doing. CRISC requirements and experience covers what qualifies, how to evidence it, and when to apply.
Is CRISC accredited, and how do you keep it?
CRISC is accredited under ISO/IEC 17024:2012 and is an ANSI Accredited Program, Personnel Certification #0694. That matters mainly for government contracts and procurement rules that name an accredited certification rather than vendor training, and it is not something every risk credential on the market can claim.
Keeping the credential means continuing professional education, a minimum of 20 CPE hours each year and 120 hours across each three-year cycle, plus adherence to ISACA's Code of Professional Ethics and an annual maintenance fee. The upkeep obligations are set out in full in CRISC requirements and experience.
What does the CRISC exam actually test?
Here is the thesis that should shape your preparation: CRISC rewards the risk practitioner's sequence over the fixer's instinct.
The domains are full of technical and procedural vocabulary, and the questions lean on qualifiers. Which action is MOST appropriate, what should be done FIRST, which is the BEST response, what is the PRIMARY concern. On a well-written CRISC item there are frequently no wrong options at all. All four are things a competent professional might do, and your task is to rank them the way ISACA ranks them.
What decides the ranking is where the stem has actually got to. You do not select a treatment for exposure nobody has sized, you do not report a number nobody has validated, and whether a risk needs a response at all is settled by the appetite the board approved rather than by how alarming it sounds. Once you can see that, families of questions that looked ambiguous resolve themselves.
That is why explained practice matters more here than on a recall-heavy exam. The ISACA CRISC: Simply Certified Study Guide is built around that decision lens, with all four domains taught at their real weights and four full-length practice exams where every option is explained. To see the ranking argued out item by item, read CRISC practice questions, and for a paced schedule there is the 12-week CRISC study plan.
Should you sit CRISC, or a different ISACA credential?
An opinion, since you read this far.
Sit CRISC if risk is already your job title or your daily reality: you maintain a risk register, you argue about appetite thresholds, you chase action plans to closure, or you sit in a second-line function watching the first line manage its own risk. For that person CRISC is the closest fit ISACA sells, and the three-year experience rule will not be a problem because you already meet it.
Look elsewhere in our catalog in three cases. If you are early in your career or your work is assessment and assurance, CISA is the better first ISACA credential, and not only because the content fits. Its waivers can take up to three years off the experience requirement, where CRISC takes off none, so it is the one you can realistically finish sooner. If you own a security program, with a budget, a team, and an incident response plan, CISM is aimed squarely at that seat and CRISC will feel like a sideways move. And if your risk work is really privacy work, CDPSE is the closer match.
The honest failure mode for CRISC is the candidate who wants a risk credential in order to get into risk work. The exam is passable that way. The certification is not, for three years at least. CRISC vs CISM sets out the choice between the two most commonly confused options in the family.
FAQ
How many questions is the CRISC exam?
150 multiple-choice questions in a single 4-hour session, which works out to roughly 96 seconds per question. There are no simulations or written components. Unscored pretest items are mixed in with the scored ones, so answer everything.
What score do you need to pass the CRISC?
450 on a scaled range of 200 to 800. Because the score is scaled, there is no official percentage equivalent, and ISACA does not publish CRISC pass rates. Domain-level results are reported for information only and have no bearing on whether you pass.
Can I take the CRISC exam without three years of experience?
Yes. The exam and the certification application are separate steps, so you can sit and pass while the experience accrues. What you cannot do is shorten the requirement, because CRISC allows no experience waivers and no substitutions. Until you meet it and apply, you have a passing score rather than a certification.
How much does the CRISC cost in total?
The exam is USD 575 for ISACA members and USD 760 for nonmembers, plus a one-time USD 50 application processing fee once you apply for certification. After that, expect an annual maintenance fee alongside the CPE requirement. Confirm the current amounts on ISACA's own pages before you budget.
Is the CRISC exam changing soon?
Not as far as ISACA has announced. The current CRISC Exam Content Outline took effect in 2025 and has been live since November 3, 2025, so material written to the 26/22/32/20 weights is current. The change that produced this outline moved Domain 2 from 20% to 22% and Domain 4 from 22% to 20%.
Looking for a plain-English CRISC guide? ISACA CRISC: Simply Certified Study Guide covers all four domains at their 26/22/32/20 weights, with four full-length practice exams, every answer explained.
Simply Certified is an independent publisher. CRISC and ISACA are trademarks of ISACA. Our books are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.