Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

CISA Master Guide 2026

Updated 13 min read
Key takeaway

The 2026 CISA exam has 150 multiple-choice questions, four hours, and five domains in the outline effective August 2024.

  • A scaled score of 450 on ISACA's 200-to-800 scale passes.
  • You may sit before meeting certification experience requirements, but the credential requires an approved application, qualifying experience, ethics and standards commitments, and continuing education.
On this page12 sections
  1. What the CISA certification covers
  2. The five domains and their weights
  3. How to think like an information systems auditor
  4. How the exam works
  5. Scoring and results
  6. Eligibility to sit versus certification eligibility
  7. Registration, appointment, and cost
  8. A useful way to prepare
  9. How to maintain the certification
  10. What the credential does and does not establish
  11. If you do not pass on the first attempt
  12. Original worked decision example

What the CISA certification covers

CISA stands for Certified Information Systems Auditor. ISACA awards it to professionals who pass the exam and meet its experience, application, ethics, continuing education, and auditing standards requirements. The exam and the certification are related but separate: anyone may register for the exam, while the credential requires verified professional experience.

CISA focuses on auditing, control, assurance, and security work around information systems. A candidate should understand how to plan an audit, assess IT governance, review acquisition and implementation, evaluate operations and resilience, and assess protection of information assets. The credential does not grant a government license to audit or practice in a particular country. Employers, regulators, and clients may set separate requirements.

Exam detailCurrent published information
Questions150 multiple-choice questions
TimeFour hours, or 240 minutes
Passing result450 or higher on a 200-to-800 scaled score
Current outlineFive domains, effective August 2024
RegistrationContinuous registration; six-month eligibility after registration
DeliveryComputer-based at authorized PSI centers or remotely proctored, where available
Certification experienceFive years of relevant IS audit, control, assurance, or security experience, with eligible substitutions up to three years

The five domains and their weights

ISACA's current CISA outline took effect on August 1, 2024. The 2026 Candidate Guide continues to show that outline. It adds contemporary subjects such as data governance, privacy, cloud and emerging technology considerations within the domains. The published weights help you allocate study time, but they do not promise an exact number of questions from each domain.

DomainWeightWhat you need to reason about
1. Information System Auditing Process18%Risk-based planning, audit execution, sampling, evidence, analytics, reporting, communication, and audit quality.
2. Governance and Management of IT18%Governance structure and strategy, policy, laws and standards, enterprise risk, privacy, data governance, resources, vendors, and IT performance.
3. Information Systems Acquisition, Development, and Implementation12%Project oversight, business cases, development approaches, control design, readiness testing, release and data conversion, and post-implementation review.
4. Information Systems Operations and Business Resilience26%Operations, asset and change management, incidents, logs, availability, business impact, backup, continuity, and disaster recovery.
5. Protection of Information Assets26%Security policies and controls, identity, access, data protection, physical security, monitoring, vulnerability management, and response.

The two largest domains together account for just over half of the stated outline weight. That is a sound reason to give Operations and Protection sustained attention, not a reason to skip Domain 3 or Domain 1. The exam can ask a lifecycle question in which a change-management decision affects asset protection, evidence, or resilience.

How the domains connect in practice

Domain 1 asks whether the audit itself is well designed and supported. The auditor defines a risk-based objective, obtains suitable evidence, tests a population or sample, investigates exceptions, and communicates a conclusion. Domain 2 establishes the governance environment behind that work: who owns IT decisions, how strategy and risk are governed, and whether vendor, privacy, and data practices align with organizational needs.

Domain 3 follows an information system through acquisition and implementation. A good business case does not prove that the control design is adequate, and a successful technical test does not prove that converted data are complete. The auditor considers project oversight, readiness criteria, release controls, migration, and post-implementation review. Domain 4 asks whether the live service remains reliable and recoverable, including incident, capacity, change, backup, and continuity practices.

Domain 5 examines protection of information assets. That includes more than a firewall or encryption setting. Classification, identity, authorization, physical safeguards, monitoring, vulnerability handling, and incident response all contribute to whether information is protected. A scenario can ask you to evaluate the connection between a business requirement and a control, rather than recall a product feature.

For example, a business owner proposes a cloud service for customer data. Governance establishes the owner, risk tolerance, classification, vendor responsibility, and requirements. Acquisition work documents the business case and control design. Implementation testing validates migration and access. Operations monitors change and resilience. Asset protection controls who can use the information and how incidents are handled. An auditor can examine each stage, but first defines the engagement objective and criteria.

How to think like an information systems auditor

CISA questions often ask what the auditor should do first, what evidence is strongest, or which conclusion is best supported. The disciplined response begins with the audit objective and criteria. Identify the risk, the control or process in scope, the population, and the period. Then decide what evidence would answer the question and what test can produce it.

For example, an organization says terminated workers lose access quickly. A report from Human Resources proves that people were marked as terminated in that system. It does not prove that each account in the finance application was disabled. An auditor could reconcile a defined termination population to identity and application logs, investigate mismatches, and report against the policy's timing requirement. The conclusion should stay within the systems and period tested.

A common trap is to recommend a new technology before establishing the control gap. If an audit finds late access removals, first determine whether the cause is delayed HR notification, an interface failure, an unclear responsibility, or an exception process. A recommendation should address the supported cause and fit the business environment. The auditor evaluates and advises; management owns the process and accepts business risk.

For a government audit, the GAO Yellow Book may be a governing standard, and the 2026 GAO Federal Information System Controls Audit Manual supports assessment of federal information-system controls in its stated context. Those publications are valuable references for government work. They do not govern every private audit or every CISA engagement. Use the standards, scope, and criteria that actually apply to the engagement.

How the exam works

The CISA exam is a computer-based, fixed-length multiple-choice exam with 150 questions and four hours of test time. ISACA describes standard multiple-choice and scenario-based questions. A scenario may provide a short business or audit situation followed by one or more questions. The question asks you to choose the best response from the options, so identify the requested action and qualifier before selecting an answer.

The current candidate guide says candidates can take approved breaks with the proctor's permission. Two breaks of up to ten minutes each are allowed; the exam timer continues. Remotely proctored exams are closed book, and the same guide also sets strict room and device rules. The center and remote experience differ in check-in details, so read the instructions for the delivery choice you book.

ISACA's exam uses scored and pretest items. Pretest items do not count toward the score, but candidates are not told which items are pretest. Answer every question. The candidate guide says there is no penalty for an incorrect answer, so leaving an item blank cannot improve your result.

Scoring and results

ISACA reports CISA scores on a scaled range from 200 to 800. A score of 450 or higher passes; 800 is the published perfect score. The scale supports comparable reporting across different exam forms. It is not a percentage, and a 450 result does not mean that a candidate answered 56.25 percent correctly. ISACA does not publish a simple raw-score conversion for candidates.

The guide says preliminary pass status appears on screen immediately after the exam. The official score is emailed and posted in MyISACA within ten working days. Domain feedback is provided for information, but domain percentages do not determine the total score. If you do not pass, you may request a rescore through ISACA support within 30 days of score release; the current guide lists a US$75 fee.

Eligibility to sit versus certification eligibility

You do not need years of experience or a particular degree to register for the CISA exam. ISACA states that the exam is open to anyone interested in information security. The experience requirement applies when you apply for certification after passing.

To earn CISA, an applicant generally needs five years of professional IS information systems auditing, control, assurance, or security work experience described by the CISA job practice areas. The qualifying experience must fall within the ten-year period before the certification application. Candidates have five years after passing to apply. ISACA permits qualifying substitutions and waivers up to three years; the specific route and evidence must meet its application criteria.

The application requires a supervisor or manager to verify experience. The application processing fee is currently US$50. Applicants must agree to the ISACA Code of Professional Ethics, the CPE policy, and Information Systems Auditing Standards. Passing alone does not confer CISA status. ISACA also offers a CISA Associate designation for eligible exam passers who have not completed experience requirements; its separate eligibility and fee details should be read on that program's page.

Registration, appointment, and cost

Registration is continuous. After paying the exam fee, a candidate has a six-month eligibility window to sit. The 2026 ISACA Candidate Guide lists an exam fee of US$575 for a member and US$760 for a nonmember. It states that registration fees are nonrefundable and nontransferable. A candidate can schedule as early as 48 hours after payment, subject to available appointment inventory.

Appointments are offered at authorized PSI testing centers globally or by remote proctoring, where an eligible appointment and compatible device are available. Check the actual scheduling options before purchasing if a particular location or remote format is essential. A single six-month extension is available for US$75 under the guide's conditions. The same guide warns that a missed appointment, arriving more than 15 minutes late, or failing to test in the eligibility period can forfeit the registration fee.

An ISACA membership can change the exam registration price, but compare the full membership cost and benefits with the exam savings before joining just to register. Your total may also include preparation resources, travel, and the separate certification application fee. The exam fee and application fee are distinct charges.

The 2026 Candidate Guide lists English, Spanish, Simplified Chinese, French, German, Korean, and Japanese for CISA. A listed language does not guarantee a seat at each location or in each delivery mode. Check the actual scheduling choices before paying if you need a specific language, test center, or remote appointment.

A useful way to prepare

Start with the current outline and a diagnostic set. Mark each objective as familiar, partial, or new, then choose one main instructional resource aligned to the current version. Add question practice that provides explanations. Avoid studying from old materials without checking them against the active outline, especially because the current job practice version became effective in 2024.

Use questions to practice audit judgment, not to memorize phrases. For each answer, ask: What is the objective? What evidence supports the conclusion? Does the auditor need to validate scope or data completeness? Is the question asking for a first step, a best control, or a conclusion? Keep an error log that records why you missed an item. A label such as 'Domain 4' is less helpful than 'treated restoration of one database as full business recovery.'

Budget practice time against the four-hour duration. The simple average is 96 seconds per question. Some scenario questions need more reading, so answer more direct questions efficiently and avoid spending several minutes trying to prove every distractor false. ISACA's guide encourages candidates to answer all items and manage time so the entire exam is completed.

How to maintain the certification

Under the policy in effect during 2026, CISA holders must report at least 20 CPE hours each year and 120 over a three-year reporting period. The hours should relate to maintaining knowledge and ability to perform CISA-related tasks. ISACA also requires an annual maintenance payment; its current policy page lists the fee and payment deadline. Keep evidence and report activities in MyISACA.

A separate change begins on January 1, 2027. The total remains 120 CPE hours over three years, and the annual minimum remains 20. Under the announced policy, at least 90 hours across the cycle must align with the certification's exam outline or domains, while up to 30 may support broader professional development such as leadership, mentoring, or non-domain volunteer work. ISACA says there will be no system change in the 2026 cycle. This is a maintenance-policy change, not a change to the CISA exam outline.

Track the cycle dates in the member portal and keep receipts, agendas, course records, and other evidence. ISACA may audit CPE claims. Failure to comply can lead to revocation, so treat continuing education and annual maintenance as part of holding the credential.

What the credential does and does not establish

CISA is a global professional certification, not a jurisdiction-specific government license. It signals that a holder has passed ISACA's exam and met certification requirements. It does not automatically authorize regulated audit work, guarantee employment, or replace an employer's professional standards. Public-sector auditors may also need to follow rules such as the Yellow Book when that framework applies to their engagements.

The credential is most useful when its focus fits the work: audit planning and execution, IT governance, system acquisition and implementation, operations and resilience, or information asset protection. Candidates should compare those job-practice areas with the responsibilities they want to take on, then plan for both the exam and the verified-experience step.

If you do not pass on the first attempt

The 2026 candidate guide allows four attempts in a rolling 12-month period. After a first unsuccessful attempt, wait 30 days before a second attempt. A third attempt requires a 90-day wait after the second, and a fourth requires 90 days after the third. Pay the full registration fee for each attempt. A passing candidate cannot retake the same exam during the five-year application period, and a current CISA holder cannot retake while certified.

Use domain feedback as a starting point, not a precise diagnosis. ISACA says domain-level results are informational and the total score is based on the total number of scored items answered correctly. Rebuild your study plan around specific missed concepts and reasoning. If you request a rescore, the current guide requires a written request within 30 days after results and lists a US$75 fee.

Original worked decision example

A company is migrating a finance application. The project sponsor says testing is complete, but the auditor finds no evidence that migrated balances were reconciled. The live system is scheduled to go online tomorrow. The best immediate audit action is to establish the migration acceptance criteria and obtain evidence of reconciliation or other approved validation before concluding readiness. A sponsor's statement is not sufficient evidence, and a penetration test does not address whether financial data converted accurately.

If the evidence shows that reconciliation was not performed, the auditor should communicate the control gap and its potential effect to the appropriate project and business owners. The auditor does not independently authorize launch. Management decides whether to delay, accept a documented risk, or apply another control. The audit conclusion should distinguish verified facts from the risk of proceeding without the required validation.

That example crosses project governance, implementation testing, operations, and audit evidence. CISA preparation is strongest when you can explain those connections and keep the auditor's role distinct from management's decision.

Common questions

How many questions and how much time are on the CISA exam?

The current CISA exam has 150 multiple-choice questions and a four-hour, or 240-minute, time limit. ISACA's 2026 Candidate Guide describes it as computer-based at authorized PSI centers or remotely proctored where available.

What is the CISA passing score?

A score of 450 or higher passes on ISACA's 200-to-800 scaled score. It is not a raw percentage. The official guide says 800 represents a perfect score and domain-level results are informational.

Can I take the CISA exam without five years of experience?

Yes. ISACA allows candidates to sit before they meet the certification experience requirement. To earn CISA, you must later meet the professional experience and application requirements or qualify under approved substitutions and waivers.

What changed for CISA in 2027?

ISACA announced a CPE policy effective January 1, 2027. The 120-hour three-year total and 20-hour annual minimum stay, while at least 90 hours must align with the credential and up to 30 can support broader professional development. This is separate from the exam outline.

Is CISA a government audit license?

No. CISA is an international professional certification issued by ISACA. It does not replace any jurisdiction-specific license, public-sector standard, or employer requirement that may apply to an audit engagement.