CISA Passing Score: What 450 out of 800 Means
A CISA score of 450 or higher on ISACA's 200-to-800 scaled scale is a pass.
- It is not 450 correct answers, 56.25 percent, or a raw percentage.
- ISACA converts performance to a scaled score so results across different exam forms can be compared; domain feedback helps guide study but is not a separate pass requirement.
On this page14 sections
- The CISA passing standard is 450 on a scaled score
- Why a scale is used
- Do not turn 450 out of 800 into a percentage
- Domain feedback is diagnostic, not a second pass gate
- How pretest questions fit into scoring
- A practical example of interpreting a report
- How to use practice scores responsibly
- Results and score review
- What passing the exam does and does not establish
- Use a sample question to understand what practice scores show
- How to respond to a failing result
- Do not overread domain labels
- What the score cannot tell you
- The useful takeaway
The CISA passing standard is 450 on a scaled score
ISACA reports CISA exam results on a scale from 200 to 800. A score of 450 or higher passes. The number is a scaled score, not a count of correct answers and not a percentage. A reported 450 does not mean that a candidate answered 450 of the 150 questions correctly, nor does it mean 56.25 percent correct because 450 divided by 800 is not the exam's raw-score conversion.
| Reported result | Interpretation |
|---|---|
| 200 | The lowest possible scaled score; it indicates that only a small number of questions were answered correctly. |
| 449 or below | Below the passing standard. |
| 450 | The minimum passing scaled score. |
| 451 to 799 | Above the passing standard. |
| 800 | The highest possible scaled score, representing a perfect score under ISACA's description. |
ISACA uses scaled scores so results can be compared across exam forms. The public candidate guide explains the scale endpoints and passing standard, but does not publish a raw-answer cutoff or conversion table. It is therefore not possible to infer the exact number of correct items needed from a candidate's scaled score, and an unofficial raw-percent estimate should not be presented as an ISACA rule.
Why a scale is used
Not every candidate necessarily receives the same exact set of questions. ISACA's scoring scale provides a common reporting frame rather than treating each form's raw number correct as directly interchangeable. A scaled score accounts for differences among forms so that the passing standard has a consistent interpretation. The practical conclusion is straightforward: prepare to meet the standard, but do not try to reverse-engineer an unpublished conversion.
This also explains why practice test percentages do not map directly to official scores. If a candidate earns 72 percent on a self-made quiz, the result is evidence about that quiz and those topics. It is not an official prediction of a CISA scaled score. Question difficulty, exam blueprint representation, and the scoring process differ. Use practice results to locate knowledge gaps and improve judgment, not to claim a guaranteed 450 equivalent.
Do not turn 450 out of 800 into a percentage
The scale runs from 200 to 800, so basic arithmetic can mislead. Saying that 450 is 56.25 percent of 800 ignores the scale's nonzero lower bound and the conversion from performance to scaled score. Saying that the candidate needs 56.25 percent correct is equally unsupported. ISACA does not publish a formula that lets candidates translate 450 into a raw percentage.
A better description is: 450 is the minimum scaled score required to pass. If you discuss preparation, describe a practice score as performance on that particular set, then explain what it reveals. For example, a 68 percent result on a timed quiz may indicate that the candidate should review weak objectives and question reasoning. It cannot establish the exact official exam score or number correct needed.
Domain feedback is diagnostic, not a second pass gate
ISACA reports performance information by exam domain to help candidates understand relative strengths and weaknesses. The guide states that the total score is based on the total number of correct answers and candidates are not required to pass each domain independently. A low domain indicator therefore does not automatically fail someone whose overall scaled score is 450 or higher.
The domain report is still useful. If a candidate falls short overall and receives comparatively weak feedback in Information Systems Acquisition, Development and Implementation, that signal can guide a targeted review of business cases, project governance, system development methods, testing, migration, and post-implementation evaluation. It is a study clue, not a numerical formula for calculating a retake score.
Likewise, strong performance in four domains does not guarantee a pass if the overall score is below 450. Domain feedback is not a bank of separate subtests with independent passing bars. Read the total result first, then use the diagnostic indicators to plan the next attempt.
How pretest questions fit into scoring
The CISA exam includes pretest items that are not counted in the score calculation. They are used for evaluation and are not identified to the candidate during the exam. This means candidates should treat every question seriously. A difficult or unfamiliar item cannot safely be assumed to be unscored, and spending disproportionate time trying to identify pretest questions provides no benefit.
The guide says the score is based on the number of correct responses among the scored material, with pretest items excluded. It does not provide candidates a way to see which questions counted or to reconstruct a raw total after the exam. This is another reason that a post-exam recollection of question difficulty cannot determine whether a pass was earned.
A practical example of interpreting a report
Imagine two candidates receive a result of 450. Both have met the minimum standard, even if their domain feedback differs. Candidate A's report shows relatively balanced performance. Candidate B appears stronger in Protection of Information Assets and weaker in Governance and Management of IT. Both have passed. Candidate B may choose to study governance topics before a later professional assignment, but does not need to retake CISA solely to raise a domain indicator.
Now imagine a candidate receives 447. That result is below the passing standard, even if four domain indicators look strong. The candidate should use the domain feedback to prioritize study, but must retake the full exam to pass. The report does not reveal that the candidate was three questions away or three raw points short; 447 and 450 are scaled results, and no public conversion supports that inference.
How to use practice scores responsibly
- Record the practice set's source, date, topic coverage, and whether it was timed.
- Review missed questions by cause: knowledge gap, misread qualifier, weak evidence judgment, wrong actor, or rushed choice.
- Track results by domain or objective to see where additional learning may help.
- Repeat with new questions that test the concept in a different context rather than memorizing answer patterns.
- Treat percentage trends as preparation evidence, not a prediction of the official scaled score.
- Answer every live exam question; ISACA says incorrect answers do not incur a penalty.
For instance, if a practice set shows repeated errors on evidence reliability, ask whether you are selecting evidence that directly supports the audit objective and whether its source and completeness can be evaluated. If errors cluster around management responsibility, practice separating the auditor's role from the control owner's. Those changes address reasoning patterns that can transfer across scenarios, unlike memorizing a percentage target.
Results and score review
Candidates receive a preliminary pass or fail indication on screen after completing the exam. ISACA sends the official score report by email and makes it available online, generally within 10 working days. The report includes total scaled score and domain-level diagnostic information; it does not provide a replay of the items or a question-by-question answer key.
A candidate who fails may request a rescore in writing through ISACA support within 30 days and pay the published US$75 fee. This is a review request, not a guaranteed score change or a substitute for retaking. ISACA's candidate guide describes a four-attempt limit within a rolling 12 months and waiting periods of 30 days after the first failure, then 90 days after the second and third failures. Each new attempt requires the full registration fee.
What passing the exam does and does not establish
A passing score means the candidate met ISACA's exam standard. It is not by itself the CISA credential. Certification requires a separate application and documentation of qualifying professional experience, along with acceptance of applicable professional requirements. ISACA gives candidates five years after passing to submit the application. Thus, a score report confirms exam success, while the credential depends on completing the later application process.
A passing score also does not mean that every CISA task is mastered equally. The exam samples a broad role across governance, risk, audit, acquisition, operations, resilience, and information asset protection. The report can help identify learning priorities, and continued professional education helps keep knowledge current. The credential's exam threshold should be understood precisely without overstating what one result says about an individual's entire professional capability.
Use a sample question to understand what practice scores show
Consider this original practice question: an auditor is testing whether terminated employees lose access promptly. The practice set gives the candidate 7 correct answers out of 10 on access-management questions. That 70 percent result says the candidate got seven items in that particular set right. It may justify reviewing the missed explanations and checking whether errors involved population completeness, timing, or evidence quality. It does not establish that the candidate has a 70 percent chance of passing or would receive a particular scaled score.
If the candidate later scores 450 on the actual CISA result, the official interpretation is pass. If the actual score is 449, the interpretation is below the standard. There is no basis to infer that the difference represents one raw question, one percentage point, or a particular amount of knowledge. A scaled score puts the result on ISACA's reporting scale; the public report is not a raw answer ledger.
How to respond to a failing result
A fail is useful when the candidate treats the report as evidence about preparation rather than as a hidden score formula. Start with the domain feedback and map it to the current outline. Review the specific areas that plausibly need attention, then examine practice errors for patterns. Did you select an answer that bypassed the audit objective? Did you confuse management's responsibility with the auditor's? Did you choose convenient evidence instead of reliable evidence? Those patterns point to study actions more clearly than repeatedly calculating the practice percentage.
Next, build a new study cycle and schedule only when the knowledge review and timed practice support readiness. ISACA's waiting periods are 30 days after the first failed attempt and 90 days after the second and third failures; the candidate guide allows four attempts in a rolling 12 months. Use the waiting period to fix identified gaps. Each attempt requires the full exam fee, so a deliberate retake plan also protects the candidate's budget.
Do not overread domain labels
Domain feedback is relative information, not a detailed competency transcript. It does not list which questions were missed, expose the scoring weight of each item, or prescribe a particular study product. A weaker indicator can reflect several topics within a domain and the interaction of question difficulty and performance. Use the outline to turn a broad signal into a list of learning objectives, then use fresh scenarios to test application.
The distinction is especially important for candidates who pass. A passing total is not revoked because one domain appears weaker. Nor should a candidate who receives a strong domain indicator assume that no maintenance or continued learning is necessary. The exam report answers the certification-exam question; it is not a complete appraisal of professional skill.
What the score cannot tell you
- It cannot reveal the exact number of correct answers because ISACA reports a scaled result and excludes pretest items.
- It cannot be converted to a raw percentage using 450 divided by 800.
- It cannot identify which exam items were pretest or show an answer-by-answer review.
- A domain indicator is not a separate subscore that must reach a second passing mark.
- A practice quiz percentage is not an official forecast of a scaled result.
- A pass confirms the exam standard was met, but certification still requires the separate application and qualifying experience.
The useful takeaway
The CISA passing threshold is 450 on a 200-to-800 scaled scale. Read it as a standardized pass mark, not as a raw count or percentage. Domain feedback can guide study but is not an independent gate, and pretest questions are not identifiable during the exam. Candidates gain the most from using practice data to diagnose reasoning and knowledge gaps while leaving official score interpretation to the scale ISACA reports.
Common questions
What score do you need to pass CISA?
You need a scaled score of at least 450 on ISACA's 200-to-800 reporting scale.
Is 450 the same as 56.25 percent correct?
No. CISA reports a scaled score, not a raw percentage. ISACA does not publish a raw-answer conversion that supports that calculation.
Do I need to pass every CISA domain?
No. ISACA says the total score is based on total correct responses and domain feedback is informational. There is no separate passing threshold for each domain.
Are some CISA exam questions unscored?
Yes. ISACA includes pretest questions that are excluded from scoring, but candidates cannot identify them. Treat every question as important.
How soon will I get my official CISA score?
A preliminary result appears on screen after the exam. ISACA generally provides the official score report online and by email within 10 working days.
Can a high domain score offset an overall score below 450?
The reported total determines pass or fail. Domain feedback helps diagnose strengths and weaknesses but does not replace the overall passing standard.