CISA Exam Eligibility and Certification Requirements
ISACA lets anyone interested in information security take the CISA exam; you do not need five years of experience to register.
- Certification is separate: it generally requires five years of relevant IS audit, control, assurance, or security work, with qualifying substitutions or education waivers of up to three years, a passing exam within five years, and a verified application.
On this page7 sections
There are two different eligibility questions
The first question is whether you can sit the CISA exam. The answer is yes: ISACA says the exam is open to anyone with an interest in information security. You do not need to finish a degree or accumulate several years of work before registering.
The second question is whether you can receive the CISA certification after passing. That requires a separate experience application, verification, and agreement to ISACA's professional requirements. The distinction lets a candidate study and pass while building qualifying experience, but a passing score alone does not authorize use of the CISA designation.
| Stage | Requirement | What it means |
|---|---|---|
| Register and sit | No work experience prerequisite | You can take the exam before qualifying for certification. |
| Pass the exam | At least 450 on the scaled score | A pass meets the examination component, not the experience component. |
| Apply for certification | Five years of relevant experience or accepted substitutions and waivers | Experience is verified and must match ISACA's criteria. |
| Receive CISA status | Approved application and applicable fee, ethics, CPE, and standards commitments | The credential follows ISACA approval, not the exam result alone. |
Experience needed for certification
ISACA requires at least five years of professional information systems auditing, control, assurance, or security work experience described by CISA job practice areas. The experience must be gained within the ten-year period before the certification application. Relevant work can span more than one employer, but you need to describe the responsibilities and dates well enough for a verifier to attest to them.
The job title does not decide whether work qualifies. An internal auditor might test access controls, change management, data governance, and recovery processes. An IT professional might perform security or control responsibilities as a defined part of the job. Explain the work performed and map it to the current CISA job practice areas. Generic statements such as 'worked in technology' do not show what the role involved.
The qualifying experience requirement and the exam are evaluated separately. Someone can pass first and complete qualifying experience later, provided they apply within the allowed period. Someone with substantial general IT work should not assume every year counts directly as CISA experience; some types of related work may fit a substitution or waiver route instead.
Substitutions and education waivers
ISACA's CISA application permits experience substitutions and education waivers, up to a combined maximum of three years. The current application form lists a one-year waiver for general information systems or general audit work, and education or professional qualifications that may provide one, two, or three years depending on the category. The applicant must provide the documentation called for by the form.
| Application route shown by ISACA | Potential waiver | Important limit |
|---|---|---|
| General information systems work or general audit work | One year | The same period cannot also be counted as qualifying direct experience. |
| Associate degree | One year | Submit the required degree evidence. |
| Bachelor's, master's, or doctorate in any field | Two years | The application identifies this category; total substitutions and waivers cannot exceed three years. |
| Master's degree in Information Systems or a related field | Three years | The field must meet ISACA's related-field criteria; evidence is required. |
| Full CIMA certification | Two years | This is an alternative professional qualification route listed on the application. |
| ACCA member status | Two years | The application identifies full member status, not merely exam progress. |
These are maximum credits associated with the listed routes, not automatic approval for every credential or transcript. ISACA decides whether an education field is related and whether the records are sufficient. Add accepted substitutions and direct professional experience only as the application allows, with no more than three years coming from waivers or substitutions.
A few examples show how the arithmetic works. A candidate with two qualifying years and a three-year eligible master's waiver may reach the five-year total. A candidate with four qualifying years and an eligible one-year general audit substitution may also reach five. A candidate with one qualifying year and a three-year waiver still has only four total years and does not meet the five-year requirement. The cap does not erase the need for five combined years.
Do not count the same period twice as both qualifying direct experience and a general-work substitution. Do not add waivers beyond the three-year cap. If your case depends on whether a program or responsibility qualifies, preserve your documents and use ISACA's certification application instructions rather than relying on an informal interpretation from another candidate.
When the exam pass expires for application purposes
ISACA requires candidates to apply within five years after passing the exam. A candidate who passes before meeting the experience requirement therefore has a real planning deadline. Keep the pass date and application date in the same record as the experience timeline. Do not treat exam registration validity, which is a separate six-month period before sitting, as the same clock.
If your remaining experience will take longer, check the CISA Associate option. ISACA describes CISA Associate for students who lack the experience requirement, participate in an ISACA partner program, and pass the exam. The current program page lists a one-time US$25 application fee, active ISACA membership at any level, and validity for up to four years or until the candidate meets experience requirements. The page says there are no CPE requirements for the Associate designation.
CISA Associate is a distinct designation, not full CISA certification. Its partner-program condition matters. A candidate who passed independently should not assume the Associate route is automatically available without meeting the current program's eligibility terms. Review the official program page and retain its terms when applying.
How the experience application is verified
Once you have a passing result, use ISACA's application form to report employment and requested waivers. ISACA asks for experience to be verified by a supervisor or manager. Gather employer names, dates, position details, descriptions of duties, and contact information before completing the application. If you claim a degree or professional qualification waiver, have the certificate, transcript, or other evidence the form requests.
Ask a verifier who can speak to your work and dates. A manager may not know technical details from an earlier role, so provide a concise summary of responsibilities and project periods. The verifier attests to facts; the applicant remains responsible for making accurate claims. Keep a copy of the submitted application and supporting documents.
Build an evidence file before the application
A practical record can be a simple table with employer, role, start and end dates, key duties, and the CISA job practice area each duty supports. Add the name and contact details of a supervisor or manager who can verify the dates and work. For a waiver, keep the degree certificate, transcript, or professional qualification record identified by the current form. This preparation helps you distinguish direct qualifying work from a general-work substitution.
Suppose a four-year career includes three years testing system access and change controls, then one year supporting general IT operations. The first three years may be direct relevant experience if the duties meet the job practice criteria. The fourth year should not automatically be described as direct experience; the candidate can determine whether it fits a listed substitution and whether the application accepts it. The form and verification control the decision, not the employer's department name.
Also review the date windows. Experience must fit the ten years preceding your application, while the exam pass must fall within the five years before that application. A role can be relevant but too old for the experience window. A pass can remain valid while you gain experience, but the five-year application deadline continues to move closer.
ISACA's current page says the application processing fee is US$50 and that it is paid after official exam scores are released. Complete the application within five years of passing. The remaining certification conditions include adherence to the ISACA Code of Professional Ethics, Continuing Professional Education Policy, and Information Systems Auditing Standards.
Candidate examples
An early-career candidate
A recent graduate has two years in IT operations and passes the CISA exam. The candidate can take the exam without experience, but must distinguish whether those operations duties qualify directly or fit a substitution. If an eligible education waiver applies, the candidate can combine it with qualifying work, subject to the three-year cap. The application and waiver evidence still need approval.
An experienced financial auditor
A financial auditor has four years testing business controls and one year on system access and change controls. The application should describe the IT-related work precisely and show which periods qualify as direct CISA experience. If the candidate needs to use general audit work as a substitution, the same period cannot be double-counted. A verifier should be able to confirm dates and actual responsibilities.
A candidate who passed but lacks time
A candidate passes with two qualifying years and no accepted waiver. The candidate has up to five years from the pass date to apply for full certification, so they should track additional relevant experience and confirm their remaining timeline. If the candidate participated in the required partner program, the CISA Associate designation may provide an interim option under its separate program conditions.
Common misunderstandings
- You do not have to meet the experience requirement to register for the exam.
- A passing score is not the CISA certification; application and experience approval remain.
- Five years means a combined total after accepted substitutions and waivers, with a three-year maximum waiver or substitution credit.
- Experience must be within the ten-year period before applying, and the exam pass must be within five years of the application.
- A role title or degree alone does not guarantee that ISACA will accept the experience or waiver.
- CISA Associate is a separate pathway with a partner-program requirement, membership condition, and its own validity period.
The practical way to plan is to separate the milestones: register and pass, assemble verified qualifying experience, decide whether a permitted waiver applies, and submit the certification application before the pass deadline. Keeping those dates and records distinct prevents a common mistake: treating permission to take the exam as proof that you already qualify for the credential.
Common questions
Can I take the CISA exam with no experience?
Yes. ISACA says the CISA exam is open to anyone with an interest in information security. Experience is required for certification after passing, not to sit the exam.
How many years of experience are required for CISA certification?
The standard requirement is five years of relevant professional IS audit, control, assurance, or security experience. ISACA allows approved substitutions and education waivers totaling no more than three years.
How long after passing can I apply for CISA?
ISACA gives candidates five years from the exam pass date to apply for certification. The qualifying work experience also must fall within the ten years preceding the application date.
Does passing the CISA exam automatically make me certified?
No. You must submit the experience application, have work verified, pay the application fee, and agree to ISACA's ethics, CPE, and auditing standards requirements before certification is complete.
Can every CISA exam passer use CISA Associate?
Not automatically. ISACA's current CISA Associate page describes a route for students who participate in an ISACA partner program and pass the exam, with membership and application conditions. It is separate from full CISA certification.