CISA Certification Requirements After the Exam
Passing the CISA exam is open to candidates before they meet certification experience requirements.
- To earn the credential, applicants need five years of relevant information systems auditing, control, assurance, or security experience in the 10 years before applying, subject to listed waivers.
- Submit a verified application and the US$50 fee within five years after passing.
On this page12 sections
- Exam eligibility and certification eligibility are different
- The five-year experience standard
- Which experience substitutions may count
- Worked qualification examples
- Document and verify your experience
- The five-year application deadline
- After ISACA approves the application
- A practical application checklist
- Translate job duties into application evidence
- How to avoid common waiver errors
- Plan for the verifier and application review
- Credential status language matters
Exam eligibility and certification eligibility are different
A person can register for and pass the CISA exam before meeting the professional experience requirement. Passing demonstrates that the candidate met the exam standard; it does not itself award the CISA designation. To become certified, the candidate must separately submit an application, show qualifying work experience or approved substitutions, obtain verification, pay the application fee, and meet ISACA's professional requirements.
This distinction lets students and career changers take the exam while building experience. However, until ISACA approves the application, they should describe the achievement accurately as having passed the exam, not as holding the CISA certification. ISACA offers a separate CISA Associate designation through partner programs for candidates who have passed but do not yet meet full experience requirements; it has its own eligibility, application, fee, and time limits.
The five-year experience standard
ISACA requires at least five years of professional information systems auditing, control, assurance, or security work experience described in the CISA job practice areas. The experience must have been gained within the 10-year period before the certification application date. Current application materials state that at least two years must be direct experience in the qualifying audit, control, assurance, or security work category; approved waivers can account for part of the five-year total, up to three years.
The work should map to CISA practice areas rather than merely involve working near technology. Examples can include planning or performing audits, assessing IT controls, evaluating security or assurance processes, testing system implementation controls, examining operations and resilience, and reporting findings. Job title alone is not decisive. A systems administrator may have relevant security-control work, while a role with an 'auditor' title may include duties that need clearer explanation to show the connection.
Which experience substitutions may count
ISACA's application lists experience waivers and substitutions. The listed education and professional credentials can cover up to three years in total, while general information systems or general audit work can provide a one-year waiver. A candidate must document the basis for each claimed waiver and avoid counting overlapping periods twice.
| Listed basis | Potential waiver |
|---|---|
| Associate degree | 1 year |
| Bachelor's, master's, or doctorate in any field | 2 years |
| Master's degree in Information Systems or a related field | 3 years |
| Full CIMA certification | 2 years |
| ACCA member status | 2 years |
| General audit work or general information systems work | 1 year, subject to the application rules |
These amounts are not additive without limit. The application caps education and certification substitutions at three years, and the general-work waiver is limited to one year. A candidate still needs at least two years of qualifying professional IS audit, control, assurance, or security experience. The general-work waiver cannot be used to erase that minimum, and general experience claimed as a waiver cannot duplicate dates already used for the direct-experience section.
Worked qualification examples
Example: relevant bachelor's degree and direct experience
Maya has three years of professional IT audit experience and a bachelor's degree in accounting. The listed bachelor's waiver can contribute two years, subject to supporting documentation. The combination may reach the five-year total, and Maya's three years satisfy the minimum two-year direct experience threshold. She should make sure the work maps to CISA practice areas and the degree dates and credential meet the application requirements.
Example: general IT plus a related master's degree
Darius has two years in security-control testing and a master's degree in Information Systems. The degree may qualify for up to three years of waiver, while his two years meet the direct-experience minimum. He should provide the transcript or degree verification requested and describe his actual security-control duties. The degree does not replace the requirement to document professional work experience.
Example: experience that is too general
Elena has four years in general help desk support and no qualifying degree or professional credential. Some general information systems work may qualify for a one-year waiver, but it does not count as five years of direct CISA experience. Elena would still need the required direct professional experience. Tasks such as resetting passwords alone may not demonstrate the audit, control, assurance, or security work described in the job practice areas; she would need to document duties that genuinely meet those areas.
Example: overlapping dates
Noah has three years of direct security-control experience and one year of general systems work during the same employment period, plus an associate degree. He cannot count the overlapping year twice. The associate degree is a one-year waiver, and the non-overlapping general work may qualify for another one-year waiver, subject to the stated caps and documentation. He should calculate distinct periods carefully and confirm the total reaches five years without exceeding allowed substitutions.
Document and verify your experience
The application asks for employment details and experience verification. ISACA instructs applicants to have a supervisor or manager verify experience; if several verifiers are needed, applicants can submit additional verification forms. Select a verifier who can confirm dates and responsibilities, and prepare a factual description of duties mapped to the CISA job practice areas. Do not inflate a title or describe tasks you did not perform.
Before submitting, assemble employment dates, role summaries, supporting educational or professional documents for waivers, and contact information for the verifier. If a former employer has closed or a manager is unavailable, review the current application guidance for acceptable verification arrangements rather than assuming that a resume alone is sufficient. An application may be delayed when dates, role descriptions, or evidence do not reconcile.
The five-year application deadline
Candidates must apply within five years after passing the CISA exam. This is separate from the exam's six-month eligibility window. The six-month window governs when a paid exam registration can be used; the five-year period governs when a passing candidate must submit the certification application. Track the pass date and start the experience review early enough to resolve verification questions.
If experience is already complete, the applicant can proceed after the official score is released, pay the one-time US$50 application processing fee, and submit the required application and verification. If experience is still accumulating, maintain records while working toward the requirement and calendar the application deadline. Do not wait until the final weeks to locate former supervisors or educational evidence.
After ISACA approves the application
A CISA holder must follow the Code of Professional Ethics, comply with ISACA's Information Systems Auditing Standards, and maintain the certification through annual fees and CPE reporting. These obligations begin with certification and continue while the credential is active. Passing the exam and meeting experience are therefore distinct stages in a professional credential, not a one-time test transaction.
For candidates still building experience, keep the wording accurate on a resume or profile. Passing the examination can be listed truthfully as an exam achievement; using the CISA designation after one's name requires that the certification has been awarded and remains in good standing. ISACA also restricts individual use of the CISA logo, so use the acronym rather than reproducing the logo in personal materials.
A practical application checklist
- Confirm the exam pass is within five years of the planned application.
- Map qualifying employment to the CISA job practice areas and confirm the 10-year experience window.
- Ensure at least two years are direct professional IS audit, control, assurance, or security work.
- Calculate waivers within the maximums and exclude overlapping dates.
- Collect degree, transcript, CIMA, or ACCA evidence for a claimed substitution.
- Ask an appropriate supervisor or manager to verify experience, using additional forms when needed.
- Pay the one-time US$50 fee and submit the complete current application.
- After award, meet CPE, maintenance, ethics, and auditing standards requirements.
Translate job duties into application evidence
A job description may use broad language such as 'IT risk' or 'security operations.' The application reviewer needs enough detail to see the connection to the CISA practice areas. Describe the system or control, your responsibility, and the type of work performed. For example, 'reviewed quarterly privileged-access certification evidence, tested a sample of approvals against role criteria, documented exceptions, and tracked remediation' is more specific than 'worked on access management.'
A second example might be 'assessed backup restoration test results against approved recovery objectives and reported missing application dependencies.' That description communicates evaluation and evidence. If a candidate only helped operate backups, explain the actual duties honestly and determine whether they meet a qualifying security or control responsibility. The application is not asking candidates to rename general technical work as audit experience.
How to avoid common waiver errors
The education waiver should match the exact degree level and field shown by the transcript or diploma. A three-year substitution is specifically associated with a master's degree in Information Systems or a related field; it should not be assumed for every graduate degree. A bachelor's, master's, or doctorate in any field is listed for two years, but the combined education and credential substitutions remain capped at three years.
The general-work waiver is also limited. General audit work or general information systems work can provide one year under the current application, but experience dates used in the direct category cannot be reused for that waiver. For overlapping roles, create a timeline by month or date range and assign each period to one category. The applicant should be able to explain the arithmetic and provide records for each claimed basis.
For instance, a person with two years of direct CISA-related experience, a two-year bachelor's substitution, and one year of separate general information systems work may reach five years if the application criteria are met. A person with only one year of direct qualifying experience does not satisfy the stated two-year direct minimum simply by stacking more education substitutions. The direct work requirement and total experience requirement both matter.
Plan for the verifier and application review
Ask a supervisor or manager before submitting so the verifier expects ISACA's request and can confirm the periods and responsibilities. If the candidate has several employers, use an appropriate verifier for each relevant period and attach the additional verification pages permitted by the form. Keep copies of what was submitted and the date of submission. If employment records use different titles or dates than the applicant's resume, reconcile them before applying.
A former supervisor can be helpful if that person had direct knowledge of the candidate's work, but the candidate should follow current ISACA application instructions about acceptable verification. If an employer cannot verify a period, do not assume an unrelated colleague can attest to it. Contact ISACA for acceptable alternatives and document the response. This is particularly useful for contract work, reorganizations, or roles where the reporting manager has left the organization.
Credential status language matters
Before approval, describe the status accurately. 'Passed the CISA exam' identifies an exam result. 'CISA Associate' is a distinct designation available to eligible participants through partner programs and is valid under its own conditions. 'CISA' after a name indicates that the full certification has been awarded and remains active. These terms are not interchangeable.
After certification, use the acronym as authorized and follow ISACA's restrictions on the CISA logo. A candidate should not imply that passing alone is a current professional designation. Accurate status language helps employers and clients understand the difference between exam achievement, an associate status, and full certification.
The credential path is manageable when each stage is tracked separately: exam, experience, verified application, and ongoing maintenance. Use the current application form as the controlling source for exact evidence and submission instructions. If a work history sits near the boundary of a qualifying category, describe actual responsibilities precisely and ask ISACA for clarification rather than assuming that a job title or general IT tenure automatically satisfies the rule.
Common questions
Can I take the CISA exam before I have five years of experience?
Yes. ISACA allows candidates to take the exam before satisfying certification experience requirements. They must meet the experience and application requirements to earn the designation.
How much CISA work experience is required?
The standard is five years of qualifying professional IS audit, control, assurance, or security experience gained within the 10 years before applying. Current application materials require at least two years of direct qualifying experience.
What experience waivers are available for CISA?
ISACA lists substitutions for certain degrees and credentials, plus a one-year waiver for general audit or general information systems work. Waivers are capped, documented, and cannot remove the minimum direct-experience requirement.
How long do I have to apply after passing CISA?
Candidates must submit the certification application within five years of passing the exam.
How much is the CISA application fee?
ISACA lists a one-time US$50 application processing fee, paid separately from exam registration.
Does passing the CISA exam make me certified?
No. Certification requires an approved application with qualifying experience and verification, plus compliance with professional requirements.