Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

CISA Renewal and Continuing Professional Education

Updated 12 min read
Key takeaway

Active CISA holders currently need at least 20 CPE hours each year and 120 over three years, pay an annual maintenance fee, follow ISACA's ethics and auditing standards, and respond to an audit if selected.

  • Beginning January 1, 2027, the 120-hour total remains, with at least 90 hours aligned to the credential and up to 30 for other professional development.
On this page13 sections
  1. What active CISA holders must do today
  2. How CPE activity is earned and counted
  3. Report activities and retain evidence
  4. A concrete annual CPE plan
  5. What changes on January 1, 2027
  6. Keep current requirements separate from announced future rules
  7. Maintenance fees, lapses, and status
  8. Use CPE to keep work knowledge relevant
  9. An annual maintenance checklist
  10. A transition example for a reporting cycle that spans 2027
  11. Choose CPE based on the work you actually do
  12. What happens if requirements are missed
  13. Make CPE records useful for both renewal and practice

What active CISA holders must do today

CISA certification is maintained through continuing professional education, an annual maintenance fee, and ongoing professional obligations. Under ISACA's current policy in 2026, a holder reports at least 20 CPE hours each calendar year and at least 120 CPE hours over a three-year reporting cycle. The hours must be appropriate to maintaining or advancing knowledge and ability to perform CISA-related tasks. The holder must also follow ISACA's Code of Professional Ethics and Information Systems Auditing Standards and provide documentation if selected for the annual CPE audit.

RequirementCurrent policy in 2026
Annual CPE minimum20 hours each year
Three-year cycle minimum120 hours related to CISA over the cycle
Annual maintenance feeUS$45 for members; US$85 for nonmembers, due January 1 for renewal through the upcoming year
Audit responseSubmit supporting records if selected
Professional conductComply with ISACA's Code of Professional Ethics and Information Systems Auditing Standards

CPE and the maintenance fee are separate. Paying the fee does not satisfy the CPE requirement, and completing learning does not pay the fee. Failure to meet the policy can lead to revocation. The account dashboard and annual invoice show the holder's reporting period and amount due, so use those account-specific dates rather than assuming every certificate's cycle ends on the same date.

How CPE activity is earned and counted

Qualifying activities can include professional education and meetings, ISACA or non-ISACA training, conferences, seminars, workshops, relevant university courses, eligible self-study with completion evidence, teaching or presenting, publication, exam question development, and certain professional contributions or volunteer activities. The activity should relate to information systems auditing, control, security, or managerial skills relevant to CISA. Basic office productivity instruction such as ordinary word-processing training does not qualify under ISACA's stated policy.

For educational events, count active participation rather than breaks or meals. ISACA's reporting guidance uses one CPE hour for each 50 minutes of active participation and permits quarter-hour reporting. For structured self-study, use the provider's completion certificate and awarded hours. Other activities have their own calculation rules and annual limits; check the CPE policy before relying on teaching, volunteer work, mentoring, or vendor presentations to fill a cycle.

Activity typePractical exampleRecord to keep
Professional educationA conference session on identity governance or incident responseRegistration or attendance evidence, agenda, active hours, topic
Self-studyA structured course on audit analytics with a completion certificateCertificate stating provider, course, completion date, and CPE hours
Teaching or presentingDeveloping and delivering a CISA-related sessionPresentation details, date, audience, material and calculation
PublicationWriting an article on IT control testing for a professional outletPublished copy or URL, title, publication date, and time spent
Volunteer or committee workActive participation on a qualifying ISACA working groupRole, dates, description of work, and active hours; apply policy limits
MentoringSupporting a specific person's ISACA exam preparation or career developmentMentee activity, dates, subject, and hours; apply current annual cap

ISACA opportunities include conferences, webinars and online training, on-demand learning, training courses and skills-based labs, journal quizzes, and volunteer work. ISACA advertises certain annual maximums for those programs, but each activity's eligibility and available hours depend on the specific offering. A free webinar can support ongoing learning; it does not eliminate the need to track the annual and three-year totals.

Report activities and retain evidence

CPE from some ISACA learning activities may appear preloaded in MyISACA, but the holder may still need to apply it to the certification record. Chapter events and other sponsors may require self-reporting. For each record, capture the activity title and description, sponsor, date, and hours claimed. Keep a certificate, attendance record, completion letter, or another independent attestation when the activity provides one.

ISACA says holders selected for audit must supply supporting documentation from the selected calendar year. Keep records for 12 months after the end of each three-year reporting cycle. A safe routine is to save the evidence when the activity occurs and reconcile the dashboard quarterly, rather than trying to reconstruct a year's worth of webinars and training at renewal time.

A concrete annual CPE plan

A CISA working in technology risk might plan one relevant conference with 12 active CPE hours, four webinars of one hour each, and a self-study course that awards four hours. That adds to 20 hours for the year if each activity meets the policy and the records support the claimed amounts. The holder should still check whether the three-year total is on pace for 120. Activities can be distributed unevenly across the cycle, but the annual 20-hour floor remains in effect under the current policy.

Another holder might earn hours through employer training on cloud controls, a university course on information assurance, and presenting an internal session on audit evidence. The fact that an activity occurred at work does not automatically make it eligible. It must be a qualifying professional education or other approved activity, not ordinary performance of day-to-day job duties. Describe the educational content and retain supporting records.

What changes on January 1, 2027

ISACA has announced a revised CPE policy effective January 1, 2027. The total requirement remains 120 CPE hours over a three-year cycle. At least 90 hours must align to the certification exam content outline or domains, while up to 30 hours may come from professional development that is not domain specific, such as leadership, communication, mentoring, or other qualifying activities. This update creates a category distinction; it does not increase the total hours required.

Policy periodTotal over three yearsAlignment expectation
Through the 2026 cycle120 CPE; at least 20 each yearCurrent CISA policy requires job-related CPE; do not apply the 2027 categories early
Effective January 1, 2027120 CPEAt least 90 aligned to CISA content outline/domains; up to 30 for other professional development

The announcement says no system changes will occur during the 2026 cycle. Holders should follow the current policy for current-year reporting and prepare for the revised alignment categories beginning in 2027. The 2027 policy describes aligned activities such as cybersecurity or audit learning, ISACA conferences, certification working groups, review manual development, and publishing on domain topics. Professional-aligned examples include communication or leadership development and certain mentoring or volunteer work, subject to the policy's specific caps.

Volunteer CPE has nuanced limits under the new policy. ISACA states that volunteer activity aligned with the exam domains may count up to 20 hours per year and 60 over three years; non-domain-aligned volunteer work is limited to 30 hours total over the cycle. Vendor sales or marketing demonstrations will no longer qualify, although a vendor case study that is not a demo may still qualify. Read the detailed 2027 policy for the activity category and evidence requirements before claiming hours.

Keep current requirements separate from announced future rules

A holder renewing in 2026 should not retroactively impose the 2027 minimum of 90 domain-aligned hours on the current cycle. Conversely, planning a cycle that runs into 2027 should account for the new policy when it takes effect. ISACA has said the overall 120-hour total is unchanged, but the categories and limits will affect which activities count toward the domain-aligned portion.

For a simple transition plan, retain the current CPE evidence and record the topic and domain for each activity. Beginning in 2027, tag activities as aligned or professional development according to ISACA's descriptions. This gives the holder a clear audit trail and reduces the risk of discovering near the cycle deadline that too many hours fall into the 30-hour non-domain category.

Maintenance fees, lapses, and status

The annual CISA maintenance fee is US$45 for ISACA members and US$85 for nonmembers, payable by January 1 for renewal through the coming calendar year. Holders of more than two ISACA certifications receive reduced maintenance rates for the third and later credentials: US$25 for members and US$50 for nonmembers, according to ISACA's current maintenance page. Check the account invoice to see which amount applies.

If a holder cannot meet CPE requirements because of unemployment, disability, leaving the field, or another qualifying circumstance, ISACA provides status options such as non-practicing or retired status for those who qualify. These options have their own criteria and fees. They are not an automatic extension of active status. If a designation is revoked for noncompliance, reinstatement may require an appeal, documentation, outstanding fees, and a reinstatement fee; in some cases returning to active status may require retaking the exam and reapplying.

Use CPE to keep work knowledge relevant

CPE is most useful when selected to address a real responsibility. An auditor moving into cloud assurance might study shared responsibility, identity boundaries, resilience, and supplier evidence. An IT risk professional leading a system implementation review could learn current testing and data-conversion practices. A security practitioner assigned to internal audit may strengthen sampling, evidence evaluation, and reporting. These examples describe learning choices, not guaranteed career outcomes.

CISA holders work in varied roles such as IT audit, assurance, internal controls, information security, technology risk, compliance, and consulting. The credential and ongoing learning can help demonstrate relevant knowledge, but a certification alone does not guarantee a particular job, promotion, salary, or client engagement. Use role descriptions, employer requirements, and your own experience to decide which CPE topics are valuable.

An annual maintenance checklist

  • Check the CPE cycle dates and annual minimum in the MyISACA account.
  • Select learning that is relevant to CISA duties and understand any activity-specific limit.
  • Record active hours and save evidence as soon as an activity finishes.
  • Apply preloaded CPE and self-report external or chapter activities as required.
  • Review the 120-hour three-year total and resolve missing records before year end.
  • Pay the maintenance invoice by January 1 and follow the ethics and auditing standards.
  • For the 2027 cycle, classify each activity as domain aligned or other professional development under the new policy.

A transition example for a reporting cycle that spans 2027

Consider a holder with a three-year cycle that includes 2027. During the 2026 reporting cycle, the holder follows the current requirements and does not retroactively classify those hours under the future policy. For activity beginning January 1, 2027, the holder records whether each course or contribution aligns to the CISA outline or falls under other professional development. By the end of the cycle, the holder can demonstrate at least 90 aligned hours and no more than 30 professional-aligned hours, while meeting the 120 total and any applicable annual minimums.

Suppose the holder completes 40 hours on information security controls and audit analytics, 28 hours at a conference covering resilience and governance, 22 hours developing CISA-related training, and 30 hours on leadership and mentoring. The first three categories total 90 domain-aligned hours, while the final 30 are professional development. This reaches the announced category boundary exactly, provided each activity qualifies and the records support the hours. The example illustrates planning arithmetic; ISACA's policy determines each activity's classification.

Choose CPE based on the work you actually do

A technology auditor assessing a cloud migration can select training about shared responsibility, identity permissions, resilience design, and supplier assurance. Someone reviewing financial system controls may choose data analytics, access governance, change management, and fraud-risk education. A professional moving into a leadership role may also value communication or mentoring, especially under the 2027 allowance. Keep the domain-aligned portion substantial and connect the learning to CISA responsibilities.

CPE need not all come from paid conferences. ISACA lists webinars, online training, journal quizzes, on-demand courses, and qualifying volunteer work, while non-ISACA professional education can include employer training, universities, conferences, and workshops. Availability and CPE caps differ by activity. Confirm the hours awarded, active participation requirements, and evidence before building an annual plan around a particular option.

What happens if requirements are missed

If the holder cannot meet active requirements, act before the deadline. Review the account status, report eligible hours, pay outstanding fees, and ask ISACA about options. Non-practicing status may be available for unemployment, disability, leaving the field while considering a return, or other approved circumstances. Retired status also has eligibility rules. These statuses are formal options; simply stopping work or ceasing to report CPE does not automatically change an active credential's requirements.

ISACA states that failure to comply can result in revocation. A revoked holder may submit a reinstatement appeal with an explanation and CPE documentation for the period from revocation to the current year. If approved, the holder must pay outstanding maintenance fees and a US$50 reinstatement fee per certification. If an appeal is not approved, returning to active status may require retaking and passing the exam and submitting a new certification application with the required experience.

Make CPE records useful for both renewal and practice

A record can include the activity, date, sponsor, hours, evidence, and the relevant CISA task or domain. Add a brief note about how the learning applies to current work. For example, after a session on cloud incident response, note which incident evidence or supplier escalation practice you would evaluate in an audit. This makes the learning easier to recall and supports accurate classification if the activity is reviewed.

Do not claim routine work hours as CPE merely because the work uses technology. The policy focuses on qualifying education and specified professional contributions. A project assignment might prompt learning, but the CPE claim should be for an eligible course, meeting, self-study activity, publication, teaching, or other accepted category. If classification is uncertain, ask ISACA before reporting rather than inventing an interpretation.

The CISA credential remains active through steady attention to learning, reporting, fees, and professional conduct. Under current 2026 rules the key targets are 20 hours annually and 120 over three years. Beginning January 1, 2027, the total stays 120 while at least 90 hours must align to the credential and no more than 30 may be other professional development. Keep those dates clear, document activities, and use the account dashboard and current ISACA policy for individual status.

Common questions

How many CPE hours does CISA require each year?

Under the current policy, holders need at least 20 CPE hours annually and 120 hours over a three-year cycle.

What is the CISA annual maintenance fee?

ISACA currently lists US$45 for members and US$85 for nonmembers, due January 1 for the upcoming calendar year.

What changes to CISA CPE begin in 2027?

The 120-hour three-year total remains. At least 90 hours must align to the CISA exam outline or domains, and up to 30 may be other professional development.

Can I earn CISA CPE at work?

Qualifying professional education may be employer sponsored, but ordinary day-to-day work does not automatically count. The activity must meet ISACA's criteria and be documented.

What evidence should I keep for CISA CPE?

Keep certificates, attendance records, or other independent evidence showing the activity, sponsor, dates, description, and hours. Retain records for 12 months after the cycle ends.

Does CISA guarantee a job or salary increase?

No. The credential can document knowledge, but employment and compensation depend on experience, employer needs, and other factors.