CRISC Master Guide 2026
CRISC is ISACA's certification for professionals who manage IT risk and information system controls.
- The current exam has 150 multiple-choice questions over four hours and four domains: Governance, Risk Assessment, Risk Response and Reporting, and Technology and Security.
- Candidates may sit before meeting the certification experience rule, but earning CRISC requires three years of relevant work across at least two domains and an approved application.
On this page12 sections
- What CRISC is designed to validate
- The current CRISC outline
- How to reason through IT risk
- Follow risk from scenario to action
- Use metrics that can change a decision
- Expand the study sequence with active practice
- How the exam works
- Registration, cost, and results
- Exam eligibility and certification experience
- A practical study plan
- Certification maintenance
- Choose a useful next step
What CRISC is designed to validate
CRISC means Certified in Risk and Information Systems Control. ISACA describes it for professionals who identify and manage risk through the development, implementation, and maintenance of information systems controls. The work connects business objectives, technology, risk ownership, and control effectiveness. A CRISC professional helps an organization understand uncertainty and choose proportionate responses, rather than treating each vulnerability as a stand-alone technical problem.
The credential can be relevant to IT risk managers, information security and control leads, governance and compliance professionals, business analysts, project managers, and technology managers with risk responsibilities. It is a professional certification, not a statutory license or permission to approve risk on behalf of any employer. Organizations retain their own authority structures and may set additional role requirements.
| Candidate question | Current published information |
|---|---|
| Exam format | 150 multiple-choice questions; four hours |
| Current outline | 2025 version with four domains: Governance 26%, Risk Assessment 22%, Risk Response and Reporting 32%, Technology and Security 20% |
| Passing score | 450 or higher on ISACA's 200-to-800 scaled score |
| Exam eligibility | Open to candidates interested in information security; experience is not required before sitting |
| Certification experience | Three years of relevant work across at least two of four CRISC domains |
| Application deadline | Apply within five years after passing |
| Maintenance | 120 CPE in a three-year period, at least 20 annually, plus annual maintenance fee |
The current CRISC outline
ISACA updated CRISC's exam content for appointments beginning November 3, 2025. The four domains remain, while Risk Assessment now has 22 percent rather than 20, and Technology and Security now has 20 percent rather than 22. Governance is 26 percent and Risk Response and Reporting is 32 percent. The 2026 exam uses this updated outline; candidates should not study a prior edition's percentages or task list.
Governance establishes how risk fits the organization's strategy, roles, culture, policies, resilience, and enterprise risk framework. Risk Assessment identifies and analyzes events and scenarios, threats, vulnerabilities, likelihood, impact, inherent and residual risk, and business consequences. Risk Response and Reporting is the largest domain; it includes response choices, ownership, suppliers, controls, action plans, monitoring, and communication. Technology and Security examines how business practices align with technology and security principles, architecture, operations, development, data, resilience, and awareness.
The domain weights are a study-planning aid, not a guarantee of an exact question count or a separate passing score for each domain. A risk scenario often crosses domains. A new system project may raise governance questions about who owns the decision, assessment questions about threats and impact, response questions about controls and reporting, and technology questions about architecture or operations.
How to reason through IT risk
Start with the business objective and the asset, process, or service at stake. Then identify the risk scenario: an event or condition, its potential business impact, and the vulnerabilities or causes that make it plausible. Determine what controls already exist and whether the risk is inherent or residual. Use the organization's assessment method and tolerance so risks can be compared consistently.
The risk owner and control owner are related but distinct. A business or process owner is accountable for the risk decision within delegated authority. A control owner operates or monitors a safeguard. The CRISC professional may assess, advise, challenge, and report, but should not silently assume the authority to accept business risk. Documentation should connect the analysis to a decision and an action plan.
Response options can include mitigating, accepting, avoiding, or transferring part of the risk. The right choice depends on objectives, risk appetite, legal or contractual duties, control feasibility, and cost. A contract may transfer some financial exposure while leaving operational and regulatory accountability with the organization. A control can lower likelihood or impact but may introduce new dependencies. Monitor residual risk after treatment.
Reporting turns analysis into governance. A risk register, key risk indicator, control metric, heatmap, or dashboard is useful only if its definitions are stable and its audience can make a decision from it. CRISC candidates should distinguish a measurement from a conclusion: rising failed logins are evidence to investigate, not proof that a breach occurred.
Follow risk from scenario to action
A CRISC process begins with a business context, not a technology alert by itself. Identify the objective, the process and information involved, and the people who depend on them. Describe a risk event in a way that links a cause to an impact. “Credential theft may allow unauthorized changes to payment instructions” is more decision-useful than “the identity platform is risky.” Define assessment criteria so likelihood and impact can be compared with the organization’s tolerance.
Separate inherent risk from residual risk. Inherent risk describes exposure before considering controls; residual risk is what remains after controls are considered. A control design may be appropriate on paper but ineffective in operation. Look at evidence such as access reviews, configuration history, test results, incidents, or monitoring records. Use evidence to decide whether risk assumptions and control confidence are still valid.
A risk register should support ownership and follow-through. A useful entry describes the scenario, business impact, inherent and residual assessment, existing controls, owner, response decision, action plan, due date, and monitoring indicator. It should be clear which facts are measured and which estimates are judgments. If the record is stale, lacks an owner, or uses inconsistent scales, a dashboard can make uncertainty look more precise than it is.
Worked risk-to-control path
Suppose a company plans a customer data warehouse. The risk team identifies unauthorized access to exported data and incomplete deletion after analytics use. Governance assigns the data owner and risk approval authority. Assessment identifies the data flows, provider access, retention, threats, impact, and existing controls. Response owners compare minimization, access limits, deletion verification, and contract terms against risk criteria. Reporting tracks unresolved actions and evidence that deletion works. Technology and Security verifies architecture, logging, lifecycle controls, and operational monitoring. The risk professional documents the residual risk and ensures the authorized business owner makes any acceptance decision.
This path explains why domains overlap without becoming interchangeable. Governance determines accountability and criteria; assessment explains exposure; response chooses and monitors treatment; technology and security evaluates the systems and controls that deliver it. If a question describes a control failure, ask what the scenario requests: identify a risk, select treatment, report an exception, or evaluate a technology practice. The task word points to the best domain lens.
Use metrics that can change a decision
CRISC candidates should know the difference between a key risk indicator and a control-performance measure. A risk indicator can show whether exposure is changing; a control metric describes whether a safeguard is operating. A count of open critical vulnerabilities may show exposure, while the percentage of systems patched within a target window measures response performance. Neither number is self-explanatory. Define the population, data source, threshold, owner, reporting interval, and escalation action.
Before presenting a risk dashboard, validate the data and aggregation method. Combining systems with very different business impacts into one average can hide a critical outlier. A heatmap is a communication aid, not a replacement for scenario detail. Explain what changed, why the change matters, who owns the response, and what decision is needed. If the data are incomplete, say so and identify the next validation step.
Expand the study sequence with active practice
During the first pass through the outline, make a compact concept map for each domain. Governance connects strategy, risk appetite, roles, and enterprise risk. Assessment connects scenarios, threats, vulnerabilities, likelihood, impact, and residual risk. Response and Reporting connects treatment, ownership, controls, action plans, metrics, and communication. Technology and Security connects architecture, development, operations, data, security, and resilience to risk objectives. Use the map to retrieve relationships rather than memorize isolated headings.
A useful weekly cycle has three passes. First, learn a task from the outline and explain it without notes. Second, solve a short scenario and identify the decision owner and evidence. Third, return after a delay and solve a new variation. Keep an error log with the reasoning mistake and an action. For example, “I chose transfer before analyzing what contract and operational exposure remained” leads to a targeted review of response options, not another general reading block.
For the final preparation stage, work mixed scenarios under time limits and revisit weak tasks. Compare your reasoning with the official materials and record any ambiguous terminology for follow-up. Make sure your practice source aligns with the 2025 outline. A score from a third-party question set is a trend for that set; it is not a conversion to ISACA’s scaled score. Readiness is stronger when you can justify an answer and explain why the distractors fail.
How the exam works
The 2026 ISACA Candidate Guide lists 150 multiple-choice questions in four hours, delivered by computer at an authorized PSI test center or remotely where available. The public format does not identify a CAT exam, hands-on lab, or performance task. Questions may describe business and technology situations that require selecting a risk or control decision. Use the current guide for navigation, breaks, delivery, identification, and other rules.
The 240 minutes average 96 seconds per question. This is a pacing calculation, not an official deadline for each item. Read the qualifier, identify the requested role and action, and avoid adding facts that the scenario does not state. If an option jumps to a tool before the risk is assessed, or accepts risk without an authorized owner, examine whether another choice better fits the stated process.
Original worked question
A business process owner wants to connect a customer platform to a new analytics vendor. The risk assessment finds that the vendor retains exported data after the service ends. The contract owner says the clause is standard and asks the risk team to approve it. What should the CRISC professional recommend first? A. Approve the connection because the vendor's contract is standard. B. Clarify the data and business exposure, evaluate treatment against the organization's criteria, and obtain a documented decision from the authorized risk owner. C. Purchase cyber insurance and treat the issue as transferred. D. Block all vendor access permanently.
Best answer: B. The organization needs to understand the actual exposure and evaluate options under its risk process, with an accountable owner making the decision. A standard contract does not prove that retention is acceptable. Insurance may cover some financial effects but does not resolve data handling or obligations. A permanent block is premature without analyzing the business need and feasible treatments.
Registration, cost, and results
Register through an ISACA account and schedule after paying the exam fee. The 2026 Candidate Guide lists US$575 for members and US$760 for nonmembers. Registration is continuous, with a six-month eligibility period after payment; appointments may be scheduled as early as 48 hours later. Confirm PSI center or remote availability, language, and date before paying. The guide says fees are nonrefundable and nontransferable, although eligible rescheduling at least 48 hours in advance is permitted.
ISACA scores on a common 200-to-800 scale. A score of 450 or higher passes. This is not a raw percentage or a claim that a fixed number of answers correct will pass. The guide says exams include scored and pretest questions; pretest items do not count and are not identified to candidates. Domain-level feedback is informational and is not used as a separate pass threshold.
Candidates see a preliminary status after testing and receive an official score report through MyISACA and email, generally within 10 working days. Retakes require the full fee and follow the four-attempt rolling 12-month limit: a 30-day wait after attempt one, then 90 days after attempts two and three. A failed candidate may request a US$75 rescore within 30 days of result release.
Exam eligibility and certification experience
ISACA lets candidates take CRISC before meeting the certification experience requirement. To earn the credential, applicants need at least three years of professional information systems auditing, control, or security work across at least two of the four CRISC domains. The work must fall within the ten years before the application. ISACA's current CRISC requirements do not list experience waivers or substitutions.
Apply within five years after passing. ISACA requires a supervisor or manager to verify experience and charges a one-time US$50 application processing fee. Applicants also agree to the Code of Professional Ethics and CPE Policy. A candidate who passes early should track the application deadline and build a documented record of risk, control, assessment, response, and reporting responsibilities.
A practical study plan
Start with the official 2025 outline and take a diagnostic set across all domains. For each miss, identify whether you lacked knowledge, chose the wrong risk owner, skipped assessment, confused a control with a treatment decision, or misread the qualifier. This classification determines the next study action better than another broad reading session.
A six-week structure can work for a candidate with a foundation in IT or risk. In week one, map Governance and the risk framework. In week two, study Risk Assessment, including scenarios, business impact, and inherent versus residual risk. Weeks three and four focus on Risk Response and Reporting, the largest domain: treatment, control design, ownership, suppliers, monitoring, and reporting. Week five covers Technology and Security, followed by mixed-domain practice. Week six emphasizes timed questions, explanation review, and remaining gaps.
Adjust the schedule to your background. An auditor may need to focus on operational technology and risk response ownership. A technical project manager may need governance, assessment methods, and risk reporting. Someone who manages enterprise risk may need to connect general risk concepts to information systems controls and technology lifecycles. Do not assume experience in one domain covers the entire blueprint.
Use original scenarios and legitimate practice resources. For each answer, explain why it fits the business context and why the alternatives are weaker. Mixed questions test whether you can recognize the risk-management lens without being told which domain to use. A practice percentage is diagnostic for that resource; it is not an official conversion to the 450 scaled passing score.
Certification maintenance
After certification, holders must earn and report at least 20 CPE hours each year and 120 over a three-year period, with activity related to CRISC knowledge or job tasks. The annual maintenance fee is US$45 for members and US$85 for nonmembers, due by January 1. ISACA may audit reported CPE, and holders must retain evidence. Credential holders also follow the Code of Professional Ethics.
CRISC can support risk and control work, but does not guarantee a job, salary, or a specific level of authority. Its value depends on how a professional applies risk reasoning, supports clear ownership, selects proportionate controls, and communicates uncertainties. A credential demonstrates that ISACA's requirements have been met; the organization still decides who may approve a risk.
Choose a useful next step
If you need a quick orientation, use the official outline and this guide. For a targeted question, focus on eligibility, registration, fees, scoring, domains, study materials, or certification application. Match every study resource to the 2025 outline and keep the distinction clear between passing the exam and earning the CRISC designation.
Common questions
How many questions are on the CRISC exam?
The exam has 150 multiple-choice questions and four hours of testing time.
What is the CRISC passing score?
A scaled score of 450 or higher on ISACA's 200-to-800 scale passes. It is not a raw percentage.
Can I take CRISC before I have experience?
Yes. ISACA permits candidates to sit before meeting the experience requirement. Certification requires three years of relevant work across at least two domains.
What are the current CRISC domains?
Governance (26%), Risk Assessment (22%), Risk Response and Reporting (32%), and Technology and Security (20%) under the 2025 outline.
Does passing the CRISC exam make me certified?
No. Submit an application with verified experience within five years, pay the US$50 application fee, and meet ISACA's ethics and maintenance requirements.