CRISC Eligibility: Exam and Experience Requirements
You can take the CRISC exam before meeting the experience requirement.
- To become certified, ISACA requires three years of professional information systems auditing, control, or security work across at least two of the four CRISC domains.
- Experience must be within the ten years before applying, and the application must be submitted within five years after passing.
- CRISC has no experience waivers or substitutions.
On this page8 sections
Exam eligibility is separate from certification eligibility
ISACA lets anyone with an interest in information security register for and take the CRISC exam. You do not need three years of experience to sit. The professional experience condition applies when you apply for the certification after passing. A pass can therefore come before your qualifying work is complete, but it is not the credential by itself.
To become CRISC certified, ISACA requires at least three years of professional information systems auditing, control, or security experience across at least two of the four CRISC domains. The work must be within the ten years before your application. You must apply within five years after passing the exam, and a supervisor or manager verifies the experience. The current CRISC candidate guide lists no experience waivers or substitutions.
| Stage | Requirement |
|---|---|
| Register and sit | Open to interested candidates; no experience prerequisite to take the exam |
| Certification experience | Three years of professional IS auditing, control, or security work |
| Domain coverage | Experience across at least two of the four CRISC domains |
| Experience recency | Within ten years before the application date |
| Waivers or substitutions | None listed in the 2026 ISACA Candidate Guide |
| Application timing | Within five years after passing |
| Verification and fee | Supervisor or manager verification; one-time US$50 processing fee |
What the four domains mean for experience
The domains are Governance, Risk Assessment, Risk Response and Reporting, and Technology and Security. Your work should map to real tasks in at least two of these areas. Domain titles give a useful map, but the application is about responsibilities. A candidate should describe what they assessed, decided, monitored, implemented, or reported and identify the period when they did it.
Governance experience might involve aligning risk practices with strategy, defining roles, establishing risk tolerance, or connecting IT risk with enterprise risk. Risk Assessment work may include identifying scenarios, evaluating threats and vulnerabilities, assessing likelihood and impact, maintaining a risk register, or analyzing residual risk. Risk Response and Reporting can include choosing treatment, assigning risk and control owners, overseeing suppliers, testing controls, tracking action plans, or reporting metrics. Technology and Security may involve assessing architecture, operations, system development, resilience, or security practices through a risk lens.
A title such as risk analyst, IT auditor, project manager, security engineer, or compliance lead does not automatically qualify or disqualify someone. The substance of the work matters. An engineer who designs and monitors a control based on risk may have relevant control experience. A business analyst who merely records requirements without assessing or managing risk may need to explain how their work connects to the CRISC job practice.
Keep a practical record for each position: dates, employer, role, tasks, domains, supervisor or manager, and examples of accountable decisions. If duties changed materially within a role, separate the periods. Do not claim a project outcome as your responsibility if you only supported one part. Accurate wording helps the verifier confirm the experience.
How to count three years across two domains
The requirement is three years of relevant professional work and experience across at least two domains. It does not mean that each domain requires three years. A candidate could, for example, spend part of the experience in Risk Assessment and part in Risk Response and Reporting. If a single role includes both, the same calendar period remains one year of work, although it may show breadth across both domains.
Example: a professional spends three years assessing IT risk scenarios and maintaining risk registers, then supports the treatment plan process by helping control owners test mitigations and report residual risk. These duties may demonstrate Risk Assessment and Risk Response and Reporting coverage, depending on the actual work and verification. The application should describe the tasks rather than simply state the names of two domains.
A different candidate has six years installing network controls but no documented assessment, risk governance, monitoring, or control evaluation responsibilities. The calendar total exceeds three years, but the candidate should determine whether the real duties fit one or more CRISC domains. They should not rename routine configuration as enterprise risk management. If needed, pursue responsibilities that genuinely involve risk identification, assessment, treatment, reporting, or control assurance.
There are no CRISC experience waivers
The 2026 ISACA Candidate Guide states that the CRISC experience requirement has no waivers or substitutions. Candidates should plan to document the full three years of qualifying work. A degree or another credential does not replace this experience under the current published summary. This differs from ISACA certifications that list their own waiver policies, so do not transfer another exam's rules to CRISC.
The practical implication is that passing early does not shorten the work period. It simply completes the exam component while you continue developing experience. If you already have three years, prepare the verification details before or soon after the exam. If you do not, map the gaps and discuss opportunities with a supervisor to take on real risk and control responsibilities.
Track the five-year and ten-year windows
Two timing rules matter. You must apply within five years after passing. Your qualifying experience must be in the ten-year period before you apply. If you pass well before meeting the experience requirement, note the pass date and set reminders well before the application deadline. If older work is approaching the ten-year boundary, verify whether it remains eligible on the planned application date.
Suppose you pass on October 15, 2026, with only two years of qualifying work. You may continue accumulating the third year and apply later, but the pass-to-application window continues to run. The exact deadline should be confirmed in MyISACA. A reminder one year before expiry gives time to complete work, collect verification, and submit without a last-minute scramble.
Three eligibility examples
IT auditor with risk-control duties
A candidate has three years reviewing IT risk assessments, validating controls, and tracking remediation. The work appears to span Risk Assessment and Risk Response and Reporting. The candidate can sit the exam at any time, then should document dates and responsibilities and ask a supervisor or manager to verify them. The application still depends on ISACA's review.
Project manager with technology risk
A project manager has four years delivering system changes. Some duties involve assessing project risks, tracking control requirements, and reporting unresolved exposure to an authorized owner. Those parts may be relevant; simply coordinating schedules may not establish CRISC experience. The candidate should describe the risk and control responsibilities precisely, then have an appropriate manager verify them.
Candidate who passed first
A professional with one year of qualifying work passes the CRISC exam. They may continue building work experience and apply later, within five years of the pass. They should not use CRISC after their name as a certified designation until the application is approved. A passing result is proof of the exam result, not a certification grant.
Application preparation
After official results are released, submit the application through MyISACA and pay the one-time US$50 fee. ISACA requires experience verification by a supervisor or manager. Prepare a concise work history with employer, position, dates, domain coverage, and task examples. If a verifier changed jobs, identify someone else who can substantiate both dates and responsibilities.
The application is not just a resume. Make the connection between your duties and the CRISC job practice explicit. 'Worked on security' is too broad. 'Assessed likelihood and impact for application risks, maintained the register, and presented treatment status to process owners' makes the nature of the work clearer. Keep a record of the application and any follow-up from ISACA.
Certification also requires adherence to ISACA's Code of Professional Ethics and Continuing Professional Education Policy. Once certified, holders maintain the designation through CPE and an annual maintenance fee. Those are post-certification obligations and do not replace the initial three-year experience requirement.
Common eligibility mistakes
- Waiting to sit because you think three years are required before the exam; the experience rule applies to certification.
- Assuming a degree or another credential can substitute; the current guide lists no CRISC waiver or substitution.
- Counting years without documenting work across at least two domains.
- Treating a job title as proof that work is in the CRISC job practice.
- Forgetting that experience must be within the ten years before applying.
- Applying more than five years after passing or assuming a pass alone grants the credential.
A clear eligibility decision comes from a simple timeline and task map. Record when you will sit, when the five-year application window ends, and where each qualifying work period fits. Identify at least two domains with actual responsibilities and a verifier. That lets you decide whether to apply now or continue gaining relevant work without confusing exam eligibility with certification eligibility.
Common questions
Can I take the CRISC exam without experience?
Yes. ISACA allows candidates to sit before meeting the experience requirement. Experience is required to earn the certification after passing.
How much experience do I need for CRISC certification?
Three years of professional information systems auditing, control, or security work across at least two CRISC domains.
Can I use a degree or another certification as a CRISC waiver?
The 2026 Candidate Guide states that CRISC has no experience waivers or substitutions.
How long after passing can I apply?
You must submit the CRISC certification application within five years after passing. The experience must be within the ten years before applying.
Does passing the CRISC exam make me certified?
No. You must submit an approved experience application, pay the US$50 processing fee, and satisfy ISACA's professional requirements.