CRISC Certification Requirements After the Exam
After passing CRISC, apply within five years and document three years of professional information systems auditing, control, or security work across at least two of the four domains.
- Experience must fall within the ten years before applying and be verified by a supervisor or manager.
- ISACA charges a one-time US$50 processing fee; CRISC has no experience waivers or substitutions.
On this page9 sections
- Passing the exam is not the certification
- What CRISC experience looks like
- Three years across at least two domains
- No experience waivers or substitutions
- The two application time windows
- Prepare the application and experience verification
- Three candidate examples
- Professional obligations after approval
- After-exam checklist
Passing the exam is not the certification
CRISC has two milestones: pass the exam, then qualify for and complete the certification application. ISACA permits candidates to sit before they have accumulated experience, so the exam result can come first. The CRISC designation is not awarded until the experience is reviewed and the application is approved. A test result does not authorize you to use the credential after your name.
| Application condition | Current CRISC requirement |
|---|---|
| Exam | Pass within the five years before the application |
| Relevant work | Three years in professional information systems auditing, control, or security work |
| Domain coverage | Experience across at least two of four CRISC domains |
| Recency | Work is within the ten years before applying |
| Waivers/substitutions | None listed for CRISC in the 2026 Candidate Guide |
| Verification | A supervisor or manager verifies experience |
| Application fee | One-time US$50 processing fee after the official result |
What CRISC experience looks like
Qualifying experience connects to the CRISC job practice: Governance, Risk Assessment, Risk Response and Reporting, and Technology and Security. The work may involve identifying risk scenarios, analyzing likelihood or business impact, designing or evaluating controls, advising owners on treatment, monitoring remediation, or communicating risk and control status. The application should make your actual contribution clear.
A job title does not determine eligibility. A risk analyst may perform relevant professional work, but the role description alone does not prove it. A software engineer may have CRISC-related duties if they assess risks and controls, while a person called 'risk manager' may need to show what they actually manage. Document tasks, periods, and the domains they support.
For example, an IT auditor may assess control design, test operations, report deficiencies, and follow remediation. A security engineer may analyze threats and vulnerabilities, evaluate controls, and monitor residual exposure. A project manager may document and escalate risks, but routine schedule coordination alone may not establish information systems audit, control, or security experience. Describe the work accurately and connect it to the job practice tasks.
Three years across at least two domains
The requirement is three years of relevant professional work and coverage across at least two of the four domains. It does not require three years in each domain. Your work can span multiple domains during a period, but the calendar period is counted once. Build a role-by-role map that shows the tasks and evidence for each area.
A candidate who spent two years assessing risks and one year managing treatment plans may demonstrate Risk Assessment and Risk Response and Reporting coverage. Another candidate may have three years evaluating technology controls and risk governance. The application should show what decisions, testing, analysis, or reporting the person performed rather than simply listing two domain names.
If your experience appears concentrated in one area, do not rename the work to create domain breadth. Identify genuine responsibilities that connect to another domain. A technology control review may include risk assessment and response if you assessed exposure, evaluated a treatment, and reported residual risk. The actual duties and verifier evidence matter.
No experience waivers or substitutions
The 2026 ISACA Candidate Guide states CRISC has no experience waivers or substitutions. A degree, another ISACA credential, or a different certification should not be counted toward the three-year CRISC requirement unless ISACA updates the policy. Candidates must document the full period of qualifying work across the required domains.
This is a useful distinction when planning across multiple credentials. Other ISACA certifications may allow their own waivers, but their policies do not transfer to CRISC. A candidate who passed early should continue gaining relevant professional experience and keep a record of the dates and tasks.
The two application time windows
The exam pass must be within five years of the application. The qualifying experience must be within the ten years before the application date. These windows are separate. If you pass before reaching three years, track the pass date and make a realistic plan to qualify and submit before that deadline.
Suppose you pass on November 10, 2026, with two years of relevant experience. You need another qualifying year and must apply within five years of passing. As you approach that application date, check whether all work periods remain within the ten-year lookback. Use the exact dates in MyISACA and leave time for verifier follow-up rather than waiting until the last month.
Prepare the application and experience verification
After the official score is released, pay the one-time US$50 application processing fee and submit through MyISACA. ISACA requires a supervisor or manager to verify the work. Before starting, prepare employer names, position names, start and end dates, a summary of responsibilities, and contact details for the verifier.
A concise evidence file might have one section for each role. Include the CRISC tasks performed, domain coverage, decisions supported, control or risk evidence, and the verifier who can confirm the work. For example, 'evaluated access-control findings for the payment platform and reported residual risk to the service owner' is more informative than 'worked on payment security.'
Choose a verifier who can confirm both dates and duties. A supervisor may not have worked with you for every period, particularly after a transfer or departure. If a former manager is unavailable, identify another appropriate manager able to verify the work. Keep submitted records and any ISACA follow-up correspondence.
Do not disclose confidential client or employer information unnecessarily. Describe responsibilities at a level that supports verification while respecting internal policy. Be accurate about your own contribution: if you advised a risk owner, do not claim you accepted the risk; if you tested part of a control, do not claim you designed the whole program.
Three candidate examples
Candidate who already has relevant experience
A professional has four years reviewing IT controls, assessing risks, and tracking remediation. They pass CRISC and apply. The application should show at least three years of work within the ten-year window and evidence that duties span at least two domains. A supervisor or manager verifies the record. The candidate should not treat four calendar years alone as proof if the work description lacks relevant tasks.
Candidate who passes early
A new security analyst has one year of relevant work and passes the exam. They may continue building experience, but are not yet certified. They should track the five-year application window and seek responsibilities that develop real risk assessment, control, and reporting experience. They should not use the CRISC designation until ISACA approves the application.
Candidate with a long but narrow role
An infrastructure administrator has six years managing network equipment. They may have relevant control or security tasks, but must also demonstrate experience across at least two CRISC domains. If duties were limited to routine configuration, the candidate should not assume all years qualify. Map actual responsibilities and discuss gaps with a supervisor before applying.
Professional obligations after approval
CRISC holders agree to ISACA's Code of Professional Ethics and Continuing Professional Education Policy. They maintain the credential through at least 20 CPE hours each year and 120 over a three-year period, along with an annual maintenance fee. These are ongoing obligations after approval, separate from the initial experience application.
CRISC is a professional certification rather than a government-issued license. Employers and regulators may require additional experience, approval, or qualifications for particular work. The designation demonstrates that ISACA's certification requirements have been met; it does not grant authority to approve risk in every organization.
After-exam checklist
- Record the official pass date and the five-year application deadline.
- Map at least three years of qualifying work to two or more CRISC domains.
- Check that experience is within ten years of the planned application date.
- Do not apply waivers or substitutions; CRISC does not list them.
- Select a supervisor or manager who can verify the work.
- Pay the US$50 application processing fee and submit through MyISACA.
- Review CPE, maintenance fee, and ethics obligations after certification approval.
Certification follows both an exam and a verified professional record. Keep those milestones separate, describe your work precisely, and submit within the required time windows. That gives ISACA clear evidence to review and prevents a passing score from being mistaken for full certification.
Common questions
What are the CRISC certification requirements after passing?
Apply within five years, show three years of qualifying professional work across at least two domains, have a supervisor or manager verify the experience, pay the US$50 fee, and meet ISACA's professional requirements.
Does CRISC require experience before the exam?
No. You can sit before meeting the experience requirement, but certification requires the work experience after passing.
Can I use education or another certification as a CRISC waiver?
No. The 2026 Candidate Guide lists no CRISC experience waivers or substitutions.
How long after passing can I apply for CRISC?
You must apply within five years of passing. Qualifying experience must be within the ten years before your application.
What is the CRISC application fee?
ISACA lists a one-time US$50 application processing fee after official results are released.