Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

CRISC Renewal and Continuing Professional Education

Updated 7 min read
Key takeaway

CRISC holders must earn and report at least 20 CPE hours each year and 120 over a three-year reporting period.

  • The annual fee is US$45 for members or US$85 for nonmembers, due by January 1.
  • Record relevant activities in MyISACA, retain evidence, follow the Code of Professional Ethics, and respond if selected for a CPE audit.
On this page9 sections
  1. CRISC renewal requirements at a glance
  2. What CPE activities are relevant
  3. Report and apply activities in MyISACA
  4. Pay the annual maintenance fee
  5. Keep evidence for a possible audit
  6. Ethics, status, and consequences
  7. A realistic annual routine
  8. Career value and its limits
  9. CRISC maintenance checklist

CRISC renewal requirements at a glance

After earning CRISC, maintain it by earning and reporting at least 20 CPE hours each year and 120 hours during each three-year reporting period. The activities should maintain knowledge or ability related to CRISC tasks. Pay an annual maintenance fee of US$45 if an ISACA member or US$85 if a nonmember. The fee is due by January 1 for renewal through the upcoming calendar year.

Maintenance requirementCurrent rule
Annual CPE minimumAt least 20 hours
Three-year totalAt least 120 CRISC-related hours
Annual fee, memberUS$45
Annual fee, nonmemberUS$85
Payment dateJanuary 1 for the upcoming calendar year
Record retention12 months after the end of a three-year reporting cycle
Professional conductISACA Code of Professional Ethics

What CPE activities are relevant

Relevant CPE develops the knowledge or ability needed to perform CRISC-related work. ISACA lists learning through conferences, webinars, online and on-demand courses, training, skills-based labs, professional activities, and volunteer contributions. Each category has rules and limits in the current CPE policy. The activity must fit a qualifying category and connect to IT risk, systems controls, assessment, response, reporting, or related professional duties.

A CRISC holder might attend a seminar on third-party risk, study a new control framework, complete training on cloud risk assessment, teach a session on risk reporting, or contribute to professional guidance. A general event is not automatically relevant because it contains the word technology. Be able to explain how the activity supports CRISC knowledge or job performance.

ISACA's current maintenance page lists up to 36 free CPE per year from webinars and online training and up to 20 free per year from volunteering, among other options. Those are maximum opportunities, not automatic credits. Review the current policy for how hours are calculated and reported, including any limits on reading, teaching, or professional contributions.

Report and apply activities in MyISACA

Sign in to MyISACA and open Certifications and CPE Management. Activities through ISACA may appear as preloaded hours, but the holder still needs to apply them to the CRISC record. Activities from chapters and other providers may need to be self-reported with the title, sponsor, date, qualifying activity, and hours.

After entering an activity, verify that it appears against CRISC rather than only in an unapplied list. If a professional activity is relevant to multiple ISACA certifications, the same hours may count toward each when the activity supports the job-related knowledge of each credential. Do not assume that one entry automatically satisfies every designation.

Use a calendar reminder each quarter to compare annual progress and the three-year total. The two requirements are separate: 120 hours across the cycle does not excuse a year below the 20-hour minimum. Likewise, earning 20 hours each year for three years produces only 60, not the required 120. Track both totals and plan additional learning early.

Pay the annual maintenance fee

ISACA says the annual CRISC maintenance fee is due by January 1 and renews the certification through the upcoming calendar year. Invoice notifications start in September for the following year, and payment is available in the certification dashboard. The listed fee is US$45 for members and US$85 for nonmembers.

Holders with more than two ISACA certifications pay a reduced annual amount for the third and each additional credential: US$25 for members or US$50 for nonmembers, according to the maintenance page. This rate is for annual maintenance, not the initial exam registration or certification application. Review the account invoice for membership status and the number of active certifications.

Payment and CPE reporting are separate conditions. Paying the maintenance fee does not satisfy the learning requirement. Reporting 120 hours does not clear an unpaid fee. Confirm both the account's fee status and CPE totals before the year ends.

Keep evidence for a possible audit

ISACA randomly selects certification holders for CPE audits. If selected, holders must provide documentation for the reported activity year. The current CRISC maintenance page says to retain documents for 12 months after the end of each three-year reporting cycle. A record should include attendee, sponsoring organization, activity title and description, date, and CPE hours awarded or claimed.

Keep a certificate, attendance roster, provider letter, verification form, or another independent attestation of completion. Save it in a folder indexed by year and add a ledger entry that shows how the activity relates to CRISC. A calendar event or a credit card receipt alone may not prove attendance, content, or duration.

If ISACA selects you, follow the audit instructions and deadline. Failure to provide supporting evidence can result in revocation. Report only hours permitted under the relevant activity category and keep details accurate. Organized records make an audit manageable and discourage claiming time from an activity that does not qualify.

Ethics, status, and consequences

CRISC holders agree to ISACA's Code of Professional Ethics. Failure to meet CPE or fee requirements can result in revocation. Once revoked, a person cannot present themselves as an active CRISC holder. ISACA's status options include non-practicing and retired status for people who qualify; these are formal categories with their own rules, not automatic exemptions during a career break.

ISACA describes an appeal path for reinstatement after CPE-related revocation. If approved, the holder must pay outstanding maintenance fees and a US$50 reinstatement fee for each credential. If the appeal is denied, returning to active status may require retaking and passing the exam and reapplying with the appropriate experience. Keeping a calendar and reporting hours is simpler than trying to restore a revoked certification.

A realistic annual routine

  1. January: confirm that the annual maintenance fee shows as paid and set a CPE target above the 20-hour floor.
  2. Each quarter: complete relevant learning, record it, apply preloaded hours, and save independent proof.
  3. Midyear: compare the year's hours with the minimum and the three-year total with the 120-hour requirement.
  4. September: review the coming year's invoice and confirm membership and multi-certification pricing.
  5. Before year end: self-report outside activities and confirm the account shows them under CRISC.
  6. At the end of each three-year cycle: verify each year's minimum, the 120-hour total, and retain records for the following 12 months.

Suppose a holder reports 28 hours in year one and 42 in year two. Year three still needs at least 20 and the cycle needs 120 total, so at least 50 additional hours are required across the remaining period. Extra hours in one year can contribute to the total but cannot replace a later year's minimum. Check the rolling account totals as well as your own ledger.

Career value and its limits

CPE keeps a CRISC holder engaged with changing risk and control practices. It can strengthen the ability to interpret new technology, supplier, security, and resilience exposures. The designation does not guarantee employment, pay, or authority to accept business risk. Practical experience and organizational governance remain important.

If you hold multiple credentials, choose learning that is genuinely relevant to each and apply hours under each policy. A cloud-risk seminar may support CRISC and a security credential; a general business event may not. Review each designation's policy and record the basis rather than assuming one universal total covers everything.

CRISC maintenance checklist

  • Earn and report at least 20 qualifying CPE hours every year.
  • Reach at least 120 CRISC-related hours during the three-year period.
  • Pay the annual fee by January 1 and check any member or multi-certification reduction.
  • Apply ISACA-preloaded CPE and self-report external activities in MyISACA.
  • Retain proof with the date, activity, sponsor, description, and credit amount.
  • Respond to a CPE audit if selected and follow the Code of Professional Ethics.
  • Apply for non-practicing or retired status only if you meet the separate requirements.

Renewal is manageable when it is part of regular professional recordkeeping. Keep a relevant learning calendar, report hours as you earn them, save the evidence, and confirm the account each quarter. The process supports both an active credential and continued competence in IT risk and controls.

Common questions

How many CPE hours does CRISC require?

At least 20 hours each year and 120 hours during a three-year reporting period, related to CRISC knowledge or tasks.

What is the CRISC annual maintenance fee?

ISACA lists US$45 for members and US$85 for nonmembers, due by January 1. Reduced fees apply to the third and additional ISACA certifications under the policy.

How long should I keep CRISC CPE records?

ISACA says to retain supporting records for 12 months following the end of each three-year reporting cycle.

Can one CPE activity count for multiple ISACA credentials?

Yes, if the activity is applicable to the job-related knowledge of each credential and is reported according to each policy.

What happens if I fail a CPE audit?

Failure to comply with an audit can lead to revocation. ISACA has an appeal process, but reinstatement depends on its approval and may require fees or retesting.