CISA Exam · 15 min read Updated

CISA Exam Changes 2026: What Candidates Need to Know

Rob Pfleghardt

10-year PwC alumnus · Founder of VoraPrep · Previously CPA-licensed

CISA Exam Changes 2026: What Candidates Need to Know

Key Takeaways

  • - Blueprint Focus: Heavy emphasis on AI, cloud computing, and modern cybersecurity threats, requiring application of auditor judgment.
  • New Domain Weightings: This is the most visible update, and it’s a direct signal from ISACA about where your focus should be.
  • This is the factual correction that most candidates miss.
  • The percentage shifts are only part of the story.
  • This is where judgment, not memorization, earns you a passing score.

You see the 2026 CISA exam changes and think, "Minor tweaks. The five domains are still there." That assumption is the #1 reason qualified, experienced candidates will fail this year. The real trap isn't a change in format; it's the fundamental shift in mindset and content depth, where ISACA has redefined what a competent IS auditor must know about AI ethics, cloud-native architecture, and modern cybersecurity threats. Merely knowing the definitions is no longer enough; you must be able to apply auditor judgment to them.

Quick answer

The 2026 CISA exam updates the blueprint with a heavy focus on AI, cloud, and modern cybersecurity. Critically, the domain weightings have shifted: Domain 1 decreased to 18%, while Domains 2, 3, and 4 increased. The format of 150 questions in 4 hours and the 450/800 passing score remain the same.

The CISA exam has a <50% pass rate.

VoraPrep's AI finds your weak spots before the exam does — adaptive practice that actually moves your score.

Try Free →

Key facts

  • Blueprint Focus: Heavy emphasis on AI, cloud computing, and modern cybersecurity threats, requiring application of auditor judgment.
  • Domain 1 Weighting: Decreased to 18%, signaling a reduced focus on foundational auditing processes.
  • Domains 2, 3, 4 Weighting: Increased, indicating greater importance on governance, operations, and information asset protection.
  • Exam Format: Remains 150 multiple-choice questions to be completed within 4 hours.
  • Passing Score: A scaled score of 450 out of 800 is still required to pass the exam.

Key Changes in the 2026 CISA Exam Blueprint: A Deeper Look

Let's get straight to the point. ISACA has updated the CISA Job Practice Analysis (JPA) to reflect the real-world demands on auditors today. This isn't just a fresh coat of paint. Ignoring the implications of these changes is a direct path to a failing score.

New Domain Weightings: This is the most visible update, and it’s a direct signal from ISACA about where your focus should be. The reduction in Domain 1 and the increases elsewhere mean your study time must be reallocated. Spending 21% of your time on Domain 1, as you would have before, now means you're neglecting more heavily tested areas. Emerging Tech is Now Core: Topics like AI governance, cloud security, and DevOps audit are no longer specialized footnotes or a single question at the end of a chapter. They are central to the exam and integrated across all five domains. You won't just be asked what a CI/CD pipeline is; you'll be asked how to audit its security controls. Your ability to answer these questions correctly depends on a platform with up-to-date content. Try VoraPrep's free CISA practice questions to see the difference. Modern Security is Mandatory: Your knowledge must reflect the end of the traditional network perimeter. You must demonstrate judgment on concepts like Zero Trust architecture, supply chain risk management (think SolarWinds), and API security. If your study material talks more about firewalls than identity and access management (IAM) as a primary control, it's dangerously outdated. Outdated Materials are a Liability: Relying solely on pre-2026 study guides is a critical mistake. They have the wrong domain weightings, lack the necessary depth on new task statements, and will leave you completely unprepared for at least 15-20% of the exam questions. This is not an exam you can pass by being mostly prepared. Who is Affected? If your exam is scheduled for on or after January 1, 2026, you will sit for the new exam. There is no grace period.

The 2026 CISA Domain Weightings: What Really Changed

This is the factual correction that most candidates miss. The domain percentages have changed. Sticking to an old study plan means you'll be over-studying a less important domain and under-prepared for others where ISACA has added significant depth.

Here is the official CISA exam domain weighting for 2026:

CISA Exam Domain2026 WeightingChange from PriorApprox. Questions
Domain 1: The Process of Auditing Information Systems18%▼ Down from 21%~27
Domain 2: Governance and Management of IT18%▲ Up from 17%~27
Domain 3: Information Systems Acquisition, Development, and Implementation14%▲ Up from 12%~21
Domain 4: Information Systems Operations and Business Resilience24%▲ Up from 23%~36
Domain 5: Protection of Information Assets26%▼ Down from 27%~39
Total100%150

The takeaway is clear: the 3% reduction in Domain 1 is significant. That's roughly 4-5 questions' worth of emphasis shifted directly to Domains 2, 3, and 4—the areas most impacted by new technology, governance challenges, and modern development practices. Your study plan must reflect this reality.

What Has NOT Changed in 2026?

Amid the updates, the exam's foundation remains solid, which is good news. You don't have to relearn everything.

  • Question Count and Format: Still 150 multiple-choice questions, each with four possible answers.
  • Exam Duration: Still 4 hours (240 minutes), averaging 1.6 minutes per question.
  • Passing Score: The scaled score of 450 out of 800 is unchanged.
  • Core Mission: The exam still validates your ability to apply a risk-based approach to audit, control, and provide assurance on information systems.

A Domain-by-Domain Breakdown of the New Focus Areas

The percentage shifts are only part of the story. The real challenge—and where candidates will pass or fail—is mastering the new task and knowledge statements within each domain.

Domain 1: The Process of Auditing Information Systems (18%)

With its reduced weight, the focus here is less on rote memorization of the ISACA IT Audit and Assurance Framework (ITAF) and more on applying it to modern contexts. You need to demonstrate that you can plan and execute an audit in a technologically complex environment.
  • New Emphasis: Auditing in agile/DevOps environments, using data analytics for continuous auditing, and assessing risk for cloud service providers (CSPs).
  • Exam Scenario You'll See: You might be asked to identify the best sampling technique when auditing logs from a cloud-based serverless application, where transaction volumes are highly variable. The answer will test your understanding of statistical vs. non-statistical sampling in a non-traditional context.
  • Study Tip: Don't just read the ITAF standards. Think about how you would apply Standard 1204 (Professional Judgment) when an organization has no formal documentation for its cloud environment but relies on Infrastructure as Code (IaC) scripts. A solid foundation is still essential, as covered in our CISA Information Systems Auditing Process Cheat Sheet (2026).

Domain 2: Governance and Management of IT (18%)

This domain's increased weight reflects the growing importance of strategic oversight in a world of complex regulations and high-stakes technology. It's no longer just about IT steering committees; it's about enterprise-level risk management.
  • New Emphasis: Data governance (especially regarding privacy regulations like GDPR and CCPA), supply chain risk management, and the governance of emerging technologies like AI and machine learning.
  • Exam Scenario You'll See: A question might describe a company using a third-party AI service for credit scoring and ask for the greatest risk. The answer won't be about system uptime; it will be about the risk of inherited bias from the vendor's training data, demonstrating your grasp of modern supply chain and AI ethical risks.
  • Study Tip: Move beyond just knowing COBIT's principles. Understand how to apply the NIST Cybersecurity Framework (CSF) to a hybrid-cloud environment or how to evaluate an organization's framework for Explainable AI (XAI).

Domain 3: Information Systems Acquisition, Development, and Implementation (14%)

The significant 2% jump here points to a decisive shift from auditing traditional waterfall SDLC to auditing modern Agile and DevOps practices. This is a major stumbling block for auditors with more traditional backgrounds.
  • New Emphasis: Auditing CI/CD pipelines, assessing security controls for Infrastructure as Code (IaC) (e.g., Terraform, CloudFormation), evaluating API security, and understanding the due diligence for acquiring a Software-as-a-Service (SaaS) solution.
  • Exam Scenario You'll See: You could be asked to evaluate the controls in a CI/CD pipeline. The correct answer would involve identifying the need for Static Application Security Testing (SAST) tools early in the development cycle and Dynamic Application Security Testing (DAST) tools in the testing phase, before deployment.
  • Study Tip: If you can't explain the difference between a container and a virtual machine or what a secret management tool like HashiCorp Vault does, you have a critical knowledge gap in this domain. Our CISA IS Acquisition, Development & Implementation Cheat Sheet (2026) can help bridge this gap.

Domain 4: Information Systems Operations and Business Resilience (24%)

This domain has expanded to fully embrace cloud and hybrid environments. Your knowledge must go far beyond traditional on-premise data centers to include the operational realities of cloud services.
  • New Emphasis: The cloud shared responsibility model, container security (Docker, Kubernetes), disaster recovery in the cloud (multi-region vs. multi-availability zone), and Cloud Security Posture Management (CSPM).
  • Exam Scenario You'll See: A question will test your understanding of the shared responsibility model by asking who is responsible for patching the operating system of an EC2 instance on AWS. (Answer: The customer). The trick is that for a serverless service like AWS Lambda, the answer would be the cloud provider. You must know the difference.
  • Study Tip: Focus on the "how," not just the "what." How do you audit the resilience of an application using auto-scaling groups and multiple availability zones? How do you gain assurance that data is being properly encrypted at rest within a cloud object storage service? Our CISA IS Operations and Business Resilience Cheat Sheet (2026) is a great quick reference.

Domain 5: Protection of Information Assets (26%)

Though its weight was slightly reduced, this remains the largest and most technically demanding domain. It's packed with modern security concepts that reflect today's threat landscape.
  • New Emphasis: Zero Trust architecture, Secure Access Service Edge (SASE), modern Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms, and advanced identity and access management (IAM).
  • Exam Scenario You'll See: You'll be asked to identify the most effective control to prevent lateral movement by an attacker within a corporate network. The outdated answer is network segmentation with firewalls. The 2026 answer is the implementation of a Zero Trust architecture that authenticates and authorizes every request, regardless of its origin.
  • Study Tip: "Identity is the new perimeter" is the core concept. Master modern authentication methods (MFA, FIDO2), privileged access management (PAM), and the principles of least privilege as applied to cloud IAM roles and policies. Mastering these concepts requires practice on questions aligned with the 2026 blueprint's focus on modern tech.

Worked Example: Auditing an AI-Powered System (2026 Thinking)

This is where judgment, not memorization, earns you a passing score. The CISA exam is designed to test your ability to prioritize risk.

Scenario: You are the lead IS auditor for a regional bank that has just implemented a new AI-driven system to approve small business loan applications. Management claims it will reduce bias and speed up decisions. What is the most important initial step in your audit plan?
  1. A) Verify that the servers hosting the AI model are in a physically secure data center with appropriate environmental controls.
  2. B) Review the end-user training materials for the loan officers who will be interacting with the new system's output.
  3. C) Assess the governance framework established for the AI system, including data sources, model validation processes, and ongoing performance monitoring.
  4. D) Confirm that the system's source code is securely stored in a version control repository with strict access controls.
Analysis:
  • The Tempting Wrong Answer is (A). Why? Because physical security is a classic, fundamental IT audit control. It's in every textbook. It feels safe and correct. For a traditional application, it's a high priority. But for an AI system, the biggest risks aren't someone stealing a server; they are strategic, ethical, and reputational. This answer shows a pre-2026 mindset.
  • Why (B) and (D) are insufficient: User training and source code control are important tactical controls. They are absolutely part of a comprehensive audit plan. However, they are not the most important initial step. You can have perfect source code control and great user training, but if the underlying AI model is a "black box" making biased and incorrect decisions, the bank is exposed to enormous regulatory and reputational risk. These are secondary concerns.
  • The Correct (2026) Answer is (C). This is the "think like the examiner" approach. The unique and highest risks of AI are strategic: biased training data leading to discriminatory lending, a lack of transparency making it impossible to explain decisions to customers or regulators, and "model drift" where the AI's performance degrades over time. A strong governance framework is the primary control to mitigate these foundational risks. Your first step as an auditor is to determine if management has even considered these issues. This question tests your understanding of modern risk prioritization, not just your memory of an old control checklist.

The adaptive learning engine at VoraPrep is designed specifically to drill you on these judgment calls. It identifies where you're relying on outdated thinking and serves you questions that force you to analyze risk in a modern context. You can compare VoraPrep's features to other providers to see the difference.

Your Action Plan: A Checklist for CISA Candidates

Whether you're halfway through your studies or just starting, here’s your plan to conquer the 2026 exam.

For Candidates Already Studying for a 2026 Exam:

  • [ ] Download the Official Blueprint: Go to the ISACA website and get the 2026 CISA Exam Content Outline. This is your non-negotiable source of truth.
  • [ ] Conduct a Ruthless Gap Analysis: Print the new outline. Go through it line-by-line and compare it to your current study material's table of contents. Use a highlighter to mark every new task statement or knowledge area (e.g., "Knowledge of techniques used to audit blockchain applications"). Be honest about your weak spots.
  • [ ] Supplement Your Resources Strategically: You must fill those gaps. This is where a continuously updated platform is critical. A resource like VoraPrep's CISA course is fully aligned with the 2026 blueprint and can provide the targeted practice you need on topics your textbook glosses over.
  • [ ] Reallocate Your Study Time Immediately: Adjust your schedule to match the new domain weightings. If you were planning to spend 3 weeks on Domain 1, cut it to two and a half and add that time to Domain 3 or 4.

For Candidates Starting Their CISA Journey Now:

  • [ ] Invest in 2026-Ready Materials from Day One: Do not buy a used 2023 textbook to save money. It's a recipe for failure and will cost you more when you have to pay the exam retake fee. Start with a review course or question bank explicitly advertised for the 2026 exam.
  • [ ] Build a Modern Study Plan: Don't just divide your time by domain percentage. If your background is in traditional finance audit and you're weak in cybersecurity, you need to allocate significantly more time to Domain 5, even though its weight slightly decreased. Our 90-Day CISA Study Plan (2026) provides a great structure.
  • [ ] Prioritize Judgment-Based Practice: From day one, focus on why an answer is correct in a given scenario. The 24/7 Vory AI tutor in VoraPrep is designed for this, providing instant, detailed explanations for every question, helping you build the critical thinking skills the exam demands.

Frequently asked questions

Will my old CISA study materials work for the 2026 exam? No. While foundational concepts remain, pre-2026 materials are dangerously incomplete. They lack the required depth on new task statements for AI governance, cloud security, and Zero Trust, and they reflect outdated domain weightings. Using them is a significant risk. Are the 2026 CISA exam changes making the test harder? The exam's scope has expanded to reflect more complex technologies, which may make it feel more challenging. It demands deeper judgment on current topics, not just memorization of legacy controls. For auditors already working with modern tech, it will feel more relevant and fair. Is the ISACA CISA Review Manual (CRM) 27th Edition still valid for the 2026 exam? The CRM 27th Edition was aligned with the previous exam blueprint. While it contains valuable foundational knowledge, it is not sufficient on its own for the 2026 exam. ISACA typically releases an updated manual (e.g., a 28th Edition) to align with a new Job Practice. Always check the ISACA bookstore for the most current version. What is the single biggest topic to focus on for the 2026 CISA exam? While all domains are critical, the most significant evolution is in applying modern security concepts. A deep, practical understanding of zero-trust architecture, cloud security posture management (CSPM), and identity and access management (IAM) as the primary control plane is absolutely essential across multiple domains. How much more study time will the new topics require? This depends on your background. If you have extensive experience in cloud security and DevOps, the transition will be easier. For a traditional IT auditor, you should budget an additional 20-30 hours to master the new concepts in Domains 3, 4, and 5. Are there any changes to the CISA eligibility requirements in 2026? As of now, ISACA has not announced any changes to the CISA experience requirements for 2026. The requirement remains five years of professional IS audit, control, or security work experience, with various substitutions and waivers available. Always confirm the latest requirements in the official CISA Candidate Information Guide.

Official resources and references

--- Ready to Pass Your CISA Exam? Don't let the 2026 exam changes catch you off guard. VoraPrep's adaptive learning engine, 2,300+ up-to-date practice questions, and 24/7 Vory AI tutor are all aligned with the latest blueprint. We teach you to think like an examiner so you can walk into the test with confidence.

Visit voraprep.com to get started.

Start Your Free 14-Day Trial at voraprep.com →

Studying for the CISA?

Stop guessing which topics to review. VoraPrep's adaptive engine diagnoses exactly where you're losing points and rebuilds those areas. 10 minutes a day, measurable score improvement.

Start your free trial → voraprep.com
RP

About the Author: Rob Pfleghardt

Rob Pfleghardt is the founder of VoraPrep, a comprehensive exam prep platform for the CPA, CMA, EA, CIA, CISA, and CFP exams. A Virginia Tech graduate in Accounting and Finance, Rob began his career at Price Waterhouse, spending a decade in audit and IT consulting. After holding an active CPA license for 37 years (1987–2024) and successfully scaling his own enterprise IT consultancy serving the Department of Defense, Rob launched VoraPrep. He now leverages his deep systems architecture background to build the adaptive training technology and curriculum that helps candidates pass their certification exams efficiently.

Connect with Rob on LinkedIn →

Don't let this be why you retake the CISA.

Most candidates fail because they study the wrong things, not because they don't study enough. VoraPrep's AI identifies your actual weak spots and targets them — so you walk in knowing exactly where you're strong.

Start Free — No Credit Card →

Keep reading