CISA Exam · 10 min read Updated

CISA Requirements 2026: Education, Experience & Fees

Rob Pfleghardt

10-year Price Waterhouse alumnus · Founder of VoraPrep · Former CPA (1987–2024) · with the VoraPrep Editorial Team

CISA Requirements 2026: Education, Experience & Fees

Key Takeaways

  • Your application's success hinges on describing your work experience using ISACA's preferred verbs (e.g., "evaluated," "assessed," "audited") not just IT operational terms.
  • A maximum of three years of the five-year experience requirement can be waived through a combination of university degrees and specific professional certifications.
  • Passing the exam is just one of four pillars; you must also meet experience requirements, submit the application, and adhere to the ISACA Code of Ethics.
  • Becoming an ISACA member before registering for the exam saves you approximately $185, which more than covers the cost of membership itself.
  • The CISA requirements are globally uniform, meaning there are no state-by-state variations, simplifying the process for international professionals.

Most candidates think the CISA exam is the main obstacle. That assumption is the #1 reason qualified people fail to get certified. The real trap isn't the 150 questions; it's the experience verification form you fill out after you pass.

Quick answer

The CISA certification requires passing a 150-question exam, accumulating five years of verified IS audit, control, assurance, or security experience, and adhering to the ISACA Code of Ethics. Experience can be reduced by up to three years with substitutions for education, other ISACA certifications (like CISM), or non-ISACA certifications (like CISSP).

Key facts

  • Official Body: ISACA (Information Systems Audit and Control Association)
  • Exam Format: 150 multiple-choice questions over 4 hours
  • Passing Score: 450 on a scaled score of 200-800
  • Experience Required: 5 years (with substitutions), gained within 10 years pre-application or 5 years post-exam
  • Application Deadline: Within 5 years of passing the exam
  • Governing Standards: ISACA 2024 Job Practice domains, COBIT principles, and NIST standards

What Are the Core CISA Requirements?

Earning your CISA credential involves successfully navigating four distinct pillars: passing the exam, demonstrating sufficient work experience, formally applying for certification, and adhering to the ISACA Code of Professional Ethics. While you can sit for the exam at any point, the full certification is only granted once you've met all criteria.

This structured approach ensures CISA holders possess both theoretical knowledge and practical expertise. It also means you must plan for the long term. After certification, you must adhere to the Continuing Professional Education (CPE) policy to maintain your credential, which requires reporting a minimum of 20 CPE hours annually and 120 hours over a three-year period.

Free 5-Min Diagnostic

Studying for CISA? Benchmark your score in 5 minutes.

Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.

Ready to see if you're thinking like an auditor? Try VoraPrep's free CISA practice questions to test your judgment.

What Are the CISA Education and Certification Waivers?

There is no mandatory degree to sit for the CISA exam, but your educational and professional background can significantly reduce the five-year work experience requirement.

The myth is that only a computer science degree counts. The reality is that ISACA offers a flexible system of waivers for degrees, other professional certifications, and even specific types of non-audit experience. However, a hard cap exists: a maximum of three years can be waived in total, regardless of how many qualifications you hold.

Degree-Based Waivers

  • Two-Year Waiver: Granted for a bachelor's degree from an accredited university.
  • One-Year Waiver: Granted for an associate's degree or 60-120 semester credit hours.

Other Substitutions (Certifications & Experience)

You can substitute one year of experience for one of the following:
  • One year of full-time experience in general information systems (non-audit).
  • One year of full-time experience in financial or operational auditing.
  • A master's degree in a related field like Information Security or Information Technology from an accredited university.

Additionally, certain professional certifications provide waivers:

  • One-Year Waiver: For certifications like a CISSP or CPA.
  • Two-Year Waiver: For other ISACA certifications like CISM, CRISC, or CGEIT.
Important: All experience substitutions must have been gained within the 10-year period preceding your application date.

What Does the CISA Exam Entail?

The CISA exam is a single, four-hour test comprising 150 multiple-choice questions designed to assess your competence across the five CISA Job Practice domains.

The exam is not a test of memorization. The myth is that you can pass by cramming definitions from the CISA Review Manual. The reality, as reflected in the 50-55% pass rate, is that the exam tests judgment. Questions are scenario-based, forcing you to choose the best course of action from a list of plausible options, mirroring the thinking process of a seasoned IS auditor.

To pass, you must achieve a scaled score of 450 or higher on a scale of 200-800. This is a standardized score, not a raw percentage, ensuring fairness across different exam forms. If you don't pass, you can retake the exam up to three more times in a 12-month period, waiting 30 days between attempts and paying the full fee each time. For a deeper dive into the exam's structure, see our CISA Exam Study Guide (2026): Domains, Pass Rates, Strategy.

How Does the CISA Experience Requirement Work?

ISACA requires five years of professional experience in IS audit, control, assurance, or security, which can be reduced to as little as two years with the waivers discussed above.

The 10-Year and 5-Year Windows

Your experience must meet one of two timing criteria:
  1. Gained within the 10-year period before you submit your certification application.
  2. Gained within the 5-year period after you pass the exam.

This flexibility allows you to pass the exam first and then accumulate the necessary experience.

The Real Trap: Describing Your Experience

The most common failure point isn't a lack of experience; it's failing to describe it correctly on the verification form. ISACA reviewers are looking for evidence of specific audit-related tasks.

The myth is that your job title (e.g., "IT Security Manager") is enough. The reality is that the verbs you use to describe your duties are what matter. Your verifier must attest that you performed tasks aligned with the CISA domains.

✨ Free Domain Calculator

Calculate Your CISA Study Hours by Domain

See the exact domain-by-domain study breakdown reflecting the 2024 ISACA Job Practice weighting shifts.

Calculate CISA Study Plan →
Worked Example: Experience Description

Let's look at Maria, an IT Security Analyst.

  • Weak Description (Likely to be Questioned): "Responsible for network security. Managed firewalls and antivirus software. Handled user access requests and system patching."
  • Why it's weak: These are operational IT tasks. They don't demonstrate audit, control, or assurance functions.
  • Strong Description (Likely to be Approved): "Audited firewall rule sets for compliance with corporate policy. Assessed the effectiveness of antivirus controls through periodic testing. Evaluated and tested user access control procedures to ensure segregation of duties. Verified that system patching processes were operating effectively and met security benchmarks."
  • Why it's strong: It uses verbs directly from the auditor's lexicon—audited, assessed, evaluated, tested, verified. This reframes the same job duties through the lens of control and assurance, which is exactly what ISACA needs to see.

Before you apply, review your job descriptions and translate your operational duties into the language of audit and control.

What Is the Total Cost to Get CISA Certified?

The total investment to become a CISA typically ranges from $950 to over $2,500, depending on your membership status and choice of study materials.

Becoming an ISACA member first is the single best way to reduce costs. The exam discount for members is greater than the cost of membership itself.

Here is a typical cost breakdown for 2026 (all figures are approximate and subject to change by ISACA):

ItemISACA MemberNon-MemberNotes
ISACA Membership (Annual + New Member)$155N/AProfessional membership is $145/year + $10 one-time fee.
CISA Exam Registration$575$760The $185 member discount makes membership a clear financial win.
Certification Application Fee$50$50A one-time fee paid after you pass the exam.
Subtotal (ISACA Fees)$780$810
VoraPrep Review Course (1-year access)+ $199+ $199A crucial investment given the exam's difficulty.
Total Estimated Investment$979$1,009
Cost-Saving Tip: If you are a full-time university student, ISACA Student Membership is only $30, offering a significant path to savings.

For a more detailed analysis, read our CISA Exam Cost Breakdown (2026): ISACA Membership, Exam Registration & Prep. If you're on a tight budget, our guide to CISA Review Courses Under $500 2026 can help you find value.

Are CISA Requirements Different by State or Country?

No, the CISA requirements are identical worldwide.

The myth, often held by those familiar with state-licensed credentials like the CPA, is that requirements vary by jurisdiction. The reality is that CISA is a global certification administered by a single international body, ISACA. Whether you are in California, Germany, or Japan, the exam, experience requirements, and ethical code are exactly the same. This global standardization is a key reason for the CISA's widespread international recognition and value.

How Do I Get Started on the CISA Path?

Follow these steps to build a structured and effective plan.

  1. Assess Your Experience Gap. Go to the official ISACA CISA page. This week, create a spreadsheet listing your job roles, dates, and key responsibilities. Map them to the experience waivers to calculate exactly how many months of experience you still need.
  2. Join ISACA. The financial benefit is clear. Sign up for a Professional or Student membership to unlock the exam discount and access member-only study resources.
  3. Select a Review Course. A high-quality prep course is not optional for most candidates. VoraPrep's adaptive platform, with over 2,300 practice questions and our 24/7 Vory tutor, is designed to build the critical judgment skills the exam demands. Explore our CISA course details.
  4. Register and Schedule the Exam. Once you've committed to a study plan, register for the exam via the ISACA website. You can then schedule your test at a convenient time and location through the Pearson VUE testing service.
  5. Pass the Exam. Focus your study on why a control is the best choice in a given scenario, not just on what the control is.
  6. Submit Your Application. After you receive your passing score, complete the CISA Application for Certification. Ensure your experience verifiers understand they are confirming your audit and assurance functions, not just your IT duties.

---

Ready to Pass Your CISA Exam? Don't leave your CISA certification to chance. VoraPrep provides the tools you need to succeed, with an adaptive learning engine, over 2,300 practice questions, and 24/7 AI tutor support. Our program is designed to teach you how to think like the examiner, not just memorize answers. Visit voraprep.com to get started and experience the VoraPrep difference. Start Your Free 14-Day Trial at voraprep.com →

Frequently asked questions

Do I need a specific degree to get the CISA? No, a specific degree is not mandatory. While relevant degrees can waive up to three years of the five-year experience requirement, you can still qualify through work experience alone. ISACA's flexible substitution policy also recognizes other professional certifications. How long do I have to apply for certification after passing the CISA exam? You have a five-year window from your exam pass date to submit the CISA application and meet all the experience requirements. If you miss this deadline, your passing exam score will be voided. Can I take the exam before meeting the experience requirement? Yes. You are encouraged to take the exam as soon as you feel prepared. You can then use the five years after passing to accumulate and document the required professional experience. Are the CISA requirements different in India, the UK, or Canada? No. The CISA requirements are globally uniform. ISACA sets a single standard for the exam, experience, and ethics that applies to all candidates regardless of their location.
⚡ Instant Knowledge Check · 1-Click Test Drive
CISA Domain 5: Protection of Information Assets

When conducting an IS audit of an enterprise cloud infrastructure environment, which of the following identity and access management (IAM) findings represents the GREATEST information security risk?

Official resources and references

RP

About the Author: Rob Pfleghardt

Rob Pfleghardt is the founder of VoraPrep, a comprehensive exam prep platform for the CPA, CMA, EA, CIA, CISA, and CFP exams. A Virginia Tech graduate in Accounting and Finance, Rob began his career at Price Waterhouse, spending a decade in audit and IT consulting. After holding a CPA license for 37 years (1987–2024) and successfully scaling his own enterprise IT consultancy serving the Department of Defense, Rob launched VoraPrep. He now leverages his deep systems architecture background to build the adaptive training technology and curriculum that helps candidates pass their certification exams efficiently.

Connect with Rob on LinkedIn →
Free Diagnostic Assessment

Find your exact CISA weak spots in 10 minutes.

Most candidates fail because they study blindly. Take our free 10-question diagnostic to identify your weakest blueprint topics and receive a custom 12-week study plan PDF generated instantly.

Keep reading

Free 5-min CISA diagnostic + 12-week plan PDF

Start →
CISA 1:1 Prometric Simulator

2,300+ practice questions with instant Socratic feedback