Most candidates think the CISA exam is the main obstacle. That assumption is the #1 reason qualified people fail to get certified. The real trap isn't the 150 questions; it's the experience verification form you fill out after you pass.
The CISA certification requires passing a 150-question exam, accumulating five years of verified IS audit, control, assurance, or security experience, and adhering to the ISACA Code of Ethics. Experience can be reduced by up to three years with substitutions for education, other ISACA certifications (like CISM), or non-ISACA certifications (like CISSP).
Key facts
- Official Body: ISACA (Information Systems Audit and Control Association)
- Exam Format: 150 multiple-choice questions over 4 hours
- Passing Score: 450 on a scaled score of 200-800
- Experience Required: 5 years (with substitutions), gained within 10 years pre-application or 5 years post-exam
- Application Deadline: Within 5 years of passing the exam
- Governing Standards: ISACA 2024 Job Practice domains, COBIT principles, and NIST standards
What Are the Core CISA Requirements?
Earning your CISA credential involves successfully navigating four distinct pillars: passing the exam, demonstrating sufficient work experience, formally applying for certification, and adhering to the ISACA Code of Professional Ethics. While you can sit for the exam at any point, the full certification is only granted once you've met all criteria.
This structured approach ensures CISA holders possess both theoretical knowledge and practical expertise. It also means you must plan for the long term. After certification, you must adhere to the Continuing Professional Education (CPE) policy to maintain your credential, which requires reporting a minimum of 20 CPE hours annually and 120 hours over a three-year period.
Studying for CISA? Benchmark your score in 5 minutes.
Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.
Ready to see if you're thinking like an auditor? Try VoraPrep's free CISA practice questions to test your judgment.
What Are the CISA Education and Certification Waivers?
There is no mandatory degree to sit for the CISA exam, but your educational and professional background can significantly reduce the five-year work experience requirement.
The myth is that only a computer science degree counts. The reality is that ISACA offers a flexible system of waivers for degrees, other professional certifications, and even specific types of non-audit experience. However, a hard cap exists: a maximum of three years can be waived in total, regardless of how many qualifications you hold.
Degree-Based Waivers
- Two-Year Waiver: Granted for a bachelor's degree from an accredited university.
- One-Year Waiver: Granted for an associate's degree or 60-120 semester credit hours.
Other Substitutions (Certifications & Experience)
You can substitute one year of experience for one of the following:- One year of full-time experience in general information systems (non-audit).
- One year of full-time experience in financial or operational auditing.
- A master's degree in a related field like Information Security or Information Technology from an accredited university.
Additionally, certain professional certifications provide waivers:
- One-Year Waiver: For certifications like a CISSP or CPA.
- Two-Year Waiver: For other ISACA certifications like CISM, CRISC, or CGEIT.
What Does the CISA Exam Entail?
The CISA exam is a single, four-hour test comprising 150 multiple-choice questions designed to assess your competence across the five CISA Job Practice domains.
The exam is not a test of memorization. The myth is that you can pass by cramming definitions from the CISA Review Manual. The reality, as reflected in the 50-55% pass rate, is that the exam tests judgment. Questions are scenario-based, forcing you to choose the best course of action from a list of plausible options, mirroring the thinking process of a seasoned IS auditor.
To pass, you must achieve a scaled score of 450 or higher on a scale of 200-800. This is a standardized score, not a raw percentage, ensuring fairness across different exam forms. If you don't pass, you can retake the exam up to three more times in a 12-month period, waiting 30 days between attempts and paying the full fee each time. For a deeper dive into the exam's structure, see our CISA Exam Study Guide (2026): Domains, Pass Rates, Strategy.
How Does the CISA Experience Requirement Work?
ISACA requires five years of professional experience in IS audit, control, assurance, or security, which can be reduced to as little as two years with the waivers discussed above.
The 10-Year and 5-Year Windows
Your experience must meet one of two timing criteria:- Gained within the 10-year period before you submit your certification application.
- Gained within the 5-year period after you pass the exam.
This flexibility allows you to pass the exam first and then accumulate the necessary experience.
The Real Trap: Describing Your Experience
The most common failure point isn't a lack of experience; it's failing to describe it correctly on the verification form. ISACA reviewers are looking for evidence of specific audit-related tasks.The myth is that your job title (e.g., "IT Security Manager") is enough. The reality is that the verbs you use to describe your duties are what matter. Your verifier must attest that you performed tasks aligned with the CISA domains.
Calculate Your CISA Study Hours by Domain
See the exact domain-by-domain study breakdown reflecting the 2024 ISACA Job Practice weighting shifts.
Let's look at Maria, an IT Security Analyst.
- Weak Description (Likely to be Questioned): "Responsible for network security. Managed firewalls and antivirus software. Handled user access requests and system patching."
- Why it's weak: These are operational IT tasks. They don't demonstrate audit, control, or assurance functions.
- Strong Description (Likely to be Approved): "Audited firewall rule sets for compliance with corporate policy. Assessed the effectiveness of antivirus controls through periodic testing. Evaluated and tested user access control procedures to ensure segregation of duties. Verified that system patching processes were operating effectively and met security benchmarks."
- Why it's strong: It uses verbs directly from the auditor's lexicon—audited, assessed, evaluated, tested, verified. This reframes the same job duties through the lens of control and assurance, which is exactly what ISACA needs to see.
Before you apply, review your job descriptions and translate your operational duties into the language of audit and control.
What Is the Total Cost to Get CISA Certified?
The total investment to become a CISA typically ranges from $950 to over $2,500, depending on your membership status and choice of study materials.
Becoming an ISACA member first is the single best way to reduce costs. The exam discount for members is greater than the cost of membership itself.
Here is a typical cost breakdown for 2026 (all figures are approximate and subject to change by ISACA):
| Item | ISACA Member | Non-Member | Notes |
|---|---|---|---|
| ISACA Membership (Annual + New Member) | $155 | N/A | Professional membership is $145/year + $10 one-time fee. |
| CISA Exam Registration | $575 | $760 | The $185 member discount makes membership a clear financial win. |
| Certification Application Fee | $50 | $50 | A one-time fee paid after you pass the exam. |
| Subtotal (ISACA Fees) | $780 | $810 | |
| VoraPrep Review Course (1-year access) | + $199 | + $199 | A crucial investment given the exam's difficulty. |
| Total Estimated Investment | $979 | $1,009 |
For a more detailed analysis, read our CISA Exam Cost Breakdown (2026): ISACA Membership, Exam Registration & Prep. If you're on a tight budget, our guide to CISA Review Courses Under $500 2026 can help you find value.
Are CISA Requirements Different by State or Country?
No, the CISA requirements are identical worldwide.
The myth, often held by those familiar with state-licensed credentials like the CPA, is that requirements vary by jurisdiction. The reality is that CISA is a global certification administered by a single international body, ISACA. Whether you are in California, Germany, or Japan, the exam, experience requirements, and ethical code are exactly the same. This global standardization is a key reason for the CISA's widespread international recognition and value.
How Do I Get Started on the CISA Path?
Follow these steps to build a structured and effective plan.
- Assess Your Experience Gap. Go to the official ISACA CISA page. This week, create a spreadsheet listing your job roles, dates, and key responsibilities. Map them to the experience waivers to calculate exactly how many months of experience you still need.
- Join ISACA. The financial benefit is clear. Sign up for a Professional or Student membership to unlock the exam discount and access member-only study resources.
- Select a Review Course. A high-quality prep course is not optional for most candidates. VoraPrep's adaptive platform, with over 2,300 practice questions and our 24/7 Vory tutor, is designed to build the critical judgment skills the exam demands. Explore our CISA course details.
- Register and Schedule the Exam. Once you've committed to a study plan, register for the exam via the ISACA website. You can then schedule your test at a convenient time and location through the Pearson VUE testing service.
- Pass the Exam. Focus your study on why a control is the best choice in a given scenario, not just on what the control is.
- Submit Your Application. After you receive your passing score, complete the CISA Application for Certification. Ensure your experience verifiers understand they are confirming your audit and assurance functions, not just your IT duties.
---
Ready to Pass Your CISA Exam? Don't leave your CISA certification to chance. VoraPrep provides the tools you need to succeed, with an adaptive learning engine, over 2,300 practice questions, and 24/7 AI tutor support. Our program is designed to teach you how to think like the examiner, not just memorize answers. Visit voraprep.com to get started and experience the VoraPrep difference. Start Your Free 14-Day Trial at voraprep.com →