Candidates receive an immediate preliminary pass/fail result on screen upon submitting their 150-question CISA exam at PSI testing centers or via remote proctoring. Official scaled scores (ranging from 200 to 800, with 450 required to pass) are released by ISACA within 10 business days via email and posted directly to your MyISACA account profile.
Earning the Certified Information Systems Auditor (CISA) designation from ISACA is the premier gold standard for IT audit, cybersecurity governance, and enterprise risk management professionals.
Because the CISA exam transitioned to continuous computer-based testing through PSI, candidates enjoy flexible year-round scheduling and instant preliminary score feedback. However, managing ISACA's strict annual retake limits, understanding scaled scoring across the 2024 Job Practice domains, and meeting the 5-year post-exam work experience window require clear strategic planning.
Below is the definitive, operational guide to CISA score reporting, scaled score mechanics, testing windows, and certification completion for 2026.
Studying for CISA ALL? Benchmark your score in 5 minutes.
Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.
Key facts
- Immediate Preliminary Result: Preliminary Pass or Fail appears on your computer screen immediately upon submitting the exam.
- Official Score Release Window: Within 10 business days of testing, ISACA transmits official score notifications via email and updates your MyISACA profile.
- Scaled Score Range: 200 to 800 scaled points. The minimum passing standard is 450.
- Exam Architecture: Single comprehensive examination of 150 multiple-choice questions (4 hours testing time).
- Domain Weighting (2024 Job Practice): Domain 1 (18%), Domain 2 (18%), Domain 3 (12%), Domain 4 (26%), Domain 5 (26%).
- Retake Limits: Candidates may take the exam up to four times in a rolling 365-day period.
- Work Experience Window: Candidates have 5 years from their exam passing date to satisfy and verify the 5-year professional IT audit experience requirement.
How ISACA Calculates Your Scaled Score
The CISA exam contains 150 multiple-choice questions:
- 139 Scored Questions: Used directly in calculating your performance.
- 11 Unscored Pre-Test Questions: Mixed throughout the testlet to evaluate potential future exam items without impacting your score.
The 450 Passing Benchmark
ISACA does not use raw arithmetic percentages (such as 75% correct) to determine passing. Raw scores are converted to a common 200–800 scaled score through psychometric equating:- A scaled score of 450 or higher represents passing competency as established by ISACA's working audit committees.
- A score of 800 represents a perfect scaled performance.
- A score of 200 represents the lowest possible scaled mark.
Equating ensures that candidates taking slightly more difficult versions of the exam are treated fairly, as fewer raw correct answers are required to achieve the 450 threshold on a higher-difficulty question set.
Calculate Your CISA Study Hours by Domain
See the exact domain-by-domain study breakdown reflecting the 2024 ISACA Job Practice weighting shifts.
2026 CISA Testing Availability & Score Timeline
| Milestone | Timeframe | Where to Access | Status / Notes |
|---|---|---|---|
| Exam Completion | Minute 0 | On-screen at PSI center or remote test | Preliminary Pass / Fail result displayed |
| Official Score Notification | Within 10 business days | Email from ISACA & MyISACA portal | Official Scaled Score (200–800) released |
| Domain Performance Breakdown | Delivered with official score | MyISACA "Certifications & CPE Management" | Sub-scores across Domains 1 through 5 |
| Certification Application Window | Within 5 years of passing | Online ISACA Certification Application | Verifies 5 years of professional IT audit experience |
ISACA Retake Policies & Waiting Periods
If your preliminary result is an unsuccessful attempt, ISACA enforces clear rules across a rolling 365-day window:
- Attempt 1: Initial examination.
- Attempt 2: Must wait at least 30 calendar days from the date of your first attempt.
- Attempt 3: Must wait at least 90 calendar days from the date of your second attempt.
- Attempt 4: Must wait at least 90 calendar days from the date of your third attempt.
- Annual Maximum: A maximum of 4 attempts is permitted within any rolling 365-day window. You must purchase a new exam registration fee ($575 for ISACA members, $760 for non-members) for each attempt.
Worked Example: Overcoming an Initial Miss to Secure 450+
Consider Marcus, an IT compliance analyst preparing for the CISA examination:
- March 12, 2026: Marcus sits for the CISA exam at a PSI testing center. Upon submission, his screen displays a preliminary result of Fail.
- March 22, 2026 (Day 8): Marcus receives his official email from ISACA showing an official scaled score of 420 (30 points short of 450).
- Analyzing the Domain Breakdown: His sub-scores reveal strong performance in Domain 1 (Auditing Process: 510) and Domain 2 (IT Governance: 480), but severe deficits in Domain 4 (Operations: 380) and Domain 5 (Asset Protection: 390). Because Domains 4 and 5 represent 52% of total exam points, weakness here caused his failure.
- The Retake Plan: Marcus must wait 30 days (earliest retest: April 12, 2026). He uses VoraPrep CISA review to drill 700 adaptive practice questions specifically covering disaster recovery, incident response, network cryptography, and access controls.
- May 5, 2026: Marcus sits for Attempt 2. His preliminary screen immediately flashes Pass. Within 7 business days, his official score posts at 535.
Completing the 5-Year Work Experience Requirement
Passing the CISA exam is step one. To formally use the CISA credential, you must satisfy ISACA's professional experience requirement:
- General Requirement: A minimum of 5 years (60 months) of professional work experience in information systems auditing, control, or security.
- Experience Waivers: You can substitute up to a maximum of 3 years of experience through qualifying waivers:
- 1 year for 60 to 120 completed college semester hours (associate or bachelor's degree).
- 2 years for a completed master's degree in information security, accounting, or information technology.
- 1 or 2 years for related non-IS audit or IT experience.
- 5-Year Lookahead Window: You have 5 full years from the date you pass the exam to complete and document this experience. If 5 years elapse without certification approval, your exam pass expires.
PSI Test Center Logistics: Remote Online Proctoring vs. In-Person Testing
ISACA candidates can choose between in-person testing at a commercial PSI center or remote proctoring from a private home or office:
- In-Person Testing: Arrive 30 minutes before your scheduled appointment. PSI administrators verify two forms of government ID, conduct a physical security inspection (pockets, eyeglasses), and assign a locked workstation.
- Remote Online Proctoring: Requires a private room with closed doors, an uninterrupted high-speed internet connection, and an external webcam capable of performing a 360-degree room scan. Work surfaces must be completely clear of papers, dual monitors, or books.
- Unscheduled Breaks: You may take unscheduled breaks during the 4-hour session, but the examination timer continues to run. During remote proctoring, leaving the webcam frame requires proctor acknowledgment and triggers a full room re-inspection.