CISA Exam · 7 min read 2026 Blueprint Verified

CISA Exam Score Release Dates & Testing Windows (2026): Official Guide

Rob Pfleghardt

10-year Price Waterhouse alumnus · Founder of VoraPrep · Former CPA (1987–2024) · with the VoraPrep Editorial Team

Key Takeaways

  • Immediate Preliminary Result: Preliminary Pass or Fail appears on your computer screen immediately upon submitting the exam.
  • Official Score Release Window: Within 10 business days of testing, ISACA transmits official score notifications via email and updates your MyISACA profile.
  • Scaled Score Range: 200 to 800 scaled points. The minimum passing standard is 450.
  • Exam Architecture: Single comprehensive examination of 150 multiple-choice questions (4 hours testing time).
  • Domain Weighting (2024 Job Practice): Domain 1 (18%), Domain 2 (18%), Domain 3 (12%), Domain 4 (26%), Domain 5 (26%).
  • Retake Limits: Candidates may take the exam up to four times in a rolling 365-day period.
Quick answer

Candidates receive an immediate preliminary pass/fail result on screen upon submitting their 150-question CISA exam at PSI testing centers or via remote proctoring. Official scaled scores (ranging from 200 to 800, with 450 required to pass) are released by ISACA within 10 business days via email and posted directly to your MyISACA account profile.

Earning the Certified Information Systems Auditor (CISA) designation from ISACA is the premier gold standard for IT audit, cybersecurity governance, and enterprise risk management professionals.

Because the CISA exam transitioned to continuous computer-based testing through PSI, candidates enjoy flexible year-round scheduling and instant preliminary score feedback. However, managing ISACA's strict annual retake limits, understanding scaled scoring across the 2024 Job Practice domains, and meeting the 5-year post-exam work experience window require clear strategic planning.

Below is the definitive, operational guide to CISA score reporting, scaled score mechanics, testing windows, and certification completion for 2026.

Free 5-Min Diagnostic

Studying for CISA ALL? Benchmark your score in 5 minutes.

Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.

Key facts

  • Immediate Preliminary Result: Preliminary Pass or Fail appears on your computer screen immediately upon submitting the exam.
  • Official Score Release Window: Within 10 business days of testing, ISACA transmits official score notifications via email and updates your MyISACA profile.
  • Scaled Score Range: 200 to 800 scaled points. The minimum passing standard is 450.
  • Exam Architecture: Single comprehensive examination of 150 multiple-choice questions (4 hours testing time).
  • Domain Weighting (2024 Job Practice): Domain 1 (18%), Domain 2 (18%), Domain 3 (12%), Domain 4 (26%), Domain 5 (26%).
  • Retake Limits: Candidates may take the exam up to four times in a rolling 365-day period.
  • Work Experience Window: Candidates have 5 years from their exam passing date to satisfy and verify the 5-year professional IT audit experience requirement.

How ISACA Calculates Your Scaled Score

The CISA exam contains 150 multiple-choice questions:

  • 139 Scored Questions: Used directly in calculating your performance.
  • 11 Unscored Pre-Test Questions: Mixed throughout the testlet to evaluate potential future exam items without impacting your score.

The 450 Passing Benchmark

ISACA does not use raw arithmetic percentages (such as 75% correct) to determine passing. Raw scores are converted to a common 200–800 scaled score through psychometric equating:
  • A scaled score of 450 or higher represents passing competency as established by ISACA's working audit committees.
  • A score of 800 represents a perfect scaled performance.
  • A score of 200 represents the lowest possible scaled mark.

Equating ensures that candidates taking slightly more difficult versions of the exam are treated fairly, as fewer raw correct answers are required to achieve the 450 threshold on a higher-difficulty question set.

✨ Free Domain Calculator

Calculate Your CISA Study Hours by Domain

See the exact domain-by-domain study breakdown reflecting the 2024 ISACA Job Practice weighting shifts.

Calculate CISA Study Plan →

2026 CISA Testing Availability & Score Timeline

MilestoneTimeframeWhere to AccessStatus / Notes
Exam CompletionMinute 0On-screen at PSI center or remote testPreliminary Pass / Fail result displayed
Official Score NotificationWithin 10 business daysEmail from ISACA & MyISACA portalOfficial Scaled Score (200–800) released
Domain Performance BreakdownDelivered with official scoreMyISACA "Certifications & CPE Management"Sub-scores across Domains 1 through 5
Certification Application WindowWithin 5 years of passingOnline ISACA Certification ApplicationVerifies 5 years of professional IT audit experience

ISACA Retake Policies & Waiting Periods

If your preliminary result is an unsuccessful attempt, ISACA enforces clear rules across a rolling 365-day window:

  1. Attempt 1: Initial examination.
  2. Attempt 2: Must wait at least 30 calendar days from the date of your first attempt.
  3. Attempt 3: Must wait at least 90 calendar days from the date of your second attempt.
  4. Attempt 4: Must wait at least 90 calendar days from the date of your third attempt.
  5. Annual Maximum: A maximum of 4 attempts is permitted within any rolling 365-day window. You must purchase a new exam registration fee ($575 for ISACA members, $760 for non-members) for each attempt.

Worked Example: Overcoming an Initial Miss to Secure 450+

Consider Marcus, an IT compliance analyst preparing for the CISA examination:

  • March 12, 2026: Marcus sits for the CISA exam at a PSI testing center. Upon submission, his screen displays a preliminary result of Fail.
  • March 22, 2026 (Day 8): Marcus receives his official email from ISACA showing an official scaled score of 420 (30 points short of 450).
  • Analyzing the Domain Breakdown: His sub-scores reveal strong performance in Domain 1 (Auditing Process: 510) and Domain 2 (IT Governance: 480), but severe deficits in Domain 4 (Operations: 380) and Domain 5 (Asset Protection: 390). Because Domains 4 and 5 represent 52% of total exam points, weakness here caused his failure.
  • The Retake Plan: Marcus must wait 30 days (earliest retest: April 12, 2026). He uses VoraPrep CISA review to drill 700 adaptive practice questions specifically covering disaster recovery, incident response, network cryptography, and access controls.
  • May 5, 2026: Marcus sits for Attempt 2. His preliminary screen immediately flashes Pass. Within 7 business days, his official score posts at 535.

Completing the 5-Year Work Experience Requirement

Passing the CISA exam is step one. To formally use the CISA credential, you must satisfy ISACA's professional experience requirement:

  • General Requirement: A minimum of 5 years (60 months) of professional work experience in information systems auditing, control, or security.
  • Experience Waivers: You can substitute up to a maximum of 3 years of experience through qualifying waivers:
  • 1 year for 60 to 120 completed college semester hours (associate or bachelor's degree).
  • 2 years for a completed master's degree in information security, accounting, or information technology.
  • 1 or 2 years for related non-IS audit or IT experience.
  • 5-Year Lookahead Window: You have 5 full years from the date you pass the exam to complete and document this experience. If 5 years elapse without certification approval, your exam pass expires.

PSI Test Center Logistics: Remote Online Proctoring vs. In-Person Testing

ISACA candidates can choose between in-person testing at a commercial PSI center or remote proctoring from a private home or office:

  • In-Person Testing: Arrive 30 minutes before your scheduled appointment. PSI administrators verify two forms of government ID, conduct a physical security inspection (pockets, eyeglasses), and assign a locked workstation.
  • Remote Online Proctoring: Requires a private room with closed doors, an uninterrupted high-speed internet connection, and an external webcam capable of performing a 360-degree room scan. Work surfaces must be completely clear of papers, dual monitors, or books.
  • Unscheduled Breaks: You may take unscheduled breaks during the 4-hour session, but the examination timer continues to run. During remote proctoring, leaving the webcam frame requires proctor acknowledgment and triggers a full room re-inspection.

Frequently asked questions

Can a preliminary "Pass" on the CISA exam be reversed upon official score release?

In over 99.9% of cases, the preliminary result matches the official score. Preliminary results are subject to final forensic auditing by ISACA to detect software irregularities, candidate collusion, or test security breaches. Unless a security violation occurred, your preliminary result is completely reliable.

What is the most common reason candidates fail the CISA exam?

The most common reason is underestimating Domain 4 (Operations and Business Resilience) and Domain 5 (Protection of Information Assets). Together, these two domains account for 52% of the examination. Candidates who focus excessively on basic audit procedures (Domain 1) while ignoring technical cloud security, disaster recovery metrics (RTO/RPO), and cryptography often score below 450.

Where can I schedule my CISA exam appointment?

After purchasing your exam registration through the MyISACA portal, you will receive an Eligibility ID. You use this ID to schedule either an in-person session at a local PSI testing center or an online remotely proctored appointment via the PSI online scheduling platform.

How much does it cost to retake the CISA exam?

Every exam attempt requires paying the full registration fee. For ISACA members, the fee is $575; for non-members, the fee is $760. Avoiding retakes through rigorous practice testing is the single most impactful way to control your certification budget.

Does ISACA provide paper score reports by mail?

No. ISACA communicates all examination results electronically. Official score reports are sent to your registered email address and can be accessed or printed anytime through your account at isaca.org.
⚡ Instant Knowledge Check · 1-Click Test Drive
CISA Domain 5: Protection of Information Assets

When conducting an IS audit of an enterprise cloud infrastructure environment, which of the following identity and access management (IAM) findings represents the GREATEST information security risk?

Official resources and references

RP

About the Author: Rob Pfleghardt

Rob Pfleghardt is the founder of VoraPrep, a comprehensive exam prep platform for the CPA, CMA, EA, CIA, CISA, and CFP exams. A Virginia Tech graduate in Accounting and Finance, Rob began his career at Price Waterhouse, spending a decade in audit and IT consulting. After holding a CPA license for 37 years (1987–2024) and successfully scaling his own enterprise IT consultancy serving the Department of Defense, Rob launched VoraPrep. He now leverages his deep systems architecture background to build the adaptive training technology and curriculum that helps candidates pass their certification exams efficiently.

Connect with Rob on LinkedIn →
Free Diagnostic Assessment

Find your exact CISA weak spots in 10 minutes.

Most candidates fail because they study blindly. Take our free 10-question diagnostic to identify your weakest blueprint topics and receive a custom 12-week study plan PDF generated instantly.

Keep reading

Free 5-min CISA diagnostic + 12-week plan PDF

Start →
CISA 1:1 Prometric Simulator

2,300+ practice questions with instant Socratic feedback