ISACA CISA

CISA Exam Guide: Domains, Format, Scoring, and Experience

A complete reference for the ISACA CISA exam: the five domains and their weights, the 150-question four-hour format, how the 200-800 scaled score and 450 pass mark work, the five-year experience requirement and its waivers, fees, and retake rules.

Last verified:

What is the CISA exam and how does it work?

The CISA exam is ISACA's Certified Information Systems Auditor test: 150 multiple-choice questions across five domains, completed in four hours. It is scored on a converted scale from 200 to 800, and you need a 450 to pass. Full certification also requires five years of IS audit, control, or security experience, which you can complete after you pass.

CISA - Certified Information Systems Auditor - is ISACA's flagship credential for professionals who audit, control, and secure information systems. The exam itself is a single four-hour sitting, but the credential has two gates: you first pass the scored exam, then satisfy a separate work-experience requirement to become certified. This guide walks through both, plus fees and retake rules.

  • •150 multiple-choice questions in four hours (240 minutes), computer-based at a PSI center or online with remote proctoring.
  • •Five domains, weighted 12% to 26% each; Domains 4 and 5 are the heaviest at 26% apiece.
  • •Scored 200 to 800; you need a scaled 450 to pass.
  • •Full certification also requires five years of IS audit, control, or security experience, with waivers of up to three years.

What are the five CISA exam domains?

The CISA exam is built on five domains defined in ISACA's official Exam Content Outline. Each domain carries a published percentage weight that tells you how much of the 150-question exam it drives, and those weights are the single most useful planning tool you have. They are lopsided on purpose: two domains together account for more than half the exam, while the lightest domain is barely more than a tenth of it.

Domain 4 (IS Operations and Business Resilience) and Domain 5 (Protection of Information Assets) are the heavyweights at 26% each, so roughly half your questions come from operations, resilience, and information security combined. Domains 1 and 2 - the audit process and IT governance - sit at 18% apiece, and Domain 3 (acquisition, development, and implementation) is the lightest at 12%. If you are triaging study time, weight it toward Domains 4 and 5 and treat Domain 3 as the place you can afford to be efficient.

ISACA publishes the percentage weights, not fixed question counts, so the per-domain question numbers below are proportional estimates from the 150-question total. Use them for pacing intuition, not as a guarantee of how many items you will see in any one area.

CISA exam domains and their weights (ISACA Exam Content Outline; question counts are proportional estimates from 150 items).
DomainFocusExam weightApprox. questions
Domain 1Information Systems Auditing Process18%about 27
Domain 2Governance and Management of IT18%about 27
Domain 3IS Acquisition, Development and Implementation12%about 18
Domain 4IS Operations and Business Resilience26%about 39
Domain 5Protection of Information Assets26%about 39

Scroll horizontally to view all columns.

What is the format and timing of the CISA exam?

The CISA exam is 150 multiple-choice questions with a four-hour (240-minute) time limit. That works out to roughly 96 seconds per question if you spread the clock evenly, though in practice you will bank time on quick recall items and spend it on the longer scenario questions that make up much of the exam. There is no separate written, oral, or practical component - every question is multiple choice.

You can take the exam one of two ways: in person at a PSI test center, or online from home or work with live remote proctoring. Both cover identical content and the same time limit; the choice is about logistics and your tolerance for remote-proctoring rules. Whichever you pick, the exam is computer-based and delivered in a single continuous sitting rather than split into separately timed modules.

Because the questions are heavily scenario-driven, CISA rewards applied judgment over memorization. Many items describe an audit situation and ask for the best next step, the greatest risk, or the most appropriate control - which is why the exam and the five-year experience requirement reinforce each other. Candidates who have actually run audits tend to find the phrasing more intuitive than those studying purely from books.

  • •150 multiple-choice questions, four hours (240 minutes), computer-based.
  • •No separate essay, oral, or practical section - all questions are multiple choice.
  • •Delivered at a PSI test center or online with live remote proctoring; same content either way.
  • •Scenario-driven questions reward applied audit judgment over rote recall.

How is the CISA exam scored, and what is a passing score?

Your raw number of correct answers is converted to a scaled score that runs from 200 to 800, and you need a 450 to pass. The 450 threshold is fixed - it applies to every version of the exam - so it does not shift with how difficult your particular question set happened to be. Scaling exists precisely so that a 450 represents the same standard of competence no matter which form you sat.

The practical consequence is that you cannot map a raw percentage straight onto the 200-800 scale or onto the 450 line. A scaled 450 does not mean answering 450 out of 800, and it does not correspond to a clean percentage such as 56 or 62 percent; ISACA does not publish the raw-to-scaled conversion, and it can differ between exam forms. Aim comfortably above a bare pass in practice tests rather than trying to reverse-engineer the exact raw number a 450 requires.

ISACA does not publish an official CISA pass rate. Third-party sources commonly cite something in the region of 50 to 60 percent, but none of those figures trace back to an ISACA primary source, so treat them as rough folklore rather than fact. What is documented is the standard itself: a scaled 450 on the 200-800 scale, applied uniformly, with no curve you can game.

  • •Scaled score range: 200 to 800.
  • •Passing score: a scaled 450, fixed across all exam versions.
  • •Raw correct answers are converted to the scaled score; ISACA does not publish the conversion.
  • •No official pass rate is published; third-party 50 to 60 percent figures are unverified.

What experience do you need for CISA certification?

Passing the exam and becoming certified are two separate things. Full CISA certification requires five years of professional experience in information systems auditing, control, or security. You do not have to have that experience before you sit - you can pass the exam first and then have up to five years from your pass date to submit the experience application, which is why many candidates take the exam early in their careers and certify later.

You can shorten the five years with substitutions and waivers, up to a maximum of three years off, so at least two years of actual IS audit, control, or security experience always stands. ISACA's published examples include roughly two years for a relevant Bachelor's or Master's degree and roughly one year for an associate degree, 60 completed semester hours, or certain qualifying certificates. The exact substitution table lives on ISACA's CISA experience-requirements page - confirm your specific waiver there before counting on it, because the precise year-values come from ISACA's own documentation and can be applied narrowly.

Since 2025, ISACA also offers a CISA Associate designation for candidates who pass the exam but have not yet met the full experience requirement. It lets you signal that you have cleared the exam while you accumulate the qualifying years. Eligibility windows and any cost for the Associate designation should be checked against ISACA's current pages, as those specifics change and were not confirmed here.

Baseline: five years

Five years of professional experience in IS auditing, control, or security is the full requirement for certification.

Exam first, experience later

You may sit and pass the exam before you qualify, then submit the experience application within five years of your pass date.

Degree substitution

A relevant Bachelor's or Master's degree can waive roughly two years; verify the exact amount on ISACA's experience-requirements page.

Other waivers

An associate degree, 60 semester hours, or certain certificates can waive about one year. Total waivers cap at three years.

CISA Associate (2025)

Introduced in 2025 for those who pass but lack the full experience; check ISACA for current eligibility and cost.

How much does the CISA exam cost?

The main cost is the exam registration fee: ISACA lists US$575 for members and US$760 for non-members for the 2026 cycle. ISACA membership carries its own annual fee, so whether joining nets out cheaper depends on how many ISACA products you plan to use - for a single exam, the member discount offsets a chunk of membership but rarely all of it. Fees are in US dollars and can vary by region, currency, and any promotions running when you register.

Two further fees apply after you pass. There is a one-time certification application fee of about US$50 when you submit your experience and claim the credential, and then an annual maintenance fee - covering ISACA's continuing professional education program - of roughly US$45 for members and US$85 for non-members to keep the certification active. Budget for the maintenance fee every year, not just once; a CISA lapses if you stop paying it and stop logging CPE hours.

The application and maintenance figures come from ISACA cost documentation and are treated here as 2026 estimates, while the US$575 and US$760 exam fees were the amounts ISACA listed this cycle. Always confirm the exact figures at checkout in your ISACA account, since prices and regional pricing move over time.

CISA fees for the 2026 cycle in US dollars (confirm current amounts at ISACA checkout; application and maintenance figures are estimates).
FeeISACA memberNon-member
Exam registrationUS$575US$760
Certification application (one-time, after passing)US$50US$50
Annual maintenance (CPE)US$45US$85

Scroll horizontally to view all columns.

How does CISA registration and scheduling work?

ISACA’s CISA credentialing page states the exam is computer-based and administered at authorized PSI testing centers globally or as a remotely proctored exam — the at-home option runs under remote proctoring rather than at a venue. Registration is continuous, meaning you can register at any time with no restrictions, and you can schedule a testing appointment as early as 48 hours after paying the exam registration fee.

The reschedule rule is unusually generous: ISACA states you can reschedule a CISA exam anytime, without penalty, during your eligibility period, as long as it is done at least 48 hours before the scheduled testing appointment. Rescheduling runs through your ISACA account.

Passing the exam is not the finish line. After the pass you pay a US$50 application processing fee, submit the application demonstrating the experience requirements, and agree to the Code of Professional Ethics and the Continuing Professional Education policy. ISACA gives candidates five years from passing the exam to apply for CISA certification — a window that closes quietly if the application is never filed.

What happens if you fail the CISA exam?

A fail is not the end of the road, but ISACA does cap how often and how fast you can retry. You get up to four attempts within any rolling 12-month period, and each attempt costs the full exam fee - there is no discounted retake. The rolling window matters: it is not four attempts per calendar year but four within any 12 months counting back from your latest sitting.

There are also mandatory waiting periods between attempts. You must wait 30 days before your second attempt, and 90 days before both your third and fourth attempts. Plan those gaps into your timeline, especially if you are aiming to certify by a specific date - a single 90-day wait can push a retake into the next quarter. Use the wait productively by targeting the domains where you fell short, and remember that Domains 4 and 5 carry the most weight if you are unsure where to focus.

If a deadline is tight or you have already used an attempt, Exam Assist supports ISACA candidates on pay-after-pass terms - you pay only once your target result is achieved, not upfront. We are independent and not affiliated with ISACA. If you are still deciding whether CISA is the right ISACA credential for you versus CISM or CRISC, the comparison guide breaks down who each one is for before you commit a registration fee.

1

Attempt 1

Sit the exam. If you do not reach a scaled 450, you can retake - but the waiting periods and the annual cap begin here.

2

30 days before attempt 2

You must wait at least 30 days after a failed first attempt before booking your second.

3

90 days before attempts 3 and 4

A 90-day wait applies before both the third and fourth attempts, and the full exam fee is charged each time.

4

Four attempts per rolling 12 months

You are capped at four attempts in any rolling 12-month period; beyond that you wait for the window to clear.

Frequently Asked Questions

What is a passing score on the CISA exam? +
You need a scaled score of 450 on a range that runs from 200 to 800. The 450 mark is fixed and applies to every version of the exam, so it does not move with the difficulty of the particular question set you are given. Because the raw-to-scaled conversion is not published, a 450 does not map to a clean percentage of correct answers.
How many questions are on the CISA exam and how long is it? +
The CISA exam has 150 multiple-choice questions and a four-hour (240-minute) time limit. It is delivered as a single computer-based sitting with no separate essay or practical section. You can take it in person at a PSI test center or online from home or work with live remote proctoring; both options cover identical content and the same time limit.
What are the five CISA domains and their weights? +
The five domains are Information Systems Auditing Process (18%), Governance and Management of IT (18%), IS Acquisition, Development and Implementation (12%), IS Operations and Business Resilience (26%), and Protection of Information Assets (26%). Domains 4 and 5 are the heaviest at 26% each, so more than half the exam covers operations, resilience, and information security, while Domain 3 is the lightest.
Do you need work experience to get CISA certified? +
Yes. Full certification requires five years of professional experience in IS auditing, control, or security. You can pass the exam first and then have up to five years from your pass date to submit the experience application. Substitutions and waivers can reduce the requirement by up to three years, so at least two years of relevant experience always stands.
What is the CISA pass rate? +
ISACA does not publish an official CISA pass rate. Third-party sources commonly cite something around 50 to 60 percent, but none of those figures trace to an ISACA primary source, so treat them as rough estimates rather than fact. What is documented is the standard itself: a scaled 450 on the 200-800 scale, applied uniformly across exam versions.
How much does the CISA exam cost? +
For the 2026 cycle ISACA lists the exam registration fee at US$575 for members and US$760 for non-members. After you pass there is a one-time certification application fee of about US$50 and an annual maintenance fee of roughly US$45 for members and US$85 for non-members. Fees are in US dollars and can vary by region, so confirm the amounts at ISACA checkout.
How many times can you retake the CISA exam? +
You get up to four attempts within any rolling 12-month period, and the full exam fee is charged each time. Mandatory waiting periods apply: 30 days before your second attempt, and 90 days before both your third and fourth attempts. Plan those gaps into your timeline, since a single 90-day wait can push a retake into the next quarter.
What is the CISA Associate designation? +
Introduced by ISACA in 2025, the CISA Associate designation is for candidates who pass the exam but have not yet met the full five-year experience requirement. It lets you signal that you have cleared the exam while you accumulate qualifying experience. Eligibility windows and any cost were not confirmed here, so check ISACA's current pages for the exact details before relying on them.

Ready to Pass Your Exam?

Exam Assist handles the Exam sitting end to end. Pay only after you pass.

Book Exam Help