What is the CISA exam and how does it work?
The CISA exam is ISACA's Certified Information Systems Auditor test: 150 multiple-choice questions across five domains, completed in four hours. It is scored on a converted scale from 200 to 800, and you need a 450 to pass. Full certification also requires five years of IS audit, control, or security experience, which you can complete after you pass.
CISA - Certified Information Systems Auditor - is ISACA's flagship credential for professionals who audit, control, and secure information systems. The exam itself is a single four-hour sitting, but the credential has two gates: you first pass the scored exam, then satisfy a separate work-experience requirement to become certified. This guide walks through both, plus fees and retake rules.
- •150 multiple-choice questions in four hours (240 minutes), computer-based at a PSI center or online with remote proctoring.
- •Five domains, weighted 12% to 26% each; Domains 4 and 5 are the heaviest at 26% apiece.
- •Scored 200 to 800; you need a scaled 450 to pass.
- •Full certification also requires five years of IS audit, control, or security experience, with waivers of up to three years.
What are the five CISA exam domains?
The CISA exam is built on five domains defined in ISACA's official Exam Content Outline. Each domain carries a published percentage weight that tells you how much of the 150-question exam it drives, and those weights are the single most useful planning tool you have. They are lopsided on purpose: two domains together account for more than half the exam, while the lightest domain is barely more than a tenth of it.
Domain 4 (IS Operations and Business Resilience) and Domain 5 (Protection of Information Assets) are the heavyweights at 26% each, so roughly half your questions come from operations, resilience, and information security combined. Domains 1 and 2 - the audit process and IT governance - sit at 18% apiece, and Domain 3 (acquisition, development, and implementation) is the lightest at 12%. If you are triaging study time, weight it toward Domains 4 and 5 and treat Domain 3 as the place you can afford to be efficient.
ISACA publishes the percentage weights, not fixed question counts, so the per-domain question numbers below are proportional estimates from the 150-question total. Use them for pacing intuition, not as a guarantee of how many items you will see in any one area.
CISA exam domains and their weights (ISACA Exam Content Outline; question counts are proportional estimates from 150 items).
| Domain | Focus | Exam weight | Approx. questions |
| Domain 1 | Information Systems Auditing Process | 18% | about 27 |
| Domain 2 | Governance and Management of IT | 18% | about 27 |
| Domain 3 | IS Acquisition, Development and Implementation | 12% | about 18 |
| Domain 4 | IS Operations and Business Resilience | 26% | about 39 |
| Domain 5 | Protection of Information Assets | 26% | about 39 |
Scroll horizontally to view all columns.
The CISA exam is 150 multiple-choice questions with a four-hour (240-minute) time limit. That works out to roughly 96 seconds per question if you spread the clock evenly, though in practice you will bank time on quick recall items and spend it on the longer scenario questions that make up much of the exam. There is no separate written, oral, or practical component - every question is multiple choice.
You can take the exam one of two ways: in person at a PSI test center, or online from home or work with live remote proctoring. Both cover identical content and the same time limit; the choice is about logistics and your tolerance for remote-proctoring rules. Whichever you pick, the exam is computer-based and delivered in a single continuous sitting rather than split into separately timed modules.
Because the questions are heavily scenario-driven, CISA rewards applied judgment over memorization. Many items describe an audit situation and ask for the best next step, the greatest risk, or the most appropriate control - which is why the exam and the five-year experience requirement reinforce each other. Candidates who have actually run audits tend to find the phrasing more intuitive than those studying purely from books.
- •150 multiple-choice questions, four hours (240 minutes), computer-based.
- •No separate essay, oral, or practical section - all questions are multiple choice.
- •Delivered at a PSI test center or online with live remote proctoring; same content either way.
- •Scenario-driven questions reward applied audit judgment over rote recall.
How is the CISA exam scored, and what is a passing score?
Your raw number of correct answers is converted to a scaled score that runs from 200 to 800, and you need a 450 to pass. The 450 threshold is fixed - it applies to every version of the exam - so it does not shift with how difficult your particular question set happened to be. Scaling exists precisely so that a 450 represents the same standard of competence no matter which form you sat.
The practical consequence is that you cannot map a raw percentage straight onto the 200-800 scale or onto the 450 line. A scaled 450 does not mean answering 450 out of 800, and it does not correspond to a clean percentage such as 56 or 62 percent; ISACA does not publish the raw-to-scaled conversion, and it can differ between exam forms. Aim comfortably above a bare pass in practice tests rather than trying to reverse-engineer the exact raw number a 450 requires.
ISACA does not publish an official CISA pass rate. Third-party sources commonly cite something in the region of 50 to 60 percent, but none of those figures trace back to an ISACA primary source, so treat them as rough folklore rather than fact. What is documented is the standard itself: a scaled 450 on the 200-800 scale, applied uniformly, with no curve you can game.
- •Scaled score range: 200 to 800.
- •Passing score: a scaled 450, fixed across all exam versions.
- •Raw correct answers are converted to the scaled score; ISACA does not publish the conversion.
- •No official pass rate is published; third-party 50 to 60 percent figures are unverified.
What experience do you need for CISA certification?
Passing the exam and becoming certified are two separate things. Full CISA certification requires five years of professional experience in information systems auditing, control, or security. You do not have to have that experience before you sit - you can pass the exam first and then have up to five years from your pass date to submit the experience application, which is why many candidates take the exam early in their careers and certify later.
You can shorten the five years with substitutions and waivers, up to a maximum of three years off, so at least two years of actual IS audit, control, or security experience always stands. ISACA's published examples include roughly two years for a relevant Bachelor's or Master's degree and roughly one year for an associate degree, 60 completed semester hours, or certain qualifying certificates. The exact substitution table lives on ISACA's CISA experience-requirements page - confirm your specific waiver there before counting on it, because the precise year-values come from ISACA's own documentation and can be applied narrowly.
Since 2025, ISACA also offers a CISA Associate designation for candidates who pass the exam but have not yet met the full experience requirement. It lets you signal that you have cleared the exam while you accumulate the qualifying years. Eligibility windows and any cost for the Associate designation should be checked against ISACA's current pages, as those specifics change and were not confirmed here.
Baseline: five years
Five years of professional experience in IS auditing, control, or security is the full requirement for certification.
Exam first, experience later
You may sit and pass the exam before you qualify, then submit the experience application within five years of your pass date.
Degree substitution
A relevant Bachelor's or Master's degree can waive roughly two years; verify the exact amount on ISACA's experience-requirements page.
Other waivers
An associate degree, 60 semester hours, or certain certificates can waive about one year. Total waivers cap at three years.
CISA Associate (2025)
Introduced in 2025 for those who pass but lack the full experience; check ISACA for current eligibility and cost.
How much does the CISA exam cost?
The main cost is the exam registration fee: ISACA lists US$575 for members and US$760 for non-members for the 2026 cycle. ISACA membership carries its own annual fee, so whether joining nets out cheaper depends on how many ISACA products you plan to use - for a single exam, the member discount offsets a chunk of membership but rarely all of it. Fees are in US dollars and can vary by region, currency, and any promotions running when you register.
Two further fees apply after you pass. There is a one-time certification application fee of about US$50 when you submit your experience and claim the credential, and then an annual maintenance fee - covering ISACA's continuing professional education program - of roughly US$45 for members and US$85 for non-members to keep the certification active. Budget for the maintenance fee every year, not just once; a CISA lapses if you stop paying it and stop logging CPE hours.
The application and maintenance figures come from ISACA cost documentation and are treated here as 2026 estimates, while the US$575 and US$760 exam fees were the amounts ISACA listed this cycle. Always confirm the exact figures at checkout in your ISACA account, since prices and regional pricing move over time.
CISA fees for the 2026 cycle in US dollars (confirm current amounts at ISACA checkout; application and maintenance figures are estimates).
| Fee | ISACA member | Non-member |
| Exam registration | US$575 | US$760 |
| Certification application (one-time, after passing) | US$50 | US$50 |
| Annual maintenance (CPE) | US$45 | US$85 |
Scroll horizontally to view all columns.
How does CISA registration and scheduling work?
ISACA’s CISA credentialing page states the exam is computer-based and administered at authorized PSI testing centers globally or as a remotely proctored exam — the at-home option runs under remote proctoring rather than at a venue. Registration is continuous, meaning you can register at any time with no restrictions, and you can schedule a testing appointment as early as 48 hours after paying the exam registration fee.
The reschedule rule is unusually generous: ISACA states you can reschedule a CISA exam anytime, without penalty, during your eligibility period, as long as it is done at least 48 hours before the scheduled testing appointment. Rescheduling runs through your ISACA account.
Passing the exam is not the finish line. After the pass you pay a US$50 application processing fee, submit the application demonstrating the experience requirements, and agree to the Code of Professional Ethics and the Continuing Professional Education policy. ISACA gives candidates five years from passing the exam to apply for CISA certification — a window that closes quietly if the application is never filed.
What happens if you fail the CISA exam?
A fail is not the end of the road, but ISACA does cap how often and how fast you can retry. You get up to four attempts within any rolling 12-month period, and each attempt costs the full exam fee - there is no discounted retake. The rolling window matters: it is not four attempts per calendar year but four within any 12 months counting back from your latest sitting.
There are also mandatory waiting periods between attempts. You must wait 30 days before your second attempt, and 90 days before both your third and fourth attempts. Plan those gaps into your timeline, especially if you are aiming to certify by a specific date - a single 90-day wait can push a retake into the next quarter. Use the wait productively by targeting the domains where you fell short, and remember that Domains 4 and 5 carry the most weight if you are unsure where to focus.
If a deadline is tight or you have already used an attempt, Exam Assist supports ISACA candidates on pay-after-pass terms - you pay only once your target result is achieved, not upfront. We are independent and not affiliated with ISACA. If you are still deciding whether CISA is the right ISACA credential for you versus CISM or CRISC, the comparison guide breaks down who each one is for before you commit a registration fee.
1
Attempt 1
Sit the exam. If you do not reach a scaled 450, you can retake - but the waiting periods and the annual cap begin here.
2
30 days before attempt 2
You must wait at least 30 days after a failed first attempt before booking your second.
3
90 days before attempts 3 and 4
A 90-day wait applies before both the third and fourth attempts, and the full exam fee is charged each time.
4
Four attempts per rolling 12 months
You are capped at four attempts in any rolling 12-month period; beyond that you wait for the window to clear.