ISACA Certifications

CISA vs CISM vs CRISC: How They Differ and Which to Choose

A role-first comparison of ISACA's three flagship certifications - CISA for audit, CISM for security management, and CRISC for risk - covering domains, experience requirements, exam mechanics, cost, and the 2026 CISM change, so you can pick the right one.

CISA vs CISM vs CRISC: What Is the Difference and Which Should You Choose?

CISA, CISM, and CRISC are three ISACA certifications for different roles: CISA validates IT audit and assurance skills, CISM certifies information security management, and CRISC covers IT risk management and GRC. Choose CISA if you audit controls, CISM if you run a security program, and CRISC if you assess and respond to risk. All three share one exam format.

All three are ISACA certifications built on the same exam mechanics - 150 questions in four hours, scored 200 to 800 with 450 to pass - but each certifies different work and sets a different experience bar. The sections below break down the domains, eligibility, and cost of each so you can match a credential to your role.

Which ISACA Certification Matches Your Role?

Start from your job, not the certification. All three credentials come from ISACA and share the same 150-question, four-hour exam, but they validate different work. CISA is for the people who audit and test controls, CISM is for the people who run a security program, and CRISC is for the people who identify and respond to risk. Pick the one that describes what you already do, or the role you are moving toward.

The fastest way to choose is to name your deliverable. If your output is an audit report or a controls assessment, CISA fits. If you own a security program, a budget, and a team, CISM is the management-track credential. If you spend your days building risk registers, scoring likelihood and impact, and reporting risk to leadership, CRISC is the GRC-focused option.

These are mid-to-senior credentials, each expecting years of relevant experience. If you are earlier in your career, an entry-level credential may come first, and project-focused roles sometimes weigh a project credential instead. To see where the three ISACA certifications sit in the wider landscape, browse the top IT certifications guide.

  • •Audit, assurance, or controls testing - choose CISA.
  • •Running or leading a security program - choose CISM.
  • •Risk identification, assessment, and GRC - choose CRISC.
  • •Lowest experience bar - CRISC needs 3 years; CISA and CISM each need 5.

How Do CISA, CISM, and CRISC Compare Side by Side?

The three certifications look almost identical on exam mechanics and diverge on everything that matters for your career. Every version is 150 multiple-choice questions in a four-hour computer-based sitting, scored on a 200 to 800 scale with 450 as the passing mark. The exam fee is the same across all three: US$575 for ISACA members and US$760 for nonmembers, at ISACA's 2026 USD rates. Each exam is delivered at a PSI test center or under remote proctoring.

Where they split is focus, number of domains, and the experience you must document to certify. CISA carries five domains and targets audit; CISM and CRISC each carry four domains and target management and risk respectively. Use the table below to compare the three side by side, then read the domain breakdowns that follow to see exactly what each exam tests.

CISA vs CISM vs CRISC at a glance (2026, ISACA USD rates)
AttributeCISACISMCRISC
Focus areaIT audit and assuranceSecurity managementIT risk and GRC
Best-fit roleIT auditors, controls testersSecurity managers, CISOsIT risk managers, GRC practitioners
Domains5 domains4 domains4 domains
Experience required5 years IS audit, control, or security5 years security management3 years across risk domains
Exam format150 questions, 4 hours150 questions, 4 hours150 questions, 4 hours
Passing score450 on a 200 to 800 scale450 on a 200 to 800 scale450 on a 200 to 800 scale
Exam feeUS$575 member / US$760 nonmemberUS$575 member / US$760 nonmemberUS$575 member / US$760 nonmember

Scroll horizontally to view all columns.

What Does the CISA Certification Cover?

CISA - Certified Information Systems Auditor - is ISACA's audit and assurance credential, and it is the natural fit for IT auditors, assurance professionals, and anyone who tests controls or compliance. The exam covers five domains, weighted so that operations and information-asset protection carry the most marks. If your job is to evaluate whether controls exist and work as intended, CISA is the credential that maps to it.

Two domains - IS Operations and Business Resilience, and Protection of Information Assets - each carry 26% of the exam, so more than half your score comes from those two areas. The auditing process and IT governance domains sit at 18% each, and systems acquisition and development is the lightest at 12%. To certify you need a minimum of five years of professional IS audit, control, or security experience.

IS Auditing Process - 18%

The standards, planning, evidence, and reporting behind a professional IS audit. The backbone of the credential.

Governance and Management of IT - 18%

IT strategy, policies, and organizational structures that keep IT aligned with the business.

IS Acquisition, Development and Implementation - 12%

How systems are acquired, built, tested, and moved into production. The lightest-weighted domain.

IS Operations and Business Resilience - 26%

Day-to-day operations, service management, backups, and continuity. Tied for the heaviest domain.

Protection of Information Assets - 26%

Physical and logical security, identity, and data protection controls. Tied for the heaviest domain.

What Does the CISM Certification Cover?

CISM - Certified Information Security Manager - is the management-track credential, aimed at security managers, program leads, and aspiring or sitting CISOs. Rather than testing whether you can audit a control, it tests whether you can build and run a security program: governance, risk, the program itself, and incident response. It is the credential that signals you manage security rather than only perform it.

The current exam covers four domains, and the weighting is deliberately top-heavy toward running the program: Information Security Program is the largest at 33%, Incident Management follows at 30%, Information Security Risk Management is 20%, and Information Security Governance is 17%. To certify you need a minimum of five years of information-security management experience spanning at least three of the four domains.

One change to plan around: ISACA has confirmed an updated CISM Exam Content Outline effective 3 November 2026, with new preparation materials available for purchase from September 2026. The revised domain weightings had not been published at the time of writing, so if you test in late 2026 or later, confirm the current outline on ISACA's site before you build a study plan around the percentages above.

Information Security Governance - 17%

Aligning the security program with business goals, strategy, and policy. The smallest domain by weight.

Information Security Risk Management - 20%

Identifying and managing information risk to acceptable levels across the organization.

Information Security Program - 33%

Building, resourcing, and running the security program. The largest domain on the current exam.

Incident Management - 30%

Planning for, detecting, and responding to security incidents. The second-heaviest domain.

What Does the CRISC Certification Cover?

CRISC - Certified in Risk and Information Systems Control - is ISACA's risk credential, built for IT risk managers, risk-and-control practitioners, and GRC teams. It certifies that you can identify, assess, respond to, and report on IT risk, and that you understand the controls that mitigate it. If your work lives in risk registers and control frameworks rather than audit reports, CRISC is the match.

The exam covers four domains led by Risk Response and Reporting at 32% and Governance at 26%, with IT Risk Assessment at 22% and Information Technology and Security at 20%. CRISC also carries the lowest experience bar of the three: a minimum of three years of experience across at least two of the four domains, versus five years for CISA and CISM. That makes it the most accessible of the three for people earlier in a risk career.

Governance - 26%

The risk governance framework, culture, and alignment of IT risk with enterprise objectives.

IT Risk Assessment - 22%

Identifying and analyzing IT risk, including likelihood and business impact.

Risk Response and Reporting - 32%

Selecting responses, tracking risk, and reporting to stakeholders. The heaviest domain.

Information Technology and Security - 20%

The technology and security controls that mitigate IT risk.

What Experience and Eligibility Do CISA, CISM, and CRISC Require?

Experience is where the three certifications differ most, and it is the part candidates most often get wrong. You can sit any of the exams before you meet the experience requirement, but you cannot claim the certification until you document the required work. CRISC has the lowest bar at three years; CISA and CISM each require five. All three insist the experience fall within the ten-year period before you apply, and give you up to five years after passing the exam to certify.

The retake rules are identical across all three: you get up to four attempts within any rolling twelve-month period, so a first failure leaves room for three retakes inside the year. On substitutions, be careful. CISA and CISM have historically allowed limited experience waivers for certain degrees and related certifications, but ISACA's current get-certified pages did not itemize them at the time of writing, so treat any specific waiver amount as unverified. CRISC states that no substitutions apply. If even the three-year CRISC bar is out of reach for now, an entry credential like CompTIA Security+ can bridge the gap, and project-focused professionals sometimes prioritize the PMP first.

  • •CISA: 5 years of IS audit, control, or security experience.
  • •CISM: 5 years of security-management experience across at least 3 of the 4 domains.
  • •CRISC: 3 years across at least 2 of the 4 domains - the lowest bar.
  • •All three: experience must fall within the 10 years before you apply; certify within 5 years of passing; up to 4 exam attempts per rolling 12 months.

How Much Do the Exams Cost, and How Do You Keep the Certification?

The cost of getting certified is the same for all three, and it does not end when you pass. The exam itself is US$575 for ISACA members and US$760 for nonmembers at 2026 USD rates. After you pass, a US$50 application processing fee claims the certification. From there the credential is an ongoing commitment, not a one-time purchase.

Keeping any of the three certifications active means paying an annual maintenance fee - US$45 for members, US$85 for nonmembers - and earning continuing professional education credits: 120 CPE hours per three-year cycle, with a minimum of 20 hours each year. All figures here are ISACA's standard USD rates confirmed for 2026; local pricing, taxes, and currency can differ, and fees are subject to change, so confirm the current numbers on ISACA's site before you budget.

If you are weighing an ISACA exam and want support, Exam Assist works with candidates on pay-after-pass terms - you pay only after you achieve your target result, not upfront. Tell us which certification you are pursuing, your exam date, and where you are strongest and weakest, and we will lay out your options confidentially. Exam Assist is independent and is not affiliated with ISACA.

ISACA exam and certification costs (2026 USD, member / nonmember)
ItemMemberNonmember
Exam registrationUS$575US$760
Certification processing (after passing)US$50US$50
Annual maintenance feeUS$45US$85
CPE requirement120 hours per 3-year cycle, min 20 per year120 hours per 3-year cycle, min 20 per year

Scroll horizontally to view all columns.

Frequently Asked Questions

Which is harder, CISA, CISM, or CRISC? +
There is no reliable answer, because ISACA does not publish official pass rates for CISA, CISM, or CRISC. Any figures circulating online are third-party estimates, not primary data. Difficulty is better judged by fit: the exam that matches your daily work and experience will feel most manageable. CISA is broad across five audit domains, while CISM and CRISC each focus four domains on management and risk.
Which ISACA certification needs the least experience? +
CRISC has the lowest experience requirement of the three. It asks for a minimum of three years of experience across at least two of its four domains, compared with five years each for CISA and CISM. That makes CRISC the most accessible entry point for people building a career in IT risk or GRC who cannot yet document five years of specialized work.
How much does the CISA, CISM, or CRISC exam cost in 2026? +
All three exams cost the same: US$575 for ISACA members and US$760 for nonmembers, at 2026 USD rates. After you pass, a US$50 processing fee claims the certification, and keeping it active costs an annual maintenance fee of US$45 for members or US$85 for nonmembers. Local pricing and taxes can vary, so confirm current figures on ISACA's site.
What is the passing score for CISA, CISM, and CRISC? +
All three use the same scoring: your raw score is converted to a scaled score from 200 to 800, and 450 is the passing mark for every version. The exam is 150 multiple-choice questions with a four-hour time limit. Because the scaled score is not a simple percentage, you cannot map 450 to a fixed number of correct answers.
Is the CISM exam changing in 2026? +
Yes. ISACA has confirmed an updated CISM Exam Content Outline effective 3 November 2026, with new preparation materials available for purchase from September 2026. The revised domain weightings were not yet published at the time of writing. If you plan to test in late 2026 or later, check ISACA's current outline before you build a study plan around the existing percentages.
Can you hold CISA, CISM, and CRISC at the same time? +
Yes. Many professionals stack two or all three to cover audit, security management, and risk. Each certification is earned separately, with its own exam and experience requirements, and each typically carries its own annual maintenance fee and continuing-education upkeep once you hold it. Weigh whether a second or third credential adds enough to your role to justify the ongoing cost.
Which ISACA certification is best for a GRC or risk role? +
CRISC is the clearest fit for governance, risk, and compliance work. It certifies that you can identify, assess, respond to, and report on IT risk, with domains led by Risk Response and Reporting at 32% and Governance at 26%. It also has the lowest experience bar at three years, which suits risk practitioners who have not spent five years in a single specialty.

Ready to Pass Your Exam?

Exam Assist handles the Exam sitting end to end. Pay only after you pass.

Book Exam Help