CISA vs CISM vs CRISC: What Is the Difference and Which Should You Choose?
CISA, CISM, and CRISC are three ISACA certifications for different roles: CISA validates IT audit and assurance skills, CISM certifies information security management, and CRISC covers IT risk management and GRC. Choose CISA if you audit controls, CISM if you run a security program, and CRISC if you assess and respond to risk. All three share one exam format.
All three are ISACA certifications built on the same exam mechanics - 150 questions in four hours, scored 200 to 800 with 450 to pass - but each certifies different work and sets a different experience bar. The sections below break down the domains, eligibility, and cost of each so you can match a credential to your role.
Which ISACA Certification Matches Your Role?
Start from your job, not the certification. All three credentials come from ISACA and share the same 150-question, four-hour exam, but they validate different work. CISA is for the people who audit and test controls, CISM is for the people who run a security program, and CRISC is for the people who identify and respond to risk. Pick the one that describes what you already do, or the role you are moving toward.
The fastest way to choose is to name your deliverable. If your output is an audit report or a controls assessment, CISA fits. If you own a security program, a budget, and a team, CISM is the management-track credential. If you spend your days building risk registers, scoring likelihood and impact, and reporting risk to leadership, CRISC is the GRC-focused option.
These are mid-to-senior credentials, each expecting years of relevant experience. If you are earlier in your career, an entry-level credential may come first, and project-focused roles sometimes weigh a project credential instead. To see where the three ISACA certifications sit in the wider landscape, browse the top IT certifications guide.
- •Audit, assurance, or controls testing - choose CISA.
- •Running or leading a security program - choose CISM.
- •Risk identification, assessment, and GRC - choose CRISC.
- •Lowest experience bar - CRISC needs 3 years; CISA and CISM each need 5.
How Do CISA, CISM, and CRISC Compare Side by Side?
The three certifications look almost identical on exam mechanics and diverge on everything that matters for your career. Every version is 150 multiple-choice questions in a four-hour computer-based sitting, scored on a 200 to 800 scale with 450 as the passing mark. The exam fee is the same across all three: US$575 for ISACA members and US$760 for nonmembers, at ISACA's 2026 USD rates. Each exam is delivered at a PSI test center or under remote proctoring.
Where they split is focus, number of domains, and the experience you must document to certify. CISA carries five domains and targets audit; CISM and CRISC each carry four domains and target management and risk respectively. Use the table below to compare the three side by side, then read the domain breakdowns that follow to see exactly what each exam tests.
| Attribute | CISA | CISM | CRISC |
|---|---|---|---|
| Focus area | IT audit and assurance | Security management | IT risk and GRC |
| Best-fit role | IT auditors, controls testers | Security managers, CISOs | IT risk managers, GRC practitioners |
| Domains | 5 domains | 4 domains | 4 domains |
| Experience required | 5 years IS audit, control, or security | 5 years security management | 3 years across risk domains |
| Exam format | 150 questions, 4 hours | 150 questions, 4 hours | 150 questions, 4 hours |
| Passing score | 450 on a 200 to 800 scale | 450 on a 200 to 800 scale | 450 on a 200 to 800 scale |
| Exam fee | US$575 member / US$760 nonmember | US$575 member / US$760 nonmember | US$575 member / US$760 nonmember |
Scroll horizontally to view all columns.
What Does the CISA Certification Cover?
CISA - Certified Information Systems Auditor - is ISACA's audit and assurance credential, and it is the natural fit for IT auditors, assurance professionals, and anyone who tests controls or compliance. The exam covers five domains, weighted so that operations and information-asset protection carry the most marks. If your job is to evaluate whether controls exist and work as intended, CISA is the credential that maps to it.
Two domains - IS Operations and Business Resilience, and Protection of Information Assets - each carry 26% of the exam, so more than half your score comes from those two areas. The auditing process and IT governance domains sit at 18% each, and systems acquisition and development is the lightest at 12%. To certify you need a minimum of five years of professional IS audit, control, or security experience.
IS Auditing Process - 18%
The standards, planning, evidence, and reporting behind a professional IS audit. The backbone of the credential.
Governance and Management of IT - 18%
IT strategy, policies, and organizational structures that keep IT aligned with the business.
IS Acquisition, Development and Implementation - 12%
How systems are acquired, built, tested, and moved into production. The lightest-weighted domain.
IS Operations and Business Resilience - 26%
Day-to-day operations, service management, backups, and continuity. Tied for the heaviest domain.
Protection of Information Assets - 26%
Physical and logical security, identity, and data protection controls. Tied for the heaviest domain.
What Does the CISM Certification Cover?
CISM - Certified Information Security Manager - is the management-track credential, aimed at security managers, program leads, and aspiring or sitting CISOs. Rather than testing whether you can audit a control, it tests whether you can build and run a security program: governance, risk, the program itself, and incident response. It is the credential that signals you manage security rather than only perform it.
The current exam covers four domains, and the weighting is deliberately top-heavy toward running the program: Information Security Program is the largest at 33%, Incident Management follows at 30%, Information Security Risk Management is 20%, and Information Security Governance is 17%. To certify you need a minimum of five years of information-security management experience spanning at least three of the four domains.
One change to plan around: ISACA has confirmed an updated CISM Exam Content Outline effective 3 November 2026, with new preparation materials available for purchase from September 2026. The revised domain weightings had not been published at the time of writing, so if you test in late 2026 or later, confirm the current outline on ISACA's site before you build a study plan around the percentages above.
Information Security Governance - 17%
Aligning the security program with business goals, strategy, and policy. The smallest domain by weight.
Information Security Risk Management - 20%
Identifying and managing information risk to acceptable levels across the organization.
Information Security Program - 33%
Building, resourcing, and running the security program. The largest domain on the current exam.
Incident Management - 30%
Planning for, detecting, and responding to security incidents. The second-heaviest domain.
What Does the CRISC Certification Cover?
CRISC - Certified in Risk and Information Systems Control - is ISACA's risk credential, built for IT risk managers, risk-and-control practitioners, and GRC teams. It certifies that you can identify, assess, respond to, and report on IT risk, and that you understand the controls that mitigate it. If your work lives in risk registers and control frameworks rather than audit reports, CRISC is the match.
The exam covers four domains led by Risk Response and Reporting at 32% and Governance at 26%, with IT Risk Assessment at 22% and Information Technology and Security at 20%. CRISC also carries the lowest experience bar of the three: a minimum of three years of experience across at least two of the four domains, versus five years for CISA and CISM. That makes it the most accessible of the three for people earlier in a risk career.
Governance - 26%
The risk governance framework, culture, and alignment of IT risk with enterprise objectives.
IT Risk Assessment - 22%
Identifying and analyzing IT risk, including likelihood and business impact.
Risk Response and Reporting - 32%
Selecting responses, tracking risk, and reporting to stakeholders. The heaviest domain.
Information Technology and Security - 20%
The technology and security controls that mitigate IT risk.
What Experience and Eligibility Do CISA, CISM, and CRISC Require?
Experience is where the three certifications differ most, and it is the part candidates most often get wrong. You can sit any of the exams before you meet the experience requirement, but you cannot claim the certification until you document the required work. CRISC has the lowest bar at three years; CISA and CISM each require five. All three insist the experience fall within the ten-year period before you apply, and give you up to five years after passing the exam to certify.
The retake rules are identical across all three: you get up to four attempts within any rolling twelve-month period, so a first failure leaves room for three retakes inside the year. On substitutions, be careful. CISA and CISM have historically allowed limited experience waivers for certain degrees and related certifications, but ISACA's current get-certified pages did not itemize them at the time of writing, so treat any specific waiver amount as unverified. CRISC states that no substitutions apply. If even the three-year CRISC bar is out of reach for now, an entry credential like CompTIA Security+ can bridge the gap, and project-focused professionals sometimes prioritize the PMP first.
- •CISA: 5 years of IS audit, control, or security experience.
- •CISM: 5 years of security-management experience across at least 3 of the 4 domains.
- •CRISC: 3 years across at least 2 of the 4 domains - the lowest bar.
- •All three: experience must fall within the 10 years before you apply; certify within 5 years of passing; up to 4 exam attempts per rolling 12 months.
How Much Do the Exams Cost, and How Do You Keep the Certification?
The cost of getting certified is the same for all three, and it does not end when you pass. The exam itself is US$575 for ISACA members and US$760 for nonmembers at 2026 USD rates. After you pass, a US$50 application processing fee claims the certification. From there the credential is an ongoing commitment, not a one-time purchase.
Keeping any of the three certifications active means paying an annual maintenance fee - US$45 for members, US$85 for nonmembers - and earning continuing professional education credits: 120 CPE hours per three-year cycle, with a minimum of 20 hours each year. All figures here are ISACA's standard USD rates confirmed for 2026; local pricing, taxes, and currency can differ, and fees are subject to change, so confirm the current numbers on ISACA's site before you budget.
If you are weighing an ISACA exam and want support, Exam Assist works with candidates on pay-after-pass terms - you pay only after you achieve your target result, not upfront. Tell us which certification you are pursuing, your exam date, and where you are strongest and weakest, and we will lay out your options confidentially. Exam Assist is independent and is not affiliated with ISACA.
| Item | Member | Nonmember |
|---|---|---|
| Exam registration | US$575 | US$760 |
| Certification processing (after passing) | US$50 | US$50 |
| Annual maintenance fee | US$45 | US$85 |
| CPE requirement | 120 hours per 3-year cycle, min 20 per year | 120 hours per 3-year cycle, min 20 per year |
Scroll horizontally to view all columns.