ISACA · Information Systems Audit and Control Association

Certified in the Governance of Enterprise IT

CGEIT

CGEIT is ISACA's senior-level credential for professionals who direct, manage, and assure the governance of enterprise IT. It is aimed at IT directors, governance leads, and senior consultants — not entry-level technicians — and a passing score is often tied to a promotion, a consulting engagement, or a contractual requirement. With 150 scenario-heavy questions in a single 4-hour sitting and a strict 450 pass mark, one weak attempt can stall a board-level career move. This page breaks down exactly what the exam tests, how ISACA delivers it, and how to get it done right the first time.

4 Hours
150 Questions
450 to Pass (200–800)
Center or Online

Pay Only After You Pass

No upfront fee — you settle only after your verified passing score. We advertise guaranteed results — 100% pass guaranteed or money back.

Exam Spec Sheet

Provider ISACA
Format Multiple choice · 4 domains
Duration 4 hours
Questions 150
Scoring 200–800 · 450 to pass
Fee ~$575 member / ~$760 non-member
Proctoring PSI (center or online)
Experience 5 yrs for certification
Renewal 120 CPE / 3 years
See CGEIT Help Options

EXAM FORMAT

How the CGEIT exam is built — at a glance

150

Multiple-choice questions

A single bank of 150 scenario-based, four-option multiple-choice items spanning all four governance domains. There are no labs or simulations — but the questions favor the "best" answer over the merely correct one.

4h

One timed sitting

You have 240 minutes to complete the whole exam in one block — roughly 96 seconds per question. There are no formal section breaks, so pacing and stamina matter as much as knowledge.

450

Scaled pass mark

ISACA converts your raw result to a 200–800 scaled score; 450 is the fixed passing line. The scale accounts for form difficulty, so it is not a flat percent-correct target.

Pacing & question style

CGEIT questions are written from the perspective of a governance leader advising a board. They rarely ask for a definition; instead they describe an enterprise situation and ask what should be done first, what provides the most value, or what best manages a risk. Reading carefully and choosing the "most appropriate" option is the core skill.

How scoring works

Every question is scored, and there is no penalty for wrong answers, so you should answer all 150. Your raw score is statistically converted to the 200–800 scale and a 450 or higher passes. ISACA reports a pass/fail outcome plus domain-level subscores, which help diagnose where an attempt fell short before a retake.

WHAT'S TESTED

Four job-practice domains — bars show each domain's share of the exam

1

Governance of Enterprise IT

40%

The largest domain. Establishing and maintaining a governance framework, leadership, organizational structures, policies, and a strategy that aligns IT with enterprise objectives and stakeholder needs.

2

Benefits Realization

26%

Ensuring IT-enabled investments actually deliver value: portfolio and investment management, performance measurement, and translating IT outcomes into business benefits.

3

Risk Optimization

19%

Embedding IT risk into enterprise risk management — defining risk appetite and tolerance, applying a risk framework, and balancing risk against the value IT delivers.

4

IT Resources

15%

Optimizing IT resources — people, information, infrastructure, and applications — through resource planning, sourcing strategy, and capability development aligned to governance goals.

Because Domain 1 alone accounts for roughly 40% of scored items, a candidate who is strong on risk and resources but shaky on governance frameworks and strategy is in real danger of missing 450. The domains overlap heavily with ISACA's COBIT framework, so framework fluency pays off across the whole exam.

DELIVERY & PROCTORING

Two ways to sit the exam — and what to expect on test day

At a PSI test center

You sit the exam in a quiet, monitored room at a PSI testing center. Staff verify your government-issued ID, store your belongings, and supervise the room. You schedule through your ISACA account during your assigned exam window after registering.

Online, remotely proctored by PSI

You take the exam from a private room at home or in the office, monitored live by a PSI proctor over webcam. You run a system check beforehand, complete an ID verification and a 360° room scan, and stay on camera for the full 4 hours.

ID & identity check

A valid, unexpired government photo ID with a name matching your ISACA registration exactly. The proctor captures a photo before the exam unlocks.

Environment scan

A clear desk, no second monitor, no phone or notes within reach, and a webcam scan of the whole room. No one else may enter while you test.

During the exam

Stay in frame and on-camera throughout. No scheduled breaks; leaving the seat, talking aloud, or losing connection can pause or flag the session.

WHO SHOULD TAKE THIS

CGEIT is built for senior IT governance professionals

  • IT directors, CIOs, and senior IT managers accountable for governance
  • IT governance, risk, and compliance (GRC) leads
  • Management consultants and advisors who design governance frameworks
  • IS auditors and risk professionals moving up to a board-facing role
  • Professionals targeting CIO-track or governance-leadership positions

PREREQUISITES & DIFFICULTY

No barrier to sitting — a high bar to certify

  • No prerequisite to sit the exam — anyone can register and test
  • 5 years of IT-governance experience required to earn the credential
  • Experience must span ≥3 of 4 domains, with ≥1 year in Domain 1
  • Working familiarity with COBIT and enterprise governance frameworks helps

Difficulty: CGEIT is regarded as one of ISACA's tougher exams — not because the content is technical, but because the questions demand board-level judgment and the "best" answer is often two plausible options apart. Most candidates invest weeks of focused study mapping their hands-on experience to ISACA's governance vocabulary, which is exactly the kind of pressure point our help is designed to remove.

HOW EXAM ASSIST HELPS YOU PASS THE CGEIT

CGEIT is a high-stakes, judgment-heavy exam that often sits between you and a governance-leadership role. Exam Assist pairs you with a vetted ISACA-track specialist and works on a pay-after-you-pass model — so the risk sits with us, not you. No upfront fee, guaranteed results: Exam Assist handles the sitting end to end, and you settle only after the verified result.

1

Share your exam details

Tell us your delivery method (PSI center or online), your exam window, and your goal. Takes a couple of minutes over WhatsApp, Telegram, or Discord.

2

Get an honest feasibility answer

We review your timeline and the PSI setup and tell you plainly whether it's realistic — before any money is discussed. If it isn't a fit, we say so.

3

The sitting is handled

Exam Assist handles the sitting end to end. You're matched with a specialist who maps the work around the four domains, the COBIT-aligned question style, and the PSI proctoring environment — discreetly and confidentially.

4

Settle after the verified result

You only pay once your passing score is confirmed on your official ISACA report. No verified result, nothing owed.

Ready to lock in your CGEIT result?

See the full pay-after-you-pass ISACA service, how matching works, and what to expect.

Explore the ISACA Service

FREQUENTLY ASKED

Straight answers about the CGEIT exam

What is the passing score for the CGEIT exam? +
ISACA scores the CGEIT exam on a converted 200 to 800 scale, and you need a 450 or higher to pass. The scaled score is not a raw percentage of questions answered correctly — it reflects question difficulty across the four domains — so there is no single "percent correct" target that guarantees a pass.
How many questions are on the CGEIT exam and how long is it? +
The CGEIT exam has 150 multiple-choice questions and a time limit of 4 hours. The questions are spread across four job-practice domains, with Governance of Enterprise IT carrying the largest share of the exam at 40 percent, followed by Benefits Realization (26%), Risk Optimization (19%), and IT Resources (15%).
What experience do I need to become CGEIT certified? +
Passing the exam is only one part. To earn the credential you must have at least five years of experience managing, advising, or supporting the governance of enterprise IT, covering at least three of the four CGEIT domains, with a minimum of one year in Domain 1 (Governance of Enterprise IT). You have five years from your passing date to submit the certification application.
Can I take the CGEIT exam online from home? +
Yes. ISACA delivers CGEIT through PSI, both at PSI test centers and as a remotely proctored online exam you take from a private room at home. The online option requires a webcam, a stable connection, a clear workspace, and a live proctor session with an ID check and room scan before the exam unlocks.
How much does the CGEIT exam cost? +
The CGEIT exam registration fee is approximately $575 USD for ISACA members and $760 USD for non-members. Earning and keeping the certification also involves an application fee and an annual maintenance fee once you are certified, along with 120 CPE hours every three years.
Do I pay Exam Assist before or after I see my CGEIT result? +
You settle only after your verified passing score is confirmed. There is no upfront fee — you share your exam details, receive an honest feasibility answer, and decide before any money changes hands. We advertise a guaranteed pass with money back if you do not pass; we offer a transparent, results-first arrangement.
EXAM HELP SERVICE CGEIT Exam Help: Pay After You Pass We handle the sitting end to end. Pass guaranteed — settle only after the result posts. View Service

KEEP EXPLORING

Service, booking, and sibling ISACA exams

YOUR CGEIT RESULT, HANDLED

Get expert CGEIT help with no upfront fee — you settle only after your verified passing score. Honest feasibility answer first, results-first arrangement always.

OR CHAT WITH US