CISA
CISA is ISACA's flagship credential for IS audit, control, and security professionals — one of the most-requested certifications in audit and assurance job listings worldwide. It is a single 150-question, four-hour exam scored 200–800, and you need a 450 to pass: there is no partial credit for "almost," and a missed sitting means rebooking, re-paying, and waiting out the retake window before you can try again. This page breaks down exactly what the exam tests, how PSI delivers it, and how to get it done right the first time.
Pay Only After You Pass
No upfront fee — you settle only after your verified passing result. We advertise guaranteed results — 100% pass guaranteed or money back.
How the CISA exam is built — at a glance
150
Every item is a four-option multiple-choice question. Many are scenario-based and ask for the "best" or "most appropriate" answer — not just a recall of definitions.
240
Four hours for 150 questions is roughly 1.6 minutes each. The linear (non-adaptive) format lets you flag and revisit items, so pacing and review discipline matter.
450
ISACA converts your raw score to a 200–800 scale; 450 is the pass line. It is a fixed standard, not a percentage of questions — there is no curve against other candidates.
CISA is a linear, fixed-form exam — you see all 150 questions and can move backward and forward freely within the four hours. The challenge is rarely the math; it is parsing long audit scenarios and choosing the single best response when two options both look defensible. That "best answer" judgment is what trips up well-prepared candidates.
Your number of correct answers is converted to a scaled score from 200 to 800. A 450 or higher passes. At a PSI test center you receive a preliminary pass/fail result on screen at the end, and the official scaled score posts to your ISACA account shortly after. Unscored pretest items are mixed in, so not every question counts toward your result.
Five job-practice domains — bars show each domain's weight on the exam
Planning and executing IS audits in line with standards: risk-based audit strategy, evidence collection, sampling, and reporting findings to management.
IT governance frameworks, organizational structure, policies, enterprise risk management, and how IT strategy aligns with business objectives.
Evaluating project management, the SDLC, system acquisition controls, testing, and post-implementation review for new and changed systems.
One of the two heaviest domains: IT operations, end-user computing, problem and incident management, business continuity, and disaster recovery.
Tied for the heaviest weight: information security frameworks, access controls, network and endpoint security, encryption, and data classification.
Domains 4 and 5 together make up 52% of the exam, so operations, resilience, and information protection are where most questions — and most easy marks lost — actually live.
Domain weights reflect ISACA's current CISA job-practice outline. More than half of the exam comes from IS Operations & Business Resilience and Protection of Information Assets, so a candidate strong in audit theory but thin on security controls and continuity planning can still fall short of 450.
Two ways to sit the exam — and what to expect on test day
You sit the exam in a quiet, monitored room at an authorized PSI testing center. Staff verify your government-issued ID, store your belongings, and watch the room. You answer all 150 questions on a provided workstation and get a preliminary pass/fail result on screen when you finish.
You take the exam from a private room, monitored live by a PSI proctor through your webcam and screen-sharing software. You complete a system check, a webcam room scan, and an ID check beforehand. You can schedule a slot as soon as 48 hours after paying your registration fee.
A valid, unexpired government photo ID whose name matches your ISACA registration exactly. The proctor captures a photo and verifies your identity before the exam unlocks.
A clear desk, no second monitor, no phone or notes within reach, and a full webcam scan of the room. No one else may enter while the exam is in progress.
Stay in frame and on-camera the whole four hours. Leaving the seat, reading aloud, or losing your connection can flag the session. Plan to be uninterrupted for the full window.
CISA is built for IS audit, control, and assurance professionals
No prerequisite to sit — but a five-year bar to certify
Difficulty: CISA is widely considered demanding — not because of hard math, but because of dense audit scenarios and "best answer" judgment across five broad domains. Most candidates invest months of focused study, which is exactly the kind of pressure point our help is designed to remove.
CISA is a four-hour, 150-question test where 450 is the line between certified and starting over. Exam Assist pairs you with a vetted ISACA specialist and works on a pay-after-you-pass model — so the risk sits with us, not you. No upfront fee, guaranteed results: Exam Assist handles the sitting end to end, and you settle only after the verified result.
Tell us your delivery method (PSI center or online), test date, and which domains worry you most. Takes a couple of minutes over WhatsApp, Telegram, or Discord.
We review your timeline and target and tell you plainly whether it's realistic — before any money is discussed. If it isn't a fit, we say so.
Exam Assist handles the sitting end to end. You're matched with a CISA specialist who maps the work around the five domains, the "best answer" question style, and the PSI environment — discreetly and confidentially.
You only pay once your passing result is confirmed. No verified result, nothing owed.
See the full pay-after-you-pass ISACA service, pricing model, and how matching works.
Straight answers about the ISACA CISA exam
Service, booking, and sibling ISACA exams
Pair with a vetted ISACA specialist on a results-first arrangement. No upfront fee — settle only after a verified passing result.
Explore the service BookReady to start? Share your CISA details and test date and get a fast, honest feasibility answer — before any money is discussed.
Start now CISMISACA's management-focused security credential — the natural next step for CISA holders moving from auditing into security leadership.
View exam CRISCISACA's risk and controls certification — a strong pairing with CISA for professionals in IT risk and governance roles.
View exam CGEITISACA's enterprise IT governance credential, aimed at senior professionals who set and oversee IT strategy and controls.
View exam CDPSEISACA's technical privacy certification, blending privacy-by-design and data governance — relevant to auditors covering data protection.
View examGet expert CISA help with no upfront fee — you settle only after your verified passing result. Honest feasibility answer first, results-first arrangement always.