Certified in Risk and Information Systems Control
CRISC is ISACA's benchmark certification for professionals who identify, assess, and govern IT risk and design the controls that keep it in check. It is one of the credentials employers tie most directly to GRC and security-risk roles, so a pass on your exam window can unlock a promotion, a clearance requirement, or a job offer that is already conditional on the letters after your name. A single missed attempt means another registration fee and weeks of waiting before you can retest. This page breaks down exactly what CRISC tests under the updated 2025 blueprint, how it's delivered, and how to get it done right the first time.
Pay Only After You Pass
No upfront fee — you settle only after your verified passing result. We advertise guaranteed results — 100% pass guaranteed or money back.
How the CRISC exam is built — at a glance
150
Every item is single-best-answer and scenario-driven. There is no separate simulation or experience component — just 150 questions drawn from four job-practice domains.
4h
You get a single 4-hour block — roughly 96 seconds per question — with no scheduled breaks. Pacing, not raw knowledge, is the silent failure point on CRISC.
450
Scores are reported on a fixed 200–800 scale and 450 is the line. The scaled score is not a percentage — it is a normalized standard ISACA applies equally to every exam form.
All 150 questions are linear, not adaptive — you can flag items, skip them, and return to anything within the 4-hour window. There is no penalty for guessing, so you should never leave a question blank. Most candidates who run short of time do so because a dense governance or risk-response scenario pulled them down a rabbit hole early.
Your raw count of correct answers is converted into a scaled score from 200 to 800, with 450 as the passing standard. Because ISACA uses scaled scoring, a 450 reflects the same level of competence on every version of the test regardless of which questions you saw. You get a provisional pass/fail on screen, and an official score report follows in your ISACA account.
Four domains under the updated 3 Nov 2025 blueprint — bars show each domain's share of the exam
Organizational and risk governance, risk appetite and tolerance, policies and frameworks, the three-lines model, and aligning IT risk with business objectives and culture.
Identifying threats, vulnerabilities, and risk scenarios, then analyzing and evaluating likelihood and impact with qualitative and quantitative methods to rank what matters most.
The heaviest domain: choosing response options, designing and implementing controls, managing residual risk, and communicating risk through KRIs, KPIs, and dashboards to stakeholders.
Enterprise architecture, security controls, emerging-technology risk including AI and machine learning, resilience, and the technical concepts that underpin sound control design.
The 2025 refresh re-weighted the blueprint and folded in current topics such as AI and machine-learning risk under Technology and Security. With Risk Response and Reporting carrying nearly a third of the exam, control selection and clear risk communication should be the center of gravity in your preparation.
Two ways to sit CRISC through PSI — and what to expect on test day
You sit the exam in a quiet, monitored room at an authorized PSI center. Staff verify your government-issued ID, store your belongings in a locker, and watch the room. You're given an on-screen exam and an erasable noteboard — no personal materials are allowed at the workstation.
You take the exam from a private room, monitored live by a PSI proctor through your webcam. You'll run a system check, an ID check, and a 360° room scan beforehand. No second monitor, no notes, and no one else in the room — the proctor can pause or end the session if rules are broken.
A valid, unexpired government photo ID whose name matches your ISACA registration exactly. The proctor captures your photo before the exam unlocks.
A clear desk, no second screen, no phone within reach, and a full webcam scan of the room. The remote exam uses an on-screen whiteboard — no physical scratch paper.
Stay in frame and on-camera the whole time. There are no scheduled breaks in the 4-hour window; leaving the seat, reading aloud, or losing connection can flag the session.
CRISC is built for IT risk and control professionals
Anyone may sit it — but certification needs experience
Difficulty: CRISC is regarded as one of ISACA's tougher exams. The content is more conceptual than technical, and the wording often offers two defensible options where only one is the best response in context. Candidates commonly invest 80–120 hours mapping the four domains to ISACA's risk vocabulary — exactly the kind of pressure point our help is designed to remove.
CRISC is a 4-hour, 150-question test of judgment that often stands between you and a role or clearance you already need. Exam Assist pairs you with a vetted ISACA-track specialist and works on a pay-after-you-pass model — so the risk sits with us, not you. No upfront fee, guaranteed results: Exam Assist handles the sitting end to end, and you settle only after the verified result.
Tell us your delivery method (PSI center or online), exam window, ISACA member status, and target date. Takes a couple of minutes over WhatsApp, Telegram, or Discord.
We review your timeline and the updated four-domain blueprint and tell you plainly whether it's realistic — before any money is discussed. If it isn't a fit, we say so.
Exam Assist handles the sitting end to end. You're matched with a specialist who maps the work around the Risk Response and Reporting weighting, the PSI environment, and ISACA's risk vocabulary — discreetly and confidentially.
You only pay once your passing result is confirmed on your official ISACA report. No verified result, nothing owed.
See the full pay-after-you-pass ISACA service, the model, and how matching works.
Straight answers about the ISACA CRISC exam
Service, booking, and sibling ISACA exams
Pair with a vetted ISACA-track specialist on a results-first arrangement. No upfront fee — settle only after a verified passing result.
Explore the service BookReady to start? Share your CRISC details and get an honest feasibility answer before any money changes hands.
Start now CISMISACA's management-focused security credential for those who design and run enterprise security programs.
View exam CISAISACA's premier audit credential — same 200–800 scoring and 450 pass mark, focused on IS audit and control.
View exam CGEITISACA's credential for professionals who direct and govern enterprise IT at the strategic, board-facing level.
View exam CDPSEISACA's technical privacy credential for those who build and implement privacy solutions across the lifecycle.
View examGet expert CRISC help with no upfront fee — you settle only after your verified passing result. Honest feasibility answer first, results-first arrangement always.