CISA Certification Guide 2026: Exam Format, Domains, and Study Plan

Complete CISA certification guide: five domains, exam format, work experience requirements, and study strategies for IT auditors.

CISA Certification Guide 2026: Exam Format, Domains, and Study Plan
CISA Key Facts: Issued by ISACA | 150 questions | 4-hour time limit | Five domains | Passing score: 450 on 200–800 scale | Requires 5 years of IT audit/control work experience | Delivered at PSI testing centers or remote proctoring | Globally recognized for IT audit, governance, and risk roles

CISA Certification: The Complete Guide for IT Audit Professionals

The CISA (Certified Information Systems Auditor) is ISACA's flagship credential for professionals working in IT audit, information security, risk management, and governance. It's been awarded since 1978, making it one of the oldest specialized IT certifications in existence, and it remains the most widely recognized credential specifically for the IT audit function. If your career involves auditing information systems, assessing IT controls, ensuring compliance with regulations, or advising management on IT-related risks, the CISA is the standard credential that signals professional competency in those areas.

Unlike many cybersecurity certifications that focus on technical offensive or defensive skills, the CISA tests a combination of technical knowledge and audit methodology. You're expected to understand how information systems work AND how to assess and test the controls around them. A CISA-certified professional isn't primarily a system administrator or a security engineer — they're an independent assessor who evaluates whether IT systems are designed, controlled, and operated effectively. This auditor mindset — asking not just "does this work?" but "how do we know this works reliably and securely?" — is what distinguishes CISA candidates from purely technical certifications like CISSP or CCSP.

The CISA exam consists of 150 questions delivered over 4 hours, with scores reported on a 200–800 scale and a passing threshold of 450. The exam tests five content domains weighted differently across the question pool. Information Systems Auditing Process carries 21% of the exam and tests the IS audit methodology, planning, execution, and reporting process. Governance and Management of IT accounts for 17% and tests IT governance frameworks (COBIT, ITIL), risk management, and management oversight of IT functions. Information Systems Acquisition, Development, and Implementation covers 12% of exam questions. IS Operations and Business Resilience covers 23%, testing operational IT controls, change management, and business continuity. Information Asset Security and Control carries 27%, the heaviest weight, covering logical and physical access controls, network security, and data protection. Build familiarity with the network and infrastructure security content by working through a cisa network security practice test that mirrors the control-assessment framing CISA uses across security-related questions.

Work experience is a non-negotiable component of CISA certification. You must have 5 years of professional work experience in IS auditing, control, assurance, or security — and this experience must be verified. ISACA allows substitutions: a bachelor's degree substitutes for 1 year; a master's degree in information security or IT substitutes for 1 year; and some related certifications substitute for 1 year. This means the minimum qualified candidate with a master's degree still needs 3 years of relevant work experience. The experience requirement isn't just bureaucratic gatekeeping — it reflects ISACA's intent that CISA certifies practitioners who can do IS audit work, not just people who passed an exam. You can pass the exam first and then complete the experience requirement within 5 years of passing, but certification isn't issued until the full experience is verified.

Five years of work experience is a significant requirement that makes CISA a mid-to-senior career credential. Most CISA candidates already work in IT audit, internal audit, risk management, or compliance roles before beginning exam preparation. The exam tests applied knowledge in a context that assumes professional audit exposure — questions are framed as scenarios where an IS auditor must make a judgment call about scope, evidence, risk materiality, or control assessment adequacy. Understanding data management controls at an audit level — what controls should exist, how to test whether they operate effectively, and how to evaluate exceptions — is tested across multiple domains. Review cisa data management practice test questions to build comfort with the audit-framing of data management questions before encountering them under exam time pressure.

Cisa - Certified Information Systems Auditor - CISA - Certified Information Systems Auditor certification study resource

CISA Overview

  • Domain 1 (21%): IS Auditing Process — audit planning, risk-based approach, evidence, audit programs, reporting and follow-up
  • Domain 2 (17%): Governance and Management of IT — COBIT, IT strategic alignment, risk management frameworks, performance measurement
  • Domain 3 (12%): IS Acquisition, Development, and Implementation — SDLC phases, project controls, application testing, change management
  • Domain 4 (23%): IS Operations and Business Resilience — operations management, patch management, BCP/DRP, incident response
  • Domain 5 (27%): Information Asset Security and Control — access control, cryptography, network security, data classification, physical controls

CISA Breakdown

Domain 1: IS Auditing Process
  • Risk-based audit planning: how to prioritize what to audit based on risk assessment
  • Audit programs: designing specific test procedures for each control area
  • Evidence types: inquiry, observation, inspection, re-performance — when each is appropriate
  • Audit documentation: working papers standards, referencing, supervisor review
  • Audit reports: findings format, management responses, follow-up procedures
Domain 5: Asset Security and Control (Heaviest Weight)
  • Logical access controls: authentication methods, access rights management, privileged access
  • Network security: firewall placement, IDS/IPS, encryption in transit, DMZ architecture
  • Cryptography: symmetric vs asymmetric, PKI, digital signatures, key management
  • Physical security controls: data center security, access logging, media handling
  • Data classification: sensitivity levels, handling requirements, retention and disposal
Domain 4: Operations and Resilience
  • Change management controls: authorization, testing, rollback procedures
  • Patch management: vulnerability prioritization, testing before deployment, emergency patching
  • Business continuity planning (BCP): business impact analysis, recovery objectives
  • Disaster recovery planning (DRP): recovery time objectives, testing procedures
  • Incident response: detection, containment, evidence preservation, post-incident review
Cisa - Certified Information Systems Auditor - CISA - Certified Information Systems Auditor certification study resource

CISA Cost Breakdown

📝CISA Exam Fee
📚ISACA Study Materials
🏢Third-Party Prep

CISA Exam Strategy: How to Study Across Five Domains

CISA exam preparation requires a different mindset than technical certification study. You're not learning how to exploit a system or configure a firewall — you're learning how to evaluate whether controls around these functions are adequate, operate as intended, and address relevant risks. Every CISA question that asks what an IS auditor should do has an answer rooted in this assessment orientation: the correct response is almost always the one that gathers evidence, assesses risk, applies professional skepticism, and documents findings objectively. Questions that offer shortcuts — concluding without adequate evidence, taking management's word without verification, or choosing a finding that's more damaging than the evidence supports — are wrong answers.

Domain 5 (Information Asset Security and Control) carries 27% of the exam and deserves proportional study time. The security control questions test conceptual knowledge of control categories and their effectiveness rather than deep technical configuration knowledge. You should understand access control models (DAC, MAC, RBAC), know what network security controls should look like at the architectural level, understand encryption concepts without needing to implement them, and be able to assess whether physical controls are adequate for the sensitivity of information being protected. The system development and implementation domain tests similar applied judgment — whether controls built into the SDLC are adequate, whether testing is sufficiently rigorous, and how to evaluate vendor-developed systems against organizational requirements. Review cisa system development questions and answers to practice the audit judgment required in acquisition and development scenarios.

COBIT (Control Objectives for Information and Related Technologies) is ISACA's own governance framework, and it appears throughout CISA exam content. Understanding COBIT's structure — governance objectives, management objectives, and how they connect to specific IS audit objectives — is important for Domain 2 questions. You don't need COBIT expertise at the practitioner level for the CISA, but you do need to understand its purpose, its domain structure (Evaluate, Direct, Monitor — EDM — and Align, Plan, Organize — APO — among others), and how it relates to IT governance and risk management. CISA questions frequently require you to identify which COBIT objective or control category is most relevant to a given audit situation.

Business continuity and disaster recovery content in Domain 4 is consistently tested and well-defined. The key concepts: Recovery Time Objective (RTO) is how quickly a system must be restored after failure; Recovery Point Objective (RPO) is how much data loss is acceptable. Business Impact Analysis (BIA) is the process for determining which business functions are critical and setting RTO/RPO requirements. DRP tests should include tabletop exercises, walk-through tests, parallel tests, and full interruption tests — and audit questions often ask which type of test is most appropriate for a given situation or resource level. The privacy controls aspect of data management intersects with governance requirements and is increasingly important as regulations multiply. Practice with cisa privacy controls practice test questions to build familiarity with how privacy control assessments are framed across ISACA's domain structure.

Time management during the CISA exam is tighter than many candidates expect. 150 questions in 240 minutes gives you an average of 96 seconds per question. Most straightforward knowledge questions take 30–60 seconds. Complex scenario questions with long vignettes can take 2–3 minutes. Doing the math: if 30 questions are complex scenarios and you average 2.5 minutes each, that's 75 minutes spent on 20% of the exam. You need to move through simpler questions efficiently and allocate remaining time to harder scenarios. Practice under timed conditions — not just for content familiarity but for developing the pacing discipline the 4-hour exam demands. Working through a focused cisa practice test set in timed format is the most realistic way to calibrate your actual pacing before exam day.

Cisa Exam Strategy - CISA - Certified Information Systems Auditor certification study resource

CISA Pros and Cons

Pros
  • +Globally recognized — CISA-certified professionals work in IT audit roles at Big Four firms, Fortune 500 companies, and government agencies
  • +Directly applicable content — exam tests what IS auditors actually do in practice
  • +ISACA's established framework aligns with how most organizations structure IT governance and audit
  • +Experience requirement filters for candidates with genuine professional competency
  • +Strong salary premium — CISA is consistently among the highest-compensated IT certifications
Cons
  • 5-year experience requirement makes CISA unavailable to early-career professionals
  • Exam fee is relatively high: $575 (member) / $760 (non-member)
  • 120 CPE hours over 3 years requires sustained professional development investment
  • Domain 5 requires broad security control knowledge that non-security-focused auditors may need to build
  • Non-technical managers may find the technical control content in Domains 4 and 5 challenging

Step-by-Step Timeline

Verify Eligibility

Confirm 5 years of IS audit/control/security experience (with any applicable degree/cert substitutions), gather employer verification documentation
📚

Study (3–4 Months)

Work through CISA Review Manual domain by domain, complete ISACA QAE practice questions after each domain, weight study time by domain percentage
📝

Register and Schedule

Purchase ISACA membership ($135), register for exam ($575 member), schedule at PSI center or configure remote proctoring setup
🎯

Exam Day

150 questions over 4 hours — apply IS auditor mindset throughout, manage pace at ~90 seconds per question, flag uncertain items and return
🏅

Certification and Maintenance

Submit work experience verification after passing, receive CISA credential, begin tracking CPE hours (20+ per year, 120 over 3 years)

CISA Questions and Answers

About the Author

James R. HargroveJD, LLM

Attorney & Bar Exam Preparation Specialist

Yale Law School

James R. Hargrove is a practicing attorney and legal educator with a Juris Doctor from Yale Law School and an LLM in Constitutional Law. With over a decade of experience coaching bar exam candidates across multiple jurisdictions, he specializes in MBE strategy, state-specific essay preparation, and multistate performance test techniques.