CISA Certification Cost, Eligibility, and Requirements Explained

đź•–Est. Reading Time: 12 minutes

The CISA certification is open to more people than its five-year experience requirement suggests. You do not need five years of experience to take the exam. You do need qualifying professional experience before ISACA will award you the full Certified Information Systems Auditor designation.

That distinction matters for anyone weighing CISA as an upskilling credential. An experienced security analyst, GRC specialist, internal auditor, or IT professional may already be doing work that counts. A student or career starter can study for and pass the exam, but will normally need to build relevant experience before becoming certified.

This guide covers the current CISA exam cost, who is eligible to take it, what experience counts, which waivers apply, and what you have to do to earn and keep the certification.

If you are still deciding whether the credential fits your goals, start with our guide to What Is CISA Certification? It explains the work CISA holders do and how the certification fits into cybersecurity, audit, risk, and compliance careers.

Want to see how the exam approaches audit, controls, and risk? Try our free CISA practice tests organized by domain and subdomain.

CISA Cost and Requirements at a Glance

ItemCurrent requirement or cost
Who can take the exam?Anyone with an interest in information systems audit, control, and security
Exam fee for ISACA membersUS$575
Exam fee for non-membersUS$760
Exam format150 multiple-choice questions in four hours
Passing score450 or higher on ISACA’s 200–800 scale
Experience needed for full certificationFive years of professional IS audit, control, assurance, or security experience
Experience windowWithin the 10 years before applying
Possible waiversUp to three years, depending on education and other qualifying experience
Experience remaining after the maximum waiverTwo years
Deadline to apply after passingFive years
Certification application feeUS$50
Annual maintenance feeUS$45 for members; US$85 for non-members
Continuing educationAt least 20 CPE hours each year and 120 over three years

The figures above are current as of August 2026. ISACA changes its fees and policies from time to time, so check its CISA pages before you register.

How Much Does the CISA Exam Cost?

The CISA exam currently costs:

  • US$575 for ISACA members
  • US$760 for non-members

The US$185 gap makes membership worth a look before you register, but do not judge it on the exam discount alone. Professional ISACA membership currently costs US$145 a year, plus local chapter dues. Joining may shave a little off your combined first-year cost, though the actual saving depends on your chapter’s dues and whether you use the rest of the membership.

Students and recent graduates pay less. ISACA currently lists student membership at US$25 a year and recent graduate membership at US$68 a year, both plus chapter dues. Each category has its own eligibility rules.

You do not have to be an ISACA member to take the exam or earn the full CISA certification. Membership is optional. It helps if you plan to buy member-priced study materials or training, or if you want the networking and continuing education, but it is not a hidden requirement.

Member vs. Non-Member Cost

RouteExamOther immediate costTotal before study materials
ISACA memberUS$575US$145 membership, plus chapter duesAt least US$720
Non-memberUS$760None requiredUS$760

Neither total includes the US$50 certification application fee, which you pay after passing when you are ready to apply. They also exclude review courses, books, question banks, travel, retakes, and future maintenance costs.

If the exam discount is your only reason for joining, check the full amount at checkout before you decide. If you also expect to use member resources and the lower member renewal fees, membership tends to pay off over time.

What Is the Total Cost of Earning CISA?

The minimum direct cost is higher than the registration fee alone.

If You Register as a Non-Member

  • CISA exam: US$760
  • Certification application: US$50
  • Minimum direct cost: US$810

If You Join as a Professional Member

  • Professional membership: US$145, plus local chapter dues
  • CISA exam: US$575
  • Certification application: US$50
  • Minimum direct cost: US$770, plus chapter dues

The member route is not automatically cheaper once chapter dues are added. It can still be the better value if you want the member benefits or plan to keep your membership after certification.

Your real budget may also include:

  • An official review manual or question database
  • A self-paced or instructor-led review course
  • Additional practice exams
  • Travel to a testing center, if you do not use remote proctoring
  • Currency conversion charges or taxes
  • A second exam fee if you need to retake the test

Preparation does not have to start with an expensive course. Reviewing the exam domains and working through a set of questions will tell you how much structure you actually need. Our free CISA practice tests let you sample the material by domain and spot unfamiliar areas before you buy a full study package.

Cost is only half of the return question. Our guide to CISA salaries in 2026 sets these fees against what IT auditors, risk consultants, and audit managers actually earn.

Who Is Eligible to Take the CISA Exam?

Anyone with an interest in information systems audit, control, and security may take the CISA exam. ISACA does not require a degree, a particular job title, or five years of experience before registration.

That opens the exam to:

  • Cybersecurity and IT professionals adding audit, risk, or control knowledge
  • GRC, compliance, and technology risk professionals
  • Internal or external auditors moving into information systems audit
  • Accountants and finance professionals who review technology-dependent controls
  • Students and early-career learners exploring IT audit or security assurance
  • Career changers who understand that passing the exam is only one part of certification

Being allowed to sit the exam does not make it the right next certification for everyone. CISA assumes a professional view of organizations, risk, evidence, governance, and controls. If you are still building basic IT and security knowledge, a foundational certification and some practical experience will serve you better first.

You do not have to be an IT auditor to get value out of studying CISA, though. Security professionals increasingly handle access reviews, control testing, policy compliance, risk assessments, third-party reviews, incident processes, business continuity, and regulatory requirements. All of that overlaps with the CISA job-practice areas.

Passing the Exam Is Not the Same as Becoming CISA-Certified

The CISA process has two separate eligibility points:

  1. Exam eligibility: The exam is open to anyone interested in information systems audit, control, and security.
  2. Certification eligibility: To receive and use the CISA designation, you must pass the exam and meet ISACA’s experience and application requirements.

After passing, you can accurately say you passed the CISA exam. You should not describe yourself as CISA-certified or put “CISA” after your name until ISACA has reviewed and approved your certification application.

Candidates have five years from the exam passing date to apply. That gives someone who passes before meeting the experience requirement time to earn the rest. If the five-year window closes before you qualify and apply, the passing result can no longer be used for certification.

So timing matters. An early attempt makes sense if you are already moving into audit, GRC, controls, or security assurance and have a realistic path to qualifying within five years. It makes less sense if you are still exploring cybersecurity and do not yet know whether your future work will line up with CISA.

What Is the Five-Year CISA Experience Requirement?

For full certification, ISACA requires five years of professional experience in information systems auditing, control, assurance, or security. That experience must:

  • Fall within the 10-year period before the date of your application
  • Relate to at least one current CISA job-practice domain
  • Be independently verified as part of the application
  • Total five years once any approved substitutions or waivers are counted

The five current domains are:

  1. Information Systems Auditing Process
  2. Governance and Management of IT
  3. Information Systems Acquisition, Development and Implementation
  4. Information Systems Operations and Business Resilience
  5. Protection of Information Assets

The requirement is based on the work you performed, not the title printed on your employment contract. Being called an IT auditor does not get every month accepted if the duties and verification do not support it. A security, risk, compliance, consulting, or IT professional may have qualifying experience without “audit” in the title at all.

Can Cybersecurity Experience Count Toward CISA?

Yes, cybersecurity experience can count when it falls within the CISA job-practice areas. ISACA names professional security work in the experience requirement.

Relevant work may involve:

  • Assessing identity and access controls
  • Reviewing security policies, standards, and procedures
  • Evaluating vulnerability, patch, configuration, or change-management processes
  • Performing security risk or control assessments
  • Reviewing cloud, network, endpoint, or data-protection controls
  • Assessing third-party security and technology risk
  • Evaluating incident response, backup, disaster recovery, or business continuity arrangements
  • Testing compliance with security or regulatory requirements
  • Collecting evidence, reporting control weaknesses, and following up on remediation

The word assessing is doing a lot of work in that list. CISA is about evaluating whether systems and controls are properly designed, implemented, managed, and monitored. Purely operational work aligns less clearly unless it also carries control, assurance, risk, or evaluation responsibilities.

Configuring a firewall is technical security work. Reviewing firewall rule-management controls, testing whether approvals were obtained, sampling rule changes, and reporting exceptions is much closer to the CISA perspective. A security professional may do both. The application should describe the qualifying tasks specifically rather than lean on a broad job title.

If you think your experience may count, compare your actual duties against the current CISA domains and task statements. Keep role descriptions, dates, project records, and the names of people who can verify the work. ISACA makes the final call on whether submitted experience meets its requirements.

CISA Experience Waivers and Substitutions

ISACA lets candidates substitute certain education or broader work experience for part of the standard five-year requirement. The combined waiver is capped at three years.

Current options include:

QualificationPotential waiver
General information systems or general audit experience1 year
Associate degree1 year
Bachelor’s, master’s, or doctorate degree in any field2 years
Master’s degree in information systems or a related field3 years
CIMA full certification2 years
ACCA member status2 years

These waivers do not stack without limit. The maximum reduction is three years, which still leaves two years of directly relevant, verified CISA experience to document.

A bachelor’s degree, for example, can bring the remaining requirement down from five years to three. A qualifying master’s degree in information systems can bring it down to two. No combination of waivers gets someone with no relevant professional experience to full certification.

Do not assume that a degree title, certification, or job automatically qualifies. Review the current ISACA requirements and the application instructions before you build a timeline around a waiver.

How Is CISA Work Experience Verified?

The certification application asks you to document your qualifying work: the employer, the dates, the duration, and the CISA domains the tasks fall under.

That experience has to be independently verified. ISACA’s current verification form allows a supervisor, manager, colleague, or client to verify the work. A verifier cannot be an immediate or extended family member, and cannot work in human resources.

If your qualifying experience spans several jobs or consulting engagements, you may need more than one verifier. Identify those people before you are ready to apply, especially if some of the experience is a few years old.

Your application should describe what you actually did. Avoid stretching technical duties into audit claims they do not support. The verifier is attesting that the dates and CISA-related tasks are correct, and ISACA may come back with questions.

How to Become CISA-Certified

The process comes down to six steps.

1. Decide Whether CISA Fits Your Career Direction

Review the five domains and the kinds of roles that ask for CISA. The credential lines up most directly with IT audit, technology risk, controls, GRC, compliance, and security assurance.

2. Review Your Experience

Map your work to the CISA task statements, estimate any waiver you can claim, and identify possible verifiers. You do not have to meet the full requirement before testing, but you should know your likely route to certification.

3. Prepare for and Pass the Exam

The exam is 150 multiple-choice questions in four hours, scored on a 200–800 scale with 450 to pass. CISA questions usually ask for the BEST, FIRST, NEXT, or MOST important response from an auditor’s point of view.

If that point of view is new to you, try a few CISA practice tests by domain. Use the explanations to work out why one reasonable answer beats the others, rather than memorizing the correct option.

4. Gain Any Remaining Experience

If you passed before qualifying, keep building relevant work and apply within five years of your passing date. Keep enough documentation to support the dates and tasks you plan to claim.

5. Pay the Application Fee and Submit Your Experience

Once you have passed and can meet the requirements, pay the one-time US$50 application processing fee and submit your application with the verification form and supporting documents.

6. Follow ISACA’s Professional Requirements

CISA holders agree to ISACA’s Code of Professional Ethics, comply with its information systems auditing standards, and follow the continuing professional education policy.

Can Students or Cybersecurity Beginners Earn CISA?

Students and beginners can take and pass the CISA exam, but most cannot immediately earn the full certification because they do not yet have the required professional experience.

That does not make CISA study pointless. It can be worth the effort if you:

  • Want to move into IT audit, technology risk, GRC, or security assurance
  • Are studying accounting, information systems, cybersecurity, or a related field
  • Have access to internships or entry-level work involving controls, compliance, risk, or audit
  • Understand that the exam is one milestone in a longer professional plan

Eligible students taking part through an ISACA partner program can apply for the separate CISA Associate designation after passing. It requires an active ISACA membership at any level and a one-time US$25 application fee. There is no CPE requirement, and it stays valid for up to four years or until the holder meets the requirements for full CISA certification.

CISA Associate is not open to every student or inexperienced exam passer. The partner program participation is what makes someone eligible, and the designation is not the full CISA credential.

For other learners, the practical route is to build a foundation, gain relevant experience, and come back to CISA when audit and control concepts start connecting to real work. You can still use CISA practice questions to explore the field before the exam fee becomes part of your budget.

What Does It Cost to Maintain CISA?

Certification creates ongoing obligations. To keep CISA active, holders must:

  • Earn and report at least 20 CPE hours each year
  • Earn and report at least 120 CPE hours over each three-year reporting period
  • Pay an annual maintenance fee of US$45 for ISACA members or US$85 for non-members
  • Comply with an annual CPE audit if selected
  • Keep following ISACA’s ethics and auditing standards

CPE can come from qualifying training, conferences, webinars, professional education, volunteering, or other approved activities. Some of it is free. The rest adds to the long-term cost of holding the credential.

Membership and certification maintenance are separate costs. A member who wants to keep both would pay the membership fee, applicable chapter dues, and the US$45 CISA maintenance fee. A non-member keeps CISA by paying the higher US$85 certification fee and skipping membership entirely. If you hold three or more ISACA certifications, the maintenance fee for the third and any additional ones currently drops to US$25 for members and US$50 for non-members.

Is It Worth Taking CISA Before You Have Five Years of Experience?

It can be, when the timing supports a realistic plan.

Taking the exam early may make sense if:

  • You already have some qualifying security, IT, audit, risk, or control experience
  • A degree or other approved waiver reduces the amount still needed
  • You are moving into a role that will provide relevant experience
  • The employers you are targeting value a passed CISA exam or the future certification
  • You expect to qualify and apply within five years

Waiting may be wiser if:

  • You are still learning basic IT and cybersecurity concepts
  • You do not know whether you want to work in audit, GRC, risk, or assurance
  • Your planned role has little connection to CISA’s domains
  • The exam cost would take resources away from training that is more useful now

For most upskillers, the right question is not “Do I already have five years?” It is “How much of my work is relevant, what waiver applies, and can I finish the rest inside the application window?” For learners, the question is whether CISA supports a defined career direction rather than adding another exam to a list.

Frequently Asked Questions

Do You Need Five Years of Experience to Take the CISA Exam?

No. Anyone with an interest in information systems audit, control, and security may take the exam. The experience requirement applies when you apply for the full CISA certification.

Can You Become CISA-Certified Without Experience?

No. Waivers can reduce the five-year requirement by up to three years, which still leaves two years of direct, verified CISA-related professional experience to document.

Does a Cybersecurity Job Count as CISA Experience?

It can. The deciding factor is whether your work involves tasks aligned with CISA’s audit, governance, systems lifecycle, operations, resilience, or information asset protection domains. ISACA reviews the application and makes the final determination.

Does a Degree Reduce the CISA Experience Requirement?

It may. An associate degree can provide a one-year waiver, while a bachelor’s, master’s, or doctorate degree in any field can provide a two-year waiver. A qualifying master’s degree in information systems or a related field can provide a three-year waiver. The total waiver cannot exceed three years.

How Long Do You Have to Apply After Passing CISA?

You have five years from the date you pass the exam to meet the experience requirement and apply for certification.

How Much Is the CISA Certification Application Fee?

The one-time application processing fee is US$50. This is separate from the exam registration fee.

Do You Have to Be an ISACA Member to Earn CISA?

No. Membership is not required for the exam or full CISA certification. Members do pay lower exam and annual maintenance fees. The separate CISA Associate designation does require active ISACA membership.

Does CISA Expire?

CISA has to be maintained. Holders need to meet the annual and three-year CPE requirements, pay the annual maintenance fee, and comply with ISACA’s professional policies. Failing to do so can lead to revocation of the credential.

Plan the Certification, Not Just the Exam

CISA is accessible to learners, but the full designation is meant to validate knowledge and professional experience together. Before paying the exam fee, look at the whole path: the work you have already done, the experience you still need, any waiver you can claim, the five-year application deadline, and the ongoing cost of keeping the credential.

For cybersecurity professionals, the experience requirement is often a smaller barrier than it first appears. Security assessment, controls, risk, compliance, resilience, and assurance work all overlap with the CISA domains. The step that matters is mapping your actual responsibilities carefully and getting them verified.

If CISA looks like a fit, review the domains and test your current understanding before you commit to a study plan. Start with our free CISA practice tests by domain and subdomain.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top