How to Pass the ISACA CISA in 2026: Format, Cost, Domains and Study Plan

The CISA format, fees, languages, all five domain weights and a seven week study plan that puts the time where the marks actually are.

What the CISA is and who it is for

The CISA is ISACA’s flagship certification for information systems audit, control and security professionals, and one of the most globally recognised credentials in IT audit. It covers the full lifecycle of information systems, from auditing and governance through acquisition, development, operations and the protection of information assets. It is required or strongly preferred for IT auditor, audit manager, compliance officer and IT governance roles across virtually every industry.

It suits people who audit systems for a living, and it suits security or IT professionals who want to move into audit, risk or compliance. What it tests is not deep technical skill but the ability to think like an auditor: independent, risk focused and interested in whether controls actually work.

Full certification requires five years of relevant IS audit, control or security experience. You can sit the exam before you have all of it, but you will not be certified until the experience requirement is met, so check ISACA’s current rules on waivers and timing.

ISACA CISA at a glance

Item Detail
Exam code CISA
Questions 150
Time allowed 4 hours
Passing score 450 out of 800
Exam fee US$575 for ISACA members, US$760 for non members
Languages English, Spanish, Chinese (Simplified), French, German, Korean and Japanese
Where you sit it PSI testing centres or remote proctored

What is on the exam

Information systems auditing process (18%). How an audit is planned, executed and reported: audit standards, risk based audit planning, evidence gathering, sampling, control testing and communicating findings. This domain also sets the mindset the rest of the exam rewards, so its questions are about what the auditor should do, not what the technician should fix.

Governance and management of IT (18%). Whether IT is directed and controlled in line with the organisation’s strategy: IT governance structures, policies, organisational roles, resource management, performance monitoring and the frameworks that tie them together. Expect questions on who should be accountable for what.

Information systems acquisition, development and implementation (12%). The smallest domain. It covers project governance, the system development lifecycle, control design in new systems, testing, implementation and post implementation review. It is well documented and easy to over study relative to its weight.

Information systems operations and business resilience (26%). Over a quarter of the exam. Day to day IT operations, service management, change and problem management, data governance, backups, disaster recovery and business continuity. The auditor’s job here is to judge whether operations are reliable and recoverable, and the questions test that judgement.

Protection of information assets (26%). The other quarter. Information security frameworks, access control, network and endpoint security, encryption, physical security, security awareness and incident response, all viewed from the audit angle of whether the controls exist, are effective and are evidenced.

Why people fail it

Where the marks sit surprises people. Operations and business resilience, and protection of information assets, are 26% each, which is over half the exam between them, while acquisition, development and implementation is only 12%. Candidates who have a development background naturally over invest in the SDLC material, because it is comfortable, and then skim operations. They pay for it on the day.

The second cause is answering as a technician. ISACA’s answer style rewards the independent, risk focused auditor’s option over one that is technically correct but blind to process. A question will describe a control problem and offer a fix an engineer would apply, and that will be a distractor. The right answer is often to assess the risk, report to the right person or verify evidence before acting. That reflex only comes from seeing a lot of exam style questions.

The third is the cost of a retry. Every failed attempt costs the full fee again, US$575 for members or US$760 for non members. It is not an exam to cram in a weekend: five domains, 150 questions and four hours demand a proper run up, and candidates who book too early to save time end up paying twice.

A study plan that fits the exam

Seven weeks, weighted to the domains: two weeks each on the two 26% domains, a week each on the two 18% domains, and the 12% domain shared with revision. Take the free CISA practice questions first to see the auditor’s answer style before you open a textbook.

  1. Week 1: information systems auditing process. Standards, planning, evidence and reporting. Learn the auditor’s sequence of assess, verify, report, because it recurs in every domain.
  2. Week 2: governance and management of IT. Structures, accountability, policies and performance measurement. Practise questions on who owns a decision.
  3. Weeks 3 and 4: operations and business resilience. Operations, change management, backups, disaster recovery and continuity. Start working through the 1,823 questions in the CISA practice pack for this domain, reading why each wrong option is wrong.
  4. Weeks 5 and 6: protection of information assets. Access control, network security, encryption, physical security and incident response, always from the angle of what the auditor checks and what evidence proves it.
  5. Week 7: acquisition, development and implementation, then timed runs. Cover the SDLC domain in the first half of the week. Then use the questions only copy for full 150 question sessions at four hours and return to whichever domain scored lowest.

On exam day

You sit the CISA at a PSI testing centre or remotely with a proctor, and the exam is offered in English, Spanish, Chinese (Simplified), French, German, Korean and Japanese, so choose the language you read fastest under pressure. For remote testing, check the room and equipment requirements well in advance and expect a thorough check in.

Four hours for 150 questions is 96 seconds each, which is generous if you keep moving. Read each scenario asking what an independent auditor would do next, and be suspicious of any option that has the auditor fixing the problem personally. Answer everything, since there is no benefit in leaving a question blank, and use the remaining time to revisit the ones you marked. The pass mark is 450 out of 800 on ISACA’s scaled score, so ignore any attempt to count raw correct answers as you go.

Frequently asked questions

What happens if I fail the CISA?

You pay the full exam fee again, US$575 for members or US$760 for non members, and you register for a new attempt. ISACA sets limits on how many times you can sit within a year and on the gap between attempts, so check the current retake policy on the ISACA site before you rebook. Use your score report to see which domains fell short and focus your second run there.

Is the practice pack enough on its own?

No. The pack is 1,823 practice questions with full explanations. Its job is to build the auditor’s answer instinct and to give you realistic timed runs, and at that volume it covers a great deal of ground. It is still practice, not a course. You need a study source that teaches the five domains properly and your own audit experience to make sense of the scenarios.

Can I take the CISA in a language other than English?

Yes. The exam is available in English, Spanish, Chinese (Simplified), French, German, Korean and Japanese. Pick the one you read most fluently, because comprehension speed matters over 150 scenario questions.

Do I need five years of experience before I sit the exam?

Five years of relevant IS audit, control or security experience is required for full certification, not necessarily to sit the exam. Confirm the current experience and waiver rules with ISACA before you plan your attempt.

When you are ready to practise the auditor’s way of answering, the CISA practice question pack is US$39, refunded if you fail.