CISA Exam Guide 2026: Domains, Cost, Salary, and a 12-Week Study Plan
Why the CISA exam guide 2026 conversation is louder than usual
Every year a handful of certifications get talked up as "essential." Most of that talk is noise. CISA — the Certified Information Systems Auditor credential from ISACA — is one of the rare exceptions where the hype is backed by a genuine, structural gap in the labor market. Regulators keep expanding what counts as a reportable IT control failure, from DORA in the EU to RBI's IT governance circulars in India to the SEC's cybersecurity disclosure rules in the US, and every one of those frameworks needs someone qualified to test whether the controls actually work. That someone, increasingly, needs to hold a CISA.
If you're building a CISA exam guide 2026 study plan, you're stepping into a market where demand for qualified IT auditors is outpacing the supply of certified professionals by a wide margin. ISACA itself has flagged the widening gap between the number of open GRC and IT audit roles and the number of credentialed candidates able to fill them, and hiring managers at banks, Big Four firms, and technology companies alike report the same bottleneck: plenty of applicants who understand IT, not nearly enough who can prove they understand IT audit specifically. That's the gap CISA is designed to close, and it's why the certification carries real weight from Mumbai to Dubai to London to New York.
This guide covers everything you need to plan your path: what's actually tested and how it's weighted, the experience requirements that trip people up, what CISA-certified professionals actually earn and where, a realistic 10-12 week study plan, sample question types with reasoning guidance, the mistakes that sink first-time candidates, and a set of direct answers to the questions people ask most. Wherever it's useful, we've pointed toward free tools that make the harder, less obvious part of this journey — the interview that comes after you pass — less of a guessing game.
The 2026 landscape: regulatory complexity meets a real talent shortage
Three forces are converging to make this a genuinely good year to pursue CISA, not just a marketed one.
First, regulatory complexity is compounding rather than simplifying. Financial services firms operating across multiple jurisdictions now have to satisfy overlapping frameworks — SOX and GLBA in the US, GDPR and the EU's Digital Operational Resilience Act (DORA) in Europe, RBI and SEBI IT governance requirements in India, and central bank cybersecurity circulars across the Gulf. Each of these frameworks requires independent assurance that IT general controls, change management, access provisioning, and business continuity processes actually function as documented — not just that a policy exists on paper. That assurance work is precisely what a CISA-certified auditor is trained and credentialed to perform.
Second, the talent pipeline hasn't kept pace. Internal audit and IT audit teams at banks, insurers, and large enterprises have been trying to hire IT auditors for years without finding enough qualified candidates, and job postings for "IT Audit Manager" or "Senior IT Auditor" increasingly list CISA as a hard requirement rather than a nice-to-have, particularly in regulated industries. A recognizable, globally portable credential does real work here: it lets a hiring manager screen a stack of resumes with confidence instead of trying to reverse-engineer competence from job titles alone.
Third, CISA's reach is genuinely global in a way many technical certifications aren't. Unlike region-specific compliance credentials, CISA is recognized by ISACA chapters and employers across more than 180 countries, and it maps cleanly onto IT audit, risk, and GRC roles regardless of which local regulatory framework an employer operates under. If you're in India's banking sector, a Gulf-based financial institution, a US regional bank, or a European insurer, the same credential opens the same category of door — which is unusual, and part of why it's worth the investment. If you're weighing which certification fits your target role, our companion piece on GRC and IT audit analyst interview questions is a useful read alongside this one — it covers what interviewers actually ask once you've landed the CISA-adjacent interview this guide is meant to help you earn.
Exam format: domains, weightings, and what changed
Here's the structure so you know exactly what you're preparing for.
Format basics:
- 150 multiple-choice questions
- 4-hour (240-minute) time limit — roughly 1 minute 36 seconds per question on average, so time pressure is rarely the dominant challenge
- Scored on a scaled range of 200-800; a scaled score of 450 or higher is a pass
- Delivered via computer-based testing at PSI/ISACA-authorized test centers or remotely proctored, with a six-month window to schedule your exam once registered
- Available year-round in continuous testing windows rather than fixed quarterly dates
ISACA updated the CISA job practice content outline effective 1 August 2024, and that revised weighting structure is still current for 2026. It shifted more of the exam toward operational resilience and asset protection, reflecting how much IT audit work now centers on ransomware readiness, cloud resilience, and data protection rather than classic change-management paperwork. The five domains and their current weightings:
- Information Systems Auditing Process (18%) — audit planning, risk-based audit approaches, evidence gathering, control frameworks (COBIT, COSO), and how to communicate audit results to stakeholders.
- Governance and Management of IT (18%) — IT governance structures, strategic alignment, IT risk management, organizational structure, and policies that tie IT activity back to business objectives.
- Information Systems Acquisition, Development and Implementation (12%) — project governance, system development lifecycle controls, testing methodologies, and change/configuration management during builds and rollouts.
- Information Systems Operations and Business Resilience (26%) — IT service management, data governance, third-party/vendor risk, and — the domain that's grown the most — business continuity and disaster recovery planning.
- Protection of Information Assets (26%) — the other largest domain: information security frameworks, identity and access management, network and endpoint security, encryption, and incident response.
Domains 4 and 5 together now account for 52% of the entire exam — more than half. If you're short on study time, these are the two domains to over-invest in, and it's a meaningful shift from the older weighting, which spread emphasis more evenly across all five areas. For the authoritative, continuously updated version of this breakdown, ISACA's own CISA certification page is the best primary source, and it's worth checking directly before you finalize a study plan since ISACA does periodically revise weightings.
Experience requirements — the part people underestimate
Passing the exam only gets you "CISA exam passed." Full certification requires demonstrating five years of professional work experience in information systems auditing, control, assurance, or security, earned within the ten years before your certification application (or within five years after passing the exam).
The good news: up to three years of that requirement can be waived through education or other certifications. Common substitutions include:
- One year waived for a two- or four-year degree in a related field
- An additional year waived for a master's degree in information security or IT, or for holding certain other certifications (such as CISM or CISSP)
- One year waived for each year of instructor experience in information systems at the university level (up to two years)
At least two years of actual, non-waivable qualifying experience is always required — you can't waive your way to zero hands-on time. If you don't yet have the experience but are ready on knowledge, you can still sit and pass the exam; ISACA gives you up to five years after your exam date to accumulate the required experience and formally apply for certification. This is a meaningful piece of planning most first-time candidates miss: passing early and banking the result while your experience clock catches up is a completely legitimate strategy, not a shortcut.
Cost breakdown
Budgeting for CISA involves more than the exam fee alone:
- Exam registration: US$575 for ISACA members, US$760 for non-members
- Application processing fee: US$50, paid once after you pass
- Annual certification maintenance fee: US$45 for members, US$85 for non-members, once certified
- ISACA membership (optional but usually worth it): roughly US$135/year plus local chapter dues, which typically pays for itself through the $185 savings on the exam fee alone
- Study materials: official review manuals, question banks, or instructor-led courses commonly run US$300-550 depending on format
All told, most candidates should budget somewhere between roughly US$970 and US$1,445 for the full first-year path to certification, depending on membership status and how much you spend on study materials. These figures are current as of ISACA's published 2026 fee schedule — always confirm against ISACA's official pricing before you register, since fees are reviewed periodically.
Career paths and salary data
CISA doesn't just validate knowledge — it moves compensation. Salary data varies by source and region, but the pattern is consistent: certified professionals earn a meaningful premium over uncertified peers doing similar work.
In the United States, a realistic working range for a CISA holder sits between roughly $95,000 and $140,000, with audit managers and directors clearing that ceiling and first-year IT auditors typically landing below the floor. Different salary trackers report different midpoints — some sources put the average nearer $110,000-$125,000, while ISACA's own member compensation survey reports figures north of $140,000 when senior and leadership roles are included in the average — but the direction is unanimous: certified professionals out-earn non-certified peers in comparable roles, often by a meaningful double-digit percentage.
What actually moves your number more than the certification itself is where it sits organizationally. A CISA embedded inside a cybersecurity or technology risk function tends to command higher pay than the same credential sitting inside a traditional internal-audit-under-finance reporting line, because the former is treated as a specialist technical function and the latter as a generalist compliance cost center. If you're negotiating an offer, it's worth asking directly which reporting line the role sits under — the org chart often explains the salary gap more than the job title does.
By industry, financial services consistently pays the strongest premium for CISA — banks, insurers, and payment companies operate under the heaviest audit and regulatory burden, so they pay to attract auditors who can navigate it. Consulting and Big Four advisory firms pay well too, particularly for candidates who can bill client-facing IT audit engagements. Technology companies and cloud providers are a newer but fast-growing source of demand, especially for SOC 2 and ISO 27001-adjacent audit work. Government and public-sector roles typically pay less in absolute terms but often offer the fastest path to a first CISA-relevant role for career-changers, plus valuable clearance-adjacent experience.
Geographically, the certification travels well. In India, CISA-certified professionals in banking and Big Four advisory roles command a substantial premium over uncertified peers, and demand has grown sharply alongside RBI's tightening IT governance expectations. In the Gulf, banks and telecom operators building out compliance functions under evolving central bank cybersecurity frameworks are actively recruiting CISA holders, often with relocation packages attached. In Europe, DORA implementation has created a wave of new IT audit and third-party risk hiring specifically calling for CISA or equivalent credentials.
Typical roles CISA opens or accelerates access to: IT Auditor, Senior IT Auditor, IT Audit Manager, Information Security Auditor, IT Risk and Controls Analyst, GRC Analyst/Manager, and — for candidates who later add a CISM or CRISC — IT Risk Director or CISO-track roles.
CISA vs CISSP: which one fits your goal
This comparison comes up constantly, and the honest answer depends entirely on which side of the fence you want to work from. CISSP is built for security management and technical security design — the people who architect and run security programs. CISA is built for audit and assurance — the people who independently evaluate whether those programs, and IT controls generally, actually work. If your target role has "audit," "assurance," "controls," "risk," or "GRC" in the title, CISA is the more directly aligned certification and the one hiring managers in that space will look for first. If your target role is security engineering, security architecture, or CISO-track leadership, CISSP carries more weight. CISSP is also generally regarded as the broader and more technically demanding exam of the two, while CISA is narrower but audit-specific. Plenty of senior GRC and security leaders eventually hold both — CISA for the assurance credibility, CISSP for the technical breadth — but if you're choosing where to start and IT audit is the door you're trying to open, CISA is the more efficient first move.
A realistic 10-12 week prep plan
Most candidates with some IT, audit, or security background can prepare for CISA in 10-12 weeks at roughly 8-12 hours a week. If you're newer to formal audit methodology specifically (even if you're technically strong), lean toward the 12-week end and add extra time to Domain 1 early on, since the audit-process vocabulary and COBIT/COSO framework references show up as a lens across every other domain.
Weeks 1-2: Build the audit-process foundation Read through a primary CISA review manual once, cover to cover, without trying to memorize — the goal is exposure to vocabulary and structure. Focus extra attention on Domain 1 (Information Systems Auditing Process), since its concepts — risk-based auditing, evidence sufficiency, audit sampling — get reused as reasoning tools throughout the other four domains. Start a running glossary; CISA is dense with framework acronyms (COBIT, COSO, ITIL, NIST) and confusing them costs points.
Weeks 3-4: Governance and acquisition domains Work through Domain 2 (Governance and Management of IT) and Domain 3 (Acquisition, Development and Implementation). These two together are only 30% of the exam but are conceptually foundational — governance structures and SDLC controls come up as background assumptions in later scenario questions even when they're not the domain being tested directly.
Weeks 5-7: The two 26% domains — go deep Domains 4 (Operations and Business Resilience) and 5 (Protection of Information Assets) together make up 52% of the exam, so give them three full weeks, not two. Use scenario-based practice questions rather than pure recall drills — these domains test judgment under a described situation far more than they test definitions. Pay particular attention to business continuity/disaster recovery planning within Domain 4 and identity/access management plus incident response within Domain 5, since both are consistently over-represented in released sample questions.
Week 8: First full practice exam Take a full-length, timed, 150-question practice exam under real conditions. Don't be discouraged by a score in the 55-65% range at this stage — this is diagnostic, not predictive. Score each domain separately so you know exactly where the gaps are.
Weeks 9-10: Close the gaps Re-study only the domains and sub-topics where you scored weakest, rather than re-reading everything uniformly. This is where the 52%-weighted domains earn their keep again: a few extra points recovered in Domain 4 or 5 move your overall score more than the same effort spent on Domain 3.
Weeks 11-12: Full-length drills and final review Take at least two more full timed practice exams under exam-day conditions — same time limit, no notes, no pausing. In the final days, do light review only: skim your glossary, re-read summary notes on your two weakest domains, and rest fully the day before your exam rather than cramming new material.
Throughout this plan, don't treat interview prep as something that starts after certification. Employers hiring for CISA-track roles almost always test audit judgment and communication skills in the interview itself — walking through how you'd scope an audit, how you'd document a finding, how you'd handle pushback from an audited team — not just whether you passed the exam. Practicing how you talk through those scenarios out loud, early, saves you from discovering the gap for the first time in a real interview.
Sample question types (and how to reason through them)
CISA questions are almost always scenario-based rather than pure definition recall. Here's what that looks like, with guidance on the reasoning the exam is actually testing.
Domain 1 style — audit evidence: "During a system audit, an IS auditor discovers that management has already implemented a corrective action for a control weakness the auditor identified mid-engagement. What should the auditor do?" Reasoning guidance: The auditor should still report the original finding, note that corrective action has since been taken, and independently verify the fix rather than simply accepting management's word or omitting the finding. The exam consistently tests whether you preserve audit independence and complete documentation even when the "problem" appears to have resolved itself — don't let a good outcome shortcut the process.
Domain 2 style — governance judgment: "An IT steering committee approves a new system without formal risk assessment because the CEO personally requested it. What is the GREATEST concern for an IS auditor reviewing this decision?" Reasoning guidance: The greatest concern is the bypass of established governance process itself, not the system choice. CISA questions frequently present a scenario where the technically "correct" outcome happened through the wrong process, and the exam wants you to flag the process failure — because a bypassed control this time sets precedent for bypassed controls next time.
Domain 4 style — resilience scenario: "A business continuity plan has not been tested in three years, though the plan document itself was updated last quarter. What should an IS auditor recommend FIRST?" Reasoning guidance: Recommend testing the plan before anything else — an untested plan, however recently updated on paper, provides no assurance it will actually work under real failure conditions. The exam repeatedly tests the distinction between a control existing on paper and a control being demonstrably operational; when in doubt, favor the answer that tests or verifies over the one that merely documents.
Domain 5 style — access control: "An auditor reviewing user access finds several terminated employees still have active system credentials. What control failure does this MOST likely indicate?" Reasoning guidance: This points to a breakdown in the user access de-provisioning process tied to HR termination workflows, not simply "weak password policy" or another distractor answer. CISA questions often include several plausible-sounding wrong answers; the right one usually maps most directly and specifically to the root process failure described, not to a generic security concept in the same neighborhood.
Common mistakes that sink first-time candidates
Treating it as a pure memorization exercise. Flashcard-only prep covers definitions but leaves you exposed on the scenario-based questions that dominate the real exam. CISA is testing judgment applied to a described situation, not recall of a glossary.
Under-investing in the two 26% domains. A candidate who's strong across Domains 1-3 but weak in Operations/Resilience and Protection of Information Assets can still fail, because those two domains alone are worth as much as the other three combined. Don't let comfort with familiar material crowd out time on the material that actually decides your score.
Ignoring the "auditor's perspective" framing. Many wrong answers on CISA questions are technically true statements — they're just not what an independent auditor should prioritize or recommend first. Train yourself to ask "what would an auditor, specifically, do here" rather than "what would a good IT manager do here" — they're often different answers.
Delaying practice exams until the final week. Practice exams are diagnostic tools meant to redirect your remaining study time, not a victory lap. Taking your first one at week 8 rather than week 11 gives you real weeks to close gaps instead of scrambling.
Forgetting the experience-and-application step. Passing the exam is not the same as holding the CISA credential. Candidates sometimes pass, celebrate, and then let the formal application and experience-verification step slide for months — don't let paperwork be the reason your resume can't yet say "CISA" next to your name.
Assuming the certification alone gets you hired. CISA gets your resume past filters and signals real competence, but the interview still has to go well, and IT audit interviews lean heavily on "walk me through how you'd approach this engagement" scenario questions. If your resume doesn't clearly connect your audit experience and new certification to the language recruiters and applicant tracking systems are scanning for, it's worth running it through an ATS resume checker before you start applying, and using a structured framework like ClavePrep's STAR-format answer builder to turn your audit projects and control findings into concrete interview stories rather than a recitation of exam domains.
Frequently asked questions
Is CISA worth it in 2026? For anyone targeting IT audit, GRC, risk, or IT controls roles, yes. It remains the most globally recognized credential in the field, commands a real salary premium in most markets, and is increasingly listed as a hard requirement — not just a preference — on job postings at banks, insurers, and Big Four firms as regulatory frameworks like DORA and RBI's IT governance circulars expand.
How long does it take to study for CISA? Most candidates with some IT or audit background need 10-12 weeks at roughly 8-12 hours a week. Candidates newer to formal audit methodology should budget closer to 14-16 weeks and add extra time upfront on Domain 1's audit-process vocabulary, since it underpins how questions in every other domain are framed.
How much does the CISA exam cost? As of 2026, exam registration is US$575 for ISACA members and US$760 for non-members, plus a one-time US$50 application processing fee after passing. Including membership, study materials, and first-year maintenance fees, most candidates should budget roughly US$970-$1,445 for the complete first-year path.
Do I need five years of experience before I can take the exam? No — you can sit and pass the exam with no prior experience. The five-year experience requirement (up to three years waivable through education or other certifications) only applies to earning full certification after you pass. You have up to five years after your exam date to accumulate the required experience and apply.
What's the passing score for CISA? A scaled score of 450 or higher on ISACA's 200-800 scale, which generally corresponds to answering roughly 60-70% of the 150 questions correctly, though the exact percentage varies slightly by exam form due to scaled scoring.
CISA vs CISSP — which should I get first? If your target role is IT audit, assurance, risk, or GRC, get CISA first — it's the credential hiring managers in that space look for by name. If your target role is security architecture, engineering, or CISO-track leadership, CISSP is more directly aligned. Many senior professionals eventually hold both, but pick based on which door you're trying to open first.
What jobs can I get with CISA? Common roles include IT Auditor, Senior IT Auditor, IT Audit Manager, Information Security Auditor, IT Risk and Controls Analyst, and GRC Analyst or Manager. With additional experience or a second certification like CISM or CRISC, it also supports a path toward IT Risk Director or CISO-track leadership roles.
Is CISA recognized outside the United States? Yes, extensively. ISACA chapters and CISA-holding professionals operate in more than 180 countries, and the credential is actively recruited for in India's banking and Big Four advisory sector, Gulf banks and telecom operators building out compliance functions, and European firms implementing DORA. It's one of the few IT-adjacent certifications that carries essentially the same weight regardless of which country's job market you're in.
Your next step
Passing CISA proves you understand IT audit. The interview that follows is where you prove you can actually do the job — walk an interviewer through a real finding, defend an audit judgment call, explain how you'd scope an engagement under time pressure. That's a different skill than exam recall, and it's worth practicing deliberately rather than hoping it comes naturally on interview day. Once your study plan is locked in, start layering in interview rehearsal alongside it. ClavePrep's AI-powered mock interview tools are built to simulate exactly the kind of scenario-based questioning IT audit and GRC interviews actually use, and understanding how ClavePrep's practice process works before your first real interview can take a lot of the uncertainty out of the transition from certified to hired.
