, ,

CIA vs. CISA: Which Certification First? Cost and Career

The CIA and the CISA are compared constantly because the people who hold them sit next to each other. Every internal audit function of any size now has an IT audit team or wishes it did, every IT auditor is asked at some point to pick up a financial or operational engagement, and the two credentials that certify those halves of the department come from two different bodies with two different ideas of what an auditor is. The CIA, from The Institute of Internal Auditors, certifies command of the internal audit profession’s own Standards and the full range of engagements a function performs. The CISA, from ISACA, certifies the ability to audit, control, and secure information systems. Neither is a license, both are recognized worldwide, and which one you should pursue first depends on what you audit now and what you want to be auditing in five years.

This guide was rewritten in September 2026 with the current exam structures, fees, and eligibility rules for both credentials: the 2025 CIA syllabus and the CISA job practice that took effect in 2024. It compares them on what they certify, who qualifies, how the exams are built, how hard they are, what they cost, how long they take, what they do for a career by role, how they are maintained, and how to hold both. It is the IT-side companion to the CIA vs. CPA comparison, and it leans on the CIA exam roadmap for the detail of the CIA route.

In this guide

What each credential certifies, and who grants it

The CIA is the IIA’s flagship certification and the only global credential specific to internal auditing. Its three parts cover the foundations of the profession and the Global Internal Audit Standards, the conduct of an engagement from planning through reporting, and the management of an internal audit function from the chief audit executive’s chair. It certifies breadth: a CIA is expected to plan a risk-based audit of anything, from route cash at a distributor to a treasury function at a bank, and to do it under the Standards the Standards overview describes. Technology appears throughout the syllabus, but as a subject an internal auditor must understand, not as the subject.

The CISA is ISACA’s credential for information systems audit, established in 1978 and now held by well over a hundred thousand people worldwide. Its five domains cover the IS audit process, IT governance and management, system acquisition and development, IT operations and resilience, and the protection of information assets. It certifies depth in one discipline: a CISA is expected to audit access management, change management, system development, operations, business continuity, and security controls, to read a SOC report intelligently, and to judge whether the technology environment supports the financial and operational controls the rest of the function relies on. The ITGC primer and the cybersecurity program audit guide describe the work the CISA certifies.

Put the two side by side and the shape of the choice is obvious. The CIA tells an employer you can run any engagement under the Standards and, in time, the function. The CISA tells an employer you can run the technology engagements that most generalists cannot, and that you can be trusted with the ITGC scoping, the access reviews, and the cyber work that regulators and external auditors ask about first. Internal audit needs both kinds of person, and the strongest IT audit leaders hold both credentials because their careers eventually require them to manage generalists and to sit in front of an audit committee that will ask about the Standards.

Eligibility: experience, education, and the waivers

The two credentials gate entry differently. The CIA gates on education first and adjusts the experience requirement to match; the CISA gates on experience, five years of it, and allows education and adjacent work to substitute for part of that total. The practical effect is that a graduate can begin the CIA program on day one of a first job and be certified inside two years, while the same graduate can pass the CISA exam early but will usually wait several years for the experience to accrue before the certification is granted.

RequirementCIACISA
EducationDetermines the experience requirement: a master’s, a bachelor’s, the Internal Audit Practitioner designation, or no degree with more experienceNot required; a degree can substitute for part of the experience requirement
Experience requiredTwelve months with a master’s, twenty-four with a bachelor’s, sixty with the IAP designation or no degreeFive years of professional information systems audit, control, or security work
What experience countsInternal audit or equivalent work in seven qualifying fields, including external audit, compliance, quality assurance, and internal controlIS audit, IS control, or IS security work; ISACA verifies it against the CISA job practice domains
Waivers and substitutionsNone beyond the education-based scaleUp to three years can be substituted: one year for a year of non-IS audit or general information systems experience, one or two years for a two-year or four-year degree, one year for a master’s in information security or IT, plus a small set of other qualifying credentials; check ISACA’s current table before counting on any of them
When experience must be earnedBefore certification; the exam can be passed firstWithin the ten years before the application, or within five years after passing the exam
Ethics and conductCharacter reference and agreement to the IIA Code of EthicsAgreement to the ISACA Code of Professional Ethics and to the CPE policy
Program windowThree years from application approval to pass all parts, extendable for a feeCertification must be applied for within five years of passing the exam
MembershipNot required; membership lowers feesNot required; membership lowers fees

The waiver table is where CISA candidates lose the most time to misunderstanding, and the safe reading is this: the exam can be sat at any point, the credential is granted when ISACA has verified five years of qualifying experience net of substitutions, and a bachelor’s degree plus a year of financial audit typically leaves a candidate needing two years of hands-on IS audit before the letters arrive. The CIA’s rule is simpler and more forgiving, which is one reason the CIA requirements guide is shorter than ISACA’s experience policy.

Exam structure side by side

Both exams are multiple choice, both are computer-delivered year-round, and both are scaled rather than raw-scored. The CIA spreads its content over three sittings totaling six and a half hours; the CISA puts everything into one four-hour sitting of 150 questions. That single-sitting format is the CISA’s defining feature: there is no partial credit for knowing three domains well, and a candidate who is weak in the two heaviest domains, operations and resilience and the protection of information assets, will fail regardless of strength elsewhere.

FeatureCIA (2025 syllabus, English from 28 May 2025)CISA (2024 job practice)
PartsThree: Part 1 Internal Audit Fundamentals, Part 2 Internal Audit Engagement, Part 3 Internal Audit FunctionOne exam
Questions and timePart 1: 125 questions, 150 minutes; Parts 2 and 3: 100 questions, 120 minutes each150 questions, 240 minutes
Content weightsPart 1: foundations 35%, ethics 20%, governance, risk, and control 30%, fraud 15%. Part 2: planning 50%, information gathering and analysis 40%, supervision and communication 10%. Part 3: operations 25%, the audit plan 15%, quality 15%, engagement results and monitoring 45%Domain 1 Information Systems Auditing Process 18%; Domain 2 Governance and Management of IT 18%; Domain 3 Information Systems Acquisition, Development, and Implementation 12%; Domain 4 Information Systems Operations and Business Resilience 26%; Domain 5 Protection of Information Assets 26%
ScoringScaled 250 to 750, pass mark 600 on each partScaled 200 to 800, pass mark 450
DeliveryPearson VUE test centers, year-round; 180-day registration window per partPSI test centers or online remote proctoring, year-round; a registration is valid for twelve months and the exam must be scheduled within it
RetakesThirty-day wait after a failed part; the part fee againLimited attempts within a rolling year, with a waiting period between them; the full exam fee again
LanguagesEnglish plus rotating translations by partEnglish plus a set of translations that ISACA lists by exam
Question styleStandards-based judgment: which action is most consistent with the StandardsPractice-based judgment: what the IS auditor should do first, or which control best addresses a risk, with the ISACA answer favoring risk assessment and reporting over technical fixes

Difficulty: pass rates, study hours, and where each exam bites

The IIA publishes pass rates; ISACA does not. The CIA’s cumulative rates on the current syllabus are 44 percent for Part 1, 48 percent for Part 2, and 56 percent for Part 3, which are low enough that the CIA difficulty guide exists to explain them. For the CISA the only figures in circulation are estimates from prep providers and forum surveys, which cluster around one in two, and none of them should be quoted as fact. What can be said from watching candidates is that the CISA fails people for a different reason than the CIA does: CIA candidates fail for answering as their firm practices rather than as the Standards say, and CISA candidates fail for answering as a technologist rather than as an auditor.

AspectCIACISA
Published pass ratesPart 1 44%, Part 2 48%, Part 3 56%; Challenge Exam 47%Not published; third-party estimates around 50 percent, unverifiable
Study hours, as commonly quoted by prep providers150 to 250 hours across three parts100 to 200 hours for the single exam, more for candidates without hands-on IS audit experience
Where the difficulty sitsJudgment questions with two defensible answers where only the Standards’ answer scores; Part 3’s chief-audit-executive viewpointISACA’s way of thinking: the right answer is usually to assess risk, report to management, or verify a control rather than to fix the technology; Domains 4 and 5 carry more than half the marks
Who finds it easierPracticing internal auditors who have read the StandardsWorking IT auditors who have performed ITGC and application control reviews and read SOC reports
Who finds it harderExternal auditors and candidates who study summaries rather than the StandardsEngineers and security specialists who know the technology and answer as operators; financial auditors with no IT exposure who cannot picture the controls
Sitting format riskThree separate attempts; a weak part can be retaken aloneOne four-hour sitting; no way to isolate a weak domain
VerdictMore total study and three sittings, with published evidence that most candidates fail at least one partLess total study, one sitting, and a mindset shift that technical candidates underestimate

Ask the people who hold both and most will say the CIA took longer and the CISA surprised them more. The CIA’s difficulty is honest and visible: three exams, published pass rates, a syllabus that runs to the whole profession. The CISA’s difficulty hides inside a single exam that looks, on the surface, like a knowledge test of technology terms, and turns out to be a test of whether you think like an IS auditor. The hardest CIA topics guide covers the first; for the second, ISACA’s own review manual and question database remain the preparation that maps to the exam.

Cost: line items and three budgets for each

Prices are as of September 2026 from the IIA’s and ISACA’s own fee pages, with prep materials at list price. Both bodies price the exam lower for members, and in both cases the membership pays for itself: the IIA’s $290 dues save $525 in CIA fees, and ISACA’s international dues of about $135, plus local chapter dues that vary, save $185 on the CISA exam and $40 a year on maintenance.

Line itemCIA, IIA memberCIA, non-memberCISA, ISACA memberCISA, non-member
Application$120$240None to sit the exam; $50 certification application after passing$50 certification application
ExamPart 1 $310; Parts 2 and 3 $280 each; $870 for threePart 1 $445; Parts 2 and 3 $415 each; $1,275 for three$575$760
Membership$290 a year ($200 public sector and educators; students free)NoneAbout $135 international dues plus chapter duesNone
RetakeThe part fee, after thirty daysThe part fee$575, subject to the attempt limits$760
Other feesReschedule $75; program extension $275; registration extension $100SameRescore request $75; deferral fees apply if you move the exam outside the rulesSame
Annual maintenanceIncluded in dues; non-member reporting fee about $120 in North AmericaAbout $120$45$85
Prep materialsQuestion bank from $499; full courses $899 to $1,599 at list, $764 to $1,199 with the member discount at the official partnerSame at listISACA review manual around $120; twelve-month question database $299; third-party courses roughly $300 to $1,500Manual and database at higher non-member prices; $399 for the database
Fees only, no retakes, no prep$1,280 including a year of dues$1,515$760 including dues and the certification application$810
ScenarioCIA line items (member)CIA totalCISA line items (member)CISA total
Frugal: self-study, no retakes$990 fees, $290 dues, $499 question bank$1,779$135 dues, $575 exam, $50 application, $120 review manual$880
Standard: official materials or mid-tier course, one retake for the CIA$990 fees, $290 dues, $1,099 course, $280 retake, $75 reschedule$2,734$135 dues, $575 exam, $50 application, $120 manual, $299 question database$1,179
Premium: top course, retakes, two years$990 fees, $580 dues over two years, $1,599 course, $560 in retakes, $75 reschedule$3,804$135 dues, $575 exam, $50 application, $1,500 third-party course, $299 database, $575 retake$3,134

The CISA is the cheaper credential on every scenario and by a wide margin at the frugal end, because there is one exam fee instead of three and because ISACA’s own manual and question database are enough preparation for most working IT auditors. The CIA’s higher cost buys three separate sittings and a syllabus three times the size, which is a fair trade for what it certifies; the CIA cost guide has the full fee schedule, the hidden costs, and a reimbursement request script that works for either credential.

Time to credential

StageCIACISA
Application and approvalDays to a few weeks in the candidate management systemExam registration is immediate; the certification application comes after passing
Study and sittingsNine to eighteen months for three parts around a full-time job; six for an experienced auditor who studies seriouslyThree to six months for one sitting; longer for candidates without hands-on IS audit work
ExperienceTwelve to sixty months depending on education; usually already met by working auditorsFive years net of substitutions; usually the gating item for candidates under thirty
IssuanceWeeks after experience verificationWeeks after ISACA approves the certification application
Realistic total for an experienced auditorTwelve to twenty-four months, as little as six to nineFour to eight months
Realistic total for a new graduateTwo to three years, with the exam passed early and the credential issued when experience is verifiedThree to five years, with the exam passed early and the credential issued when experience net of substitutions reaches five years
What kills the timelineSitting Part 1 underprepared; letting the three-year window lapseAssuming a waiver applies without reading ISACA’s table; letting the five-year application window pass

Career impact by role

Credentials matter in hiring to the extent that the person reading the resume knows what they mean, and for these two the readers split cleanly. Internal audit leaders read the CIA as proof you know the profession; IT audit leaders, IT risk managers, security teams, external auditors’ IT specialists, and bank examiners read the CISA as proof you can audit a system. The table sets out what each does for you by role, with salary claims again left out, since ISACA’s and the IIA’s compensation surveys both report premiums for their own holders and both are self-reported.

Role or pathWhat the CIA does for youWhat the CISA does for youThe practical read
IT audit staff or seniorHelpful context; rarely decisiveThe credential postings ask for; the one the hiring manager holdsCISA first, without much debate
IT audit manager or directorIncreasingly expected, because the role now manages engagements under the Standards and reports to a CAE who will askAssumed; its absence in an IT audit leader draws questionsBoth; CISA first if you lack it, CIA within two years of taking the manager role
Cybersecurity auditLimitedStrong; often paired with CISM, CISSP, or CRISC as the work deepensCISA plus a security credential; see the cybersecurity audit guide
SOX ITGC and application controlsHelpful for the control-testing methodStrong; external auditors’ IT specialists hold it and expect itCISA; the ITGC scoping guide shows the work
Generalist internal auditorThe natural first credentialA differentiator for the generalist who wants the technology engagementsCIA first; CISA if you keep getting pulled onto IT work and like it
Audit manager, generalist functionExpectedValued where the function has no IT audit team and the manager covers itCIA; CISA optional
Chief audit executiveExpected; listed in most postingsA strong addition, because technology risk is the audit committee’s most frequent question and a CAE who can speak to it directly is rarer than one who cannotCIA, with the CISA as the differentiator the CAE interview guide describes committees noticing
IT risk, IT GRC, or second-line technology riskLimitedStrong; CRISC is the closer fit as the role moves from audit to risk managementCISA, then CRISC
SOC and third-party assurance at a CPA firmLimitedExpected alongside the CPA for signing staffCISA plus CPA
Information security operationsNoneSome; CISM, CISSP, or hands-on security certifications count moreNeither is the right first credential
Data analytics within auditContext for what to testContext for where the data lives and how systems produce itEither, plus demonstrated analytics work; the journal entry analytics guide is the kind of thing hiring managers want to see you have done
Bank and insurance IT auditValued by examiners as audit competenceExpected; examiners reviewing the IT audit function look for itCISA, then CIA as you move up
Careers outside the United StatesRecognized everywhere the IIA operatesRecognized everywhere ISACA operates, which is nearly everywhereEither; both travel

The pattern is symmetrical. The CISA is decisive for technology roles and a differentiator for generalist ones; the CIA is decisive for leadership roles in internal audit and a differentiator for technology ones. An IT auditor who never intends to manage generalists can spend a whole career on the CISA and its ISACA siblings. An IT auditor who wants to run a function needs the CIA eventually, because the audit committee, the external quality assessor, and the Standards the function is measured against all speak the IIA’s language. The By Role hub sets out both ladders, and the interview guide shows how credential questions are asked at each rung.

Keeping the credential: CPE, fees, and lapses

Maintenance itemCIACISA
Continuing education40 hours a year for practicing CIAs, 20 for those not practicing120 hours per three-year cycle with a minimum of 20 in any year
EthicsTwo hours a year within the totalNo separate hours requirement; adherence to the ISACA Code of Professional Ethics is a condition of holding the credential
ReportingBetween 1 October and 31 December; first report due 31 December of the year after certificationAnnually, with the maintenance fee; the three-year cycle starts on 1 January after certification
Annual feeIncluded in IIA membership; non-member reporting fee about $120 in North America$45 for members, $85 for non-members
What countsCourses, conferences, teaching, publishing, translating, presenting, subject-matter expert work, and external quality assessments, each under an annual capISACA and third-party training, conferences, teaching, publishing, volunteer work, and self-study within ISACA’s category limits; ISACA’s own events carry free or discounted CPE for members
RecordsThree yearsTwelve months after the end of each reporting cycle at minimum; ISACA audits a sample
LapseGrace, then inactive, then revocation after an extended lapse; Part 1 must be passed again to recertifyRevocation for non-compliance with CPE or fees; reinstatement requires the missing hours, fees, and in some cases the exam again
Shared credit for dual holdersMost audit, controls, governance, and technology risk courses count for both; a dual holder needs roughly the same 40 hours a year, reported twice, with one certificate file tagged by both bodies’ categories

The detail for the CIA side is in the CIA CPE guide and the maintenance guide. For the CISA, ISACA’s CPE policy document is short and worth reading once, because its category caps differ from the IIA’s and dual holders who plan their year around the IIA’s rules occasionally find a block of hours that ISACA counts differently.

The decision, by candidate profile

ProfileRecommendationSequenceWhy
New graduate joining an IT audit teamCISA exam early, CIA laterPass the CISA exam in year one and bank it; certification arrives when the experience does; add the CIA around year threeThe exam is fresh in your mind and the five-year experience clock is the constraint, not the test
New graduate joining a generalist internal audit teamCIACIA within two years; CISA only if you gravitate to the technology engagementsThe CIA is the credential your function reads and the experience rule is met quickly
IT auditor with three to five years and no credentialCISACISA in four to eight months, then decide about the CIA based on whether management is the goalIts absence is the first thing an IT audit hiring manager notices
CISA holder promoted to manage a mixed teamAdd the CIAThree parts inside eighteen months, Part 3 lastYou now run engagements under the Standards and report to a CAE and a committee that will ask about them
CIA holder pulled into ITGC and access workAdd the CISAOne sitting after three to six months of study; count your audit experience toward the waiverThe external auditor’s IT specialists and the CIO’s team both read it; your CIA does not cover the ground
Engineer or security analyst moving into auditCISACISA first, studying the auditor mindset rather than the technology; CIA later if you move toward leading a functionYour technical knowledge is the easy part; the exam tests whether you think like an auditor
Financial auditor with no IT exposure who wants itCIA first, then CISACIA to secure the audit credential; CISA once you have a year of hands-on IT audit work to make the material concreteThe CISA exam is much harder to pass on reading alone
Aspiring CAE from an IT audit backgroundBothCIA now if you lack it; keep the CISA currentThe committee expects the CIA; the CISA is your differentiator
Aspiring IT risk or GRC leaderCISA, then CRISCCISA first; CRISC as the role moves from audit to risk management; the CIA is optionalSecond-line technology roles read ISACA credentials, not the IIA’s
Consultant or co-source providerBoth, over timeWhichever matches your current engagements firstClients read the CIA for internal audit services and the CISA for technology assurance

Holding both: sequencing and shared CPE

Holding both is the normal end state for IT audit leaders and an increasingly common one for generalist managers, and the sequencing question answers itself if you start from the experience rules. The CISA’s exam can be passed years before the credential is granted, so a candidate on the IT side should sit it early and let the experience accrue; the CIA’s credential follows the exam quickly for anyone with a degree and two years in audit, so it is the one to complete when you want letters on the resume now. A candidate who starts in IT audit typically holds the CISA by year three and the CIA by year five; one who starts as a generalist typically reverses the order. Neither body offers a shortcut for holders of the other: there is no CIA Challenge Exam for CISAs, and ISACA grants no exam waiver for CIAs, though the CIA’s audit experience counts toward the CISA’s experience requirement under the non-IS audit substitution.

The maintenance overlap is where holding both stops costing extra. Forty hours a year satisfies the IIA outright and puts you on pace for ISACA’s 120 per cycle; an audit or technology-risk course counts for both, an IIA conference counts for ISACA and vice versa, and only the reporting is duplicated. Keep the two deadlines in one calendar, tag each certificate with both bodies’ categories when you file it, and pay ISACA’s maintenance fee with the CPE report rather than treating it as a separate task, because a missed fee revokes a CISA as surely as missed hours do. The one trap is category caps: the IIA caps publishing, presenting, and similar categories at annual limits that ISACA sets differently, so a year built heavily on teaching or writing can satisfy one body and fall short for the other.

Common mistakes

MistakeWhat it looks likeCostFix
Treating the CISA as a technology examAn engineer studies the protocols and fails on the audit judgment questionsA $575 retake and a waiting periodStudy ISACA’s manual for how the IS auditor thinks; the answer is usually to assess, verify, or report
Assuming a CISA waiver appliesCounting a master’s in business or years of help-desk work toward the five yearsA credential delayed by years after the exam is passedRead ISACA’s substitution table and map your own experience to it before you register
Sitting the CIA on experience aloneA ten-year IT auditor sits Part 1 after two weekends with a question bankA retake, a thirty-day wait, and a dented registration windowRead the Standards; the exam wants their answer
Letting the CISA application window passPassing the exam, changing jobs, and forgetting that certification must be applied for within five yearsThe exam againApply the moment the experience is verifiable; set the five-year date in the calendar the day the score arrives
Paying non-member feesRegistering for either exam without joining$525 extra for the CIA route; $185 extra for the CISA exam plus $40 a year on maintenanceJoin first; both memberships pay for themselves on the first exam
Choosing by which exam is easierPicking the CISA because it is one sitting, in a career that will need the CIAThe wrong credential first and the right one delayedChoose by the roles you want; the difficulty gap is months, the career gap is years
Reporting CPE to one bodyDoing the hours and reporting them to the IIA onlyA revoked CISA and reinstatement workOne certificate file, two deadlines, one calendar
Stopping at the first credentialAn IT audit manager with a CISA and no CIA, or a CAE with a CIA who cannot discuss technology risk without the IT audit director presentA visible gap at exactly the level where committees notice itPlan the second credential into the two years after each promotion

Which one first, then. If you audit systems, the CISA; if you audit everything else, the CIA; if you intend to lead an internal audit function, both, in the order your first job set for you. The exams are different in kind, the costs are modest against the value of either, and the mistake that costs the most is not choosing the wrong one but stopping at one when the role you want expects two.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading