The CIA and the CISA are compared constantly because the people who hold them sit next to each other. Every internal audit function of any size now has an IT audit team or wishes it did, every IT auditor is asked at some point to pick up a financial or operational engagement, and the two credentials that certify those halves of the department come from two different bodies with two different ideas of what an auditor is. The CIA, from The Institute of Internal Auditors, certifies command of the internal audit profession’s own Standards and the full range of engagements a function performs. The CISA, from ISACA, certifies the ability to audit, control, and secure information systems. Neither is a license, both are recognized worldwide, and which one you should pursue first depends on what you audit now and what you want to be auditing in five years.
This guide was rewritten in September 2026 with the current exam structures, fees, and eligibility rules for both credentials: the 2025 CIA syllabus and the CISA job practice that took effect in 2024. It compares them on what they certify, who qualifies, how the exams are built, how hard they are, what they cost, how long they take, what they do for a career by role, how they are maintained, and how to hold both. It is the IT-side companion to the CIA vs. CPA comparison, and it leans on the CIA exam roadmap for the detail of the CIA route.
In this guide
- What each credential certifies, and who grants it
- Eligibility: experience, education, and the waivers
- Exam structure side by side
- Difficulty: pass rates, study hours, and where each exam bites
- Cost: line items and three budgets for each
- Time to credential
- Career impact by role
- Keeping the credential: CPE, fees, and lapses
- The decision, by candidate profile
- Holding both: sequencing and shared CPE
- Common mistakes
What each credential certifies, and who grants it
The CIA is the IIA’s flagship certification and the only global credential specific to internal auditing. Its three parts cover the foundations of the profession and the Global Internal Audit Standards, the conduct of an engagement from planning through reporting, and the management of an internal audit function from the chief audit executive’s chair. It certifies breadth: a CIA is expected to plan a risk-based audit of anything, from route cash at a distributor to a treasury function at a bank, and to do it under the Standards the Standards overview describes. Technology appears throughout the syllabus, but as a subject an internal auditor must understand, not as the subject.
The CISA is ISACA’s credential for information systems audit, established in 1978 and now held by well over a hundred thousand people worldwide. Its five domains cover the IS audit process, IT governance and management, system acquisition and development, IT operations and resilience, and the protection of information assets. It certifies depth in one discipline: a CISA is expected to audit access management, change management, system development, operations, business continuity, and security controls, to read a SOC report intelligently, and to judge whether the technology environment supports the financial and operational controls the rest of the function relies on. The ITGC primer and the cybersecurity program audit guide describe the work the CISA certifies.
Put the two side by side and the shape of the choice is obvious. The CIA tells an employer you can run any engagement under the Standards and, in time, the function. The CISA tells an employer you can run the technology engagements that most generalists cannot, and that you can be trusted with the ITGC scoping, the access reviews, and the cyber work that regulators and external auditors ask about first. Internal audit needs both kinds of person, and the strongest IT audit leaders hold both credentials because their careers eventually require them to manage generalists and to sit in front of an audit committee that will ask about the Standards.
Eligibility: experience, education, and the waivers
The two credentials gate entry differently. The CIA gates on education first and adjusts the experience requirement to match; the CISA gates on experience, five years of it, and allows education and adjacent work to substitute for part of that total. The practical effect is that a graduate can begin the CIA program on day one of a first job and be certified inside two years, while the same graduate can pass the CISA exam early but will usually wait several years for the experience to accrue before the certification is granted.
| Requirement | CIA | CISA |
|---|---|---|
| Education | Determines the experience requirement: a master’s, a bachelor’s, the Internal Audit Practitioner designation, or no degree with more experience | Not required; a degree can substitute for part of the experience requirement |
| Experience required | Twelve months with a master’s, twenty-four with a bachelor’s, sixty with the IAP designation or no degree | Five years of professional information systems audit, control, or security work |
| What experience counts | Internal audit or equivalent work in seven qualifying fields, including external audit, compliance, quality assurance, and internal control | IS audit, IS control, or IS security work; ISACA verifies it against the CISA job practice domains |
| Waivers and substitutions | None beyond the education-based scale | Up to three years can be substituted: one year for a year of non-IS audit or general information systems experience, one or two years for a two-year or four-year degree, one year for a master’s in information security or IT, plus a small set of other qualifying credentials; check ISACA’s current table before counting on any of them |
| When experience must be earned | Before certification; the exam can be passed first | Within the ten years before the application, or within five years after passing the exam |
| Ethics and conduct | Character reference and agreement to the IIA Code of Ethics | Agreement to the ISACA Code of Professional Ethics and to the CPE policy |
| Program window | Three years from application approval to pass all parts, extendable for a fee | Certification must be applied for within five years of passing the exam |
| Membership | Not required; membership lowers fees | Not required; membership lowers fees |
The waiver table is where CISA candidates lose the most time to misunderstanding, and the safe reading is this: the exam can be sat at any point, the credential is granted when ISACA has verified five years of qualifying experience net of substitutions, and a bachelor’s degree plus a year of financial audit typically leaves a candidate needing two years of hands-on IS audit before the letters arrive. The CIA’s rule is simpler and more forgiving, which is one reason the CIA requirements guide is shorter than ISACA’s experience policy.
Exam structure side by side
Both exams are multiple choice, both are computer-delivered year-round, and both are scaled rather than raw-scored. The CIA spreads its content over three sittings totaling six and a half hours; the CISA puts everything into one four-hour sitting of 150 questions. That single-sitting format is the CISA’s defining feature: there is no partial credit for knowing three domains well, and a candidate who is weak in the two heaviest domains, operations and resilience and the protection of information assets, will fail regardless of strength elsewhere.
| Feature | CIA (2025 syllabus, English from 28 May 2025) | CISA (2024 job practice) |
|---|---|---|
| Parts | Three: Part 1 Internal Audit Fundamentals, Part 2 Internal Audit Engagement, Part 3 Internal Audit Function | One exam |
| Questions and time | Part 1: 125 questions, 150 minutes; Parts 2 and 3: 100 questions, 120 minutes each | 150 questions, 240 minutes |
| Content weights | Part 1: foundations 35%, ethics 20%, governance, risk, and control 30%, fraud 15%. Part 2: planning 50%, information gathering and analysis 40%, supervision and communication 10%. Part 3: operations 25%, the audit plan 15%, quality 15%, engagement results and monitoring 45% | Domain 1 Information Systems Auditing Process 18%; Domain 2 Governance and Management of IT 18%; Domain 3 Information Systems Acquisition, Development, and Implementation 12%; Domain 4 Information Systems Operations and Business Resilience 26%; Domain 5 Protection of Information Assets 26% |
| Scoring | Scaled 250 to 750, pass mark 600 on each part | Scaled 200 to 800, pass mark 450 |
| Delivery | Pearson VUE test centers, year-round; 180-day registration window per part | PSI test centers or online remote proctoring, year-round; a registration is valid for twelve months and the exam must be scheduled within it |
| Retakes | Thirty-day wait after a failed part; the part fee again | Limited attempts within a rolling year, with a waiting period between them; the full exam fee again |
| Languages | English plus rotating translations by part | English plus a set of translations that ISACA lists by exam |
| Question style | Standards-based judgment: which action is most consistent with the Standards | Practice-based judgment: what the IS auditor should do first, or which control best addresses a risk, with the ISACA answer favoring risk assessment and reporting over technical fixes |
Difficulty: pass rates, study hours, and where each exam bites
The IIA publishes pass rates; ISACA does not. The CIA’s cumulative rates on the current syllabus are 44 percent for Part 1, 48 percent for Part 2, and 56 percent for Part 3, which are low enough that the CIA difficulty guide exists to explain them. For the CISA the only figures in circulation are estimates from prep providers and forum surveys, which cluster around one in two, and none of them should be quoted as fact. What can be said from watching candidates is that the CISA fails people for a different reason than the CIA does: CIA candidates fail for answering as their firm practices rather than as the Standards say, and CISA candidates fail for answering as a technologist rather than as an auditor.
| Aspect | CIA | CISA |
|---|---|---|
| Published pass rates | Part 1 44%, Part 2 48%, Part 3 56%; Challenge Exam 47% | Not published; third-party estimates around 50 percent, unverifiable |
| Study hours, as commonly quoted by prep providers | 150 to 250 hours across three parts | 100 to 200 hours for the single exam, more for candidates without hands-on IS audit experience |
| Where the difficulty sits | Judgment questions with two defensible answers where only the Standards’ answer scores; Part 3’s chief-audit-executive viewpoint | ISACA’s way of thinking: the right answer is usually to assess risk, report to management, or verify a control rather than to fix the technology; Domains 4 and 5 carry more than half the marks |
| Who finds it easier | Practicing internal auditors who have read the Standards | Working IT auditors who have performed ITGC and application control reviews and read SOC reports |
| Who finds it harder | External auditors and candidates who study summaries rather than the Standards | Engineers and security specialists who know the technology and answer as operators; financial auditors with no IT exposure who cannot picture the controls |
| Sitting format risk | Three separate attempts; a weak part can be retaken alone | One four-hour sitting; no way to isolate a weak domain |
| Verdict | More total study and three sittings, with published evidence that most candidates fail at least one part | Less total study, one sitting, and a mindset shift that technical candidates underestimate |
Ask the people who hold both and most will say the CIA took longer and the CISA surprised them more. The CIA’s difficulty is honest and visible: three exams, published pass rates, a syllabus that runs to the whole profession. The CISA’s difficulty hides inside a single exam that looks, on the surface, like a knowledge test of technology terms, and turns out to be a test of whether you think like an IS auditor. The hardest CIA topics guide covers the first; for the second, ISACA’s own review manual and question database remain the preparation that maps to the exam.
Cost: line items and three budgets for each
Prices are as of September 2026 from the IIA’s and ISACA’s own fee pages, with prep materials at list price. Both bodies price the exam lower for members, and in both cases the membership pays for itself: the IIA’s $290 dues save $525 in CIA fees, and ISACA’s international dues of about $135, plus local chapter dues that vary, save $185 on the CISA exam and $40 a year on maintenance.
| Line item | CIA, IIA member | CIA, non-member | CISA, ISACA member | CISA, non-member |
|---|---|---|---|---|
| Application | $120 | $240 | None to sit the exam; $50 certification application after passing | $50 certification application |
| Exam | Part 1 $310; Parts 2 and 3 $280 each; $870 for three | Part 1 $445; Parts 2 and 3 $415 each; $1,275 for three | $575 | $760 |
| Membership | $290 a year ($200 public sector and educators; students free) | None | About $135 international dues plus chapter dues | None |
| Retake | The part fee, after thirty days | The part fee | $575, subject to the attempt limits | $760 |
| Other fees | Reschedule $75; program extension $275; registration extension $100 | Same | Rescore request $75; deferral fees apply if you move the exam outside the rules | Same |
| Annual maintenance | Included in dues; non-member reporting fee about $120 in North America | About $120 | $45 | $85 |
| Prep materials | Question bank from $499; full courses $899 to $1,599 at list, $764 to $1,199 with the member discount at the official partner | Same at list | ISACA review manual around $120; twelve-month question database $299; third-party courses roughly $300 to $1,500 | Manual and database at higher non-member prices; $399 for the database |
| Fees only, no retakes, no prep | $1,280 including a year of dues | $1,515 | $760 including dues and the certification application | $810 |
| Scenario | CIA line items (member) | CIA total | CISA line items (member) | CISA total |
|---|---|---|---|---|
| Frugal: self-study, no retakes | $990 fees, $290 dues, $499 question bank | $1,779 | $135 dues, $575 exam, $50 application, $120 review manual | $880 |
| Standard: official materials or mid-tier course, one retake for the CIA | $990 fees, $290 dues, $1,099 course, $280 retake, $75 reschedule | $2,734 | $135 dues, $575 exam, $50 application, $120 manual, $299 question database | $1,179 |
| Premium: top course, retakes, two years | $990 fees, $580 dues over two years, $1,599 course, $560 in retakes, $75 reschedule | $3,804 | $135 dues, $575 exam, $50 application, $1,500 third-party course, $299 database, $575 retake | $3,134 |
The CISA is the cheaper credential on every scenario and by a wide margin at the frugal end, because there is one exam fee instead of three and because ISACA’s own manual and question database are enough preparation for most working IT auditors. The CIA’s higher cost buys three separate sittings and a syllabus three times the size, which is a fair trade for what it certifies; the CIA cost guide has the full fee schedule, the hidden costs, and a reimbursement request script that works for either credential.
Time to credential
| Stage | CIA | CISA |
|---|---|---|
| Application and approval | Days to a few weeks in the candidate management system | Exam registration is immediate; the certification application comes after passing |
| Study and sittings | Nine to eighteen months for three parts around a full-time job; six for an experienced auditor who studies seriously | Three to six months for one sitting; longer for candidates without hands-on IS audit work |
| Experience | Twelve to sixty months depending on education; usually already met by working auditors | Five years net of substitutions; usually the gating item for candidates under thirty |
| Issuance | Weeks after experience verification | Weeks after ISACA approves the certification application |
| Realistic total for an experienced auditor | Twelve to twenty-four months, as little as six to nine | Four to eight months |
| Realistic total for a new graduate | Two to three years, with the exam passed early and the credential issued when experience is verified | Three to five years, with the exam passed early and the credential issued when experience net of substitutions reaches five years |
| What kills the timeline | Sitting Part 1 underprepared; letting the three-year window lapse | Assuming a waiver applies without reading ISACA’s table; letting the five-year application window pass |
Career impact by role
Credentials matter in hiring to the extent that the person reading the resume knows what they mean, and for these two the readers split cleanly. Internal audit leaders read the CIA as proof you know the profession; IT audit leaders, IT risk managers, security teams, external auditors’ IT specialists, and bank examiners read the CISA as proof you can audit a system. The table sets out what each does for you by role, with salary claims again left out, since ISACA’s and the IIA’s compensation surveys both report premiums for their own holders and both are self-reported.
| Role or path | What the CIA does for you | What the CISA does for you | The practical read |
|---|---|---|---|
| IT audit staff or senior | Helpful context; rarely decisive | The credential postings ask for; the one the hiring manager holds | CISA first, without much debate |
| IT audit manager or director | Increasingly expected, because the role now manages engagements under the Standards and reports to a CAE who will ask | Assumed; its absence in an IT audit leader draws questions | Both; CISA first if you lack it, CIA within two years of taking the manager role |
| Cybersecurity audit | Limited | Strong; often paired with CISM, CISSP, or CRISC as the work deepens | CISA plus a security credential; see the cybersecurity audit guide |
| SOX ITGC and application controls | Helpful for the control-testing method | Strong; external auditors’ IT specialists hold it and expect it | CISA; the ITGC scoping guide shows the work |
| Generalist internal auditor | The natural first credential | A differentiator for the generalist who wants the technology engagements | CIA first; CISA if you keep getting pulled onto IT work and like it |
| Audit manager, generalist function | Expected | Valued where the function has no IT audit team and the manager covers it | CIA; CISA optional |
| Chief audit executive | Expected; listed in most postings | A strong addition, because technology risk is the audit committee’s most frequent question and a CAE who can speak to it directly is rarer than one who cannot | CIA, with the CISA as the differentiator the CAE interview guide describes committees noticing |
| IT risk, IT GRC, or second-line technology risk | Limited | Strong; CRISC is the closer fit as the role moves from audit to risk management | CISA, then CRISC |
| SOC and third-party assurance at a CPA firm | Limited | Expected alongside the CPA for signing staff | CISA plus CPA |
| Information security operations | None | Some; CISM, CISSP, or hands-on security certifications count more | Neither is the right first credential |
| Data analytics within audit | Context for what to test | Context for where the data lives and how systems produce it | Either, plus demonstrated analytics work; the journal entry analytics guide is the kind of thing hiring managers want to see you have done |
| Bank and insurance IT audit | Valued by examiners as audit competence | Expected; examiners reviewing the IT audit function look for it | CISA, then CIA as you move up |
| Careers outside the United States | Recognized everywhere the IIA operates | Recognized everywhere ISACA operates, which is nearly everywhere | Either; both travel |
The pattern is symmetrical. The CISA is decisive for technology roles and a differentiator for generalist ones; the CIA is decisive for leadership roles in internal audit and a differentiator for technology ones. An IT auditor who never intends to manage generalists can spend a whole career on the CISA and its ISACA siblings. An IT auditor who wants to run a function needs the CIA eventually, because the audit committee, the external quality assessor, and the Standards the function is measured against all speak the IIA’s language. The By Role hub sets out both ladders, and the interview guide shows how credential questions are asked at each rung.
Keeping the credential: CPE, fees, and lapses
| Maintenance item | CIA | CISA |
|---|---|---|
| Continuing education | 40 hours a year for practicing CIAs, 20 for those not practicing | 120 hours per three-year cycle with a minimum of 20 in any year |
| Ethics | Two hours a year within the total | No separate hours requirement; adherence to the ISACA Code of Professional Ethics is a condition of holding the credential |
| Reporting | Between 1 October and 31 December; first report due 31 December of the year after certification | Annually, with the maintenance fee; the three-year cycle starts on 1 January after certification |
| Annual fee | Included in IIA membership; non-member reporting fee about $120 in North America | $45 for members, $85 for non-members |
| What counts | Courses, conferences, teaching, publishing, translating, presenting, subject-matter expert work, and external quality assessments, each under an annual cap | ISACA and third-party training, conferences, teaching, publishing, volunteer work, and self-study within ISACA’s category limits; ISACA’s own events carry free or discounted CPE for members |
| Records | Three years | Twelve months after the end of each reporting cycle at minimum; ISACA audits a sample |
| Lapse | Grace, then inactive, then revocation after an extended lapse; Part 1 must be passed again to recertify | Revocation for non-compliance with CPE or fees; reinstatement requires the missing hours, fees, and in some cases the exam again |
| Shared credit for dual holders | Most audit, controls, governance, and technology risk courses count for both; a dual holder needs roughly the same 40 hours a year, reported twice, with one certificate file tagged by both bodies’ categories | |
The detail for the CIA side is in the CIA CPE guide and the maintenance guide. For the CISA, ISACA’s CPE policy document is short and worth reading once, because its category caps differ from the IIA’s and dual holders who plan their year around the IIA’s rules occasionally find a block of hours that ISACA counts differently.
The decision, by candidate profile
| Profile | Recommendation | Sequence | Why |
|---|---|---|---|
| New graduate joining an IT audit team | CISA exam early, CIA later | Pass the CISA exam in year one and bank it; certification arrives when the experience does; add the CIA around year three | The exam is fresh in your mind and the five-year experience clock is the constraint, not the test |
| New graduate joining a generalist internal audit team | CIA | CIA within two years; CISA only if you gravitate to the technology engagements | The CIA is the credential your function reads and the experience rule is met quickly |
| IT auditor with three to five years and no credential | CISA | CISA in four to eight months, then decide about the CIA based on whether management is the goal | Its absence is the first thing an IT audit hiring manager notices |
| CISA holder promoted to manage a mixed team | Add the CIA | Three parts inside eighteen months, Part 3 last | You now run engagements under the Standards and report to a CAE and a committee that will ask about them |
| CIA holder pulled into ITGC and access work | Add the CISA | One sitting after three to six months of study; count your audit experience toward the waiver | The external auditor’s IT specialists and the CIO’s team both read it; your CIA does not cover the ground |
| Engineer or security analyst moving into audit | CISA | CISA first, studying the auditor mindset rather than the technology; CIA later if you move toward leading a function | Your technical knowledge is the easy part; the exam tests whether you think like an auditor |
| Financial auditor with no IT exposure who wants it | CIA first, then CISA | CIA to secure the audit credential; CISA once you have a year of hands-on IT audit work to make the material concrete | The CISA exam is much harder to pass on reading alone |
| Aspiring CAE from an IT audit background | Both | CIA now if you lack it; keep the CISA current | The committee expects the CIA; the CISA is your differentiator |
| Aspiring IT risk or GRC leader | CISA, then CRISC | CISA first; CRISC as the role moves from audit to risk management; the CIA is optional | Second-line technology roles read ISACA credentials, not the IIA’s |
| Consultant or co-source provider | Both, over time | Whichever matches your current engagements first | Clients read the CIA for internal audit services and the CISA for technology assurance |
Holding both: sequencing and shared CPE
Holding both is the normal end state for IT audit leaders and an increasingly common one for generalist managers, and the sequencing question answers itself if you start from the experience rules. The CISA’s exam can be passed years before the credential is granted, so a candidate on the IT side should sit it early and let the experience accrue; the CIA’s credential follows the exam quickly for anyone with a degree and two years in audit, so it is the one to complete when you want letters on the resume now. A candidate who starts in IT audit typically holds the CISA by year three and the CIA by year five; one who starts as a generalist typically reverses the order. Neither body offers a shortcut for holders of the other: there is no CIA Challenge Exam for CISAs, and ISACA grants no exam waiver for CIAs, though the CIA’s audit experience counts toward the CISA’s experience requirement under the non-IS audit substitution.
The maintenance overlap is where holding both stops costing extra. Forty hours a year satisfies the IIA outright and puts you on pace for ISACA’s 120 per cycle; an audit or technology-risk course counts for both, an IIA conference counts for ISACA and vice versa, and only the reporting is duplicated. Keep the two deadlines in one calendar, tag each certificate with both bodies’ categories when you file it, and pay ISACA’s maintenance fee with the CPE report rather than treating it as a separate task, because a missed fee revokes a CISA as surely as missed hours do. The one trap is category caps: the IIA caps publishing, presenting, and similar categories at annual limits that ISACA sets differently, so a year built heavily on teaching or writing can satisfy one body and fall short for the other.
Common mistakes
| Mistake | What it looks like | Cost | Fix |
|---|---|---|---|
| Treating the CISA as a technology exam | An engineer studies the protocols and fails on the audit judgment questions | A $575 retake and a waiting period | Study ISACA’s manual for how the IS auditor thinks; the answer is usually to assess, verify, or report |
| Assuming a CISA waiver applies | Counting a master’s in business or years of help-desk work toward the five years | A credential delayed by years after the exam is passed | Read ISACA’s substitution table and map your own experience to it before you register |
| Sitting the CIA on experience alone | A ten-year IT auditor sits Part 1 after two weekends with a question bank | A retake, a thirty-day wait, and a dented registration window | Read the Standards; the exam wants their answer |
| Letting the CISA application window pass | Passing the exam, changing jobs, and forgetting that certification must be applied for within five years | The exam again | Apply the moment the experience is verifiable; set the five-year date in the calendar the day the score arrives |
| Paying non-member fees | Registering for either exam without joining | $525 extra for the CIA route; $185 extra for the CISA exam plus $40 a year on maintenance | Join first; both memberships pay for themselves on the first exam |
| Choosing by which exam is easier | Picking the CISA because it is one sitting, in a career that will need the CIA | The wrong credential first and the right one delayed | Choose by the roles you want; the difficulty gap is months, the career gap is years |
| Reporting CPE to one body | Doing the hours and reporting them to the IIA only | A revoked CISA and reinstatement work | One certificate file, two deadlines, one calendar |
| Stopping at the first credential | An IT audit manager with a CISA and no CIA, or a CAE with a CIA who cannot discuss technology risk without the IT audit director present | A visible gap at exactly the level where committees notice it | Plan the second credential into the two years after each promotion |
Which one first, then. If you audit systems, the CISA; if you audit everything else, the CIA; if you intend to lead an internal audit function, both, in the order your first job set for you. The exams are different in kind, the costs are modest against the value of either, and the mistake that costs the most is not choosing the wrong one but stopping at one when the role you want expects two.
Related guides
- CIA vs. CPA
- The ultimate guide to passing the CIA exam
- CIA exam requirements
- How hard is the CIA exam
- CIA exam cost breakdown
- CIA CPE requirements
- ITGC audit primer for non-IT auditors
- ITGC vs. application controls
- How to audit identity and access management
- Auditing cybersecurity programs
- Auditing cloud risk
- Internal audit interview questions
- Internal audit careers by role
- Start here
- The CIA exam, explained — requirements, the three parts and their 2025 weightings, every fee, scoring, twelve-week study plans and a directory of every CIA guide on this site
- Free CIA practice questions — an interactive 156-question bank across all three parts with a rationale for every option, in study and exam modes
Leave a Reply