,

CISA for Internal Auditors: When It Is Worth It, What It Tests and How to Pass

The CISA is the certification internal auditors ask about most after the CIA, and the question is rarely “how do I pass it”. It is “is it worth it for me”, asked by a financial auditor who keeps being handed the IT general controls section, by a senior who wants the IT audit manager role when it opens, or by a small-shop generalist who is the closest thing the function has to a technology auditor. This guide answers that question first, with a profile-by-profile view of who gains from the credential and who does not, and then covers the rest: what the 2024 job practice actually tests and how each domain shows up in internal audit work, the requirements, costs and timeline as ISACA publishes them, a twelve-week study plan built around a full-time audit job, how ISACA writes its questions, what to do with the credential in the first year after passing, and how to keep it.

Everything factual here comes from ISACA’s own certification pages as they stood in September 2026. Fees, waivers and the job practice change on ISACA’s schedule, not ours, so treat the figures as a snapshot and confirm them on the registration page before you pay. Where we give an opinion, it is labelled as one. For the head-to-head decision between the two big credentials, see CIA vs CISA; for the internal audit credential itself, start with the CIA exam requirements.

In this guide

What the CISA certifies, and what it does not

The Certified Information Systems Auditor is ISACA’s credential for people who audit, control, monitor and assess information systems. ISACA introduced it in 1978, which makes it older than most of the technology it is now used to audit, and its own count of holders since inception runs well past 150,000. The exam is 150 multiple-choice questions in four hours, scored on a scale of 200 to 800 with 450 as the pass mark, and it is offered year-round at PSI test centers and by remote proctoring. Passing the exam does not make you a CISA. Certification requires five years of information systems auditing, control or security experience, with waivers available for up to three of those years, an application within five years of passing, and then continuing education to keep it.

What the credential certifies is narrower than the marketing suggests and broader than sceptics assume. It certifies that you know how an information systems audit is planned, evidenced and reported; how IT governance and management are supposed to work; what good looks like in system acquisition and development; how operations and resilience are controlled; and how information assets are protected. It does not certify that you can configure a firewall, read a packet capture or write a query. A CISA who has never touched a production system is a common and legitimate thing, in the same way a CIA who has never run a warehouse count is.

For an internal auditor the honest description is this: the CISA is the shared vocabulary of IT audit. It is what lets a financial auditor read a SOC 1 report without asking the IT team what a complementary user entity control is, scope ITGCs and application controls without confusing the two, and sit across from a security architect without being talked past. It is also the credential most often named in IT audit job postings, in our reading of them, which matters less for what it proves and more for what it lets recruiters filter on. The rest of this guide takes those two uses, competence and signalling, seriously and separately, because they pay off for different people.

Who should take it: five internal audit profiles

Most “is it worth it” advice is written for the median candidate, who does not exist. The question splits cleanly by where you sit and where you want to go, and the five profiles below cover nearly everyone who asks it. Read yours, then read the one above and below it, because the boundaries are where the interesting cases sit.

ProfileWhere the CISA helpsWhere it does notOur view
Financial or operational auditor who keeps inheriting ITGC sectionsDomains 1, 2 and 5 map directly onto the access, change and operations work you are already doing without a framework for itWill not make you the IT auditor; the function still needs someone who can test a configurationTake it. The study is the training the function never gave you, and the credential stops the “you are not an IT auditor” objection in scoping meetings
IT auditor in a large function without the credentialSignalling: manager and lead roles increasingly filter on it, and external moves almost always doYou already have the competence; the exam will feel like documentation of what you knowTake it soon. Every year you wait is a year the filter costs you options, and the study time is low for you
Small-shop generalist who is the function’s de facto technology auditorStructure for the technology universe, a defensible basis for the IT audit plan, credibility with the IT directorCannot replace co-sourced specialists for penetration testing or cloud configuration reviewsTake it, and pair it with one deep skill (identity, cloud or ERP) chosen from the organization’s own risk profile
Senior or manager aiming at CAEBroad literacy across the IT risk universe that a board will ask about; complements the CIA rather than competing with itBoards do not hire CAEs for certifications; they hire for judgment and stakeholder recordOptional. Worth it if technology is more than a third of your audit universe, or if your route runs through an IT audit leadership role
Career changer from IT operations, security or developmentThe fastest bridge into audit: experience waivers recognize your years, and the domains you find hard (1 and 2) are the ones the exam weights sensiblyDoes not teach audit judgment: evidence, sampling, finding severity, report writing come from doing the workTake it early, then learn the audit craft deliberately; the guides on audit evidence and finding severity ratings are the two places to start

Two profiles are missing from the table on purpose. The auditor who wants the credential because a colleague has it should read the salary question in the internal auditor salary guide before spending a year of evenings on a signal that may not move their pay. And the auditor who has decided IT audit is not for them should not take the CISA as a hedge; the CIA, or the CFE for a fraud path (see CIA vs CFA for how the comparison works with another credential), is a better use of the same hours. Certifications are cheap compared with the time they consume, and the time is the real cost.

The 2024 job practice, translated into internal audit work

ISACA revises the CISA job practice every few years from a survey of what practitioners actually do, and the version in force is the one introduced in 2024. It has five domains, and the weights tell you where the questions are. The two heaviest, operations and resilience and protection of information assets, are together more than half the exam, which surprises candidates who assumed the CISA was mostly about auditing. It is mostly about what is being audited. The table below gives each domain’s weight, what ISACA puts in it, and where the same material appears in internal audit work, because the fastest way to learn a domain is to recognize that you have already done parts of it.

DomainWeightWhat ISACA puts in itWhere you have already met it
1. Information Systems Auditing Process18%Audit standards and guidelines, risk-based planning, evidence, sampling, data analytics, reporting, follow-up, quality assuranceEvery engagement you have run; the vocabulary differs from the IIA’s but the logic is the same, and the audit work program guide is the internal audit version of the same planning discipline
2. Governance and Management of IT18%IT strategy and its alignment with the enterprise, organizational structure, policies, risk management, resource and portfolio management, IT performance measurement, vendor and outsourcing managementGovernance audits, the entity-level portion of SOX work, and every vendor master audit or third-party review you have touched
3. Information Systems Acquisition, Development and Implementation12%Business case and feasibility, project governance, system development methodologies, control identification and design, testing, data migration, post-implementation reviewPre- and post-implementation reviews, and the pipeline work described in the SDLC and DevOps pipeline audit
4. Information Systems Operations and Business Resilience26%IT asset and job scheduling, end-user computing, systems performance, problem and incident management, change and patch management, backup and recovery, business impact analysis, continuity and disaster recoveryThe ITGC change and operations work in IT change management audits and backup and recovery audits, and the resilience engagements in business continuity and organizational resilience
5. Protection of Information Assets26%Security frameworks and standards, privacy, physical and environmental controls, identity and access management, network and endpoint security, data classification and encryption, public key infrastructure, security awareness, incident response and forensicsAccess reviews and privileged access work such as the IAM audit and the Active Directory and Entra ID audit, privacy audits, and the incident response coverage in the incident response audit

Three things follow from the weights. First, an internal auditor with two or three years of ITGC exposure already holds most of domains 1, 2 and 4 and should budget study time toward domain 5, which is where the unfamiliar vocabulary lives: cryptographic concepts, network architecture, the mechanics of authentication. Second, domain 3 is small but has the most “which comes first” questions, because it is a lifecycle, and lifecycle questions punish candidates who learned the topics as a list. Third, ISACA tests the auditor’s perspective inside every domain. A domain 5 question about encryption is rarely about how encryption works; it is about what an auditor should verify, recommend or conclude. Candidates who study the technology and forget the role fail domain 5 despite knowing more about security than the people who pass it.

One more translation. The CISA’s audit process domain is written against ISACA’s own standards, the ITAF framework, not the Global Internal Audit Standards. The concepts line up closely, risk-based planning, sufficient and appropriate evidence, documented conclusions, communication of results, follow-up, but the numbering and some terms differ. Learn ITAF for the exam; keep practising to GIAS at work. Nobody will ask you in an audit committee meeting which standard you cited in your workpapers, but the exam will ask which ISACA standard applies to a scenario.

Requirements, costs and timeline

The requirements are simpler than the CIA’s and the costs are higher per exam, because there is one exam rather than three. What follows is ISACA’s published position as of September 2026, with the two places candidates most often go wrong called out: the experience window and the deadline for applying after you pass.

ItemISACA’s positionWhat candidates get wrong
Exam eligibilityAnyone may register and sit the exam; no prerequisite experience or degree to sitAssuming they must have the experience first. You can pass early and accumulate the experience afterward
Exam fee575 dollars for ISACA members, 760 dollars for non-members, per attempt; registration is valid for twelve monthsNot pricing membership. Annual dues are in the low hundreds of dollars plus chapter dues, and the member discount on the exam and study materials usually covers most of them; check the current dues before deciding
Exam format150 multiple-choice questions, 240 minutes, scaled score 200 to 800, pass mark 450; PSI test centers or online remote proctoringTreating 450 as 75 percent. It is a scaled score, and the raw percentage needed varies with the form; aim to be consistently above 75 percent on practice questions and stop trying to reverse-engineer the scale
Experience for certificationFive years of professional information systems auditing, control or security work experience, gained within the ten years before the application or within five years of passing the examLetting the ten-year window slide. Experience older than ten years at the date you apply does not count
Experience waiversUp to three years may be substituted: one year for a year of non-IS auditing or of information systems experience, one to two years for completed university credit, one year for a master’s degree in information security or IT from an accredited university, among others as listed by ISACAAssuming financial audit years count in full. A year of non-IS audit experience substitutes for one year, and the total substitution is capped
ApplicationWithin five years of the passing date; 50-dollar application fee; experience verified by an employer or supervisorPassing, changing jobs twice, and discovering at year six that the pass has expired
MaintenanceMinimum 20 CPE hours each year and 120 per three-year cycle; an annual maintenance fee, lower for members; agreement to the ISACA Code of Professional Ethics; CPE subject to auditReporting hours that are not verifiable. Keep the certificates

Put together, a realistic all-in cost for a first-time member candidate who passes once is the membership dues, the exam fee, the review manual and a question database, and the application fee, which lands in the low four figures in dollars and is usually reimbursable under an employer’s professional development policy. The timeline for a working auditor is three to four months of preparation, an exam date chosen when registering rather than when ready, and then the application as soon as the experience is in place. Compare that with the multi-part structure and cost breakdown in the CIA exam cost guide and the CISA looks expensive per sitting and cheap per credential.

A twelve-week study plan around a full-time audit job

The plan below assumes eight to ten hours a week, a busy-season-free window, the current ISACA review manual and a question database, and an exam date already booked for the end of week twelve. Booking first is the single most effective study technique we know; candidates who plan to book “when ready” are still not ready a year later. The plan front-loads the two heavy domains, puts the audit process domain last because it is the one an internal auditor needs least time on, and reserves the final three weeks for practice questions, which is where CISA exams are actually passed.

Weeks 1 to 2: Domain 5, Protection of Information Assets (26%). Read the domain in full, then build a one-page glossary of every term you did not already know: authentication factors, PKI components, network zoning, encryption at rest versus in transit, data classification levels, incident response phases. Fifty practice questions at the end of week two, reviewed answer by answer.

Weeks 3 to 4: Domain 4, Operations and Business Resilience (26%). Map each topic to an engagement you have done or seen: change management, patching, backup, job scheduling, incident and problem management, business impact analysis, recovery objectives. Note where the exam’s expected answer differs from your organization’s practice; those are the questions you will get wrong by experience. Fifty questions.

Weeks 5 to 6: Domain 2, Governance and Management of IT (18%). Governance frameworks, IT strategy alignment, policies and standards, risk management, vendor management, performance measurement. Internal auditors usually find this the easiest domain to read and the hardest to score on, because the questions ask for the best governance answer rather than the practical one. Fifty questions.

Week 7: Domain 3, Acquisition, Development and Implementation (12%). Learn it as a lifecycle with controls at each gate, not as a list. Draw it once from memory. Thirty questions.

Week 8: Domain 1, Information Systems Auditing Process (18%). ITAF standards and guidelines, risk-based planning, evidence, sampling, analytics, reporting and follow-up. Fast for a practising auditor; spend the time on ISACA’s terminology and on the question style. Fifty questions.

Week 9: First full-length practice exam. 150 questions, timed, in one sitting. Score by domain. Anything under 70 percent goes back on the list for week ten.

Week 10: Targeted review. Reread the weak domains against the notes from weeks one to eight, not the manual from scratch. A second batch of 100 mixed questions.

Week 11: Second full-length practice exam, then a review of every wrong answer with a written note on why the correct answer is the better one from an auditor’s point of view.

Week 12: Light review, glossary, logistics. Confirm the test center or the remote-proctoring system check, read the candidate guide, and stop studying two days before the exam. Fatigue loses more marks than an extra chapter gains.

Two adjustments. A candidate coming from IT operations or security swaps the order: domains 1 and 2 first, because they are the unfamiliar ones, and domain 5 last as a confidence-builder. A candidate with under two years of any audit experience should stretch the plan to sixteen weeks and read the domain 1 material twice, since the audit judgment the exam expects is easier to learn from the manual than from nothing. Either way, keep a log of hours; the habit transfers directly to CPE tracking later, and it tells you honestly whether the plan is slipping before the exam does.

How ISACA writes questions, and how to answer them

ISACA questions have a house style, and most failed first attempts are a failure to read the style rather than a failure of knowledge. The stem describes a situation and asks for the BEST, MOST important, PRIMARY or FIRST response. Two of the four options are usually wrong on the facts. The other two are both defensible, and the exam wants the one an information systems auditor would choose, which is generally the one that addresses the control objective, precedes the others in a logical sequence, or reflects the auditor’s role rather than management’s. A candidate who answers as the IT manager, the security engineer or the project sponsor will pick the plausible wrong option with great confidence.

Some rules that hold across all five domains. Where an option says the auditor should fix, implement or configure something, it is nearly always wrong; auditors assess, recommend and report. Where the question asks what to do first, the answer is usually to understand, assess or verify before acting. Where two options differ only in scope, the broader control objective beats the specific mechanism. Where an option mentions the business objective, the risk to the business or management’s accountability, it beats a purely technical option. And where the stem includes a detail that seems irrelevant, it is not; ISACA stems are edited hard, and a stray fact is there to distinguish the best answer from the second best.

Timing is rarely the problem: 240 minutes for 150 questions is 96 seconds each, and most candidates finish with 40 minutes to spare. Use them. Flag every question where you narrowed to two, and come back to the flagged set with the whole exam’s context in your head, because a later question often reveals how ISACA thinks about an earlier one. Do not change an answer without a reason you could write down; changing on feel loses marks on average. And read the practice-question explanations for the options you rejected as carefully as for the one you chose. The explanation of why a good-looking option is wrong is where ISACA’s reasoning is most visible, and that reasoning is the exam.

The first twelve months after passing

A credential earns its keep in the year after the exam or not at all. The auditors who report that the CISA changed their work are the ones who changed their work: they asked for the engagements the credential qualified them for, rebuilt a piece of the audit universe, or moved. The ones who report that it made no difference usually put the letters on a signature block and waited. The table sets out what to do, in order, and what each step is for.

WhenWhat to doWhy it matters
Week of the passSubmit the certification application if the experience is in place; if not, write down the date the five-year application window closes and the date each waiver-eligible item was earnedThe application deadline is the one candidates miss; the experience window is the one they misunderstand
First monthAsk the chief audit executive for the next IT-heavy engagement, and name it: the ITGC scope of the SOX program, a change management audit, an access review, a SOC report reviewCompetence is proven on engagements, and the request is far easier to grant right after a pass than at plan time
First quarterRe-read the technology portion of the audit universe and risk assessment with the domain 2 and 4 material in mind; propose one change, with reasons, to the CAEThe exam gave you a framework for what the universe should contain; the guide on building the IT audit plan shows what a coverage map built that way looks like
Months four to sixChoose one deep skill to pair with the credential, driven by the organization’s risk profile rather than by fashion: identity, ERP security, cloud configuration or data analyticsThe CISA is broad by design; the market pays for breadth plus one thing you can do better than the IT team expects
Months six to nineTake the lead, or the second seat, on an engagement where you write the IT findings yourself and defend them with the IT directorFinding quality is what the credential cannot certify and what promotion committees notice
Month twelvePrice yourself against the market for the role you now do, not the one you were hired into, using the method in the internal auditor salary guide; raise it internally before looking externallyThe signalling value of the credential is highest in the first two years; use it while it is fresh

One warning that belongs here rather than in the exam section. A newly certified auditor who has never tested a system will be tempted to hide behind the credential when an IT manager pushes back. Do not. Say what you tested, what you found and what standard or policy you measured it against, in the plain form described in the 5 Cs of audit findings, and let the credential sit quietly on the report cover. Credibility with technologists comes from being right about their systems, and they can tell the difference within a meeting.

Keeping it: CPE, the maintenance fee and the audit

ISACA’s maintenance requirements are a minimum of 20 continuing professional education hours reported each year, 120 hours across each three-year cycle, an annual maintenance fee that is lower for members, and continued adherence to the Code of Professional Ethics. ISACA selects a sample of certificants each year for a CPE audit and asks for supporting documentation, so the practical rule is to keep the certificate or attendance record for every hour claimed, for the whole cycle plus a year. Internal auditors rarely struggle to find the hours; most functions run internal training, conferences and vendor sessions that count, and ISACA chapter meetings are a standing source. The struggle is the record-keeping, and it is the same struggle as the one described in the CIA CPE requirements guide for the CIA, which is why a single CPE log for every credential you hold is the only system that survives contact with a busy year.

Two points of design. First, hours earned for the CIA generally qualify for the CISA and the reverse, subject to each body’s rules on relevance, so a dual-credentialed auditor is not doing double the learning, only double the reporting. Second, the three-year cycle rewards front-loading: sixty hours in year one, when the material is fresh and the appetite is high, leaves two light years and removes the December scramble that produces unverifiable hours. If the cycle lapses, ISACA’s reinstatement route exists but costs more in fees and paperwork than the hours would have; treat the annual minimum as a floor, not a target.

Worked example: a small-shop auditor makes the case

MidState Beverage runs a six-person internal audit function for a three-state drinks distributor with twelve depots, a 2013 ERP and no compliance department. One of the six is the analytics and IT auditor, who joined the function three years ago after two years on MidState’s IT service desk and as a junior systems analyst. She had run the ERP user access audit, built the first accounts payable analytics run, and carried the technical half of the cyber program audit that produced eleven findings and a Level 2 rating. What she did not have was a credential, and when the chief audit executive wrote the function’s three-year strategy, with technology coverage as its first objective, she asked whether the CISA was the right next step or an expensive badge.

The case she made to the CAE fitted on one page. The IT audit universe stood at 38 items after the cyber audit, most of them assessed by her alone, and the FY28 plan carried a directory change control audit, a 120-hour identity follow-up and the resilience engagement in the second half. The function could not afford a second IT auditor and the co-source budget was already committed. What it could afford was a structured body of knowledge for the person it had, at a cost in the low four figures: ISACA membership, the exam, the review manual and question database, and the application fee, all within the professional development line. The CAE approved it under the technology coverage objective and asked for one thing in return, a rewritten IT section of the audit universe after the exam.

She booked the exam for the end of a twelve-week window in the quietest quarter of the year, after the validation of the prior year’s findings and before the depot rotations. The plan above was hers with one change: she started with domain 1, because ITAF terminology was new to her even though the audit process was not, and she left domain 4 to the end because change, backup and incident management were the areas she had audited most recently. Her first full-length practice exam scored 64 percent overall and 52 percent on domain 5; her glossary for that domain ran to four pages. Her second scored 78 percent. She passed at the first sitting with a scaled score comfortably above the mark, and spent the following week on a question she had not thought about until then: whether she was eligible to certify.

She was not, quite. Her three years in the function counted as information systems audit experience in full, because the engagements she had led were IS audits. Her two years in IT operations counted for at most one year under the substitution rules. Four years against a five-year requirement, with a five-year window from the pass date to apply; she diarized the application for the following year, kept the CAE’s confirmation letters, and noted the date her oldest experience would fall outside the ten-year window, which was not a concern but is the kind of thing an auditor writes down.

The universe rewrite was where the credential paid. Working from the domain 2 and domain 4 material she added two items that the function had been auditing around rather than auditing: the managed security service adopted after the cyber audit, as a third-party arrangement with its own control expectations, and the depot handheld fleet, 380 devices of which fewer than 200 sat under mobile device management, as an asset population rather than a footnote to the network. She led the IT findings on the directory change control audit, wrote them herself, and defended them with the IT director in a meeting that ended with an agreed action plan rather than a dispute about whether an auditor could understand Active Directory. Twelve months after the pass, the CAE’s report to the audit committee under the technology coverage objective cited a 40-item IT universe with 60 percent of it covered in the cycle, up from a 38-item universe with less than half; and the analytics and IT auditor, now with a market-priced comparison from the salary guide in hand, had a conversation about her band that the CAE had been expecting.

The lesson is not that the CISA made her better at Active Directory. It is that the credential gave a one-person IT audit capability a framework to plan against, a language to use with the IT director, and a reason to ask for the work that proved it, and that the function got a rewritten universe for the price of an exam fee. That is the deal a small shop should be looking for.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading