What is CISA and who is it for?
CISA stands for Certified Information Systems Auditor, the longest-established credential of ISACA, the professional association for information systems audit, governance, risk and security. It certifies the ability to audit, control and assure information systems β not to build them β which is why it is held far more widely by internal auditors, external auditors and compliance professionals than by technologists. To be certified you must pass the proctored CISA examination, which covers five job practice domains: the information systems auditing process; governance and management of IT; information systems acquisition, development and implementation; information systems operations and business resilience; and protection of information assets. You must also document five years of relevant professional experience in information systems auditing, control or security, with defined waivers of up to a maximum period for degrees and certain other credentials, apply for certification within the window ISACA allows after passing, and agree to ISACA's Code of Professional Ethics and its auditing standards. Certification is maintained through annual and three-year continuing professional education requirements.
- CISA is an audit and assurance credential covering information systems, not a hands-on technical qualification.
- Certification requires five years of relevant experience with defined waivers, plus the examination.
- Passing the exam is separate from being certified β the experience application and ethics agreement complete it.
- It is maintained continuously through annual and three-year continuing professional education requirements.
CISA at a glance
| Cost | ISACA sets exam registration, application and annual maintenance fees, which differ for members and non-members and are revised periodically β see ISACA's current fee schedule |
| Duration | A proctored examination of four hours across five domains |
| Issued by | ISACA |
| Format | Proctored multiple-choice examination at a test centre or by remote proctoring, plus an experience-based certification application |
| Expiry | Maintained continuously through annual and three-year continuing professional education requirements plus an annual maintenance fee |
| Who needs it | Internal and external auditors, IT auditors, compliance and risk professionals, and audit managers in regulated industries |
| Experience | Five years of relevant information systems audit, control, assurance or security experience, with defined waivers |
| Domains | Audit process; governance of IT; acquisition and development; operations and resilience; protection of information assets |
Sources: ISACA, official site Β· ISACA CISA certification. Reviewed August 2026 by the GlobalCybers team.
The Exam, the Experience Rule and the Application
Passing the exam is not being certified
Candidates frequently conflate the two. Passing the examination is one requirement; certification additionally requires documenting five years of relevant experience, submitting the application within the window ISACA allows after passing, and agreeing to the Code of Professional Ethics and ISACA's auditing standards. Waivers reduce the experience requirement for defined degrees and credentials up to a published maximum, so many candidates sit the exam first and complete the experience afterwards.
The five job practice domains
Does CISA matter outside technology companies?
It matters most in internal audit and compliance functions across regulated industries β banking, insurance, healthcare, utilities and government β where audit plans increasingly concentrate on systems and data rather than on paper processes. BLS reports pay by occupation, not by credential.
GlobalCybers reimburses certification fees after a successful permanent placement through our network.
What CISA Covers, Job Practice Areas
Audit Method First
The largest domain is the audit process itself. CISA is an auditing credential that happens to be about systems, not a systems credential that mentions auditing.
Governance of IT
Structures, policies, roles and how technology decisions are made and overseen β the questions a board-level audit committee cares about.
Access Controls
Provisioning, review and segregation of duties are where systems audit and financial audit meet, and where most findings are actually raised.
Resilience
Backups, continuity and recovery testing. Regulators and audit committees look closely at whether the plan has ever been genuinely exercised.
Evidence Discipline
Sampling, sufficiency and documentation β the difference between an observation and a finding that survives management challenge.
Ethics & Standards
Certification carries an obligation to ISACA's Code of Professional Ethics and its auditing standards, which is what makes the credential meaningful to regulators.
How do you get CISA certified, step by step?
Check the experience requirement and its waivers
Five years of relevant information systems audit, control, assurance or security experience is required for certification, with defined waivers up to a published maximum for degrees and certain other credentials. Confirm the current rules with ISACA before planning.
Prepare against the job practice domains
ISACA publishes the domains and their weightings, and the audit process domain carries the most. Candidates from a technology background usually need to work hardest on audit method rather than on the technical content.
Register and sit the proctored exam
The examination is delivered at test centres and by remote proctoring across ISACA's testing windows. Registration and application fees differ for members and non-members and are revised periodically, so check the current fee schedule.
Apply for certification with documented experience
Passing is not being certified. Submit the certification application with verified experience within the window ISACA allows after passing, and agree to the Code of Professional Ethics and the auditing standards.
Maintain it with CPE every year
ISACA sets annual and three-year continuing professional education minimums plus an annual maintenance fee. Log hours as they happen β the annual minimum makes it impossible to catch up entirely at the end of a cycle.
Why Regulated Industries Ask for CISA
No law requires an individual auditor to hold CISA. What creates the demand is the regulatory environment around the work: financial services examinations, healthcare privacy and security requirements, utility and critical-infrastructure standards and public sector audit expectations all push organisations to demonstrate that systems controls are examined by qualified people. Internal audit departments and audit firms use the credential as evidence of that qualification, and it appears routinely in IT audit job specifications and in requests for proposal from external audit providers.
CISA Certification, Frequently Asked Questions
CISA certified? Audit teams are hiring.
Internal audit functions in regulated industries recruit systems auditors. Tell us your sector and experience.
Join the Network βMore about CISA
Your career research journey
Do your homework, then let the network do the rest.Get the job, then keep rising
FreeSet your intent, matching jobs come to you. No applying.
A roadmap to your next licence tier and higher pay band.
Once placed, we cover all certification, licence & career-guide fees.
Hiring trade workers?
Get a verified shortlist of 3β5 qualified candidates in 48 hours
GlobalCybers verifies active state licenses, trade certifications, Intent and right-to-work status before any candidate reaches your portal. Flat $2,999/mo RPO (Recruitment Process Outsourcing), up to 3 concurrent roles, or a free trial (pay on hire). 90-day written guarantee.