What is ISACA certification and which credential should I choose?
ISACA is a global professional association for information systems audit, governance, risk, security and privacy, and it issues several distinct certifications rather than one. The best known is the Certified Information Systems Auditor, the audit and assurance credential. Alongside it sit a certification for information security management aimed at security leadership rather than hands-on engineering, one for risk and information systems control aimed at risk professionals, one for governance of enterprise IT aimed at senior leaders accountable for how technology is directed and overseen, and a data privacy engineering credential covering the technical implementation of privacy. ISACA also issues shorter certificates and foundational credentials for people entering the field. All of the flagship certifications share a common architecture: a proctored examination against published job practice domains, a documented professional experience requirement, agreement to ISACA's Code of Professional Ethics, and ongoing continuing professional education with annual and three-year minimums plus a maintenance fee. Choosing between them is a question of role, not of difficulty ranking.
- ISACA is an association issuing several distinct certifications, not a single credential.
- Credentials map to different roles: audit, security management, risk and control, IT governance and data privacy.
- All flagship certifications combine an examination with verified experience and an ethics agreement.
- Every credential is maintained through annual and three-year continuing professional education plus a maintenance fee.
ISACA at a glance
| Cost | Examination, application and annual maintenance fees are set per credential by ISACA and differ for members and non-members β see ISACA's current fee schedule for the credential you are considering |
| Duration | Each flagship credential is a single proctored examination, typically four hours |
| Issued by | ISACA |
| Format | Proctored examination against published job practice domains, plus an experience-verified certification application |
| Expiry | Maintained continuously through annual and three-year continuing professional education requirements and an annual maintenance fee |
| Who needs it | Internal and external auditors, risk and compliance professionals, security managers, privacy specialists and IT governance leaders |
| Common architecture | Exam plus verified experience plus ethics agreement plus continuing education |
| Choose by | Role and responsibility β audit, security management, risk, governance or privacy |
Sources: ISACA, official site Β· ISACA credentialing. Reviewed August 2026 by the GlobalCybers team.
One Association, Several Credentials
'ISACA certified' is not a statement
Job adverts and rΓ©sumΓ©s both use the phrase, and it means nothing on its own β ISACA issues credentials for audit, security management, risk and control, enterprise IT governance and data privacy, aimed at genuinely different jobs. Name the credential. A hiring manager reading 'ISACA certified' will assume the audit credential, because it is the association's oldest and largest, and the conversation gets awkward if that is not what you hold.
Mapping credentials to roles
Which ISACA credential affects a career most?
It depends entirely on the function you work in: the audit credential dominates internal audit hiring, while the risk, security management and governance credentials appear in their own specialist job specifications. Choosing the wrong one is the common mistake. BLS reports pay by occupation, not by credential.
GlobalCybers reimburses certification fees after a successful permanent placement through our network.
What ISACA Certifications Cover, Across the Portfolio
Choose by Role
Audit, security management, risk, governance and privacy are different jobs. The credential should follow the role you hold or are targeting.
Job Practice Domains
Each credential publishes its domains and weightings, derived from practice analysis. They are the authoritative syllabus and the fairest way to compare credentials.
Verified Experience
The flagship credentials all require documented professional experience, verified as part of the application. Passing the exam alone never produces certification.
Ethics Obligation
Every ISACA certification carries an agreement to the Code of Professional Ethics, enforceable through the association's processes.
CPE Discipline
Annual and three-year continuing education minimums apply, so holding several credentials multiplies the maintenance obligation as well as the fees.
Entry Certificates
ISACA also offers shorter certificates and foundational credentials, which suit people entering audit, risk or privacy work before they have the experience for a flagship certification.
How do you choose and earn an ISACA certification, step by step?
Start from the job specification, not the credential list
Read the roles you want. Internal audit postings name the audit credential; risk functions name the risk credential; security leadership roles name the security management credential. Let the market tell you which to pursue.
Check the experience requirement for that credential
Each flagship certification has its own documented experience requirement and its own waiver rules, published by ISACA. Verify the current terms before committing, because they have been revised over time.
Prepare against the published domains
ISACA publishes job practice domains and weightings per credential, derived from practice analysis. They are the syllabus, and the weightings tell you where preparation time belongs.
Sit the proctored exam
Examinations are delivered at test centres and by remote proctoring. Registration and application fees differ per credential and between members and non-members, so check ISACA's current fee schedule.
Apply, agree to the ethics code, then maintain it
Submit the experience-verified application, agree to the Code of Professional Ethics, and thereafter meet the annual and three-year continuing education minimums plus the maintenance fee.
Why ISACA Credentials Appear in Job Specifications
None of these credentials is legally required. Their currency comes from the environment audit, risk and security functions operate in: regulators and examiners expect organisations to demonstrate that qualified people assess systems controls, audit committees ask who is doing the work, and procurement processes for external assurance providers ask for credentialed staff. Because ISACA's certifications combine an examination with verified experience and an enforceable ethics obligation, they satisfy that expectation in a way that a training certificate does not.
ISACA Certifications, Frequently Asked Questions
ISACA credentialed? Name the credential.
Audit, risk and compliance functions hire against specific certifications. Tell us which one you hold.
Join the Network βMore about ISACA
Your career research journey
Do your homework, then let the network do the rest.Get the job, then keep rising
FreeSet your intent, matching jobs come to you. No applying.
A roadmap to your next licence tier and higher pay band.
Once placed, we cover all certification, licence & career-guide fees.
Hiring trade workers?
Get a verified shortlist of 3β5 qualified candidates in 48 hours
GlobalCybers verifies active state licenses, trade certifications, Intent and right-to-work status before any candidate reaches your portal. Flat $2,999/mo RPO (Recruitment Process Outsourcing), up to 3 concurrent roles, or a free trial (pay on hire). 90-day written guarantee.