ISACA · IT audit

CISA exam preparation

Practice for the Certified Information Systems Auditor (CISA) exam with adaptive questions, full-length mock exams, and a readiness score that tells you when you're actually ready to pass.

Before you register: You can sit the CISA exam before you have the experience — but passing it does not make you certified.

Certification requires five years of professional information systems auditing, control, assurance or security work experience. Up to three of those years can be waived by education or by certain other credentials, but waivers cannot take you below the remaining direct experience floor — no combination of degrees removes the requirement entirely. You have five years from the date you pass to submit the application evidencing that experience. Since July 2025 ISACA has also offered a CISA Associate designation for candidates who have passed the exam but do not yet meet the experience requirement, valid until you qualify for full certification. Confirm the current rules with ISACA before you plan around them.

CISA exam at a glance

Issuer
ISACA
Questions
150 multiple-choice questions
Duration
4 hours (240 minutes)
Scoring
Scaled score 200–800
Pass mark
450 to pass
Format
Computer-based, multiple choice

CISA exam domains

The CISA exam covers 5 domains, with the approximate weighting shown below:

What each CISA domain covers

Information Systems Auditing Process. How an audit is actually run: risk-based planning, evidence and sampling, materiality, documenting findings, and reporting. The exam cares whether you can tell sufficient evidence from convenient evidence.

Governance and Management of IT. The structures above the controls — IT strategy aligned to the business, policies and standards, organisational structure, and how management demonstrates that IT is being directed rather than merely operated.

Information Systems Acquisition, Development and Implementation. Project governance, build-versus-buy, testing, and the controls that must exist before a system goes live. The smallest domain on the outline, and the one candidates most often skim.

Information Systems Operations and Business Resilience. Running systems day to day and surviving when they fail: change and incident management, backup, business continuity and disaster recovery. One of the two heaviest domains.

Protection of Information Assets. Access control, network and endpoint security, encryption, physical security, and data classification. The other heaviest domain, and the one that overlaps most with security rather than audit work.

CISA exam facts

How CertPrepX helps you pass the CISA

Who the CISA is for

IT auditors, audit managers, security and compliance professionals, and consultants who assess an organization’s information systems and controls.

Start preparing for the CISA — free

Create a free account and start practicing today. Go Premium ($99/year) for full mock exams, analytics, and a Pass Guarantee.

Start free practice

CISA exam FAQ

How many questions are on the CISA exam?

The CISA exam has 150 multiple-choice questions and a 4-hour time limit.

What is the passing score for CISA?

CISA is scored on a scale of 200 to 800, and you need a scaled score of 450 or higher to pass. That scale is a statistical conversion of how many questions you answered correctly — it is not a percentage, so there is no fixed proportion of the paper that guarantees a pass.

Do I need five years of experience before I can sit the exam?

No. Anyone can sit the exam. The five years of IS audit, control, assurance or security experience is required to become certified, and up to three years can be waived by education or other credentials. You have five years after passing to evidence it, or you can hold the CISA Associate designation in the meantime.

Which CISA domain is weighted the most?

Domains 4 (IS Operations and Business Resilience) and 5 (Protection of Information Assets) are the heaviest, at 26% each — together over half the exam.

Does CertPrepX cover all five CISA domains?

Yes. CertPrepX maps practice questions and mock exams to all five CISA domains so you can see your readiness in each one.

Sources

Exam details on this page come from ISACA’s own published materials and were last verified on 24 August 2026. ISACA can change exam policy at any time, so confirm current requirements with ISACA before you register.

Related reading

Other certifications