CISA exam preparation
Practice for the Certified Information Systems Auditor (CISA) exam with adaptive questions, full-length mock exams, and a readiness score that tells you when you're actually ready to pass.
Before you register: You can sit the CISA exam before you have the experience — but passing it does not make you certified.
Certification requires five years of professional information systems auditing, control, assurance or security work experience. Up to three of those years can be waived by education or by certain other credentials, but waivers cannot take you below the remaining direct experience floor — no combination of degrees removes the requirement entirely. You have five years from the date you pass to submit the application evidencing that experience. Since July 2025 ISACA has also offered a CISA Associate designation for candidates who have passed the exam but do not yet meet the experience requirement, valid until you qualify for full certification. Confirm the current rules with ISACA before you plan around them.
CISA exam at a glance
CISA exam domains
The CISA exam covers 5 domains, with the approximate weighting shown below:
- Information Systems Auditing Process18%
- Governance and Management of IT18%
- Information Systems Acquisition, Development and Implementation12%
- Information Systems Operations and Business Resilience26%
- Protection of Information Assets26%
What each CISA domain covers
Information Systems Auditing Process. How an audit is actually run: risk-based planning, evidence and sampling, materiality, documenting findings, and reporting. The exam cares whether you can tell sufficient evidence from convenient evidence.
Governance and Management of IT. The structures above the controls — IT strategy aligned to the business, policies and standards, organisational structure, and how management demonstrates that IT is being directed rather than merely operated.
Information Systems Acquisition, Development and Implementation. Project governance, build-versus-buy, testing, and the controls that must exist before a system goes live. The smallest domain on the outline, and the one candidates most often skim.
Information Systems Operations and Business Resilience. Running systems day to day and surviving when they fail: change and incident management, backup, business continuity and disaster recovery. One of the two heaviest domains.
Protection of Information Assets. Access control, network and endpoint security, encryption, physical security, and data classification. The other heaviest domain, and the one that overlaps most with security rather than audit work.
CISA exam facts
- Questions: 150 multiple-choice questions.
- Duration: 4 hours (240 minutes).
- Answer options: Four per question: one correct response and three distractors.
- Scoring: A scaled score from 200 to 800 — a statistical conversion of how many questions you answered correctly, not a percentage.
- Passing score: 450.
- Qualifier style: Stems commonly turn on BEST, MOST, FIRST, LEAST or EXCEPT. More than one option is usually defensible; the qualifier decides which the exam wants.
- Content outline: The current CISA job practice took effect on 1 August 2024 and is still the live outline.
- Application window: Five years from passing to evidence the experience and apply.
How CertPrepX helps you pass the CISA
- Adaptive practice that focuses on your weakest CISA domains.
- Full-length, timed mock exams that mirror the real CISA format and scoring.
- A readiness score per domain, so you know when you're ready to sit the exam.
- Weak-area review and spaced repetition to lock in what you miss.
- A personalized study plan built around your target CISA exam date.
Who the CISA is for
IT auditors, audit managers, security and compliance professionals, and consultants who assess an organization’s information systems and controls.
Start preparing for the CISA — free
Create a free account and start practicing today. Go Premium ($99/year) for full mock exams, analytics, and a Pass Guarantee.
Start free practiceCISA exam FAQ
How many questions are on the CISA exam?
The CISA exam has 150 multiple-choice questions and a 4-hour time limit.
What is the passing score for CISA?
CISA is scored on a scale of 200 to 800, and you need a scaled score of 450 or higher to pass. That scale is a statistical conversion of how many questions you answered correctly — it is not a percentage, so there is no fixed proportion of the paper that guarantees a pass.
Do I need five years of experience before I can sit the exam?
No. Anyone can sit the exam. The five years of IS audit, control, assurance or security experience is required to become certified, and up to three years can be waived by education or other credentials. You have five years after passing to evidence it, or you can hold the CISA Associate designation in the meantime.
Which CISA domain is weighted the most?
Domains 4 (IS Operations and Business Resilience) and 5 (Protection of Information Assets) are the heaviest, at 26% each — together over half the exam.
Does CertPrepX cover all five CISA domains?
Yes. CertPrepX maps practice questions and mock exams to all five CISA domains so you can see your readiness in each one.
Sources
Exam details on this page come from ISACA’s own published materials and were last verified on 24 August 2026. ISACA can change exam policy at any time, so confirm current requirements with ISACA before you register.