Certified Information Systems Auditor (CISA) (CISA) Exam Blueprint

CISA

150Questions
240 minDuration
450 (200–800 scaled score; 450 required to pass)Passing Score
$760Price
3 yearsValid For
8Languages
Practice Certified Information Systems Auditor (CISA) on QuizForge

Credential type: certification examination · verified on the issuer's site September 19, 2026 issuer page

What This Exam Validates

The Certified Information Systems Auditor examination is administered by ISACA and evaluates your professional knowledge and practical competencies across five specific domains. Candidates answer a total of 150 multiple-choice questions during a linear test spanning a 240-minute duration, requiring a passing score of 450 to successfully earn the professional credential.

Who Should Take This Exam

Information systems professionals, auditors, and security practitioners with experience in auditing, control, and security should take this exam to validate their technical knowledge and professional competency.

Skills You Should Be Ready to Demonstrate

How to Prepare

Review all five examination domains and focus on official ISACA guidance materials to ensure complete coverage of the syllabus. Practice multiple-choice questions repeatedly under timed conditions to prepare adequately for the 240-minute duration. Verify all registration details, policies, and exam pricing directly through official ISACA communication channels before scheduling your test date.

Domain Study Guidance

Information Systems Auditing Process: Study Guidance

This specific domain covers the fundamental information systems auditing process, accounting for twenty-one percent of the overall exam weight and emphasizing practical evaluation practices for candidates preparing for the certification.

Governance and Management of IT: Study Guidance

This domain focuses extensively on the governance and management of IT, successfully representing seventeen percent of the overall test content and addressing core organizational structures alongside strategic management frameworks.

Information Systems Acquisition, Development, and Implementation: Study Guidance

This domain addresses information systems acquisition, development, and implementation topics, making up twelve percent of the exam and highlighting lifecycle management and system deployment strategies within enterprise environments.

Information Systems Operations and Business Resilience: Study Guidance

This domain explores information systems operations and business resilience in depth, carrying a significant weight of twenty-three percent and emphasizing continuity planning and operational recovery methods for essential systems.

Protection of Information Assets: Study Guidance

This domain concentrates completely upon the protection of information assets, covering twenty-seven percent of the total exam weight and focusing upon asset security controls and data protection methods across modern technological infrastructures.

Exam-Day Guidance

Arrive early for your linear format examination. Manage your 240-minute time allowance carefully across all 150 questions to ensure you complete every required section successfully.

Frequently asked questions

How many questions are on the exam?

The examination consists of a total of 150 multiple-choice questions that are delivered in a structured linear format for all registered candidates participating in the event.

What is the passing score?

The evaluation uses a scaled score ranging from 200 to 800 points. You must achieve a minimum passing score of 450 to successfully pass the examination.

How long is the exam?

The complete exam duration is exactly 240 minutes, providing you with ample time to carefully read and answer all questions within the designated professional testing environment without rushing.

How much does the exam cost?

The standard non-member price for the exam is $760, while qualifying ISACA members receive a discounted registration rate and pay $575 for taking the test.

Sources and Verification

Verified 2026-08-30

How this page was made

This informational page was thoroughly developed using verified official ISACA documentation and verified certification facts without external extrapolation or unverified assumptions.

Exam Domains

1 Information Systems Auditing Process 21%
2 Governance and Management of IT 17%
3 Information Systems Acquisition, Development, and Implementation 12%
4 Information Systems Operations and Business Resilience 23%
5 Protection of Information Assets 27%

Exam Details

Question TypesMultiple Choice
FormatLinear
Online ProctoringAvailable
ID RequirementsOne valid, unexpired government-issued photo ID with full name and signature. Name must match ISACA registration exactly.
RenewalRequired -- Complete 120 CPE hours over 3 years (minimum 20 hours annually). Pay annual maintenance fee. Adhere to ISACA Code of Professional Ethics. CPE hours earned through education, conferences, professional activities.
Prerequisites5 years of work experience in information systems auditing, control, or security
Retake PolicyMust wait 30 days before retaking. Maximum 3 exam attempts per 12-month period. Full exam fee required for each retake.
LanguagesEnglish, Chinese, Japanese, Korean, Spanish, German, French, Portuguese

Official Study Resources