Certified in Risk and Information Systems Control (CRISC) (CRISC) Exam Blueprint

CRISC

150Questions
240 minDuration
450 (200–800 scaled score; 450 required to pass)Passing Score
$760Price
3 yearsValid For
8Languages
Practice Certified in Risk and Information Systems Control (CRISC) on QuizForge

Credential type: certification examination · verified on the issuer's site September 20, 2026 issuer page

What This Exam Validates

The Certified in Risk and Information Systems Control credential is an esteemed designation administered by ISACA. It evaluates professional competence across four distinct domains, covering governance, information technology risk assessment, risk response, reporting, and information technology security to support organizational operations and essential assets throughout their enterprise lifecycle and operations.

Who Should Take This Exam

This credential suits risk management professionals, information security managers, system analysts, and internal auditors seeking to validate their ability to identify, assess, and manage enterprise-wide information technology risks.

Skills You Should Be Ready to Demonstrate

How to Prepare

Review ISACA study materials, official guides, and practice questions carefully to prepare for the assessment. Focus your study time on the four distinct domains, paying close attention to complex risk management frameworks and IT governance principles to ensure you master every single topic tested on the exam.

Domain Study Guidance

Governance: Study Guidance

Covers baseline organizational governance principles, management activities, enterprise architecture, and the funding of information security programs to align sound risk management strategies directly with overarching business objectives and corporate goals.

IT Risk Assessment: Study Guidance

Focuses heavily on identifying, estimating, and prioritizing risk to organizational operations, essential assets, individual stakeholders, and the wider community resulting directly from the use, deployment, and operation of modern information systems.

Risk Response and Reporting: Study Guidance

Deals with informing key decision makers and supporting effective risk responses by selecting appropriate mitigation strategies, designing action plans, and communicating vital risk assessment information across all levels of the organization.

Information Technology and Security: Study Guidance

Examines important information technology and security controls, security categorization processes, control implementation methodologies, and operational safeguards designed specifically to protect enterprise systems, networks, and sensitive data from threats.

Exam-Day Guidance

Manage your 240 minutes carefully across 150 questions. Read each multiple-choice question carefully before selecting the best answer based on ISACA frameworks and standard risk management practices.

Frequently asked questions

How many questions are on the exam?

The certification exam consists of a total of 150 multiple-choice questions delivered in a linear format, requiring candidates to demonstrate their knowledge across all established domains within the designated time frame.

What is the passing score?

The exam uses a scaled score ranging from 200 to 800. You need to achieve a minimum scaled score of 450 or higher in order to successfully pass the certification exam.

How long is the exam?

You are given a total duration of 240 minutes to complete all questions on the test, so candidates must pace themselves appropriately to answer every single item before time expires.

What does the exam cost?

The non-member registration price is $760, while the discounted ISACA member price is $575. You should always check directly with ISACA for the current certification path details.

Sources and Verification

Verified 2026-08-30

How this page was made

This detailed informational page was systematically built using official ISACA documentation, exam content outlines, and available standard references regarding risk assessment frameworks.

Exam Domains

1 Governance 26%
2 IT Risk Assessment 20%
3 Risk Response and Reporting 32%
4 Information Technology and Security 22%

Exam Details

Question TypesMultiple Choice
FormatLinear
Online ProctoringAvailable
ID RequirementsOne valid, unexpired government-issued photo ID with full name and signature. Name must match ISACA registration exactly.
RenewalRequired -- Complete 120 CPE hours over 3 years (minimum 20 hours annually). Pay annual maintenance fee. Adhere to ISACA Code of Professional Ethics. CPE hours earned through education, conferences, professional activities.
Prerequisites3 years of work experience in IT risk management and IS control
Retake PolicyMust wait 30 days before retaking. Maximum 3 exam attempts per 12-month period. Full exam fee required for each retake.
LanguagesEnglish, Chinese, Japanese, Korean, Spanish, German, French, Portuguese

Official Study Resources