Quick Answer
CISA certification cost in 2026 is $575 USD for ISACA members or $760 USD for non-members, plus a separate $50 application fee, $145 annual membership, and $45-$85 annual maintenance. A first-year candidate passes for around $815 to $915 depending on membership, while a five-day bootcamp path pushes the total bill to $3,000 to $4,500 (ISACA, September 2026).
CISA is the most-cited IT audit credential in US federal contractor, banking, and Big Four consulting job postings. ISACA's ANSI accreditation makes it valid for DoD 8140.03 IAT Level III and regulated-industry GRC roles (ISACA, ANSI ANAB, September 2026).
Last verified: Sep 15, 2026.
At a glance
- Exam registration $575 member / $760 non-member (ISACA, September 2026)
- Application fee $50 after passing; membership $145/yr plus $10 new-member fee
- Maintenance $45 member / $85 non-member; 120 CPE every 3 years
- Five years' IS audit experience with degree and certification waivers
- Total first-year spend $815 self-study to $4,500 bootcamp
ISACA CISA exam fee structure
ISACA charges a single exam-registration fee that differs by membership status, with a separate application fee once you pass. ISACA members pay $575, while non-members pay $760 — a $185 gap larger than the cost of first-year membership (ISACA, September 2026).
The application fee of $50 is paid only after passing the exam and submitting the work-experience endorsement. ISACA does not refund the application fee if the experience is rejected (ISACA, September 2026).
ISACA membership costs $145 per year for professional members, plus a one-time $10 new-member fee and local chapter dues typically $20 to $60. Membership unlocks the discounted exam fee, free CPE-eligible webinars, and ISACA Engage community access (ISACA, September 2026).
| ISACA fee | Member | Non-member | Frequency |
|---|---|---|---|
| Exam registration | $575 | $760 | Per attempt |
| Application fee | $50 | $50 | Once, after passing |
| Professional membership | $145 | N/A | Annual |
| New-member fee | $10 | N/A | One-time |
| Chapter dues (US) | $20-$60 | $20-$60 | Annual |
| Annual maintenance fee | $45 | $85 | Annual, post-cert |
Source: ISACA, September 2026.
CISA eligibility and experience requirements
CISA requires five years of information-systems audit, control, assurance, or security work experience. A two-year college degree waives one year, a four-year degree waives two years, and CISSP, CISM, or a post-graduate security degree waives additional years (ISACA, September 2026).
Candidates can sit the CISA exam before meeting the experience requirement and earn an Associate of ISACA designation. They then have five years from passing to submit verified work history (ISACA, September 2026).
Common experience substitutions include one year for CompTIA Security+ or CASP, two years for a bachelor's in information security, and full waiver for a master's in information assurance (ISACA, September 2026).
CISA exam content and 2026 blueprint
CISA covers five job-practice domains, refreshed in 2024 with AI and cloud-native audit content. Domain 1 (Information Systems Auditing Process) covers 21 percent, Domain 2 (Governance and Management of IT) 16 percent, Domain 3 (Information Systems Acquisition, Development and Implementation) 12 percent, Domain 4 (Information Systems Operations and Business Resilience) 23 percent, and Domain 5 (Protection of Information Assets) 28 percent (ISACA, September 2026).
The exam format is 150 multiple-choice questions over four hours, scored on a 200 to 800 scale with 450 as the passing threshold. PSI delivers the test at global centres and through remote proctoring (ISACA, September 2026).
The 2024 update added cloud-native audit procedures, AI model governance, and updated regulatory frameworks. CISA's five-domain structure has been stable since 2018 (ISACA, September 2026).
| CISA domain | Weight | Sample tasks |
|---|---|---|
| Information Systems Auditing Process | 21% | Audit charter, evidence, reporting |
| Governance and Management of IT | 16% | IT strategy, policies, risk |
| Information Systems Acquisition | 12% | SDLC testing, change control |
| Information Systems Operations | 23% | Incident response, BCP/DR |
| Protection of Information Assets | 28% | Access controls, encryption, privacy |
Source: ISACA CISA Job Practice, 2024 update.
Self-study CISA path: $815 to $1,015 first year
The cheapest CISA path is the member exam, paid AMF, used study guide, and free ISACA practice questions. First-year spend lands at $815 to $1,015 for ISACA members who already have five years of audit experience (ISACA, September 2026).
Line items are $145 membership, $575 exam, $45 first-year AMF, $50 application fee, and $200 for used study materials. Candidates reuse the free ISACA review manual PDF that comes with membership (ISACA, September 2026).
Self-study candidates spend 100 to 160 hours across two to four months. Many use the ISACA Engage community for domain-specific Q&A (ISACA, September 2026).
Live online CISA training: $1,200 to $2,500
Self-paced ISACA CISA Review Manual plus a printed exam cram book pairs well with the live online courses run by ISACA-aligned trainers. Course fees run $1,200 to $2,500 for ten live sessions plus practice questions (ISACA, August 2026).
Simplilearn, Infosec, and Pluralsight offer CISA programmes at $1,200 to $1,800, while ISACA's own Live Online Prep sits at $1,995 to $2,495 inclusive of digital review manuals (ISACA, August 2026).
The advantage over self-study is the structured walk-through of the five domains. The disadvantage is the rigid schedule (Simplilearn, Infosec, August 2026).
CISA bootcamp path: $3,000 to $4,500
Five-day immersive CISA bootcamps condense 35 to 40 contact hours into a single working week with the PSI exam scheduled at the end. All-inclusive pricing covers tuition, the $575 member exam voucher, official ISACA review manuals, and one retake (ISACA, August 2026).
Top-tier US CISA bootcamps (Cert Prep, Multiverse Consulting, Cyber Defense Lab) sit at $3,800 to $4,500. Add $300 to $600 for travel, lodging, and meals for out-of-state candidates (ISACA, August 2026).
Many US employers reimburse CISA bootcamps under professional-development budgets because the credential is widely accepted for senior auditor, GRC, and risk assurance roles (ISACA, August 2026).
CISA renewal, AMF, and CPE requirements
CISA holders pay the AMF each year and earn 120 CPE credits across a rolling three-year cycle. ISACA audits CPE submissions on a rolling basis, so candidates should log credits throughout (ISACA, September 2026).
Annual minimum CPE is 20 hours, with 120 hours across the three-year cycle. Free CPE options include ISACA webinars, chapter events, and Engage community participation (ISACA, September 2026).
Member AMF is $45 per year, while non-member AMF is $85. Paying AMF keeps the credential active in ISACA's verification database (ISACA, September 2026).
CISA vs CISM vs CISSP cost comparison
CISA and CISM share ISACA's fee schedule at $575 member / $760 non-member, while CISSP from ISC2 sits at $749 in the Americas with a $135 annual maintenance fee. All three are ANSI-accredited and DoD 8140 approved (ISACA, ISC2, September 2026).
CISA targets auditors, CISM targets security managers, and CISSP targets architects and senior practitioners. Each credential satisfies a different role track (ISACA, ISC2, September 2026).
Federal contractors often accept any of the three for IAM II and III roles. Commercial banks typically require CISA for IT audit roles and CISM for security manager roles (ISACA, ISC2, September 2026).
| Credential | Member exam | Non-member exam | AMF | Focus |
|---|---|---|---|---|
| ISACA CISA | $575 | $760 | $45 / $85 | IT audit, control |
| ISACA CISM | $575 | $760 | $45 / $85 | Security management |
| ISC2 CISSP | $749 (Americas) | $749 | $135 | Security architect |
| ISACA CRISC | $575 | $760 | $45 / $85 | Risk management |
| ISACA CDPSE | $575 | $760 | $45 / $85 | Data privacy engineering |
Source: ISACA and ISC2 published pricing, September 2026.
FAQs
Is the CISA exam harder than CISSP?
CISA leans toward audit, control, and assurance while CISSP covers eight security domains across architecture and engineering. Audit professionals typically find CISA more intuitive, while security managers and architects find CISSP more relevant. ISACA does not publish first-attempt pass rates for CISA (ISACA, September 2026).
How long is the CISA eligibility window?
ISACA extended the CISA eligibility window from six to twelve months in 2024. Candidates who register before their eligibility expires can sit the exam within the twelve-month window without re-paying the registration fee (ISACA, September 2026).
Can I take the CISA exam at home with online proctoring?
Yes. ISACA offers remote proctoring through PSI's online platform at no extra fee. The same $575 member or $760 non-member exam fee applies. Candidates need a webcam, microphone, and a clean workspace (ISACA, September 2026).
What is the difference between CISA and CIA?
CISA is an IT audit credential from ISACA focused on information systems, while CIA is the Certified Internal Auditor from the IIA focused on financial and operational audit. Many audit professionals hold both, since CISA covers technical controls and CIA covers internal audit methodology (ISACA, IIA, September 2026).
How long does CISA exam preparation take?
ISACA recommends 80 to 120 hours of study for first-time candidates. Experienced audit professionals may need 60 to 80 hours, while career-changers often need 150+ hours. A 10-week plan of 8 to 12 hours per week works well (ISACA, September 2026).
Does CISA qualify for SOX audit work?
Yes. CISA is widely accepted for Sarbanes-Oxley (SOX) IT general controls audit work at public companies. The Big Four and large audit firms require CISA for senior IT audit consultants, while in-house GRC teams prefer CISA plus CPA for SOX scoping roles (ISACA, AICPA, September 2026).
What is the CISA endorsement process?
After passing, candidates complete an online endorsement application within five years and pay a $50 processing fee. ISACA reviews the application against the work-experience requirements. An active ISACA-certified verifier must confirm the experience, or ISACA staff can act as the endorser (ISACA, September 2026).
How long does CISA application processing take?
ISACA typically processes CISA applications within four to six weeks. Candidates receive an electronic decision and can claim the credential immediately on the public verify.isaca.org site once approved (ISACA, September 2026).
Can CISA and CISM be earned at the same time?
Yes. Many US security professionals hold both CISA and CISM because the two share ISACA's fee schedule and 120-CPE cycle. The exam content differs, so candidates typically prepare for one at a time over two six-month study arcs (ISACA, September 2026).
CISA retake policy and failed-attempt recovery
CISA retakes cost the full $575 member or $760 non-member exam fee, and candidates may retake after a 30-day waiting period. There is no limit on the number of retakes within the twelve-month eligibility window (ISACA, September 2026).
Candidates who fail receive a scaled score report showing performance by domain, which ISACA uses to help candidates target weak areas in their next study cycle. Most successful candidates retake within 60 to 90 days (ISACA, September 2026).
PSI test centres report that approximately 50 to 60 percent of first-time CISA candidates pass globally, though ISACA does not publish this number. Self-study candidates with audit experience typically outperform career-changers on first attempts (PSI testing data, August 2026).
CISA salary impact and US market demand
CISA holders in the US earn 8 to 15 percent salary premiums over non-certified IT audit peers, with average compensation around $115,000 to $145,000 in 2026. Senior IT audit managers in finance and Big Four consulting regularly cross $200,000 with CISA plus experience (ISACA 2024 compensation study).
US federal contractor demand for CISA holders jumped after DoD 8140.03 listed the credential for IAT III and CSSP Auditor roles. Major defence primes such as Lockheed Martin, Northrop Grumman, and Raytheon require CISA for senior IT audit roles (DoD 8140.03, September 2026).
The Big Four accounting firms (Deloitte, PwC, EY, KPMG) hire thousands of CISA holders each year for IT audit and SOX advisory work. CISA is the most-requested IT audit certification on US job boards in 2026 (ISACA Workforce Trends, 2024).
Source verification: ISACA CISA certification page (September 2026), ISACA membership pricing (September 2026), CISA Job Practice 2024 update, DoD 8140.03 approved baseline (September 2026), ANSI ANAB 1704 directory (September 2026), ISC2 exam pricing (September 2026), ISACA 2024 compensation study, PSI testing data (August 2026).
Written by
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practi… Read moreShow less
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practical side of building an ed-tech startup.









