Study offer Save 5% off your preparation plan Use codeEXAM4FUTURE5
View offer

Isaca certification exams.

Compare current exam codes, certification paths, and preparation options in one focused Isaca catalog.

3 current examsPublished preparation files available now.
4 certification pathsOrganized routes through the Isaca catalog.
August 2026Latest catalog update represented in this provider view.

Choose your Isaca preparation path.

Move between current exams, certification groups, and provider guidance without losing the context of this catalog.

ISACA Certification Guide: Choosing a Credential in Audit, Security, Risk and Governance

ISACA’s credential ecosystem serves professionals working across information-systems audit, cybersecurity, information security management, risk, privacy and enterprise governance. It includes professional certifications, advanced AI-focused certifications, role-oriented CMMC credentials and shorter certificates for foundational knowledge. This overview explains how those options differ, who each path suits, what the official preparation process involves and which questions to answer before registering. Use it to connect your current responsibilities and experience with a sensible ISACA next step rather than choosing a credential by title alone.

How ISACA organizes its credential ecosystem

The first decision is whether you need a certification, an advanced certification, a CMMC credential or a certificate. ISACA separates these categories because they communicate different kinds of achievement and are intended for different stages or areas of professional development.

ISACA describes its credentialing portfolio as covering IS/IT audit, security, risk and governance. Its main certification catalogue includes CISA, CISM, CRISC, CGEIT and CDPSE, alongside newer credentials focused on artificial intelligence and cybersecurity operations. The catalogue also includes CMMC credentials for professionals working in the Cybersecurity Maturity Model Certification environment.

The distinction between a certification and a certificate matters. ISACA presents certificates as evidence that a learner understands key concepts and principles in a specific information-systems or cybersecurity field. A certificate can therefore be a useful way to build or demonstrate focused knowledge, while a professional certification is the more relevant category to investigate when a role calls for a broader, experience-based credential.

The catalogue is not static. ISACA’s credentialing pages identify beta, current and retired offerings, and the candidate-guide hub is the practical place to confirm whether the credential you are considering is available, what its current guide says and which policies apply. Exam content, preparation materials and administrative details can change, so readers should treat the official page for the selected credential as the final authority.

Professional certifications

The professional certification group is designed around recurring responsibilities rather than a single technology platform. CISA centers on information-systems auditing; CISM on information security management; CRISC on risk and information-systems control; CGEIT on governance of enterprise IT; and CDPSE on data privacy solutions engineering. These are distinct work orientations, even though real jobs can overlap them.

ISACA’s certification catalogue also lists AAIA, AAISM and AAIR as advanced AI credentials, as well as CCOA, the Certified Cybersecurity Operations Analyst. The best choice among them depends on whether AI audit, AI security management, AI risk or operational cybersecurity is already part of your professional direction.

Certificates and focused learning

ISACA’s certificate catalogue includes options such as AI Fundamentals, Blockchain Fundamentals, Cloud Fundamentals, COBIT 2019 Foundation, Cybersecurity Fundamentals, Data Science Fundamentals, Digital Trust Ecosystem Framework Foundation Certificate, IoT Fundamentals, IT Audit Fundamentals and IT Risk Fundamentals. It also lists COBIT design and implementation and cybersecurity audit-related learning options.

These offerings can suit a reader who wants a defined subject area without immediately pursuing a professional certification. They may also help someone test an interest before committing to an experience-oriented path. Confirm the current status, assessment format and maintenance terms for the specific certificate, because the catalogue contains several different kinds of focused credential.

CMMC credentials

ISACA’s certification catalogue includes the CMMC Certified Assessor, CMMC Credentialed Instructor, CMMC Certified Professional and Lead CMMC Certified Assessor designations. The role is central to choosing among them. For example, ISACA describes CMMC Certified Assessors as preparing experienced cybersecurity and compliance professionals to conduct formal CMMC Level 2 assessments, while Lead CMMC Certified Assessors lead assessment teams, oversee evaluation activities and make final compliance determinations for organizations undergoing CMMC Level 2 assessments.

A CMMC credential is therefore a specialist route tied to a defined assessment, instruction or professional role. It should not be treated as a general substitute for CISA, CISM, CRISC or another ISACA certification. Review the applicable catalogue entry and program requirements before assuming that one credential creates eligibility for another role.

Which ISACA path fits your work

Choose the credential whose subject matter matches the decisions you make at work, not merely the technology you touch. ISACA’s paths overlap at the boundaries of governance, assurance, security and risk, but their primary questions are different.

A useful first step is to write down the outputs your role is expected to produce: audit findings, security program decisions, risk treatment recommendations, privacy engineering controls, enterprise governance decisions, security operations analysis or CMMC assessment conclusions. Then compare those outputs with the official credential descriptions and exam domains.

Choose CISA for audit and assurance responsibilities

CISA is ISACA’s Certified Information Systems Auditor certification. ISACA says it is for professionals who audit and assess organizational information technology. This makes it a natural path for people whose work involves evaluating controls, examining systems and processes, reporting findings or supporting assurance over information technology.

ISACA identifies five CISA domains: the information-systems auditing process; governance and management of information technology; information-systems acquisition, development and implementation; information-systems operations and business resilience; and protection of information assets. Those domains give prospective candidates a practical readiness check. If your experience is mainly in audit planning, evidence evaluation, control assessment and communicating assurance conclusions, CISA’s coverage is directly relevant.

CISA can also be relevant to technology professionals who contribute to audit work or control reviews, but a reader should distinguish familiarity with systems from experience performing audit or assessment responsibilities. Before applying, review ISACA’s experience requirements and the current candidate guide rather than relying on a job title alone.

Choose CISM for information security management

CISM is the better direction to investigate when your main responsibility is managing an information-security program rather than independently auditing it. The credential appears in ISACA’s professional certification portfolio, and its title points toward security leadership, program oversight and management decisions.

Candidates comparing CISM with CISA should ask whether they are primarily assessing the effectiveness of controls or directing the security function that designs, operates and improves those controls. A professional may eventually find value in both perspectives, but the first credential should reflect the work they can document and the role they want to develop toward.

Use the CISM candidate guide and certification page to confirm current domains, experience conditions, examination administration and maintenance obligations. Those details should be checked directly because ISACA updates program information over time.

Choose CRISC for IT risk and control

CRISC is the path to examine when information-technology risk identification, analysis, response and control are central to your responsibilities. It can make sense for professionals who translate business objectives and technology exposure into risk decisions, control expectations or monitoring activities.

CRISC may overlap with both CISA and CISM. The distinction is the dominant purpose of the work: CISA emphasizes assurance over systems and controls, CISM emphasizes security management, and CRISC emphasizes risk and information-systems control. Compare the official domains and experience requirements with the projects you have actually performed before choosing.

A risk-focused candidate should also consider whether a focused IT Risk Fundamentals certificate is enough for the immediate learning objective. A certificate may be a sensible preliminary step when the goal is concept development, whereas CRISC deserves closer review when the goal is a professional certification aligned with documented risk responsibilities.

Choose CGEIT for enterprise IT governance

CGEIT is the credential to investigate when your work connects technology decisions with enterprise governance. Its name, Certified in the Governance of Enterprise IT, distinguishes it from credentials centered more narrowly on audit execution, security operations or privacy engineering.

This path can suit professionals involved in governance structures, strategic alignment, value delivery, resource decisions, risk oversight and performance monitoring. It may be relevant to technology executives, governance practitioners and advisers whose work requires connecting IT activity with organizational objectives.

If governance is a new subject rather than an established work responsibility, a COBIT-related certificate may provide a narrower introduction. ISACA’s certificate catalogue includes COBIT 2019 Foundation and COBIT 2019 Design & Implementation options. Compare the learning purpose and any current prerequisites before treating either as a stepping stone to CGEIT.

Choose CDPSE for privacy technology and data solutions

CDPSE, the Certified Data Privacy Solutions Engineer, is the route to examine when privacy requirements must be translated into technology, systems, processes and controls. ISACA’s catalogue positions privacy as a distinct professional area rather than simply a subset of security.

This path is especially relevant to people working on privacy-by-design, data handling, privacy controls, technical implementation and the operational connection between privacy obligations and information systems. A legal or policy background can be valuable, but the credential’s engineering orientation means prospective candidates should examine the official domains and experience requirements carefully.

Readers who are still building privacy vocabulary may prefer a focused certificate or learning course first. Those who already design, implement or evaluate privacy solutions should compare CDPSE with their current responsibilities and the roles they are targeting.

Choose CCOA for cybersecurity operations

CCOA, the Certified Cybersecurity Operations Analyst, is aimed at a more operational cybersecurity profile. ISACA describes it as focusing on the technical skills needed to evaluate threats, identify vulnerabilities and recommend countermeasures to prevent cyber incidents.

This is a different starting point from governance, audit or executive security management. It may fit analysts and practitioners whose work involves monitoring, threat evaluation, vulnerability analysis and operational recommendations. A reader with primarily policy, audit or governance experience should not assume that general cybersecurity exposure establishes readiness for an operations-oriented credential.

Review the current CCOA candidate guide and preparation materials to determine the precise scope and eligibility position. The candidate-guide hub includes CCOA among the examinations for which ISACA provides program guidance.

Consider advanced AI credentials when AI is already part of the role

ISACA’s advanced AI credentials are specialized choices for professionals applying established audit, security or risk expertise to artificial-intelligence environments. AAIA is Advanced in AI Audit, AAISM is Advanced in AI Security Management and AAIR is Advanced in AI Risk.

The titles suggest three different professional applications: assessing AI systems and related audit concerns, managing security issues and opportunities involving AI, or evaluating and managing AI risk across the enterprise. ISACA describes AAISM as validating AI-specific security knowledge and experience of CISM and CISSP holders, while AAIR is described as expanding and applying existing IT risk-management expertise to assess and manage AI risk.

These credentials are not automatically the right first ISACA purchase for someone who is simply curious about AI. Start with the relevant audit, security or risk foundation if that reflects your experience, then verify the advanced credential’s current eligibility and examination requirements. A fundamentals certificate may be more proportionate when the immediate objective is general AI literacy.

How certificates can support a longer-term plan

Use a certificate to close a specific knowledge gap or test a direction; use a professional certification when your experience and career objective support a broader role credential. That distinction keeps the learning investment aligned with the outcome you want.

For example, someone moving toward technology assurance could begin with IT Audit Fundamentals, then evaluate CISA once audit responsibilities and the formal experience requirements are in place. Someone exploring enterprise governance could begin with COBIT 2019 Foundation before deciding whether CGEIT matches their professional scope. Someone seeking basic exposure to cloud, cybersecurity or AI can use the corresponding fundamentals option as a focused learning choice rather than presenting it as equivalent to a professional certification.

The catalogue also contains certificates in areas such as data science, blockchain, IoT and digital trust. These may be useful where the subject intersects with a current project, but the reader should ask what evidence the credential represents, whether it has maintenance requirements and how it will be understood by the employers or clients relevant to their own career.

Do not infer a formal progression ladder unless ISACA explicitly defines one. The ecosystem offers related subjects, but moving from a certificate to a certification may require separate experience, application or examination steps. Confirm those steps on the credential’s official page.

A practical certificate decision test

Choose a certificate first when your main need is structured orientation, terminology or a bounded subject review. Choose a professional certification first when you can already connect the subject to substantial responsibilities and can satisfy the published requirements.

Ask three questions: What work product will this learning improve? What formal evidence does the credential require? What will I do next if I complete it? If the answer to the third question is unclear, a focused certificate or training course may be more useful than beginning a longer certification process.

What official requirements mean for certification candidates

Treat the official candidate guide as the controlling checklist. ISACA says its exam candidate guides cover registration, scheduling, preparation, exam rules, administration, scoring and retake policy. The guide for the chosen credential should be reviewed before payment, not after a study plan has already been built.

CISA illustrates the difference between passing an exam and becoming certified. ISACA states that a CISA candidate must pass the certification exam, pay the US$50 application processing fee, submit an application demonstrating experience requirements, adhere to the Code of Professional Ethics, follow the Continuing Professional Education Policy and comply with the Information Systems Auditing Standards. Candidates have five years from passing the exam to apply for CISA certification.

That example is useful because it prevents a common misunderstanding: an examination result is not necessarily the entire certification process. Requirements vary by credential, so do not transfer CISA’s application or experience rules to CISM, CRISC, CGEIT, CDPSE, CCOA, an advanced AI credential or a CMMC credential without checking the relevant official materials.

ISACA’s CISA page states that exam eligibility is required to schedule and take the exam. It also says registration and payment are required before scheduling. Candidates should therefore verify eligibility, fees, policy terms and the available testing route in the current documentation before treating an intended date as confirmed.

CISA as a concrete example of readiness

For CISA specifically, ISACA identifies experience requirements as part of the certification application. A prospective candidate should map their own audit and assessment work to those requirements, retain suitable evidence and confirm how the current application process treats their background.

The CISA exam focuses on the five domains listed by ISACA. A sensible readiness review is not simply a count of practice questions completed. It is an honest comparison between the domain outline, your working knowledge, your ability to reason about controls and risk, and your experience explaining evidence-based conclusions.

How to prepare without treating preparation as memorization

Build preparation around the official exam outline, the candidate guide and the way the credential is used in practice. ISACA offers official exam preparation for CISA, AAIA, CISM, AAISM, CRISC, CDPSE, CGEIT and CCOA, with options that include self-paced study and guidance from live expert instruction.

ISACA says its training materials use industry professionals so that preparation aligns with current job practices. That makes the official domain structure a useful organizing framework: identify each subject, learn the underlying concepts, connect them to workplace decisions and then test whether you can apply them in unfamiliar scenarios.

The preparation choice should reflect your constraints. Self-directed study can work for a candidate who already has relevant experience, a stable schedule and a clear way to identify weak areas. An instructor-led option may be more useful when concepts are new, work experience is uneven or discussion will help resolve ambiguity. Neither format removes the need to read the current candidate guide and understand the credential’s requirements.

A four-part preparation approach

Start with scope. Download or review the current candidate guide for the selected examination and list its domains, policies and administrative steps. Do not build a plan from an old manual or an unofficial summary when ISACA has published a newer guide.

Next, assess experience. For each domain, record projects, responsibilities and decisions you have handled. Mark areas where you can explain the purpose, process, risks, controls and evidence rather than merely recognize terminology.

Then study actively. Use official manuals, review courses, practice questions and relevant ISACA resources to explain why an answer is appropriate. Practice should reveal reasoning gaps; it should not become an exercise in memorizing leaked or reconstructed questions. ISACA itself warns readers to beware of training organizations promising 100% pass rates.

Finally, rehearse administration. Confirm eligibility, registration, payment, scheduling, identification, delivery method, system compatibility and rescheduling rules from the current official instructions. A strong study plan can still be disrupted by an overlooked administrative condition.

Official preparation resources worth comparing

ISACA’s preparation catalogue includes review courses, manuals and practice resources, with availability varying by credential. The CISA page, for example, lists a CISA Review Manual, a CISA Online Review Course and a CISA Questions, Answers & Explanations Database. The page also provides a free CISA practice quiz and links to candidate guidance.

Use these resources according to purpose. A manual is useful for structured reference; a course can provide sequencing and explanation; practice questions can expose weak concepts and pacing issues. Check the edition and credential alignment before buying, especially when the certification page announces exam or content changes.

Preparation products are not the same as certification requirements. Buying a manual or course does not establish eligibility, and completing practice questions does not demonstrate the professional experience that a certification application may require.

Planning registration, delivery and maintenance

Confirm the administrative path before you choose a target date. ISACA’s candidate-guide hub provides scheduling resources for PSI test centers and online remote proctoring, while the CISA page describes computer-based delivery through authorized PSI testing centers globally or remotely proctored exams.

CISA candidates can schedule a testing appointment as early as 48 hours after payment of exam registration fees, but the same page says appointments are only available 90 days in advance. It also states that CISA candidates have a six-month eligibility period after registration. These are CISA-specific details and should not be assumed to apply identically to every ISACA examination.

The CISA page lists a US$575.00 member exam cost and a US$760.00 non-member exam cost. Fees and policies can change, and other credentials may have different charges, so use the current page for the examination you intend to take. Membership should be evaluated as a separate cost-and-benefit decision rather than assumed to be mandatory.

Membership can support the journey, but it is not the credential

ISACA membership provides access to community, learning and professional-development resources, but membership itself does not replace certification eligibility or examination requirements. ISACA lists Professional membership at US$145 per year, Recent Graduate membership at US$68 per year and Student membership at US$25 per year.

The membership pages describe benefits including free CPE opportunities, discounts, publications, networking, mentorship, webinars and chapter participation. ISACA says members can participate in more than 200 chapters worldwide and that membership benefits include opportunities to earn more than 72 free continuing professional education credits. The exact value depends on how actively a member uses those benefits and on the current terms.

Student membership has specific conditions. ISACA says it is limited to first-time ISACA members and may be held for a maximum of six years; the membership page also requires verification that the student is enrolled in a qualifying degree-seeking program. Recent Graduate membership requires proof of graduation from a recognized college or university within the preceding two years.

Compare the member and non-member examination costs, the resources you expect to use and the renewal or CPE support you value. Join because the overall package fits your plan, not because membership alone signals readiness for a certification.

Maintenance belongs in the initial decision

Plan for continuing obligations before you register. CISA’s certification requirements include adherence to ISACA’s Continuing Professional Education Policy, and the membership and credentialing pages highlight CPE as an ongoing part of professional participation.

The number, reporting period and other maintenance rules can differ by credential and may change. Read the current policy linked from the selected certification page. A credential that fits your target role but cannot realistically be maintained is a poor practical choice, even if the examination subject is attractive.

Consider how you will earn relevant learning through work activities, courses, chapter events, webinars, publications or other accepted sources. Keep records as you go and check whether each activity qualifies under the current policy rather than assuming all professional learning counts automatically.

How to compare two plausible ISACA credentials

When two credentials appear suitable, compare the work each one validates. Start with the dominant responsibility, then check experience, domains, maintenance and the role you want next.

Use this comparison sequence:

1. Identify the primary decision you make: assurance, security management, risk treatment, enterprise governance, privacy solution design, security operations, AI audit, AI security or AI risk.

2. Compare the official scope and domain outline for each credential. Look for the subjects that occupy the greatest share of your current work and the subjects you need for the intended role.

3. Check experience and application rules independently for both options. Do not assume that years in a related technology role satisfy an audit, management, risk, privacy or assessment requirement.

4. Compare preparation resources, examination availability, delivery options, costs and maintenance obligations as they appear on the current official pages.

5. Choose the credential that produces the clearest professional story: what you do now, what the credential validates and what responsibility you intend to take on next.

For instance, a control reviewer may compare CISA and CRISC. The deciding question is whether the work is primarily assurance over controls or the identification and management of technology risk. A security leader may compare CISM and CCOA by asking whether the role directs a security program or performs operational threat and vulnerability analysis. A technology governance practitioner may compare CGEIT with a COBIT certificate by asking whether they need a professional governance certification or focused framework knowledge.

There is no universal order in which to take ISACA credentials. A path can be narrow and role-specific, broad and governance-oriented, or built around a foundational certificate followed by a professional certification. The sensible choice is the one supported by your experience, goals and ability to meet the current rules.

Questions to ask before selecting a credential

What work do I perform repeatedly, and which credential describes that work most closely?

Am I seeking evidence of foundational understanding or a professional certification with experience and maintenance obligations?

Can I document the experience required by the current credential?

Which official candidate guide applies, and has the examination or domain outline recently changed?

Would a certificate let me test the subject before committing to a certification?

Which preparation format suits my schedule, budget and knowledge gaps?

Where will I take the exam, and have I checked delivery requirements and appointment availability?

What ongoing CPE or other maintenance duties will I need to meet?

Will membership provide resources or savings that I am likely to use?

If I earn this credential, what specific responsibility or work direction will it support?

A sensible next step for different starting points

Your next step should match your current evidence, not the most advanced title in the catalogue. Use the following routes as decision aids, then confirm every requirement on ISACA’s current page for the selected credential.

If you are new to IS/IT governance, audit, security or risk, begin by comparing the fundamentals certificates and the introductory material in ISACA’s credential catalogue. Select a subject connected to your intended work and use it to build vocabulary and context before deciding whether a professional certification is appropriate.

If you already perform audit or control-assessment work, review CISA’s five domains and candidate requirements. Map your responsibilities to the certification application, identify weak domains and choose preparation resources that address both conceptual understanding and practical judgment.

If you manage information security, investigate CISM and compare its scope with the decisions you make as a security leader. If your role is more operational, examine CCOA instead. If your primary responsibility is technology risk, compare CRISC; if it is enterprise-level governance, compare CGEIT.

If privacy engineering, privacy-by-design or technical data controls define your work, examine CDPSE and its current requirements. If AI is a major part of an established audit, security-management or risk practice, compare AAIA, AAISM or AAIR with the relevant foundational certification and verify the advanced credential’s eligibility.

If your work is tied to formal CMMC assessment, instruction or professional practice, use the CMMC credential descriptions and current program guidance to identify the role that matches your responsibilities. Do not select a CMMC designation solely because its subject is cybersecurity; its value depends on the specific role and program conditions.

If you are considering ISACA primarily for community and continuing learning, review membership separately. ISACA lists a global chapter network, CPE opportunities, professional resources and member discounts, but those benefits should be weighed against your actual use and the current membership terms.

Use official pages as a final verification step

Before paying for an exam, course or membership, open the relevant ISACA page and verify the current credential name, status, exam outline, eligibility, application requirements, fees, scheduling rules, delivery method and maintenance policy. Candidate guides are particularly important because ISACA says they cover registration, scheduling, preparation, exam rules, administration, scoring and retake policy.

For CISA, also check eligibility, the six-month eligibility period, the current exam cost, the available scheduling window and the certification application steps. These details are time-sensitive and belong to the official page rather than a static third-party summary.

If an official page announces an upcoming exam or preparation change, decide whether to use the current version or wait for the new one only after checking the stated transition rules. Avoid buying materials based on a date or edition that is no longer aligned with the exam you will take.

What makes an ISACA path a good fit

An ISACA credential is a good fit when its subject, evidence requirements and continuing obligations line up with the work you want to perform. The ecosystem is broad enough to support distinct directions, but that breadth makes selection more important than simply collecting titles.

Choose CISA when assurance and IT audit are central; investigate CISM when information-security management is the core responsibility; consider CRISC for IT risk and control; look to CGEIT for enterprise IT governance; examine CDPSE for privacy solution engineering; and consider CCOA for cybersecurity operations. Use the AI credentials when AI-specific audit, security or risk work is already relevant, and use CMMC designations for their defined assessment and program roles.

Certificates can provide a focused introduction or close a specific knowledge gap. Membership can add learning, networking and CPE resources, but it should be evaluated independently from certification eligibility. Across every route, the current official candidate guide is the best checkpoint for requirements and policy.

The strongest next step is therefore specific: select one work direction, read its official credential page and candidate guide, document your readiness gaps, and then decide whether to begin with a certificate, preparation resource, membership or professional certification application. That process keeps the choice evidence-led and connected to the role you want to do.

Conclusion

ISACA offers more than a single certification route: it brings together professional credentials in audit, security, risk, governance and privacy; advanced AI designations; cybersecurity operations; CMMC roles; and certificates for focused foundational learning. The right path depends on the work you perform, the experience you can document, the depth of recognition you need and the maintenance commitments you can sustain. Start with the role, validate the current official requirements and choose the smallest credential step that genuinely supports your next professional responsibility.

Related exams

Official sources

Build a focused Isaca study route.

Use the live catalog data to move from provider research to a preparation format that fits your exam date and routine.

Choose the exact exam code

Match the certification objective to the currently published exam before starting practice.

Check recency and availability

Review question totals, update dates, retirement status, and pre-order availability directly in the catalog.

Choose the study format

Continue to the exam page to compare PDF review, test-engine practice, and supported bundle options.