CISAISACA Certified Information Systems Auditor
Created per CertMap methodology · Updated 12 May 2026 · About the editorial team → · Official page ↗

▾ Jump to …6 sections
What is CISA?
The CISA has been considered the gold standard for IT auditors and audit professionals worldwide for decades. It covers the entire lifecycle of IS audits, from planning through execution to reporting, and is in high demand in regulated industries such as banking, insurance, and the public sector. The certification requires five years of relevant professional experience, clearly positioning it as a senior-level credential. For career changers from IT, it serves as a springboard toward governance and compliance. The CISA is recognized globally by employers and regulators and is nearly ubiquitous in job postings for IT audit roles.
Quick facts
Cost, prerequisites, exam & renewal
Cost over 5 years
AMF prices are ISACA member prices. Membership adds 195 USD/year once per person (135 USD dues + 60 USD Germany chapter, varies by chapter); without membership the AMF is 85 USD per cert.
How is TCO calculated? →Prerequisites
5 years of experience in IS audit, control, or security. Up to 3 years may be substituted through education/certifications.
Exam format
Renewal & maintenance
Valid for 3 years. 20 CPE hours/year (min. 120 over 3 years) + annual AMF (45 USD Member / 85 USD Non-Member). A one-time application fee of 50 USD applies after passing the exam.
CertMap score and matching roles
Rating
Matching NICE roles
How to prepare
Our editorial recommendation to get started: freely accessible, no paid placement, no affiliate links.
Pete Zerger – CISA Exam Prep 2026
Free complete CISA preparation series by Pete Zerger (Inside Cloud and Security): ten parts across all domains. The link starts part 1 and opens the full playlist.
Watch on YouTube ↗ · checked on Aug 19, 2026
Curated, not sponsored: the recommendation is chosen editorially and cannot be bought. Official provider materials are available via the certification page link at the top of this page.
More certifications

Personal consulting
Not sure what's next? Ask someone who knows.
Personal strategy instead of weeks of self-research. Vendor-independent, with auditable recommendations and transparent sources.
From the knowledge base
View all articles →CISSP or CISM? Two Careers, One Decision
Both require five years of experience, both cost roughly the same at first glance. Yet CISSP and CISM lead to different professions. The comparison with the numbers that course providers don't show.
CISM or CISA? Two ISACA paths, one directional decision
Both come from ISACA, both require five years of experience, and both cost almost the same. The difference is not the price but the role: managing or auditing. The comparison with the numbers and the role mapping.
CC or Security+? The Free Entry Point and the Job-Market Classic
Both are entry-level certifications with no admission barrier, both cover the fundamentals of cybersecurity, and yet they stand for different strategies: one as a low-threshold, temporarily free start, the other as an established credential with weight in the job market. The comparison with the numbers and the opposing cost logic.
