Skip to content
CertMapCertMap

CISAISACA Certified Information Systems Auditor

ISACAPersonnel certification (ISO 17024)Audit
Official certification page

Created per CertMap methodology · Updated 12 May 2026 · About the editorial team

Jump to …4 sections

Overview

What is CISA?

The CISA has been considered the gold standard for IT auditors and audit professionals worldwide for decades. It covers the entire lifecycle of IS audits, from planning through execution to reporting, and is in high demand in regulated industries such as banking, insurance, and the public sector. The certification requires five years of relevant professional experience, clearly positioning it as a senior-level credential. For career changers from IT, it serves as a springboard toward governance and compliance. The CISA is recognized globally by employers and regulators and is nearly ubiquitous in job postings for IT audit roles.

Quick facts

AccreditationISO/IEC 17024 by ANSI
Languagesen · de · fr · es · ja · ko · zh · it · tr
RecognitionGlobal

Key details

Cost, prerequisites, exam & renewal

Cost over 5 years

Exam fee (acquisition)€699
AMF (5 years)€207
CPE time value (5 years)€8,000
5-year total€8,906
CPE effort: 20 h per year · 100 h over 5 years · Valued at 80 €/h.

AMF prices are ISACA member prices. Membership adds 195 USD/year once per person (135 USD dues + 60 USD Germany chapter, varies by chapter); without membership the AMF is 85 USD per cert.

How is TCO calculated?

Classification

CertMap score and matching roles

Rating

Market recognition
3/3
Scheme quality
3/3
Practice evidence
2/3
Maintenance
2/3

Matching NICE roles

Oversee and GovernCybersecurity Curriculum Development
Oversee and GovernCybersecurity Instruction
Oversee and GovernPrivacy Compliance
Oversee and GovernSecurity Control Assessment
Oversee and GovernTechnology Program Auditing
Protect and DefendVulnerability Analysis

More certifications

More certifications

This page follows CertMap methodology: editorial content is curated by hand. Score, costs and NICE mapping are aggregated from official provider documents. Score methodology · TCO methodology

Transparency: CertMap is operated by Daniel Thomas Heessel, who is also managing director of Threat‑Informed, a company specialising in Threat‑Informed Defense. CertMap currently receives no commissions from certification providers, no affiliate links, no sponsored placements. Podcast and interview guests are not paid for appearances and receive no affiliate commissions.

Daniel Heessel, CISO of the Year 2026

1:1 with the CISO

Personal strategy instead of weeks of self-research. Vendor-independent, with auditable recommendations and transparent sources.

Open consulting
CISAView in quadrant