CRISCISACA Certified in Risk and Information Systems Control
Created per CertMap methodology · Updated 12 May 2026 · About the editorial team → · Official page ↗

▾ Jump to …4 sections
What is CRISC?
Certified in Risk and Information Systems Control is the leading certification in IT risk management and is considered the gold standard for professionals at the intersection of IT risk and enterprise governance. CRISC complements CISM and CISA in the ISACA portfolio and is particularly highly valued in regulated industries (banking, insurance, healthcare). The certification was substantially revised in 2025: The new exam content emphasizes Risk Response and Reporting with 32% weighting. CRISC's strength is its direct applicability in GRC roles and strong market penetration; its weakness lies in its broad abstraction, which does not reflect technically deep skills. In career terms, CRISC is a strong signal for risk-focused leadership roles.
Quick facts
Cost, prerequisites, exam & renewal
Cost over 5 years
AMF prices are ISACA member prices. Membership adds 195 USD/year once per person (135 USD dues + 60 USD Germany chapter, varies by chapter); without membership the AMF is 85 USD per cert.
How is TCO calculated? →Prerequisites
3 years experience in IT risk management and IS control. Min. 1 year in Domain 1 or 2.
Exam format
Renewal & maintenance
Valid for 3 years. 20 CPE hours/year (min. 120 over 3 years) + annual AMF (45 USD Member / 85 USD Non-Member). A one-time application fee of 50 USD applies after passing the exam.
CertMap score and matching roles
Rating
Matching NICE roles
More certifications
From the knowledge base
View all articles →CISSP or CISM? Two Careers, One Decision
Both require five years of experience, both cost roughly the same at first glance. Yet CISSP and CISM lead to different professions. The comparison with the numbers that course providers don't show.
CISM or CISA? Two ISACA paths, one directional decision
Both come from ISACA, both require five years of experience, and both cost almost the same. The difference is not the price but the role: managing or auditing. The comparison with the numbers and the role mapping.
CC or Security+? The Free Entry Point and the Job-Market Classic
Both are entry-level certifications with no admission barrier, both cover the fundamentals of cybersecurity, and yet they stand for different strategies: one as a low-threshold, temporarily free start, the other as an established credential with weight in the job market. The comparison with the numbers and the opposing cost logic.