CRISC
ISACA Certified in Risk and Information Systems Control
Created per CertMap methodology · Updated 12 May 2026 · About the editorial team →
▾ Jump to …4 sections
Overview
What is CRISC?
Certified in Risk and Information Systems Control is the leading certification in IT risk management and is considered the gold standard for professionals at the intersection of IT risk and enterprise governance. CRISC complements CISM and CISA in the ISACA portfolio and is particularly highly valued in regulated industries (banking, insurance, healthcare). The certification was substantially revised in 2025: The new exam content emphasizes Risk Response and Reporting with 32% weighting. CRISC's strength is its direct applicability in GRC roles and strong market penetration; its weakness lies in its broad abstraction, which does not reflect technically deep skills. In career terms, CRISC is a strong signal for risk-focused leadership roles.
Quick facts
Key details
Cost, prerequisites, exam & renewal
Cost over 5 years
Prerequisites
3 years experience in IT risk management and IS control. Min. 1 year in Domain 1 or 2.
Exam format
150 multiple-choice questions, 4 hours, proctored via PSI. Passing score: 450/800.
Renewal & maintenance
Valid for 3 years. 20 CPE hours/year (min. 120 over 3 years) + annual AMF (45 USD Member / 85 USD Non-Member).
Classification
CertMap score and matching roles
Rating
Matching NICE roles
Mapping from NIST NICE Framework SP 800-181, status 2025. NIST source ↗
More certifications
More certifications
From ISACA
AAIAAdvanced in AI AuditAAIRAdvanced in AI RiskAAISMAdvanced in AI Security ManagementCCOACertified Cybersecurity Operations AnalystCDPSECertified Data Privacy Solutions EngineerCGEITISACA Certified in the Governance of Enterprise ITCISAISACA Certified Information Systems AuditorCISMISACA Certified Information Security ManagerThis page follows CertMap methodology: editorial content is curated by hand. Score, costs and NICE mapping are aggregated from official provider documents. Score methodology → · TCO methodology →
Transparency: CertMap is operated by Daniel Thomas Heessel, who is also managing director of Threat‑Informed, a company specialising in Threat‑Informed Defense. He additionally offers consulting services on CertMap. CertMap currently receives no commissions from certification providers, no affiliate links, no sponsored placements. Podcast and interview guests are not paid for appearances and receive no affiliate commissions.
From the knowledge base
View all articles →About the CertMap editorial team
CertMap is an independent platform for comparing cybersecurity certifications, built on data-journalism standards that combine editorial curation with mechanical aggregation.
Certification vs. Certificate: What's the Difference?
Personnel certification per ISO/IEC 17024 versus a training certificate. Why the distinction matters.
BSI IT-Grundschutz: Practitioners, Advisors, and the Accreditation Question
What distinguishes Practitioner from Advisor, and where does accreditation sit in the BSI path?

1:1 with the CISO
Need the full picture for your case?
60 minutes of personal strategy instead of weeks of self-research. Vendor-independent, with a written report.