Master IT Security with NYTCC

Elevate Your Career with Premier Training

About NYTCC
At NYTCC, we lead the way in security and technology education. Our mission is to empower individuals to achieve their educational and professional goals. By offering top-notch training programs, we help our clients succeed, enhance their professional standing, and increase their marketability. Join NYTCC and become an IT security expert, unlocking new career opportunities.

The CRISC certification from ISACA validates professional capability in IT risk management, governance, risk assessment, risk response, reporting, and information systems controls. The current CRISC exam contains 150 questions, allows four hours, and covers four domains weighted from 20% to 32%. Candidates need a scaled score of 450 or higher to pass. Certification also requires at least three years of relevant professional experience across two or more CRISC domains and completion of ISACA’s certification application process.

What Is CRISC Certification?

CRISC, short for Certified in Risk and Information Systems Control, is an ISACA credential built for professionals responsible for identifying, assessing, responding to, monitoring, and reporting technology-related business risk.Unlike certifications focused mainly on technical security configuration, the ISACA CRISC certification sits at the intersection of technology, governance, business objectives, risk ownership, and controls.That makes it particularly relevant for professionals working in:

  • IT risk management
  • Cybersecurity governance
  • Governance, Risk and Compliance (GRC)
  • Information security
  • IT audit and assurance
  • Enterprise risk management
  • Internal controls
  • Compliance
  • Technology management
  • Third-party and supply-chain risk

A useful way to understand CRISC is this: a security engineer may ask, “How do we technically secure this system?” A CRISC-focused professional must also ask, “What business risk does this system create, how significant is that risk, who owns it, which controls are justified, and how should management monitor it?”That business-to-technology connection is central to the credential.

CRISC Exam Format in 2026

ISACA updated the CRISC exam content in November 2025, and the revised structure is the relevant framework for candidates preparing in 2026. The examination continues to cover four major job-practice domains, with revised weighting across Risk Assessment and Technology and Security.

CRISC Exam DetailCurrent Information
CertificationCertified in Risk and Information Systems Control
ProviderISACA
Exam Questions150
Exam Duration4 hours
Passing Score450 out of 800 scaled score
Exam Domains4
Testing MethodPSI testing center or remote proctoring
RegistrationContinuous
Certification Application FeeUS$50

ISACA uses a scaled scoring system ranging from 200 to 800. A score of 450 or higher is required to pass. Domain-level results can help candidates understand their performance, but the final pass/fail result is based on the total exam score rather than requiring candidates to pass every domain separately.

CRISC Exam Domains and Weightage

Understanding domain weighting is one of the most important parts of CRISC exam preparation.

DomainWeight
Domain 1: Governance26%
Domain 2: Risk Assessment22%
Domain 3: Risk Response and Reporting32%
Domain 4: Technology and Security20%

These percentages are based on ISACA’s current CRISC Exam Content Outline.

Domain 1: Governance – 26%

Governance tests whether you can connect technology risk with organizational strategy and decision-making.Important areas include organizational goals, governance structures, roles and responsibilities, policies, business resilience, enterprise risk management, risk appetite, risk tolerance, risk profiles, legal requirements, and regulatory obligations.Candidates often underestimate this domain because it does not feel as technical as cybersecurity. That can be a mistake. CRISC expects candidates to understand why risk decisions exist within a business context.

Domain 2: Risk Assessment – 22%

Risk Assessment focuses on identifying threats, vulnerabilities, risk events, and possible business impact.You should understand concepts such as threat modeling, risk scenarios, business impact analysis, risk registers, inherent risk, residual risk, qualitative assessment, and quantitative assessment.Strong candidates do more than calculate or classify risk. They understand how risk information affects business decisions.

Domain 3: Risk Response and Reporting – 32%

At 32%, this is the largest CRISC exam domain.Topics include risk-response options, control ownership, vendor risk, control frameworks, control design, implementation, testing, risk action plans, Key Risk Indicators, Key Performance Indicators, Key Control Indicators, dashboards, scorecards, and emerging-risk reporting.Because almost one-third of the exam is associated with this domain, your CRISC training should devote significant attention to risk treatment and control-management scenarios.A common exam-style distinction is between recognizing a risk and deciding what should happen after that risk has been analyzed. Candidates should understand when organizations accept, mitigate, transfer, or avoid risk and who should authorize those decisions.

Domain 4: Technology and Security – 20%

This section connects risk management with practical technology operations.Areas include enterprise architecture, change management, DevOps, incident management, system development, data lifecycle management, projects, technology resilience, disaster recovery, emerging technologies, security frameworks, awareness programs, privacy, and data protection.You do not need to approach this section as a hands-on engineering examination. The important skill is understanding technology from a risk-and-control perspective.

CRISC Certification Requirements

One important distinction is that the requirements for taking the CRISC exam and becoming CRISC certified are different.ISACA states that candidates can take the examination before meeting the professional experience requirement. However, passing the exam alone does not immediately make someone CRISC certified.To earn the certification, candidates must:

  1. Pass the CRISC exam.
  2. Have at least three years of relevant professional experience.
  3. Have experience across at least two of the four CRISC domains.
  4. Ensure the qualifying experience falls within the 10 years preceding the certification application.
  5. Apply for certification within five years of passing the exam.
  6. Pay the US$50 certification application fee.
  7. Agree to comply with ISACA's professional and certification requirements.

This structure benefits professionals who are still building experience. You may complete the examination first and then satisfy the remaining experience requirement within the allowed certification application period.

CRISC Certification Cost

The CRISC certification cost has several components. Candidates should distinguish the exam registration price from certification application and ongoing maintenance costs.According to ISACA's current pricing, the CRISC exam cost is:ISACA Member: US$575

Non-Member: US$760After passing and meeting the requirements, candidates pay a separate US$50 certification application processing fee.Certification holders must also pay annual maintenance fees. Current annual CRISC maintenance fees are US$45 for ISACA members and US$85 for non-members.CRISC courses, books, question banks, and instructor-led CRISC certification training may create additional preparation costs depending on the learning method selected.

How Difficult Is the CRISC Exam?

The difficulty of the CRISC exam comes less from memorizing terminology and more from choosing the best risk-management decision within a scenario.A candidate may understand what a vulnerability is but still struggle when asked what management should do first after discovering it.CRISC questions frequently require you to think about:business objectives → risk → ownership → assessment → controls → monitoring → reportingThis sequence is more valuable than trying to memorize isolated facts.For example, imagine a business discovers a major vulnerability in a third-party platform. A purely technical response might be to immediately implement additional security controls.A risk-management response asks additional questions. What business process is affected? What is the likelihood and impact? Who owns the risk? Does the current exposure exceed risk tolerance? What contractual controls exist? What treatment decision should be recommended?That mindset is essential for CRISC.

CRISC Training: What Should a Good Course Cover?

A strong CRISC course should follow the current ISACA Exam Content Outline rather than an outdated syllabus.Your CRISC certification training should combine conceptual learning with scenario-based practice.Look for preparation covering:

  • Governance and business objectives
  • Enterprise risk management
  • Risk appetite and tolerance
  • Risk identification
  • Threats and vulnerabilities
  • Risk scenario development
  • Business impact analysis
  • Risk registers
  • Inherent and residual risk
  • Risk-response strategies
  • Control selection and design
  • Control testing
  • Vendor and supply-chain risk
  • KRIs, KPIs, and KCIs
  • Risk reporting
  • Technology resilience
  • Information security frameworks
  • Emerging technology risk

ISACA currently offers several official preparation options, including a CRISC Online Review Course, review manuals, practice resources, study groups, and a Questions, Answers & Explanations database. Its current question database contains a pool of 833 practice items.

How to Prepare for CRISC Efficiently

A practical study process can be divided into five stages.Step 1: Study the latest exam outline.
Before buying a course or starting a study plan, compare the material with the current four CRISC domains.Step 2: Build your risk-management foundation.
Make sure you clearly understand risk appetite, tolerance, ownership, inherent risk, residual risk, controls, KRIs, and governance.Step 3: Practice scenario-based questions.
CRISC preparation should teach decision-making rather than simple vocabulary recall.Step 4: Review every incorrect answer.
Do not only track your score. Understand why another response was more appropriate.Step 5: Complete timed mock exams.
With 150 questions and four hours available, candidates have an average of about 96 seconds per question. Practice should therefore include both accuracy and pacing.One useful exam technique comes directly from ISACA's candidate guidance: pay close attention to qualifiers such as MOST, BEST, and similar wording, eliminate clearly incorrect options, and answer every question because incorrect responses do not carry a separate penalty.

Is CRISC Certification Worth Considering?

CRISC is particularly relevant when your responsibilities extend beyond cybersecurity technology into decisions about business risk.A network engineer who mainly configures infrastructure may not use CRISC concepts every day. A security professional who regularly speaks with management, evaluates risk, recommends controls, handles compliance requirements, works with vendors, manages risk registers, or reports security exposure to stakeholders is much closer to the certification's intended skill set.This distinction matters when comparing CRISC with purely technical certifications.CRISC asks whether you can help an organization make defensible risk-based decisions, not simply whether you know how a security technology works.

Maintaining the ISACA CRISC Certification

Passing the exam is not the end of the certification lifecycle.CRISC holders must earn at least 20 Continuing Professional Education hours each year and at least 120 CPE hours during every three-year reporting period. They must also pay annual maintenance fees and comply with ISACA's Code of Professional Ethics and applicable audit requirements.These requirements are designed to keep the credential connected to current professional practice rather than treating certification as a one-time achievement.

Your Next Step for CRISC Certification

Start your CRISC certification preparation with the current ISACA exam outline, not an old study plan. Give particular attention to Risk Response and Reporting, which now represents 32% of the exam, but do not ignore governance and business-oriented questions.Choose CRISC training that teaches you how to analyze risk scenarios, identify ownership, evaluate controls, understand residual risk, and communicate risk to decision-makers. Use practice questions to improve judgment rather than memorize answers, then move into timed mock examinations as your test date approaches.The strongest CRISC candidates learn to think beyond “What is the technical problem?” and consistently ask the more important question: “What should the organization do about the risk, and why?”

19Sep

The ISACA CISA Certification is the world's leading credential for IT audit, information systems control, and cybersecurity governance professionals.

The ISACA CISA Certification is the world's leading credential for IT audit, information systems control, and cybersecurity governance professionals. The CISA exam 2026 covers five domains, includes 150 multiple-choice questions, lasts 4 hours, and requires a scaled score of 450/800 to pass. Candidates also need relevant professional experience to earn the certification. This guide explains the CISA syllabus 2026, exam pattern, fees, requirements, certification cost, and the step-by-step process to become a Certified Information Systems Auditor.

What is CISA?

CISA (Certified Information Systems Auditor) is a globally recognized certification offered by ISACA for professionals who audit, assess, monitor, and secure enterprise information systems.Unlike general cybersecurity certifications, CISA focuses on IT auditing, governance, risk management, compliance, and internal controls. Organizations worldwide use CISA-certified professionals to evaluate whether technology systems are secure, reliable, and compliant with business and regulatory requirements.

Who should pursue CISA?

  • IT Auditors



  • Information Security Analysts



  • Risk & Compliance Professionals



  • Internal Auditors



  • Cybersecurity Consultants



  • Governance & GRC Specialists



  • IT Managers handling audit or compliance



 

ISACA CISA Certification at a glance

FeatureDetails
CertificationISACA Certified Information Systems Auditor (CISA)
Exam Questions150 Multiple Choice Questions
Exam Duration4 Hours
Passing Score450 (Scaled Score)
Exam FormatComputer-Based Testing
Testing WindowYear-round scheduling
Certification ValidityAnnual maintenance with CPE requirements
Skill LevelIntermediate to Advanced

 

CISA syllabus 2026: Complete exam domains

The CISA exam syllabus 2026 is divided into five weighted domains that reflect real-world IT audit responsibilities.

Domain 1: Information Systems Auditing Process (18%)

This domain measures your ability to plan, conduct, and report IT audits.Key topics include:

  • Audit standards and ethics



  • Risk-based audit planning



  • Evidence collection



  • Audit documentation



  • Reporting audit findings



Real-world example: Evaluating whether an organization's cloud infrastructure follows established audit controls.

Domain 2: Governance and Management of IT (18%)

Focuses on aligning technology with business objectives.Topics include:

  • IT governance frameworks



  • Organizational structure



  • Enterprise architecture



  • Vendor management



  • Performance measurement



Professionals working with COBIT, governance policies, or enterprise IT strategy often find this section familiar.

Domain 3: Information Systems Acquisition, Development & Implementation (12%)

This section evaluates project and system lifecycle knowledge.Important areas:

  • SDLC



  • Agile and DevOps controls



  • Change management



  • System testing



  • Implementation reviews



Domain 4: Information Systems Operations & Business Resilience (26%)

The largest operational domain covers:

  • Incident management



  • Disaster recovery



  • Business continuity



  • IT service management



  • Database and infrastructure operations



  • Cloud operational controls



This domain carries significant weight and often determines overall performance.

Domain 5: Protection of Information Assets (26%)

The cybersecurity-heavy section includes:

  • Identity & Access Management



  • Network security



  • Encryption



  • Vulnerability management



  • Security monitoring



  • Data protection



  • Privacy controls



Candidates with security experience often perform strongly here, making it highly valuable alongside CISA CISM certification career paths. 

CISA exam pattern 2026

Understanding the CISA exam pattern is just as important as studying the syllabus.

ComponentDetails
Questions150
Question TypeMultiple Choice
Duration240 Minutes
Passing Score450/800
Negative MarkingNo
DeliveryComputer-Based Exam

How is CISA scored?

ISACA uses a scaled scoring model instead of raw marks.

  • Score range: 200–800



  • Passing score: 450



  • Every question is not equally weighted in difficulty.



  • Candidates receive performance feedback by domain after the exam.



 

How much is the CISA exam fee in 2026?

One of the most searched questions is "How much is CISA?" or "How much is the CISA exam fee?"The CISA certification cost depends primarily on whether you're an ISACA member.

Fee TypeISACA MemberNon-Member
CISA Exam FeeLower member rateHigher standard rate
ISACA MembershipOptionalOptional
Application FeeAdditionalAdditional
Annual MaintenanceRequiredRequired

The total CISA certification fees typically include:

  • Exam registration



  • Certification application



  • Annual maintenance fee



  • Continuing Professional Education (CPE)



Joining ISACA before registering often reduces the overall CISA examination fees, especially if you plan to maintain the credential long term. 

How to get CISA certification: Step-by-step

Many candidates confuse passing the exam with earning the certification. They're different.

Step 1: Meet the eligibility goal

You can take the exam before completing the experience requirement.

Step 2: Study the CISA syllabus

Create a structured study plan covering all five domains.

Step 3: Register for the ISACA CISA exam

Schedule your preferred testing date through ISACA's authorized exam system.

Step 4: Pass the exam

Achieve the required 450 scaled score.

Step 5: Apply for certification

Submit your professional experience and agree to ISACA's Code of Professional Ethics.

Step 6: Maintain your credential

Earn annual CPE credits and renew your certification each year. 

ISACA CISA requirements

To officially become certified, candidates generally need professional experience in information systems auditing, control, security, or assurance.The experience requirement can often be reduced through approved educational substitutions, making CISA accessible to professionals with relevant academic backgrounds.Typical qualifying experience areas include:

  • IT Audit



  • Security Operations



  • Risk Management



  • Compliance



  • Internal Controls



  • Information Assurance



 

CISA vs CISM certification

Many professionals compare CISA CISM certification when planning their careers.

FeatureCISACISM
Primary FocusIT AuditInformation Security Management
Ideal RoleAuditorSecurity Manager
Core SkillAssurance & ControlsSecurity Governance
Best ForCompliance, AuditLeadership, Cybersecurity Strategy
Offered ByISACAISACA

Choose CISA if your work revolves around auditing systems, evaluating controls, or regulatory compliance. CISM is better aligned with managing enterprise security programs.Many senior professionals eventually hold both certifications. 

CISA IT Audit: Skills you'll develop

The CISA IT audit framework builds practical skills beyond exam knowledge.You'll learn to:

  • Identify weaknesses in enterprise controls



  • Evaluate cloud security governance



  • Assess cybersecurity risks



  • Audit ERP and business applications



  • Review access management policies



  • Perform evidence-based compliance assessments



  • Recommend risk mitigation strategies



These capabilities are highly relevant in banking, healthcare, government, consulting, and multinational enterprises. 

CISA exam schedule 2026

The CISA exam schedule 2026 follows a year-round testing model rather than fixed exam dates.Candidates can typically:

  1. Register online.



  2. Select a nearby testing center.



  3. Choose an available date.



  4. Reschedule within permitted policies if needed.



This flexible scheduling allows professionals to prepare at their own pace instead of waiting for quarterly exam windows. 

CISA practice tests: Are they worth it?

Yes—but only if they're used strategically.A strong preparation approach includes:

  • Domain-wise practice questions



  • Full-length timed mock exams



  • Performance analysis by domain



  • Reviewing explanations instead of memorizing answers



Aim to consistently score 80% or higher on realistic mock exams before attempting the actual CISA exam. 

12-week CISA study roadmap

WeekFocus
1–2Domain 1
3–4Domain 2
5Domain 3
6–8Domain 4
9–10Domain 5
11Full Practice Tests
12Revision & Weak Areas

A balanced schedule is more effective than trying to master every domain equally. Prioritize Domains 4 and 5 because together they represent 52% of the exam. 

Career opportunities after CISA

CISA opens opportunities across audit, governance, and cybersecurity.Common job roles include:

  • IT Auditor



  • Senior Information Systems Auditor



  • Internal Audit Consultant



  • Cyber Risk Analyst



  • Governance, Risk & Compliance (GRC) Specialist



  • Information Security Auditor



  • Technology Risk Consultant



  • Compliance Manager



Industries hiring CISA professionals include financial services, consulting firms, healthcare, telecommunications, government, manufacturing, and cloud service providers. 

Frequently Asked Questions

What is CISA certification?

CISA certification is ISACA's globally recognized credential validating expertise in information systems auditing, governance, risk, and security controls.

How much is the CISA exam fee?

The CISA exam fee varies for ISACA members and non-members. The total certification cost also includes application and annual maintenance fees.

What is the CISA syllabus 2026?

The CISA syllabus 2026 includes five domains: IT Auditing Process, Governance & Management, System Acquisition & Development, Operations & Resilience, and Protection of Information Assets.

What is the CISA exam pattern?

The exam contains 150 multiple-choice questions, lasts 4 hours, and requires a 450 scaled score to pass.

How do I get CISA certification?

Pass the ISACA CISA exam, meet the professional experience requirement, submit your certification application, and maintain annual CPE compliance.

Is CISA suitable for beginners?

Yes. Beginners can take the exam, although professional experience is required before ISACA awards the certification.

What is شهادة CISA?

شهادة CISA is the Arabic term for the Certified Information Systems Auditor certification issued by ISACA.

Your next move

If your goal is to build a career in IT audit, cybersecurity governance, risk, or compliance, start with the CISA syllabus 2026 and create a structured 12-week study plan. Focus on mastering the five domains, practice under timed conditions, and understand control-based thinking rather than memorizing questions. Passing the exam is only one milestone—the real value of ISACA CISA certification comes from applying audit principles to secure and improve enterprise information systems.  

ISACA CISA Certification 2026: Complete Exam Guide, Syllabus, Fees & Career Path

The ISACA CISA Certification is the world's leading credential for IT audit, information systems control, and cybersecurity governance professionals. The CISA exam 2026 covers five domains, includes 150 multiple-choice questions, lasts 4 hours, and requires a scaled score of 450/800 to pass. Candidates also need relevant professional experience to earn the certification. This guide explains the CISA syllabus 2026, exam pattern, fees, requirements, certification cost, and the step-by-step process to become a Certified Information Systems Auditor. 

What is CISA?

CISA (Certified Information Systems Auditor) is a globally recognized certification offered by ISACA for professionals who audit, assess, monitor, and secure enterprise information systems.Unlike general cybersecurity certifications, CISA focuses on IT auditing, governance, risk management, compliance, and internal controls. Organizations worldwide use CISA-certified professionals to evaluate whether technology systems are secure, reliable, and compliant with business and regulatory requirements.

Who should pursue CISA?

  • IT Auditors



  • Information Security Analysts



  • Risk & Compliance Professionals



  • Internal Auditors



  • Cybersecurity Consultants



  • Governance & GRC Specialists



  • IT Managers handling audit or compliance



 

ISACA CISA Certification at a glance

FeatureDetails
CertificationISACA Certified Information Systems Auditor (CISA)
Exam Questions150 Multiple Choice Questions
Exam Duration4 Hours
Passing Score450 (Scaled Score)
Exam FormatComputer-Based Testing
Testing WindowYear-round scheduling
Certification ValidityAnnual maintenance with CPE requirements
Skill LevelIntermediate to Advanced

 

CISA syllabus 2026: Complete exam domains

The CISA exam syllabus 2026 is divided into five weighted domains that reflect real-world IT audit responsibilities.

Domain 1: Information Systems Auditing Process (18%)

This domain measures your ability to plan, conduct, and report IT audits.Key topics include:

  • Audit standards and ethics



  • Risk-based audit planning



  • Evidence collection



  • Audit documentation



  • Reporting audit findings



Real-world example: Evaluating whether an organization's cloud infrastructure follows established audit controls.

Domain 2: Governance and Management of IT (18%)

Focuses on aligning technology with business objectives.Topics include:

  • IT governance frameworks



  • Organizational structure



  • Enterprise architecture



  • Vendor management



  • Performance measurement



Professionals working with COBIT, governance policies, or enterprise IT strategy often find this section familiar.

Domain 3: Information Systems Acquisition, Development & Implementation (12%)

This section evaluates project and system lifecycle knowledge.Important areas:

  • SDLC



  • Agile and DevOps controls



  • Change management



  • System testing



  • Implementation reviews



Domain 4: Information Systems Operations & Business Resilience (26%)

The largest operational domain covers:

  • Incident management



  • Disaster recovery



  • Business continuity



  • IT service management



  • Database and infrastructure operations



  • Cloud operational controls



This domain carries significant weight and often determines overall performance.

Domain 5: Protection of Information Assets (26%)

The cybersecurity-heavy section includes:

  • Identity & Access Management



  • Network security



  • Encryption



  • Vulnerability management



  • Security monitoring



  • Data protection



  • Privacy controls



Candidates with security experience often perform strongly here, making it highly valuable alongside CISA CISM certification career paths. 

CISA exam pattern 2026

Understanding the CISA exam pattern is just as important as studying the syllabus.

ComponentDetails
Questions150
Question TypeMultiple Choice
Duration240 Minutes
Passing Score450/800
Negative MarkingNo
DeliveryComputer-Based Exam

How is CISA scored?

ISACA uses a scaled scoring model instead of raw marks.

  • Score range: 200–800



  • Passing score: 450



  • Every question is not equally weighted in difficulty.



  • Candidates receive performance feedback by domain after the exam.



 

How much is the CISA exam fee in 2026?

One of the most searched questions is "How much is CISA?" or "How much is the CISA exam fee?"The CISA certification cost depends primarily on whether you're an ISACA member.

Fee TypeISACA MemberNon-Member
CISA Exam FeeLower member rateHigher standard rate
ISACA MembershipOptionalOptional
Application FeeAdditionalAdditional
Annual MaintenanceRequiredRequired

The total CISA certification fees typically include:

  • Exam registration



  • Certification application



  • Annual maintenance fee



  • Continuing Professional Education (CPE)



Joining ISACA before registering often reduces the overall CISA examination fees, especially if you plan to maintain the credential long term. 

How to get CISA certification: Step-by-step

Many candidates confuse passing the exam with earning the certification. They're different.

Step 1: Meet the eligibility goal

You can take the exam before completing the experience requirement.

Step 2: Study the CISA syllabus

Create a structured study plan covering all five domains.

Step 3: Register for the ISACA CISA exam

Schedule your preferred testing date through ISACA's authorized exam system.

Step 4: Pass the exam

Achieve the required 450 scaled score.

Step 5: Apply for certification

Submit your professional experience and agree to ISACA's Code of Professional Ethics.

Step 6: Maintain your credential

Earn annual CPE credits and renew your certification each year. 

ISACA CISA requirements

To officially become certified, candidates generally need professional experience in information systems auditing, control, security, or assurance.The experience requirement can often be reduced through approved educational substitutions, making CISA accessible to professionals with relevant academic backgrounds.Typical qualifying experience areas include:

  • IT Audit



  • Security Operations



  • Risk Management



  • Compliance



  • Internal Controls



  • Information Assurance



 

CISA vs CISM certification

Many professionals compare CISA CISM certification when planning their careers.

FeatureCISACISM
Primary FocusIT AuditInformation Security Management
Ideal RoleAuditorSecurity Manager
Core SkillAssurance & ControlsSecurity Governance
Best ForCompliance, AuditLeadership, Cybersecurity Strategy
Offered ByISACAISACA

Choose CISA if your work revolves around auditing systems, evaluating controls, or regulatory compliance. CISM is better aligned with managing enterprise security programs.Many senior professionals eventually hold both certifications. 

CISA IT Audit: Skills you'll develop

The CISA IT audit framework builds practical skills beyond exam knowledge.You'll learn to:

  • Identify weaknesses in enterprise controls



  • Evaluate cloud security governance



  • Assess cybersecurity risks



  • Audit ERP and business applications



  • Review access management policies



  • Perform evidence-based compliance assessments



  • Recommend risk mitigation strategies



These capabilities are highly relevant in banking, healthcare, government, consulting, and multinational enterprises. 

CISA exam schedule 2026

The CISA exam schedule 2026 follows a year-round testing model rather than fixed exam dates.Candidates can typically:

  1. Register online.



  2. Select a nearby testing center.



  3. Choose an available date.



  4. Reschedule within permitted policies if needed.



This flexible scheduling allows professionals to prepare at their own pace instead of waiting for quarterly exam windows. 

CISA practice tests: Are they worth it?

Yes—but only if they're used strategically.A strong preparation approach includes:

  • Domain-wise practice questions



  • Full-length timed mock exams



  • Performance analysis by domain



  • Reviewing explanations instead of memorizing answers



Aim to consistently score 80% or higher on realistic mock exams before attempting the actual CISA exam. 

12-week CISA study roadmap

WeekFocus
1–2Domain 1
3–4Domain 2
5Domain 3
6–8Domain 4
9–10Domain 5
11Full Practice Tests
12Revision & Weak Areas

A balanced schedule is more effective than trying to master every domain equally. Prioritize Domains 4 and 5 because together they represent 52% of the exam. 

Career opportunities after CISA

CISA opens opportunities across audit, governance, and cybersecurity.Common job roles include:

  • IT Auditor



  • Senior Information Systems Auditor



  • Internal Audit Consultant



  • Cyber Risk Analyst



  • Governance, Risk & Compliance (GRC) Specialist



  • Information Security Auditor



  • Technology Risk Consultant



  • Compliance Manager



Industries hiring CISA professionals include financial services, consulting firms, healthcare, telecommunications, government, manufacturing, and cloud service providers.

Your next move

If your goal is to build a career in IT audit, cybersecurity governance, risk, or compliance, start with the CISA syllabus 2026 and create a structured 12-week study plan. Focus on mastering the five domains, practice under timed conditions, and understand control-based thinking rather than memorizing questions. Passing the exam is only one milestone—the real value of ISACA CISA certification comes from applying audit principles to secure and improve enterprise information systems.  


CDPSE certification is ISACA’s experience-based credential for technology and privacy professionals who design, implement, and manage privacy solutions. The Certified Data Privacy Solutions Engineer (CDPSE) exam contains 120 questions across four domains: Privacy Governance, Privacy Risk Management and Compliance, Data Life Cycle Management, and Privacy Engineering. Candidates can take the exam before meeting the experience requirement, but earning the certification requires three years of relevant professional experience, passing the exam, applying to ISACA, and maintaining continuing education requirements.

What Is CDPSE Certification?

CDPSE, or Certified Data Privacy Solutions Engineer, is an ISACA certification focused on putting privacy principles into technical practice.Unlike credentials centered mainly on privacy law or policy, ISACA CDPSE certification examines how privacy requirements are translated into systems, applications, infrastructure, data processes, security controls, and technology architectures.ISACA describes the credential as validating a professional’s ability to implement privacy-by-design principles within existing and future systems, networks, and applications.That makes the certification particularly relevant to professionals working where privacy, cybersecurity, data governance, engineering, compliance, and technology overlap.Typical candidates may include:

  • Privacy engineers
  • Security engineers
  • Information security professionals
  • Data protection specialists
  • Privacy analysts
  • Compliance professionals with technical responsibilities
  • Solution and enterprise architects
  • Developers working with personal data
  • Risk professionals
  • IT managers responsible for privacy controls

The important distinction is that CDPSE is not simply about knowing what a privacy regulation says. Candidates are expected to understand how privacy requirements affect technology decisions.

CDPSE Exam Details at a Glance

The current CDPSE exam reflects the updated job practice introduced by ISACA in June 2025. The previous three-domain structure was replaced with four domains, including a dedicated Privacy Risk Management and Compliance domain and a substantially weighted Privacy Engineering domain.

CDPSE Exam DetailCurrent Information
CertificationCertified Data Privacy Solutions Engineer
VendorISACA
Exam Questions120
Exam Duration3.5 hours / 210 minutes
Passing Score450 on ISACA's 200–800 scale
Member Exam CostUS$575
Non-Member Exam CostUS$760
Application FeeUS$50
Experience Requirement3 years
DeliveryPSI test center or remote proctoring
Main Domains4

ISACA currently lists the CDPSE exam cost at US$575 for members and US$760 for non-members. Exam registration is continuous rather than restricted to fixed testing windows.ISACA uses a scaled scoring system from 200 to 800, and candidates need at least 450 to pass.

CDPSE Exam Domains and Weightings

A strong CDPSE course should be based on the current four-domain blueprint rather than older study material that still references three domains.

DomainWeight
Privacy Governance20%
Privacy Risk Management and Compliance18%
Data Life Cycle Management23%
Privacy Engineering39%

These weightings immediately reveal an important preparation strategy: Privacy Engineering represents 39% of the examination, making technical implementation the largest single area.

Domain 1: Privacy Governance — 20%

Privacy Governance includes topics such as personal information, privacy principles, privacy laws and regulations, privacy documentation, organizational responsibilities, vendor management, incident management, and data-subject rights.Candidates should understand how regulatory requirements translate into organizational controls rather than simply memorizing privacy terminology.

Domain 2: Privacy Risk Management and Compliance — 18%

This domain covers risk processes, privacy-focused assessments, privacy awareness, threats and vulnerabilities, risk responses, frameworks, evidence, monitoring, and metrics.A practical example is a Privacy Impact Assessment (PIA). You should understand not only what a PIA is but when it should be performed, which stakeholders should participate, what risks should be documented, and how findings influence system design.

Domain 3: Data Life Cycle Management — 23%

This section follows personal information from collection through eventual destruction.Candidates should understand:

  • Data inventories
  • Data-flow diagrams
  • Classification
  • Data quality
  • Use limitation
  • Data minimization
  • Data analytics
  • Storage and retention
  • Disclosure and transfer
  • Archiving
  • Secure destruction

Think beyond definitions. If customer information passes from an application to an analytics platform and then to a third-party processor, a CDPSE professional should be able to identify privacy risks throughout that flow.

Domain 4: Privacy Engineering — 39%

This is the largest CDPSE domain.It covers infrastructure, cloud platforms, endpoints, connectivity, secure development, APIs, identity and access management, encryption, monitoring, pseudonymization, anonymization, tracking technologies, privacy-enhancing technologies, and AI/ML considerations.Professionals with security, cloud, networking, architecture, or software engineering experience may recognize many technologies here, but CDPSE changes the perspective: the question becomes how those technologies protect personal information and support privacy requirements.

CDPSE Certification Requirements

One common misunderstanding is that candidates need three years of experience before they can sit the CDPSE exam.They do not.ISACA states that candidates may take the examination even if they have not yet satisfied the work-experience requirement. However, passing the exam alone does not immediately make someone CDPSE certified.To earn the designation, candidates must:

  1. Pass the CDPSE examination.
  2. Accumulate at least three years of relevant professional experience performing CDPSE-related work.
  3. Ensure qualifying experience falls within the 10 years preceding the certification application.
  4. Pay the US$50 certification application fee.
  5. Submit the certification application with experience verification.
  6. Agree to ISACA's Code of Professional Ethics.
  7. Follow ISACA's continuing professional education requirements.

Candidates have five years after passing the examination to apply for certification.This means an early-career professional can pass the exam first and complete the required experience afterward, provided the ISACA application conditions are eventually met.

CDPSE Certification Cost

When people search for CDPSE certification cost, CDPSE exam cost, or CDPSE certification ISACA cost, they often combine several expenses.The current core fees are:

  • ISACA member exam fee: US$575
  • Non-member exam fee: US$760
  • Certification application processing fee: US$50

These figures do not automatically include your CDPSE training, books, online courses, practice resources, membership fees, or other preparation expenses.Always verify current pricing directly with ISACA before registration because certification fees and policies can change.

How Difficult Is the CDPSE Exam?

CDPSE difficulty comes less from memorizing isolated facts and more from selecting the best professional response to a scenario.A question may present four technically reasonable answers, but only one may best satisfy privacy principles, business requirements, regulatory obligations, and risk management priorities simultaneously.Strong candidates therefore need three abilities:

  • Understand privacy concepts.
  • Understand the underlying technology.
  • Apply both to realistic business scenarios.

ISACA's own practice materials demonstrate this style by asking candidates to choose the BEST response to privacy and technology situations rather than simply recall definitions.

How to Prepare With CDPSE Training

Effective CDPSE training should follow the official current blueprint.A practical preparation sequence is:

  1. Download the current exam content outline.
    Confirm that your material uses the four-domain structure effective from June 2025.
  2. Assess your technical gaps.
    Privacy specialists may need additional study in encryption, IAM, cloud architecture, APIs, logging, and secure development.
  3. Assess your privacy gaps.
    Security engineers may need greater depth in consent, data-subject rights, data minimization, PIAs, retention, transparency, and privacy governance.
  4. Give Privacy Engineering additional study time.
    It represents 39% of the exam, although all four domains remain important.
  5. Practice scenario-based questions.
    Focus on why one answer is better than the alternatives.
  6. Review mistakes by concept.
    Do not simply memorize the correct option. Identify whether the error came from privacy principles, governance, risk judgment, data lifecycle knowledge, or technical implementation.

For candidates searching for CDPSE certification training, CDPSE training, or a CDPSE course, check that the provider explicitly teaches the current 2025-and-later examination outline.

Official ISACA CDPSE Study Resources

For anyone searching for ISACA CDPSE official certification preparation materials, ISACA currently provides several resources, including:

  • CDPSE Official Review Manual, 3rd Edition
  • CDPSE Online Review Course
  • Questions, Answers & Explanations Database
  • Free CDPSE practice quiz
  • Group and self-paced learning options

ISACA states that its online review course covers all four current domains, while its question database allows candidates to build customized study sessions and track progress.Third-party CDPSE certification training can supplement preparation, but candidates should cross-check technical claims, exam weightings, and policies against current ISACA information.

CDPSE Certification Maintenance

Becoming CDPSE certified also creates an ongoing professional-development obligation.ISACA requires holders to report at least:

  • 20 CPE hours each year
  • 120 CPE hours during a three-year reporting period

Qualifying CPE activities may also count toward multiple ISACA certifications when they satisfy the relevant requirements.This requirement matters when calculating the long-term commitment associated with the credential rather than looking only at the initial CDPSE certification cost.

Is CDPSE Right for Your Career?

The Certified Data Privacy Solutions Engineer CDPSE credential is most closely aligned with professionals who need to turn privacy requirements into operational technology.It can be particularly relevant when your role involves questions such as:

  • What personal information does this system collect?
  • Where does that data travel?
  • Who can access it?
  • How long should it remain stored?
  • How should consent be captured?
  • Should data be encrypted, anonymized, or pseudonymized?
  • What privacy controls should developers build into an application?
  • What happens when information is transferred to a vendor?
  • How should AI or analytics systems process personal information responsibly?

That engineering-oriented perspective separates CDPSE ISACA certification from credentials focused primarily on legal interpretation or privacy program administration.

Your Next Step Toward CDPSE Certification

Start with the current ISACA CDPSE exam blueprint and measure your knowledge against all four domains. Prioritize Privacy Engineering (39%), but do not neglect governance, risk and compliance, or data lifecycle management.Then choose CDPSE training and practice resources that teach decision-making rather than answer memorization. The exam evaluates whether you can connect privacy principles, risk, data handling, and technical controls in realistic environments.Once prepared, register through ISACA, complete the 120-question examination, achieve the required 450 scaled score, document your qualifying professional experience, and submit the certification application. That structured path takes you from exam preparation to earning the Certified Data Privacy Solutions Engineer designation.

18Sep

The ISACA AAISM Certification validates advanced expertise in AI governance, implementation, risk management, and organizational adoption.

The ISACA AAISM Certification validates advanced expertise in AI governance, implementation, risk management, and organizational adoption. The certification is designed for professionals who lead enterprise AI initiatives and need practical knowledge beyond foundational AI concepts. Candidates typically prepare through AAISM virtual training, instructor-led courses, and the official ISACA AAISM study guide. Understanding the exam fee, prerequisites, domains, and training options helps professionals choose the most effective path toward earning this globally recognized credential.

What is the ISACA AAISM Certification?

AAISM (Advanced AI Solutions Manager) is an advanced certification from ISACA focused on managing artificial intelligence across business, governance, security, compliance, and operational environments.Unlike introductory AI certifications, AAISM emphasizes how organizations deploy AI responsibly while aligning technology with business objectives. It is intended for professionals who already understand enterprise IT, cybersecurity, governance, or digital transformation.

Who should pursue AAISM?

  • AI Program Managers



  • IT Managers and Technology Leaders



  • Governance, Risk & Compliance Professionals



  • Information Security Managers



  • Digital Transformation Consultants



  • Enterprise Architects



If your role involves making strategic decisions about AI adoption, AAISM is considerably more relevant than a purely technical machine learning credential.

AAISM Certification Exam Cost

The AAISM certification exam cost depends on whether you're an ISACA member.

Candidate TypeAAISM Exam Fee
ISACA MemberUS$595
Non-MemberUS$795

Additional costs to consider

ExpenseTypical Cost
Official Review ManualVaries
Practice Questions DatabaseOptional
Virtual Training CourseProvider dependent
ISACA MembershipOptional

The ISACA AAISM cost is often lower for members because ISACA provides discounted pricing on exams and official learning resources.Tip: If you're planning multiple ISACA certifications, membership can significantly reduce overall certification expenses.

AAISM Prerequisites & Certification Requirements

One of the most common questions is whether there are mandatory eligibility requirements.

AAISM prerequisites

The ISACA AAISM prerequisites are relatively accessible:

  • No mandatory college degree



  • No compulsory programming experience



  • Professional IT or governance experience is recommended



  • Understanding of AI concepts is beneficial



This makes the certification suitable for experienced professionals transitioning into AI leadership roles.

AAISM certification requirements

To earn the AAISM certificate, candidates generally need to:

  1. Register for the AAISM exam.



  2. Complete preparation using approved learning resources.



  3. Pass the certification examination.



  4. Meet ISACA's certification policies and continuing professional education requirements after certification.



Although technical coding skills are not required, practical knowledge of enterprise AI implementation is highly valuable during the exam.

AAISM Exam Structure at a Glance

FeatureDetails
CertificationISACA AAISM
Exam FormatMultiple-choice
DeliveryTesting center / online options
Difficulty LevelAdvanced
FocusEnterprise AI management
Ideal CandidateAI & IT Leaders

The ISACA AAISM exam measures decision-making rather than programming ability. Expect scenario-based questions involving governance, ethics, implementation, and organizational strategy.

AAISM Domains You Must Master

The AAISM domains form the blueprint of the examination. Rather than memorizing terminology, successful candidates understand how these domains interact within real organizations.

1. AI Strategy & Business Alignment

Topics include:

  • AI adoption roadmaps



  • Business value realization



  • Executive stakeholder engagement



  • AI investment prioritization



2. AI Governance

This domain focuses on:

  • Responsible AI



  • Ethical frameworks



  • Regulatory compliance



  • Accountability models



3. AI Risk Management

Candidates should understand:

  • Model risk



  • Bias detection



  • Operational risk



  • Third-party AI governance



4. AI Operations & Lifecycle

Key concepts include:

  • Model deployment



  • Monitoring and performance



  • Data quality management



  • Continuous improvement



A practical understanding of these domains is more valuable than rote memorization because the exam frequently uses business scenarios.

AAISM Virtual Training vs Live Online Training

Many candidates choose between self-study and instructor-led learning.

Training TypeBest For
AAISM Virtual TrainingFlexible learners
AAISM Live Online TrainingInteractive classroom experience
Self-Paced CourseIndependent professionals
Corporate Training ProgramEnterprise teams

Benefits of AAISM live online training

  • Real-time instructor guidance



  • Interactive case discussions



  • Structured study schedule



  • Immediate doubt resolution



Benefits of AAISM virtual training

  • Learn from any location



  • Recorded sessions for revision



  • Better flexibility for working professionals



  • Suitable across different time zones



Professionals balancing full-time employment often prefer AAISM virtual training, while organizations typically select AAISM - ISACA Advanced Instructor Led Training for team upskilling.

How to Choose the Right AAISM Course

Not every AAISM course offers the same value. Evaluate providers using these criteria:

Selection FactorWhy It Matters
Official curriculum alignmentCovers current exam objectives
Experienced instructorsBetter practical insights
Practice examsImproves exam readiness
Updated study materialMatches latest domains
Student supportFaster doubt resolution

Avoid choosing a course solely because it's the cheapest. Quality practice questions and experienced instruction usually have a greater impact on passing the exam.

ISACA AAISM Study Guide: Best Preparation Strategy

A strong ISACA AAISM study guide should combine theory with practical application.

Recommended 6-week study plan

WeekFocus Area
1AI fundamentals & governance
2Business strategy & value creation
3Risk management
4AI lifecycle & operations
5Practice questions & weak areas
6Full mock exams & revision

Study resources

  • Official ISACA review manual



  • Practice question databases



  • Instructor-led virtual classes



  • Enterprise AI governance frameworks



  • Case-study based revision



Consistency matters more than marathon study sessions. Two focused hours daily generally produce better retention than occasional weekend cramming.

AAISM Review Manual PDF: Is It Enough?

Many candidates search for an AAISM review manual PDF, but relying only on a manual is rarely sufficient.A balanced preparation approach includes:

  • Official review manual



  • Practice exams



  • Scenario-based learning



  • Instructor explanations



  • Revision notes



The manual explains concepts, while practice questions develop the analytical thinking required during the actual examination.

AAISM Training Program: What Should It Include?

A complete AAISM training program should cover far more than slides.

Look for these components

  • 40+ hours of structured instruction



  • Domain-wise lessons



  • Governance case studies



  • AI ethics workshops



  • Mock examinations



  • Performance analytics



  • Instructor Q&A sessions



Programs that incorporate real enterprise scenarios generally prepare candidates better than theory-only courses.

How Difficult is the AAISM Exam?

The AAISM exam is considered advanced because it evaluates managerial judgment rather than factual recall.

Common challenges

  • Interpreting governance scenarios



  • Selecting the best business decision



  • Understanding AI risk trade-offs



  • Applying ethical AI principles



Professionals with experience in governance, cybersecurity, or enterprise IT often find the concepts familiar, while newcomers to organizational AI strategy may need additional preparation.

Career Benefits of the AAISM Certificate

The AAISM certificate demonstrates specialized capability in enterprise AI leadership.Potential career paths include:

  • AI Governance Manager



  • AI Risk Manager



  • Digital Transformation Lead



  • Enterprise AI Consultant



  • Responsible AI Program Manager



  • Technology Strategy Manager



As organizations increasingly formalize AI governance, certifications validating strategic AI management continue gaining recognition across regulated industries.

Your Next Step

If your goal is to lead enterprise AI initiatives rather than build AI models, the ISACA AAISM Certification offers a focused pathway into AI governance and strategic management. Begin by reviewing the exam domains, selecting a structured AAISM training program, and building a study plan around the official ISACA AAISM study guide before scheduling your exam.


LCCA Certification is ISACA’s senior CMMC assessor designation for experienced professionals who lead official CMMC Level 2 assessment teams and make final determinations for accredited C3PAOs. To qualify, candidates must hold active CCP and CCA credentials, pay a US$500 application fee, document required experience, hold a favorable Tier 3 determination, meet the DoD 8140.3 advanced proficiency requirement for Certified Assessor 612, and follow ISACA’s Code of Professional Ethics. LCCA maintenance currently requires a US$500 annual fee and no additional CPE.

What Is LCCA Certification?

The Lead CMMC Certified Assessor (LCCA) is the highest assessor designation in the current CMMC professional pathway administered by ISACA as the CMMC Assessor and Instructor Certification Organization, or CAICO. It is intended for experienced assessors who are ready to lead formal CMMC Level 2 assessments rather than simply participate as members of an assessment team.An LCCA is responsible for directing assessment activities, coordinating the assessment team, reviewing evidence, resolving assessment issues and supporting the final determination of whether CMMC requirements have been met. ISACA describes the LCCA as the senior assessor with final determination authority for Level 2 certification assessments conducted through accredited Certified Third-Party Assessment Organizations, or C3PAOs.That distinction matters. A CMMC Certified Assessor develops the capability to conduct Level 2 assessment activities, while the LCCA designation demonstrates readiness to take responsibility for leading the assessment itself.

LCCA vs CCA vs CCP

Professionals researching cmmc assessor certification often encounter three credentials: CCP, CCA and LCCA. They represent progressively greater responsibility within the CMMC assessment ecosystem.

CredentialPrimary RoleKey Position in the Path
CCP – CMMC Certified ProfessionalSupports assessment and CMMC-related activitiesEntry professional credential in the assessor pathway
CCA – CMMC Certified AssessorConducts formal CMMC Level 2 assessment activitiesProfessional assessor certification
LCCA – Lead CMMC Certified AssessorLeads assessment teams and oversees final assessment determinationsHighest assessor designation

ISACA states that the CCA certification enables qualified professionals to perform formal CMMC Level 2 assessments. The LCCA designation builds on that assessor experience by adding leadership, quality assurance and final determination responsibilities.This makes the typical LCCA career path:CCP → CCA → LCCAYou cannot simply skip the earlier stages and apply directly for the Lead CMMC Certified Assessor designation because active CCP and CCA credentials are part of the current LCCA eligibility requirements.

LCCA Requirements in 2026

The current LCCA requirements published by ISACA are specific. Applicants must already have progressed far enough through the CMMC assessor pathway to demonstrate both technical competence and assessment experience.To apply for the ISACA LCCA designation, candidates must:

  1. Hold an active CCP certification.
  2. Hold an active CCA certification.
  3. Pay the US$500 LCCA application processing fee.
  4. Submit an application demonstrating the required experience.
  5. Hold a favorable Tier 3 determination.
  6. Meet one advanced proficiency level for Career Pathway Certified Assessor 612 under DoD Manual 8140.3.
  7. Agree to follow ISACA’s Code of Professional Ethics.

These Lead CCA requirements show why LCCA is better understood as a senior professional designation rather than a beginner certification exam.

How to Become a Lead CMMC Assessor

For someone researching How to become a Lead CMMC Assessor, the process begins well before the LCCA application.

1. Earn the CCP Certification

CCP establishes the initial professional foundation for participating in the CMMC ecosystem. ISACA currently requires candidates seeking CCP certification to meet its education or relevant experience criteria, complete the certification process and obtain the required Tier 3 determination for full credentialing.

2. Advance to CMMC Certified Assessor

The next stage is becoming a CMMC Certified Assessor. CCA candidates must complete mandatory CAICO-approved training before taking the exam. ISACA's current CCA examination consists of 150 questions covering four domains: evaluating organizations against CMMC Level 2, assessment scoping, the CMMC Assessment Process and assessing Level 2 practices.To earn the CCA credential, candidates must also meet professional experience requirements. ISACA currently lists at least three years of cybersecurity experience and one year of assessment or audit experience, along with an active CCP and the applicable proficiency requirement.

3. Build Real Assessment Experience

The move from CCA to LCCA is not simply another theory-based certification step. The LCCA application requires applicants to demonstrate experience, which means the career progression should include meaningful exposure to assessment activities, evidence validation, CMMC scoping, interviews, findings and assessment-team operations.This is one of the most important differences between ordinary certification preparation and Lead CMMC Assessor requirements. Leadership authority depends on proven professional capability, not just passing an additional knowledge test.

4. Meet the Tier 3 and 8140.3 Requirements

Applicants must hold the required Tier 3 determination and satisfy the advanced proficiency requirement for Certified Assessor 612 under DoD Manual 8140.3 before qualifying for the LCCA designation.

5. Submit the LCCA Application

Once the prerequisites are satisfied, candidates can pay the application fee and submit the LCCA application process through ISACA.The application is used to verify that the candidate meets the designation's professional requirements.

Is There an LCCA Exam?

This is an area where certification websites can easily create confusion.ISACA's current public LCCA Certification requirements page does not list a separate LCCA certification exam as a requirement. Instead, it lists active CCP and CCA credentials, the application fee, experience verification, Tier 3 determination, the advanced 8140.3 proficiency level and professional ethics requirements.That is different from CCA, which has a defined certification exam and mandatory training requirement.Therefore, candidates searching for LCCA training or Lead CMMC Assessor training should distinguish between professional development aimed at preparing for lead-assessor responsibilities and a mandatory LCCA exam-preparation course.ISACA recognizes Accredited Training Organizations that can provide training associated with LCCA and other CMMC credentials, but its current LCCA eligibility page does not list completion of a separate LCCA course or exam as an independent designation requirement.

How Long Does It Take to Obtain LCCA Certificate?

A common query is how long does it take to obtain LCCA certificate.There is no single fixed duration published on ISACA's current LCCA designation page. The timeline depends heavily on where the professional starts.Someone who already has an active CCP, an active CCA, sufficient assessment experience, an approved Tier 3 determination and the required advanced 8140.3 proficiency level may be much closer to eligibility.A cybersecurity professional starting without those credentials has a substantially longer path because they must progress through CCP, complete required CCA training, pass the CCA exam, satisfy experience requirements, meet background and proficiency conditions, and then complete the LCCA application.For planning purposes, candidates should therefore measure their readiness against the prerequisites rather than rely on claims such as “become an LCCA in 30 days.”Also note that ISACA refers to LCCA as a designation. Searches for “LCCA certificate” or “LCCA certification” commonly refer to the same professional designation.

LCCA Certification Cost

The direct LCCA designation cost currently begins with a US$500 application processing fee.After earning the designation, holders must pay an LCCA annual maintenance fee of US$500. The current fee is the same for ISACA members and non-members and is due annually by 1 January for the upcoming calendar year.These figures should not be confused with the complete cost of progressing from a beginner to LCCA. Someone beginning earlier in the pathway may also incur costs for CCP and CCA training, examinations, applications and credential maintenance.That makes the direct LCCA cost only one part of the total investment required to become a Lead CMMC Certified Assessor.

LCCA Renewal Requirements

The current LCCA renewal requirements are unusually straightforward compared with many professional certifications.ISACA currently states that LCCA holders must pay the US$500 annual maintenance fee and comply with its Code of Professional Ethics. ISACA specifically states that there are no additional CPE requirements for LCCA itself.There is an important practical detail, however. LCCA requires active prerequisite credentials. For example, maintaining the CCA currently requires at least 20 CPE hours each year and 120 CPE hours over three years, along with the CCA maintenance fee and other requirements.So “no LCCA CPE” should not be interpreted as meaning a Lead CMMC Certified Assessor has no continuing credential obligations.

What Does an LCCA Actually Do?

The Lead CMMC Certified Assessor designation is centered on assessment leadership.An LCCA may direct CMMC Level 2 assessment activities, coordinate assessors, guide evidence analysis, resolve discrepancies, verify that the assessment follows required methodology and oversee the final determination process for an accredited C3PAO.This creates a natural professional route for experienced cybersecurity auditors, compliance professionals, CMMC assessors and assessment-practice leaders.The credential is particularly relevant to professionals seeking senior responsibilities within organizations supporting the Defense Industrial Base, including C3PAOs conducting official certification assessments.

LCCA Career Path and Professional Value

The practical value of ISACA LCCA comes from what the designation authorizes and represents rather than simply adding another acronym to a résumé.A CCA can build experience conducting CMMC assessment work. An LCCA progresses toward responsibility for directing teams, handling difficult evidence decisions, maintaining assessment quality and supporting defensible final determinations.Potential professional directions include senior CMMC assessor work, assessment-team leadership, C3PAO practice management, quality assurance, compliance leadership and mentoring less experienced assessors.The designation therefore makes the most sense for professionals committed to the CMMC assessment ecosystem rather than someone seeking a broad entry-level cybersecurity credential.

Your Next Step Toward the LCCA Designation

If your objective is to earn LCCA Certification, start by checking your current position in the credential pathway. Confirm that your CCP and CCA are active, review your documented assessment experience, verify your Tier 3 status and compare your qualifications with the Certified Assessor 612 advanced proficiency requirement.Candidates who have not yet earned CCA should focus first on approved cmmc certified assessor training, the CCA examination and the required professional experience. Those who already meet the prerequisites can move directly to reviewing the ISACA LCCA application process and current designation policy.The key is to treat LCCA as the senior stage of a professional assessment career—not as a standalone exam. That approach aligns preparation with what the designation actually validates: the ability to lead CMMC Level 2 assessments and take responsibility for accurate, defensible assessment outcomes.

17Sep

The ISACA CCOA certification (Certified Cybersecurity Operations Analyst) validates practical skills in security operations, threat detection, incident response, log analysis, and Security Operations Center (SOC) workflows.


The ISACA CCOA certification (Certified Cybersecurity Operations Analyst) validates practical skills in security operations, threat detection, incident response, log analysis, and Security Operations Center (SOC) workflows. Designed for cybersecurity analysts and blue team professionals, the CCOA exam focuses on real-world operational security rather than theoretical concepts. Candidates should understand SIEM platforms, network monitoring, endpoint detection, and incident handling. The certification helps demonstrate job-ready cybersecurity operations expertise for SOC analyst, incident responder, and security operations roles.

What Is the ISACA CCOA Certification?

The ISACA Certified Cybersecurity Operations Analyst (CCOA) is a professional cybersecurity credential that measures an individual's ability to detect, analyze, investigate, and respond to cyber threats within a Security Operations Center (SOC).Unlike governance-focused certifications, CCOA emphasizes operational cybersecurity. The exam evaluates how analysts work with security telemetry, identify malicious activity, prioritize incidents, and support continuous monitoring across enterprise environments.Organizations increasingly value analysts who can move beyond alert fatigue and make evidence-based security decisions. That practical focus is what separates the CCOA certification from many entry-level security credentials.

Who should earn CCOA?

The certification is suitable for:

  • SOC Analysts (Tier 1 & Tier 2)



  • Incident Response professionals



  • Security Operations Engineers



  • Threat Detection Analysts



  • Blue Team practitioners



  • IT professionals transitioning into cybersecurity



If your daily work involves monitoring alerts, investigating suspicious behavior, or responding to security incidents, CCOA aligns closely with those responsibilities. 

ISACA CCOA Certification at a Glance

FeatureDetails
Certification NameISACA Certified Cybersecurity Operations Analyst (CCOA)
OrganizationISACA
Focus AreaSecurity Operations & Incident Response
Exam FormatMultiple-choice, scenario-based
Skill LevelIntermediate
Primary AudienceSOC & Cybersecurity Analysts
RenewalContinuing professional education (CPE) required

The certification is designed around operational cybersecurity rather than compliance or auditing, making it particularly relevant for defensive security teams. 

Why CCOA Is Different from Other Cybersecurity Certifications

Many cybersecurity certifications concentrate on governance, penetration testing, or broad security knowledge. ISACA CCOA certification narrows its attention to day-to-day defensive operations.

CertificationPrimary FocusBest For
CCOASecurity Operations & SOCCybersecurity Analysts
CISAAudit & AssuranceIT Auditors
CISMSecurity ManagementSecurity Managers
Security+Foundational SecurityBeginners
CDPSEPrivacy EngineeringPrivacy Professionals

A SOC analyst investigating suspicious PowerShell activity, correlating firewall logs, and escalating ransomware indicators is performing the type of work reflected in the CCOA exam. 

CCOA Certification Requirements

One of the most common questions is whether prior experience is mandatory.

Recommended CCOA certification requirements

Although candidates benefit from hands-on cybersecurity experience, successful preparation generally includes:

  • Understanding of networking fundamentals



  • Familiarity with Windows and Linux systems



  • Knowledge of security monitoring concepts



  • Basic incident response workflow



  • Experience with SIEM or log analysis tools



Professionals with 1–3 years of cybersecurity operations experience typically find the exam objectives closely aligned with their daily responsibilities. 

What Topics Are Covered in the CCOA Exam?

The CCOA exam measures operational decision-making through realistic cybersecurity scenarios.

1. Security Operations Fundamentals

Core concepts include:

  • SOC architecture



  • Security monitoring



  • Asset visibility



  • Security telemetry



  • Alert prioritization



2. Threat Detection & Analysis

Candidates should understand how to identify malicious activity using:

  • Network traffic analysis



  • Endpoint telemetry



  • Log correlation



  • Indicators of Compromise (IOCs)



  • Indicators of Attack (IOAs)



3. Incident Response

This domain focuses on responding efficiently to security events.Typical workflow:

  1. Detect suspicious activity



  2. Validate the alert



  3. Investigate evidence



  4. Determine impact



  5. Contain the threat



  6. Document findings



  7. Escalate or recover



4. Log Analysis & SIEM

A significant portion of cybersecurity operations depends on interpreting machine-generated data.Expect concepts involving:

  • Windows Event Logs



  • Syslog



  • Authentication events



  • DNS logs



  • Firewall logs



  • Email security logs



Rather than memorizing log IDs, candidates should understand how multiple log sources build an investigation timeline.

5. Endpoint & Network Monitoring

Security analysts continuously evaluate endpoint behavior.Important concepts include:

  • EDR alerts



  • Malware detection



  • Privilege escalation



  • Lateral movement



  • Command-and-control traffic



 

ISACA CCOA Exam Cost

The CCOA exam cost varies depending on ISACA membership status and regional pricing.

Candidate TypeEstimated Exam Fee
ISACA MemberUS$459
Non-MemberUS$599

Additional expenses may include:

  • CCOA review manual



  • Study guides



  • Practice exams



  • Instructor-led CCOA training



  • Membership fees (optional)



Always verify current pricing before registration, as exam fees may change. 

Best CCOA Training Options

Choosing the right CCOA training depends on your learning style rather than simply selecting the longest course.

Self-paced CCOA course

Best for professionals who already work in cybersecurity.Advantages:

  • Flexible schedule



  • Lower overall cost



  • Ideal for experienced analysts



Instructor-led CCOA course

Suitable for candidates who prefer structured learning.Benefits include:

  • Live Q&A sessions



  • Lab demonstrations



  • Guided exam preparation



  • Accountability through scheduled classes



The strongest programs emphasize practical investigations instead of slide-heavy lectures. 

How to Prepare for the CCOA Exam

Passing requires more than reading theory. Focus on operational thinking.

Eight-week study roadmap

WeekFocus
1Networking & Security Fundamentals
2SOC Operations
3Log Analysis
4SIEM & Detection Rules
5Incident Response
6Endpoint Security
7Threat Hunting & Review
8Full-Length Practice Tests

Allocate consistent daily study sessions instead of marathon weekend cramming. 

CCOA Review Manual: Is It Worth Using?

The CCOA review manual serves as the official knowledge reference for exam objectives. It is especially valuable because it organizes topics according to the certification blueprint rather than general cybersecurity concepts.Use it for:

  • Understanding terminology



  • Reviewing operational workflows



  • Mapping objectives to study sessions



  • Identifying weak domains before testing



Pairing the manual with hands-on labs creates a stronger learning experience than relying on reading alone. 

CCOA Practice Test vs. CCOA Practice Questions

Many candidates treat these as the same resource—they are not.

ResourcePurpose
CCOA practice questionsReinforce individual topics
CCOA practice testSimulate full exam conditions

A good strategy is to begin with topic-specific questions and transition to timed practice exams during the final two weeks.

What makes a quality practice question?

It should require candidates to:

  • Analyze logs



  • Interpret attack behavior



  • Choose the most effective response



  • Prioritize incidents based on risk



Memorization-based questions provide limited exam value because CCOA emphasizes analytical decision-making. 

Career Opportunities After CCOA

The Certified Cybersecurity Operations Analyst credential supports several operational cybersecurity roles.

Job RolePrimary Responsibility
SOC AnalystMonitor and investigate alerts
Incident ResponderHandle active security incidents
Security Operations EngineerMaintain detection infrastructure
Threat AnalystAnalyze attacker behavior
Blue Team AnalystImprove defensive security posture

As organizations expand 24×7 security operations, professionals capable of reducing false positives and accelerating incident investigations remain in strong demand. 

Common Mistakes Candidates Make

Avoid these preparation pitfalls:

  • Studying only theory without log analysis practice



  • Ignoring incident response documentation



  • Skipping SIEM investigation workflows



  • Memorizing questions instead of understanding scenarios



  • Taking full practice tests too early without reviewing weak domains



Operational cybersecurity rewards reasoning, not rote memory.  

Your Next Step

The ISACA CCOA certification is most valuable when combined with practical SOC experience. Build a study plan around security monitoring, log analysis, incident response, and realistic CCOA practice questions rather than memorization alone. A structured CCOA course, consistent hands-on labs, and repeated CCOA practice tests provide the strongest preparation for becoming a Certified Cybersecurity Operations Analyst.


AAIA certification, officially the ISACA Advanced in AI Audit™, is an advanced credential for qualified audit and advisory professionals who assess artificial intelligence governance, risk, operations, controls, and audit processes. The AAIA exam contains 90 questions across three domains: AI Governance and Risk, AI Operations, and AI Auditing Tools and Techniques. Candidates must hold an active CISA or another approved audit-focused designation. AAIA is designed for experienced professionals rather than entry-level candidates pursuing general AI knowledge.

What Is the AAIA Certification?

The AAIA certification is ISACA's Advanced in AI Audit credential. It was created specifically for experienced auditors and advisors who need to evaluate how artificial intelligence is governed, developed, operated, controlled, monitored, and audited.Unlike a general AI Auditor Course, AAIA is not simply an introduction to artificial intelligence. The certification tests whether an audit professional can apply established assurance principles to AI-specific risks such as data quality, bias, privacy, model behavior, security, governance, lifecycle management, regulatory requirements, and automated decision-making.ISACA introduced AAIA in 2025 as an advanced, audit-specific artificial intelligence certification. The credential sits alongside other ISACA AI Certifications and AI-focused programs, including Advanced in AI Security Management and Advanced in AI Risk, but AAIA is specifically centered on audit and assurance.For organizations adopting machine learning, generative AI, automated decision systems, and AI-enabled business processes, traditional IT controls alone may not provide enough assurance. An AI audit may need to examine the model, its training or operational data, governance responsibilities, human oversight, security controls, monitoring, output reliability, regulatory compliance, and downstream business impact.That is the practical problem the ISACA AAIA credential addresses.

AAIA Certification at a Glance

AAIA DetailCurrent ISACA Information
Official nameISACA Advanced in AI Audit™ (AAIA™)
Primary focusArtificial Intelligence Audit and assurance
Exam questions90 questions
Domain 1AI Governance and Risk – 33%
Domain 2AI Operations – 46%
Domain 3AI Auditing Tools and Techniques – 21%
Member exam feeUS$459
Non-member exam feeUS$599
Certification application feeUS$50
Exam eligibility period6 months after registration
Application deadline after passingWithin 5 years
DeliveryPSI test centers; remote proctoring where permitted

The domain weights and 90-question structure come from ISACA's current AAIA Exam Content Outline. Current registration information lists a US$459 member fee and US$599 non-member fee.

Who Is Eligible for ISACA AAIA?

One of the most important differences between AAIA ISACA certification and many general AI credentials is its prerequisite requirement.AAIA is an advanced certification rather than a beginner-level AI Audit Certification.ISACA currently states that candidates must hold an active CISA or another qualifying professional designation. CISA holders qualify directly. ISACA also recognizes specified audit and accounting credentials when they have an appropriate IT audit or IT advisory focus, including credentials such as CIA, ACCA/FCCA, and qualifying CPA designations. Because ISACA has expanded this list since AAIA was launched, candidates should check the current eligibility page before registering.This prerequisite changes the nature of the exam. AAIA does not need to establish that a candidate understands basic auditing from the beginning. Instead, it builds on existing audit expertise and asks professionals to apply that expertise to AI environments.

Who Should Consider AAIA?

The certification is particularly relevant to:

  • IT auditors responsible for AI audit engagements.
  • CISA-certified professionals moving into artificial intelligence assurance.
  • Internal auditors working with AI-enabled business systems.
  • Technology risk and assurance consultants.
  • Professionals evaluating AI governance, privacy, security, and compliance.
  • Audit leaders advising management on AI adoption and control design.
  • Professionals who assess, implement, maintain, or audit AI systems.

ISACA specifically identifies experienced IT auditors, advisors, and professionals involved in evaluating or auditing AI systems as primary audiences for the credential.

What Does an AI Auditor Actually Audit?

An AI Auditor does more than verify whether an AI platform is functioning.A serious Artificial Intelligence Audit asks whether the organization's use of AI is controlled, explainable to the required degree, appropriately governed, legally compliant, secure, monitored, and aligned with business objectives.Consider an organization using an AI model to approve customer transactions. A conventional technology audit might focus heavily on user access, configuration, availability, change management, and security.An AI-focused audit must go further.The auditor may need to examine whether training and operational data are suitable, whether privacy requirements are respected, whether model outputs are monitored for unintended effects, whether management has established accountability, whether model changes are controlled, whether third-party AI providers create additional risks, and whether humans can intervene when automated decisions create unacceptable outcomes.That is why AI audit certification increasingly intersects with governance, cybersecurity, data governance, model risk, privacy, and regulatory compliance.

AAIA Exam Domains Explained

The AAIA certification exam contains 90 questions across three officially defined domains.

Domain 1: AI Governance and Risk – 33%

This domain evaluates whether an auditor can assess AI governance structures and advise stakeholders on responsible AI implementation.Topics include AI models and requirements, program governance, AI risk management, privacy, data governance, ethics, regulations, standards, and organizational policies.A strong candidate should understand that governance is not simply about creating an "AI policy." Effective governance establishes accountability for models, data, risk acceptance, oversight, monitoring, exceptions, vendors, and automated decisions.For an Artificial Intelligence Audit, the auditor may ask: Who owns the model? Who approves material changes? Who accepts AI risk? How is regulatory compliance evaluated? What happens when the model begins producing unexpected results?Those are assurance questions rather than purely technical AI questions.

Domain 2: AI Operations – 46%

At 46%, AI Operations is the largest portion of the exam.It includes AI-specific data management, solution development methodologies, lifecycle management, change management, supervision of AI outputs and decisions, testing techniques, AI threats and vulnerabilities, and incident response.This weighting provides an important preparation insight: candidates should not study AAIA as a governance-only credential.An AI Auditor must understand how AI operates through its lifecycle.Suppose an organization approves an AI model after successful testing. Six months later, the underlying business data changes significantly. The model may still technically operate while producing less reliable decisions. An auditor therefore needs to understand monitoring, data drift, model performance, change processes, control ownership, and escalation procedures.This operational perspective separates meaningful AI Audit work from checklist-based compliance reviews.

Domain 3: AI Auditing Tools and Techniques – 21%

This domain focuses directly on conducting AI-related audits and using technology to improve audit execution.ISACA's outline covers audit planning and design, testing and sampling, evidence collection, data quality, analytics, audit outputs, and reporting. It also expects professionals to understand how AI solutions can enhance audit planning, execution, and reporting.This creates two distinct capabilities.The auditor must know how to audit AI, but also how AI can be used within the audit function.For example, an audit team could use AI-assisted analytics to examine larger data populations, identify unusual transactions, classify documentation, or highlight patterns requiring human investigation. The auditor remains responsible for evaluating whether those tools produce dependable evidence and whether their use introduces additional risk.

AAIA vs General AI Auditor Course

Searching for an AI Auditor Course may produce training programs covering anything from introductory AI concepts to ISO-based AI management systems.AAIA has a more specific positioning.

AreaAAIA CertificationGeneral AI Auditor Course
Credential typeAdvanced professional certificationVaries by provider
IssuerISACAVaries
PrerequisiteQualified professional credential requiredOften none
Main emphasisAI governance, operations and auditingDepends on course
ExamFormal 90-question certification examVaries
Target levelExperienced auditors/advisorsBeginner to advanced
Audit applicationStrong emphasisVaries significantly

Someone new to auditing may benefit from foundational audit and AI education first. Professionals already holding CISA or another qualifying designation are much closer to the intended audience for ISACA AI Certification at the AAIA level.

How to Get AAIA Certified

The current certification path is straightforward:

  1. Confirm eligibility. Make sure you hold an active CISA or another currently accepted designation.
  2. Study the AAIA Exam Content Outline. Build your preparation around the 33%, 46%, and 21% domain weighting.
  3. Prepare with legitimate resources. ISACA offers an AAIA Review Manual, online review course, Questions, Answers and Explanations database, workshops and a free practice exam.
  4. Register for the AAIA exam. Registration provides a six-month eligibility window in which to take the exam.
  5. Schedule through PSI. Testing is available through authorized centers and remote proctoring where allowed.
  6. Pass the certification exam.
  7. Pay the US$50 application processing fee and apply. ISACA allows candidates five years after passing to submit their certification application.

Candidates in India, Mainland China, and Hong Kong should note that ISACA currently states the AAIA exam is available only through testing centers in those locations, not live remote proctoring.

How to Prepare for the AAIA Exam

The strongest AAIA preparation starts with the exam content outline rather than trying to memorize isolated artificial intelligence terminology.First, build enough technical AI understanding to discuss training data, models, outputs, bias, privacy, security, monitoring and lifecycle risks accurately.Next, connect every concept to an audit objective.Do not only ask, "What is model drift?" Ask, "What evidence would demonstrate that management detects, evaluates and responds to model drift?"Do not only study AI governance frameworks. Ask, "How would an auditor determine whether governance responsibilities are actually operating?"That mindset is critical because Artificial Intelligence Audit Certification preparation should develop assurance judgment rather than vocabulary recognition.ISACA's official AAIA preparation resources currently include the review manual, online review course, a database containing more than 200 practice questions, virtual workshops and a free 12-question practice exam.

Is AAIA the Same as ISACA's Other AI Certifications?

No. ISACA now has multiple AI-focused credentials aimed at different professional disciplines.AAIA is centered on artificial intelligence audit and assurance. AAISM focuses on AI security management, while AAIR focuses on AI risk. ISACA's broader AI resources also include introductory courses and certificate-level learning options.For an established auditor, this distinction matters. Choosing a credential should follow the professional responsibility you actually perform.If your work asks, "Can we independently assess whether this AI system and its controls are trustworthy?" AAIA is directly aligned with that audit responsibility.

What Makes AI Audit Different From Traditional IT Audit?

Traditional IT audit controls remain important, but AI introduces additional assurance questions.The output of a conventional deterministic system generally follows programmed rules. An AI model may produce outputs based on statistical patterns, evolving data and model behavior that cannot always be interpreted through conventional application-control testing.Auditors therefore need to evaluate issues such as training and input data, bias, model reliability, human oversight, privacy, third-party AI dependencies, lifecycle controls, monitoring, ethical requirements and organizational accountability.ISACA has highlighted this challenge, noting that AI systems can differ significantly from traditional IT systems and may introduce risks related to models and technologies that auditors need specialized knowledge to evaluate.That is where specialized AI audit expertise creates practical value.

Turn Your Existing Audit Experience Into AI Assurance Expertise

The AAIA certification is best approached as an extension of professional audit capability, not simply another AI credential to add to a résumé.Start with the official AAIA content outline. Measure your knowledge against AI Governance and Risk, AI Operations, and AI Auditing Tools and Techniques. Give additional preparation time to AI Operations because it represents 46% of the current exam, but do not treat domain percentages as permission to ignore governance or audit methodology.For professionals already qualified through CISA or another accepted audit designation, the next step is clear: strengthen the AI knowledge needed to ask better audit questions, evaluate AI controls with evidence, and communicate AI risk in terms management can act on. That is the real professional value behind ISACA AAIA.

16Sep

CISM Certification, formally Certified Information Security Manager, is ISACA’s management-focused credential for professionals who govern, design, oversee, and improve enterprise information security programs.

CISM Certification, formally Certified Information Security Manager, is ISACA’s management-focused credential for professionals who govern, design, oversee, and improve enterprise information security programs. The exam contains 150 multiple-choice questions and lasts four hours. Anyone may take the exam, but earning the certification requires five years of professional information security management experience across at least three of the four CISM domains. Current exam fees are US$575 for ISACA members and US$760 for non-members, plus a US$50 certification application fee after passing.

What Is CISM Certification?

The CISM certification full form is Certified Information Security Manager. It is issued by ISACA and focuses on managing information security at an organizational level rather than testing only technical security skills.When professionals ask, “What is CISM certification?”, the most useful distinction is that CISM evaluates whether you understand how security should support business objectives.The certification covers four core areas:

  • Information Security Governance
  • Information Security Risk Management
  • Information Security Program
  • Incident Management

These areas reflect responsibilities commonly handled by security managers, information security leaders, governance professionals, risk managers and professionals moving toward senior cybersecurity management.ISACA describes CISM as a management-focused certification for professionals involved in developing and managing enterprise information security programs.

CISM Certification Requirements

There is an important difference between CISM exam eligibility and the requirements for becoming officially CISM certified.

Can You Take the CISM Exam Without Experience?

Yes.The CISM certification exam is open to anyone interested in information security. You do not have to complete the full work-experience requirement before sitting for the examination.However, passing the exam alone does not immediately make you CISM certified.

CISM Certification Experience Requirements

To obtain the certification, ISACA currently requires:

  1. Pass the CISM exam.
  2. Have at least five years of professional information security management experience.
  3. Your experience must cover at least three of the four CISM domains.
  4. Relevant work experience must have been gained within the 10 years preceding your certification application.
  5. Submit your certification application within five years of passing the exam.
  6. Pay the US$50 application processing fee.
  7. Agree to ISACA's Code of Professional Ethics and ongoing CPE requirements.

This distinction matters when researching CISM certification prerequisites: there is no five-year experience prerequisite merely to attempt the exam, but experience is required to receive the actual certification.

CISM Certification Cost and Fees

The current CISM certification exam cost depends on your ISACA membership status.

CISM FeeISACA MemberNon-Member
CISM Exam RegistrationUS$575US$760
Certification ApplicationUS$50US$50
Annual CISM Maintenance FeeUS$45US$85

ISACA currently lists the exam at US$575 for members and US$760 for non-members. After passing, candidates pay a US$50 application processing fee when applying for certification.Once certified, professionals must also pay the annual maintenance fee. ISACA currently lists this as US$45 for members and US$85 for non-members.Training courses, review manuals, practice-question databases and other preparation resources are separate from these certification fees.

CISM Certification Exam Format

The ISACA CISM certification exam contains:

Exam DetailCurrent CISM Format
Questions150 multiple-choice questions
Exam Duration4 hours / 240 minutes
DeliveryComputer-based
Testing OptionsPSI testing center or remote proctoring
RegistrationContinuous
Main Domains4

ISACA confirms that CISM is a 150-question, four-hour examination. It may be taken through authorized PSI testing locations or remote proctoring where available.Candidates should avoid treating the CISM exam as a technical-memory test. Many questions are management-oriented and require identifying the action that best supports governance, risk ownership, business objectives or organizational priorities.

CISM Exam Domains: Important 2026 Change

Candidates preparing for CISM Certification in 2026 need to pay particular attention to their planned exam date.The current exam outline remains in effect until November 2, 2026.

CISM DomainCurrent WeightFrom Nov. 3, 2026
Information Security Governance17%18%
Information Security Risk Management20%20%
Information Security Program33%33%
Incident Management30%29%

Beginning November 3, 2026, ISACA will use its updated CISM Exam Content Outline. The four domains remain the same, but Governance increases from 17% to 18%, while Incident Management decreases from 30% to 29%.The revised content also places greater emphasis on information security strategy and program development and introduces additional coverage relating to enterprise architecture and information security architecture. Updated preparation resources became available in September 2026.Practical preparation point: if your exam is scheduled for November 3, 2026 or later, make sure your CISM training, study guide and practice questions follow the updated exam content.

What Does CISM Training Actually Cover?

Effective CISM certification training should go beyond definitions and memorization.A strong CISM course should teach candidates how to think from the perspective of an information security manager.

Information Security Governance

This area connects security strategy with enterprise objectives, organizational structures, legal requirements, frameworks, responsibilities and strategic planning.The key mindset is alignment: security decisions should support business objectives rather than operate independently of them.

Information Security Risk Management

Candidates need to understand risk assessment, threats, vulnerabilities, control deficiencies, risk response, ownership and risk reporting.One common exam mistake is immediately choosing a technical control when the question first requires risk assessment, business impact analysis or management approval.

Information Security Program

This is the largest CISM domain.It covers areas such as security resources, asset classification, standards, policies, metrics, control selection, implementation, testing, security awareness, third-party management and reporting.

Incident Management

Candidates should understand incident readiness, response planning, business impact analysis, business continuity, disaster recovery, incident classification, investigation and post-incident improvement.The CISM perspective is not simply “stop the attack.” It includes maintaining business resilience, coordinating stakeholders and improving controls based on lessons learned.

How to Get CISM Certification

For professionals searching how to get CISM certification, the pathway is straightforward:

  1. Review the applicable CISM Exam Content Outline.
  2. Select structured CISM training and study materials.
  3. Complete domain-based preparation and a CISM practice test program.
  4. Register for the ISACA CISM exam.
  5. Schedule the examination through PSI.
  6. Pass the CISM certification exam.
  7. Pay the US$50 application fee.
  8. Document and verify the required professional experience.
  9. Submit the CISM certification application within five years.
  10. Maintain the credential through CPE and annual certification requirements.

ISACA requires certified professionals to earn at least 20 CPE hours annually and at least 120 CPE hours during each three-year reporting cycle.

How to Prepare for the CISM Exam

A productive CISM certification course should combine conceptual knowledge with management-level scenario practice.Start by learning each domain rather than immediately attempting hundreds of questions. Once the concepts are clear, use CISM practice tests to learn how ISACA frames management decisions.Pay particular attention to words such as BEST, FIRST, MOST important and PRIMARY. Several answers may appear technically correct, but the examination expects the option that best fits governance and management priorities.A useful preparation cycle is:Learn → Review → Practice → Analyze mistakes → Retest.Do not measure preparation simply by the number of practice questions completed. Your ability to explain why the correct answer is stronger than the alternatives is more valuable.Candidates taking their exam after November 3, 2026 should specifically use study resources aligned with the new 2026 content outline.

CISA vs CISM Certification

The terms CISA CISM certification are sometimes searched together, but they represent different credentials.CISA, or Certified Information Systems Auditor, is centered more heavily on information systems auditing, assurance, controls and assessment.CISM, or Certified Information Security Manager, emphasizes security governance, risk management, security program management and incident management.A professional working primarily in auditing may find CISA more directly connected to current responsibilities, while information security managers and professionals responsible for security programs may encounter more direct alignment with CISM.Some professionals eventually earn both because audit assurance and security management responsibilities can overlap, but they should not be treated as interchangeable certifications.

Who Should Consider CISM Certification Training?

Certified Information Security Manager training is particularly relevant for professionals working toward responsibilities such as:

  • Information Security Manager
  • Cybersecurity Manager
  • Security Governance Manager
  • Information Security Program Manager
  • GRC Manager
  • Security Risk Manager
  • Security Consultant
  • IT Risk Manager
  • Security Operations Leader

Technical professionals can also pursue CISM when moving from implementation-focused roles into positions that require budgeting, governance, risk decisions, policy development, program management and executive communication.

Build Your CISM Preparation Around the Exam Date

Before enrolling in a CISM course or CISM training program, establish your target exam date first.Candidates testing before November 3, 2026 should prepare against the current CISM outline. Candidates testing on or after November 3, 2026 should use the updated ISACA CISM materials and domain coverage.For structured CISM certification training, exam-focused preparation, practice questions and guided study support, explore the CISM training options available through NYTCC and build your study plan around the version of the examination you will actually take.The most important preparation decision is not how many hours you study—it is whether those hours develop the management-focused judgment, risk perspective and governance mindset the CISM exam is designed to evaluate.

15Sep

PMP Certification is PMI’s globally recognized credential for experienced project professionals who can lead people, manage processes, and deliver business value across predictive, agile, and hybrid environments.

PMP Certification is PMI’s globally recognized credential for experienced project professionals who can lead people, manage processes, and deliver business value across predictive, agile, and hybrid environments. To qualify, candidates need relevant education, professional project management experience, and 35 hours of project management training or an active CAPM credential. The current exam has 180 questions, lasts 240 minutes, and tests People, Process, and Business Environment. PMP holders must earn 60 PDUs every three years to maintain certification with PMI requirements.The Project Management Professional (PMP) credential is one of the best-known professional project management certifications worldwide. Issued by the Project Management Institute (PMI), it validates more than knowledge of schedules, budgets, and project documentation. The certification is designed for professionals who can make decisions, lead teams, respond to uncertainty, work with stakeholders, and deliver measurable project outcomes.The PMP exam was updated in July 2026, making current preparation particularly important. The revised exam places more emphasis on business impact, value delivery, artificial intelligence, sustainability, stakeholder engagement, and realistic project situations.

What Is PMP Certification?

If you are asking what is PMP certification, it is a professional credential demonstrating that you have both practical project leadership experience and the knowledge required to manage modern projects.The PMP certificate is different from a general academic project management certificate. A university or training-provider certificate normally confirms that you completed a course. The PMP credential requires candidates to meet PMI eligibility standards, submit an application, pass a controlled examination, and maintain the certification through continuing professional development.A Project Management Professional PMP holder is expected to understand multiple ways of working rather than rely on a single project methodology. PMI specifically positions PMP around predictive, agile, and hybrid approaches, making the credential relevant across technology, construction, engineering, finance, healthcare, consulting, operations, government, and other industries.

PMP Certification Requirements in 2026

The current PMP certification requirements provide several eligibility pathways. Project management experience must generally have been gained during the previous 10 years, and overlapping projects cannot be double-counted.

EducationRequired Project Management Experience
High school/secondary qualification60 months / 5 years
Associate-level, advanced technical or qualifying vocational education48 months / 4 years
Bachelor’s degree or higher36 months / 3 years
Bachelor’s/postgraduate degree from a PMI GAC-accredited program24 months / 2 years

Candidates must also complete 35 hours of Project Professional training, unless an active CAPM certification fulfills the training requirement.These PMP requirements are important because PMP is not designed as an entry-level credential. You do not necessarily need the job title "Project Manager," but your experience should demonstrate responsibility for managing projects, planning work, making decisions, coordinating delivery, and contributing to project outcomes.

PMP Training Requirement: Important December 2026 Change

Anyone selecting a PMP certification course, PMP training, or PMP prep course should pay particular attention to PMI’s upcoming training rule.Currently, candidates need 35 hours of project management education or Project Professional training.Starting December 1, 2026, live instructor-led training used toward PMP eligibility must come from a PMI Authorized Training Partner (ATP), a China Registered Education Provider, or an eligible accredited academic program. PMI states that self-paced courses may continue to come from other organizations, provided they meet its requirements. Training completed before December 1, 2026 remains eligible under the current rules.That distinction matters when comparing PMP certification training, PMP training and certification programs, and PMP certification classes. Candidates should verify whether the program is intended only for exam preparation or whether it can also satisfy PMI's required education hours.

PMP Exam Format for 2026

The current PMI PMP certification exam contains 180 questions with 240 minutes of testing time. PMI also provides two 10-minute breaks.The 2026 domain weighting is:

  • People – 33%
  • Process – 41%
  • Business Environment – 26%

The exam can include single-response multiple-choice, multiple-response questions, drag-and-drop activities, case-based questions, and other scenario-driven formats. Of the 180 questions, the current Exam Content Outline identifies 170 scored questions and 10 unscored pretest questions.The shift in domain weighting is significant. Before the July 2026 update, Business Environment represented a much smaller portion of the exam. PMI increased it to 26%, reflecting the growing importance of strategic alignment, organizational value, sustainability, compliance, stakeholder needs, and business outcomes.

What Does the PMP Exam Actually Test?

Successful PMP course preparation should focus on decision-making rather than memorizing terminology.You should be comfortable deciding what a project manager should do first, next, or best when faced with situations involving:

  • Stakeholder disagreement and changing expectations
  • Team conflict and leadership challenges
  • Risk identification and response
  • Scope and requirement changes
  • Agile, predictive, and hybrid delivery
  • Schedule and cost pressures
  • Supplier and resource problems
  • Governance and compliance requirements
  • Value delivery and business outcomes
  • Artificial intelligence and emerging project practices
  • Sustainability considerations
  • Organizational change

This is where strong PMP certification online preparation differs from simple reading. A useful PMP course should train you to interpret scenarios, identify the real problem, eliminate weak answers, and choose an action consistent with responsible project leadership.

How to Get PMP Certification Step by Step

For candidates researching how to get PMP certification, the process can be simplified into six stages:

  1. Confirm your eligibility. Match your education to the appropriate experience requirement.
  2. Complete 35 training hours. Choose qualifying project management training or use an active CAPM credential where applicable.
  3. Prepare your experience records. Document projects individually and avoid double-counting overlapping periods.
  4. Submit your PMI application. Provide accurate education, training, and professional experience details.
  5. Prepare for the examination. Use the current 2026 Exam Content Outline rather than relying entirely on material created for the previous exam.
  6. Pass and maintain the credential. After earning the PMP credential, complete the required continuing-development activities.

PMI permits candidates to take the exam up to three times during the one-year eligibility period.

PMP Certification Training: What a Good Course Should Include

A serious professional project management certification preparation program should do more than provide videos or a large question bank.Look for PMP certification training that covers the current Exam Content Outline, predictive and adaptive delivery approaches, realistic scenario questions, timed practice exams, explanation of incorrect answers, exam strategy, and structured revision.Effective PMP certification classes should also help learners understand why an answer is correct. Memorizing thousands of questions without understanding the underlying project-management principle creates a major weakness when the exam presents a new scenario.A strong PMP certification course should therefore combine:

  • Concept development
  • Current 2026 exam-domain coverage
  • Scenario-based questions
  • Full-length mock exams
  • Weak-area analysis
  • Agile and hybrid project management
  • Leadership and stakeholder scenarios
  • Business Environment preparation
  • Exam-time management

PMP vs General Project Management Certification

Not every project management certification serves the same purpose.

Credential TypeMain Purpose
Course completion certificateShows completion of a training program
Entry-level project management credentialBuilds foundational knowledge
Specialized certificationFocuses on areas such as agile, risk, scheduling, or business analysis
PMP CertificationValidates experienced project leadership across industries and delivery approaches

The PMP is therefore better suited to professionals who already have qualifying experience and want a widely recognized project management professional certification rather than a basic introductory qualification.

Is PMP Certification Worth It?

For experienced professionals, PMP can add value because it provides an external validation of project leadership experience rather than simply proving course completion.PMI reports that PMP-certified professionals have 17% higher median salaries on average than non-certified counterparts across surveyed markets, while PMP-certified professionals in the United States report a median salary of $135,000. PMI also reports more than 1.7 million PMP certification holders worldwide.Actual salary and career results depend on location, industry, project size, experience, technical knowledge, leadership responsibility, and employer demand. A PMI certification should therefore be viewed as a career multiplier—not a substitute for experience.

Who Should Consider PMP Certification?

The project management professional credential can be relevant for Project Managers, Program Managers, Technical Project Managers, IT Managers, Engineers, Consultants, Construction professionals, Operations Managers, Delivery Managers, Scrum or Agile practitioners, and professionals moving into broader project leadership.It can also complement existing technical or business expertise. For example, an experienced cybersecurity professional may use PMP knowledge to improve security-program delivery, while an infrastructure specialist may apply the same framework to data-center, networking, cloud, or transformation projects.That cross-industry portability is one reason PMP remains distinct among project management certifications.

How Do You Maintain the PMP Credential?

Passing the exam does not make your PMP cert permanent without maintenance.PMI requires PMP holders to earn 60 Professional Development Units (PDUs) during each three-year certification cycle. Eligible activities can include learning, teaching, presenting, reading, volunteering, and creating relevant professional content.This continuing-development requirement helps ensure the PMP credential remains connected to current project-management practices.

Build Your PMP Preparation Around the 2026 Exam

Candidates beginning a PMP certification online journey should make one decision before purchasing training: verify that the study material reflects the July 2026 PMP exam, particularly the new 33% People, 41% Process, and 26% Business Environment weighting.Choose a PMP training and certification preparation path that develops scenario judgment rather than encouraging memorization. Confirm your eligibility, complete the required 35 training hours, document your project experience carefully, and practice under the real 180-question, 240-minute exam conditions.If you are ready to begin structured PMP certification training, explore the PMP preparation options available through NYTCC and build your study plan around the current PMI requirements and 2026 examination framework.

CRMA certification is The Institute of Internal Auditors’ specialist credential for professionals who provide assurance over risk management and governance. CRMA stands for Certification in Risk Management Assurance®. Candidates complete one 120-question, 150-minute exam covering internal audit responsibilities, risk management governance, and risk management assurance. A CIA designation is not required. Eligibility depends on education and relevant professional experience, while certification must generally be completed within two years after acceptance into the program.

What Is CRMA Certification?

If you are searching what is CRMA, the simplest CRMA definition is this: it is a professional certification focused on evaluating whether an organization identifies, manages, monitors, and communicates risk effectively.The credential is issued by The Institute of Internal Auditors (The IIA). Its full name is Certification in Risk Management Assurance (CRMA). Unlike a broad risk-management qualification, CRMA approaches risk through the assurance perspective—asking whether governance structures, controls, risk processes, reporting, and management responses actually work.The CRMA meaning becomes clearer when you look at the work involved. A professional who is Certified in Risk Management Assurance may evaluate enterprise risk frameworks, risk culture, emerging risks, strategic objectives, cybersecurity controls, risk reporting, assurance coverage, and management's response to unacceptable risk.So, what is a CRMA professional? It is typically an experienced auditor, risk specialist, compliance professional, control professional, or assurance practitioner who can independently assess how effectively an organization manages risk.

CRMA IIA Certification at a Glance

The current IIA CRMA structure is relatively straightforward:

CRMA DetailCurrent Requirement
Certification bodyThe Institute of Internal Auditors (IIA)
Exam1 exam
Number of questions120
Exam duration150 minutes
Domain 1Internal Audit Roles and Responsibilities — 20%
Domain 2Risk Management Governance — 25%
Domain 3Risk Management Assurance — 55%
CIA prerequisiteNot required
Program period2 years after approval
Current exam languageEnglish
DeliveryAuthorized Pearson VUE test center

The official syllabus assigns more than half of the examination—55%—to Risk Management Assurance, making applied risk evaluation the central focus of the CRMA exam.

CRMA Certification Requirements and Eligibility

Current CRMA certification requirements allow several routes depending on education and experience. Importantly, candidates may sit for the exam before completing all required professional experience, but both the exam and experience requirements must be completed within the program eligibility period.

CRMA Eligibility by Education

Master's degree or equivalent/higher: You need one year of relevant experience.Bachelor's degree or equivalent: You need two years of relevant experience.No qualifying university degree: Candidates with a high school diploma, associate degree, GCE, A-level, or equivalent can qualify with five years of relevant experience, with two of those years occurring within the previous three years.An active Internal Audit Practitioner (IAP) holder may also enter the program. Experience requirements can be reduced if that candidate separately holds a qualifying bachelor's or master's degree.For CRMA eligibility, relevant experience is broader than a job carrying the title "internal auditor." The IIA recognizes areas including internal audit, quality assurance, risk management, compliance, external audit, internal control, and audit/assessment disciplines.That makes the certification relevant to professionals moving from compliance, controls, enterprise risk management, or external audit into higher-level assurance roles.

What Does the CRMA Exam Cover?

The CRMA exam tests judgment and application rather than simple memorization.

1. Internal Audit Roles and Responsibilities — 20%

Candidates must understand how internal audit contributes to risk management without taking ownership of management's responsibilities. Topics include assurance and advisory work, auditor competency, organizational independence, coordination with other assurance providers, and risk assurance mapping.

2. Risk Management Governance — 25%

This area evaluates governance structures, risk and control frameworks, organizational culture, risk oversight, risk appetite, strategy, emerging risks, performance management, and integrated risk reporting.

3. Risk Management Assurance — 55%

This is the most heavily weighted domain. Candidates must evaluate risk assessment approaches, apply analytics, assess enterprise risks, prioritize risk-based audit work, evaluate remediation, review IT and cybersecurity controls, assess monitoring processes, and communicate significant risk concerns.This is also where CRMA strategic projects knowledge becomes relevant. The syllabus expects candidates to assess risk management, project management, and change controls throughout systems development and to connect risk decisions with organizational strategy.

CRMA Certification Cost

The current published CRMA certification cost differs for IIA members and non-members.

FeeIIA MemberNon-member
CRMA application$100$220
CRMA exam$465$610
Basic application + exam total$565$830

These prices may vary by country or local IIA institute. Taxes may also apply, and certification fees are generally non-refundable and non-transferable.When calculating the actual CRMA cost, also budget for membership if desired, a CRMA course, study resources, rescheduling if necessary, and annual certification maintenance.

CRMA Certification Online: Can You Take the Exam From Home?

You can complete CRMA training, a CRMA study guide program, and much of your CRMA exam preparation online. The examination itself, however, should not be marketed as a home-proctored CRMA certification online exam.The IIA discontinued online testing on May 27, 2025. Certification exams must now be taken through an authorized Pearson VUE test center.Candidates apply through the IIA's Certification Candidate Management System (CCMS) and, once approved, register and schedule their examination through Pearson VUE.

CRMA Study Guide and Study Material

A strong CRMA certification study guide should follow the official domain percentages instead of dividing study time equally.Because Risk Management Assurance represents 55% of the syllabus, it deserves the largest part of your preparation.The IIA offers official CRMA study guide and practice question resources. Preparation materials may cover frameworks and concepts related to COSO, ISO 31000, risk appetite and tolerance, risk culture, data analytics, enterprise risk management, governance, and the IPPF.A practical study sequence is:

  1. Read the official syllabus before buying extensive CRMA certification study material.
  2. Build strong foundations in governance, risk appetite, risk culture, and assurance roles.
  3. Spend most study time on Domain 3.
  4. Use scenario-based CRMA practice questions rather than relying only on definitions.
  5. Review why incorrect options are wrong.
  6. Practice evaluating risks from an assurance perspective rather than acting as risk owner.
  7. Finish with timed question sets to improve judgment under exam conditions.

The CRMA is designed as a self-study examination, so candidates are not required to follow one prescribed training curriculum.

A Critical Study Point: Standards and Exam Preparation

Candidates should carefully check the current CRMA syllabus before choosing a CRMA study guide.The CRMA examination framework may not change at the same time as other IIA certification programs or professional standards. For that reason, candidates should prepare according to the current CRMA exam syllabus, domain weights, and listed reference materials rather than assuming that another IIA certification syllabus uses exactly the same framework.This approach reduces the risk of spending too much time on content that is useful professionally but not directly aligned with the current CRMA exam.

Is CRMA Certification Worth It?

The answer to CRMA certification worth it depends on your role.CRMA has particularly strong alignment with professionals working in:

  • Internal audit
  • Enterprise risk management
  • Governance and controls
  • Compliance
  • Risk assurance
  • IT and cybersecurity assurance
  • Audit leadership
  • Strategic risk oversight

Its value is narrower but deeper than a general management certification. Someone working primarily in project delivery, financial accounting, cybersecurity operations, or pure risk ownership may benefit more from another credential first.For an auditor expected to provide assurance to senior management or an audit committee about the effectiveness of enterprise risk management, however, CRMA Certified in Risk Management Assurance knowledge directly matches that responsibility.The credential is especially useful for professionals who want to demonstrate deeper capability in risk assurance, governance evaluation, control effectiveness, and enterprise-level risk oversight.

How to Earn the CRMA Certification

The practical pathway is simple:

  1. Confirm your CRMA eligibility.
  2. Gather education documentation and government-issued identification.
  3. Apply through CCMS.
  4. Wait for application approval.
  5. Register for the CRMA exam.
  6. Schedule an authorized Pearson VUE test center.
  7. Complete focused CRMA exam preparation.
  8. Pass the examination.
  9. Submit and complete required experience verification.
  10. Receive the CRMA certification through The IIA.

Candidates generally have two years from acceptance into the CRMA program to complete the applicable requirements.

Make CRMA Preparation Match the Actual Job

The best CRMA preparation does more than teach definitions. Train yourself to answer questions such as: Is management's risk process effective? Is assurance coverage sufficient? Does risk reporting support decision-making? Is management accepting risk beyond the organization's tolerance?That mindset is the difference between simply memorizing CRMA study material and developing the professional judgment tested by the IIA CRMA exam.For candidates whose work already involves internal audit, governance, controls, compliance, enterprise risk, or assurance over strategic initiatives, the crma certification offers a focused route to demonstrate advanced risk assurance capability.

The AAISM certification, formally ISACA Advanced in AI Security Management, is an advanced credential for experienced security professionals who want to lead AI governance, risk management, and security controls. It is available to active CISM or CISSP holders and validates practical ability across AI governance, AI risk, and AI technologies and controls. The exam contains 90 questions, and current ISACA pricing is US$459 for members and US$599 for non-members, followed by a US$50 certification application fee after passing exam successfully.

What Is AAISM Certification?

AAISM is ISACA's specialized security-management certification for professionals responsible for securing artificial intelligence systems and managing AI-related enterprise risk.The AAISM full form is Advanced in AI Security Management. ISACA launched the credential to extend established security-management knowledge into AI-specific governance, risk, technology, controls, data security, and responsible-use issues.Unlike an entry-level AI certificate, ISACA AAISM certification is designed for established security professionals. It builds on the management knowledge represented by credentials such as CISM and CISSP.An AAISM professional may be expected to help an organization:

  • Develop AI security policies and standards.
  • Assess threats and vulnerabilities affecting AI solutions.
  • Evaluate third-party and AI supply-chain risk.
  • Define security controls for AI architectures.
  • Protect training, validation, and operational data.
  • Integrate AI risk into enterprise security programs.
  • Manage AI-related incidents and business continuity.
  • Address privacy, ethics, trust, explainability, and safety.

That management perspective is what separates AAISM ISACA from general AI courses focused mainly on prompting, machine learning, or AI development.

AAISM Certification Requirements

The most important AAISM certification requirement is straightforward:You must hold an active CISM or CISSP certification to take the AAISM exam.ISACA specifically designed AAISM as an advanced credential that supplements established security-management expertise. Candidates should also have some familiarity with assessing, implementing, or maintaining AI systems.To earn the credential, candidates must:

  1. Hold an active CISM or CISSP.
  2. Register for and pass the AAISM certification exam.
  3. Pay the US$50 application processing fee.
  4. Submit the certification application.
  5. Follow ISACA's Code of Professional Ethics.
  6. Meet ongoing Continuing Professional Education requirements.

Candidates have five years after passing the exam to apply for certification. Once certified, AAISM holders must earn and report 10 AI-focused CPE hours annually, beginning the calendar year after certification.This means professionals without CISM or CISSP should not treat AAISM as their first cybersecurity certification.

AAISM Exam Format and Key Details

The ISACA AAISM exam measures practical judgment rather than simply testing AI terminology.

AAISM Exam DetailCurrent Information
CertificationAdvanced in AI Security Management
Exam providerISACA
Number of questions90
Exam typeComputer-based
Passing score450 on ISACA's 200–800 scale
EligibilityActive CISM or CISSP
Member exam costUS$459
Non-member exam costUS$599
Certification application feeUS$50
Exam eligibility after registration6 months
Exam administratorPSI

ISACA confirms that the AAISM exam consists of 90 questions. ISACA's certification scoring model requires 450 or higher to pass.Registration is continuous. After paying the AAISM exam fee, candidates receive a six-month eligibility period and may generally schedule through PSI. Testing-center and remote-proctoring availability depends on location. ISACA currently states that candidates in India, Mainland China, and Hong Kong must take AAISM at a testing center rather than through live remote proctoring.

AAISM Syllabus and Exam Domains

Understanding the official AAISM syllabus is more useful than memorizing isolated definitions.

Domain 1: AI Governance and Program Management — 31%

This domain addresses the management structure surrounding enterprise AI.Key subjects include:

  • AI governance roles and responsibilities
  • Regulatory and industry requirements
  • AI security policies and procedures
  • AI asset and data lifecycle management
  • AI security program development
  • Business continuity
  • AI incident response

Candidates should understand how AI security requirements connect with broader enterprise governance rather than treating AI as an isolated technology project.

Domain 2: AI Risk Management — 31%

This domain evaluates the ability to identify, assess, monitor, and treat AI-related security risk.Major topics include:

  • AI risk assessments
  • Risk thresholds and treatment
  • AI threats and vulnerabilities
  • AI-specific attack exposure
  • Vendor risk
  • Third-party AI services
  • AI supply-chain management

The practical challenge is choosing the best risk response in a business context, not simply identifying every technically possible vulnerability.

Domain 3: AI Technologies and Controls — 38%

This is the largest portion of the AAISM certification exam.It covers:

  • AI security architecture and design
  • Model selection, training, and validation
  • Data-management controls
  • Privacy controls
  • Ethical and responsible AI
  • Trust and safety
  • AI security controls
  • Monitoring and detection

Because 38% of the examination comes from this domain, candidates should spend significant preparation time connecting AI architecture with security controls, data protection, monitoring, and risk treatment.

AAISM Certification Cost

The current official AAISM certification cost begins with the exam registration fee:

  • ISACA member AAISM exam cost: US$459
  • Non-member AAISM exam cost: US$599
  • Certification application fee after passing: US$50

Therefore, the minimum direct credentialing cost is approximately US$509 for members or US$649 for non-members, before optional training or study resources.Your total AAISM cost can be higher if you purchase an AAISM course, review manual, question database, workshop, or third-party AAISM certification training.Candidates should compare membership benefits before registration rather than evaluating only the headline AAISM exam fee.

AAISM Training and Online Course Options

Effective AAISM training should combine AI knowledge with security-management decision making.ISACA currently provides several official preparation options:

  • AAISM Online Review Course
  • AAISM Official Review Manual
  • Questions, Answers & Explanations Database
  • Virtual workshops
  • Free practice questions
  • ISACA member study groups

The official QAE database provides access to a pool of 200+ practice questions, while the AAISM study guide/review manual serves as the principal reference for the exam content.When evaluating an AAISM online course or AAISM training course, prioritize one that teaches why one governance, risk, or control decision is stronger than another. Question memorization alone is a weak preparation method for scenario-based security-management decisions.

How to Prepare for the AAISM Certification Exam

A practical preparation sequence is:

  1. Download the official exam content outline.
    Map your current knowledge against all three domains.
  2. Study the official AAISM material.
    Build understanding before attempting large quantities of questions.
  3. Give Domain 3 additional attention.
    AI Technologies and Controls represents 38% of the examination.
  4. Study AI risk as an enterprise problem.
    Connect technical weaknesses with governance, business impact, regulatory obligations, and risk treatment.
  5. Practice scenario-based questions.
    Learn to distinguish a technically possible answer from the best management decision.
  6. Review every incorrect answer.
    Identify whether the weakness is knowledge, interpretation, governance perspective, or exam technique.

An ISACA-published 2026 account from a successful candidate specifically emphasized repeated reading of the official manual and carefully reviewing explanations for practice questions rather than merely tracking scores.

Who Should Consider an AAISM Cert?

The AAISM cert is particularly relevant to:

  • CISOs and security leaders
  • Information security managers
  • Cybersecurity architects
  • Security consultants
  • AI governance professionals
  • Enterprise risk professionals with security responsibilities
  • Security professionals reviewing GenAI deployments
  • CISM or CISSP holders moving into AI security leadership

For example, a security manager approving an enterprise generative-AI platform must consider more than access control. They may need to assess training-data exposure, prompt injection, sensitive-data leakage, third-party model risk, model monitoring, incident response, regulatory obligations, and human oversight.That cross-functional responsibility closely reflects what ISACA Advanced in AI Security Management AAISM is intended to validate.

Is AAISM Worth It?

AAISM can be worth it for experienced CISM or CISSP holders whose responsibilities increasingly involve AI security, governance, or risk.Its strongest value is specialization. Instead of proving general cybersecurity knowledge again, it demonstrates that an established security professional can apply management principles to AI-specific threats and controls.It may be especially valuable if your organization is deploying generative AI, machine-learning systems, AI-enabled security tools, or third-party AI services.AAISM is less suitable for someone beginning a cybersecurity career or looking primarily for hands-on machine-learning engineering skills.For eligible professionals, the best next step is simple: review the official AAISM certification requirements and exam content outline, identify gaps across the three domains, then choose an AAISM certification training approach that combines structured study material, scenario practice, and real AI-security decision making.

14Sep

CFE Certification is the Certified Fraud Examiner credential awarded by the Association of Certified Fraud Examiners (ACFE).

CFE Certification is the Certified Fraud Examiner credential awarded by the Association of Certified Fraud Examiners (ACFE). It validates practical knowledge in fraud schemes, investigations, legal issues, prevention, and deterrence. Candidates must be ACFE members, meet the eligibility-point rules, pass all three CFE Exam sections, satisfy professional-experience requirements, and follow ACFE ethics standards. The credential is designed for auditors, investigators, compliance professionals, accountants, risk specialists, and others responsible for detecting, preventing, or investigating fraud across public, private, and nonprofit organizations.

What Is CFE Certification?

The CFE Certification, formally known as the Certified Fraud Examiner certification, is a professional anti-fraud credential administered by the Association of Certified Fraud Examiners (ACFE).If you are asking what is a CFE certification, the simplest answer is that it confirms a professional has demonstrated knowledge across the major disciplines involved in preventing, detecting, investigating, and deterring fraud.A Certified Fraud Examiner (CFE) may work in internal audit, external audit, compliance, investigations, forensic accounting, financial crime, corporate security, risk management, law enforcement, or fraud prevention.Unlike a credential focused only on accounting or auditing, the certified fraud examiner CFE certification combines several areas:

  • Fraud schemes and financial crimes
  • Investigative methods
  • Documentary and digital evidence
  • Interviewing and information gathering
  • Legal considerations
  • Fraud prevention and deterrence
  • Governance and fraud risk management
  • Professional ethics

This cross-functional approach is important because real fraud cases rarely remain inside one department. A procurement fraud investigation, for example, can involve accounting records, supplier relationships, employee interviews, digital evidence, internal controls, legal considerations, and management oversight.

CFE Certification Requirements

The CFE certification requirements are more detailed than simply passing an examination. ACFE identifies five core requirements for earning the credential.

RequirementCurrent ACFE Requirement
MembershipMust be an ACFE Associate Member
Eligibility to take examAt least 40 qualifying points
Eligibility for certificationAt least 50 qualifying points
ExperienceAt least 2 years of fraud-related professional experience before certification
ExaminationPass every section of the CFE Exam
EthicsFollow ACFE bylaws and Code of Professional Ethics

Eligibility Points

ACFE uses a point system based primarily on education and professional experience.A bachelor's degree or equivalent can provide 40 eligibility points. No particular academic major is required. Candidates without a bachelor's degree may use qualifying professional experience to help meet the eligibility requirements.This distinction is important:

  • 40 points can make you eligible to take the examination.
  • 50 points are required before the CFE credential can be awarded.

Certain approved professional certifications can also contribute qualifying education points, but they do not replace the fraud-related work-experience requirement.

Professional Experience

To become certified, candidates need at least two years of professional experience related directly or indirectly to fraud detection or deterrence.Relevant work can include areas such as:

  • Accounting and auditing
  • Fraud investigation
  • Proactive fraud detection
  • Loss prevention
  • Compliance
  • Fraud risk management
  • Research, teaching, or writing on fraud-related subjects

Candidates who have 40 eligibility points but have not yet completed two years of qualifying experience may still be able to take the exam. The actual credential is awarded after all certification requirements are satisfied.

CFE Exam Structure: Important 2026 Update

Anyone researching the CFE exam should check the date of the information they are reading.ACFE introduced a revised CFE Exam on June 2, 2026. Older articles may still describe the previous four-section structure. The current exam has three sections.

CFE Exam SectionQuestionsTime
Fraud Schemes and Financial Crimes1202.5 hours
Fraud Investigations and Legal Issues1202.5 hours
Fraud Prevention and Deterrence701.5 hours

Each section is taken separately and contains multiple-choice and True/False questions. The examination is closed-book and closed-notes.Candidates must correctly answer at least 75% of the questions in each section to pass.The exam can be delivered through Prometric, either remotely with live proctoring or at an eligible Prometric testing center. A valid government-issued photo ID is required.

What Does the Current CFE Exam Cover?

The 2026 exam redesign focuses on competencies used by practicing certified fraud examiners rather than treating fraud topics as isolated subjects.

Fraud Schemes and Financial Crimes

This section covers how different fraud schemes operate and how fraud professionals identify warning signs.Topics include occupational fraud, financial statement fraud, basic accounting principles, financial crimes, fraud schemes affecting individuals and organizations, and methods used to detect suspicious activity.

Fraud Investigations and Legal Issues

This section tests the practical mechanics of an investigation.Candidates should understand:

  • Investigation planning
  • Evidence collection
  • Documentary and digital evidence
  • Interview techniques
  • Data analysis
  • Asset tracing
  • Public and nonpublic information
  • Report writing
  • Rules of evidence
  • Civil and criminal legal concepts
  • Expert testimony

Fraud Prevention and Deterrence

The third section moves from investigation to prevention.It covers fraud risk, theories explaining fraudulent behavior, corporate governance, management responsibilities, auditors' roles, fraud risk assessments, prevention programs, deterrence, and professional ethics.

CFE Certification Cost

One of the most searched questions is how much does CFE certification cost?The current CFE Exam Application fee is $480, which covers the candidate's first attempt at each exam section.However, the exam fee should not be treated as the complete certified fraud examiner cost.Your total investment can include:

Cost ComponentWhat to Expect
CFE Exam Application$480
ACFE MembershipSeparate membership cost applies
Exam PreparationDepends on the preparation method selected
Retake$110 per failed section
ReschedulingAdditional fees may apply in some situations

Because ACFE membership is required and preparation products are optional, the final CFE certification cost varies between candidates.A candidate using independent study resources may spend less than someone enrolling in an instructor-led certified fraud examiner course or purchasing a full exam-preparation package.

How to Get a CFE Certification

If your question is how to become a CFE, the process can be simplified into five stages.

  1. Join the ACFE.
    Candidates must hold the appropriate ACFE membership status.
  2. Check your eligibility points.
    Confirm that your education and professional background provide enough points to apply.
  3. Prepare for the current CFE Exam.
    Study according to the three-section blueprint introduced in June 2026.
  4. Submit your CFE Exam application.
    Candidates may need documentation supporting education, professional experience, and professional recommendations.
  5. Pass all three exam sections and satisfy certification requirements.
    After the exam and eligibility requirements are verified, ACFE's Certification Committee reviews the application before awarding the credential.

That is the practical answer to both how to get a CFE certification and how to become a certified fraud examiner.

How Should You Prepare for the CFE Exam?

A good preparation strategy should be built around the current exam blueprint rather than memorizing isolated questions.ACFE identifies several preparation approaches, including self-paced exam-preparation material, instructor-led review, and independent study using the Fraud Examiners Manual.For most candidates, an effective study sequence is:

  • Review the official exam content outline first.
  • Identify your weakest section.
  • Study concepts before attempting large question banks.
  • Use practice questions to identify knowledge gaps.
  • Review why incorrect answers are wrong.
  • Practice working within the section time limits.
  • Spend extra time on unfamiliar legal, investigative, or accounting concepts.
  • Complete final revision using mixed-topic questions.

An auditor, for example, may already understand internal controls and financial statements but need more preparation in investigation law and interviewing. An investigator may have the opposite problem. Your study plan should reflect those differences.

CFE Exam Retake Rules

Candidates who do not pass a section do not normally need to repeat sections they have already passed.The current retake fee is $110 for each failed section, and candidates may have up to five attempts per section. After the third attempt, ACFE requires a waiting period before further attempts. Failure to pass within the permitted attempts can result in expiration of the candidate's eligibility and previous exam results.This makes targeted preparation important. Repeatedly attempting the exam without correcting specific weaknesses increases both cost and preparation time.

Is CFE Certification Worth It?

The value of an ACFE certification is strongest when the credential aligns with your actual responsibilities.CFE may be particularly relevant for professionals handling:

  • Internal fraud investigations
  • Forensic accounting
  • Internal audit
  • Financial crime
  • AML-related investigative work
  • Compliance investigations
  • Corporate investigations
  • Fraud analytics
  • Ethics and misconduct investigations
  • Fraud risk assessments
  • Loss prevention

The credential does not replace professional experience. Its value comes from demonstrating structured knowledge across the fraud examination discipline while complementing practical work.For someone who regularly investigates suspicious transactions, assesses fraud controls, conducts interviews, reviews evidence, or advises management about fraud risk, the certification has a clear connection to day-to-day responsibilities.

Maintaining Your Certified Fraud Examiner Certification

Passing the exam is not the final professional requirement.Active CFEs generally need 20 Continuing Professional Education (CPE) credits per compliance year. At least 10 credits must be fraud-related, and at least 2 must relate to ethics.This continuing education requirement matters because fraud methods evolve. Cyber-enabled fraud, payment fraud, synthetic identities, data manipulation, third-party schemes, and emerging technologies continually change the techniques investigators and fraud-risk professionals need to understand.

Prepare for the Current CFE Certification

The most important starting point is to use 2026-current CFE information. The exam changed significantly in June 2026, so preparation based on the old four-section structure can waste valuable study time.Confirm your eligibility, understand the CFE certification requirements, build your preparation around the current three-section blueprint, and identify the areas where your professional experience gives you an advantage—or leaves a knowledge gap.For structured CFE Certification training and exam preparation, explore the CFE Certification program and choose a study approach that matches your experience, timeline, and exam readiness.


I BUILT MY SITE FOR FREE USING