CISA — Certified Information Systems Auditor
CISA is ISACA’s information systems audit certification and the global standard for IT auditors. It tests audit process, controls, governance and assurance rather than security engineering. Certification requires five years of information systems audit, control or security work experience. It is the dominant credential in Big Four IT audit practices and internal audit functions.
Last updated: 6 August 2026
The facts
| Vendor | ISACA |
|---|---|
| Level | Management |
| Format | 150 multiple-choice questions in 4 hours, scaled 200–800 with 450 to pass. Delivered at PSI centres or online-proctored. Five domains: the information systems audit process, governance and management of IT, systems acquisition and development, operations and business resilience, and protection of information assets. |
| Cost | High band, comparable to CISM. Exam registration is in US dollars with a meaningful member discount, plus an annual certification maintenance fee for the life of the credential. Official review manuals and question banks are separate purchases. Verify current pricing directly with ISACA rather than through resellers. |
| Validity / renewal | Three years, requiring 20 continuing professional education hours annually and 120 over the cycle, plus the annual maintenance fee. Non-compliance can lead to revocation. |
| Prerequisites | Five years of professional information systems auditing, control or security work experience. Substitutions and waivers exist — for example for degrees and certain teaching or accounting credentials — but they are capped. You may pass the exam first and apply later; candidates have a limited number of years from the passing date to submit the certification application with verified experience. |
Vendors revise prices, formats and eligibility. Always confirm on the vendor's own site before you pay — including against this page.
Is it worth it?
CISA proves you can evaluate whether controls exist, work and are evidenced — a distinct skill from building or breaking systems. In India it is close to mandatory for IT audit careers: Big Four assurance practices, internal audit teams at banks and NBFCs, and RBI or SEBI-driven compliance functions all recruit on it. It also travels well internationally and holds its value across decades rather than versions.
The downside
It is not a security engineering certification and will not help you get a technical role — the work it leads to is checklists, evidence, sampling and reports, which many technically-minded people find genuinely tedious. It is expensive, gated on five years of audit-shaped experience, and carries a permanent CPE and fee obligation.
Compared to
| Versus | Verdict |
|---|---|
| CISM | CISA checks that controls work; CISM builds and manages them. Auditors and assurance consultants take CISA; security programme managers take CISM. Career paths diverge early, so pick based on whether you want to review or to own the security function. |
| CISSP | CISSP is security management and architecture; CISA is audit and assurance. If your employer is an audit firm or an internal audit function, CISA is the credential that gets recognised, and CISSP will be the nice-to-have. |
| CEH | Almost unrelated. CEH is technical offensive theory; CISA is audit process. Some VAPT-adjacent audit roles in India list both, but they signal completely different competencies. |
Where we fit
We do not teach CISA and do not prepare candidates for it. Our courses are hands-on offensive and defensive security, which is a different career family from IT audit. We do not issue CISA, we are not an ISACA accredited training organisation, and we do not sell exam registrations. Amit Kumar holds CEH and CRTA, not CISA. If audit is your goal, an ISACA-focused provider or a Big Four graduate programme is the honest recommendation.
We issue no vendor certification and resell no exam vouchers. Buy from the vendor.
CISA — FAQs
Is CISA a security certification or an audit certification?
▾
How much experience does CISA need?
▾
Is CISA in demand in India?
▾
CISA ke baad hacking ki job mil sakti hai kya?
▾
Not sure if CISA is the right next step?
Free call. If the honest answer is a cheaper certification, or six more months of lab work before you pay anyone, that is what you will hear.
Call +91 75175 72000