ISACACERTIFICATION GUIDE

CISA, CISM, CRISC, CDPSE and CGEIT certification paths

Choose CISA for audit, CISM for security management, CRISC for technology risk, CDPSE for privacy engineering, or CGEIT for enterprise IT governance. Each path connects official guidance, eight focused units, a free 30-question original diagnostic and transparent booking information.

CISA, CISM, CRISC, CDPSE OR CGEIT?

Choose the path that matches the decisions you make.

CISA develops audit judgement. CISM develops security-management judgement. CRISC develops technology-risk judgement. CDPSE develops privacy-engineering judgement. CGEIT develops enterprise-governance judgement. Every pathway uses official ISACA guidance, original learning scenarios and transparent booking information.

AUDIT PATH

CISA certification training

Study eight units across risk-based auditing, governance, delivery, operations, resilience and protection.

View CISA course →
MANAGEMENT PATH

CISM certification training

Study eight units across governance, risk ownership, security-program delivery and incident leadership.

View CISM course →
RISK PATH

CRISC certification training

Study eight units across governance, assessment, treatment, controls, reporting and technology risk.

View CRISC course →
PRIVACY PATH

CDPSE certification training

Study eight units across privacy governance, risk, data lifecycle, architecture and privacy controls.

View CDPSE course →
CISA PRACTICE

30-question audit diagnostic

Use a 45-minute timer, five-domain result, explanations and an official reference.

Start CISA diagnostic →
CISM PRACTICE

30-question management diagnostic

Use a 45-minute timer, four-domain result, explanations and the 2026 transition guidance.

Start CISM diagnostic →
CRISC PRACTICE

30-question risk diagnostic

Use a 45-minute timer, four-domain result, explanations and an official reference.

Start CRISC diagnostic →
CDPSE PRACTICE

30-question privacy diagnostic

Use a 45-minute timer, four-domain result, explanations and an official reference.

Start CDPSE diagnostic →
BOOK CISA

CISA exam booking guide

Verify pricing, exam delivery, experience and application requirements.

Review CISA booking →
BOOK CISM

CISM exam booking guide

Verify pricing, outline date, exam delivery and certification requirements.

Review CISM booking →
BOOK CRISC

CRISC exam booking guide

Verify pricing, delivery, eligibility window and certification requirements.

Review CRISC booking →
BOOK CDPSE

CDPSE exam booking guide

Verify pricing, delivery, eligibility window and certification requirements.

Review CDPSE booking →
CURRENT CISA DOMAIN WEIGHTING

Plan complete coverage across all five domains.

18%
DOMAIN 1

Information System Auditing Process

Risk-based audit planning, standards, evidence, sampling, reporting and follow-up.

Study domain →
18%
DOMAIN 2

Governance and Management of IT

Strategy alignment, policies, enterprise architecture, performance, people and third-party governance.

Study domain →
12%
DOMAIN 3

Information Systems Acquisition, Development and Implementation

Business cases, requirements, project governance, testing, migration and post-implementation review.

Study domain →
26%
DOMAIN 4

Information Systems Operations and Business Resilience

Service operations, change, incident and problem management, capacity, backup, continuity and recovery.

Study domain →
26%
DOMAIN 5

Protection of Information Assets

Identity, access, network and endpoint controls, encryption, privacy, monitoring and incident response.

Study domain →
CISM 2026 OUTLINE TRANSITION

Use the weighting tied to your exam appointment.

ISACA keeps the same four CISM domains. The left weight applies through 2 November 2026; the right weight applies from 3 November 2026.

17% → 18%
DOMAIN 1

Information Security Governance

Enterprise governance, legal and regulatory context, security strategy, architecture, business cases, roles and executive reporting.

Study domain →
20% → 20%
DOMAIN 2

Information Security Risk Management

Threat and vulnerability analysis, risk assessment, ownership, treatment, monitoring and decision-ready reporting.

Study domain →
33% → 33%
DOMAIN 3

Information Security Program

Resources, asset classification, policies, control design and testing, awareness, suppliers, metrics and program communication.

Study domain →
30% → 29%
DOMAIN 4

Incident Management

Readiness, business impact, continuity and recovery alignment, classification, investigation, containment, communication and lessons learned.

Study domain →

Verify ISACA's 3 November 2026 CISM update →

CURRENT CRISC DOMAIN WEIGHTING

Follow the complete risk decision chain.

26%
DOMAIN 1

Governance

Organizational strategy, roles, culture, policy, resilience, enterprise risk management, risk appetite, frameworks and obligations.

Study domain →
22%
DOMAIN 2

Risk Assessment

Threats, vulnerabilities, scenarios, business impact, risk registers, analysis methods, and inherent and residual risk.

Study domain →
32%
DOMAIN 3

Risk Response and Reporting

Treatment, ownership, third-party risk, control design and testing, action plans, KRIs, KCIs, KPIs and stakeholder reporting.

Study domain →
20%
DOMAIN 4

Technology and Security

Architecture, operations, SDLC, data lifecycle, resilience, emerging technology, security principles, privacy and risk awareness.

Study domain →

Verify the current CRISC outline with ISACA →

CURRENT CDPSE DOMAIN WEIGHTING

Connect privacy intent to engineered controls.

20%
DOMAIN 1

Privacy Governance

Personal information, privacy principles and obligations, policies, roles, vendor oversight, incidents and data-subject rights.

Study domain →
18%
DOMAIN 2

Privacy Risk Management and Compliance

Privacy risk processes, PIAs, awareness, threats, response, frameworks, evidence, monitoring and metrics.

Study domain →
23%
DOMAIN 3

Data Life Cycle Management

Inventory, flows, classification, quality, use limitation, analytics, minimization, disclosure, retention and destruction.

Study domain →
39%
DOMAIN 4

Privacy Engineering

Technology stacks, secure development, APIs, cloud, identity, encryption, logging, consent, de-identification, PETs and AI considerations.

Study domain →

Verify the current CDPSE outline with ISACA →

CURRENT CGEIT DOMAIN WEIGHTING

Govern value, resources and risk as one enterprise system.

40%
DOMAIN 1

Governance of Enterprise IT

Governance frameworks, structures, strategy alignment, stakeholder engagement, enterprise architecture, policies and information governance.

Study domain →
15%
DOMAIN 2

IT Resources

Sourcing, capacity, acquisition, asset lifecycles, workforce capability and accountable management of contracted services.

Study domain →
26%
DOMAIN 3

Benefits Realization

Performance oversight, change, monitoring, reporting, quality, business cases, investment governance, metrics and benefit evaluation.

Study domain →
19%
DOMAIN 4

Risk Optimization

Risk strategy, appetite, tolerance, enterprise risk alignment, assessment, response, monitoring and governance of IT-enabled exposure.

Study domain →

Verify the current CGEIT outline with ISACA →

ISACA OPTIONS

Choose a certification training path

Open a course to review its overview, full curriculum, instructor guidance, FAQs and enquiry options.

01

Certificate of Cloud Auditing Knowledge

Structured ISACA certification training with guided concepts, practical review and exam-readiness support.

View training →
02

Certified Data Privacy Solutions Engineer

Structured ISACA certification training with guided concepts, practical review and exam-readiness support.

View training →
03

Certified in the Governance of Enterprise IT

Structured ISACA certification training with guided concepts, practical review and exam-readiness support.

View training →
04

Certified Information Systems Auditor

Structured ISACA certification training with guided concepts, practical review and exam-readiness support.

View training →
05

Certified Information Security Manager

Structured ISACA certification training with guided concepts, practical review and exam-readiness support.

View training →
06

COBIT 2019 Foundation

Structured ISACA certification training with guided concepts, practical review and exam-readiness support.

View training →
07

A Business Framework for the Governance and Management of Enterprise IT

Structured ISACA certification training with guided concepts, practical review and exam-readiness support.

View training →
08

Certified in Risk and Information Systems Control

Structured ISACA certification training with guided concepts, practical review and exam-readiness support.

View training →
QUESTIONS ANSWERED

ISACA certification FAQs

Should I choose CISA, CISM, CRISC, CDPSE or CGEIT?

Choose CISA for information-systems audit and assurance, CISM for enterprise security management, CRISC for technology risk and controls, CDPSE for engineered privacy solutions, or CGEIT for enterprise IT governance, resources, benefits and risk oversight.

What changes in the CISM exam on 3 November 2026?

CISM keeps four domains. ISACA changes the weighting from 17/20/33/30 to 18/20/33/29 and refreshes coverage including security strategy, program development and architecture. Use the outline tied to your appointment date.

Can I take these ISACA exams before meeting the experience requirement?

Yes. ISACA permits candidates to take CISA, CISM, CRISC, CDPSE and CGEIT before completing the applicable certification experience requirements. Certification is a separate step with experience, ethics, application and maintenance requirements.

How much do these ISACA exams cost?

ISACA currently lists US$575 for members and US$760 for non-members for CISA, CISM, CRISC, CDPSE and CGEIT. Confirm membership, taxes, regional checkout and the final amount directly with ISACA.

Are the ITCertPath ISACA diagnostics full exams?

No. Each is a free 30-question, 45-minute diagnostic with original learning scenarios and explanations. CDPSE is a focused preview of the 120-question official pattern; the others are focused previews of their current patterns.

Does ITCertPath issue ISACA certifications?

No. ISACA controls registration, delivery, experience review, certification and maintenance. ITCertPath provides independent courses, original practice and booking guidance.