Comprehensive practice questions and study materials from ISACA. Build confidence with adaptive learning and domain-specific analytics.
Exam Domains
Master every domain to maximize your exam score
Organizational governance, risk governance frameworks, and the three lines of defense model
IT risk identification, analysis, evaluation, and assessment techniques
Risk treatment options, control design and implementation, risk monitoring, and reporting
Enterprise architecture, IT operations, project and change management, and information security concepts
Pricing
Both certifications included with every plan
Auto-renews · Cancel anytime
No renewal · Pay once
Not sure yet? Try the app free with limited content — no credit card required.
Upgrade to Premium inside the app or web platform.
Prices shown are in USD. Actual prices may vary based on your location.
FAQ
Everything you need to know before getting started.
The CRISC exam has 150 multiple-choice questions. You have 4 hours (240 minutes) to complete the exam.
You need a scaled score of 450 out of 800 to pass the CRISC exam. ISACA uses a scaled scoring methodology consistent across CISA, CISM, and CRISC.
The CRISC exam fee is $575 USD for ISACA members and $760 USD for non-members. ISACA membership costs $135/year and provides significant exam fee savings.
CRISC covers four domains: Governance (26%), IT Risk Assessment (20%), Risk Response and Reporting (32%), and Information Technology and Security (22%).
CRISC requires a minimum of 3 years of cumulative work experience performing the tasks of a CRISC professional across at least two of the four CRISC domains, with at least one of those domains being Domain 1 (Governance) or Domain 2 (IT Risk Assessment). Unlike CISA and CISM, there are no experience substitutions or waivers.
CRISC certification requires annual maintenance. You must earn at least 20 CPE hours per year (minimum 120 over 3 years) and pay annual maintenance fees to keep your certification active.
CRISC is focused specifically on IT risk management and controls — identifying, assessing, and responding to enterprise IT risk. CISA focuses on IS auditing, and CISM focuses on information security management. Many professionals pursue CRISC after CISA or CISM to round out their risk-management credentials.
Your $575 (members) / $760 (non-members) exam fee deserves the best preparation.
Join 250,000+ professionals preparing with LearnZapp · Free · No credit card required
Take Free Diagnostic Test