Eight to sixteen weeks. That's the honest range for how long to study for CISA, and where you land in that range depends mostly on whether you've actually done audit work before — not on how much IT or security experience you bring.
I want to flag that distinction up front because it's where most candidates miscalculate. People with ten years in security infrastructure often assume they'll be on the short end of the timeline, and then they get blindsided by Domain 1 questions that have nothing to do with technology and everything to do with how an auditor thinks. More on that below.
The Quick Answer by Background
If you've spent real time doing IS audit work — internal audit, external audit, GRC, control testing — plan on 8 to 10 weeks of focused study. You already know the vocabulary and the mindset. You're filling gaps and learning ISACA's specific framing.
If you're transitioning into audit from IT operations, security engineering, or a sysadmin track, plan on 10 to 14 weeks. You'll move fast through Domains 4 and 5, but Domains 1 and 2 will be slower than you expect.
If you're early career or shifting fields entirely, 14 to 16 weeks is realistic. Sometimes longer if you're juggling the five-year experience requirement on the side.
These ranges assume 10 to 15 hours of study per week. Drop below 8 hours and you'll need to extend by a few weeks. Go above 20 and you'll plateau anyway — at some point the constraint becomes how much your brain can absorb, not how many hours you log.
What's Actually on the Exam
150 questions, four hours, scored 200-800 with a 450 pass mark. Five domains:
| Domain | Weight | What it covers |
|---|---|---|
| 1. Information Systems Auditing Process | 18% | Planning, executing, and reporting on audits |
| 2. Governance & Management of IT | 18% | IT governance, risk, alignment with business |
| 3. IS Acquisition, Development & Implementation | 12% | SDLC, project management, system implementation |
| 4. IS Operations & Business Resilience | 26% | Operations, monitoring, BCP, DR |
| 5. Protection of Information Assets | 26% | Security, IAM, encryption, incident response |
Notice that Domains 4 and 5 are 52% of the exam combined. Most study guides give every domain roughly equal coverage. Don't let yours do that. If you're tight on time, the cheapest weeks to cut are on Domain 3.
One detail worth knowing: you can sit for the exam before you have the five years of experience. ISACA gives you up to five years after passing to satisfy the requirement. Useful if you want to lock in the credential while you're building the work history.
The Thing Most Posts Don't Tell You
Here's the part I want to spend real time on, because it's where I've watched smart, technically strong people lose months.
CISA isn't a technical exam. It looks technical — there are questions about firewalls and encryption and disaster recovery — but it's testing whether you can think like an auditor. And the auditor mindset is genuinely different from how engineers and security pros usually approach problems.
A scenario I've seen play out more than once: someone with 10+ years in security ops starts CISA prep. They blow through Domains 4 and 5 in three weeks because the material is mostly familiar. They start practice questions and consistently score in the high 70s. They book the exam. They fail.
When they go back to look at what went wrong, the pattern is almost always the same. They were picking the technically optimal answer instead of the audit-appropriate answer. ISACA wants you to identify the control that addresses the risk, not the technology fix. They want you to recommend the policy before the implementation. They want you to flag the governance gap, not solve the engineering problem.
A concrete example. Question gives you a scenario: a company has weak password policies and a recent breach. What should the IS auditor recommend first? An engineer's instinct is to recommend MFA or a password manager rollout. The audit answer is almost always going to be: review the existing policy, identify the gap, recommend a policy update with management oversight, then talk implementation. The technically better answer is the wrong one because the auditor's job is to assess and recommend governance, not engineer the fix.
This is why technically strong candidates need almost as much study time as career-changers — they need to retrain a default instinct. If you're coming from a hands-on technical background, budget extra time on Domain 1 and Domain 2, even though they're "only" 18% each. They're where the mindset lives.
A pattern I've noticed: people scoring 75%+ on practice tests but consistently missing the same handful of question types are usually missing them for the same reason. They keep solving instead of auditing. If that's you, the fix isn't more questions — it's slowing down on each question and asking, "what would an auditor's first move be here?"
A Sample 12-Week Plan
This is built for someone with an IT or security background, putting in roughly 12 hours a week. Adjust the front and back if your situation differs.
Weeks 1-2. Get the lay of the land. Read the CISA Review Manual intro chapters, skim each domain at a high level, take a diagnostic so you know your real starting point. Don't memorize anything yet.
Weeks 3-5. Domain 1 and Domain 2. This is where I'd spend disproportionate time if you're coming from a non-audit background. Go slow. The audit process and governance frameworks (COBIT especially) need to feel intuitive, not memorized.
Weeks 6-7. Domain 3 (SDLC, project management). Move through this faster — the volume is lower and the concepts are familiar to most IT folks.
Weeks 8-9. Domain 4 (Operations & Business Resilience). Dense material, but if you've done ops work, much of it is review with new vocabulary. Focus on the BCP/DR sections — those generate a lot of exam questions.
Weeks 10-11. Domain 5 (Protection of Information Assets). Same logic as Domain 4 — familiar material, ISACA's framing.
Week 12. Two or three full-length practice exams. Time them. Review every wrong answer and write down why you missed it — was it a knowledge gap or a mindset gap? Those need different fixes.
If you have less than 12 hours a week available, stretch the plan to 14-16 weeks rather than compressing it. Compressing this material past 12 hours a week tends to produce shallow recall that doesn't survive the exam.
When You're Actually Ready
A few signals to watch for:
You're consistently scoring 70%+ on full-length practice exams (not on individual domain quizzes — those run easier).
You can talk through why a wrong answer is wrong, not just identify the right one.
You're not getting tripped up on the "first/best/most appropriate" question stems anymore. These are CISA's signature pattern, and they're a useful proxy: if those still feel like coin flips, you need more time.
You've finished a full 4-hour practice exam without your brain melting in hour three. CISA is a stamina test as much as a knowledge test.
If three out of four of those are true, schedule the exam. Waiting for a perfect 85% practice average usually means waiting forever.
The Cost Side
ISACA member rate for the exam is $575. Non-member is $760, and the membership itself runs $135-225, so doing the math: if you're not already a member, joining for the exam discount is a small win.
Study materials run anywhere from $200 (review manual + question database) to $800+ (boot camps, full courses, multiple question banks). Most people don't need the high end. The official ISACA review manual plus a quality question bank covers it.
Time is the bigger cost. 8-16 weeks at 10-15 hours per week works out to 80-240 hours of your life. Whether that math works depends on what CISA does for your career — for most people in audit, GRC, or security leadership tracks the ROI is real, but it's worth thinking through before you start. The next section does that.
Is CISA Worth It in 2026?
If you're already working in audit, compliance, or IT governance, CISA is almost certainly worth it in 2026. If you're not, no amount of salary data is going to change that. The people who get the most out of CISA are the ones whose day jobs already look like the exam content — so the real question isn't whether CISA is valuable, it's whether it's valuable for you.
What CISA signals
CISA has been around since 1978 and more than 200,000 people hold it. That longevity means it has settled into a specific role in the market: it's the credential hiring managers in audit and compliance expect to see. If you're applying for an IT audit manager role at a Big Four firm or a bank, you're either CISA-certified or you're explaining why you're not.
It's also portable in a way most certifications aren't. Because it's governance-focused, it travels across industries — healthcare to finance, finance to consulting, consulting to a CIO's office — without losing relevance. A cloud architecture cert doesn't mean much if you pivot to on-prem; an offensive security cert doesn't help outside offensive security. CISA is one of the few credentials where both the skills and the signal generalize.
And it tracks toward management. Audit has a built-in ladder: senior auditor, audit manager, director of audit, Chief Audit Executive. Every step up wants CISA, and past a certain level expects it. If you want to run an audit function someday, CISA is less a bonus and more a gate. (The ISACA certification path lays out where it sits relative to CISM and CRISC.)
CISA salary and who's hiring
CISA salaries sit consistently near the top of the certification leaderboards, and the reason is structural. The roles that value CISA — IT audit, risk, compliance — sit closer to finance functions than to IT. They get budgeted differently, promoted differently, and in regulated industries they're non-negotiable headcount.
Roughly where CISA holders land in 2026:
- Entry-level IS auditors and junior compliance analysts: $70K–$90K, most often in healthcare, government, and smaller financial firms.
- Mid-career senior auditors and compliance officers: $100K–$130K, with a meaningful premium (often 25–35%) in New York, San Francisco, London, or Singapore.
- IT audit managers, compliance directors, and Chief Audit Executives: $130K–$180K+. Big Four partners and senior consulting roles go well beyond that.
The industries paying most for CISA talent haven't changed much in a decade: financial services (SOX compliance work alone keeps the market hot), healthcare (HIPAA), government and defense (FedRAMP, FISMA, NIST), and the Big Four consultancies. What has shifted is tech — as SaaS companies have matured past the "move fast" phase, they've built out real compliance and audit functions, and CISA is increasingly showing up in those postings.
The caveat most "is it worth it" articles skip: if your employer doesn't have an internal audit function or a dedicated compliance team, CISA probably won't move your salary much. The credential's value depends on whether your organization is set up to reward it.
The ROI math
Upfront, plan on $1,600–$2,400 in your first year: the exam, membership, study materials, and possibly a retake — the first-attempt pass rate sits somewhere around 50–60%, depending on how ISACA slices the data. Ongoing, budget roughly $200/year for membership plus CPE costs, assuming your employer covers most training.
Against that, CISA holders in audit and compliance roles earn 15–25% more than non-certified peers doing similar work. Call it $15,000/year for a mid-career professional, conservatively. The certification pays for itself in roughly the first month of your next raise and clears six figures of additional earnings over a decade — if you land in a role where CISA is valued. Pass the exam at an employer with no audit function and you may see no immediate change. That's not CISA's fault; it's a mismatch between the credential and the job.
The experience requirement is doing more work than people realize
I mentioned above that you can sit for the exam before you have the five years. There are also waivers of up to three years for degrees and certain related certifications, so technically you can take it with one year of experience. But technically eligible and market-ready are different things.
I've seen people certify early — one year of experience, a bachelor's waiver, first-try pass — and land in a weird spot. They have the credential, their resume doesn't back it up, and hiring managers can tell. The salary bumps CISA is famous for are tied to the roles CISA unlocks, and those roles almost always want real audit experience. A CISA on a resume with two years of general IT doesn't land the $130K senior audit job. It lands interviews where you have to explain yourself. Then people start wondering whether the credential even "works." It does. They just used it before the market was ready to value it.
If you're earlier in your career, the honest move is often to take the exam, bank the pass, and let certification activate as your experience catches up — the exam result doesn't expire. Or, better in most cases, work in audit-adjacent roles for two or three years first. You'll study faster, score better, and be able to use the credential the day you pass.
When CISA isn't the move
If you're a network engineer, developer, or cloud architect and you want the security credential your manager will respect, you're looking at CISSP or Security+ territory, not CISA. CISA will teach you to audit your own work, which is a useful perspective, but it won't make you a better engineer and it won't put you on a technical career track.
If you're a security analyst aiming at SOC leadership, CISM is probably the better ISACA credential — governance-focused like CISA, but oriented around running security programs rather than running audits. The CISA vs CISM comparison covers when each one makes sense.
If you're in an unregulated tech environment — a startup, a mid-size SaaS company without SOX or HIPAA exposure, a product team whose compliance story is still "we'll figure it out" — CISA probably won't change how you're paid. It might still be personally valuable. It won't be financially valuable, at least not at your current employer.
And if you don't have at least a few years of audit-adjacent experience, I'd wait. The exam is passable without it. The career move isn't.
For the right person, though, the answer is clearly yes. CISA is one of the few certifications where the ROI math works, the role market is stable, and the credential has real signaling power. Regulation isn't going anywhere — AI governance, data privacy expansion, and tightening SOX interpretations are adding work to audit teams, not taking it away.
Where to Start
Before you commit to a 12-week plan or buy a stack of study materials, take a diagnostic and find out where you actually stand on each domain. Most candidates are wrong about their weak spots — security pros think Domain 5 will be easy and get crushed by Domain 1 framing; auditors think Domain 4 will be a slog and find it familiar.
LearnZapp has a free CISA diagnostic that takes about 20 minutes and gives you a domain-level breakdown. No signup. Use it to figure out which version of the timeline above actually applies to you, then build your plan around real gaps instead of guessed ones: free CISA diagnostic test.
It doubles as a gut check on the worth-it question. If the governance and audit framing clicks — if it feels like how you already think about work — you're in CISA's target market. If it feels alien, that's useful information too.