ISACA Certification Exam Process and Logistics Guide 2025
Introduction
What's the real hurdle in earning that prestigious ISACA credential? It's not mastering audit, risk, or security concepts—it's the logistics that trip up even experienced pros. This guide covers practical answers to every stage of the ISACA journey.
Core ISACA Certification Options in 2025
CISA (Certified Information Systems Auditor): Auditing, control, assurance, and security of IT systems
CISM (Certified Information Security Manager): Information security management and governance
CRISC (Certified in Risk and Information Systems Control): Enterprise risk identification and management
CGEIT (Certified in the Governance of Enterprise IT): IT governance leadership
CDPSE (Certified Data Privacy Solutions Engineer): Implementing and managing privacy solutions
All exams are computer-based, available year-round, and delivered through PSI. You have a 12-month exam eligibility window after registration.
Exam Format
CISA, CISM, CRISC, CGEIT: 150 multiple-choice questions, 4 hours
CDPSE: 120 multiple-choice questions, 3.5 hours
Scoring: 200–800 scale, with 450 as the passing score
There is no penalty for guessing, so you should answer every question.
Eligibility and Registration
Anyone can register—there is no education or employment pre-approval required just to sit for the exam.
The 12-month exam eligibility window starts at the time of payment. Fees are non-refundable and non-transferable.
Your ISACA account name must exactly match the name on your government-issued photo ID (including middle names/initials and suffixes where applicable).
Registration steps typically include:
Create or log in to your ISACA account.
Select your desired certification exam.
Pay the exam fee (member vs. non-member pricing).
Receive your authorization and schedule with PSI within the 12-month window.
Exam Logistics
Identification and Check-In
You must present a valid government-issued photo ID (e.g., passport, driver’s license, national ID card) with your name matching your ISACA profile.
Expect a security check, which may include: