CISA vs CRISC

The published facts of both certifications side by side. Which one fits depends on your role, experience and goals; the Plan Advisor and Role readiness weigh them against your own profile.

CISA
ISACA Certified Information Systems Auditor
CRISC
ISACA Certified in Risk and Information Systems Control
IssuerISACAISACA
LevelIntermediateIntermediate
DomainSecurity Assessment & TestingSecurity & Risk Management
Exam fee$760$760
Experience required5 years3 years
Prerequisite certificationsNoneNone
Exam150 questions, 4 hours150 questions, 4 hours
Passing score450/800450/800
RenewalEvery 3 years · 120 CPE per cycleEvery 3 years · 120 CPE per cycle
Annual fee$85$85
Career tracks that use it34

Fees and requirements change: each certification's page links to the issuer's own terms. CertAscent lists them side by side; no issuer pays to be listed or compared.