How Hard Is the CISA Exam? Passing Score, Format & Domains (2026)
The Certified Information Systems Auditor (CISA) exam has a reputation for being tough — not because the questions are obscure, but because they test judgment, not recall. This guide breaks down exactly what you're facing and where candidates actually lose points.
CISA exam format at a glance
- Questions: 150 multiple-choice
- Time limit: 4 hours (240 minutes)
- Options per question: four — one key, three distractors
- Scoring: Scaled score from 200 to 800
- Passing score: 450
- Delivery: Computer-based, remote or at a test center
Two format facts worth internalising before you study anything:
There is no penalty for a wrong answer. Your score is the count of correct responses. Never leave anything blank — an eliminated-down guess is free.
Some items don't count. ISACA mixes unscored pre-test items into the paper and you cannot tell which they are. A question that felt bizarre may simply have been experimental. Do not let it rattle the next ten.
What 450 actually means
A scaled score of 450 does not mean 450 out of 800, and it is not a percentage. ISACA converts your raw score to a 200–800 scale that accounts for slight difficulty differences between exam forms, so the same raw count can scale differently across versions.
You will see specific claims online about the raw percentage this "really" equates to. ISACA does not publish a raw-to-scaled mapping, so treat every one of those numbers as speculation. The practical implication is simply that you cannot compute your way to a safe margin — you can only be consistently strong across the blueprint.
The five CISA domains (and their weights)
The exam is built directly from ISACA's job-practice blueprint. The weighting matters — over half the exam comes from just two domains:
| Domain | Weight |
|---|---|
| Information Systems Auditing Process | 18% |
| Governance and Management of IT | 18% |
| IS Acquisition, Development and Implementation | 12% |
| IS Operations and Business Resilience | 26% |
| Protection of Information Assets | 26% |
If you're short on time, Domains 4 and 5 (52% combined) are where your study hours pay off most.
What actually makes CISA hard
- It's scenario-based, not definitional. Questions rarely ask "what is X?" They ask what the IS auditor should do first — and several options are technically defensible, with only one being most appropriate.
- The "auditor mindset" is unfamiliar. Even strong technical professionals miss items because they answer as an engineer or a manager, not as an independent auditor.
- Breadth. Five domains span audit process, governance, development, operations, and asset protection — it's wide.
Reading the stem: the qualifier decides the answer
This is the skill that separates candidates who know the material from candidates who pass.
Most items hinge on a single word. Find it before you read the options:
| Qualifier | What it is asking for |
|---|---|
| BEST | The most complete or effective option. Others may be valid but inferior. |
| MOST (likely / effective / important) | The strongest single choice among several plausible ones. |
| FIRST / NEXT | Sequence. What a competent auditor does first — even if every option eventually happens. |
| GREATEST / PRIMARY | The dominant concern, driver or benefit. |
| LEAST | Inverts the logic — the weakest or lowest-priority option. |
| EXCEPT / NOT | Three options are appropriate; identify the one that is not. |
The trap is that ISACA writes distractors that are real domain concepts, wrong only relative to the qualifier. If three options look right to you, that is the item working as designed — not a sign you have missed something. Go back to the qualifier.
FIRST items deserve special care. They are asking about order, not merit. The most thorough option is frequently the wrong answer because something must precede it.
The tie-breakers ISACA rewards
When two options both look defensible, this ranked hierarchy resolves most close calls. Higher rules override lower ones.
- Life and physical safety. An absolute override wherever it appears.
- Independence and objectivity. An auditor does not review their own work, implement the control they will assess, or accept a position that creates a conflict. Segregation of duties sits here too.
- Address the dominant risk first. Rank concerns by business impact, not by technical severity.
- Governance, ownership and policy precede technical fixes. Establish who owns the risk and what policy requires before choosing a mechanism.
- Prevent beats detect beats correct; root cause beats symptom.
- Precise-capability match. The mechanism must achieve the stated objective. A control that provides integrity does not thereby provide confidentiality.
Two further habits: the most inclusive option — one that encompasses the others — is often strongest, and absolutes ("always", "never", "all") are usually wrong unless the absolute is itself the principle.
Where candidates actually lose marks
- Answering as the fixer. The scenario shows a control gap and the instinct is to select the remediation. The auditor's job is to observe, evaluate and report — implementing the fix is management's role, and choosing it breaks independence.
- Re-assessing a finding that is already established. If the scenario states a weakness has been identified, the next step is usually to report it, not to test for it again.
- Ignoring the qualifier. By far the most common. A BEST item and a FIRST item over the same scenario can have different keys.
- Even study across five domains. Domains 4 and 5 are 52% of the paper. Equal time is a losing allocation.
- Reading the options first. The options are engineered to be attractive. Form your own answer from the stem, then look.
A worked pattern
Consider an invented scenario in the shape ISACA uses: an auditor reviewing change management finds that emergency changes bypass approval and are documented retrospectively. The stem asks what the auditor should do FIRST.
Plausible options might include strengthening the approval workflow, testing a sample of emergency changes, reporting the weakness to management, and recommending automated logging.
Strengthening the workflow and recommending logging are both sensible — and both are management's decisions, not the auditor's, so rule 2 removes them. Between the remaining two, the qualifier is FIRST: before reporting, the auditor needs evidence sufficient to support the finding, so testing a sample precedes reporting. Had the stem said the weakness was already confirmed, reporting would win instead.
Notice that the deciding factor was never technical knowledge about change management. It was independence, then sequence.
How to prepare efficiently
The candidates who pass don't just grind questions — they measure where they stand and fix the gaps:
- Practice by domain so you can see which of the five is weakest, and weight your hours to the blueprint rather than evenly.
- Take full-length, timed mock exams scored on the real 200–800 scale, so "ready" means ready.
- Review your misses with spaced repetition rather than re-reading everything.
- Drill the qualifier explicitly. For every item you get wrong, say out loud what the qualifier demanded and why the runner-up loses. If you cannot articulate why the second-best option fails, you have not learned the item — you have memorised a letter.
Aim for consistent high scores across all five domains before you sit, not a single good overall average that hides a weak domain.
That's exactly how CertPrepX works: adaptive practice across all five CISA domains, blueprint-weighted mock exams, and a readiness score that tells you when you'd actually pass.
Want the full exam breakdown? See our CISA exam prep guide, or start free practice now.
Sources
Exam facts on this page were read from ISACA's own published material. Last verified 25 August 2026.
Frequently asked questions
Is the CISA exam harder than the CISM? They share the same format and 450 passing score, but most candidates find CISA broader (five domains vs. four) while CISM leans more conceptual. See CISM vs CISA.
How long should I study for CISA? Most candidates spend 8–12 weeks, depending on audit experience. Plan backwards from your exam date and study your weakest domains first.
What percentage do I need to pass CISA? There isn't one. 450 is a scaled score, and ISACA does not publish how raw scores convert to it. Any specific percentage you see quoted is an estimate, not a published figure.
Should I guess if I don't know? Yes. There is no penalty for a wrong answer, so leaving anything blank only costs you.
What happens if I fail? ISACA lets you retake the exam — up to four attempts in a rolling 12-month period, with a 30-day wait before the second attempt and 90 days before the third and fourth. A near miss isn't the end, but a readiness score helps you avoid sitting before you're ready.