Skip to main content
← Back to certifications
ISACAGRC and AuditAdvancedVendor-neutralActive

ISACA CRISC

A risk-focused credential covering IT risk identification, assessment, response, monitoring, and the design and evaluation of information-system controls.

Last verified: 2026-09-01

Overview

ISACA CRISC is an advanced, vendor-neutral certification focused on enterprise information systems risk and control. It validates the ability to support governance, identify and assess risk, design and evaluate risk responses and controls, report risk information, and understand the technology and security context in which risk decisions are made.\n\nCRISC is suited to IT risk professionals, GRC practitioners, security and controls specialists, and technology leaders who help organizations connect business objectives with practical risk management and information-system controls.

Recommended experience
The CRISC exam is open to anyone, but full certification requires at least three years of professional experience across at least two of the four CRISC domains. Candidates must satisfy ISACA's current experience requirements and apply within five years of passing the exam.
Estimated study time
100–160 hours
Target job roles
IT Risk ManagerGRC AnalystTechnology Risk ConsultantInformation Security Risk AnalystIT Controls ManagerRisk and Compliance Manager

Exam Details

ISACA CRISC Exam

Exam code
CRISC
Number of exams
1
Duration
240 minutes
Question count
150 questions
Delivery method
PSI testing center or remote-proctored exam
Price
$575 USD member / $760 USD nonmember

Skills and Domains

Governance

26%

Organizational and risk governance, policies, roles, risk appetite, enterprise risk management, resilience, and standards.

Risk Assessment

22%

Risk identification, threat and vulnerability analysis, business impact, risk scenarios, registers, and assessment methods.

Risk Response and Reporting

32%

Risk treatment, control design and testing, third-party risk, action plans, metrics, monitoring, and stakeholder reporting.

Technology and Security

20%

Technology architecture, operations, SDLC, data lifecycle, resilience, emerging technologies, security, privacy, and awareness.

Study Resources

ISACA CRISC Certification

Official resource

Documentation · Free

Official ISACA CRISC certification overview, exam, application, and credential information.

View resource

ISACA CRISC Exam Content Outline

Official resource

Official Guide · Free

Official current CRISC exam domains and job-practice outline.

View resource

Maintain CRISC Certification

Official resource

Documentation · Free

Official ISACA CPE, maintenance-fee, and renewal requirements.

View resource

Renewal

Validity period
3-year CPE reporting cycle
Renewal method
Earn at least 20 CPE hours each year and 120 CPE hours over three years, pay the annual maintenance fee, and comply with ISACA certification requirements.
Notes
Current annual maintenance fee is U.S. $45 for ISACA members and U.S. $85 for non-members.

Recommended Before

Verify with official provider.

Recommended After

Verify with official provider.

Alternatives

Verify with official provider.

Specializations

Verify with official provider.

Keep exploring on ThirdBadge

Connect this certification to its broader technology area, career roadmaps, training, and study resources.

Explore certification categories

Browse focused certification guides by technology and career domain.