1.1 About the CRISC Exam

Key Takeaways

  • The ISACA CRISC exam consists of 150 multiple-choice questions administered over a 4-hour (240-minute) testing session, providing approximately 96 seconds per item.
  • Scoring is evaluated on a 200 to 800 scaled range, with a minimum passing standard of 450 established through psychometric equating.
  • The exam blueprint spans four weighted domains: Governance (26%), Risk Assessment (22%), Risk Response and Reporting (32%), and Technology and Security (20%).
  • Full certification requires passing the exam and verifying at least three (3) years of cumulative work experience across at least two domains (with at least one year in Domain 1 or Domain 2) within a 5-year post-exam window.
  • Credential maintenance mandates earning a minimum of 20 CPE hours annually (120 CPEs triennially), remitting annual maintenance fees, and adhering to the ISACA Code of Professional Ethics.
Last updated: August 2026

1.1 About the CRISC Exam

The Certified in Risk and Information Systems Control (CRISC) designation, established in 2010 by ISACA (Information Systems Audit and Control Association), is globally recognized as the premier professional certification for practitioners who design, implement, monitor, and manage enterprise IT risk management programs and information systems controls.

Accredited by the ANSI National Accreditation Board (ANAB) under ISO/IEC 17024:2012 (Conformity assessment — General requirements for bodies operating certification of persons), the CRISC credential demonstrates that a professional possesses the multidisciplinary knowledge required to align information technology risk strategy with overarching enterprise business objectives, establish defensible governance frameworks, and bridge communication barriers between technical security teams and executive leadership.


1. Exam Structure & Delivery Parameters

The CRISC examination is an intensive, closed-book assessment designed to evaluate both theoretical governance acumen and practical, scenario-based decision-making.

+-----------------------------------------------------------------------------+
|                        CRISC EXAM SPECIFICATION SUMMARY                     |
|                                                                             |
|   Total Questions:     150 Multiple-Choice Questions (Single Best Answer)   |
|   Testing Time:        4 Hours (240 Minutes) = ~96 Seconds per Question     |
|   Scoring Scale:       200 to 800 Scaled Score Range                        |
|   Passing Standard:    450 Scaled Score (Criterion-Referenced Standard)     |
|   Delivery Modalities: In-Person CBT (PSI Centers) OR Online Remote Proctor |
|   Exam Language:       English (and localized language offerings)          |
|   Exam Nature:         Strictly Closed-Book / Scenario-Heavy                |
+-----------------------------------------------------------------------------+

Key Exam Delivery Dimensions

  • Item Format: All 150 questions are multiple-choice items featuring four possible options and a single best answer. Questions frequently present complex organizational scenarios requiring candidates to assume the role of an enterprise risk leader, CISO advisor, or IT governance director.
  • Time Allocation: With 240 minutes allotted for 150 items, candidates have exactly 1.6 minutes (96 seconds) per question. Maintaining disciplined pacing is critical, as lengthy scenario stems require rapid reading comprehension and structured elimination.
  • Scaled Scoring Methodology: Raw scores (the number of correctly answered questions) are mathematically transformed into a scaled score ranging from 200 to 800 points. ISACA establishes a passing threshold of 450, representing the minimum standard of knowledge determined by psychometric standard-setting committees. Because questions vary in psychometric difficulty, raw-to-scaled conversion ensures fairness across different examination forms.
  • No Negative Marking: ISACA does not penalize incorrect responses. A candidate's score is based entirely on the number of correct selections. Consequently, leaving questions blank is never strategically advisable.

[!NOTE] Computer-Based Testing (CBT) Options: Candidates can register for the exam year-round through ISACA and schedule testing via PSI testing centers globally or via PSI remote online proctoring from a private, secure location with an active webcam and microphone.


2. The Four Weighted Blueprint Domains

The CRISC job practice outline is divided into four interconnected domains, formulated through extensive global Job Practice Analyses (JPA) of enterprise risk professionals.

+-----------------------------------------------------------------------------+
|                     CRISC BLUEPRINT DOMAIN DISTRIBUTION                    |
|                                                                             |
|   [DOM 1] Governance                                (26%)  ---> ~39 Items   |
|   [DOM 2] Risk Assessment                           (22%)  ---> ~33 Items   |
|   [DOM 3] Risk Response and Reporting               (32%)  ---> ~48 Items   |
|   [DOM 4] Technology and Security                   (20%)  ---> ~30 Items   |
|                                                                             |
|   *Total Exam Questions: 150 Multiple-Choice Items                          |
+-----------------------------------------------------------------------------+

Detailed Domain Breakdown & Competency Scope

DomainWeightApprox. ItemsPrimary Competency Areas & Evaluated Concepts
Domain 1: Governance26%~39Enterprise IT governance frameworks (COBIT, ISO 38500); organizational structures and the Three Lines Model; risk strategy alignment with business objectives; risk culture, ethics, and tone at the top; risk appetite, tolerance, and capacity; policies, standards, guidelines, and procedures architecture; data ownership vs. custodianship; legal, regulatory, and contractual compliance mandates.
Domain 2: Risk Assessment22%~33Risk identification methodologies (Delphi technique, workshops, interviews); threat landscape analysis, threat actors, and attack vectors; vulnerability assessments and exposure analysis; risk scenario development (STRIDE, MITRE ATT&CK); qualitative, semi-quantitative, and quantitative risk analysis (FAIR, Single Loss Expectancy, Annualized Rate of Occurrence, Annualized Loss Expectancy); risk registers, risk aggregation, and Business Impact Analysis (BIA) integration.
Domain 3: Risk Response & Reporting32%~48Risk treatment options (mitigation, transfer, avoidance, acceptance); cost-benefit analysis and Return on Security Investment (ROSI); control design principles (preventive, detective, corrective, compensating); control testing, evaluation, and deficiency remediation; Third-Party Risk Management (TPRM), vendor contracts, and cloud shared responsibility; Key Risk Indicators (KRIs), thresholds, triggers, and executive stakeholder reporting.
Domain 4: Technology and Security20%~30Enterprise architecture (TOGAF, SABSA) and IT operations governance; virtualization and cloud computing architectures; systems resilience, high availability, and disaster recovery; information security principles and the CIA Triad; Identity and Access Management (IAM), Privileged Access Management (PAM), and Role-Based Access Control (RBAC); cryptography and key management; Secure Software Development Lifecycle (SSDLC) and DevSecOps; incident response management and business continuity testing; emerging technologies risk (AI/ML, quantum computing, IoT/OT).

[!IMPORTANT] The Heavyweight Domains: Notice that Domain 1 (Governance) and Domain 3 (Risk Response & Reporting) together account for 58% of the examination (~87 questions). Achieving mastery in governance principles, risk response strategies, control selection, and KRI reporting is non-negotiable for passing.

[!NOTE] Domain Names in Older Study Materials: ISACA's current CRISC Exam Content Outline titles Domain 2 Risk Assessment and Domain 4 Technology and Security. Older textbooks, courseware, and third-party summaries still print the earlier titles IT Risk Assessment and Information Technology and Security, and some also print the earlier 20%/22% split for those two domains. The domains cover the same subject matter — always confirm the weights against the outline published on isaca.org rather than a secondary summary.


3. Experience Requirements & Certification Pathway

Passing the CRISC examination is an essential milestone, but full certification requires satisfying ISACA's professional experience and ethical standards.

+-----------------------------------------------------------------------------+
|                        CRISC CERTIFICATION TIMELINE                         |
|                                                                             |
|   [STAGE 1: EXAMINATION]                                                    |
|   Pass the 150-Question CRISC Exam (Score >= 450)                           |
|                            |                                                |
|                            v                                                |
|   [STAGE 2: APPLICATION WINDOW (5-YEAR CLOCK)]                              |
|   Accumulate / Verify 3 Years of Qualifying Work Experience                 |
|   - Across at least TWO (2) CRISC Domains                                   |
|   - Minimum 1 Year in Domain 1 (Governance) OR Domain 2 (Risk Assessment)   |
|   - Verified by Supervisor, Colleague, or ISACA Member                      |
|                            |                                                |
|                            v                                                |
|   [STAGE 3: APPLICATION SUBMISSION]                                         |
|   Submit Formal Application + $50 Processing Fee + Code of Ethics Sign-off  |
|                            |                                                |
|                            v                                                |
|   [STAGE 4: CREDENTIAL ISSUANCE]                                            |
|   Receive Official CRISC Credential & Digital Badge                         |
+-----------------------------------------------------------------------------+

Professional Experience Rules

  • 3-Year Minimum: Candidates must possess a minimum of three (3) years of cumulative professional experience in IT risk management and information systems control.
  • Domain Breadth Requirement: Experience must span across at least two (2) of the four CRISC domains.
  • Core Domain Prerequisite: At least one (1) year of the required experience must be specifically in Domain 1 (Governance) or Domain 2 (Risk Assessment).
  • No General Degree Substitutions: Unlike ISACA's CISA or CISM credentials, which allow undergraduate/master's degrees or allied certifications to waive portions of the experience requirement, the CRISC program does not grant general educational waivers in place of the 3-year hands-on experience requirement.
  • 5-Year Post-Exam Window: Candidates have up to five (5) years from the date of passing the examination to submit their verified application for certification.

4. Continuing Professional Education (CPE) & Maintenance Policy

To ensure that certified practitioners maintain currency in a rapidly evolving threat and regulatory landscape, ISACA enforces a mandatory Continuing Professional Education (CPE) policy.

+-----------------------------------------------------------------------------+
|                     3-YEAR CRISC CPE MAINTENANCE CYCLE                      |
|                                                                             |
|     YEAR 1                       YEAR 2                       YEAR 3        |
|   +-----------------------+    +-----------------------+    +---------------+|
|   | - Min 20 CPE Hours    |    | - Min 20 CPE Hours    |    | - Min 20 CPE  ||
|   | - Pay Annual Fee (AMF)| -> | - Pay Annual Fee (AMF)| -> | - Pay AMF     ||
|   | - Comply with Ethics  |    | - Comply with Ethics  |    | - Reach 120   ||
|   +-----------------------+    +-----------------------+    +---------------+|
|                                                                     |        |
|                           TOTAL: Minimum 120 CPE Hours ------------> v        |
|                                                       [3-YEAR RENEWAL]      |
+-----------------------------------------------------------------------------+

Core Maintenance Mandates

  1. Annual Minimum: Earn and report a minimum of 20 qualifying CPE hours per calendar year.
  2. Triennial Minimum: Earn and report a minimum of 120 qualifying CPE hours across the fixed three-year reporting cycle.
  3. Annual Maintenance Fee (AMF): Remit the annual maintenance fee to ISACA ($45 for ISACA members, $85 for non-members).
  4. Code of Professional Ethics: Continuously adhere to the ISACA Code of Professional Ethics, which requires maintaining personal integrity, protecting information confidentiality, performing duties with professional competence and due care, and disclosing conflicts of interest.
  5. Audit Trail Maintenance: Retain physical or electronic documentation supporting all reported CPE activities for at least 12 months following the end of each three-year reporting cycle. ISACA conducts random annual audits of certified individuals.
Test Your Knowledge

A candidate is evaluating the eligibility and experience verification criteria for the ISACA CRISC designation. Which requirement must be satisfied to earn and receive full certification?

A
B
C
D
Test Your Knowledge

An IT risk practitioner is analyzing the domain weightings of the CRISC examination blueprint to optimize study time. Which domain represents the largest percentage of the examination content?

A
B
C
D
Test Your Knowledge

Which statement accurately describes the psychometric structure, timing, and scoring mechanics of the ISACA CRISC examination?

A
B
C
D
Test Your Knowledge

To maintain the CRISC credential in good standing over the three-year certification cycle, what Continuing Professional Education (CPE) and compliance requirements must a certified professional fulfill?

A
B
C
D