CISA CPE Requirements: Maintaining Your Certification
Everything you need to know about CISA continuing professional education requirements, including CPE hours, reporting, and qualifying activities.
Earning your CISA certification is an achievement, but maintaining it requires ongoing commitment to professional development through continuing professional education (CPE). Understanding CPE requirements ensures your certification remains active and in good standing.
CPE Hour Requirements
CISA holders must earn a minimum of 20 CPE hours annually and at least 120 CPE hours over each three-year certification period. These hours must be in activities related to information systems auditing, control, security, or other relevant professional domains.
Annual vs. Three-Year Requirements
The annual minimum of 20 hours ensures continuous learning, while the 120-hour three-year total allows flexibility in how you distribute your learning across the period. Many professionals aim for 40 hours per year to stay well ahead of requirements.
Qualifying CPE Activities
ISACA accepts a wide range of activities for CPE credit. Understanding which activities qualify helps you plan your professional development effectively.
- ISACA conferences, seminars, and chapter events
- University or college courses in relevant subjects
- Self-study courses and online training programs
- Publishing articles or books on IS audit topics
- Teaching or lecturing on relevant subjects
- Participating in ISACA volunteer activities
- Vendor training sessions related to audit tools and technologies
- Professional mentoring in the IS audit field
CPE Hour Calculations
One CPE hour equals 50 minutes of active learning. For university courses, each semester hour typically equates to 45 CPE hours, while quarter hours convert to 30 CPE hours. Self-study activities are generally credited at the actual time spent.
Reporting and Documentation
You must report CPE hours through the ISACA website by the annual deadline, which is January 15 of each year for the prior reporting period. Maintain documentation for all claimed CPE activities, as ISACA may audit your submissions. Keep records for at least one year beyond the end of your certification period.
Documentation Best Practices
- Save certificates of completion for all courses and seminars
- Keep attendance records for conferences and chapter meetings
- Document self-study activities with dates, topics, and time spent
- Retain copies of published articles or presentation materials
- Store all records in a dedicated digital folder for easy retrieval
Annual Maintenance Fee
In addition to CPE requirements, CISA holders must pay an annual maintenance fee. The fee is reduced for ISACA members, providing an additional incentive for maintaining membership alongside certification.
What Happens If You Fall Behind
If you fail to meet CPE requirements or pay the maintenance fee, your certification may be suspended or revoked. ISACA provides a grace period and remediation options in some cases, but prevention through careful planning is far preferable to remediation.
Strategies for Earning CPE Hours
Many professionals find it helpful to create an annual CPE plan at the beginning of each year. Join your local ISACA chapter for regular learning opportunities. Subscribe to relevant journals and publications. Attend at least one major conference per year. These strategies make meeting CPE requirements a natural part of professional growth rather than a burdensome obligation.
By staying proactive with your CPE requirements, you demonstrate ongoing commitment to professional excellence and ensure your CISA certification remains a valuable career asset.