9 min read

CISA Experience Requirements: What Counts and What Does Not

A detailed breakdown of ISACA experience requirements for CISA certification, including qualifying activities and common questions.

CISAPractice|

Understanding the Experience Requirement

To earn the CISA certification, you must demonstrate a minimum of five years of professional work experience in information systems auditing, control, or security. This requirement ensures that CISA holders possess practical, hands-on expertise in addition to the knowledge validated by the exam. Understanding exactly what qualifies as acceptable experience helps you plan your path to certification.

Experience That Counts

Information Systems Auditing

Direct experience conducting IS audits is the most straightforward qualifying activity. This includes planning and performing audits of IT systems, evaluating internal controls over information systems, testing IT general controls and application controls, and reporting audit findings. Both internal and external IT audit experience qualifies.

Information Systems Control

Experience designing, implementing, monitoring, or managing information systems controls also counts toward the requirement. This can include work in IT governance roles, compliance management, quality assurance of IT processes, and oversight of IT control frameworks. The key is that your work directly relates to ensuring IT systems are properly controlled.

Information Security

Professional experience in information security roles qualifies when the work involves security policy development, access control management, security monitoring, incident response, vulnerability management, or security program management. The experience must demonstrate direct involvement with protecting information assets.

Experience That Does Not Count

  • General IT support or help desk work that does not involve audit, control, or security functions
  • Software development unless it involves security-focused development or control implementation
  • Project management unless the projects specifically involve audit or security deliverables
  • General business administration or management without IT audit, control, or security responsibilities
  • Academic research or teaching (though these may qualify for experience substitution)

Verification Process

All claimed experience must be verified by your employer or an independent third party. ISACA may audit experience claims, so maintain documentation of your job responsibilities and accomplishments. Your experience verification should clearly describe audit, control, or security activities you performed, not just your job title.

Part-Time and Contract Experience

Part-time experience counts but is calculated proportionally. For example, if you worked half-time on IS audit activities for two years, this counts as one year of qualifying experience. Contract and consulting experience qualifies as long as the work performed falls within the acceptable categories described above.

Planning Your Experience Path

If you do not yet have five years of qualifying experience, you can still pass the CISA exam and apply for certification later. You have five years from your exam passing date to submit your application. During this time, seek out opportunities to gain qualifying experience, volunteer for audit-related projects, or transition into roles with explicit audit, control, or security responsibilities. Proactive career planning can help you meet the experience requirement more quickly.

Related Tags

Career DevelopmentCertificationCISA Exam

Ready to practice?

Put this knowledge to work with scenario-based practice questions.

Start Free