8 min read

CPE Requirements for CISA Professionals

A detailed guide to CPE requirements for CISA certification holders. Learn how to earn and report continuing professional education hours.

CISAPractice|

CPE Requirements Overview

Continuing Professional Education (CPE) ensures that CISA-certified professionals maintain and enhance the knowledge and skills needed to perform IS audit and assurance work effectively. ISACA requires ongoing CPE as a condition of maintaining CISA certification.

CPE Hour Requirements

CISA holders must meet both annual and cycle requirements:

  • Minimum 20 hours annually: At least 20 CPE hours must be earned and reported each calendar year. This ensures continuous learning rather than concentrating all education at the end of the cycle.
  • 120 hours per three-year cycle: Over each three-year certification period, a total of 120 CPE hours must be completed. This averages to 40 hours per year, well above the annual minimum.

Qualifying CPE Activities

ISACA accepts CPE hours from a variety of professional development activities:

  • ISACA conferences and events: Attending ISACA-sponsored conferences, seminars, and webinars. These events directly address topics relevant to CISA certification.
  • Professional training: Completing training courses from recognized providers on topics related to IS auditing, IT governance, information security, or related fields.
  • Academic education: Completing university or college courses in relevant subjects. Each semester credit hour typically equals 45 CPE hours.
  • Self-study: Completing structured self-study programs, reading professional publications, or completing vendor-provided training modules.
  • Professional contributions: Writing articles, papers, or books on relevant topics. Developing training materials or presentations. Participating in standards development.
  • Teaching and mentoring: Teaching courses or presenting at conferences on IS audit or related topics. First-time presentations earn more CPE hours than repeat presentations.
  • ISACA chapter activities: Participating in local ISACA chapter meetings and events, or serving in chapter leadership roles.

Non-Qualifying Activities

Not all professional activities count toward CPE requirements. Activities that generally do not qualify include routine work duties, on-the-job training that is not structured, general management or leadership training unrelated to IS auditing, and social events even if organized by professional associations.

Planning Your CPE Strategy

Effective CPE planning involves several considerations:

  • Align with career goals: Choose CPE activities that support your professional development objectives, not just those that are most convenient.
  • Diversify activities: Mix different types of activities (conferences, training, self-study) to maintain engagement and broaden your knowledge.
  • Plan ahead: Do not wait until the end of the year or cycle to earn required hours. Spread activities throughout the year.
  • Track diligently: Maintain a log of all CPE activities with supporting documentation. Record activities promptly rather than trying to reconstruct them later.

Reporting and Documentation

CPE hours must be reported to ISACA through their online portal. For each activity, you should record the activity name and provider, the date and duration, the topic and its relevance to CISA certification, and supporting documentation such as certificates of completion. ISACA may audit your CPE claims at any time during the certification cycle. Maintain documentation for all claimed hours in case of audit.

Consequences of Non-Compliance

Failure to meet CPE requirements can result in certification suspension or revocation. ISACA typically provides notice and a remediation period before taking action, but chronic non-compliance will result in loss of certification.

Related Tags

CISA CertificationCPEProfessional DevelopmentISACA

Ready to practice?

Put this knowledge to work with scenario-based practice questions.

Start Free