7 min read

Maintaining Your CISA Certification

Learn the requirements for maintaining your CISA certification including CPE hours, fees, and compliance obligations.

CISAPractice|

Keeping Your CISA Active

Earning the CISA certification is a significant achievement, but maintaining it requires ongoing commitment. ISACA has established specific requirements that certified professionals must meet to keep their certification in good standing.

Continuing Professional Education (CPE)

CPE is the primary requirement for maintaining CISA certification:

  • Annual requirement: CISA holders must earn a minimum of 20 CPE hours each year during the three-year certification period.
  • Three-year requirement: A total of 120 CPE hours must be earned during each three-year certification cycle.
  • Qualifying activities: CPE hours can be earned through professional conferences and seminars, training courses and workshops, publishing articles or books on relevant topics, teaching or lecturing on IS audit or related subjects, self-study programs, participation in ISACA chapter activities, and completing college or university courses.

CPE Reporting

CISA holders are responsible for tracking and reporting their CPE activities:

  • Documentation: Maintain records of all CPE activities including certificates of completion, conference attendance records, and evidence of publications.
  • Annual reporting: Report CPE hours to ISACA annually through the ISACA website.
  • Audit possibility: ISACA may audit CPE claims. Certified professionals who cannot provide documentation for claimed hours may face suspension or revocation of their certification.

Calculating CPE Hours

Different activities earn CPE hours at different rates. Attending a professional conference typically earns one CPE hour per hour of attendance. Completing a training course earns hours based on course length. Publishing a professional article may earn additional hours based on the publication's scope and significance. Teaching earns one CPE hour per hour of instruction, plus preparation time.

Annual Maintenance Fees

CISA holders must pay annual maintenance fees to ISACA. The fee amount varies based on membership status:

  • ISACA members: Members pay a reduced annual maintenance fee.
  • Non-members: Non-members pay a higher annual maintenance fee.

Failing to pay the annual maintenance fee can result in certification suspension. ISACA provides a grace period for late payments, but extended non-payment leads to certification revocation.

ISACA Code of Professional Ethics

CISA holders must adhere to ISACA's Code of Professional Ethics. This includes supporting the implementation of appropriate standards and procedures for information systems, performing duties with objectivity and due diligence, serving the interests of stakeholders in a lawful manner, maintaining the confidentiality of information obtained during professional activities, and maintaining competence in their field of practice.

Certification Renewal

At the end of each three-year cycle, CISA holders must confirm that they have met all CPE requirements, paid all maintenance fees, and complied with the Code of Professional Ethics. Meeting these requirements renews the certification for another three-year cycle.

Lapsed Certification

If certification lapses due to non-compliance, ISACA provides reinstatement options depending on how long the certification has been lapsed. Reinstatement may require meeting back CPE requirements, paying outstanding fees, or in some cases retaking the exam. To avoid this situation, set calendar reminders for annual CPE reporting and fee payment deadlines.

Related Tags

CISA CertificationISACACPEProfessional Development

Ready to practice?

Put this knowledge to work with scenario-based practice questions.

Start Free