Post-Exam Next Steps for CISA Certification
What to do after passing the CISA exam, including the certification application process, CPE requirements, and career next steps.
After Passing the CISA Exam
Passing the CISA exam is a significant achievement, but it is not the final step in becoming a Certified Information Systems Auditor. Several administrative and professional steps remain before you can use the CISA designation and maintain it throughout your career.
The Certification Application
Passing the exam alone does not grant the CISA certification. You must also meet experience requirements and submit an application:
- Work Experience: ISACA requires a minimum of five years of professional IS auditing, control, or security work experience. Certain education and certifications can substitute for up to three years of the requirement.
- Application Submission: Submit your CISA application within five years of passing the exam. The application requires verification of your work experience by your employer or supervisor.
- Application Review: ISACA reviews applications to verify that your experience meets the requirements. This process typically takes several weeks.
- Experience Waivers: A bachelor's degree can waive one year of experience. A master's degree in information security or a related field can waive one year. Certain certifications and teaching experience may also qualify for waivers.
Maintaining Your Certification
Once certified, maintaining the CISA designation requires ongoing effort:
- Continuing Professional Education (CPE): You must earn a minimum of 20 CPE hours per year and 120 CPE hours over a three-year certification period. CPE activities include attending conferences, completing training courses, publishing articles, and participating in ISACA chapter activities.
- Annual Maintenance Fee: ISACA charges an annual maintenance fee to keep your certification active. ISACA members receive a discounted rate.
- Adherence to Standards: Certified professionals must adhere to ISACA's Code of Professional Ethics and comply with IS auditing standards.
Earning CPE Credits
Multiple activities qualify for CPE credit:
- Attending ISACA conferences, seminars, and webinars
- Completing online training courses and certifications
- Publishing articles or presenting at professional events
- Participating in ISACA chapter meetings and study groups
- Teaching or mentoring in IS audit-related subjects
- Self-study activities with documented learning outcomes
Career Next Steps
With your CISA certification in hand, consider these career advancement opportunities:
- Pursue Additional Certifications: Complement your CISA with certifications such as CISM (security management), CRISC (risk and control), or CISSP (security professional).
- Expand Your Network: Join your local ISACA chapter and participate actively. Professional networking opens doors to job opportunities, mentorship, and collaborative learning.
- Seek New Challenges: Look for opportunities to lead audit engagements, mentor junior auditors, or take on governance and risk management responsibilities.
- Share Your Knowledge: Contribute to the profession by writing articles, presenting at conferences, or volunteering with ISACA committees.
If You Did Not Pass
If you did not pass the exam, do not be discouraged. Review your score report to identify weak domains, adjust your study plan to focus on those areas, and schedule a retake when you feel prepared. Many successful CISAs passed on their second or third attempt. The experience of taking the exam itself is valuable preparation for your next attempt.