Receive consulting resources in your inbox

CRISC: Certified in Risk and Information Systems Control

1. What Is CRISC?

CRISC stands for Certified in Risk and Information Systems Control, a professional certification awarded by ISACA. It recognizes knowledge and experience in managing technology-related business risk and selecting, implementing, monitoring, and maintaining information systems controls. Its focus is the connection between technology exposure and business decisions, rather than technical security operations alone.

Current applicants must pass an examination, document qualifying professional experience, complete the certification application, and accept continuing education and ethics obligations. Passing the exam alone does not confer the credential.

For a hiring manager, CRISC is useful evidence to investigate further when evaluating a technology risk professional. It should not substitute for evidence of successful delivery, industry knowledge, or control implementation. Long-standing holders may also have qualified through the historical experience-based grandfathering route, rather than the examination route used today.

2. CRISC at a Glance

  • Full name: Certified in Risk and Information Systems Control.
  • Abbreviation: CRISC.
  • Credential type: Individual professional certification.
  • Awarding organization: ISACA.
  • Official website: ISACA CRISC credential page.
  • Current status: Active and available to new applicants.
  • First introduced: 2010, initially with an experience-based grandfathering program.
  • Professional focus: Technology risk, governance, controls, and risk reporting.
  • Intended career stage: Experienced practitioners, particularly mid-career risk, IT, and security professionals.
  • Geographic scope: International, with testing-center and remote examination delivery.
  • Main eligibility requirement: Three years of relevant experience across at least two CRISC domains.
  • Assessment: One 150-question, four-hour examination for current applicants.
  • Indicative initial cost: US$625 for an existing member or US$810 for a nonmember, covering one exam attempt and the application, before preparation, dues, and applicable taxes.
  • Maintenance: Annual fees, at least 20 continuing professional education hours annually, and 120 over three years.
  • Verification: ISACA verification using the certification number and the holder’s exact surname.

3. Who Awards and Oversees the Credential?

ISACA controls admission, certification maintenance, professional conduct requirements, and appeals. PSI administers the examination through testing centers and remote proctoring, but does not award CRISC. Examination delivery and certification approval are separate functions. ISACA’s appeals policy covers matters including application decisions and reinstatement.

CRISC is included in ISACA’s accredited scope under ANAB’s ISO/IEC 17024 personnel-certification program. This accreditation concerns the certification body and its processes. It is not accreditation of a holder’s employer, consulting firm, control environment, or project deliverables.

Holders must follow ISACA’s Code of Professional Ethics, including obligations concerning competence, professional care, confidentiality, and disclosure of significant facts. Ethical breaches can trigger investigation and disciplinary action. Consequently, the credential has conduct obligations beyond maintaining an examination record.

4. When and Why Was the Credential Created?

CRISC was created to recognize professionals who connect business risk management with information systems controls. Its original structure distinguished identifying and responding to risk from designing and maintaining the controls intended to address it.

  • 2010: ISACA introduced CRISC and opened a grandfathering program. Experienced professionals could qualify without an exam under substantially higher experience requirements, including eight years of IT and business experience and specified experience across the original domains.
  • June 2011: The first examination offering followed the initial experience-based introduction. Historical awards therefore should not automatically be interpreted as evidence of an exam pass.
  • 2021: A revised job practice placed greater emphasis on governance, business continuity, resilience, privacy, and data protection.
  • November 3, 2025: Another examination update adjusted domain weightings while retaining the four-domain structure. Updated preparation materials began appearing on September 3, 2025.

The 2025 update also addressed emerging technology risk, including AI and machine learning. This extends the credential’s risk-management context; it does not transform CRISC into a specialist qualification in developing or validating AI models.

5. Who Pursues CRISC, and Where Is It Used?

ISACA identifies IT and business professionals as its audience, including risk and compliance specialists, business analysts, and project managers who manage risk through information systems controls. The credential is particularly relevant to professionals moving between technical teams and business decision-makers.

Financial services provides a documented application. ISACA has published work by banking risk practitioners on technology risk assessment, including a CRISC-qualified IT risk director. Their work illustrates the connection between application-level exposures, business impact, assessment methods, and enterprise risk management. It is an example of professional use, not evidence that every bank requires CRISC.

As a practical interpretation of its subject matter, relevant assignments can include reviewing cloud-service dependencies, structuring a technology risk register, assessing controls during an ERP transformation, or developing management reporting. These activities can form part of a cyber risk assessment, particularly when the deliverable must translate technical findings into business exposure and prioritized responses.

Professionals should distinguish eligibility for CRISC from eligibility for a particular job. Employers may request much more experience, sector knowledge, or technical expertise than the credential requires. CRISC is an individual certification, not governmental permission to practice or organizational authorization to perform regulated services. Its role in hiring is determined by the specific employer or client.

6. What Knowledge and Skills Does It Cover?

The examination effective November 3, 2025 has four domains: Governance, 26%; Risk Assessment, 22%; Risk Response and Reporting, 32%; and Technology and Security, 20%. These percentages describe examination coverage, not separate credentials or demonstrated experience in every domain.

For practical interpretation, the syllabus can be organized into six capability areas:

  • Governance and accountability: Business objectives, organizational responsibilities, risk appetite, and tolerance. This supports deciding who owns a risk and who may accept it.
  • Risk identification and analysis: Threats, vulnerabilities, scenarios, business impact, and inherent versus residual risk. This supports evaluating business exposure rather than merely listing technical weaknesses.
  • Risk response: Treatment options, ownership, supplier risk, and exceptions. This supports selecting a proportionate response and documenting responsibility.
  • Control design and testing: Control selection, implementation, and testing methods. This supports evaluating whether controls address the intended risk.
  • Monitoring and reporting: Risk indicators, control metrics, dashboards, and action plans. This supports escalation and tracking whether exposure is changing.
  • Technology and security context: Architecture, development, operations, resilience, privacy, and emerging technologies. This supports identifying risk implications across the technology life cycle.

Applied capabilities

Illustrative assignments connected to this knowledge include:

  • For a manufacturer, tracing an ERP outage scenario to production disruption and proposing a proportionate treatment plan.
  • For a financial institution, explaining why a supplier’s contractual assurances do not, by themselves, demonstrate effective controls.
  • For an AI-enabled service, identifying information-handling risks and recommending governance checkpoints before deployment.

Boundaries

These are applications of the subject matter, not additional tasks every holder has performed. Evaluate technical implementation, quantitative modeling, and specialist AI expertise separately. In particular, knowledge of a control-testing method should not be treated as evidence that the holder has executed a reliable test in a production environment.

7. What Are the Eligibility Requirements?

Exam access and certification eligibility are different. Candidates may take the examination before completing their experience requirement. Certification requires at least three years of qualifying work across at least two of the four CRISC domains, gained within the ten years preceding the application. Applicants must apply within five years of passing. Experience is verified by a supervisor or manager.

CRISC does not offer experience waivers or substitutions. A degree or another certification therefore does not shorten its experience requirement. The current route is based on relevant work, not an academic qualification requirement.

Before paying for an exam, a candidate should map actual responsibilities to the domains. A job title such as “business analyst,” “security engineer,” or “project manager” does not explain whether the work involved risk assessment, control decisions, or risk reporting. Conversely, relevant responsibilities may sit inside a role whose title does not contain “risk.”

A useful personal eligibility file should identify employment dates, the relevant tasks, examples of responsibilities, and the manager who can verify them. Candidates with several employers should resolve verification arrangements early rather than assume a current supervisor can substantiate all earlier work.

The practical distinction is between having worked near a risk function and having performed qualifying tasks. Candidates should describe their own contribution clearly, separating work they conducted from work they observed or received from another team. ISACA makes the final eligibility decision through its application process.

8. How Do You Earn CRISC?

1. Establish a realistic qualification plan

Start with the experience mapping described above. If experience is incomplete, plan when the application can be submitted rather than treating the examination as the final step.

2. Register and schedule

Create or update the MyISACA account, ensuring the name matches the identification used for testing. Registration establishes a six-month examination eligibility period. Delivery is through PSI testing centers or remote proctoring. For remote testing, check the computer, room, identification, and proctoring requirements before choosing an appointment.

3. Prepare against the applicable outline

Use the current syllabus to identify gaps. Practice explaining why a response is appropriate given the business objective, risk owner, available evidence, and existing controls. Treat practice questions as diagnostic tools, not as a substitute for understanding the reasoning.

4. Complete the examination

The exam has 150 multiple-choice questions and allows four hours. Available languages are English, Spanish, and Japanese. It is a knowledge and judgment examination rather than a hands-on implementation assessment.

It is closed-book: candidates must follow restrictions on reference materials, communications, devices, and assistance. Remote delivery does not make outside resources permissible.

5. Receive results or arrange a retake

The passing scaled score is 450 on a 200–800 scale, not 450 divided by 800 as a percentage-correct requirement. Preliminary status appears after testing; official results are issued within ten working days. Candidates may attempt the exam four times in a rolling twelve months, with waits of 30 days after the first failure and 90 days after subsequent failures. Each attempt requires full registration payment.

6. Complete certification approval

After the official pass result, pay the US$50 application fee and submit the verified experience application and required declarations. Only approval completes the award process. An examination pass or a training completion certificate is not authorization to present oneself as CRISC-certified.

9. How Long Does It Take, and How Do Candidates Prepare?

Prerequisite-building time: A newcomer must first accumulate qualifying experience. An experienced applicant may already satisfy that element before beginning examination preparation.

Preparation time: Plan around knowledge gaps rather than a universal study-hour estimate. Someone experienced in control testing may need more work on governance and risk ownership; someone in policy or compliance may need deeper familiarity with technology operations.

Official resources: ISACA offers the CRISC Review Manual, currently presented as the eighth edition, a Questions, Answers and Explanations database, review courses, and a practice quiz. Purchasing a particular preparation product is not itself part of earning certification.

Administrative time: Allow separately for examination scheduling, official results, experience verification, and application review. Do not promise an employer that certification will be complete on the examination date.

Preparation choices: A practical approach is to combine structured reading with scenario analysis and targeted question practice. Instructor-led training can provide structure, but should be selected for the candidate’s needs rather than confused with the credential itself.

10. How Much Does CRISC Cost?

As of September 25, 2026, ISACA lists the following standard charges in US dollars. These provide a useful US candidate budget before applicable taxes, preparation, travel, and currency-conversion charges.

  • Exam registration: US$575 for members or US$760 for nonmembers.
  • Certification application: US$50.
  • First-attempt initial total: US$625 for an existing member or US$810 for a nonmember. These totals assume a successful first examination attempt and application.

Joining to obtain member pricing: ISACA advertises professional membership at US$145 plus local chapter dues. A new professional member should therefore budget US$770 plus chapter dues for membership, one examination attempt, and the application, before exclusions. The examination discount is not the same as a net saving after membership costs.

Optional preparation: Manuals, question databases, and courses are separate purchases. Avoid comparing an exam-only price with a training package as though they cover the same items.

Retakes and scheduling: Another attempt requires another examination fee. Rescheduling is permitted without penalty when completed at least 48 hours before the appointment within the eligibility period.

Ongoing costs: The standard annual CRISC maintenance fee is US$45 for members or US$85 for nonmembers. Membership dues and any paid continuing education remain separate.

11. How Do Holders Maintain CRISC?

Active holders must earn and report at least 20 continuing professional education hours each year and 120 within their three-year reporting cycle. They must also pay the annual maintenance fee, comply with the ethics code, and provide supporting evidence if selected for a CPE audit. Twenty hours annually alone would not satisfy the three-year total.

Under the current CRISC-specific recordkeeping rule, supporting documentation should be retained for twelve months after the end of the three-year cycle. Qualifying activities extend beyond ISACA courses, but ordinary job activity is not automatically continuing education.

Announced change: Beginning January 1, 2027, the total remains 120 hours, with at least 90 aligned to the certification’s examination content. Up to 30 may cover other qualifying professional development, such as leadership or communication. This flexibility is a future rule as of September 25, 2026.

ISACA also provides approved non-practicing and retired statuses. Non-practicing status retains an annual fee and has conditions for returning to active practice. Retired status removes the ongoing fee and education obligations but is not active certification status.

Failure to maintain requirements can result in revocation. Reinstatement requires review and may involve outstanding fees and an additional charge. It should not be assumed that a revoked credential can be restored simply by paying the latest annual fee.

12. What Is Its Professional Value, and What Are Its Limitations?

There is direct evidence of employer interest. A 2026 Bank of America posting for a compliance and operational risk manager covering application security and technology risk listed CRISC among desired professional certifications. The same posting required substantial experience, stakeholder influence, and technology-risk expertise. This illustrates recognition without implying that CRISC alone meets the job specification.

A reasonable professional interpretation is that CRISC can help establish a common vocabulary for discussing technology risk, control ownership, and management decisions. Its usefulness is strongest when a role requires translating technical concerns into business consequences and defensible treatment choices. That interpretation is consistent with the credential’s original risk-and-control purpose.

For a professional considering it, evaluate the credential against the work you want to do. Reviewing technology investments, challenging control assumptions, or improving risk reporting presents a different development need from becoming a penetration tester or configuring cloud infrastructure. Choose based on the capability gap, not simply the number of certifications already held.

For compensation decisions, do not infer a salary premium from the letters alone. A useful comparison would need to account for geography, seniority, responsibilities, and experience. Likewise, a credential holder’s promotion or project success does not establish that the credential caused the outcome.

For clients, the strongest use is as one input to a broader assessment: verify current status, examine relevant delivery evidence, and test how the person handles uncertain information and competing business priorities.

13. What Should Employers and Clients Infer From It?

What it establishes

For someone admitted through the current route, CRISC establishes an approved combination of examination and verified experience, followed by ongoing maintenance obligations. Historical grandfathered holders qualified differently. Neither route establishes that the person has recently been assessed on every topic in the latest syllabus.

What still needs evaluation

Evaluate industry context, analytical quality, technical depth, implementation experience, communication, and the scale of prior responsibilities separately. Ask what the individual personally delivered, not merely what the team or employer completed.

Relevant staffing situations

Consider the credential when staffing technology-risk assessment, control improvement, or security governance and reporting assignments. Its relevance is an inference from its risk-and-control focus, not proof that a holder can lead the entire engagement. An individual’s CRISC does not certify the consulting firm.

Evidence to request

Request nonconfidential examples such as a redacted risk assessment, control-testing approach, risk acceptance memorandum, management dashboard, or completed remediation plan. Ask for the assumptions, decision rights, and evidence behind the conclusions.

Three questions to assess applied competence

  • How would you assess the risk of moving a critical business process to a cloud supplier? A useful answer connects failure scenarios to business impact, evaluates existing controls, distinguishes inherent from residual risk, and identifies accountable owners.
  • When would you recommend accepting an IT risk rather than implementing another control? Look for treatment alternatives, cost and benefit, uncertainty, risk tolerance, and approval by the appropriate business authority.
  • How would you demonstrate that a control is both well designed and operating effectively? Look for a distinction between design and operation, appropriate evidence, testing frequency, exceptions, and escalation rather than reliance on a policy document alone.
  • CISA, Certified Information Systems Auditor: ISACA’s audit-oriented certification is a complement or alternative for assurance work. It has an examination and a five-year experience baseline, with permitted substitutions. CRISC is more directly oriented toward managing risk and controls, rather than organizing an audit career.
  • CISM, Certified Information Security Manager: This ISACA certification centers on managing an information security function. It requires its own examination and experience assessment, with a five-year baseline. It is a potential complement for security program leadership, not an automatic next grade of CRISC.
  • CGRC, Certified in Governance, Risk and Compliance: ISC2’s certification addresses systems, security and privacy controls, and compliance across risk-management frameworks. It has an examination and a two-year experience requirement. It is a relevant alternative or complement for framework-based governance and compliance work.
  • AAIR, Advanced in AI Risk: ISACA’s specialized AI risk certification is a formal progression option for active CRISC holders. CRISC is one of its accepted prerequisite credentials; applicants must still complete AAIR’s own assessment and award process. Its subject matter covers AI risk governance, life-cycle risk, and program management.

These comparisons concern professional emphasis, not prestige. Select the credential whose assessed subject matter and eligibility route fit the intended work. Holding one should not be presented as automatically earning another.

15. How Can You Verify CRISC and Use Its Letters Correctly?

Use ISACA’s certification verification service. Select CRISC and enter the certification number together with the holder’s surname exactly as recorded in the ISACA profile. ISACA also accepts verification requests accompanied by the individual’s signed written consent. This is more reliable than treating an old certificate image as proof of current standing.

For a hiring or procurement check, confirm identity, credential type, and current status. If the search fails, first check the number and spelling and request issuer confirmation. A failed lookup should not, by itself, settle whether a claim is false. Preserve the verification outcome and date in the hiring record rather than relying on an undated résumé statement.

ISACA permits an authorized holder to place CRISC after the name, such as “Alex Morgan, CRISC.” It does not permit individual use of the CRISC logo on business cards or promotional materials in a way that implies ISACA endorsement.

Someone who has only passed the examination should state that fact rather than use the post-nominal. Non-practicing, retired, or revoked status must not be represented as active certification; the CRISC-specific policy expressly restricts designation use on business cards for non-practicing and retired holders.

16. Frequently Asked Questions

Can I take the CRISC exam before meeting the experience requirement?

Yes. Examination access does not require the qualifying experience to be complete. Certification does. Plan the sequence carefully because the application must be submitted within five years of passing, and experience must meet ISACA’s applicable requirements.

Do I have to become an ISACA member?

No. ISACA publishes nonmember examination and maintenance prices. Membership can change the economics, but compare the discounts with membership and chapter dues. It is not a substitute for the examination, experience, or certification application.

Does CRISC prove hands-on cybersecurity implementation skills?

Not by itself. Its examination is multiple-choice rather than a practical implementation test. For a technical assignment, request work samples and test the relevant capability directly, whether that involves control configuration, security testing, or system-specific troubleshooting.

Can a legitimate CRISC holder have qualified without the exam?

Yes. The original grandfathering program allowed suitably experienced professionals to qualify without examination. That historical route is not the current applicant route. Evaluate the holder’s admission history and present standing rather than assuming all holders followed identical requirements.

Is CRISC a lifetime credential?

Not as an unconditional active designation. Holders must satisfy continuing education, annual fees, ethics, and applicable audit requirements. Someone may have earned CRISC previously without currently holding it in active standing, so verification should address present status.

17. Official Resources and Recent Changes

Official resources available: ISACA provides examination outlines, candidate guides, preparation materials, application guidance, maintenance policies, ethics requirements, appeals procedures, and certification verification. Candidates should distinguish examination rules from the requirements for final certification.

Current examination change: The November 3, 2025 update is already effective. Preparation should use the corresponding content outline rather than assume older materials reflect current coverage.

Future maintenance change: From January 1, 2027, the 120-hour three-year requirement will allow up to 30 hours of qualifying broader professional development, while requiring at least 90 hours aligned with the credential. This announced change should not be applied prematurely to 2026 reporting.

This profile is an independent Umbrex reference and is not issued or endorsed by the credential owner unless an explicit relationship is stated.