Certified in the Governance of Enterprise IT Exam Guide
The Certified in the Governance of Enterprise IT (CGEIT) exam validates knowledge across enterprise IT governance, IT resources, benefits realization and risk optimization. It is relevant to professionals who implement or manage governance of enterprise IT and to people with significant advisory or assurance responsibilities in that area. This guide helps you decide whether your experience matches the certification path, which domains deserve the most study time, how to schedule within the eligibility period and what evidence you will need after passing.
What the CGEIT exam is designed to validate
CGEIT tests whether you can apply governance thinking to enterprise technology decisions rather than focusing only on technical implementation. The official outline describes an exam of 150 questions across four job-practice domains, with questions testing knowledge and ability on real-life job practices used by expert professionals.
The central theme is alignment: IT governance should connect organizational objectives, technology decisions, resources, investment outcomes and risk oversight. A candidate therefore needs to understand how decisions are structured, evaluated, monitored and reported—not simply memorize terminology.
The CGEIT Review Manual 8th Edition is described by ISACA as preparation for the exam and as a way to understand the responsibilities of people who implement or manage governance of enterprise IT, as well as those with significant advisory or assurance responsibilities. That description is a useful test of fit. If your work regularly involves governance decisions, oversight, assurance, investment evaluation or enterprise-level technology planning, the subject matter is likely to be more familiar than it would be to someone whose role is limited to one technical product.
Who should consider the certification
The examination is open to anyone interested in the governance of enterprise IT. Passing the exam alone, however, does not complete the certification process. The certification route also requires relevant experience, an application, the application processing fee, adherence to ISACA’s Code of Professional Ethics and compliance with the Continuing Professional Education Policy.
The strongest candidates usually bring examples from work such as defining governance structures, aligning technology strategy with business objectives, managing IT-related resources, evaluating technology investments, overseeing performance or identifying and treating IT risk. These examples make abstract questions easier to interpret because you can connect a proposed action to a governance objective and its stakeholders.
Before paying for an exam appointment, separate two decisions: whether you want to sit the exam and whether you are ready to apply for the designation. You may take the exam without first having the full certification application approved, but you should review the experience requirements early so that a successful result leads to a realistic certification plan.
What it does not measure
The outline is organized around governance job practices, not around a single software platform or a narrow technical specialty. Do not prepare as though the exam were a product configuration test. Technical detail matters only when it helps you reason about governance, resources, outcomes or risk.
The official material also does not support treating unauthorized question collections, leaked content or memorized answers as a reliable preparation method. Use practice questions to diagnose reasoning gaps, then return to the relevant domain concepts and official preparation resources. No question bank can replace understanding why a governance response is appropriate in a particular enterprise situation.
How the four exam domains are weighted
Use the official weighting to allocate study effort, but do not ignore a smaller domain. The exam-domain weighting is 40% Governance of Enterprise IT, 15% IT Resources, 26% Benefits Realization and 19% Risk Optimization. Governance has the largest share, while the other domains can still expose major gaps in a candidate’s experience.
The domains and tasks were developed through research, feedback and validation from subject matter experts and industry leaders, according to the official content outline. Treat the outline as the controlling map for preparation. Build notes and practice sessions against its domain names and subtopics instead of relying on an older course outline or an informal topic list.
Domain 1: Governance of Enterprise IT — 40%
The 40% Governance of Enterprise IT domain covers governance frameworks, technology governance and information governance. Its broader focus includes the organizational structure used to build IT frameworks, strategy and technology aspects of IT governance, and essential knowledge for governing different types of information.
Study this domain as a decision system. Ask who has authority, which business objective is being supported, how accountability is assigned, what information is needed and how the decision will be monitored. A useful note for each topic should identify the governing body or role, the decision, the policy or framework connection, the affected stakeholders and the evidence that would demonstrate effective oversight.
A common mistake is to equate governance with day-to-day management. Management may execute a plan or operate a service; governance establishes direction, evaluates alternatives, sets expectations and oversees whether the intended results are achieved. When practice questions present several plausible actions, look for the choice that best preserves accountability, alignment and oversight at the enterprise level.
Domain 2: IT Resources — 15%
The 15% IT Resources domain covers IT resource planning and IT resource optimization. The outline includes sourcing strategies, resource capacity planning, acquisition of resources, the IT resource lifecycle and asset management, human resource competency assessment and development, and management of contracted services and relationships.
Prepare by tracing a resource from need through selection, use, monitoring and eventual replacement or disposal. Include people, assets, suppliers and capacity in the same mental model. For each resource decision, consider whether the organization has the capability, capacity, ownership, contractual control and lifecycle visibility required to support its objectives.
Do not reduce this domain to procurement. A sourcing decision can affect risk, resilience, capability, cost, accountability and future flexibility. Similarly, a staffing question may test competency development or capacity planning rather than recruitment alone. Practice explaining why a resource choice remains suitable over its lifecycle, not merely why it can be acquired.
Domain 3: Benefits Realization — 26%
The 26% Benefits Realization domain covers IT performance and oversight plus management of IT-enabled investments. Its listed areas include performance management, change management, governance monitoring, governance reporting, quality assurance, process development and improvement, business case development and evaluation, IT investment management and reporting, performance metrics and benefit evaluation methods.
Study this domain from proposal to realized outcome. A sound business case is not the end of the process: investment performance must be tracked, assumptions tested, changes governed and benefits evaluated against the intended objectives. Distinguish activity measures from outcome measures. Completing a project or deploying a system does not by itself prove that the expected business benefit was achieved.
A practical exercise is to take a hypothetical technology investment and write down its objective, expected benefit, owner, baseline, target measure, reporting route, review point and response if performance falls short. Then ask whether the metric shows delivery effort, system performance, user adoption, financial value or an actual business outcome. This helps prevent the common error of selecting an easy-to-measure indicator that does not demonstrate value.
Domain 4: Risk Optimization — 19%
The 19% Risk Optimization domain focuses on mitigating potential IT risks and challenges and overseeing the risk-management capabilities of IT. Preparation should connect risk identification, assessment, response, monitoring and reporting with enterprise priorities and decision rights.
Avoid studying risk as a catalogue of threats. Governance questions often turn on proportionality, ownership and the relationship between risk and business objectives. For each scenario, identify the asset or objective at stake, the uncertainty, the accountable owner, the treatment options, the residual exposure and the information needed for oversight.
Risk optimization also requires accepting that not every risk should be eliminated. A control, transfer, avoidance or acceptance decision should be explainable in relation to appetite, value, obligations and available resources. If an answer creates a new dependency or leaves ownership unclear, examine it critically even if it appears technically effective.
How to turn the outline into a study plan
Start with a diagnostic, not with a full reread. Download the current official content outline and mark each subtopic as strong, familiar or weak. Then use the domain weights to sequence study: establish the governance foundation first, develop the benefits and risk connections next, and give focused but deliberate coverage to IT resources.
Your goal is not to produce the largest set of notes. It is to build a repeatable method for analyzing scenario-based decisions. For every subtopic, write a short explanation in your own words, one example of an appropriate governance action, one likely confusion and one question that would reveal whether the concept is understood.
A five-stage preparation sequence
Stage one is orientation. Read the exam content outline from beginning to end, record the four domains and list the tasks beneath each one. Check that your study material uses the same current structure. This prevents a familiar resource from quietly directing your preparation toward retired or differently organized content.
Stage two is concept building. Study Domain 1 first because governance frameworks, technology governance and information governance provide context for the other domains. As you move to resources, benefits and risk, keep linking each topic back to objectives, accountability, decision rights and oversight.
Stage three is application. Convert every major topic into a scenario. For example, ask how an organization should evaluate a supplier relationship, how an investment’s benefits should be monitored, or how an information-governance decision should be escalated. Explain the reasoning in complete sentences rather than choosing an answer by keyword recognition.
Stage four is timed practice. Use authorized practice material to work on reading, prioritization and elimination. After each item, record why the correct option fits the governance objective and why the alternatives are weaker. A score without error analysis gives little information about readiness.
Stage five is consolidation. Stop expanding the syllabus shortly before the appointment. Review your error log, domain summaries, definitions that you repeatedly confuse and the decision principles that recur across domains. This final phase should make retrieval faster and more precise, not introduce a new collection of unrelated materials.
How to use the official review manual
ISACA lists the CGEIT Review Manual 8th Edition as a preparation resource and describes it as covering the responsibilities associated with implementing or managing governance of enterprise IT and with advisory or assurance work. Use it alongside the content outline, not instead of the outline.
A productive reading cycle is preview, retrieve and apply. Preview the section headings and tasks; retrieve the central ideas without looking at the page; then apply them to a governance scenario. Mark passages that clarify relationships between domains, because those relationships are often more useful than isolated definitions.
If you use a course, summary or question database, verify that it maps to the current official outline. Third-party explanations can help with comprehension, but the official outline should decide what belongs in your study scope. Do not assume that a large quantity of practice items proves that the material is current or representative.
A useful error-log format
Keep one table or document with the domain, topic, your chosen answer, the governing principle, the reason the correct answer is stronger and the action you will take. The action might be rereading a concept, comparing two terms, creating a scenario or discussing the issue with a qualified colleague.
Classify errors rather than simply counting them. Knowledge errors mean you did not know the concept. Interpretation errors mean you missed the role, objective or constraint in the scenario. Judgment errors mean you recognized the facts but selected an action that was too operational, premature, narrow or insufficiently accountable. Each category requires a different remedy.
Review the log at the end of each study session. Rework missed items after a gap rather than immediately repeating them. Immediate repetition can create recognition without durable understanding, while delayed explanation tests whether you can reconstruct the reasoning independently.
A practical roadmap from first review to exam day
Use the roadmap as a sequence of decisions rather than a fixed promise about how long preparation will take. The right pace depends on your governance experience, available study time and familiarity with ISACA-style scenario reasoning. Set the appointment only after you have reviewed the outline and identified a credible way to address weak domains.
Keep the eligibility period in view when scheduling. The exam fee provides a 365-day eligibility period, and the fee is forfeited if the exam is not taken during that period. That makes an early study diagnosis important: registering without a workable plan creates avoidable scheduling pressure.
Step one: confirm the certification route
Review your experience before you register. CGEIT certification requires at least five years of relevant experience across at least three of the four domains, including at least one year related to Domain 1. Relevant work experience must have been gained within the 10 years preceding the certification application date.
Create an experience inventory using the official domain labels. For each role, record the dates, responsibilities, domain coverage and a person who could verify the work if needed. This is a practical recommendation, not a substitute for ISACA’s application review. If your experience is concentrated in only one or two domains, investigate the official requirements before treating the exam as your immediate certification target.
The examination itself is open to anyone interested in enterprise IT governance, but the experience requirement applies to the certification application. Keeping those two facts separate avoids both unnecessary discouragement and an unpleasant surprise after passing.
Step two: register and select an appointment
Exam registration and payment are required before scheduling and taking the exam. ISACA states that CGEIT exams are computer-based and administered at authorized PSI testing centers globally or through remotely proctored exams.
The current CGEIT exam registration fee is US$575 for ISACA members and US$760 for non-members, according to ISACA support. Treat these as official fee facts for planning, then verify the current payment page before purchase because fees and policies can change. The exam registration fee is separate from the one-time US$50 application processing fee required when applying for certification.
Candidates can schedule an appointment as early as 48 hours after payment of exam registration fees. Appointments are available only 90 days in advance, so a preferred future date may not appear when you first look. Check site availability and system compatibility before committing to a testing arrangement, and use the official candidate and scheduling guides for operational instructions.
If your plans change, ISACA states that you can reschedule during the eligibility period without penalty when you do so a minimum of 48 hours before the scheduled testing appointment. Record that cutoff with your appointment details rather than relying on memory.
Step three: run a readiness check
A readiness check should test reasoning across all four domains, not just recall in your strongest area. Work through mixed practice, explain your choices aloud or in writing and inspect whether your errors cluster around one domain, one task or one type of scenario.
Before booking, confirm that you can distinguish governance from management, outputs from benefits, resources from procurement and risk treatment from risk oversight. These distinctions are practical indicators of conceptual readiness. If you repeatedly choose the most immediate operational action when the scenario asks for an oversight or governance response, return to Domain 1 and analyze decision authority.
Do not use exam dumps or purported leaked questions as a readiness measure. They may be unauthorized, inaccurate or detached from the current outline, and memorization does not demonstrate the ability to reason through a new situation. Use legitimate study resources and your own explanations instead.
Step four: prepare the final review
In the final review, use a compact set of domain sheets. Put the official domain name at the top, followed by its purpose, tasks, key relationships, common confusions and two or three scenario questions you can answer without notes.
Revisit your error log and experience inventory. The first shows where your reasoning has failed during study; the second shows where your professional assumptions may be narrow. A specialist who works mainly in risk, for example, should deliberately practice investment and resource scenarios rather than assuming risk knowledge will transfer automatically.
Confirm the appointment details and the applicable instructions through ISACA and PSI. If you need an accommodation or are considering remote proctoring, consult the official guidance early enough to resolve eligibility and technical questions. Do not infer test-day procedures from discussion forums or unauthorized materials.
How to reason through a CGEIT scenario question
Read the question for the requested decision before examining every answer choice. Identify the organization’s objective, the role being asked to act, the governance level, the constraint and the desired result. Then eliminate options that skip required oversight, assign responsibility to the wrong party or solve a local symptom without addressing the enterprise objective.
CGEIT scenarios often contain several actions that could eventually be useful. The best answer is usually the one that fits the stated responsibility and sequence. A governance body may set direction or oversee performance, while a management role may implement an approved response. An investment owner may evaluate benefits, while a reporting function may provide evidence. The wording matters.
When two options seem reasonable, compare them using five questions: Which option is aligned with the objective? Which creates clear accountability? Which uses appropriate information and evidence? Which considers dependencies and risk? Which can be monitored or evaluated? This framework is a study technique, not an official scoring rule, but it helps convert broad governance knowledge into a disciplined choice.
Common traps to remove from your reasoning
The first trap is choosing the most technical answer. A technically strong control can still be the wrong response if the question asks for governance direction, investment evaluation or accountability.
The second is treating approval as evidence of value. Approval authorizes an initiative; benefits realization requires later measurement and evaluation. Look for the answer that preserves follow-through.
The third is assuming that a policy alone solves a governance issue. A policy needs ownership, communication, implementation, monitoring and reporting. When an answer stops at publication, ask what demonstrates adoption and effectiveness.
The fourth is accepting a risk without identifying the owner or documenting the basis. Risk acceptance can be appropriate, but it should be a deliberate governance decision connected to objectives and risk appetite.
The fifth is selecting a metric because it is easy to collect. A metric should help decision-makers understand performance, progress or realized benefit. Ask what action the measure enables and whether it reflects the intended outcome.
Delivery, appointment changes and official logistics
The exam is computer-based and may be taken at an authorized PSI testing center globally or through a remotely proctored exam. ISACA directs candidates to verify PSI test-site availability and system compatibility, and it provides scheduling, special-accommodation and remote-proctoring guidance.
Registration is continuous, so candidates can register at any time without registration-window restrictions. That does not mean every desired date is immediately available: ISACA notes that appointments are offered only 90 days in advance. Check your eligibility in the ISACA account if a site or date is missing, particularly when looking well ahead.
To schedule, candidates log in to the ISACA account, open Certification & CPE Management and select the exam-scheduling option, which takes them to the PSI dashboard. The official CGEIT page identifies the PSI dashboard route and advises candidates to check the relevant scheduling instructions.
If an appointment must move, follow ISACA’s rescheduling steps and protect the minimum 48-hour notice requirement. A practical safeguard is to place the appointment time, eligibility end date and rescheduling cutoff in a calendar immediately after booking. The official source should control if the scheduling interface or policy changes.
What to verify before paying
Check the current registration fee, eligibility terms, appointment availability and the delivery option you intend to use. The exam fee provides a 365-day eligibility period, and an unused eligibility period does not preserve the fee after that period ends.
Check the certification application path separately. Passing the exam is one step; certification also requires the application, experience demonstration, the US$50 application processing fee, professional-ethics compliance and continuing-education compliance. Candidates have five years from passing the exam to apply, but waiting does not remove the need to preserve evidence of relevant experience.
Use only the official candidate guide and CGEIT pages for current logistical instructions. Catalogue pages and third-party summaries can become stale, especially for fees, storefront processes, scheduling interfaces and delivery rules.
What happens after you pass
Passing the exam does not automatically confer the CGEIT certification. Once official exam scores have been released, you may pay the application fee and submit the certification application. The application must demonstrate the required experience, and candidates must apply within five years of passing the exam.
The certification requirements include passing the exam, paying the one-time US$50 application processing fee, submitting the application to demonstrate experience, adhering to ISACA’s Code of Professional Ethics and adhering to the Continuing Professional Education Policy. Prepare the experience documentation while studying so that the administrative step does not become an afterthought.
Relevant experience must cover at least three of the four CGEIT domains, include at least one year related to Domain 1 and total at least five years. It must have been gained within the 10 years preceding the certification application date. Match your records to those conditions, and do not assume that a job title by itself establishes domain experience.
Build an application evidence file
Keep role descriptions, employment dates, project responsibilities and verifier information in a secure personal record. Link each responsibility to Governance of Enterprise IT, IT Resources, Benefits Realization or Risk Optimization, and note the specific nature of your contribution.
Use precise activity descriptions. “Managed IT” is too broad to be useful; a better record identifies whether you established governance reporting, evaluated an IT-enabled investment, planned resources, oversaw contracted services or monitored risk. This file is a preparation recommendation for organization and recall, not a claim about additional ISACA documentation requirements beyond the official application process.
Submit the application through the current ISACA process after scores are released and the application fee is available in your MyISACA account. If a requirement is unclear, consult ISACA rather than relying on an unofficial interpretation.
How to maintain the certification
CGEIT maintenance is an ongoing obligation. ISACA requires a minimum of 20 CPE hours annually and a minimum of 120 CPE hours related to CGEIT during each three-year reporting period. The annual requirement and the three-year total both matter, so postponing all learning until the end of the cycle is a risky administrative strategy.
CPE should advance your knowledge or ability to perform CGEIT-related tasks. Build a balanced plan around governance, resources, benefits and risk topics, and report activities as you complete them. Keep supporting documentation because individuals selected for a CPE audit must provide evidence of all reported activities from a specified calendar year.
Plan CPE before the cycle becomes urgent
At the beginning of each reporting year, choose learning activities that address both your professional development needs and the CGEIT domains. ISACA lists conferences, webinars and online training, on-demand learning, training courses and skills-based labs, and volunteer activities among possible CPE sources; the number available from any activity depends on the specific program.
Report CPE in MyISACA using the certification-management process and retain documentation for 12 months following the end of each three-year reporting cycle. Schedule a recurring review of your CPE record, annual requirement and maintenance-fee status.
ISACA states that the annual maintenance fee is US$45 for members and US$85 for non-members, and that payment is due annually by 1 January to renew through the upcoming calendar year. Verify the current fee and renewal instructions in the official maintenance page before payment. Failure to comply with certification requirements can result in revocation.
A final decision checklist for candidates
Register when you can identify your experience path, understand the current domain outline, have a realistic study sequence and can use the eligibility period responsibly. Delay the purchase when you have not checked the experience requirements, cannot explain the four domains or are relying on memorized unauthorized content.
Before registration, confirm: your likely coverage of at least three domains; at least one year of Domain 1 experience if you intend to apply; the current fee; the 365-day eligibility period; and the delivery option that suits your circumstances.
During preparation, confirm: your notes follow the official outline; your practice includes all four domains; your error log distinguishes knowledge from judgment problems; and your answers explain accountability, alignment, evidence, outcomes and risk.
After passing, confirm: official scores have been released; your application evidence is organized; the US$50 application processing fee is understood; and you apply within five years of passing. After certification, confirm: at least 20 CPE hours are earned and reported annually, 120 CPE hours are earned and reported during the three-year reporting period, the annual maintenance fee is handled and audit documentation is retained.
The next practical action is to open the official CGEIT exam content outline, map your recent responsibilities to its four domains and mark the first three topics that require study. That short diagnostic will tell you more about readiness than collecting another unverified set of questions.
Official pages to keep open
Use the content outline for domains, tasks and weightings; the certification page for registration and scheduling; the get-certified page for experience and application steps; the exam candidate guides for candidate instructions; the review-manual page for the official preparation reference; the support article for registration-cost and eligibility information; and the maintenance page for CPE, fees and audit obligations.
These pages are the appropriate checkpoints for time-sensitive details. If a price, process, appointment rule or storefront instruction changes, follow the current official page rather than an archived guide or a third-party summary.
Conclusion
CGEIT preparation is strongest when it combines the official blueprint with disciplined governance reasoning. Start with the 40% Governance of Enterprise IT domain, but build connections to resources, benefits and risk instead of studying each area in isolation. Check the experience and application requirements before registering, use the 365-day eligibility period deliberately, verify PSI arrangements through ISACA and plan maintenance from the outset. A focused diagnostic, an error log and a domain-based roadmap provide a practical next step without depending on unauthorized exam content.