CRISC Exam Guide: Domains, Eligibility, Scheduling and a Practical Study Roadmap
The Certified in Risk and Information Systems Control (CRISC) certification validates the ability to manage IT risk, support business resilience, create stakeholder value and contribute to enterprise risk management. It is relevant to professionals working in information systems risk, controls, security, governance and related assurance roles. This guide helps you make three practical decisions: whether your experience matches the certification requirement, which domains deserve the most study time, and when you are ready to register and schedule the exam. It focuses on official requirements and sound preparation methods rather than leaked questions, exam dumps or memorization shortcuts.
What does CRISC validate?
CRISC is designed around practical risk and information systems control work rather than isolated technology knowledge. ISACA describes the certification as validating expertise in IT risk management, business resilience, stakeholder value and enterprise risk management. The exam therefore asks you to connect governance, risk analysis, response decisions, reporting and technology controls to business objectives.
A useful way to understand the credential is to follow the risk lifecycle. An organization establishes direction and accountability, identifies and evaluates risk, chooses and reports responses, and then relies on technology and security controls to support the desired risk position. Strong preparation should show how those activities influence one another instead of treating the domains as unrelated chapters.
The official content outline says that the domains, subtopics and tasks were developed through research, feedback and validation from subject matter experts and industry leaders. That matters for study planning: learn the work represented by each task, not just definitions copied into flashcards.
Who should consider this certification?
CRISC is a sensible fit for professionals whose work involves identifying, assessing, treating, monitoring or reporting information systems risk and controls. Typical relevant backgrounds include IT risk, control assessment, information security, governance, compliance, audit and operational resilience. The deciding factor is the substance of your responsibilities, not whether your job title contains the word risk.
The exam is open to anyone interested in information security, and candidates may sit for it before meeting the experience requirement. Passing the exam does not by itself make the candidate CRISC certified; the certification application must also demonstrate the applicable experience and satisfy ISACA’s other requirements.
For candidates passing the exam after November 2025, ISACA’s requirements page states that certification requires verified evidence of three years of CRISC work experience in both Domain 2 Risk Assessment and Domain 3 Risk Response and Reporting. The same source states that, for those post-November-2025 exam passers, the experience has no substitutions or waivers and must be gained within the 10 years before application or within five years after initially passing the exam.
Before paying for an exam appointment, map your actual work to the two required domains if the post-November-2025 rule applies to you. Record projects, responsibilities, dates and supervisors who can verify the work. This avoids the common mistake of preparing for and passing the exam before discovering that the certification application cannot be supported.
What are the four CRISC exam domains?
The current CRISC exam contains 150 questions across four job-practice domains. The current domain weightings are Governance 26%, Risk Assessment 22%, Risk Response and Reporting 32%, and Technology and Security 20%. Use the labels with the percentages when planning study time; a percentage without its domain name is not a useful preparation instruction.
Domain 1 — Governance — 26%: This domain addresses the organization’s business and IT environments, strategy, goals and objectives, and the possible or realized effects of IT risk on business objectives and operations. It also includes Enterprise Risk Management and the Risk Management Framework.
Domain 2 — Risk Assessment — 22%: This domain focuses on understanding risk, analyzing risk and evaluating the current risk environment. A key task is to identify the current state of existing controls and evaluate their effectiveness for information system risk treatment. Another is reviewing risk or control analysis results to assess gaps between current and desired states of the risk environment.
Domain 3 — Risk Response and Reporting — 32%: This is the largest current domain. Prepare to reason through risk response choices, control response decisions, monitoring, communication and reporting. The emphasis is not simply naming a response; it is selecting an appropriate action in relation to risk, business priorities, control effectiveness, accountability and the desired risk state.
Domain 4 — Technology and Security — 20%: This domain connects technology and security considerations with risk and control objectives. Study how technology architecture, systems, data, infrastructure, security practices and control operation affect the organization’s ability to manage risk.
The weightings should influence your schedule, but they should not make you neglect a domain. The four areas form a sequence: governance defines direction, assessment establishes the risk picture, response and reporting guide decisions, and technology and security provide much of the operating context. A weakness in one area can make scenario-based questions in another harder to interpret.
How should you interpret the content outline?
Read every domain as a set of decisions and work products. A task such as evaluating control effectiveness requires you to ask what the control is intended to achieve, what evidence indicates whether it works, what risk remains and what treatment follows. This approach is more useful than memorizing the task statement alone.
Create a four-column study map with the domain, subtopic, task and an example from a real or hypothetical organization. For each task, write the decision-maker, the input information, the desired outcome and the evidence that would support the conclusion. Keep the examples generic and educational; do not attempt to reproduce live exam content.
For the control-effectiveness task, your notes might distinguish design effectiveness from operating effectiveness, then connect the conclusion to treatment. For the gap-analysis task, describe the current state, desired state, material gap, risk implication and recommended next action. This turns official wording into a repeatable reasoning process.
Do not assume that a familiar framework or tool is a substitute for understanding. A candidate may know terminology from audit, security or compliance work and still miss a question if the answer ignores business objectives, risk ownership or the sequence of assessment and response. When reviewing an answer, explain why the best option fits the scenario and why the alternatives are weaker.
Which study sequence works best?
Start with the official exam content outline, then study in the order that builds judgment: Governance, Risk Assessment, Risk Response and Reporting, and Technology and Security. Finish with integrated practice that moves across all four domains. This sequence gives later response decisions a clear organizational and risk context.
First, establish the vocabulary and relationships. Define business objectives, risk appetite, risk ownership, control objectives, current state, desired state, residual risk, treatment and reporting in your own words. Avoid building a glossary that has no examples. Attach each term to a decision or deliverable.
Next, study Governance with a business-first lens. Ask how strategy, objectives, accountability and enterprise risk management shape technology risk decisions. Then study Risk Assessment by practicing identification, analysis, evaluation and control-effectiveness judgments. Your notes should show how evidence changes the risk view.
Move to Risk Response and Reporting only after you can describe the assessed risk clearly. Compare response choices according to their fit with the organization’s objectives, authority, resources and risk position. Include monitoring and reporting because a response is not complete if nobody knows its status or whether it is working.
Study Technology and Security as an application domain. Instead of memorizing technology categories in isolation, ask how a system, service, data flow or security control changes exposure, control performance, resilience or reporting. This keeps the domain connected to CRISC’s risk-management purpose.
Use the final phase for mixed practice. Alternate a governance scenario with an assessment scenario, then a response scenario and a technology scenario. The goal is to recognize which decision the question is testing and to select the answer that best follows the risk-management logic, not the answer containing the most technical language.
A six-stage roadmap
Stage one is an eligibility and baseline review. Read the current official requirements, list your relevant work and take an honest diagnostic using legitimate practice material. Mark each result as knowledge gap, reading error, reasoning error or careless error.
Stage two is domain orientation. Read the outline from beginning to end and create a one-page map of the four domains. Do not allocate all your time to the most familiar subject; familiarity can hide gaps in governance or response judgment.
Stage three is focused learning. Work through one domain at a time, using short notes, diagrams and scenario explanations. After each study session, answer the question: what action would a risk professional take, and what evidence supports it?
Stage four is application. Use practice questions only after learning the relevant concepts. For every missed item, write the governing principle, the clue you overlooked and the reason each distractor fails. Revisit the source material rather than simply recording the correct letter.
Stage five is integration. Mix all domains and practice switching from business context to risk assessment, response and technology implications. This is where you test whether your knowledge transfers across scenarios.
Stage six is readiness and logistics. Confirm your eligibility, review the candidate guidance, check the available delivery route and testing location, schedule only when your performance is stable, and prepare a final review focused on recurring errors rather than new topics.
How can working professionals use limited study time?
Use a study plan that measures outputs, not hours. Each session should produce something you can inspect: a domain map, a comparison table, a corrected practice set, a control-analysis example or a short explanation of a risk decision. This makes preparation practical when work schedules change.
If you have strong audit or controls experience, spend extra effort on enterprise context, risk ownership, business objectives and response selection. If your background is security or infrastructure, deliberately practice governance, business impact and reporting. If you work in compliance, strengthen technical-control interpretation and risk-analysis reasoning.
A useful weekly rhythm has three parts: learn a limited topic, apply it to scenarios, and review mistakes from earlier sessions. Keep an error log with four fields: question focus, your chosen reasoning, the better reasoning and the rule you will apply next time. Review the log at increasing intervals rather than rereading the entire manual every time.
Use realistic but invented scenarios such as a critical service with weak access controls, a supplier whose control evidence is incomplete or a business unit requesting an exception. State the objective, identify the risk, assess current controls, compare the current and desired states, choose a response and identify the report recipient. These exercises develop the judgment the outline describes without implying access to exam questions.
Protect the last part of your preparation from resource overload. One authoritative outline, one coherent learning source and a reliable practice method are easier to evaluate than many disconnected summaries. ISACA states that it offers group training, self-paced training and study resources in various languages; use the official preparation and candidate-guide pages to compare options that suit your schedule and study needs.
What exam and scheduling details should you verify?
CRISC exams are computer-based and are administered at authorized PSI testing centers globally or as remotely proctored exams. Registration and payment are required before scheduling. Because appointment availability and administration policies can change, confirm the current details in ISACA’s candidate guidance and the PSI scheduling flow before committing to a date.
The listed CRISC exam registration fee is US$575 for ISACA members and US$760 for non-members. The one-time CRISC certification application processing fee is US$50. These are separate decisions: exam registration permits the testing process, while the application fee belongs to the certification application after the required exam result is available.
Candidates can schedule a testing appointment as early as 48 hours after payment of exam registration fees. ISACA also states that CRISC appointments are only available 90 days in advance. If a desired site or date is not visible more than 90 days in advance, check again closer to the preferred date rather than assuming the appointment is unavailable permanently.
To schedule, log in to your ISACA Account, open Certification & CPE Management and select the exam scheduling option; ISACA’s instructions then direct candidates to the PSI dashboard. The CRISC page specifically states: on the PSI dashboard, click Schedule Exam.
Rescheduling is permitted during the eligibility period without penalty when completed a minimum of 48 hours before the scheduled testing appointment. Review the current scheduling guide before changing an appointment, particularly if you are using remote proctoring or requesting accommodations.
Beginning November 3, 2025, ISACA no longer offers the CRISC exam in Chinese or Korean. Do not rely on an older preparation page or a third-party language list. Verify the language options and current administration instructions in the official materials linked from ISACA’s CRISC and exam candidate-guide pages.
How do you move from passing the exam to certification?
Passing the exam is one step in the CRISC certification process. The official sequence also requires the application, experience evidence, adherence to ISACA’s Code of Professional Ethics and adherence to the Continuing Professional Education Policy. Plan the application before exam day so that your experience records and verifiers are ready when official scores are released.
Once official exam scores have been released, candidates may pay the application fee and apply for certification. Candidates have five years from the passing date to apply. The experience must be gained within the 10-year period preceding the application date for certification, subject to the specific current requirements for the exam-passing cohort.
The general certification page states that a minimum of 3-years of professional information systems auditing, control or security work experience, as described in the CRISC job practice areas, is required for certification. The support requirement page adds the more specific rule for candidates passing after November 2025: verified evidence of three years in both Domain 2 Risk Assessment and Domain 3 Risk Response and Reporting, with no substitutions or waivers for that group.
Prepare evidence in a way that a reviewer can understand. For each role, describe the risk or control responsibility, the systems or business process involved, the decisions you made, the period of work and the person who can verify it. Avoid vague descriptions such as “worked on security”; identify the risk-management activity instead.
After passing, log in to MyISACA to access the application processing fee and the application forms. ISACA also provides non-English CRISC application forms for candidates who passed the exam from August 2021 until the present. Use the current form and instructions rather than an archived copy.
What should you budget beyond the exam fee?
Budget for three separate categories: exam registration, the one-time certification application and ongoing maintenance. The official listed CRISC exam registration fee is US$575 for ISACA members and US$760 for non-members, while the one-time application processing fee is US$50. Maintenance begins after certification and is governed by ISACA’s current policy.
The annual CRISC maintenance fee is US$45 for ISACA members and US$85 for non-members. This payment is due annually by 1 January and is required to renew through the upcoming calendar year. The payment button appears in the Certification Dashboard when fees are due.
Study resources are a separate choice. ISACA lists a CRISC Review Manual in print and digital versions, preparation resources, training and a practice-question product. Compare the resource’s purpose before buying: a manual supports learning, a course supplies structure, and practice questions reveal reasoning gaps. No practice resource should be treated as a source of real future exam questions or a guarantee of passing.
Check the official cost and certification pages immediately before payment because storefront, fee and policy information is time-sensitive. A third-party page may retain an old amount or an old application rule even when the official process has changed.
How do you maintain CRISC after certification?
Maintaining CRISC requires continuing education, annual maintenance payment, compliance with ISACA’s professional ethics requirements and accurate CPE reporting. Treat maintenance as an operating obligation from the date of certification, not as a task to postpone until the end of a reporting cycle.
Maintaining CRISC requires at least 20 CPE hours annually and 120 CPE hours during each three-year reporting period. The annual minimum must be reported, and the CPE should be appropriate to maintaining the knowledge or ability needed to perform CRISC-related tasks.
ISACA describes several ways to earn CPE, including conferences, webinars and online training, on-demand learning, training courses and skills-based labs, and volunteer activity. The amount available varies by activity, so read the current maintenance policy and retain evidence for each completed activity.
Those selected for a CPE audit must provide supporting documentation for all reported activities from a specific calendar year. Documentation should be retained for 12 months following the end of each three-year reporting cycle. Store certificates, attendance records, completion confirmations and relevant descriptions in a consistent folder or tracking system.
Failure to comply with certification requirements can result in revocation of the CRISC designation. Put annual reminders in your calendar, record CPE soon after completing it and review the dashboard before the annual fee deadline. This is simpler than reconstructing several years of professional-development evidence.
ISACA also describes non-practicing and retired status for individuals who qualify. If your work situation changes, review the official maintenance page to determine whether one of those statuses applies rather than allowing fees or CPE obligations to lapse without checking the policy.
Which mistakes most often weaken preparation?
The most damaging preparation errors are usually process errors: studying the wrong blueprint, ignoring the experience rule, using answer memorization instead of reasoning, and leaving scheduling or maintenance details until the last moment. Correct these before adding more study material.
Mistake one is treating all domains as equally weighted without using the labels. Risk Response and Reporting is 32%, Governance is 26%, Risk Assessment is 22% and Technology and Security is 20%. Allocate attention accordingly, while still studying every domain because the exam covers all four.
Mistake two is confusing exam eligibility with certification eligibility. You may sit for the exam before meeting the experience requirement, but certification requires the applicable experience and other obligations. Candidates passing after November 2025 should examine the specific Domain 2 and Domain 3 experience rule before registering.
Mistake three is learning controls as technical objects rather than as risk treatments. When reviewing a control, ask what risk it addresses, what objective it supports, how effectiveness is evaluated and what residual gap remains. This is especially important for questions involving current and desired states.
Mistake four is choosing an answer because it sounds authoritative or technical. Prefer the option that addresses the question’s decision, respects governance and ownership, uses appropriate analysis and connects the response to business objectives. Technical detail is useful only when it answers the scenario.
Mistake five is relying on dumps, leaked questions or memorized answer keys. Such material is not a dependable way to learn the job practices, may be inaccurate or unauthorized, and cannot substitute for understanding. Use official outlines, candidate guidance, structured learning and legitimate practice explanations instead.
Mistake six is scheduling too early because a single practice score looks good. Readiness is stronger when you can explain missed answers, perform consistently across all domains and complete mixed practice without depending on recall of a particular item.
What should you do in the final review week?
Use the final week to consolidate decisions, not to begin a new library of resources. Review your domain map, error log, key distinctions and scheduling instructions. Confirm that your appointment, identification requirements and delivery route are consistent with the current official candidate guidance.
Revisit Governance and Risk Assessment together. Practice explaining how objectives and risk context affect the evaluation of existing controls. Then connect the result to a current-versus-desired-state gap and a defensible treatment decision.
Review Risk Response and Reporting with particular attention to ownership, prioritization, monitoring and communication. Ask who needs the information, what decision it supports and how the response will be evaluated. Avoid reducing the domain to a list of response labels.
Finish with Technology and Security scenarios that require risk interpretation rather than product trivia. For each scenario, identify the asset or service, the relevant exposure, the control objective and the business consequence. Then check whether your proposed action fits the organization’s risk position.
On the final day, stop when further study becomes unfocused. Recheck the PSI appointment and any applicable rescheduling rule, prepare the materials permitted by the official instructions and avoid seeking purported live questions. Your final advantage comes from clear reasoning and reliable logistics, not last-minute volume.
What is the next action for a CRISC candidate?
Your next action should depend on the gap you find: verify experience, map the blueprint, build a study schedule or complete the registration workflow. Do not pay or schedule simply because the credential is relevant; first confirm that the certification path and your preparation evidence are realistic.
If you are still deciding, read the official CRISC content outline and requirements page, then map your work to Governance, Risk Assessment, Risk Response and Reporting, and Technology and Security. For post-November-2025 exam passers, pay particular attention to the verified Domain 2 and Domain 3 experience requirement.
If you are preparing, create the four-domain study map, prioritize the officially weighted domains, and start an error log with legitimate practice material. Use scenario explanations to test your ability to connect business objectives, risk assessment, control effectiveness, treatment and reporting.
If you are ready to register, confirm the current fee, delivery option, language information, candidate guidance and PSI availability through ISACA. Remember that registration and payment are required before scheduling, appointments are available only within the stated scheduling window, and an appointment can be rescheduled without penalty only when the official minimum notice is met.
If you have passed, organize your verification evidence, pay the application processing fee through MyISACA and submit the application within five years of the passing date. After certification, create an annual CPE and maintenance calendar so that the credential remains an active professional commitment rather than a one-time exam result.
Conclusion
CRISC preparation is strongest when it mirrors the work the certification represents: understand the business context, assess risk and controls, choose and report an appropriate response, and connect technology and security decisions to the desired risk environment. Verify the current requirements before registering, use the domain labels and weightings to organize study, and keep experience and maintenance records from the beginning. Official ISACA guidance remains the authority for fees, scheduling, delivery, candidate policies, application requirements and continuing certification obligations.