ISA Certification Overview: How to Choose Between ISACA, ISSAP and ISA/IEC 62443 Paths
“ISA” does not identify one unified certification vendor in the official material available for this overview. The term appears in several technology and security contexts: ISACA’s CISA and broader credential portfolio, ISC2’s ISSAP security-architecture certification, and ISA/IEC 62443 industrial-control-system standards referenced by AWS. This guide separates those paths, explains who each one serves, outlines verified requirements and maintenance obligations, and offers a practical way to decide whether your next step belongs in IT audit, security architecture, governance, or industrial automation security.
Start by identifying which “ISA” path you mean
The first decision is whether your target is an ISACA credential, the ISC2 ISSAP certification, or an ISA/IEC 62443 standards-based industrial security path. These are related to information security, but they are not interchangeable credentials and they are not administered by one common “ISA” certification body.
ISACA’s official certification catalogue includes CISA, CISM, CRISC, CGEIT, CDPSE, CCOA, CCA, CCI, CCP and LCCA, along with additional advanced credentials and certificates. The catalogue therefore represents a broad professional credential ecosystem rather than a single “ISA” qualification. See the official ISACA certification catalogue at https://www.isaca.org/credentialing/certifications.
ISC2’s ISSAP stands for Information Systems Security Architecture Professional. It is aimed at experienced security architects and professionals who design security solutions and provide risk-based guidance to management. Its official information is separate from ISACA’s certification pages: https://www.isc2.org/certifications/issap.
In industrial automation, ISA/IEC 62443 refers to standards developed jointly by ISA99 and IEC. AWS explains that the standards are intended to build cybersecurity robustness and resilience into industrial automation and control systems, with objectives that include improving safety, availability, integrity and confidentiality. That is a standards context, not evidence of a single general-purpose “ISA certification” administered through the pages supplied here: https://aws.amazon.com/blogs/iot/guidance-on-using-isa-iec-62443-for-iiot-projects/.
A useful next step is to write down the role or work problem you want the credential or standard to support. If the answer is auditing and assessing systems, investigate CISA. If it is enterprise security architecture, investigate ISSAP. If it is industrial control or automation security, research the applicable ISA/IEC 62443 training and assessment options through the relevant official body rather than assuming that an ISACA or ISC2 credential covers the same syllabus.
Choose CISA when your work centers on audit, controls and assurance
CISA is the clearest fit in the supplied evidence for professionals whose work involves auditing, monitoring and assessing information systems. ISACA defines CISA as Certified Information Systems Auditor and describes its focus as auditing, monitoring and assessing IT and business systems: https://www.isaca.org/credentialing/cisa.
The CISA scope covers five stated areas: the information-systems auditing process; governance and management of information technology; information-systems acquisition, development and implementation; information-systems operations and business resilience; and protection of information assets. This makes CISA more than a narrow technical-security exam. It connects assurance work with governance, implementation, operations, resilience and information protection.
CISA is consequently relevant to people who evaluate whether controls are designed appropriately, operate effectively and support organizational objectives. It can also suit professionals moving between internal audit, IT risk, compliance, control assessment and information-security assurance. The deciding factor should be the substance of your current or intended work, not the abbreviation alone.
CISA should not be treated as a generic entry-level cybersecurity badge. ISACA’s stated certification requirement is at least five years of professional information-systems auditing, control or security work experience. The experience must be gained within the 10-year period preceding the application date for certification: https://www.isaca.org/credentialing/cisa/get-cisa-certified.
ISACA also states that candidates must pass the CISA exam within the prior five years and meet the applicable experience requirements. Candidates have five years from passing the exam to apply. This creates a planning window, but it does not remove the need to document qualifying experience before certification is awarded.
CISA’s formal sequence is exam, fee, application and compliance
The official CISA process requires candidates to pass the exam, pay the one-time US$50 application-processing fee, submit an application demonstrating the experience requirement, adhere to the Code of Professional Ethics, follow the Continuing Professional Education Policy and comply with the Information Systems Auditing Standards. ISACA states that the application fee is paid after official exam scores have been released: https://www.isaca.org/credentialing/cisa/get-cisa-certified.
This distinction matters when budgeting and scheduling. Passing the exam is a required step, but it is not by itself the complete certification process. Readers should retain experience records and check the current application instructions before assuming that an exam pass automatically grants the credential.
CISA exam registration and payment are required before scheduling and taking the exam. ISACA says candidates have a six-month eligibility period to take the exam after registration, while appointments are only available 90 days in advance. If a desired site or date is not visible more than 90 days ahead, ISACA advises checking again closer to the intended date: https://www.isaca.org/credentialing/cisa.
The supplied ISACA page lists US$575.00 as the member exam cost and US$760.00 as the non-member exam cost. Because exam pricing and administrative arrangements can change, verify the current amount in the official registration flow before purchase. The application-processing fee is a separate US$50 charge supported by ISACA’s certification requirements page.
CISA maintenance should be part of the decision from the beginning
CISA is a continuing professional obligation, not a one-time exam event. ISACA requires CISA holders to report at least 120 continuing professional education hours over a three-year reporting period, including at least 20 hours each year: https://www.isaca.org/credentialing/cisa/get-cisa-certified.
That requirement favors candidates who can realistically maintain a learning record alongside their job. Before selecting CISA, ask how you will obtain relevant education, record it and meet the annual minimum. ISACA points candidates toward CPE, team training, virtual workshops, chapter events, resources and professional communities on its CISA pages.
For scheduling flexibility, ISACA states that a CISA appointment may be rescheduled without penalty during the eligibility period when the change is made at least 48 hours before the scheduled testing appointment. Candidates should still confirm the current terms and appointment instructions in their account before relying on a particular arrangement: https://www.isaca.org/credentialing/cisa.
Choose ISSAP when security architecture is the professional target
ISSAP is the more direct path for an experienced professional who designs security solutions, analyzes architecture and gives risk-based guidance to senior management. ISC2 describes the Information Systems Security Architecture Professional as a security leader who aligns security solutions with organizational context and goals: https://www.isc2.org/certifications/issap.
The credential is intended for roles such as system architect, chief technology officer, system and network designer, business analyst and chief security officer, according to ISC2’s overview. Those examples point to a design and decision-making responsibility rather than a primary focus on audit testing or day-to-day security administration.
ISSAP is therefore a sensible path when your work requires you to connect governance, risk, architecture, infrastructure, systems and identity design. It is less directly aligned with someone whose main responsibility is testing controls against an audit program, unless that person also has the architecture background and experience required by ISC2.
The current ISSAP outline identifies four domains: Governance, Risk, and Compliance; Security Architecture Modeling; Infrastructure and System Security; and Identity and Access Management Architecture. The outline is effective August 1, 2025: https://www.isc2.org/certifications/issap/issap-certification-exam-outline.
ISSAP has two documented experience routes
ISC2 states that one route requires a CISSP in good standing plus two years of cumulative, full-time experience in one or more of the four current ISSAP domains. An alternative route requires a minimum of seven years of cumulative, full-time experience in two or more of those domains.
The outline also states that a post-secondary degree in computer science, information technology or a related field, or an additional credential from the ISC2 approved list, may satisfy one year of required experience. Only one year can be waived. Part-time work and internships may also count toward the experience requirement, subject to ISC2’s rules.
These routes make ISSAP a poor match for someone seeking a first technology credential with no substantial architecture or security background. A candidate who does not hold CISSP should compare their documented experience against at least two ISSAP domains and confirm how any education or other credential would be treated before registering.
ISC2 says ISSAP complies with the requirements of the ANSI National Accreditation Board ISO/IEC Standard 17024. That accreditation statement describes the credential’s conformity framework; it does not replace the experience assessment or guarantee that the certification is appropriate for a particular job.
The ISSAP exam outline should drive preparation
The official outline is the correct starting point for ISSAP preparation because it defines the domains and examination information. ISC2 lists an exam length of 3 hours, 125 items, multiple-choice and advanced item types, a passing grade of 700 out of 1000 points, English availability and Pearson VUE testing centers: https://www.isc2.org/certifications/issap/issap-certification-exam-outline.
The domain weights supplied by ISC2 are Governance, Risk, and Compliance at 21%, Security Architecture Modeling at 22%, Infrastructure and System Security at 32%, and Identity and Access Management Architecture at 25%. Those figures should be used to allocate study attention, while still covering all four domains rather than treating the largest domain as the entire exam.
A disciplined preparation approach begins with a gap review against each domain. For every topic, distinguish between knowing terminology, explaining architectural trade-offs and applying risk-based judgment. Architecture credentials reward the ability to relate design decisions to organizational requirements, security objectives and operational constraints; memorizing isolated definitions is not a substitute for that understanding.
ISC2 encourages candidates to supplement education and experience by reviewing relevant resources connected to the current outline and identifying areas requiring additional attention. Candidates should also review ISC2 examination policies and procedures before registering. Use the current outline and policy pages rather than relying on an old course description or question bank.
ISSAP training offers different levels of structure
ISC2 lists adaptive learning, online self-paced training and online instructor-led training for ISSAP. The choice should reflect how much structure and interaction you need, not an assumption that one format is inherently superior: https://www.isc2.org/certifications/issap.
The official training information includes online self-paced access options of 90 days and 180 days, as well as instructor-led options. ISC2 also lists digital eTextbook and study-question access for 365 days from the date of first access. Verify the exact product terms at purchase because access periods belong to individual offerings.
Some ISSAP bundles include Peace of Mind Protection with two exam attempts. ISC2 states that candidates have 180 days from purchase to sit both attempts, with a 30-day waiting period between attempts. These conditions are product-specific and should be checked before purchase rather than assumed to apply to every exam registration.
Official training can help ensure alignment with the current outline, but no course removes the need to understand the experience domains. A practical selection test is whether the provider explains how its material maps to the current four-domain outline and whether the access period fits your study plan.
ISSAP maintenance depends on the route you use
ISC2’s supplied ISSAP information distinguishes maintenance obligations according to whether the holder already has another ISC2 certification. For an ISSAP holder without CISSP, the page states a requirement to earn 60 continuing professional education credits for each three-year term, with credits specific to security architecture. It also states there is no additional annual maintenance fee for earning and maintaining ISSAP in that situation.
The same information states that candidates who already hold an ISC2 certification, excluding Certified in Cybersecurity, do not pay an additional annual maintenance fee for earning and maintaining ISSAP. If the existing certification is Certified in Cybersecurity, the annual maintenance fee increases to a single fee of U.S. $135.
Because maintenance rules can depend on the credential combination, confirm the current ISC2 policy and your personal certification status before treating these details as a final budget. The central decision point is whether you can maintain architecture-focused professional development over each renewal period.
Treat ISA/IEC 62443 as an industrial-security standards direction
ISA/IEC 62443 is the relevant direction when your work concerns industrial automation and control systems rather than general IT audit or enterprise security architecture. AWS describes the standards as developed jointly by ISA99 and IEC to build cybersecurity robustness and resilience into industrial automation and control systems: https://aws.amazon.com/blogs/iot/guidance-on-using-isa-iec-62443-for-iiot-projects/.
AWS says applying ISA/IEC 62443 aims to improve the safety, availability, integrity and confidentiality of industrial automation and control components or systems. This emphasis changes the professional context: plant operations, industrial networks, control components, engineering responsibilities and safety-sensitive availability can all affect how security is designed and assessed.
The supplied sources do not establish a complete ISA/IEC 62443 credential ladder, exam catalogue, eligibility policy, renewal cycle or price schedule. It would therefore be inaccurate to present the standard as a verified, single-vendor certification program in the same way as CISA or ISSAP.
Readers pursuing this direction should first identify the industrial role they hold or want: control-system engineering, automation security, asset-owner responsibility, product development, system integration or assessment. Then confirm which official ISA, IEC or authorized training and assessment route applies. Do not assume that passing CISA or ISSAP demonstrates competence with every ISA/IEC 62443 requirement.
TISAX is a separate automotive information-security assessment context
The supplied AWS TISAX source describes the Trusted Information Security Assessment Exchange as a European automotive-industry information-security assessment. AWS says its ISA catalogue addresses subjects including data protection and third-party connections: https://aws.amazon.com/compliance/tisax/.
TISAX should not be combined casually with CISA, ISSAP or ISA/IEC 62443. It belongs to an automotive supply-chain assessment context, while CISA centers on IT auditing and ISSAP on security architecture. A reader working with automotive customers may need to understand TISAX expectations without seeking a general “ISA certification.”
The practical question is whether your employer or customer requires participation in a specific assessment scheme, evidence against a catalogue, or an individual professional credential. Those are different objectives. Confirm the contracting organization’s exact requirement before spending time on an unrelated exam.
Use role, evidence and maintenance to select a sensible path
The best path is the one whose official scope, eligibility rules and ongoing obligations match the work you need to perform. A simple comparison starts with four questions: What decisions will you make? What evidence of experience can you document? Which subject areas appear in the official outline or standard? Can you maintain the credential or knowledge after the assessment?
Choose CISA if your intended contribution is auditing, control evaluation, IT governance, systems assessment, information-asset protection or business-resilience assurance. Check the five-year professional experience requirement and plan for the exam, application fee, certification application and CPE obligations before registering.
Choose ISSAP if you are already operating at a security-architecture level and need to design solutions, model architecture, address infrastructure and system security, or architect identity and access management. Compare your experience with both ISC2 routes, and use the current domain outline to decide whether the content reflects your responsibilities.
Choose an ISA/IEC 62443 direction if industrial automation and control systems are central to your work. Because the supplied evidence does not define one complete credential program, begin with the standard, the industrial role and the customer or employer requirement. If the requirement is automotive information-security assessment, investigate whether TISAX is the actual target instead.
Do not select a path solely because a search result uses “ISA” in its title. Confirm the administering organization, credential or standard name, experience rules, exam or assessment format, renewal requirements, current cost and official registration page. Ambiguous terminology is itself a reason to verify the target before buying preparation material.
A practical readiness check for CISA candidates
Before CISA registration, map your work history to information-systems auditing, control or security responsibilities and identify which period falls within the permitted experience window. Separate duties that provide direct evidence from adjacent work that may not qualify. If the record is unclear, ask ISACA for an eligibility interpretation rather than relying on a reseller’s summary.
Then compare your knowledge with the five CISA focus areas. A candidate may be strong in technical security but need additional work in governance, acquisition and implementation, operations, resilience or audit methodology. Preparation should correct those gaps rather than concentrate only on familiar security topics.
Use ISACA’s official CISA candidate information, exam details, review manual, online review course and practice resources as the baseline. ISACA lists a CISA Review Manual, 28th Edition 2024, a free practice quiz with 10 questions and a questions-and-explanations database containing 1,070 questions with a six-month subscription. Verify current product availability and edition details before purchase: https://www.isaca.org/credentialing/cisa.
Practice questions can reveal weak areas, but they should support understanding of the job practice rather than encourage memorization of recalled exam content. No question bank or unofficial material can guarantee a passing result.
A practical readiness check for ISSAP candidates
For ISSAP, start with experience rather than a shopping list of courses. Record projects in which you designed, reviewed or governed security architecture, then map each project to one or more of the four current domains. This exercise can show whether the CISSP-plus-two-years route or the seven-year alternative is more plausible.
Next, read the current outline from beginning to end and mark each topic as familiar, partly familiar or unfamiliar. Give particular attention to the 32% Infrastructure and System Security domain while continuing to study the other three domains, whose official weights are 21%, 22% and 25%.
Use architecture exercises to test readiness: explain why a design satisfies organizational and regulatory requirements, identify risks created by a proposed control, describe how identity decisions affect system trust, and evaluate how infrastructure choices influence security and resilience. These are practical recommendations for studying, not additional ISC2 eligibility requirements.
Finally, review ISC2’s policies, testing arrangements and training access terms before purchase. Keep the exam purchase window, course access period and any retake conditions distinct; they are not automatically the same product benefit.
Preparation resources should be judged by alignment, not promises
A credible preparation plan begins with the administering organization’s current outline and requirements. Official resources establish what the credential covers; training helps organize learning; experience supplies the professional context. None of these should be replaced by claims that memorizing leaked questions or using exam dumps guarantees success.
For CISA, ISACA provides exam information, a candidate guide, official review products, practice material, online instruction and links to CPE and professional resources. The CISA page also directs candidates to scheduling guidance, remote-proctoring information, special-accommodation information and the PSI dashboard. Use those resources to confirm the current process rather than depending on a third-party checkout page.
For ISSAP, ISC2 provides the current outline, supplementary-reference guidance, policy links, adaptive learning, self-paced training and instructor-led training. Compare any external course against the outline effective August 1, 2025 and check whether the provider clearly identifies the four domains and current examination format.
For ISA/IEC 62443, the supplied AWS material is useful for understanding the industrial-security purpose of the standards, but it is not a complete individual certification handbook. Locate the official standards, training provider or assessment body relevant to your industrial role and verify the route directly.
Questions to ask before paying for an exam or course
Ask which organization issues the credential or standard recognition. “ISA” by itself is not enough evidence of an administering body in the supplied sources.
Ask what the exact credential name is and whether the purchase is for an exam, a course, an assessment, a membership benefit or a bundle. CISA, ISSAP, ISA/IEC 62443 and TISAX serve different purposes.
Ask whether you satisfy the official experience requirement. CISA requires at least five years of specified professional experience; ISSAP has the CISSP-plus-two-years route or the seven-year route described by ISC2.
Ask which version of the outline or standard the material follows. Time-sensitive content should be checked against the official page immediately before registration.
Ask what happens after a pass. CISA requires an application and continuing education; ISSAP has continuing-education and fee conditions that depend on certification status; a standards-based industrial route may have its own assessment or training rules.
Ask how long access or eligibility lasts. Examples in the supplied sources include CISA’s six-month exam eligibility period, ISSAP product-specific access periods and the ISSAP exam purchase window. Do not transfer one vendor’s timeline to another path.
Ask where the exam or assessment is delivered and what rescheduling or retake rules apply. ISACA and ISC2 publish different arrangements, so use the applicable official policy.
Ask whether the credential supports the actual work requirement. A certificate that sounds similar to an employer or customer requirement may still address a different role, industry or assessment objective.
Final direction: resolve the acronym before building a study plan
There is no single verified “ISA” ecosystem in the supplied official evidence. The sensible route depends on what the acronym represents in your situation: ISACA’s audit and governance credentials, ISC2’s ISSAP security-architecture certification, ISA/IEC 62443 industrial-control standards, or the TISAX automotive assessment context.
For most readers comparing individual professional credentials, the immediate fork is straightforward: investigate CISA for information-systems audit and assurance work, and investigate ISSAP for experienced security-architecture work. For industrial automation or automotive supply-chain requirements, begin with the applicable standard or assessment scheme instead of assuming either credential is a substitute.
Once the target is confirmed, use the official outline, eligibility requirements, registration instructions, maintenance policy and current product terms to create a plan. That evidence-led sequence reduces the risk of preparing for the wrong acronym, buying mismatched material or discovering too late that the experience and renewal obligations do not fit your career direction.
Conclusion
The most important choice is not between similarly named products; it is identifying the organization, role and assessment objective behind “ISA.” CISA, ISSAP, ISA/IEC 62443 and TISAX occupy distinct parts of the information-security landscape. Verify the target first, compare your experience with the official requirements, prepare from the current source material and include maintenance in the decision. That approach gives readers a defensible next step without treating one credential as a universal answer.