CRISC is ISACA's certification for professionals who identify, assess, and respond to IT and enterprise risk and design the controls that manage it. It is aimed at risk, control, and IT-governance practitioners.
Exam fee and domains verified 2026-08-06 against ISACA. ISACA uses a common exam format across its certifications (150 questions, 4 hours, 450 on a 200 to 800 scale). Confirm the current CRISC experience requirement and CPE policy at isaca.org before you register.
CRISC certifies that you can find IT and enterprise risk, size it, decide how to respond, and build and monitor the controls that keep it in check. It is written from the point of view of the professional who owns risk decisions, not only the engineer who implements a control.
The credential sits at the governance and risk layer of technology work. It pairs naturally with security and audit credentials and is widely recognized in financial services, insurance, healthcare, and any regulated, risk-heavy industry.
Aligning IT risk and control with enterprise governance, strategy, and business objectives.
Identifying, analyzing, and evaluating IT and enterprise risk so it can be owned and treated.
Selecting and implementing risk responses, and monitoring, communicating, and reporting on risk and controls.
The technology and security concepts that underpin sound risk and control decisions.
CRISC, Certified in Risk and Information Systems Control, is an ISACA certification for professionals who identify, assess, respond to, and monitor IT and enterprise risk, and who design the controls that manage it.
CRISC covers four domains: Corporate IT Governance; IT Risk Assessment; Risk Response and Reporting; and Information Technology and Security.
The exam fee is $575 for ISACA members and $760 for non-members, as listed by ISACA. A separate certification application applies after you pass.
Yes. ISACA requires demonstrated work experience in IT risk and control to be certified. Confirm the current requirement and any waivers on the ISACA CRISC page.
Study ISACA's official CRISC exam content outline and review manual, and use reputable published study materials. Do not use braindump sites; they violate exam rules and are often inaccurate.