GRC Careers
Home › Certifications › CRISC

CRISC Certification

Certified in Risk and Information Systems Control  ·  ISACA  ·  IT & Enterprise Risk

CRISC is ISACA's certification for professionals who identify, assess, and respond to IT and enterprise risk and design the controls that manage it. It is aimed at risk, control, and IT-governance practitioners.

Exam at a Glance

Domains
4 (below)
Exam Fee
$575 member / $760 non-member
Format
Computer-based, multiple choice
Questions
150 (ISACA standard)
Duration
4 hours (ISACA standard)
Passing Score
450 on a 200 to 800 scale
Experience
Required — see ISACA
Maintenance
ISACA CPE policy — see ISACA

Exam fee and domains verified 2026-08-06 against ISACA. ISACA uses a common exam format across its certifications (150 questions, 4 hours, 450 on a 200 to 800 scale). Confirm the current CRISC experience requirement and CPE policy at isaca.org before you register.

Overview

CRISC certifies that you can find IT and enterprise risk, size it, decide how to respond, and build and monitor the controls that keep it in check. It is written from the point of view of the professional who owns risk decisions, not only the engineer who implements a control.

The credential sits at the governance and risk layer of technology work. It pairs naturally with security and audit credentials and is widely recognized in financial services, insurance, healthcare, and any regulated, risk-heavy industry.

The Exam Domains

Domain 1 — Corporate IT Governance

Aligning IT risk and control with enterprise governance, strategy, and business objectives.

Domain 2 — IT Risk Assessment

Identifying, analyzing, and evaluating IT and enterprise risk so it can be owned and treated.

Domain 3 — Risk Response & Reporting

Selecting and implementing risk responses, and monitoring, communicating, and reporting on risk and controls.

Domain 4 — Information Technology & Security

The technology and security concepts that underpin sound risk and control decisions.

Who CRISC Is For

Browse live GRC and risk jobs →Hand-reviewed governance, risk, and compliance roles on GRC Careers
📘 Preparing for the exam? Review the official CRISC exam content outline and requirements on the ISACA official page →

Related Certifications

Frequently Asked Questions

What is the CRISC certification?

CRISC, Certified in Risk and Information Systems Control, is an ISACA certification for professionals who identify, assess, respond to, and monitor IT and enterprise risk, and who design the controls that manage it.

What are the CRISC domains?

CRISC covers four domains: Corporate IT Governance; IT Risk Assessment; Risk Response and Reporting; and Information Technology and Security.

How much does the CRISC exam cost?

The exam fee is $575 for ISACA members and $760 for non-members, as listed by ISACA. A separate certification application applies after you pass.

Is there an experience requirement for CRISC?

Yes. ISACA requires demonstrated work experience in IT risk and control to be certified. Confirm the current requirement and any waivers on the ISACA CRISC page.

How should I prepare for CRISC?

Study ISACA's official CRISC exam content outline and review manual, and use reputable published study materials. Do not use braindump sites; they violate exam rules and are often inaccurate.

Official Resources

CRISC and ISACA are trademarks of ISACA. GRC Careers is not affiliated with, endorsed by, or accredited by ISACA. This page is an independent study aid and contains no real exam questions.

Educational reference only and not legal, compliance, or certification advice. © 2026 GRC Careers · AI-Governance-Jobs.com · From the GRC Careers network.