CRISC

What is on the ISACA CRISC exam?

The ISACA CRISC exam is 150 multiple-choice questions in 4 hours, scored from 200 to 800 with 450 to pass. Since 3 November 2025 it has followed the outline effective 2025: four domains weighted 26%, 22%, 32% and 20%, with Risk Response and Reporting the largest by some way.

150Questions
4 hrsTime
450To pass (200 to 800)
32%Largest domain

Every fact below comes from ISACA: the Certification Exam Candidate Guide, version 1.26, the CRISC page and exam content outline, and ISACA's press release of 7 April 2025, all read on 2 October 2026.

What changed in the 2025 outline?

ISACA announced the update in April 2025: the new exam became available on 3 November 2025, with preparation materials from 3 September 2025. Two weights moved by two points. Risk Assessment went up to 22%, "compared to 20 percent previously", and Technology and Security went down to 20%, "compared to 22 percent previously". If your study material predates September 2025, check its weights against the table below.

DomainWeightSubdomains
1. Governance26%Organizational governance; risk governance
2. Risk Assessment22%Risk identification; risk analysis
3. Risk Response and Reporting32%Risk response; control design and implementation; risk monitoring and reporting
4. Technology and Security20%Technology principles; information security principles

Risk Response and Reporting is the only domain with three subdomains, and with Governance it makes up 58% of the exam.

How is the CRISC exam structured and scored?

ISACA rule

150 multiple-choice questions in 4 hours, each with a stem, four options and one best answer, some after a short scenario. There is no penalty for a wrong answer. Scores run from 200 to 800 and 450 or higher passes. Pretest items are included and do not count, and the domain percentages describe the exam's content, not how your score is calculated.

ISACA Certification Exam Candidate Guide v1.26

That is about 1 minute 36 seconds a question. You sit at a PSI test center or online with a remote proctor, in English, Spanish or Japanese. Two breaks of up to ten minutes each are allowed with the proctor's permission, and the timer keeps running. A preliminary result shows on screen, and the official score arrives within 10 working days.

What does the CRISC outline expect you to do?

Beneath the domains, the outline lists 24 supporting tasks. They read like a risk practitioner's job description: build and evaluate risk scenarios, keep the risk register and feed it into the enterprise risk profile, help stakeholders set risk appetite and tolerance, and decide whether a risk exceeds them. Three tasks are about indicators alone: defining key risk indicators (KRIs), refining key performance and key control indicators (KPIs and KCIs) with control owners, and monitoring all three. The last task is to facilitate tabletop exercises that test risk scenarios and responses.

Our suggestion

For the assessment domain, read NIST SP 800-30 Rev. 1, the guide for conducting risk assessments. For the response and control domains, NIST SP 800-37 Rev. 2 and the UK NCSC's risk management guidance give a working vocabulary, and ISACA's own COBIT framework is worth knowing for the governance domain. The exam tests ISACA's outline, so use them to understand it.

What does the CRISC cost, and what are the rules?

Registration is USD 575 for ISACA members and USD 760 for non-members, nonrefundable and nontransferable. From the day you register you have six months to sit, with one six-month extension available for USD 75. Appointments open 90 days ahead, and you can reschedule free until 48 hours before; inside 48 hours you sit or lose the fee.

You get four attempts in a rolling 12 months, waiting 30 days, then 90, then 90, and paying the full fee each time. If you fail, you can ask for a rescore within 30 days of the result for USD 75. ISACA gives no question-level results.

CRISC study planner

ISACA CRISC: study planner

Domain weights come from the CRISC Examination Content Outline, effective 2025, as printed in the ISACA Certification Exam Candidate Guide, version 1.26, read on 2 October 2026. The updated exam has been available since 3 November 2025. ISACA does not recommend a number of study hours; the budgets and the split are our suggestion, in proportion to the published weights.

Hours by domain

DomainWeight50 hours100 hours150 hours
1. Governance26%132639
2. Risk Assessment22%112233
3. Risk Response and Reporting32%163248
4. Technology and Security20%102030
Total100%50100150

No rounding: the weights divide every column exactly.

What 150 questions look like by domain

ISACA publishes percentages, not question counts, and some questions are unscored pretest items. These are our arithmetic on the percentages, as a guide to practice volume.

DomainWeightShare of 150
126%39
222%33
332%48
420%30

Subdomains

DomainSubdomainReadStudiedPracticed
11A Organizational Governance[ ][ ][ ]
11B Risk Governance[ ][ ][ ]
22A Risk Identification[ ][ ][ ]
22B Risk Analysis[ ][ ][ ]
33A Risk Response[ ][ ][ ]
33B Control Design and Implementation[ ][ ][ ]
33C Risk Monitoring and Reporting[ ][ ][ ]
44A Technology Principles[ ][ ][ ]
44B Information Security Principles[ ][ ][ ]

Pace for timed practice

SetQuestionsTime at the exam's average pace
One question11 minute 36 seconds
Short timed set2540 minutes
Half the exam752 hours
Full exam1504 hours

Before exam day

  • Exam taken inside the six-month eligibility period from registration (ISACA rule)
  • Appointment booked; appointments open 90 days ahead (ISACA rule)
  • Any change made at least 48 hours before the appointment, or sit or forfeit the fee (ISACA rule)
  • One current, original, government-issued photo ID with your signature, matching your registration name; no copies, no digital IDs (ISACA rule)
  • No calculators, notes, phones, smart watches, food or drink, including water (ISACA rule)
  • Two breaks of up to ten minutes each with the proctor's permission; the timer keeps running (ISACA rule)
  • No penalty for wrong answers, so answer every question (ISACA)

What experience do you need?

ISACA's Candidate Guide asks for three or more years of experience in IT risk management and IS control, with "no experience waivers or substitutions". The Get CRISC Certified page adds that the experience should span at least two of the four CRISC domains. It must fall within the 10 years before you apply, and you have five years from passing the exam to apply, with a USD 50 application fee. After that, maintenance is USD 45 a year for members or USD 85 for non-members, with 20 CPE hours a year and 120 over three years.

How should you prepare?

ISACA does not recommend a number of study hours, so the planner splits 50, 100 or 150 hours by the published weights; on 100 hours, Risk Response and Reporting gets 32. Our CRISC exam guide follows the outline effective 2025, with every chapter mapped to a published domain. For practice, the 205 CRISC practice questions are sized to the same weights, with a rationale for every answer.

What should you do this week?

Download the Candidate Guide from ISACA, check that your materials show 26, 22, 32 and 20, and book your hours. Credential Press is independent of ISACA, and nothing here comes from inside the exam.

Frequently asked questions

How many questions are on the CRISC exam?

150 multiple-choice questions in 4 hours, each with four options and one best answer. Some are unscored pretest items, and ISACA does not say how many.

What is the CRISC pass mark?

A scaled score of 450 on ISACA's 200 to 800 scale. ISACA publishes no percentage pass mark.

What are the CRISC domain weights?

Under the outline effective 2025: Governance 26%, Risk Assessment 22%, Risk Response and Reporting 32%, and Technology and Security 20%. The updated exam has been available since 3 November 2025.

What experience do you need for the CRISC?

Three or more years of experience in IT risk management and IS control, with no waivers or substitutions, gained within the 10 years before you apply. You have five years from passing the exam to apply.

How much does the CRISC cost?

USD 575 for ISACA members and USD 760 for non-members, nonrefundable, plus a USD 50 application fee after you pass.

How many times can you retake the CRISC?

Four attempts in a rolling 12 months: wait 30 days before the second, then 90 days before each of the next two, paying the full fee each time.

CRISC: test yourself in five minutes

Which books prepare you for the CRISC?

Cover of CRISC Exam Guide

CRISC Exam Guide

Certified in Risk and Information Systems Control. 14 chapters, 420 pages.

Cover of CRISC Practice Questions

CRISC Practice Questions

Practice questions with full rationales, sized to the published domain weights. 220 pages.

Sources

Every figure above was read from the document itself on 2 October 2026.

Credential Press is not affiliated with, endorsed by or authorized by ISACA. Exam names and trademarks belong to their owners.