This website is in beta — you may spot rough edges; tell us and we'll fix them fast.
Certifications

Earn the credentials that define the profession

The chapter supports the full range of ISACA certifications with study groups, review workshops and a community of peers.

New — AI credentials

ISACA's AI certifications

A new family of advanced credentials for auditing, securing and governing artificial intelligence — the fastest-growing area in the profession.

AAIA — ISACA Advanced in AI Audit™, an ISACA certification

An advanced credential for professionals auditing AI systems, models and the governance around them — the fastest-growing area of assurance work.

Auditors moving into AI assurance

AAISM — ISACA Advanced in AI Security Management™, an ISACA certification

An advanced credential for security leaders securing and managing AI across the enterprise — from model risk to the controls that keep AI trustworthy.

Security leaders & managers

AAIR — ISACA Advanced in AI Risk™, an ISACA certification

An advanced credential proving your ability to identify, assess and manage the unique risks that AI systems bring to an organization.

Risk professionals working with AI

Core certifications

The credentials employers ask for by name

ISACA's flagship certifications across audit, security, risk, privacy, governance and cyber operations.

CISA — Certified Information Systems Auditor®, an ISACA certification

The globally recognized standard for professionals who audit, control and assess an organization's IT and business systems — proving you can find vulnerabilities, report on compliance and champion controls.

IT auditors · audit managers · assurance & compliance

CISM — Certified Information Security Manager®, an ISACA certification

For the people who build and run enterprise security programs — bridging information security and business strategy so security maps to what the organization is trying to achieve.

Security managers · CISOs · risk leaders

CRISC — Certified in Risk and Information Systems Control®, an ISACA certification

Aligns IT risk management with business objectives — proving you can identify, assess and respond to enterprise IT risk and put the right controls in place.

Risk & control professionals · IT risk analysts

CDPSE — Certified Data Privacy Solutions Engineer®, an ISACA certification

ISACA's experience-based, technical privacy certification — proving you can engineer privacy by design into products, processes and platforms, not just police them.

Privacy engineers · developers · IT & legal

CGEIT — Certified in the Governance of Enterprise IT®, an ISACA certification

For the professionals who direct and govern enterprise IT — aligning technology with strategy, managing resources and delivering measurable value to the business.

IT governance · executives · consultants

CCOA — Certified Cybersecurity Operations Analyst™, an ISACA certification

A hands-on, technical credential proving the real-world skills to detect, assess and respond to cybersecurity threats in a security-operations role.

SOC analysts · cyber operations · blue teams

Start here

Fundamentals certificates

No experience required — entry-level certificates that build the foundation for the professional certifications above.

Cybersecurity Fundamentals

Cyber

Core cybersecurity concepts and principles — the strongest entry point into the field.

IT Audit Fundamentals

Audit

The foundations of IT auditing, from controls to the audit lifecycle.

IT Risk Fundamentals

Risk

How IT risk is identified, assessed and managed across an organization.

Artificial Intelligence Fundamentals

AI

A foundational understanding of AI, how it works and its impact on the profession.

Cloud Fundamentals

Cloud

Cloud concepts, service models and the shared-responsibility model.

Data Science Fundamentals

Data

Data, analytics and machine-learning basics for the modern practitioner.

Computing Fundamentals

Foundations

The building blocks of computing for those new to technology.

Networks & Infrastructure Fundamentals

Foundations

How networks and infrastructure are built, connected and secured.

Certificate of Cloud Auditing Knowledge (CCAK)

Cloud

The first credential for auditing cloud environments, built with the Cloud Security Alliance.

CISA, CISM, CRISC, CDPSE, CGEIT, CCOA, AAIA, AAISM and AAIR are trademarks or registered trademarks of ISACA. Logos used per ISACA's chapter brand guidelines.

Chapter support

You don't have to study alone

Our member-led review series pairs you with a cohort, practice questions and experienced mentors.

Study groups

Join a cohort preparing for the same exam window.

Review workshops

Multi-session, domain-by-domain walkthroughs led by certified members.

CPE tracking

Earn and track CPE credits from chapter events, right on your dashboard.

Keeping your certification

CPE policy at a glance

Every ISACA certification is maintained with continuing professional education. The essentials from ISACA's 2026 CPE Policy:

20

CPE hours minimum every year

10 for Advanced certs (AAIA · AAISM)

120

CPE hours per 3-year cycle

30 for Advanced certs

90

must align to your cert's exam content

up to 30 can be leadership, soft skills or volunteering

  • Report hours in MyISACA → Certification & CPE Management → Manage CPE.
  • Pay the annual certification maintenance fee to ISACA Global.
  • Comply with ISACA's Code of Professional Ethics.
  • ISACA audits CPE claims — keep records (your chapter event CPE lives on your dashboard).
  • Chapter events are an easy way to earn — credits post automatically when you attend.
  • Falling short can mean revocation; retired and nonpracticing statuses exist if you step back.

This is a summary — the full, authoritative policy is ISACA Global's CPE Policy ↗.