Certified Information Systems Auditor (CISA) CPE Requirements

Last updated

Maintained by CeriFi CPEdge from the same rule data our compliance engine uses — how we maintain this →

Credit hours required
120 hours
Reporting period
Fixed triennial
Reporting deadline
January 15, annually
Official source
Certified Information Systems Auditor (CISA) board site →

Regulator Details

Contact Information

How to reach the regulator directly.

Information Systems Audit and Control Association (ISACA)
3701 Algonquin Road, Suite 1010
Rolling Meadows, IL 60008

Tel: (847) 660-5660
Fax: (847) 253-1755

Email: certification@isaca.org

Core Requirements

Credit Hours Required

The total continuing education hours required.

120 hours.

Breakdown of Specific Requirements

The detailed rules behind that total -- category minimums, ethics, and other conditions.

Attain and report an annual minimum of twenty (20) CPE hours.

  • These hours must be appropriate to the currency or advancement of the CISA's knowledge or ability to perform CISA-related tasks.
  • The use of these hours towards meeting the CPE requirements for multiple ISACA certifications is permissible when the professional activity is applicable to satisfying the job-related knowledge of each certification.

Cycling Period

How the reporting cycle is structured.

Fixed triennial.

Start Date

When a reporting cycle begins.

January 1.

Deadlines & Reporting

Reporting Method

How completed credits are reported to the regulator.

CISAs who report the required number of CPE hours and submit maintenance fees, in full, in a timely manner will receive a confirmation from ISACA international headquarters. This confirmation will include the number of CPE hours accepted for the annual reporting period, hours reported for past years within the three-year certification period and the number of hours required to qualify for the fixed three-year certification period. It is the responsibility of each CISA to notify ISACA international headquarters promptly of any errors or omissions in this confirmation.

CISAs must obtain and maintain documentation supporting reported continuing professional education activities. Documentation must be retained for a minimum of twelve months following the end of each three-year reporting cycle. Documentation should be in the form of a letter, certificate of completion, attendance roster, Verification of Attendance form or other independent attestation of completion. At a minimum, each record should include:

  • The name of the attendee;
  • Name of the sponsoring organization;
  • Activity title;
  • Activity description;
  • Activity date; and
  • The number of continuing professional education hours awarded or claimed.

Reporting Date

The renewal or reporting deadline.

January 15, annually.

Get monthly reminders before this deadline

Enforcement

What happens if the requirement is not met.

Revocation

CISAs who fail to comply with the CISA CPE Policy will have their CISA credential revoked and will no longer be allowed to present themselves as a CISA. Individuals who have their CISA certification revoked will be required to take and pass the CISA exam and submit a completed application for CISA certification.

Reconsideration and Appeal
Individuals whose certification has been revoked due to noncompliance with the CPE policy and who later appeal for reinstatement may incur an additional reinstatement fee. This reinstatement fee is effective for those reinstated after January 1, 2013 (when the revocation had been outstanding more than 60 days) and is in addition to any back or current certification maintenance fees needed to bring the certified individual in compliance with the CPE policy.

Audits of Continuing Education Hours
Those chosen for an audit must provide written evidence of previously reported activities that meet the criteria described in the Qualifying Professional Education Activities. Please send copies of supporting documentation, since documents will not be returned. The CISA Certification Committee will determine the acceptance of hours for specific professional educational activities. Those individuals who do not comply with the audit will have their CISA certification revoked.

Exceptions & Special Cases

Requirements for New Licensees

Reduced or prorated requirements for a first renewal.

For newly certified CISAs, the annual and three-year certification period begins on 1 January of the year succeeding certification. Reporting continuing professional education hours attained during the year of certification is not required. However, hours attained between the date of certification and 31 December of that year can be used and reported as hours earned in the initial reporting period.

Requirements for Non-residents not addressed by regulator

Rules for professionals licensed elsewhere.

Not applicable.

Exemptions

Who may be excused from all or part of this requirement.

Retired CISA Status:

CISAs are entitled to apply for retired CISA status if over 55 years of age and permanently retired from the CISA profession, or unable to perform the duties of an IS audit, control or security professional by reason of permanent disability. CISAs granted this status are no longer required to obtain CPE hours.

Nonpracticing CISA Status:

CISAs who are no longer working in the IS audit, control or security profession are entitled to apply for nonpracticing CISA status. Requests for the nonpracticing status must be received by ISACA no later than 15 January and accompanied with your annual invoice. CISAs granted this status are not required to obtain CPE hours, but are required to pay the annual maintenance fee. Once the individual has returned to the profession, they are required to return to active status. Although previously permitted, CISAs in nonpracticing or retired status cannot use "CISA" or "CISA-nonpracticing" on business cards.

Carryover Credit not addressed by regulator

Whether unused credits can apply to the next period.

Not specified.

Rule Changes

Approved Rule Changes

Rule changes the regulator has finalized, with effective dates.

Refer to the specific sections above for more details on any of the items noted below.

Other Special Rules:

Passing related professional examinations (no limit): This activity pertains to the pursuit of other professional examinations.

  • Effective for CPE earned on and after January 1, 2014: Two (2) times the number of CPE hours are earned for each examination hour when a passing score is achieved on a related professional examination This change went into effect 1 January 2014 and has been approved by the Credentialing and Career Management Board. The change is universal and applies equally to all ISACA certifications.

General Characteristics of Accredited Education:

Effective January 2013: CPE credits can be earned in quarter hour increments rounded down to the nearest quarter hour increment.

Credit for Self-Study Education:

Effective January 2013: Additional CPE can be earned by ISACA members when participating in an online eLearning presentation event sponsored by ISACA (for example: Virtual Trade Shows, Webinars, etc.) For an updated listing of eLearning events, please visit www.isaca.org/elearning. Please note that the ISACA® Journal quiz and ISACA eLearning activities can be counted (more than once) toward each ISACA designation that is held.

Other Special Rules:

Contributions to the IS audit and control profession: (Effective January 1, 2012, 20-hour annual limitation. Prior to January 1, 2010, 10-hour annual limitation): These activities include work performed for ISACA and other bodies that contribute to the IS audit and control profession (i.e., research development, certification review manual development, Knowledge Centre Contributor, performing peer reviews).

Effective January 1, 2011: Working on ISACA Boards/Committees (20-hour annual limitation per ISACA certification): These activities include active participation on an ISACA Board, committee, sub-committee, task force or active participation as an officer of an ISACA chapter. One CPE hour is earned for each hour of active participation. Active participation includes, but is not limited to, the development, implementation, and/or maintenance of a chapter website. Such activities can be counted more than once toward each ISACA designation that is held.

Effective January 1, 2011: Mentoring (10-hour annual limitation): Certifieds are able to receive up to 10 CPEs annually for mentoring. Activities include mentoring efforts directly related to coaching, reviewing or assisting with CISA exam preparation or providing career guidance through the credentialing process either at the organizational, chapter or individual level. The mentoring activity must be an activity supporting a specific person in preparation for their ISACA exam or certification career decisions. One CPE hour is earned for each hour of assistance.

About this summary

Prepared and maintained by CeriFi CPEdge, which has tracked CPE rules for over 20 years, covering 76 accountancy regulators — all 50 state boards of accountancy, the District of Columbia, Puerto Rico and Guam, plus national bodies and professional designations including NASBA, PCAOB, Yellow Book, CFP, IRS Enrolled Agents and CTEC.

Each regulator is tracked across 44 distinct rule areas — credit categories, compliance periods, format limits, carryover, new-licensee provisions, reporting method and provider-approval requirements. When a board changes its rules the rule set is updated, and where the published wording is ambiguous CeriFi confirms the interpretation with the board directly. The Approved Rule Changes section records the dated history for Certified Information Systems Auditor (CISA).

Always verify against the regulator’s own published rules — see official links above.

Other CPE Requirements

Track your credits against these rules

CPEdge applies Certified Information Systems Auditor (CISA)’s compliance period, credit categories, carryover and new-licensee provisions to your activity history automatically, and tells you what is still outstanding — across every jurisdiction you are licensed in at once.

Get CE Tracking

Already included in all three CPE packages: Professional · Premier · Premier Pluscompare packages

Need courses too? Browse the catalog to find CPE that satisfies these requirements.

This rule summary was prepared solely by CeriFi and is not endorsed, reviewed, or approved by your State Board of Accountancy. While CeriFi takes great strides to accurately convey the CPE rules and requirements in a readily accessible and easy-to-understand format, this summary does not in any way represent or replace the official rules of the regulating authority. Thus, these summaries are not to be relied upon as a substitute for the official rules and regulations of the regulating authority. CeriFi does not warrant the accuracy of this rule summary and CeriFi may not be held liable for any damages as a result of any reliance upon it.