← All articles

August 19, 2026

The First 30 Days After Passing CISA: Endorsement, CPEs, and How Hiring Actually Reacts

Passing the CISA exam is the hard part, but it is not the finish line, and a lot of newly successful candidates are surprised to learn they are not yet certified. After passing CISA you still have to apply for the certification, have your experience verified, and then keep the credential current with continuing education and an annual fee. None of it is difficult, but it is worth knowing the steps so nothing stalls in the weeks after you get your result.

This walks through what actually happens next: the certification application and experience verification, the substitutions that can reduce the experience requirement, the ongoing CPE obligation, the maintenance fee, and an honest read on how the credential lands in the hiring market. The figures here were checked against ISACA's current published policies, but confirm them on isaca.org before you act, since ISACA updates fees and rules periodically.

You passed. The certification isn't automatic.

The exam result and the certification are two different things. Passing means you cleared the exam; certification is a separate application you submit afterward, and it is granted only once ISACA verifies that you meet the experience requirement. Until you apply and are approved, you can accurately say you passed the CISA exam, but not that you are CISA-certified.

You have five years from passing the exam to apply for certification. That window is generous by design — it lets someone pass early in their career and complete the certification once they have accrued the required experience. But it is a window, not an open-ended grace period, so if you already have the experience, there is no reason to wait.

The certification application and experience verification

The core requirement is five years of information systems auditing, control, assurance, or security work experience, gained within the ten years before your application. The experience has to be genuine and relevant, and it must be independently verified — a supervisor or manager confirms it, not you, and not a family member or HR contact acting on your behalf.

There is a floor that cannot be reduced: at least two years must be actual, unwaived experience in the field. The substitutions described below can offset up to three of the five years, but the remaining two always have to be real work experience. The application itself carries a one-time processing fee of US$50, separate from what you paid to sit the exam. Once you submit with your verifier's confirmation and the fee, ISACA reviews it and grants the certification if everything checks out.

The substitutions and waivers

If you do not have the full five years, education and certain other credentials can substitute for up to three years of the requirement. Based on ISACA's current application, the main substitutions are:

  • One year for general information systems or general audit experience (one or the other, not both).
  • One year for an associate degree; two years for a bachelor's, master's, or doctorate in any field.
  • Three years for a master's in information systems or a related field.
  • Two years for holding certain other professional credentials, such as full CIMA certification or ACCA membership.

The combined total of all substitutions cannot exceed three years, and it cannot push your genuine experience below the two-year floor. In practice, a candidate with a relevant master's and two years of real IS audit experience can meet the requirement; someone with only a bachelor's needs three years of actual experience alongside the two-year education waiver. Check the current application form for the exact categories, since these are the details most likely to be updated.

CPE requirements

Certification is not a one-time achievement; it is a status you maintain through continuing professional education. CISA requires a minimum of 20 CPE hours reported every year, and at least 120 CPE hours across each rolling three-year cycle. Both requirements apply at once — meeting the annual 20 does not exempt you from the three-year 120, and vice versa.

CPE hours come from activities relevant to your professional knowledge: ISACA events and training, vendor and professional education, relevant conferences, publishing, and presenting, among others. If you hold more than one ISACA certification, the same qualifying hours can often count toward each. The obligation is real — failing to meet the CPE requirements results in revocation of the certification — but for anyone active in the field, 20 hours a year is a modest and achievable target.

The annual maintenance fee

Alongside the CPE hours, keeping the certification active requires an annual maintenance fee, due at the start of each year. At ISACA's current rates, that is US$45 per year for ISACA members and US$85 per year for non-members. This is separate from the one-time application processing fee and from any exam costs.

The fee is small enough that it rarely factors into anyone's decision, but it is worth budgeting for as an ongoing cost of holding the credential, along with the time to earn your CPE hours. Between the two, maintaining CISA is a light annual commitment rather than a burden.

How hiring actually reacts

Be realistic about what the credential does in the market. For information systems audit roles, CISA is the recognized standard, and holding it is often a stated or implied requirement — which is exactly why it matters. But it functions as a gating credential more than an automatic raise: it gets you considered and clears a bar, rather than lifting your compensation on its own. The value shows up in the roles it opens and the requirements it satisfies, not as a fixed salary premium you can count on.

There is also a real difference between "CISA in progress" and "CISA certified" in how a hiring manager reads a profile. Passing the exam and being fully certified are not the same signal, and for roles that require the credential, the completed certification is the one that counts. If you have met the experience requirement, finishing the application promptly turns a partial signal into the full one. Treat these as general market patterns rather than guarantees — the specifics vary by employer, region, and role.

What to put on your profile now

Once you are certified, update your professional profile to reflect it accurately: add the credential, and use the summary to connect your audit experience with the CISA-validated skill set, since the combination of demonstrated experience and the credential is a stronger signal than either alone. If you have passed but not yet completed certification, represent that honestly — "passed the CISA exam" is accurate and worth stating, but it is not the same claim as "CISA certified," and conflating them is a risk not worth taking.

The stacking question, revisited

A newly certified professional often wonders whether to immediately pursue CISM or CRISC. For most people, the answer is not yet. Build real depth in the audit work your CISA supports before adding another credential, and consider stacking only once your direction is clear and a second certification genuinely matches where your role is heading. The stacking decision comes down to role fit, not credential collecting, and it is usually a question to revisit years in rather than in your first month. This is as true for someone who came to CISA through a non-IT auditor career pivot as for anyone else — depth first, breadth later, if at all.

Independent CISA practice material. Not affiliated with ISACA. CISA, CISM, and CRISC are registered trademarks of ISACA, used here for descriptive reference only.

If you're still before the exam

Most of this article is for after you pass, but if you are reading it beforehand — mapping out what the whole path looks like — the most useful thing you can do now is find out how ready you actually are, because everything here depends on clearing the exam first.

If you're reading this before sitting the exam and want to see what passing-readiness actually feels like, our free CISA mock is built for exactly this — a full-length timed sitting that shows you where you stand against real exam conditions, so the certification steps in this article become the next thing to plan rather than a distant hope. Understand the format you are working toward in the CISA exam format, then find out where you stand — the post-exam paperwork is a good problem to have, and it starts with a passing score.