ISACA is no longer a five-certification portfolio. Its current public certification directory includes the established CISA, CISM, CRISC, CGEIT and CDPSE credentials, the technical CCOA path, and the advanced AI credentials AAIA, AAISM and AAIR. The correct starting point depends on the decisions you already make at work—not on which acronym sounds most senior.
This roadmap separates exam eligibility from certification eligibility where the credential uses an experience pathway. A candidate may be able to sit an established exam before completing its experience requirement, but passing alone does not automatically award an experience-based certification. CCOA is open to anyone and does not use the same work-experience requirement, while the advanced AI credentials rely on accepted prerequisite certifications.
The page also separates global credentials from U.S.-specific CMMC credentials. ISACA administers CCP and CCA for the U.S. CMMC ecosystem, but those are not interchangeable with CISA, CISM or CCOA and should be chosen only when the candidate's work genuinely touches the U.S. Defense Industrial Base.
Scope note: this article compares ISACA's active global professional certifications. CMMC CCP and CCA are addressed as U.S.-specific ecosystem credentials, certificates remain a separate product category, CCS is not presented as generally bookable while its public launch remains upcoming, and ITCA is treated as retired.
Which ISACA path fits your role?
Start with the decisions you make at work and the evidence you can build. A more advanced title is not automatically the better first choice.
Choose CISA when you evaluate and assure
CISA fits professionals who plan audits, gather evidence, evaluate controls and communicate findings. It is not simply a general cybersecurity credential.
Create an audit program for a realistic system, map risks to control tests, document evidence quality and write a defensible finding with cause, effect and recommendation.
Choose CISM when you own the security program
CISM fits managers who align security with business objectives and own governance, risk, program delivery and incident-management outcomes.
Build a security charter, risk-prioritization method, program roadmap, measures and an incident-governance playbook that shows who decides what.
Choose CRISC when technology risk is the job
CRISC fits practitioners who translate uncertainty into risk scenarios, assess exposure, select responses and monitor whether controls change risk.
Write complete risk scenarios, define appetite and tolerance links, select treatments, identify control owners and report residual risk with meaningful indicators.
Choose CDPSE when privacy must be engineered
CDPSE fits people who convert privacy obligations into architecture, data lifecycle, access, minimization and technical protection decisions.
Map a data flow, identify purposes and retention, apply privacy by design, document access and deletion controls, and test response to a data-subject request.
Choose CGEIT when governance spans the enterprise
CGEIT is for experienced leaders who design and oversee governance systems, investment decisions, value delivery, resources and risk at enterprise level.
Build a governance operating model that links stakeholder needs to decision rights, portfolio investment, performance measures, benefits and escalation.
Choose CCOA or an advanced AI path for specialization
CCOA is the operational technical path. AAIA, AAISM and AAIR extend an existing professional foundation into AI audit, security or risk; they are not beginner AI exams.
For CCOA, build investigation and detection evidence. For an AI path, document the qualifying credential and a governed AI use case with controls and review.
9 paths and exam decisions in one place
Use the exact code shown when one exists. Always recheck the provider’s current catalog before paying because names, versions, availability and retirement dates can change.
| Level / track | Certification or exam | Code | Best fit | Preparation emphasis |
|---|---|---|---|---|
| EstablishedAudit and assurance | Certified Information Systems Auditor | CISA | IT auditors, assurance professionals and control practitioners who evaluate information systems and business processes. | Risk-based audit planning, evidence, governance, systems acquisition, operations, resilience and protection. |
| EstablishedSecurity management | Certified Information Security ManagerNew exam outline takes effect 3 November 2026; match preparation to the appointment date | CISM | Security managers, program owners and leaders responsible for governance, risk, program delivery and incident management. | Managerial decisions, governance alignment, risk ownership, program design, resources, metrics and incident leadership. |
| EstablishedTechnology risk | Certified in Risk and Information Systems Control | CRISC | Technology-risk, control, governance, audit and security practitioners who identify, assess, treat and monitor enterprise IT risk. | Governance context, risk scenarios, analysis, response, control design, monitoring, reporting and technology resilience. |
| EstablishedPrivacy engineering | Certified Data Privacy Solutions Engineer | CDPSE | Privacy technologists, engineers, architects and security professionals who turn privacy obligations into system controls. | Privacy governance, risk, lifecycle practices, data mapping, architecture, engineering controls and incident response. |
| EstablishedEnterprise governance | Certified in the Governance of Enterprise IT | CGEIT | Senior governance, strategy and technology leaders who align enterprise IT with goals, value, resources and risk. | Governance frameworks, strategic alignment, benefits realization, resource optimization and enterprise risk oversight. |
| TechnicalCybersecurity operations | Certified Cybersecurity Operations AnalystFour-hour hybrid exam; verify current PSI delivery | CCOA | Analysts who evaluate threats, identify vulnerabilities, investigate events and recommend countermeasures in operational environments. | Hands-on analysis, threat and vulnerability evidence, detection, investigation, response and performance-based tasks. |
| AdvancedAI audit | Advanced in AI AuditPrerequisite credential required | AAIA | Experienced audit professionals extending assurance work into AI governance, model risk, controls and compliance. | Confirm the accepted active audit credential first, then study AI systems, governance, risk, controls, evidence and audit reporting. |
| AdvancedAI security | Advanced in AI Security ManagementPrerequisite credential required | AAISM | Experienced security managers governing AI-specific threats, controls, programs and organizational security posture. | Confirm an accepted active security credential, then connect AI risk, architecture, controls, monitoring and response to security management. |
| AdvancedAI risk | Advanced in AI RiskPrerequisite credential required | AAIR | Experienced risk professionals who assess, treat, monitor and communicate enterprise risks introduced by AI systems. | Confirm an accepted advanced risk credential, then study AI lifecycle risk, data and model risk, governance, regulation and reporting. |
What candidates often misunderstand
These distinctions prevent the most expensive mistake: studying for or buying access to the wrong exam.
Exam pass versus certification award
Passing an ISACA exam proves exam performance; it does not by itself complete an experience-based certification. For credentials that require experience, the application verifies relevant work and includes ethics and maintenance commitments. CCOA is open to anyone and does not impose that same work-experience requirement, so candidates must read the rules for the exact credential rather than assume one process applies to all nine.
Before registration, read the candidate guide and certification-requirements page. Where experience applies, record the domains you can support, who can verify the work and when the application window closes. For CCOA or an advanced AI credential, document the separate eligibility or prerequisite rules instead.
- Exam registration and scheduling are completed through ISACA and PSI.
- Experience and prerequisite requirements vary by certification.
- Confirm maintenance obligations for the exact credential after certification.
Established credentials versus advanced AI credentials
CISA, CISM, CRISC, CDPSE and CGEIT stand on their own role and experience pathways. AAIA, AAISM and AAIR are advanced credentials designed to build on accepted audit, security or risk certifications. The advanced AI choice should therefore follow an existing professional identity rather than replace the foundation.
ISACA's current candidate guidance describes authorized PSI test centers and remote-proctored delivery. The live option can still depend on the exact certification, country, appointment availability and device compatibility. India and U.S. candidates should verify the delivery choices shown in their own scheduler before paying.
- AAIA aligns with AI audit and assurance.
- AAISM aligns with security management for AI environments.
- AAIR aligns with enterprise AI risk.
CCOA is not another management exam
CCOA is positioned for technical cybersecurity operations. Its hybrid format includes multiple-choice and performance-based work, so preparation should include investigation, evidence interpretation and defensive decisions rather than reading management definitions alone.
A useful lab portfolio might include triaging an alert, validating a suspected indicator, reviewing endpoint and network evidence, recommending containment, and documenting what additional data is required. Use safe labs and authorized data only.
- Practise a repeatable investigation workflow.
- Explain why evidence supports or contradicts a hypothesis.
- Document containment, recovery and communication decisions.
ISACA certificates are not the same as certifications
ISACA also offers certificate programs such as IT Audit Fundamentals, IT Risk Fundamentals, COBIT and other topic-based learning. Those can be valuable, but they should not be presented as equivalent to professional certifications with separate experience, application and maintenance requirements.
ITCA is retired and should not be marketed as a current exam. Existing holders may have maintenance information, but new candidates should use the current ISACA credential and certificate directory to select an active path.
- Use the exact official product label.
- Do not invent numeric exam codes where ISACA uses the credential acronym.
- Do not call a certificate holder a certified professional unless the official program does.
One official program, different checkout and delivery checks
Country guidance should help a candidate complete the same official pathway. It should not create thin location pages or imply a local classroom where none exists.
Register from India without assuming remote delivery
Start in the official ISACA account, choose the exact credential, review its candidate guide and confirm the PSI delivery options actually offered for India. ISACA describes test-center and remote-proctored routes, but the live choice can depend on the certification, appointment availability and system compatibility.
Official list prices may be shown in U.S. dollars. Use the final checkout to confirm currency, tax and card treatment; do not convert an old U.S. price into a promised Indian quote. Keep the registration receipt, eligibility window and appointment rules.
- Confirm whether the chosen exam supports remote proctoring in India.
- Run the official system test before choosing an online appointment.
- Use the India WhatsApp route for training and registration guidance, not for unofficial exam access.
Use the U.S. PSI route and separate CMMC credentials
U.S. candidates should use the same official ISACA registration workflow and check current PSI test-center or remote availability. Taxes and final checkout terms can vary, so store the payable total and policy rather than relying on a marketing page.
CCP and CCA belong to the U.S. CMMC ecosystem. They may be appropriate for candidates working with the Defense Industrial Base, but they are not general substitutes for CISA, CISM, CRISC or CCOA. Verify the CMMC role, training and assessment prerequisites on the official ISACA pages.
- Confirm the exact credential and its prerequisite status.
- Choose test-center or remote delivery only after reviewing the current guide.
- Treat the exam result and certification application as separate milestones.
Verify before paying
ITCertPath provides independent selection and preparation guidance. The certification owner controls eligibility, registration, exam delivery, scoring and the credential.
- 01
Use the official ISACA certification directory to confirm the credential is active. CCS is still a beta/upcoming path and ITCA is retired; neither should be sold as a normal current exam.
- 02
Read the candidate guide, eligibility window, scheduling and rescheduling policy before payment. For CISM, use the outline tied to the appointment date because the revised outline takes effect on 3 November 2026.
- 03
For AAIA, AAISM or AAIR, confirm the accepted active prerequisite credential in your ISACA profile before assuming you can schedule the advanced exam.
- 04
Record the official checkout total, member or non-member status, applicable taxes and payment receipt. Do not rely on an old blog price or an unverified voucher promise.
- 05
Plan the certification application where applicable: document required experience, possible verifiers, ethics agreement and application deadline. For CCOA, confirm the open-access requirements; for an advanced AI credential, confirm the prerequisite certification.
- 06
Use independent training and original practice for learning, but never use copied questions, recalled exam content or a provider promising a guaranteed pass.
A study sequence that produces usable skill
Adjust the duration to your starting point. Keep the sequence: scope, learn, practise, review and verify.
Choose and verify
Match the credential to your responsibilities, confirm prerequisites, download the current official outline and note the exam-delivery rules for India or the USA.
Build the decision model
Study each domain as a chain of business context, risk, control or governance decision, evidence and communication—not as a glossary.
Create practical evidence
Write audit workpapers, risk scenarios, program artifacts, privacy designs, governance decisions or investigation notes appropriate to the chosen path.
Diagnose with original practice
Use timed, original scenarios to identify reasoning gaps. Review why every distractor fails and map each miss back to the official outline.
Close weak domains
Revisit primary sources, perform another practical task and explain the decision aloud. Do not repeat questions until familiarity looks like competence.
Verify and schedule
Recheck the candidate guide, identification, country delivery, system requirements, eligibility window and application plan before scheduling.
Training, practice and registration guidance
Move between learning and exam decisions without losing the exact certification or code you selected.
ISACA certification hub
Open ITCertPath's connected CISA, CISM, CRISC, CDPSE and CGEIT learning, diagnostics and registration paths.
Continue →ISACA registration guidance
Compare established credential booking guides and verify direct official registration instead of assuming a transferable voucher.
Continue →CISA diagnostic
Try 30 original audit scenarios with explanations and an official reference.
Continue →CISM diagnostic
Test security-management judgement against the outline tied to your appointment date.
Continue →CRISC diagnostic
Practise the complete technology-risk decision chain through original scenarios.
Continue →Official ISACA certifications
Verify the live portfolio, prerequisites and official registration route.
Open official source ↗ISACA certification FAQs
Which ISACA certification should I take first?
Choose by responsibility. CISA is for audit and assurance, CISM for security management, CRISC for technology risk, CDPSE for privacy engineering, CGEIT for enterprise governance and CCOA for technical cybersecurity operations. AAIA, AAISM and AAIR are advanced AI paths that require an accepted existing credential.
Can I take CISA, CISM or CRISC before meeting the experience requirement?
ISACA permits exam participation before all certification experience is complete for its established credentials, but passing the exam is not the same as receiving the certification. Verify the exact experience and application rules for your chosen credential.
Does ISACA use exam codes like AWS or Microsoft?
ISACA publicly identifies these exams by credential acronyms such as CISA, CISM and CRISC. Do not invent a numeric version code. Use the official candidate guide and outline linked from the credential page.
Can India candidates take ISACA exams online?
ISACA's current candidate guidance describes remote-proctored and authorized PSI test-center routes. The option shown can depend on the exact certification, location, appointment inventory and device compatibility, so confirm the live choices in your ISACA scheduler before paying.
Are AAIA, AAISM and AAIR beginner AI certifications?
No. They extend existing audit, security-management or risk expertise and require an accepted active credential. Candidates new to AI or to those professions should build the relevant foundation first.
Is CCOA a management certification?
CCOA is a technical cybersecurity-operations credential with a hybrid exam that includes performance-based tasks. Preparation should include investigation, threat and vulnerability evidence, response decisions and safe hands-on practice.
Is ITCA still an active ISACA certification?
No. ISACA states that ITCA is retired, although maintenance information remains available for existing holders. New candidates should select from the current certification or certificate directory.
Does ITCertPath issue ISACA certification or official exam access?
No. ISACA controls registration, PSI delivery, scoring, certification applications and maintenance. ITCertPath provides independent training, original practice and transparent registration guidance.
Official sources and freshness
This guide was reviewed on 2 October 2026. Provider pages remain the source of truth for exam codes, candidate requirements, prices, delivery methods and policies.