CISA vs CISSP: which fits your job, and which comes first?
CISA vs CISSP comes down to your field: take the CISA first in IT audit, and the CISSP first in security engineering, operations or architecture. The CISA (Certified Information Systems Auditor) is for auditors, who check that security safeguards work; the CISSP (Certified Information Systems Security Professional) is for people who build or run them.
Both ask for five years of work before you can hold them. If you do neither job yet, start with the quick answer. Of 8,110 US security-analyst ads on Adzuna (a job-ad search site) in October 2026, 338 named the CISSP and 3 spelled out the CISA title. Auditor ads, the CISA's natural home, were not in that count.
| CISA | CISSP | |
|---|---|---|
| Issuer | ISACA, an association for IT audit and governance | ISC2, a membership body for security professionals |
| Written for | Information systems (IS) audit: checking that safeguards work and reporting on them | Security work across 8 technical and management domains (topic areas) |
| Experience to hold it | 5 years of IS audit, control (safeguards), assurance or security work | 5 years of full-time security work in 2 or more of the 8 domains |
| Most experience a degree or credential can replace | 3 years (only one counts) | 1 year |
| Exam | 150 multiple-choice questions, 4 hours | 100 to 150 questions, 3 hours, adaptive (each question picked by your earlier answers) |
| Exam fee | $760, or $575 for ISACA members | $749 in the Americas and Asia Pacific |
| Yearly fee | $85, or $45 for ISACA members | $135 |
Source: ISACA and ISC2 pages listed under Sources. A waiver is a degree or credential that replaces part of the experience rule. Governance here means who decides and who is accountable for IT.
Show the numbers
| Country | CISA | CISSP |
|---|---|---|
| India | 2 of 250 | 18% |
| United Kingdom | 2 of 235 | 12% |
| United States | 3 of 8,110 | 4.2% |
| Brazil | 0 of 434 | 4 of 434 |
CISA or CISSP: which do employers name more?
Instant answer from October 2026 job ads. No email needed.
CISSP is named in more job ads in the United States.
Source: Adzuna job ads, October 2026.
Get your full report
Two optional questions shape your first step. No email needed.
On this page
- Quick answer by situation
- CISSP vs CISA: what job ads ask for
- What experience does each one require?
- How do the two exams work?
- What do the CISA and CISSP cost over three years?
- How do you keep each credential?
- CISA vs CISSP difficulty: which exam is harder?
- Which should you take first?
- What we did not check
- Sources
Quick answer by situation
- No security or audit job yet: you can sit either exam, but you cannot hold either credential until you have the work (details under experience). Your first step: read our cybersecurity roadmap, then search any job site for "security analyst" and "IT auditor" near you, and list the credentials in ten ads of each. For a first exam, look at CompTIA Security+, an entry-level security exam that ISC2 counts as one year of CISSP experience; our CISSP vs Security+ comparison explains the order.
- Under two years in IT audit: keep building audit experience; a degree can shorten the CISA's five years (see the CISA waivers).
- Two to five years in IT audit, IT risk or IT control work: take the CISA. With a master's in information systems, two years qualifies you; with a bachelor's, three.
- Four to five years of hands-on security work in two or more areas: take the CISSP. Network security, identity and access, security operations and architecture all count as CISSP domains, and a degree or approved credential can cover one year.
- CISA holder moving toward security engineering: the CISSP is the next step, with its full experience rule. If the move is toward running a security program, compare the CISM (ISACA's credential for security managers) in our CISM vs CISSP comparison.
- Security practitioner asked to support audits: the CISA can follow the CISSP, as ISACA counts audit, control or security work.
CISSP vs CISA: what job ads ask for
In US security-analyst ads on Adzuna in October 2026, the CISSP appeared in 4.2% of the ads and the spelled-out CISA title in 3 of the 8,110 ads. The table gives the counts for the four countries where we counted both. We counted an ad for the CISSP when it contained CISSP, and for the CISA only when it contained Certified Information Systems Auditor. An ad can name both.
| Country | Security-analyst ads | Naming the CISSP | Naming the CISA |
|---|---|---|---|
| United States | 8,110 | 338 | 3 |
| United Kingdom | 235 | 29 | 2 |
| India | 250 | 45 | 2 |
| Brazil | 434 | 4 | 0 |
Source: Adzuna API, security-analyst ads collected in October 2026. Analysis: CertWorthIt. Method. Brazilian ads may use the Portuguese title, so the English CISA title can undercount there.
Our reading: the CISSP is written for security practitioners, the people analyst ads hire, and the CISA is written for auditors. For the analyst role itself, our cybersecurity-analyst page lists what those ads name by country.
Show the numbers
| Item | Ads | Share of ads |
|---|---|---|
| SIEM | 415 | 5.1% |
| CISSP | 338 | 4.2% |
| CompTIA | 162 | 2.0% |
| CISM | 134 | 1.7% |
| CompTIA CySA+ | 119 | 1.5% |
| CompTIA Security+ | 112 | 1.4% |
| Splunk | 100 | 1.2% |
| CEH | 81 | 81 of 8,110 |
| CISA | 3 | 3 of 8,110 |
What experience does each one require?
Both bodies require five years of work before you can hold the credential, but they count different work. ISACA counts information systems audit, control, assurance or security work for the CISA; assurance means telling management whether controls (safeguards such as access checks) do what they should. ISC2 counts full-time security work in at least two of the eight CISSP domains.
CISA: five years, up to three of them waived
ISACA asks for five years of information systems audit, control or security work, gained within the ten years before you apply. Its page adds: Candidates have 5-years from the passing date to apply. At least two of the years must fall in one of the five CISA domains, and a supervisor, manager, colleague or client verifies the work.
Waivers can replace up to three years:
- 1 year: an associate degree (a two-year college degree) or one of two cloud and IT audit certificates.
- 2 years: a bachelor's, master's or doctorate degree in any field, or one of two accounting credentials.
- 3 years: a master's degree in information systems or a related field, such as computer science.
ISACA applies only one education waiver; they can't be combined. With the three-year master's waiver, two years of qualifying work is the shortest route to holding the CISA.
CISSP: five years, one of them waived
ISC2 asks for a minimum of five years cumulative, full-time experience in two or more of the eight domains. A bachelor's or master's degree in computer science, IT or a related field can cover one year, and so can a credential from ISC2's approved list, but ISC2 states: Only one year of experience can be waived. Part-time work and internships may also count. ISC2 checks your experience through endorsement, the step where an ISC2 member or ISC2 itself confirms it.
If you pass the exam without the experience, you can become an Associate of ISC2, a lower membership level with a $50 yearly fee and six years to earn the five years required experience. The shortest route to holding the CISSP is four years of qualifying work plus one waiver.
Does one credential shorten the other?
No. ISC2's approved list for the one-year CISSP waiver does not include the CISA, though it does include the CISM, the SSCP (another ISC2 credential) and CompTIA Security+, among others. ISACA's CISA waiver list names degrees, two audit certificates and two accounting credentials, and no ISC2 credential.
Holding one therefore gives you no head start on the other's experience rule. The work itself can still count twice if it fits both ISACA's audit, control or security description and two of ISC2's domains.
How do the two exams work?
The CISA has a fixed length, and the adaptive CISSP can stop anywhere between 100 and 150 questions.
| CISA (ISACA) | CISSP (ISC2) | |
|---|---|---|
| Questions | 150, multiple choice | 100 to 150, multiple choice and other formats |
| Time | 4 hours | 3 hours |
| Passing score | 450 on a scale of 200 to 800 | 700 out of 1,000 |
| Domains | 5 | 8 |
Source: ISACA CISA page, candidate guide and scoring article; ISC2 CISSP exam outline.
The CISA's five domains are Information Systems Auditing Process; Governance and Management of IT; Information Systems Acquisition, Development and Implementation; Information Systems Operations and Business Resilience; and Protection of Information Assets.
The CISSP's eight domains are Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, and Software Development Security. In our reading, Security Assessment and Testing is the CISSP domain nearest to audit work.
Show the numbers
| Item | CISA | CISSP |
|---|---|---|
| Questions | 150 questions | 100–150 questions |
| Exam time | 240 minutes (4 h) | 180 minutes (3 h) |
| Passing score | 450 (scale 200–800) | 700 of 1,000 |
| Format | Multiple choice | Multiple choice, adaptive testing |
| Where you take it | test center · online, proctored | test center |
What do the CISA and CISSP cost over three years?
Over a first three-year cycle with one exam attempt, the CISA costs an ISACA non-member $1,065 and the CISSP costs $1,154 at the Americas price. Both totals assume you hold the credential for all three years, so each is an upper end.
| Item | CISA, non-member | CISA, ISACA member | CISSP, Americas and Asia Pacific |
|---|---|---|---|
| Exam fee | $760 x 1 attempt | $575 x 1 attempt | $749 x 1 attempt |
| Application fee (one time) | $50 | $50 | none listed |
| Yearly fee | $85 x 3 years | $45 x 3 years | $135 x 3 years |
| Three-year total | $1,065 | $760 | $1,154 |
Source: ISACA CISA and maintenance pages; ISC2 exam pricing and AMF pages.
The CISA's $50 application fee is paid once, when you apply for certification after passing. ISC2 calls its yearly fee the annual maintenance fee (AMF) and bills the first one only after your endorsement is approved. Other regions, including Europe and the UK, have their own CISSP exam prices on ISC2's pricing page.
Show the numbers
| Item | Fee |
|---|---|
| CISA: Fees to get certified: Exam | $760 |
| CISA: Fees to get certified: Annual fee, $85 a year × 3 years | $255 |
| CISSP: Fees to get certified: Exam | $749 |
| CISSP: Fees to get certified: Annual fee, $135 a year × 3 years | $405 |
How do you keep each credential?
Both require 120 hours of continuing professional education (CPE: courses, conferences and similar learning you log with the issuer) over three years, plus the yearly fee in the cost table.
- CISA: at least 120 CPE hours in each three-year period and at least 20 every year.
- CISSP: 120 CPE credits per three-year cycle. ISC2 suggests 40 a year but requires only the three-year total.
The two CPE systems are separate. Holding both means logging activities with ISACA and with ISC2, and paying both yearly fees: $220 a year for an ISACA non-member.
CISA vs CISSP difficulty: which exam is harder?
The harder exam is the one furthest from your daily work. An auditor who already plans audits and reports on controls meets the CISA's audit and governance domains as familiar ground and the CISSP's wider technical coverage as new study. A security engineer meets the opposite: the CISSP's technical domains are close to the job, while the CISA's audit process (planning an audit, collecting evidence and reporting findings) is a skill set of its own.
The formats differ too. The CISA gives you a fixed 150 questions and four hours, so you can plan your pace. The CISSP's adaptive format means you do not know in advance whether it will end at 100 questions or 150. ISACA converts CISA results to its 200-to-800 scale, so 450 is not a percentage of questions answered correctly.
For CISSP study methods, our CISSP page goes into more detail.
Which should you take first?
Your field sets the order, and waivers set how soon. With a bachelor's degree, three years of audit work qualifies you for the CISA, while the CISSP needs at least four years of security work in two domains even with a waiver. If you do neither job yet, start with the quick answer.
Should you take the CISSP while the CISA material is still fresh?
Yes, when your work will also meet the CISSP experience rule within the six-year Associate window. In our reading, the CISA's governance and Protection of Information Assets domains overlap with the CISSP's Security and Risk Management, Asset Security, and Identity and Access Management domains, so recent CISA study helps there. Before booking, check the eight CISSP domain names against your duties, especially if your audit work is mostly financial or process audit.
Is Security+ a better first step?
Yes, if you have no security or audit experience; the quick answer explains why.
Should you hold both?
Holding both makes sense when your work spans audit and security, for example on security teams that report to auditors or for auditors who review security architecture. The cost is two yearly fees and two CPE logs.
What we did not check
- Which jobs we counted. We count the CISA in security-analyst ads only, not in IT-auditor ads, and only in four countries. We also count it only when an ad uses the full title, so ads that write only "CISA" are missing, and the CISA counts are a minimum.
- Salary. We found no dated source that compares pay for CISA and CISSP holders.
- Pass rates. Neither ISACA nor ISC2 publishes a pass rate on the pages we read.
- ISACA membership dues, courses, books and retakes. The cost totals leave them out.
- Whether audit work counts toward CISSP domains. ISC2 decides that at endorsement; we found no rule that maps audit work to a domain.
- How deeply the CISA tests technical topics compared with the CISSP; we compared domain names only.
- Retake rules and study time for either exam.
Sources
All pages below were read October 8, 2026.
- ISACA: CISA page, get CISA certified, CISA exam content outline, maintain the CISA, exam candidate guide v1.26, support article: requirements to become CISA certified, support article: how exams are scored.
- ISC2: CISSP page, CISSP experience requirements, CISSP exam outline, exam pricing, AMF overview, Associate of ISC2, member policies.
- Job ads: Adzuna API, October 2026, security-analyst ads. Analysis: CertWorthIt. Method.
Questions people ask
Is the CISA or the CISSP harder?
It depends on your background, because the two exams test different work. The CISA (Certified Information Systems Auditor, from ISACA) has a fixed 150 multiple-choice questions in four hours and needs 450 on a scale of 200 to 800. The CISSP (Certified Information Systems Security Professional, from ISC2) is adaptive, meaning each question is picked based on your earlier answers, and stops between 100 and 150 questions within three hours; it needs 700 out of 1,000. The CISSP spreads its weight over eight domains (topic areas), the CISA over five.
Does the CISA count toward the CISSP experience requirement?
No. ISC2 lets one credential from its approved list replace one of the five years of security work the CISSP requires (this is called a waiver), and the CISA is not on that list. The list does include the CISM (ISACA's security management credential), the SSCP (another ISC2 credential) and CompTIA Security+ (an entry-level security exam). ISACA's CISA waiver list names degrees and a few audit and accounting credentials, not the CISSP.
Can a beginner take the CISA or the CISSP?
You can sit either exam without experience, but you cannot hold either credential until you have the work. The CISA (Certified Information Systems Auditor) needs five years of information systems audit, control or security work, and ISACA gives you five years after passing to apply. The CISSP needs five years of security work in at least two of its eight domains (topic areas); if you pass first, you become an Associate of ISC2, a lower membership level with six years to earn the experience. For a first exam, look at CompTIA Security+, an entry-level security exam that ISC2 accepts as one year of CISSP experience.
How much do the CISA and CISSP cost over three years?
With one exam attempt, the CISA costs an ISACA non-member $1,065 over three years: the $760 exam, a one-time $50 application fee and three yearly fees of $85. At ISACA member prices it comes to $760 ($575 + $50 + 3 x $45). The CISSP costs $1,154 at the Americas price: the $749 exam plus three yearly fees of $135. Both totals are upper ends: ISC2 bills its first yearly fee only after your experience is confirmed, and we did not find when ISACA bills its first.
Should I take the CISSP while the CISA material is still fresh?
Yes, if your work will reach five years of security work in at least two of the eight CISSP domains (topic areas) within six years of passing. Recent CISA study helps with governance (who decides and who is accountable), risk and asset protection, but the CISSP covers eight domains to the CISA's five, so plan study time for the rest.
Which do security-analyst job ads name, the CISA or the CISSP?
In October 2026, 338 of the 8,110 US security-analyst ads we counted on Adzuna, a job-ad search site, named the CISSP (Certified Information Systems Security Professional). The same count found the CISA spelled out in full, Certified Information Systems Auditor, in 3 of them. Auditor ads were not counted, and ads that write only the short form were missed.