CISA vs CISSP: which fits your job, and which comes first?

Job-ad data: October 2026 · Editor: · Updated

Get this as a monthly report

CISA vs CISSP comes down to your field: take the CISA first in IT audit, and the CISSP first in security engineering, operations or architecture. The CISA (Certified Information Systems Auditor) is for auditors, who check that security safeguards work; the CISSP (Certified Information Systems Security Professional) is for people who build or run them.

Both ask for five years of work before you can hold them. If you do neither job yet, start with the quick answer. Of 8,110 US security-analyst ads on Adzuna (a job-ad search site) in October 2026, 338 named the CISSP and 3 spelled out the CISA title. Auditor ads, the CISA's natural home, were not in that count.

CISA CISSP
Issuer ISACA, an association for IT audit and governance ISC2, a membership body for security professionals
Written for Information systems (IS) audit: checking that safeguards work and reporting on them Security work across 8 technical and management domains (topic areas)
Experience to hold it 5 years of IS audit, control (safeguards), assurance or security work 5 years of full-time security work in 2 or more of the 8 domains
Most experience a degree or credential can replace 3 years (only one counts) 1 year
Exam 150 multiple-choice questions, 4 hours 100 to 150 questions, 3 hours, adaptive (each question picked by your earlier answers)
Exam fee $760, or $575 for ISACA members $749 in the Americas and Asia Pacific
Yearly fee $85, or $45 for ISACA members $135

Source: ISACA and ISC2 pages listed under Sources. A waiver is a degree or credential that replaces part of the experience rule. Governance here means who decides and who is accountable for IT.

CISA vs CISSP: share of cybersecurity analyst job ads naming each
CISSP is named more often than CISA in all 4 countries with enough ads.
Show the numbers
CISA vs CISSP: share of cybersecurity analyst job ads naming each. Share of job ads that name each item. Source: Adzuna job ads, October 2026.
CountryCISACISSP
India2 of 25018%
United Kingdom2 of 23512%
United States3 of 8,1104.2%
Brazil0 of 4344 of 434

CISA or CISSP: which do employers name more?

Instant answer from October 2026 job ads. No email needed.

Country

CISSP is named in more job ads in the United States.

  1. CISA3 of 8,110 ads<0.1% (3 ads)
  2. CISSP338 of 8,110 ads4.2%

Source: Adzuna job ads, October 2026.

Get your full report

Two optional questions shape your first step. No email needed.

Your experience
Your goal

Keep these numbers up to date

Inside: CISA and CISSP side by side, by share of job ads naming each, with the official fees.

Email me my CISA vs CISSP report for the United States, plus a monthly update when these numbers change. Unsubscribe anytime.

What’s in it?
  • The certifications that rose or fell most in job ads this month
  • One new study from our data, with its sources
  • New certifications, jobs and countries we added

One email a month. Unsubscribe in one click.

We use AI to analyse the job-ad data and write your report. The counts come from Adzuna job ads; figures and sources are checked automatically.

How we use your email: privacy policy

On this page
  1. Quick answer by situation
  2. CISSP vs CISA: what job ads ask for
  3. What experience does each one require?
  4. How do the two exams work?
  5. What do the CISA and CISSP cost over three years?
  6. How do you keep each credential?
  7. CISA vs CISSP difficulty: which exam is harder?
  8. Which should you take first?
  9. What we did not check
  10. Sources

Quick answer by situation

  • No security or audit job yet: you can sit either exam, but you cannot hold either credential until you have the work (details under experience). Your first step: read our cybersecurity roadmap, then search any job site for "security analyst" and "IT auditor" near you, and list the credentials in ten ads of each. For a first exam, look at CompTIA Security+, an entry-level security exam that ISC2 counts as one year of CISSP experience; our CISSP vs Security+ comparison explains the order.
  • Under two years in IT audit: keep building audit experience; a degree can shorten the CISA's five years (see the CISA waivers).
  • Two to five years in IT audit, IT risk or IT control work: take the CISA. With a master's in information systems, two years qualifies you; with a bachelor's, three.
  • Four to five years of hands-on security work in two or more areas: take the CISSP. Network security, identity and access, security operations and architecture all count as CISSP domains, and a degree or approved credential can cover one year.
  • CISA holder moving toward security engineering: the CISSP is the next step, with its full experience rule. If the move is toward running a security program, compare the CISM (ISACA's credential for security managers) in our CISM vs CISSP comparison.
  • Security practitioner asked to support audits: the CISA can follow the CISSP, as ISACA counts audit, control or security work.

CISSP vs CISA: what job ads ask for

In US security-analyst ads on Adzuna in October 2026, the CISSP appeared in 4.2% of the ads and the spelled-out CISA title in 3 of the 8,110 ads. The table gives the counts for the four countries where we counted both. We counted an ad for the CISSP when it contained CISSP, and for the CISA only when it contained Certified Information Systems Auditor. An ad can name both.

Country Security-analyst ads Naming the CISSP Naming the CISA
United States 8,110 338 3
United Kingdom 235 29 2
India 250 45 2
Brazil 434 4 0

Source: Adzuna API, security-analyst ads collected in October 2026. Analysis: CertWorthIt. Method. Brazilian ads may use the Portuguese title, so the English CISA title can undercount there.

Our reading: the CISSP is written for security practitioners, the people analyst ads hire, and the CISA is written for auditors. For the analyst role itself, our cybersecurity-analyst page lists what those ads name by country.

What cybersecurity analyst job ads name in the United States: certifications and skills
CISA is named in 3 of these 8,110 ads; SIEM leads with 5.1%.
Show the numbers
What cybersecurity analyst job ads name in the United States: certifications and skills. Share of job ads that name each item. Source: Adzuna job ads, October 2026.
ItemAdsShare of ads
SIEM4155.1%
CISSP3384.2%
CompTIA1622.0%
CISM1341.7%
CompTIA CySA+1191.5%
CompTIA Security+1121.4%
Splunk1001.2%
CEH8181 of 8,110
CISA33 of 8,110

What experience does each one require?

Both bodies require five years of work before you can hold the credential, but they count different work. ISACA counts information systems audit, control, assurance or security work for the CISA; assurance means telling management whether controls (safeguards such as access checks) do what they should. ISC2 counts full-time security work in at least two of the eight CISSP domains.

CISA: five years, up to three of them waived

ISACA asks for five years of information systems audit, control or security work, gained within the ten years before you apply. Its page adds: Candidates have 5-years from the passing date to apply. At least two of the years must fall in one of the five CISA domains, and a supervisor, manager, colleague or client verifies the work.

Waivers can replace up to three years:

  • 1 year: an associate degree (a two-year college degree) or one of two cloud and IT audit certificates.
  • 2 years: a bachelor's, master's or doctorate degree in any field, or one of two accounting credentials.
  • 3 years: a master's degree in information systems or a related field, such as computer science.

ISACA applies only one education waiver; they can't be combined. With the three-year master's waiver, two years of qualifying work is the shortest route to holding the CISA.

CISSP: five years, one of them waived

ISC2 asks for a minimum of five years cumulative, full-time experience in two or more of the eight domains. A bachelor's or master's degree in computer science, IT or a related field can cover one year, and so can a credential from ISC2's approved list, but ISC2 states: Only one year of experience can be waived. Part-time work and internships may also count. ISC2 checks your experience through endorsement, the step where an ISC2 member or ISC2 itself confirms it.

If you pass the exam without the experience, you can become an Associate of ISC2, a lower membership level with a $50 yearly fee and six years to earn the five years required experience. The shortest route to holding the CISSP is four years of qualifying work plus one waiver.

Does one credential shorten the other?

No. ISC2's approved list for the one-year CISSP waiver does not include the CISA, though it does include the CISM, the SSCP (another ISC2 credential) and CompTIA Security+, among others. ISACA's CISA waiver list names degrees, two audit certificates and two accounting credentials, and no ISC2 credential.

Holding one therefore gives you no head start on the other's experience rule. The work itself can still count twice if it fits both ISACA's audit, control or security description and two of ISC2's domains.

How do the two exams work?

The CISA has a fixed length, and the adaptive CISSP can stop anywhere between 100 and 150 questions.

CISA (ISACA) CISSP (ISC2)
Questions 150, multiple choice 100 to 150, multiple choice and other formats
Time 4 hours 3 hours
Passing score 450 on a scale of 200 to 800 700 out of 1,000
Domains 5 8

Source: ISACA CISA page, candidate guide and scoring article; ISC2 CISSP exam outline.

The CISA's five domains are Information Systems Auditing Process; Governance and Management of IT; Information Systems Acquisition, Development and Implementation; Information Systems Operations and Business Resilience; and Protection of Information Assets.

The CISSP's eight domains are Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, and Software Development Security. In our reading, Security Assessment and Testing is the CISSP domain nearest to audit work.

CISA vs CISSP exams side by side: questions, time, format
CISA, 150 questions in 240 minutes.
Show the numbers
CISA vs CISSP exams side by side: questions, time, format. Source: isaca.org, support.isaca.org, isc2.org, checked October 3, 2026.
ItemCISACISSP
Questions150 questions100–150 questions
Exam time240 minutes (4 h)180 minutes (3 h)
Passing score450 (scale 200–800)700 of 1,000
FormatMultiple choiceMultiple choice, adaptive testing
Where you take ittest center · online, proctoredtest center

What do the CISA and CISSP cost over three years?

Over a first three-year cycle with one exam attempt, the CISA costs an ISACA non-member $1,065 and the CISSP costs $1,154 at the Americas price. Both totals assume you hold the credential for all three years, so each is an upper end.

Item CISA, non-member CISA, ISACA member CISSP, Americas and Asia Pacific
Exam fee $760 x 1 attempt $575 x 1 attempt $749 x 1 attempt
Application fee (one time) $50 $50 none listed
Yearly fee $85 x 3 years $45 x 3 years $135 x 3 years
Three-year total $1,065 $760 $1,154

Source: ISACA CISA and maintenance pages; ISC2 exam pricing and AMF pages.

The CISA's $50 application fee is paid once, when you apply for certification after passing. ISC2 calls its yearly fee the annual maintenance fee (AMF) and bills the first one only after your endorsement is approved. Other regions, including Europe and the UK, have their own CISSP exam prices on ISC2's pricing page.

CISA vs CISSP: what each certification costs
Cheapest route: CISA $760, CISSP $749. Keeping CISA costs $85 a year ($255 over the 3-year cycle). Keeping CISSP costs $135 a year ($405 over the 3-year cycle).
Show the numbers
CISA vs CISSP: what each certification costs. Source: isaca.org, isc2.org, checked October 3, 2026.
ItemFee
CISA: Fees to get certified: Exam$760
CISA: Fees to get certified: Annual fee, $85 a year × 3 years$255
CISSP: Fees to get certified: Exam$749
CISSP: Fees to get certified: Annual fee, $135 a year × 3 years$405

How do you keep each credential?

Both require 120 hours of continuing professional education (CPE: courses, conferences and similar learning you log with the issuer) over three years, plus the yearly fee in the cost table.

  • CISA: at least 120 CPE hours in each three-year period and at least 20 every year.
  • CISSP: 120 CPE credits per three-year cycle. ISC2 suggests 40 a year but requires only the three-year total.

The two CPE systems are separate. Holding both means logging activities with ISACA and with ISC2, and paying both yearly fees: $220 a year for an ISACA non-member.

CISA vs CISSP difficulty: which exam is harder?

The harder exam is the one furthest from your daily work. An auditor who already plans audits and reports on controls meets the CISA's audit and governance domains as familiar ground and the CISSP's wider technical coverage as new study. A security engineer meets the opposite: the CISSP's technical domains are close to the job, while the CISA's audit process (planning an audit, collecting evidence and reporting findings) is a skill set of its own.

The formats differ too. The CISA gives you a fixed 150 questions and four hours, so you can plan your pace. The CISSP's adaptive format means you do not know in advance whether it will end at 100 questions or 150. ISACA converts CISA results to its 200-to-800 scale, so 450 is not a percentage of questions answered correctly.

For CISSP study methods, our CISSP page goes into more detail.

Which should you take first?

Your field sets the order, and waivers set how soon. With a bachelor's degree, three years of audit work qualifies you for the CISA, while the CISSP needs at least four years of security work in two domains even with a waiver. If you do neither job yet, start with the quick answer.

Should you take the CISSP while the CISA material is still fresh?

Yes, when your work will also meet the CISSP experience rule within the six-year Associate window. In our reading, the CISA's governance and Protection of Information Assets domains overlap with the CISSP's Security and Risk Management, Asset Security, and Identity and Access Management domains, so recent CISA study helps there. Before booking, check the eight CISSP domain names against your duties, especially if your audit work is mostly financial or process audit.

Is Security+ a better first step?

Yes, if you have no security or audit experience; the quick answer explains why.

Should you hold both?

Holding both makes sense when your work spans audit and security, for example on security teams that report to auditors or for auditors who review security architecture. The cost is two yearly fees and two CPE logs.

What we did not check

  • Which jobs we counted. We count the CISA in security-analyst ads only, not in IT-auditor ads, and only in four countries. We also count it only when an ad uses the full title, so ads that write only "CISA" are missing, and the CISA counts are a minimum.
  • Salary. We found no dated source that compares pay for CISA and CISSP holders.
  • Pass rates. Neither ISACA nor ISC2 publishes a pass rate on the pages we read.
  • ISACA membership dues, courses, books and retakes. The cost totals leave them out.
  • Whether audit work counts toward CISSP domains. ISC2 decides that at endorsement; we found no rule that maps audit work to a domain.
  • How deeply the CISA tests technical topics compared with the CISSP; we compared domain names only.
  • Retake rules and study time for either exam.

Sources

All pages below were read October 8, 2026.

Keep these numbers up to date

Inside: CISA and CISSP side by side, by share of job ads naming each, with the official fees.

Email me my CISA vs CISSP report for the United States, plus a monthly update when these numbers change. Unsubscribe anytime.

What’s in it?
  • The certifications that rose or fell most in job ads this month
  • One new study from our data, with its sources
  • New certifications, jobs and countries we added

One email a month. Unsubscribe in one click.

We use AI to analyse the job-ad data and write your report. The counts come from Adzuna job ads; figures and sources are checked automatically.

How we use your email: privacy policy

Questions people ask

Is the CISA or the CISSP harder?

It depends on your background, because the two exams test different work. The CISA (Certified Information Systems Auditor, from ISACA) has a fixed 150 multiple-choice questions in four hours and needs 450 on a scale of 200 to 800. The CISSP (Certified Information Systems Security Professional, from ISC2) is adaptive, meaning each question is picked based on your earlier answers, and stops between 100 and 150 questions within three hours; it needs 700 out of 1,000. The CISSP spreads its weight over eight domains (topic areas), the CISA over five.

Does the CISA count toward the CISSP experience requirement?

No. ISC2 lets one credential from its approved list replace one of the five years of security work the CISSP requires (this is called a waiver), and the CISA is not on that list. The list does include the CISM (ISACA's security management credential), the SSCP (another ISC2 credential) and CompTIA Security+ (an entry-level security exam). ISACA's CISA waiver list names degrees and a few audit and accounting credentials, not the CISSP.

Can a beginner take the CISA or the CISSP?

You can sit either exam without experience, but you cannot hold either credential until you have the work. The CISA (Certified Information Systems Auditor) needs five years of information systems audit, control or security work, and ISACA gives you five years after passing to apply. The CISSP needs five years of security work in at least two of its eight domains (topic areas); if you pass first, you become an Associate of ISC2, a lower membership level with six years to earn the experience. For a first exam, look at CompTIA Security+, an entry-level security exam that ISC2 accepts as one year of CISSP experience.

How much do the CISA and CISSP cost over three years?

With one exam attempt, the CISA costs an ISACA non-member $1,065 over three years: the $760 exam, a one-time $50 application fee and three yearly fees of $85. At ISACA member prices it comes to $760 ($575 + $50 + 3 x $45). The CISSP costs $1,154 at the Americas price: the $749 exam plus three yearly fees of $135. Both totals are upper ends: ISC2 bills its first yearly fee only after your experience is confirmed, and we did not find when ISACA bills its first.

Should I take the CISSP while the CISA material is still fresh?

Yes, if your work will reach five years of security work in at least two of the eight CISSP domains (topic areas) within six years of passing. Recent CISA study helps with governance (who decides and who is accountable), risk and asset protection, but the CISSP covers eight domains to the CISA's five, so plan study time for the rest.

Which do security-analyst job ads name, the CISA or the CISSP?

In October 2026, 338 of the 8,110 US security-analyst ads we counted on Adzuna, a job-ad search site, named the CISSP (Certified Information Systems Security Professional). The same count found the CISA spelled out in full, Certified Information Systems Auditor, in 3 of them. Auditor ads were not counted, and ads that write only the short form were missed.