CISA: What It Verifies
- Published
- 2026-08-01
- Content type
- Certification / Standards Authority
- Read time
- 1 min
CISA — Certified Information Systems Auditor — is ISACA's credential for IT and security auditing specifically, distinct from the federal agency that shares the acronym. It covers five domains: the IS audit process, IT governance and management, information systems acquisition and development, IS operations and business resilience, and protection of information assets.
What it verifies
CISA confirms someone can plan, execute, and report on IT and security audits — the evidence-gathering discipline SOC 2, PCI DSS, SOX, and GLBA exams all depend on. ISACA requires 5 years of professional information-systems auditing, control, or security experience, with substitutions available for certain degrees and other certifications.
Who typically holds it
On the calibre° roster, CISA is checked for IT & Security Auditor — the role that plans and tests ITGCs and builds the evidence packs auditors work from.
How calibre° verifies it
CISA status is checked against ISACA's credential registry before roster eligibility, the same primary-source standard applied to every certification calibre° lists. Full procedure: Verification.
FAQ
Is CISA the same as CISM?
No — both are ISACA credentials, but CISA is scoped to auditing (evidence, controls testing, reporting) while CISM is scoped to managing a security program. They're checked separately because they verify different work.
Does CISA require continuing education?
Yes — ISACA requires ongoing CPE credits and an annual maintenance fee to keep CISA active.
Why does IT & Security Auditor also check ISO 27001 and PCIP?
Because a single audit engagement often spans multiple named standards — see [IT & Security Auditor](/calibre/roles#it-security-auditor) for the full certification set checked on that role.
Specify the role. We calibrate the match.