Skip to main content
Cybersecurity

ISACA CISA

ISACA's audit cert. The credential of choice for internal/external IT audit and audit-adjacent GRC.

DifficultyAdvanced
Study3–4 months
Exam£455 member / £600 non-member
Valid3 years
Compare
POST verdict
StrongMarket-level call. Not personal advice.

The default audit credential in UK finance, Big Four assurance practices and central government. Recognised by name on hiring panels.

Confidence: High Signal strength: High
ISACA's audit track has been the named requirement in IS audit JDs for two decades. PRA-supervised banks, Big Four assurance and NAO-adjacent work all list it explicitly. Recruiter behaviour is stable, not seasonal.
Tier-one audit firms run formal CISA pipelines and reimburse the exam. Second-line technology audit teams inside FCA-regulated firms screen for it directly. The signal is narrow but heavily weighted where it applies. The Big-Four-pipeline pattern keeps the credential heavily employer-funded inside assurance practices.
Who this pays off for
  • IT auditors inside Big Four assurance practices working FCA-regulated financial services or regulated utilities engagements
  • Second-line technology audit professionals in PRA-supervised banks, insurers and building societies where audit committee reporting is the core deliverable
  • Internal audit functions in central government, NHS arms-length bodies and large local authorities subject to NAO scrutiny
Who walks away with nothing
  • A risk credential. CRISC is the ISACA risk and control track. CISA is audit execution and IS assurance, not control design
  • A technical security signal. The exam tests audit methodology and process, not detection engineering, cloud security or vulnerability management
  • A standalone route into second-line risk. Risk teams want CRISC plus domain reps. CISA without audit experience is treated as aspiration
The named failure mode

The CISA-without-audit-reps trap. Career changers pass the exam hoping it opens audit doors, then find that Big Four and internal audit functions screen as hard on engagement experience as on the credential itself, and the cert alone reads as exam discipline rather than audit competency.

Recruiter signal, not marketing

Direct screening into senior IT auditor and second-line technology assurance roles in UK finance, defence and central government. Buys recognition on audit committee panels and accelerates progression from staff to manager grade inside Big Four. Does not substitute for risk methodology credentials in second-line risk hiring, and does not carry weight in first-line engineering teams.

Falsifiability
  • ISACA restructures the audit track or merges CISA with CRISC, changing how UK Big Four firms scope their assurance hiring requirements
  • FCA or PRA supervisory statements explicitly name an alternative audit competency framework that displaces ISACA recognition in regulated second-line audit hiring
  • Big Four UK practices shift from a CISA-by-default policy to vendor-specific or audit-firm-proprietary credentials at staff-grade entry

This tells you whether the cert is worth pursuing. It does not tell you whether it is worth pursuing for you.

See if it's right for you

This cert in isolation tells you very little. Here is where it actually sits. The pathways that use it, and the roles it realistically supports.

  • IT audit roles
  • GRC / compliance roles in regulated industries
Practitioner take

CISA is the audit cert that consultancies, the big four, and internal audit teams in UK financial services treat as table stakes. ISACA's exam rewards methodology and IS audit vocabulary, and the credential opens doors in a lane that operates somewhat apart from the rest of security. The right user is someone targeting IT audit, internal audit, or audit-leaning consultancy work. The wrong user is a technical security engineer hoping it'll round out a CV. Audit teams don't want CISSP-leaning candidates dabbling, and security teams don't reward CISA the way they reward CISM or CRISC. Take it when audit is the actual target.

Authored opinion. Updated against current hiring conditions, not vendor marketing.

Recommended prior knowledge

  • Audit or IT experience

Common misconceptions

  • ISACA CISA alone clears HR filters; it doesn't replace shipped, documented work.

What this cert does NOT guarantee

  • Engineering or pentest roles

The next step

A cert is a signal. A Career Verdict tells you whether the signal is worth sending.

A Career Verdict tells you whether this cert earns its place on your specific route, what it won't fix, and what to sit before or after it.

A route shows what people usually do. A Career Verdict judges whether it's realistic for you.

Get a judgement on your situation£39, one-off. Built for your inputs, yours to keep.

Built on POST's practitioner-authored assessment framework, calibrated by James from twenty years across helpdesk, infrastructure and security. Framework is human-authored; the verdict applies it to your inputs.