Skip to main content
GRC (Audit, Risk, Compliance)Listed as a primary cert for that lane. Back to pathway
Cybersecurity

CRISC

ISACA's risk credential. The dedicated counterpart to CISM for risk-coded governance lanes.

DifficultyIntermediate
Study3–4 months
Exam (indicative)£455 member / £600 non-member
Valid3 years

Vendor record

This entry has not yet been read against the vendor's own documentation. Exam names, codes and prices shown on this page are indicative; check the vendor before booking anything.

Compare
POST verdict

Strong

Market-level call. Not personal advice.

The canonical second-line credential in UK finance and defence. ISACA's tightest fit between cert scope and what regulated employers actually need.

Confidence
High
Signal
High
Why this confidence
CRISC appears explicitly or implicitly in risk and control JDs across FCA-regulated firms, PRA-supervised banks and defence prime contractors. It's recognised by name in hiring panels in a way that most GRC certs are not.
Why this signal strength
Regulatory pressure from DORA, FCA operational resilience rules and NIS2 transposition has pushed risk quantification and control testing into first-tier hiring requirements in UK finance. CRISC sits directly in that gap.
Who this pays off for
  • Second-line risk and control professionals in FCA or PRA-regulated firms where risk register ownership, control effectiveness testing and ICT risk appetite statements are core deliverables
  • GRC analysts and risk managers scoping DORA ICT risk framework obligations, including third-party risk and incident reporting alignment
  • Technology risk officers in UK defence or critical national infrastructure where NCSC CAF assessments and risk treatment plans require documented second-line competency
Who walks away with nothing
  • A technical security credential. CRISC tests risk and control methodology, not KMS policies, firewall rules or detection engineering
  • An audit credential. CISA is the ISACA audit track. CRISC is risk and control, not audit execution or IS assurance
  • A substitute for domain experience in regulated industries. Panels in UK finance treat it as a signal amplifier for existing second-line experience, not a replacement for it
The named failure mode

First-line-to-second-line pivot without the experience anchor. Candidates pursue CRISC to signal a move from technical security into risk, but without risk register ownership or control testing track record the cert reads as aspiration rather than competency.

Recruiter signal, not marketing

Buys immediate credibility in second-line technology risk and GRC hiring in UK finance, defence and regulated utilities. Opens ISO 27001 lead implementer and DORA ICT risk officer conversations. Does not buy technical security credibility, does not satisfy audit committee expectations on its own, and does not carry weight in first-line engineering roles.

Falsifiability
  • DORA ICT risk framework requirements become prescriptive enough that regulators name specific qualifications, either entrenching CRISC or introducing a competing benchmark
  • ISACA updates the CRISC exam domain weighting to reduce alignment with ISO 27005 and NIST RMF, reducing its cross-framework relevance for UK-regulated firms
  • FCA or PRA supervisory statements name alternative risk competency frameworks that crowd out ISACA credentials in senior risk hiring panels

This tells you whether the cert is worth pursuing. It does not tell you whether it is worth pursuing for you.

See if it's right for you

This cert in isolation tells you very little. Here is where it actually sits. The pathways that use it, and the roles it realistically supports.

  • Enterprise risk roles
  • GRC manager interviews
  • Audit-leaning consulting
Practitioner take

CRISC is the right cert for risk practitioners who've outgrown CISA but aren't aiming at security management. ISACA's risk-focused credential, recognised in UK financial services, big consultancies, and regulated enterprise. The exam rewards a couple of years of running risk assessments, owning a register, or sitting on a risk committee. Take it when you're already inside a risk team and want the senior credential. Don't take it as a CISA alternative; the audit and risk lanes diverge fast at senior level. Don't take it from a pure-technical seat either. CRISC without operational risk reps reads as manufactured on a CV.

Authored opinion. Updated against current hiring conditions, not vendor marketing.

Recommended prior knowledge

  • 3+ years GRC/audit exposure

Common misconceptions

  • CRISC alone clears HR filters; it doesn't replace shipped, documented work.

What this cert does NOT guarantee

  • Hands-on engineering roles
  • Detection or IR work

Practitioner judgement. External evidence review pending.

Last reviewed: not yet reviewed · UK market

The next step

A cert is a signal. A Career Verdict tells you whether the signal is worth sending.

A Career Verdict tells you whether this cert earns its place on your specific route, what it won't fix, and what to sit before or after it.

A route shows what is possible. A Career Verdict makes the call.

POST ATLASVerdict no. PA-2026-0512
Career analysis report

Career Verdict

Helpdesk → Security Architect

“Realistic, but not by adding another certification.”
  1. 01
    The callA clear judgement on whether your route is realistic, and under what conditions.
  2. 02
    Where the route breaksThe most likely point to stall, and why it happens in practice.
  3. 03
    What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Generated within POST’s practitioner-authored assessment frameworkPOST ATLAS

Career Verdict

£39One-off payment. No subscription.
  • The callA single written judgement on whether the route is realistic for you.
  • Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
  • Where you standThe strongest and weakest parts of your current position, named.
  • Salary realityWhat this route actually pays, set against what you've been told it pays.
See the Career Verdict

Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.

Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.