CISA vs CISM vs CRISC: Which ISACA Certification Fits Your Job?
ISACA runs four credentials that get confused with each other constantly. They are aimed at genuinely different jobs, and taking the wrong one is an expensive mistake given what ISACA charges.
CISA, the auditor
Certified Information Systems Auditor. This is for people who assess controls rather than build them. Audit process, governance, systems acquisition, operations and asset protection.
Take it if your job title contains the word audit, or you work in assurance, compliance or risk review. It is the most widely held ISACA credential and the most requested in audit roles.
CISM, the manager
Certified Information Security Manager. Governance, programme development, incident management. It is explicitly a management credential, and the questions expect you to answer as someone accountable for a function rather than someone operating it.
Take it if you manage a security team or are moving toward that. The common comparison is with CISSP, which is broader and more technical. CISM is narrower and more managerial.
Note the blueprint changes on 3 November 2026. See our CISM timing guide before booking.
CRISC, the risk specialist
Certified in Risk and Information Systems Control. IT risk identification, assessment, response and monitoring.
Take it if risk management is your actual job rather than part of it. CRISC is the most specialised of the four and the least useful if you are not in a risk function. Where it is asked for, it commands a genuine premium.
AAIA and AAISM, the AI credentials
ISACA's newest additions. AAIA covers AI auditing, and AAISM covers AI security management. Both are 2025 and 2026 launches responding to AI governance obligations.
Take one if your organisation is deploying AI systems and someone has to be accountable for governing them. Skip if AI is not yet in your remit, because these will be revised as the regulatory picture settles.
AAIA questions and AAISM questions.
Difficulty order
CISA is generally considered the most approachable, largely because the material is procedural and well documented. CISM is harder in a specific way: the content is not difficult but the required mindset is, and technical people fail it by answering as engineers. CRISC is the hardest for most candidates because risk quantification is genuinely unintuitive.
The ISACA answer
Across all four exams, one habit matters more than any other. ISACA wants the answer a governance professional would give, not the one an engineer would give. When two options are both correct, the right one is almost always the one involving process, documentation or escalation rather than direct technical action.
People who internalise that pass. People who answer from technical instinct often do not.
All four covered with full explanations for every option. Browse ISACA sets.