Does CISA Expire? Yes — 3-Year CPE & Fee Requirements

Yes, the Certified Information Systems Auditor (CISA) expires every 3 years. ISACA requires 120 Continuing Professional Education (CPE) hours over each 3-year cycle with a minimum of 20 CPE hours per year, plus an annual maintenance fee of $45 (ISACA members) or $85 (non-members). CISA is one of the most respected IT audit certifications globally, and maintaining it demonstrates ongoing commitment to the profession.

Cycle
3 Years
CPEs Required
120
Annual Fee
$45
Min CPEs/Year
20

CISA Renewal Requirements Breakdown

ISACA's Continuing Professional Education (CPE) policy ensures CISA holders stay current with evolving audit standards, control frameworks, and information security practices:

How to Earn CISA CPE Hours

At 40 CPE hours per year average, you need roughly 3-4 hours of professional development per month. Here are the most common sources:

CPE SourceHours AvailableCost
ISACA webinars1-2 per sessionFree (members)
ISACA chapter meetings1-3 per eventFree-$25
ISACA conferences (NACACS, GRC)20-40 per event$500-$2,500
Self-study (books, journals)Up to 10/yearFree-$50
Teaching/lecturing1 per hour taughtFree
Publishing articles5-10 per articleFree
Earning another certification20-40 per certVaries

CISA vs Other ISACA Certifications — Maintenance Comparison

CertificationCPEs (3yr)Annual MinAnnual Fee (Member)
CISA12020$45
CISM12020$45
CRISC12020$45
CGEIT12020$45

Key benefit: If you hold multiple ISACA certifications (CISA + CISM, for example), CPE hours count toward all certifications simultaneously. You still pay a separate maintenance fee for each certification, but the learning effort overlaps completely.

3-Year Cost of Maintaining CISA

ExpenseISACA MemberNon-Member
Maintenance Fee (3 years)$135$255
ISACA Membership (3 years)$405$0
CPE Activities (free sources)$0$0
Total (minimum)$540$255

ISACA's CPE Audit Process

ISACA randomly selects certification holders for CPE audits each year. If selected, you must provide documentation proving your claimed CPE hours. Here's what you need to know:

Frequently Asked Questions

Does CISA expire?

Yes. CISA expires on a 3-year cycle. You must earn 120 CPE hours (minimum 20/year) and pay the annual maintenance fee ($45 members, $85 non-members).

How many CPE hours does CISA require?

120 CPE hours over 3 years with a minimum of 20 per year. Topics must relate to IS auditing, control, assurance, security, or governance.

What is the CISA maintenance fee?

$45/year for ISACA members, $85/year for non-members. This is separate from ISACA membership dues ($135/year).

Can CISA CPEs count toward CISM or CRISC?

Yes. CPE hours count toward all ISACA certifications you hold simultaneously. The topics just need to be relevant to each certification's domain areas.

What happens if CISA expires?

ISACA suspends your certification. After the suspension period, you must retake the full exam ($575 members, $760 non-members) and reapply for certification with work experience verification.

Does ISACA audit CISA CPE claims?

Yes, ISACA conducts random CPE audits annually. Keep certificates of completion, conference records, and other documentation for at least 1 year after your cycle ends.

Prepare for CISA Certification

Practice with adaptive CISA questions covering all 5 domains.

Start Free CISA Practice Test →

Related Resources

How to Pass CISA CISA vs CISM Does CISM Expire?