How Do CISA and CGRC Compare Side by Side?
USD, from ISACA's and ISC2's published requirements and fees as of September 2026.
| CISA | CGRC | |
|---|---|---|
| Vendor | ISACA | ISC2 (formerly the CAP) |
| Exam fee | $575 member, $760 non-member | $599 |
| Other fees | $50 application fee after you pass | First $135 AMF due at certification |
| Experience | 5 years IS audit, control, assurance, or security within 10 years; up to 3 waivable | 2 years in 1 or more of 7 domains |
| If you pass without it | 5 years from passing to apply | Associate of ISC2, 3 years to earn it |
| Exam format | 150 questions, 4 hours, 5 domains | 125 items, 3 hours, 7 domains, pass at 700/1000 |
| Renewal | $45 member or $85 non-member per year; 120 CPE per 3 years, 20 minimum yearly | $135 per year (covers all ISC2 certs); 60 CPE per 3 years, 20 minimum yearly |
| Best for | IT audit, external audit, SOC attestation, assurance | Federal authorization, RMF, ISSO and ISSM roles |
What Does Each Exam Actually Test?
CISA is built around the audit process. Its five domains are the information system auditing process; governance and management of IT; information systems acquisition, development, and implementation; information systems operations and business resilience; and protection of information assets. The exam asks what an auditor should do, in what order, and with what evidence.
CGRC is built around the system lifecycle. Its seven domains run from the GRC program and system scoping through control selection, implementation, assessment, system compliance, and ongoing compliance maintenance. The exam asks how a system earns and keeps its authorization. If you have ever assembled a System Security Plan or tracked a POA&M, you will recognize most of it.
Which Is Cheaper Over Three Years, CISA or CGRC?
Count one exam attempt plus three years of annual fees, the length of both CPE cycles. A non-member CISA runs $760 for the exam, $50 to apply, and $85 a year, about $1,065. As an ISACA member the exam drops to $575 and maintenance to $45 a year, but ISACA membership itself is $145 a year plus chapter dues, which erases most of the savings. CGRC runs $599 for the exam and $135 a year, about $1,004.
So on fees alone the two are close, within about $60 of each other. The real difference shows up if you hold more than one credential. ISC2's $135 covers every ISC2 certification you hold, so CGRC is effectively free to maintain for a CISSP. ISACA charges maintenance per certification, discounted only from the third one on.
Study costs usually matter more than either exam fee. Both have official study materials and paid courses, and a bootcamp can add a few thousand dollars to either path. For a wider view, see what GRC training costs.
CISA or CGRC: Which Should You Choose?
Choose CISA if
- You want to work in IT audit, internal or external.
- You support SOC 1, SOC 2, or SOX IT testing.
- You want the credential with the widest recognition across industries.
- You already have, or are close to, five years of relevant experience.
Choose CGRC if
- You work on federal systems, FedRAMP, or RMF packages.
- You are an ISSO, ISSM, or security control assessor.
- You have two years of GRC experience, not five.
- You already pay the ISC2 annual fee for CISSP or another ISC2 cert.
Still undecided? The full cost picture is in how much CISA costs and is CGRC worth it. If neither fits, see six CISA alternatives.
Where Does CGE-P Fit for Engineering-Leaning GRC Roles?
CISA and CGRC both certify that you understand controls. Neither asks you to build one. A growing share of GRC roles, especially at cloud-native companies, expect you to collect evidence with code, write policy checks, and keep compliance running in a pipeline. That is the gap the CGE-P (Certified GRC Engineer, Practitioner) from the GRC Engineering Club covers, with hands-on labs, an exam, and a capstone you submit on GitHub.
The honest tradeoff: CGE-P is new, and it does not carry CISA's or CGRC's recognition with HR filters. It works best as a complement, proof that you can implement what the other two credentials assess. The fair side-by-side is in CGE-P vs CISA.
What $70 a year adds to a CISA or CGRC
Club membership is $70 per year, or $9.99 a month. Every certification in the Training Academy is included. Bought one at a time, the three current certifications are $350 each, so $1,050 of credentials come with a membership that costs less than most single exam vouchers.
- CGE-P, CGE-AUD, CGE-AZ: training, labs, exam, and certificate, no exam fee
- Hands-on AWS and Azure compliance labs you build in your own account
- Weekly private podcast and live Q&A with working GRC engineers
- Mock interviews, playbooks, and live builder sessions
- Local chapters and a Slack of 1,300+ GRC professionals
- Self-reported CPE hours for ISACA, ISC2, and IAPP renewals
Frequently Asked Questions
Which is better, CISA or CGRC?
CISA is better for IT audit, external audit, and assurance roles, and it has broader name recognition across industries. CGRC is better for federal GRC work built on the NIST Risk Management Framework, such as ISSO, ISSM, and control assessor roles. Pick the one that matches the job posts you are applying to.
Is CGRC easier than CISA?
CGRC is easier to qualify for: it needs two years of experience versus five for CISA. The exams are similar in scale, with CISA at 150 questions in four hours and CGRC at 125 items in three hours. Which exam feels harder depends on whether your background is audit or authorization.
Which costs more, CISA or CGRC?
As of September 2026, the CGRC exam is $599 and the CISA exam is $575 for ISACA members or $760 for non-members, plus a $50 application fee. Ongoing, CISA costs $45 to $85 a year and CGRC costs $135 a year. The CGRC fee covers every ISC2 certification you hold, so it is cheaper in practice if you already have CISSP.
Can I get both CISA and CGRC?
Yes. They overlap on control assessment but come from different angles: CISA from the audit process, CGRC from the system authorization lifecycle. Some federal auditors and assessors hold both, but most people should get the one that fits their current role first.
Where does CGE-P fit compared with CISA and CGRC?
CGE-P from the GRC Engineering Club covers what neither CISA nor CGRC tests: building compliance automation, collecting evidence with code, and mapping controls in a working pipeline. It has no experience requirement and is included in a $70 a year membership. It is newer and less recognized by HR screens, so many practitioners pair it with CISA or CGRC.