Choosing a GRC certification is less about which credential is most respected and more about which one will actually let you apply. Three of the four names that dominate governance, risk and compliance job adverts carry experience requirements you have to satisfy before your certificate is issued, and two of them want five years. Buy the wrong one and you sit an expensive exam only to spend the next three years as a provisional holder.
This guide compares CGRC, CRISC, CISA and CISM on the things that decide the answer: what each exam tests, what it costs, how many years you need, and where each one leads. There is also a route for people with no security experience at all, because the standard advice to "just take CISSP" is wrong for most people entering GRC.
What a GRC Certification Actually Certifies
Governance, risk and compliance is the part of security that decides what an organisation must do, proves it is doing it, and reports the gap. The work is control selection, risk registers, audit evidence, framework mapping (NIST, ISO 27001, SOC 2) and third-party assessments. It rarely involves packet captures or detection rules.
That shapes what the exams test. All four credentials here are management and process exams, not technical ones. You are asked to choose the correct control, judge whether residual risk is acceptable, or identify what an auditor should do first. Candidates who fail usually fail because they answered as a hands-on engineer rather than as a risk owner.
Exam Tip: ISACA exams reward the answer a risk manager would give, not the most technically thorough one. When two options are both correct, pick the one that happens earliest in the process or that a governing body would sign off.
The Four GRC Certifications Compared
| Certification | Body | Questions | Time | Pass mark | Exam fee | Experience needed |
|---|---|---|---|---|---|---|
| CGRC | ISC2 | 125 | 3 hours | 700/1000 | $599 | 2 years |
| CRISC | ISACA | 150 | 4 hours | 450/800 | $575 member, $760 non-member | 3 years |
| CISA | ISACA | 150 | 4 hours | 450/800 | $575 member, $760 non-member | 5 years |
| CISM | ISACA | 150 | 4 hours | 450/800 | $575 member, $760 non-member | 5 years |
ISACA adds a $50 application processing fee once you pass, and CGRC carries an annual maintenance fee of $135. Budget for the renewal, not just the sitting.
CGRC: The Control and Authorisation Exam
ISC2's Certified in Governance, Risk and Compliance is built around the system authorisation lifecycle, which makes it the natural fit for anyone working to NIST Risk Management Framework or in a federal or defence supply chain. It is 125 questions in 3 hours with a 700/1000 pass mark, and it spans seven domains: GRC Program (16%), Scope of System (10%), Control Selection (14%), Control Implementation (17%), Assessment and Audit (16%), System Compliance (14%) and Compliance Maintenance (13%).
The experience bar is the lowest of the four at two years in one or more of those domains. If you do not have it, passing the exam makes you an Associate of ISC2, and you then have three years to accumulate the two years required. That grace period is the single most useful feature of CGRC for career changers. Our CGRC deep dive covers the domain content in more detail.
CRISC: The Risk Specialist
CRISC is the one to take if risk is the job rather than a task inside the job. The outline that took effect on 3 November 2025 weights Risk Response and Reporting at 32%, Governance at 26%, Risk Assessment at 22% and Technology and Security at 20%, so a third of the exam sits in the part of the cycle most candidates under-revise: what you do after the risk has been identified.
Certification needs three years of cumulative experience across at least two of the four domains, with at least one of those years in Governance or IT Risk Assessment, earned within the ten years before you apply. Volume backs the demand: "crisc certification" draws around 1,600 searches a month in the US, against 880 for "cgrc certification" (DataForSEO). If you want the full breakdown, read the CRISC explainer, then work through the CRISC practice questions.
CISA: The Auditor's Credential
CISA is the most recognised name on this list and the one hiring managers in audit and assurance ask for by default. The exam is 150 questions over four hours across five domains weighted 18%, 18%, 12%, 26% and 26%, with Information Systems Operations and Business Resilience and Protection of Information Assets carrying the heaviest load between them.
Certification requires five years of information systems auditing, control or security experience, although up to three of those years can be substituted with relevant education or other qualifications. You may sit and pass the exam first and apply once your history qualifies. Start with the 12-week CISA study plan and the CISA practice exams.
CISM: The Management Track
CISM tests whether you can run a security programme rather than assess one, across four domains covering governance, risk management, programme development and incident management. It requires five years in information security with at least three of those in security management spanning three or more domains, which makes it the hardest of the four to qualify for cold.
The waivers soften that: a current CISA in good standing removes two years, a current CISSP removes two years, and a relevant master's degree removes up to two more. There is also a deadline worth noting. Exams sat on or after 3 November 2026 follow an updated outline with shifted domain weights and more emphasis on strategy, programme development and security architecture, so anyone revising to the current version should check the CISM exam change guide before booking.
Which GRC Certification Should You Take First?
Match the credential to where you are now, not to where the job adverts point.
You have no security experience. Take ISC2's Certified in Cybersecurity or CompTIA Security+ first. Neither has an experience requirement, both give you the vocabulary GRC work assumes, and both are recognised by the recruiters filtering CVs. OCEG's GRC Professional (GRCP) is the other no-prerequisite option, at $575 for a 100-question, two-hour open-book exam where you need 70 correct. It teaches the GRC Capability Model rather than a specific framework, which is useful context but carries less weight with hiring managers than the ISACA names. Build from ISC2 CC and revisit this list in eighteen months.
You have one to three years in IT, audit or compliance. CGRC. Two years is the lowest bar of the four, the Associate route covers you if you are short, and control selection and assessment are the tasks you will be doing daily anyway.
You have three or more years and risk is your focus. CRISC. It is the only one of the four built entirely around the risk cycle, and the 32% weighting on response and reporting matches what risk analysts are actually measured on.
You are moving into audit or assurance. CISA. Nothing else on this list carries the same recognition with audit committees and external assessors.
You are aiming at security manager or CISO. CISM, and take CISA or CISSP first if you can, because either waives two of the five years. Our CISA vs CISM comparison works through the sequencing in detail.
Exam Tip: ISACA lets you sit the exam before you meet the experience requirement, and your pass stays valid while you accrue the years. Sitting early while the material is fresh from a study cycle is usually smarter than waiting until you qualify on paper.
What GRC Roles Pay
Salary.com put the average US governance, risk and compliance analyst salary at $100,913 as of 1 July 2026, with GRC managers averaging $160,304. ERI SalaryExpert's figure for the same analyst role is lower at $88,758, and the gap between the two is mostly seniority mix and location, so treat either as a midpoint rather than a target.
The certification's effect on that number is real but indirect. None of these four credentials adds a fixed premium. What they do is clear the automated CV filter on roles that list them, which is most GRC roles above entry level, and satisfy the framework knowledge a hiring manager would otherwise have to test for.
Frequently Asked Questions
What is the best certification for GRC?
There is no single best one. CGRC suits practitioners with two years of experience working on control implementation and system authorisation, CRISC suits dedicated risk analysts with three years, CISA suits auditors, and CISM suits people managing a security programme. The experience requirement usually decides it before preference does.
How much is GRC certification?
Exam fees run from $575 to $760. ISACA charges $575 for members and $760 for non-members across CRISC, CISA and CISM, plus a $50 application fee once you pass. ISC2's CGRC is $599 with a $135 annual maintenance fee. OCEG's GRCP is $575.
Is GRC in high demand?
Demand is steady rather than explosive. The US Bureau of Labor Statistics projects 3% growth for compliance officers between 2024 and 2034, about average across all occupations, with roughly 33,300 openings a year over that decade. What keeps GRC hiring active is regulatory change, since new frameworks and reporting obligations create work regardless of the underlying growth rate.
What is the GRC certification?
GRC certification is shorthand for any credential covering governance, risk and compliance rather than one specific exam. In practice it means one of CGRC, CRISC, CISA, CISM or GRCP, each testing a different slice of the same discipline: setting policy, assessing risk, selecting controls and proving compliance to an auditor.
Ready to Start Practising?
The GRC exams are all pass-mark exams with heavy scenario weighting, which means recognising the correct answer matters more than recalling the definition. Practice questions with full explanations are the fastest way to build that instinct.
CertCrush has full practice exam banks and study guides for CRISC, CISA and CISM, each with worked explanations for every option rather than just the correct one.
Create a free account and start with a domain you think you already know. The score usually decides your study plan for you.
