Most people who fail the CRISC exam do not fail because they misunderstood risk management. They fail because they answered as an engineer when ISACA wanted them to answer as a risk practitioner reporting to a board. The knowledge gets you to roughly a coin flip. The answering technique gets you over 450.
This is a 12-week CRISC study plan built around the job practice that took effect on 3 November 2025, which is the version you will sit in 2026. It assumes eight to ten hours a week, and it front-loads the two domains that carry the most marks.
What the CRISC exam looks like in 2026
The format has been stable for years, so the numbers below are the ones to plan against.
| Detail | CRISC |
|---|---|
| Questions | 150 multiple choice |
| Time limit | 240 minutes (4 hours) |
| Score scale | 200 to 800 |
| Passing score | 450 |
| Exam fee | US$575 members, US$760 non-members |
| Certification application fee | US$50, one off, after you pass |
| Delivery | Pearson VUE test centre or remote proctored |
| Maintenance | 20 CPE hours a year, 120 over three years, plus US$45 (members) or US$85 (non-members) annually |
That works out to 96 seconds a question. It sounds generous, and for most of the exam it is, but CRISC stems are long. A scenario that sets up a third-party risk, names a control owner and then asks what the risk practitioner should do FIRST can run to five or six lines before the options start.
Exam Tip: The 450 pass mark is a scaled score, not a percentage. ISACA does not publish the raw number of correct answers that converts to 450, so ignore anyone who tells you it is exactly 65 percent or 73 percent. Aim to be comfortably above the line on practice questions rather than chasing an exact figure.
There is no penalty for a wrong answer, so leave nothing blank.
The domain weights changed on 3 November 2025
ISACA refreshed the CRISC job practice on 3 November 2025. The four domains kept their names, but the marks moved.
| Domain | Old weight | Current weight |
|---|---|---|
| 1. Governance | 26% | 26% |
| 2. IT Risk Assessment | 20% | 22% |
| 3. Risk Response and Reporting | 32% | 32% |
| 4. Information Technology and Security | 22% | 20% |
The shift is small in isolation, two points off the technical domain and two points onto risk assessment, but it confirms a direction. Domain 3 alone is nearly a third of the exam, and Domains 1 to 3 together account for 80 percent. The technical domain that most IT people find easiest is now the smallest.
Plan your hours to match. A lot of candidates spend week after week revising control types and security architecture because that material feels concrete, then walk into an exam where four out of five questions are about governance, assessment and reporting.
Check the edition of any study material you buy. A review manual or question bank written before November 2025 still teaches the right concepts, but it will apportion its content to the old weights.
Sort the experience requirement before you book
Passing the exam does not make you CRISC certified. ISACA requires three years of relevant work experience across at least two of the four domains, and one of those two must be Domain 1 (Governance) or Domain 2 (IT Risk Assessment). Experience only in Domains 3 and 4 does not qualify.
Two rules catch people out:
- There are no waivers or substitutions. A degree does not shorten the three years and neither does another certification. CISSP holders who are used to the ISC2 one-year education waiver find this out late.
- The experience must be recent. It has to fall within the 10 years before your application date.
You can sit the exam before you have the experience. You then have five years from your pass date to apply. If you are two years into a risk role, sit it now and apply when you qualify, because the pass does not expire in that window.
The 12-week CRISC study plan
Twelve weeks at eight to ten hours a week is about 110 hours of study. That is enough for someone already working in risk, audit or security governance. If IT risk is new to you, stretch the first block to six weeks rather than compressing the review block at the end.
Weeks 1 to 3: Governance and the CRISC vocabulary
Read Domain 1 in full and stop trying to map everything onto how your own employer does it. ISACA has a specific model of the world and the exam tests that model.
Focus on risk appetite versus risk tolerance versus risk capacity, the three lines model, who owns a risk against who owns the control, and the difference between a risk register and a risk profile. Write the definitions out in your own words. If you cannot explain why a risk owner cannot be the same person as the control tester, you are not ready to leave the domain.
End of week 3: take 40 questions on Domain 1 only. Expect 55 to 65 percent. That is normal at this stage.
Weeks 4 to 6: IT Risk Assessment
This domain is 22 percent of the exam and it is where quantitative material lives. Get comfortable with annualised loss expectancy, single loss expectancy and exposure factor, threat and vulnerability identification, and the difference between inherent, current and residual risk.
You will not face heavy arithmetic, but you will face questions that hinge on knowing that residual risk is what remains after controls, and that a control cannot reduce inherent risk by definition.
Spend one full session on risk scenario development. It comes up repeatedly and it is poorly covered in most free material.
Weeks 7 to 9: Risk Response and Reporting
The biggest domain, 32 percent, and the one worth the most revision time. Cover the four response options (accept, mitigate, transfer, avoid) and when each is appropriate, control design versus control effectiveness, key risk indicators against key performance indicators, and how risk gets reported upward.
The KRI and KPI distinction generates a disproportionate number of questions. A KRI is forward looking and warns you that risk is increasing. A KPI tells you how a process performed. Get that wrong on exam day and you will lose several marks in a domain you cannot afford to lose them in.
Weeks 10 to 11: Technology and Security, plus weak areas
Domain 4 is now the smallest at 20 percent, so give it two weeks, not four. Cover enterprise architecture, data lifecycle, business continuity and disaster recovery concepts including RTO and RPO, and emerging technology risk.
Use the rest of these two weeks on whatever your practice scores say is weakest. Go back to the domain, reread it, then retest it. Repeating questions you already answer correctly feels productive and teaches you nothing.
Week 12: Full mocks and timing
Sit at least two full 150-question mocks under exam conditions, four hours, no notes, no pausing. Review every question you got wrong and every question you guessed correctly. The lucky guesses are the more useful of the two, because they mark knowledge you do not actually have.
Do not learn anything new in the final three days. Reread your own definitions, sleep properly, and confirm your test centre or your remote proctoring setup.
How to answer a CRISC question
This is the part that separates candidates who know the material from candidates who pass.
Nearly every CRISC question has more than one defensible answer. The exam is asking which is BEST, or which comes FIRST, from the perspective of a risk practitioner advising the business. Four habits fix most of it:
- Read the last line of the stem first. "What should the risk practitioner do FIRST" and "which is the BEST recommendation" need different answers to the same scenario.
- Governance beats technology. When one option is a technical fix and another is updating the risk register, informing the risk owner or aligning to policy, the governance answer usually wins.
- The business decides, you advise. Options where the risk practitioner accepts a risk, approves an exception or overrules a business owner are almost always wrong. Your job is to assess, advise and report.
- Assess before you act. If nothing in the scenario has been analysed yet, the first step is usually to assess the risk or its impact, not to implement a control.
Exam Tip: When two options both look correct, ask which one a board would want to hear about. CRISC is written from the perspective of someone whose output lands in a risk committee paper, not a change ticket.
Frequently Asked Questions
Is CRISC harder than CISSP?
CRISC is narrower and shorter. CISSP is 100 to 150 adaptive questions across eight domains covering everything from cryptography to physical security, while CRISC is 150 fixed questions across four risk domains. Most people who hold both say CISSP demands more breadth of knowledge and CRISC demands more discipline in interpreting the question. If you come from a technical background, CRISC often feels harder than its syllabus suggests because the answering style is unfamiliar.
Is CRISC certification worth it?
It is worth it if you work in or want to move into IT risk, GRC or a second-line assurance role, because it is one of the few certifications hiring managers in that space recognise instantly. It is worth much less as a first certification or as a general security credential. Our CRISC deep dive covers the salary and career case in detail.
How much does the CRISC exam cost?
Registration is US$575 for ISACA members and US$760 for non-members. Add a one-off US$50 application processing fee when you apply for certification after passing, then US$45 (members) or US$85 (non-members) a year to maintain it. ISACA membership is priced separately and varies by chapter, so work out the combined figure before assuming the member rate saves you money on a single exam.
Which is harder, CISA or CRISC?
CISA is generally considered harder, mainly because it is broader. It covers the full audit process, IT operations, acquisition and development, and business resilience, and it has a reputation for wording that is harder to parse. CRISC has fewer moving parts, but its questions are more consistently judgement based. If you are choosing between them, our comparison of the ISACA certification order is a better starting point than difficulty alone.
Ready to Start Practising?
Reading about risk scenarios will not train you to pick the BEST answer under time pressure. Answering hundreds of them will.
The CertCrush CRISC question bank is built to the current job practice weights, with explanations that tell you why the other three options are wrong, which is where the real learning sits on this exam.
Create a free account and start with 40 Domain 1 questions tonight. If you are still deciding between ISACA credentials, the 12-week CISM plan and the 12-week CISA plan follow the same structure.
