Back to blog
Certification Deep Dives15 min read

ISACA CGEIT Explained: Domains, Cost and Is It Worth It in 2026?

CGEIT is ISACA's IT governance certification: 150 questions, four domains and a five-year experience rule that blocks most applicants. Here is the full breakdown of the domains, the 2026 cost, the salary data and an honest verdict on whether it is worth it.

Owen Gallagher

Owen Gallagher · Study Skills & Careers Editor

4 August 2026

CGEIT is the certification most IT leaders have heard of, glanced at once, and then quietly put back on the shelf. It sits in ISACA's catalogue next to CISA, CISM and CRISC, it carries one of the highest reported salary figures of any IT credential, and it has a reputation for being both very hard and slightly mysterious. This guide breaks down exactly what CGEIT covers, what the exam looks like, what it costs in 2026, who is actually eligible, and whether it earns its place in your career plan.

The short answer: CGEIT is worth it if you already sit in or next to an IT governance role and you need a credential that proves board-level credibility. It is a poor choice if you are early career, because you almost certainly cannot meet the experience requirement, and there is no way around it.

What Does CGEIT Stand For?

CGEIT stands for Certified in the Governance of Enterprise IT. ISACA positions it as the only certification focused purely on governance of IT at enterprise level, rather than on auditing it (CISA), securing it (CISM) or assessing its risk (CRISC).

The distinction matters more than it sounds. Most IT certifications test whether you can do something: configure a firewall, run an audit, respond to an incident. CGEIT tests whether you can decide something, and then defend that decision to an executive committee. The questions are written from the perspective of someone advising a board on how IT investment, IT risk and IT resourcing should align with what the business is actually trying to achieve.

That framing is why CGEIT feels unusual to candidates coming from technical certifications. There is very little to memorise and a great deal to judge.

Exam Tip: CGEIT questions rarely have a wrong answer in the technical sense. They have a best answer for a governance professional advising the enterprise. When two options both look defensible, pick the one that a board would act on, not the one an engineer would implement.

The Four CGEIT Domains and Their Weights

The current CGEIT exam content outline covers four domains. Domain 1 alone accounts for 40 per cent of the exam, which makes it far and away the highest-weighted single domain across ISACA's certification portfolio.

DomainTopicWeight
1Governance of Enterprise IT40%
2IT Resources15%
3Benefits Realization26%
4Risk Optimization19%

Source: ISACA CGEIT Exam Content Outline.

Domain 1: Governance of Enterprise IT (40%)

This is the exam. Two fifths of your marks come from a single domain covering governance frameworks, governance structures and reporting lines, IT strategy alignment with enterprise strategy, and information and technology governance policies. Expect heavy coverage of how a governance framework is established, who owns it, how it is communicated, and how its effectiveness is measured.

If you are short on study time, weight your revision accordingly. A candidate who knows Domain 1 cold and is merely competent elsewhere is in a much better position than one who spread their effort evenly.

Domain 2: IT Resources (15%)

The smallest domain, covering resource planning, resource optimisation, and the lifecycle management of IT resources including people, information, infrastructure and applications. Sourcing decisions and capability management sit here.

Domain 3: Benefits Realization (26%)

The second-largest domain, and the one that most surprises technical candidates. It covers IT investment evaluation and portfolio management, how benefits are defined and tracked, performance metrics and reporting, and how the enterprise decides whether an IT investment actually delivered what it promised. If you have ever sat in a business case review and wondered who checks these numbers afterwards, this domain is the answer.

Domain 4: Risk Optimization (19%)

Risk strategy, risk frameworks, risk appetite and tolerance, and risk mitigation at enterprise level. Note the word optimisation rather than management. CGEIT treats risk as something to be tuned to the enterprise's appetite, not something to be minimised at all costs. That nuance shows up repeatedly in the answer options.

CGEIT Exam Format: Questions, Time and Passing Score

The CGEIT exam is 150 multiple-choice questions in four hours. Scoring uses ISACA's standard scaled system, running from 200 to 800, with 450 required to pass.

AttributeDetail
Questions150 multiple choice
Duration4 hours
Scaled score range200 to 800
Passing score450
DeliveryPSI test centre or remote proctored
Testing windowsContinuous, register any time

That works out at roughly 96 seconds per question. In practice most candidates finish with time to spare, because CGEIT questions are read-and-judge rather than read-and-calculate. The trap is not the clock, it is second-guessing: candidates who change answers late in the sitting tend to change correct ones to incorrect ones.

The 450 scaled score is not a percentage. It is a converted score, so you cannot work backwards to a raw number of questions. Aim to be comfortably competent across all four domains rather than trying to calculate a minimum viable pass.

Exam Tip: The scaled score of 450 out of 200 to 800 is the same passing threshold ISACA uses for CISA, CISM and CRISC. If you have sat one of those, the scoring experience will feel familiar, but the question style will not.

CGEIT Certification Cost in 2026: The Full Breakdown

The exam fee is the headline number, but it is not the whole cost. Here is what CGEIT actually costs in 2026.

ItemISACA memberNon-member
Exam registrationUS$575US$760
Application processing fee (one-off)US$50US$50
Annual maintenance feeUS$45US$85
ISACA membership (optional)Varies by chaptern/a

Sources: ISACA exam pricing and the CGEIT maintenance requirements page.

A few points that catch people out:

  • The application fee is separate and comes later. You pay the one-off US$50 application processing fee after you have passed the exam and received your official scores, not at registration.
  • Membership can pay for itself immediately. The exam fee gap between members and non-members is US$185, and the annual maintenance gap is a further US$40 a year. In most chapters, membership costs less than that first-year saving.
  • Maintenance is ongoing. CGEIT requires a minimum of 20 CPE hours annually and 120 CPE hours across each three-year cycle, plus the annual maintenance fee. Budget for it, because letting a governance credential lapse is a bad look in a governance role.

If you hold more than one ISACA certification, the annual maintenance fees stack per credential, so factor that in before collecting the full set.

CGEIT Requirements: The Five-Year Rule That Stops Most People

This is the single most important thing to understand about CGEIT, and it is where most prospective candidates fall out.

To become certified, you need a minimum of five years of experience managing, serving in an advisory or oversight role, or otherwise supporting the governance of the IT-related contribution to an enterprise. That experience must:

  • span at least three of the four CGEIT domains
  • include a minimum of one year of experience related to Domain 1 (Governance of Enterprise IT)
  • have been gained within the 10 years preceding your application date

Source: ISACA, Earn a CGEIT Certification.

Two consequences follow from this.

First, unlike CISA and CISM, which allow various education and experience substitutions, CGEIT's requirement is built around genuine governance exposure and there is no shortcut that converts a degree into governance years. If you have not advised, overseen or supported enterprise IT governance, you are not eligible, however strong your technical background.

Second, and more usefully: you can sit the exam before you meet the experience requirement. Passing the exam and becoming certified are separate steps. You have five years from your exam pass date to submit a certification application. That gives a candidate with three or four years of governance exposure a legitimate strategy: sit the exam now while the material is fresh, accumulate the remaining experience, then apply.

Exam Tip: If you are two years short on experience, sit the exam anyway. Your pass stays valid for five years, and exam fees have historically only gone up. Just be careful how you describe yourself in the meantime: you are CGEIT exam passed, not CGEIT certified.

Is CGEIT Hard? What Actually Makes It Difficult

CGEIT is difficult, but not in the way most certification exams are difficult. There is no lab, no command syntax, no performance-based questions, and comparatively little pure recall.

What makes it hard is three things.

The abstraction level. Answers are judged from the perspective of the enterprise, not the IT department. Candidates with deep technical backgrounds routinely pick the technically correct option when the exam wants the governance-appropriate one. Retraining that instinct is most of the work.

The thin study market. Because CGEIT has a small candidate population compared with CISA or CISM, there are far fewer quality practice questions, video courses and study communities available. The official CGEIT Review Manual is the primary resource, and third-party material varies wildly in quality. You will spend more effort finding good practice material than you would for a mainstream certification.

Domain 1's weight. Forty per cent of the exam resting on one domain means a weakness there is very hard to compensate for elsewhere. There is no route to a pass that goes around Governance of Enterprise IT.

What makes it easier than it looks: if you genuinely do this work, a lot of CGEIT is describing your job back to you in ISACA's vocabulary. Experienced governance professionals often find the gap is terminology rather than understanding.

CGEIT vs CISM vs CRISC: Which ISACA Certification Fits Your Role?

The three senior ISACA credentials overlap enough to confuse people and differ enough to matter. Here is the practical split.

CGEITCISMCRISC
FocusGovernance of enterprise ITInformation security managementIT risk and control
AudienceGovernance advisors, IT directors, CIOsSecurity managers, CISOsRisk practitioners, control owners
Core questionIs IT delivering value to the enterprise?Is the security programme managed well?Is this risk identified and treated?
Experience needed5 years, 3 of 4 domains, 1 year Domain 15 years information security management3 years across CRISC domains
Exam questions150150150
Relative candidate poolSmallestLargestLarge

Choose CGEIT if your remit is the whole IT portfolio and your audience is the board. Choose CISM if your remit is the security programme. Choose CRISC if your remit is identifying and treating risk. If you are still deciding between the audit and management tracks entirely, our CISA vs CISM comparison covers that fork.

Most CGEIT holders arrive with another ISACA certification already in hand. It is very rarely anyone's first credential, and that is by design.

Is CGEIT Worth It in 2026? An Honest Verdict

Here is what the market data actually says.

ISACA reports that CGEIT-certified professionals earn average annual salaries exceeding US$141,000. In the UK, ITJobsWatch put the median advertised salary for roles citing CGEIT at £87,500 as of January 2026.

More interestingly, ISACA published analysis in 2026 noting that CGEIT and CISA both posted cash pay premium growth in the 11 to 20 per cent range over the final six months of 2025, according to Foote Partners' IT Skills and Certifications Pay Index, against a certification average of 6.5 per cent. ISACA attributes this to governance moving from a compliance function to board-level oversight, and to the surge in enterprise AI deployment creating demand for people who can defend AI systems to regulators and insurers.

That last point is the real 2026 story. AI governance has become a board agenda item at organisations that previously treated IT governance as a formality, and there is no large pool of people credentialed to speak to it.

CGEIT is worth it if:

  • You already hold a governance, advisory or oversight role and want the credential that matches it
  • You are targeting CIO, IT director, head of IT governance or GRC leadership roles
  • You work in a heavily regulated sector where board-level assurance is scrutinised
  • You already hold CISA, CISM or CRISC and want to move up rather than sideways

CGEIT is not worth it if:

  • You cannot meet the five-year experience requirement and will not within five years
  • You are early or mid career and looking for a credential that opens doors rather than confirming a position you already occupy
  • You want a hands-on technical certification, in which case start with our course catalogue and pick something aligned to the work you actually do
  • Your employer will not fund it and you are paying US$625 or more out of pocket for a credential with a small hiring-manager recognition footprint outside governance circles

The honest summary: CGEIT is a confirmation credential, not a door-opener. It tells the market that someone already operating at governance level has had that judgement externally validated. For the right person that is genuinely valuable. For everyone else it is an expensive exam about meetings.

How to Study for CGEIT

A realistic plan for a working governance professional is 10 to 12 weeks.

  1. Weeks 1 to 4: Domain 1. Give the biggest domain the most time, up front, while your motivation is highest. Work through governance frameworks, structures and strategic alignment until you can explain each without notes.
  2. Weeks 5 to 6: Domain 3 (Benefits Realization). The second-heaviest domain and the one most likely to contain material you do not touch day to day.
  3. Weeks 7 to 8: Domains 2 and 4. IT Resources and Risk Optimization together, since they are the two lightest weightings.
  4. Weeks 9 to 10: Practice questions only. This is where CGEIT is won. You are not testing recall, you are calibrating judgement, and the only way to do that is to answer questions and read why the best answer was best.
  5. Weeks 11 to 12: Weak-domain revision and full timed sittings. Two or three full 150-question sittings under time will tell you far more than another read of the manual.

The single highest-value activity is reviewing explanations for questions you got right for the wrong reason. On a judgement-based exam, a lucky correct answer is a hidden gap.

Frequently Asked Questions

What does CGEIT certification stand for?

CGEIT stands for Certified in the Governance of Enterprise IT. It is an ISACA credential focused on governing IT at enterprise level, covering governance frameworks, IT resources, benefits realisation and risk optimisation.

Is CGEIT difficult?

Yes, but for unusual reasons. There is little pure memorisation, and the difficulty comes from answering from an enterprise governance perspective rather than a technical one, from a thin supply of quality practice material, and from Domain 1 carrying 40 per cent of the exam. Candidates who genuinely work in governance often find the concepts familiar and the ISACA terminology the harder part.

How much does the CGEIT exam cost?

The CGEIT exam costs US$575 for ISACA members and US$760 for non-members in 2026. On top of that there is a one-off US$50 application processing fee paid after you pass, and an annual maintenance fee of US$45 for members or US$85 for non-members once certified.

Is the CGEIT certification worth it?

It is worth it for professionals already in or adjacent to IT governance roles, where ISACA reports average salaries above US$141,000 and pay premiums grew 11 to 20 per cent in late 2025. It is not worth it for early-career candidates, who cannot meet the five-year experience requirement and would get more value from a credential that opens doors rather than confirming seniority.

Can I take the CGEIT exam without five years of experience?

Yes. Sitting the exam and becoming certified are separate steps, and you have five years from passing to submit your certification application. Many candidates sit the exam while still accruing the required experience, but until the application is approved you should describe yourself as CGEIT exam passed rather than CGEIT certified.

CGEIT vs CISM: which should I take first?

Take CISM first if your role sits in information security management, because the candidate pool, study material and job-advert recognition are all far larger. Take CGEIT if your remit already spans the whole IT portfolio and your audience is the board. Most CGEIT holders earn it after another ISACA certification rather than as their first.

Ready to Start Practising?

CGEIT rewards calibrated judgement, and judgement is built by working through questions and understanding why the best answer beat three plausible ones. That is exactly the kind of practice that separates a pass from a near miss on any ISACA exam.

CertCrush provides realistic practice exams with full explanations for ISACA certifications including CISA and CISM, plus the wider CompTIA, ISC2, AWS and Microsoft catalogues. Every question comes with a detailed rationale, so you learn the reasoning rather than just the answer.

Create your free CertCrush account and start practising today.

CGEITISACAIT GovernanceCertification Deep DivesCareer AdviceCISMCRISC
Owen Gallagher

Written by

Owen Gallagher · Study Skills & Careers Editor

Owen spent years as an IT trainer watching smart people fail exams they should have passed — usually because of how they studied, not what they knew. He writes about study technique, exam psychology, career strategy and the service-management certifications (ITIL, PRINCE2, APM). His articles are the ones to read before you open a single practice question.

All articles by Owen

Want a CGEIT practice course?

We don’t cover this exam yet — we build the most-requested courses first. One click tells us you want it.

Practising for something nearby?

Try real exam-style questions free — no account needed, full explanations included.