CISA is ISACA’s certification for information systems auditors, introduced in 1978 as part of a wider effort to professionalise the field while business processes moved onto digital systems.
The Certified Information Systems Auditor certification is ISACA’s professional credential for people who audit, assess, control and monitor information systems. It should not be confused with the United States Cybersecurity and Infrastructure Security Agency, which is also commonly abbreviated as CISA. In the Belgian job market, the certification is most relevant to IT auditors, internal auditors with technology responsibilities, GRC professionals, risk and control specialists, and security professionals who work closely with audit and assurance teams.
Last reviewed: 2026. This article summarises ISACA’s CISA certification requirements and Belgian market considerations at the time of review. Exam domains, fees, application rules and CPE policies should be checked against the current ISACA CISA exam content outline, certification handbook and CPE policy before booking or applying.
CISA is built around audit judgement rather than tool administration. A candidate is expected to understand how information systems are governed, how controls are designed, how evidence is gathered, and how risk is reported to management. The work may involve security, but the certification is not mainly about configuring firewalls, testing physical locks, or managing building access systems.
That distinction matters because many candidates approach CISA as though it were a purely technical cybersecurity exam. In practice, a CISA-style question often asks whether a control is appropriate, whether evidence is sufficient, or whether an audit finding is significant in the context of business risk. The strongest preparation therefore connects IT knowledge with audit process: scope, risk assessment, testing, evidence quality, reporting, remediation and follow-up.
In Belgium, CISA knowledge often appears in work such as IT general controls testing, SAP or ERP change-control reviews, access recertification, SOC 1 or SOX support for Belgian subsidiaries, third-party assurance, cloud control assessments, and privacy or resilience reviews linked to GDPR and NIS2. A professional may not use the language of the exam every day, but the underlying reasoning is visible whenever audit teams ask whether a system is controlled, recoverable, accountable and aligned with policy.
CISA is a natural fit for professionals whose role sits between technology and assurance. That includes external IT auditors, internal auditors assigned to digital processes, compliance staff responsible for control testing, and risk professionals who need to understand how systems support financial reporting, operational resilience and regulatory obligations.
The Belgian market gives the certification a particular shape. Roles are often concentrated around Brussels and Antwerp, with demand from financial services, pharmaceuticals, professional services, public sector organisations, EU-related institutions and technology consultancies. Language expectations vary by employer: some roles operate mainly in English, while others value French, Dutch, or bilingual French-Dutch capability, especially where audit reports, stakeholder interviews or regulatory discussions cross language communities.
Hiring activity also tends to follow audit planning and reporting cycles. Organisations often define audit needs before annual plans are finalised, then recruit or contract around control testing peaks, transformation programmes or regulatory deadlines. For candidates, this means CISA is most persuasive when paired with examples of actual audit work: an ERP access review, an ITGC testing file, a cloud supplier assessment, a remediation tracker, or a report that translates technical risk into business impact.
The path to CISA has two parts that are easy to mix up: passing the exam and becoming certified. A candidate can pass the exam before meeting all experience requirements, but certification requires a successful application supported by relevant professional experience. ISACA’s standard experience requirement is five years in information systems auditing, control, assurance or security, with certain education or experience substitutions available, including a relevant degree substitution of up to two years.
After passing the exam, candidates have a defined window in which to apply for certification and have their experience verified. The practical point is simple: the exam result alone is valuable evidence of knowledge, but the credential is awarded only after the application, experience verification, ethics commitment and applicable fees are completed. Candidates should therefore keep records of relevant work while studying, including job descriptions, project responsibilities and manager contacts who can validate experience.
| Area | What candidates should verify with ISACA | Why it matters |
|---|---|---|
| Exam format | Current question count, exam duration, delivery options and identification requirements. | Exam-day planning depends on timing, language options, breaks and remote or test-centre rules. |
| Scoring | Current scaled scoring approach and passing score. | Scaled scores are not the same as a simple percentage, so practice results should be interpreted carefully. |
| Application | Experience rules, substitutions and the deadline for applying after passing. | Passing the exam and holding the certification are separate milestones. |
| Maintenance | CPE rules, annual maintenance requirements, fees and ethics obligations. | Certification has to be maintained after it is awarded. |
CISA holders must maintain the credential through continuing professional education. A practical baseline is to plan for 20 CPE hours each year and 120 over a three-year cycle, along with the annual maintenance process and continued adherence to ISACA’s Code of Professional Ethics. The most common mistake after passing is to treat maintenance as an administrative detail rather than a professional habit; CPE is easier to manage when audit work, training, conferences, webinars and internal knowledge-sharing are recorded throughout the year.
The CISA exam content is organised around the lifecycle of information systems audit and assurance. Candidates should expect governance, management, acquisition, development, implementation, operations, resilience and protection of information assets to appear as connected topics rather than isolated definitions. The latest domain names and weights should always be checked in ISACA’s current exam content outline.
From a practical perspective, the exam rewards candidates who can reason through scenarios. A question may describe a system change that was approved late, a privileged access review with incomplete evidence, a business continuity test with weak participation, or a supplier control report with exceptions. The candidate has to decide what matters most from an audit perspective, not merely identify the most technical answer.
This is where many technically strong candidates lose time. They over-index on security tools, cryptography terms or infrastructure details while neglecting governance, audit planning, evidence evaluation and reporting. A firewall setting may be relevant, but CISA often asks whether the organisation has a reliable control process around that setting, whether the control is monitored, and whether management has accepted or remediated the risk.
A useful study plan starts with the work CISA is meant to represent. A Belgian internal auditor preparing for the exam might take a recent access review, map it to CISA domains, and ask how the same engagement would be scoped, tested and reported under exam conditions. That exercise turns the syllabus into something concrete: business risk, control objective, evidence, exception, impact and recommendation.
Structured preparation helps when candidates need discipline, especially if they are balancing study with audit deadlines. A focused course such as CISA instructor-led training can be useful for candidates who want to test their understanding against the exam domains while keeping attention on audit reasoning rather than memorisation. Readers comparing self-study with classroom preparation should look for scenario discussion, domain coverage, practice questions and clear guidance on the post-exam certification application.
A light study rhythm is often more effective than long, irregular sessions. Early study should establish the language of audit and governance, middle study should work through scenario questions and weak domains, and final preparation should focus on timed practice and reviewing why incorrect answers are attractive. Candidates who need a more detailed planning aid can use a separate study planning discussion to clarify timing, experience eligibility and preparation options before booking.
The first 100 days after passing should be treated as part of the certification journey. Candidates should confirm whether they already meet the experience requirement, collect verification details, review the Code of Professional Ethics, and create a CPE tracking habit. Those who do not yet qualify should still record relevant assignments because control testing, risk assessments and assurance work can become important evidence later.
CISA can strengthen a profile, but it is not a legal requirement for IT audit work in Belgium and it does not replace local business knowledge. Employers still look for clear writing, stakeholder management, evidence handling, Excel or data analysis capability, understanding of ERP environments, and the ability to explain risk without exaggeration. The credential is most powerful when it confirms skills that are visible in a candidate’s project history.
Salary signals should be interpreted carefully. Belgian job advertisements and salary surveys may quote EUR gross monthly salary, EUR annual gross salary, package value or contractor day rates, and those categories should not be compared as if they were the same. A sound methodology is to compare roles by title, seniority, city, sector, employment type and language requirement, then cross-check whether the position is mainly audit, security operations, GRC, privacy, risk management or consulting. Without a dated Belgian source and consistent role definitions, precise salary figures would be misleading.
The credential can also help hiring managers understand what a candidate is likely to know. A CISA-certified auditor should be able to discuss audit planning, risk-based scoping, control design, sampling, evidence quality, issue rating, remediation and reporting. That does not guarantee practical excellence, but it creates a shared professional vocabulary for interviews, audit methodology and quality review.
CISA is often compared with other ISACA credentials, particularly CISM and CRISC. The better question is not which credential is more prestigious, but which role outcome the candidate is trying to support. CISA is strongest for IT audit and assurance, CISM fits security management and governance, and CRISC aligns with IT risk identification, assessment and response.
For a Belgian professional working in external audit or internal control testing, CISA is usually the logical first step. A security professional moving towards management responsibility may later find CISM more relevant, while a GRC or enterprise risk professional dealing with risk appetite, control response and risk reporting may prefer CRISC after building audit foundations. A single hub for ISACA training at Readynez can help readers compare those paths without treating all certifications as interchangeable.
One persistent myth is that CISA is only for people who work in cybersecurity. Security knowledge is useful, but the certification is broader than security operations. It deals with the way organisations govern, acquire, operate, protect and assure information systems.
Another myth is that passing the exam automatically makes someone certified. The exam is a necessary step, but certification requires a completed application and verified experience. Candidates who plan this late may pass the exam and then discover that they need more documentation, more qualifying work, or clearer evidence of audit-related responsibilities.
A third myth is that CISA guarantees a higher salary or an audit role. It can make a candidate more credible, especially when employers already value ISACA credentials, but hiring still depends on experience, communication, language fit, sector knowledge and the quality of previous work. The certification is a signal, not a substitute for evidence of performance.
This article is based on the publicly available ISACA CISA certification materials that candidates should verify before making decisions: the CISA exam content outline, the CISA certification handbook, the CISA application guidance, the CPE policy and the ISACA Code of Professional Ethics. Because ISACA may update domains, exam rules, fee schedules and maintenance requirements, publication teams should recheck those sources whenever policies change.
Belgian labour-market observations in this article are qualitative. They are based on common role patterns in IT audit, internal audit, GRC, regulated-sector assurance and consulting, with attention to location, language requirements and sector context. Salary discussion is deliberately limited to interpretation method rather than specific EUR figures because reliable comparison requires dated Belgian sources, consistent role definitions and comparable compensation types.
CISA is ISACA’s Certified Information Systems Auditor credential. It validates knowledge of information systems audit, control, assurance, governance, operations and protection of information assets.
No. In this article, CISA means the ISACA certification for information systems auditors. It is separate from the United States Cybersecurity and Infrastructure Security Agency, which uses the same abbreviation.
A candidate must pass the CISA exam, meet ISACA’s professional experience requirements, submit the certification application, agree to the Code of Professional Ethics and follow the maintenance requirements. Passing the exam and receiving the certification are related but separate steps.
ISACA’s standard requirement is five years of relevant professional experience in information systems auditing, control, assurance or security. Certain substitutions may apply, including education-related substitutions, so candidates should verify the current rules in the ISACA certification handbook.
CISA must be maintained through continuing professional education and annual maintenance requirements. A practical planning baseline is 20 CPE hours per year and 120 CPE hours across a three-year cycle, subject to ISACA’s current CPE policy.
The key takeaway is that CISA is most useful when it is treated as an audit credential with technology depth, rather than as a general cybersecurity badge. Belgian candidates should connect the syllabus to real control work, verify ISACA’s current rules before booking, and plan the certification application and CPE obligations before the exam result becomes old news.
A practical next step is to compare the candidate’s current responsibilities with CISA’s domains and decide whether the gap is knowledge, practice, documentation or confidence with scenario questions. Those who want a structured route for CISA and later security or risk credentials can consider an Unlimited Security Training membership, while keeping the focus on verifiable audit skills and long-term professional maintenance.
Krijg onbeperkte toegang tot ALLE LIVE-beveiligingscursussen onder leiding van een instructeur die je wilt - allemaal voor de prijs van minder dan één cursus.
You're viewing our Belgium (EUR) site from United States
Would you like to view the site in
English
with prices in
Dollar?