Last updated:
CISA preparation guide
CISA exam domains and weights: a preparation map
The CISA outline covers five job practice domains with weights of 18%, 18%, 12%, 26% and 26%. Use those weights to understand exam emphasis, then use topic-level practice evidence to identify what you personally need to study.
The official outline spans the audit process, IT governance, system delivery, operations and resilience, and information asset protection. Domain names group related responsibilities; they are not a substitute for reviewing the underlying topics.
A short CertArc session will not necessarily reproduce the official percentages. Small whole-question samples cannot express every weight exactly. Read a practice percentage alongside its answer count and the knowledge areas actually tested.
Start CISA baselineOfficial CISA domain weights
| Domain | Official exam weight |
|---|---|
| D1 · Information Systems Auditing Process | 18% |
| D2 · Governance and Management of IT | 18% |
| D3 · Information Systems Acquisition, Development and Implementation | 12% |
| D4 · Information Systems Operations and Business Resilience | 26% |
| D5 · Protection of Information Assets | 26% |
Original teaching example
Your assessment shows a low result in operations and resilience, but the missed scenarios were about recovery testing rather than every operations topic.
Begin by reviewing the evidence and recovery concepts you missed. Then check the rest of the domain against the outline. The result identifies a tested gap; it does not demonstrate the same weakness across all operations knowledge.
Move from a domain to a useful study task
Turn “study Domain 4” into a concrete task such as explaining what a recovery test did and did not establish. For each topic, connect the concept to the evidence an auditor would examine and the conclusion that evidence supports.
Check the authoritative outline before your exam
ISACA maintains the exam outline. This page summarizes its domain weights; use the linked official source for the complete topic list and any updates. CertArc results are independent practice signals, not official domain scores.
Frequently asked questions
How many domains are on the CISA exam?
The current ISACA CISA outline has five job practice domains.
Which domains carry the most weight?
Information Systems Operations and Business Resilience, and Protection of Information Assets, each carry 26% in the current outline.
Can I skip the 12% domain?
No. Information Systems Acquisition, Development and Implementation remains part of the tested scope. Lower weight does not mean optional.
Why does my baseline have a different distribution?
A short diagnostic uses a limited number of questions to sample your preparation. Its distribution and domain percentages are not an official exam blueprint or score conversion.
Are domain and knowledge-area results interchangeable?
No. A domain is broader; a knowledge-area result describes a narrower part of your completed practice. Use both together with the number of answers behind each result.
Sources and limits
Exam scope and weights: ISACA CISA exam content outline. Certification eligibility: ISACA certification requirements. Checked September 9, 2026.
Study methods and examples are independent CertArc teaching guidance. Practice results do not convert to an official score or guarantee a pass. CertArc is not affiliated with or endorsed by ISACA.