CRISC — Certified in Risk and Information Systems Control — is ISACA's certification for people who sit in the most consequential seam in modern organisations: the join between technology and business risk. It is less famous than CISSP and less managerial than CISM, and that is precisely its value. CRISC certifies a specific, scarce skill: translating technical reality into risk language that decision-makers can act on, and translating risk decisions back into controls that engineers can build.
What the certification actually covers
The exam is organised into four domains, weighted by what the role actually demands:
| Domain | Weight | What it certifies |
|---|---|---|
| 1 · Governance | 26% | Appetite, accountability, organisational and risk governance |
| 2 · IT Risk Assessment | 20% | Threats, vulnerabilities, scenarios, inherent vs residual risk |
| 3 · Risk Response & Reporting | 32% | Treatment options, control design, KRIs, registers, reporting |
| 4 · Information Technology & Security | 22% | The technical landscape seen through a risk lens |
Notice where the weight sits. The heaviest domain is not assessment — it is what you do after assessment: choosing responses, designing controls, defining indicators, and reporting in a way that produces decisions. That weighting is a job description in disguise.
Who CRISC is for — and who it isn't
The natural candidates are practitioners already touching risk from one side: security analysts who keep getting pulled into risk discussions, IT auditors who want to move from finding problems to managing them, control owners, GRC analysts, and engineers stepping toward governance. The certification formalises the bridge they are already walking.
It is a poor fit for two groups. Pure technologists who want deeper technical credentials will find CRISC frustratingly business-flavoured — every question routes through objectives, owners and appetite. And senior security leaders running whole programs are usually better served by CISM, which certifies program management rather than risk practice.
The cleanest test: if your job is to operate security, look elsewhere. If your job is to help the organisation decide about technology risk, CRISC is your certification.
The exam and the experience requirement
The exam is 150 questions in four hours, scored on ISACA's 200–800 scale with 450 to pass. It is scenario-heavy and famous for BEST/FIRST/MOST questions where several options are defensible and one matches the ISACA worldview: assess before acting, accountability stays with owners, business objectives anchor everything.
Certification also requires three years of cumulative work experience across at least two of the four domains, gained within the ten years preceding application (or within five years after passing). You can sit the exam before the experience is complete — many candidates pass first and certify when the experience clock fills. Plan for continuing education thereafter; the credential is maintained through annual CPE.
Where the path leads
CRISC-shaped roles cluster around titles like IT risk analyst and manager, technology risk officer, GRC lead, third-party risk manager, and operational resilience roles in regulated industries. Two forces are widening that funnel. Regulation keeps converting technology risk into board-level legal exposure — DORA and NIS2 in Europe, DPDPA in India, TRM expectations across APAC financial sectors — and every such regime needs practitioners who can evidence risk management, not just perform it. And cloud plus AI keep generating risk categories faster than organisations can govern them, which is demand for exactly the assess-respond-report loop CRISC certifies.
Salary surveys consistently place CRISC among the highest-paying certifications, typically alongside CISM and CISSP at the top of the tables. Treat exact figures with care — they vary sharply by market and survey — but the signal is stable: organisations pay a premium for people who can own the risk conversation.
How it combines with other certifications
CRISC pairs rather than competes. CRISC + CISSP reads as "deep security knowledge, plus the judgment to prioritise it." CRISC + CISM is the governance power pair for leadership tracks. CRISC + CCSP positions you for cloud risk specifically — currently the most undersupplied combination in the market.
If the seam between technology and business decisions is where you want to work, CRISC is the credential that names the skill. The exam is passable in a disciplined 90 days — and the role it certifies is one of the few in security that automation keeps making more necessary, not less.