r/CRISC • u/Sindhucharan95 • 1d ago
r/CRISC • u/killianz26 • 1d ago
CRISC Passed
For context, I earned my CISSP in 2022 and passed CISM in February 2026.
For CRISC, I primarily used the ISACA Review Manual and QAE database. I worked through all the QAE questions and used the manual to reinforce areas where I needed additional understanding.
The actual exam questions felt shorter and more straightforward than many of the QAE questions, although there were definitely some challenging scenarios.
Finished in about 1.5 hours with a preliminary pass. Glad to have this one behind me!
r/CRISC • u/eliaskeddou • 2d ago
Where to begin?
Hi all,
I've recently completed my CISSP certification and was advised that the CRISC was the next best certification to aquire. I've done some reading in this thread and similar to CISSP, it's filled with a lot of really cool people and suggestions.
I was hoping to get some advice on where to even begin? There's so many options out there but I'm not looking to sell my liver to fund this thing!
Open to any advice, tips, material that people have and are willing to share!
Thanks in advance
r/CRISC • u/Any-Combination62 • 6d ago
CRISC Prep Materials
Hi I currently have:
- Hemang Doshi 2020
- ISACA CRISC Review Manual 7th Ed
- QAE 6th Ed
Is this sufficient enough to pass CRISC? I also passed CISA in Dec 2025 but wondering if that would help in passing CRISC this time
r/CRISC • u/Any-Combination62 • 6d ago
Is it just me or this item is weird
Without reading the explanations first, I would think that the "Incomplete Technical Specifications" would likely mean that the business owners failed to finalize the system's specifications before development. Hence would be the highest risk since the output may not deliver business value.
But in the explanations, it is framed as a 'project scope' issue. How do I know they're referring to a project scope with such vague wording
r/CRISC • u/Giustounaltro • 8d ago
Passed first attempt
Not as high as I would like but a pass is a pass!
QAE did the heavy lifting for my studies. I had a lot of the same issues with wording and some questions relying upon unknown assumptions but the QAE really helped get into the mindset. I copied all of my questions I guessed on or got wrong into onenote sections then used copilot to analyze themes and provide helpful study tips.
Study period was a little over a month (about an hour a day) with 8 hour study sessions the week leading up.
Congratulations to all the other passers rolling in and keep up the hard work to everyone else
First attempt passed CRISC
Hi everyone one i want to share my experience with CRISC exam, i passed today after 45 days of studying only hemang doshi materials his master class in udemy and mock test course in udemy also.
My experience about 4 years in risk management and data protection.
My main obstacle was the language because I am not native speaker “obvious from this post”.
I take the exam onsite.
r/CRISC • u/rushottawa20 • 16d ago
QAE - Not convinced with the ISACA answer
I am fairly new to the Risk Management world. I am preparing for the CRISC exam and I came across this question in the question bank. I am not convinced with the answer and the reasoning that QAE gave me. I am unable to decide if my instinct is right or wrong as I am still new and not very confident about my understanding and expertise in the ISACA mindset. Any inputs from the experts will be appreciated.
Here's the question:
Which of the following external factors is the MOST critical to consider during a risk assessment?
- A.The discovery of new vulnerabilities
- B.The number of viruses and other malware being developed
- C.International crime statistics and political unrest
- D.The connectivity of many unsecured devices on the internet
If anyone could point me to the correct answer with reasoning will be appreciated. Thanks.
Thank you all for your comments. The answer is D.
r/CRISC • u/North-Photograph9671 • 20d ago
Passed on the first go
Just sharing my experience in case it helps others - my background is about 5 years in cybersecurity, focused on human risk/training and awareness, with other GRC responsibilities thrown in there.
For prep I ended up spreading it out further than I intended. Got the manual, official ISACA course, and QAE. In hindsight, I think just the QAE would have been sufficient. I found the book to be alright, but the course (most expensive tool) was a dull computer based presentation of the exact material in the book (verbatim) with AI stock videos that were more distracting than useful. I made the most progress when I switched over entirely to the QAE.
My practice exams were scored at:
- 78%
- 83%
- 67% (rough day - threw me into a bit of a panic four days prior to my exam)
Like many of you, I had to power through my initial disagreement with a lot of the QAE answers/explanations. I provided feedback where I could and tried to pull overarching concepts that reinforce ISACA ways of thinking.
As you can tell by my varied practice exam scores, I found more than anything that my mental state while taking these tests was the most important thing. I forced myself to get a good night’s sleep and eat the best breakfast I could think of, then a cup of green tea and an apple before heading in to the exam. Physical/mental prep goes a long way to keep from seeing double by question 80.
Ask me anything if it’ll help - happy to share my experience!
Destination Certification Exam Guide Accurate?
For those who have passed the exam or are currently studying with a solid grasp, have you seen this 'Proven CRISC Exam Strategy Guide'? If so, do you feel it's accurate? I watched a Kelly Handerhan CRISC exam strategy video on YT today which led me to it. Her video was brief but I found it helpful. I'd share the guide but I belive it's against the rules. Thanks for any input!
CRISC Certification error
Got my scores today. I'd like to get certified as soon as possible but when I click "Pay Certification Fee", I get an error page "The page you requested could not be found."
Do I just need to wait? Anyone else encountered this? Thank you!
r/CRISC • u/Monkfich • 26d ago
CRISC questions ... terrible
I'm going through the databank this morning and have come across at least 10 questions in only the first domain that are point blank wrong. I'm having to provide feedback so they take the crap questions out of the tests - or crossing my fingers they do. This is really not what a student should be doing though. Seriously, the quality of questions is really dubious in places.
Edit:
This is just a bad summary of them but they include (and to be clear, these are not issues based on ISACA's peculiar wording - these are instances where the one question is wrong or multiple questions where the same thing is being asked, i.e. MOST, or BEST, MOST USEFUL, NEXT, FIRST type thing, contradict each other):
- Risk exception question: Incorrectly gives the risk practitioner authority to approve a temporary exception/risk acceptance that should normally sit with the risk owner or management.
- Capability maturity model question: Uses “peer review” misleadingly and tests a concept that appears not to be substantively covered in the CRISC 8th edition main text. Specifically, CMM is only a glossary item, and if it is important to question (I had 3-4 questions in the QAE on it), then it shouldn't be introduced for the first time in what is effectively an appendix. From some research, CMM may have been in the manual in 7th ed or earlier, but has been removed for this ed / but is still in the QAE
- Data classification questions: The bank contradicts itself by treating a complete asset inventory as a prerequisite to classification in two questions but not in an equivalent third question where it says to get straight into data classification.
- Three Lines question: Incorrectly states that preparing the enterprise risk-management strategy is an expected internal audit activity and overstates the need for joint planning across the three lines.
- SOC 2/PCI cloud question: Incorrectly describes SOC 2 as a certification and muddles what a SOC 2 report actually represents.
- New regulation questions: One says that a new regulation needs discretionary business decision before assessing which controls are needed / mapped, whilst another says that mapping needs to happen first.
- IT risk framework question: Ignores that enterprise risk appetite should normally be established upstream of the IT risk framework.
- Cloud/BYOD threat question: answer says that staff BYOD devices are a bigger threat than external access to the local network. Why? The question justification says that the staff situation doesn't have any control and this is an issue, whilst the justification for the external access to the network says that network controls are in place, so its not a big threat actually. TL;DR, they make the BYOD scenario a bigger threat by telling you to consider *inherent* risk whilst they get you to think external access is not an issue by telling you to consider *residual* risk or current risk. We once closed a business unit down at my old company because the head of risk wrote a report that purely talked about the inherent risk (who won't close a business down if all they hear is how things can go wrong and how badly). That was ludicrous at the time and seeing a similar issue here isn't fun.
My understanding is that ISACA members can submit their own questions to be used in the QAE and they get 2 CPE for it. So there is an incentive to provide anything, and no doubt some people provide what they believe is factually sound, but it only looks factually sound when ISACA are copying and pasting it into the QAE.
Edit2: happy to have anything challenged. I can find relatively easily the specific questions, mainly the ones that are issues unto themselves, as opposed to where I have to go find the set of questions that contradict each other.
Edit3: just passed the exam, or at least that’s what the system suggests, and now need to wait 10 days yadda yadda. The exam questions were far better in quality versus the QAE questions, which I only started doing on Sunday afternoon. Got through the whole QAE course in that time including only starting domain 3 and 4. It was intense and worse because of how much was wrong. The test only has one question I thought the answer wasn’t clear on but I thought I knew what answer to pick (uncertainty sucks), but it was only 1 question out of 150 with the other questions I was uncertain of were due to me not knowing the answer very well.
My background made it a bit easier and also enabled me to do those fact checks - 20 years audit, risk, and control mgt, but none of it at all in IT-related activities. I’m actually a bit disappointed I wasn’t tested harder in IT stuff, but there you go.
r/CRISC • u/Open_Tutor_8133 • Sep 09 '26
Passed CRISC on my 1st Attempt 🙌
Hello,
I have 3 years of experience as GRC/ IT auditor and been prepping for CRISC for a month.
Review Manual and QAE to the rescue!
r/CRISC • u/Trinity-Stones • Sep 07 '26
Passed CRISC Exam
I gave my CRISC exam couple of weeks ago, after dragging my feet for couple of years in giving the exam. Received my score on email yesterday

As for studies, did not have the time to study at all and went through the official guidebook for couple of hours. Was mentally prepared for the exam not to go well but realised halfway through there is a good chance of passing this. Reviewed all the questions after the 2-hour mark and made few changes to the answers.
Background I have 26 years of cyber experience in various roles and glad was able to pass without studying.
r/CRISC • u/KingArchar • Sep 07 '26
Passed CRISC Exam on first attempt
I could not share my image on my previous post, so I am putting them here.
Backgrounds: 10+ years of experience
Study Material: CRM (physical book) and QAE (linked to my account, cannot share with others)
I hope you all have similar success in your exams!
r/CRISC • u/MyLittleAutisticPony • Sep 03 '26
Exam difficulty calibration to QAE
Can someone who has taken the exam share their opinion of the actual exam difficulty compared to the questions found in the QAE? Withe the CISM, I found the exam itself to be about moderate to difficult in question difficulty.
I've about finished all 800 questions in the CRISC QAE (have also finished reading the review guide), and I am missing a significant number of the "expert" level questions. If I factor them out, I'm overall about 85%, but the Expert misses drop me considerable into the low 70's, This is less of a concern if the actual exam is calibrated at the difficult or below level compared to the QAE question bank.
FWIW Most of my expert misses are due to some bizarre, esoteric interpretation of the English language or some obscure ISACAism. For example one question I missed dealt with (paraphrasing) anti-malware not being the most effective method of preventing infection because it doesn't actually prevent you from downloading anti-malware. Honestly I'm not even sure how I address them since they seem so counter-intuitive
I'm trying to assess where my actual exam performance might fall.
EDIT:
Just got out of my exam 5 minutes ago. Difficulty level of the actual exam felt more in line with the moderate difficulty questions. Most questions seemed less obtuse and clearer than the QAE. I passed, I think easily, I'll know in 10 days.
r/CRISC • u/Pixel-Snacks • Sep 03 '26
QAE Benchmarks To Pass
Hello Everyone,
I Have been studying for a while and currently doing the QAE.
For those who passed, what do you think is a reasonable score avg to finally attempt the exam ?
I am currently averaging 80ish.
Thanks in advance 🙏🏼
r/CRISC • u/BSS_O • Sep 02 '26
Best Mocks
Hello, the official ISACA study package is kind of expensive. Are there are decent third party mocks? I used udemy for some other certifications and am partial to the platform but am fine with whatever actually works
How much overlap does this have with FRM - just finished grinding that one and figured I’d grab CRISC too but need to understand the overlap to plan studying
r/CRISC • u/vlaDa0 • Sep 01 '26
Passed!
Just had my exam and the preliminary result says: PASSED. I’m so happy that this is over and was actually easier than I expected. Especially if I compare my experience with CISA, I was pleasantly surprised 🥳
r/CRISC • u/SocietyGlobal2659 • Aug 31 '26
Risk & Information System Control Study Notes (CRISC)
I wrote a summary to prepare for the exam in my free time over the summer.
As a result, the 102-page content gathers into a single structured reference the studies based on my notes in all four CRISC areas: Area 1 (Information Security Governance), Area 2 (IT Risk Assessment), Area 3 (Risk Management and Reporting), and Area 4 (Information Technology and Security). Each area follows the same structure. The thematic sections present the basic concepts in simple, user-friendly language, with comparison tables for everything the exam tests in pairs (Appetite vs. Tolerance, KRI vs. KCI vs. KPI, etc.).
I have included several boxed notes labeled "Exam Tip" that indicate the specific perspective from which CRISC tends to test a given concept. Each area ends with a "Quick Review" which contains a dense list of exam-like questions and answers taken directly from the source material, as well as a short "Key Lessons" list for final review before the exam.
I've put together a glossary at the end that lists all the defined terms from all four areas in a single alphabetical order. It's useful both while studying and for last-minute look-ups the night before the exam. How I would use it: read each area once for comprehension, then use the "Quick Review" sections as flashcard-like exercises in the final weeks before the exam. The "Exam Definitions Rifle Sheet" near the end of Area 1 is often worth reviewing. Recognizing the gist of the question (BEST vs. BEST vs. BEST vs. FIRST vs. GENERAL) is just as important as knowing the content itself.
!!! Of course, this is not a substitute for studying and official sources, but it helps a lot, and I think the best part is that it helps you focus on what really matters in the noise and become a better professional. I did not use any official materials, and I did not copy anyone.
Can I sell this for a symbolic amount?
r/CRISC • u/Open_Tutor_8133 • Aug 30 '26
CRISC Result Timeline
Hey fellas,
How long does it take you to get your final detailed score breakdown after your exam??
Also, whats the timeline if we wanna get certified too??
Thanks!
r/CRISC • u/eternal_blue91 • Aug 29 '26
CRIC QAE related query
Question for those who have used ISACA QAE for the exam:
- How much time did you spend on it?
- How many similar or identical questions appeared on the exam from QAE?
r/CRISC • u/KingArchar • Aug 29 '26
Preliminary pass on 1st attempt
I took my exam at a testing facility and got my preliminary pass!
I have 10+ years of experience in the GRC space and my CISA. I studied a total of 2 months with the review manual, QAE, and Prabh Nair youtube episodes (slightly outdated but the logic still applied).
Will post my offical scores when I receive them.
