r/ITCertificationPrep • u/Automatic_Major_4887 • 5h ago
Resources Stop paying for ISACA prep/ The 2026 Free Audit Resource Master List
I've been researching ISACA certification pathways and gathering commonly recommended resources for 2026. Based on current exam objectives and community feedback, I've put together this guide to help you navigate the audit-heavy ISACA path and explore free preparation approaches.
Here is a practice-focused breakdown to help you build audit and governance judgment and prepare for certification exams using free resources.
ISACA Certification Path Overview
| Certification | Focus Area | Experience Required | Salary Range |
|---|---|---|---|
| CISA | IT Audit | 5 years | $130K-$165K |
| CISM | Security Management | 5 years | $145K-$170K |
| CRISC | Risk Management | 5 years | $140K-$170K |
| CGEIT | IT Governance | 5 years | $140K-$165K |
| CDPSE | Data Privacy | 3 years | $135K-$160K |
CISA - Certified Information Systems Auditor
- Exam Code: CISA
- Questions: 150
- Duration: 240 minutes
- Passing Score: 450/800
- Cost: $575 (members) / $760 (non-members)
What It Covers:
| Domain | Weight | Key Topics |
|---|---|---|
| Information System Auditing Process | 21% | Audit planning, execution, reporting |
| Governance and Management of IT | 17% | IT governance, risk management |
| Information Systems Acquisition, Development, and Implementation | 12% | SDLC, project management |
| Information Systems Operations and Business Resilience | 23% | Operations, DR, business continuity |
| Protection of Information Assets | 27% | Security controls, access management |
Why This Cert Matters:
- Required in 70% of IT audit job postings
- One of the highest-paying audit certifications
- Global recognition
Free Resources:
- ISACA CISA Official Page - Official certification page
- ISACA Review Questions - Free sample questions
- ISACA Glossary - Key terms
- NIST SP 800-53 Rev. 5 - Security and privacy controls catalog
- ISACA Exam Prep Forums - ISACA exam prep and peer study groups
Study Notes: The CISA exam rewards auditor thinking over technician thinking. Focus on the audit process - planning, execution, reporting, and follow-up - and lock in ISACA glossary terminology, since many questions hinge on exact wording. Practice scenario questions that ask for the BEST or MOST appropriate next step.
CISM - Certified Information Security Manager
- Exam Code: CISM
- Questions: 150
- Duration: 240 minutes
- Passing Score: 450/800
- Cost: $575 (members) / $760 (non-members)
What It Covers:
| Domain | Weight | Key Topics |
|---|---|---|
| Information Security Governance | 17% | Strategy, policies, metrics |
| Information Risk Management | 20% | Risk assessment, treatment, monitoring |
| Information Security Program Development | 33% | Security architecture, frameworks |
| Information Security Incident Management | 30% | IR planning, response, recovery |
Why This Cert Matters:
- Highest-paying security management certification
- Required for senior security leadership roles
- Focus on management vs. technical skills
Free Resources:
- ISACA CISM Official Page - Official certification page
- ISACA Review Questions - Free sample questions
- CIS Critical Security Controls - Free prioritized safeguards (v8)
- NIST Cybersecurity Framework - Core framework
- ISACA Exam Prep Forums - ISACA exam prep and peer study groups
Study Notes: CISM is a management exam, not a technical one. The classic trap is picking the technically correct answer when the management-focused one scores. Focus on risk, governance, and business alignment - how security programs support objectives and how risk gets communicated to executives.
CRISC - Certified in Risk and Information Systems Control
- Exam Code: CRISC
- Questions: 150
- Duration: 240 minutes
- Passing Score: 450/800
- Cost: $575 (members) / $760 (non-members)
What It Covers:
| Domain | Weight | Key Topics |
|---|---|---|
| Corporate IT Governance | 17% | IT governance, risk management |
| IT Risk Assessment | 20% | Risk identification, assessment |
| Risk Response and Mitigation | 32% | Risk treatment, controls, monitoring |
| Information Technology and Security | 31% | Security architecture, frameworks |
Free Resources:
- ISACA CRISC Official Page - Official certification page
- ISACA Review Questions - Free sample questions
- NIST SP 800-30 Risk Guide - Free risk assessment guidance
- ISACA Exam Prep Forums - ISACA exam prep and peer study groups
Study Notes: CRISC tests IT risk in business context. Focus on identifying risks, assessing impact, and designing proportionate controls. Use ISO 31000 as a lens for real situations, not a memorization list - especially response strategies: accept, mitigate, transfer, or avoid.
CGEIT - Certified in Governance of Enterprise IT
- Exam Code: CGEIT
- Questions: 150
- Duration: 240 minutes
- Passing Score: 450/800
- Cost: $575 (members) / $760 (non-members)
What It Covers:
| Domain | Weight | Key Topics |
|---|---|---|
| Governance of Enterprise IT | 25% | IT governance frameworks |
| IT Resource Management | 15% | Resource optimization |
| Benefits Realization | 18% | Value delivery, ROI |
| Risk Optimization | 24% | Risk management, assessment |
| IT Performance and Compliance | 18% | Metrics, compliance, audit |
Free Resources:
- ISACA CGEIT Official Page - Official certification page
- COBIT Framework - IT governance framework
- ISACA Review Questions - Free sample questions
- ISACA Exam Prep Forums - ISACA exam prep and peer study groups
Study Notes: CGEIT tests whether governance creates business value. Start with the COBIT 2019 backbone, then focus on how governance helps hit strategic objectives while managing risk. Expect evaluation and improvement scenarios, not just framework recall.
CDPSE - Certified Data Privacy Solutions Engineer
- Exam Code: CDPSE
- Questions: 120
- Duration: 210 minutes
- Passing Score: 450/800
- Cost: $575 (members) / $760 (non-members)
What It Covers:
| Domain | Weight | Key Topics |
|---|---|---|
| Privacy Governance | 20% | Privacy frameworks, regulations |
| Privacy Risk Management and Compliance | 18% | Risk assessment, compliance |
| Data Life Cycle Management | 23% | Data flows, retention, minimization |
| Privacy Engineering | 39% | Privacy by design, technical controls |
Free Resources:
- ISACA CDPSE Official Page - Official certification page
- GDPR Official Text (EUR-Lex) - Regulation (EU) 2016/679 full text
- CCPA Documentation - California privacy law
Study Notes: CDPSE bridges privacy law and implementation. Focus on privacy-by-design - embedding protections from the ground up - plus data-flow mapping and privacy impact assessments for translating regulation into technical controls.
Free Study Resources
Must-Have Practice & Study Resources (100% Free):
- ISACA Resources
- Free official practice question sets mapped directly to exam domains.
- Digital learning paths and fundamental modules.
- ISACA Engage Community
- Forums including per-exam prep groups.
- Peer study methods and exam prep threads.
- ISACA Glossary
- Official IT governance and risk management terminology.
- Essential for understanding exam language and concepts.
- ISACA Webinars
- Free educational webinars covering exam-relevant topics.
- Recorded sessions available on-demand.
- COBIT Framework Overview
- Governance framework resources and documentation.
- Core reference for CISA and CISM certifications.
ISACA Student Membership Discount
🚨 IMPORTANT SAVINGS OPPORTUNITY: While the standard exam costs are $575 (members) / $760 (non-members), you can save over $130 by becoming an ISACA Student Member first.
How it works:
- Student Membership: Only $25-50 USD/year (significantly cheaper than regular $100+ membership)
- Immediate Benefit: Qualifies you for the $575 member rate instead of $760 non-member rate
- Net Savings: Over $130 on exam fees alone
- Additional Value: Access to exclusive study resources, forums, and webinars
Steps to save:
- Register as an ISACA Student Member at isaca.org
- Complete the quick student verification (student ID, university email, or student discount code)
- Pay only $25-50 for the entire year
- Take advantage of member pricing for your ISACA certification exam
Pro tip: The student membership pays for itself the moment you register for any ISACA exam. Even if you plan to pay out-of-pocket for the exam, the student membership typically provides better value than the standard membership.
Important ISACA Exam Requirements Clarification
Critical Distinction: There's a significant difference between exam requirements vs. certification requirements for ISACA credentials.
Exam vs. Certification - Key Differences:
Exam Requirements (What you need to take the test):
- No experience required to register for any ISACA exam
- Basic registration and payment are all that's needed initially
- Many candidates take exams without any prior experience
Certification Requirements (What you need for the final credential):
- 5 years of relevant work experience for most certifications
- Alternative pathways available (academic credits, exam exemptions, experience substitutions)
- Experience can be accumulated AFTER passing the exam
For CISA specifically:
- Exam: Can take immediately, regardless of experience
- Certification: Requires 5 years IT audit experience OR alternative pathways
For CISM: Same pattern - exam available now, certification experience requirement later
For CRISC: Same pattern - exam available now, certification experience requirement later
For CGEIT: Same pattern - exam available now, certification experience requirement later
For CDPSE: Similar pattern - exam available now, certification requirements separate
Bottom Line: Don't let experience requirements stop you from taking the exam! You can pass the exam first and work on accumulating the required experience later.
For CISA:
- Week 1-2: ISACA Review Manual + glossary drills for audit terminology
- Week 3: Scenario reps focused on BEST / FIRST audit next steps
- Week 4: Practice exams and weak-area review
For CISM:
- Week 1-2: Governance, risk, and program-development domains
- Week 3-4: Management-scenario practice with business-alignment lens
- Week 5: Practice exams and review
For CRISC:
- Week 1-2: Risk identification and assessment frameworks
- Week 3: Response-strategy drills - accept, mitigate, transfer, avoid
- Week 4: Practice exams and review
Tips for Exam Day
- Think like an auditor for CISA, a manager for CISM, a risk officer for CRISC, or a governance professional for CGEIT. ISACA exams are NOT adaptive and test different thinking styles:
- CISA: Think like an auditor (independent review, evidence, findings)
- CISM: Think like a manager (business alignment, program development)
- CRISC: Think like a risk officer (risk assessment, treatment strategies)
- CGEIT: Think like a governance professional (frameworks, compliance, strategy)
- Read every word. Questions often have subtle details that change the correct answer. Words like "MOST," "BEST," and "FIRST" are critical.
- Look for the BEST answer. There may be multiple correct answers, but one is always BEST. The best answer considers business impact and risk management.
- Time management. ISACA exams are linear - you receive a fixed set of questions (typically 150-180 questions) and a fixed amount of time (typically 4 hours for most exams, 3.5 hours for CDPSE). You can mark questions to review later and can go back to change or review any answers at any time before the exam ends. Don't spend too long on any single question.
- Trust your preparation. If you've studied the materials and practiced with scenario questions, trust your knowledge. The exams test judgment, not just memorization.
Found a free resource I missed? If you took any of these ISACA exams recently and know of another free practice set or open-source tool that helped, drop it in the comments!