Skip to main content
CRISC Instructor-Led All 4 Domains

CRISC Exam
Preparation

Certified in Risk and Information Systems Control training for IT risk and compliance professionals. All 4 domains with practitioner instruction. Strong alignment to NIST 800-30 and CMMC risk assessment requirements.

150
Exam Questions
4
Domains
3.5 hr
Exam Window

What Is the CRISC Certification?

CRISC (Certified in Risk and Information Systems Control) is ISACA's certification for IT risk and control professionals. It is recognized globally as the standard credential for those who identify, assess, evaluate, and manage IT risk and implement and maintain information systems controls.

CRISC holders typically work in enterprise risk management, IT audit, GRC, and cybersecurity risk roles. For organizations under CMMC, the CRISC framework maps directly to the risk assessment and risk management requirements embedded in NIST 800-171 and NIST 800-30.

ISACA requires three years of cumulative work experience across CRISC domains for certification. You can sit for the exam before meeting the experience requirement.

Exam Overview

Number of Questions150
Time Allowed3.5 hours
Scoring Scale200–800
Passing Score450
Number of Domains4
Experience Required3 years risk/control

Exam details subject to change. Verify at isaca.org.

CRISC Exam Domains

Four domains covering the full IT risk and control lifecycle.

01

Governance

26%

IT risk governance strategy and framework, risk appetite, risk tolerance, and the organizational structure needed to manage IT risk effectively. Connects to CMMC governance requirements and NIST 800-37 risk management framework.

02

IT Risk Assessment

20%

Identifying and evaluating IT risk scenarios, threats, vulnerabilities, and potential business impact. Risk identification, risk analysis methodologies, and risk assessment documentation. Direct alignment to NIST 800-30 risk assessment requirements.

03

Risk Response and Reporting

32%

The largest CRISC domain. Selecting and implementing risk treatment options (accept, mitigate, transfer, avoid), monitoring residual risk, reporting risk posture to stakeholders, and maintaining risk registers. Critical for CMMC POA&M management.

04

Information Technology and Security

22%

IT concepts, infrastructure components, and security technologies as they relate to risk and control. Covers access controls, encryption, network security, and IT operations from a risk management perspective.

CRISC and CMMC Risk Management

CMMC Level 2 requires risk assessments that align to NIST 800-30. CRISC-certified professionals have the structured methodology to conduct, document, and maintain these assessments in a way that satisfies C3PAO assessors. CRISC maps to CMMC control family 3.11 (Risk Assessment) and the risk treatment requirements across the NIST 800-171 control families.

The CRISC framework for risk reporting and residual risk monitoring also directly supports the POA&M (Plan of Action and Milestones) management process that CMMC requires. CRISC-credentialed team members can own the risk register, risk acceptance decisions, and risk reporting that C3PAO assessments scrutinize.

Related Training and Services

Start Your CRISC Preparation

Schedule a conversation to discuss your certification timeline, current background, and the training path that fits your schedule and goals.

Schedule CRISC Training Consultation

Virtual Infrastructure Services LLC · South Brunswick, NJ · +1 (732) 200-7351