CRISC — Certified in Risk and Information Systems Control
ISACA's IT risk management certification and the most recognized credential specifically for IT risk professionals. Requires three years of IT risk management experience. Not DoD 8140 approved but highly recognized in enterprise, financial services, and consulting. CRISC covers the full risk lifecycle from identification through assessment, response, and monitoring — more operationally focused on risk management processes than the broad audit scope of CISA. Often the companion cert to CISA for practitioners who want both audit and risk management credentials. One of the best-compensated ISACA credentials in the market.
| Issuer | ISACA |
| Level | expert |
| Domains | Governance, Risk & Compliance, Vulnerability Management |
| Practical weight | 0% |
| Cost (USD) | 760 |
| Renewal | 3 years |
| Skills | it_risk_identification, it_risk_assessment, risk_response, risk_monitoring, control_design, risk_reporting |
Official certification page
Browse all 426 cybersecurity certifications on EBCertMap