Everything needed to plan for the CRISC (CRISC) exam: number of questions, time limit, passing score, and the official domain weightings. For the study checklist itself, see the CRISC study guide.
CRISC (CRISC) is a Professional level ISACA certification exam with about 150 questions in 240 minutes, requiring a scaled score of 450 to pass. It covers 4 official domains: IT Risk Assessment (27%); Corporate IT Governance (26%); Information Technology and Security (24%); Risk Response and Reporting (23%).
Exam code
CRISC
Questions
~150
Time limit
240 min
Passing score
450
Official domains
4
Level
Professional
Provider
ISACA
Practice questions
300+ on CertStud
| Domain | Weight | What it covers |
|---|---|---|
| IT Risk Assessment | 27% | Risk identification, analysis, evaluation, scenario development, and threat/vulnerability assessment techniques. |
| Corporate IT Governance | 26% | IT governance frameworks, risk appetite, risk culture, regulatory alignment, and governance oversight mechanisms. |
| Information Technology and Security | 24% | IT security architecture, cloud security, identity management, data protection, incident response, and technology risk. |
| Risk Response and Reporting | 23% | Risk treatment options, control design, KRI development, risk reporting, and stakeholder communication. |
Percentages reflect published official domain weightings. Prerequisite knowledge and current scoring rules are confirmed on the ISACA exam page before booking.
The CRISC exam has approximately 150 questions. Question counts can vary slightly between deliveries, so treat 150 as the planning figure rather than a fixed number.
Candidates get about 240 minutes to complete the CRISC exam, which works out to roughly 2 minute(s) per question at 150 questions.
The CRISC exam requires a scaled score of 450 to pass. Scores are reported on a scaled rather than a raw percentage basis, so a passing result does not correspond to a simple count of correct answers.
The CRISC exam covers 4 official domains: Corporate IT Governance (26%), IT Risk Assessment (27%), Risk Response and Reporting (23%), Information Technology and Security (24%).
IT Risk Assessment carries the heaviest weighting on the CRISC exam at 27% of the exam. Risk identification, analysis, evaluation, scenario development, and threat/vulnerability assessment techniques.
CRISC is the exam code for CRISC (CRISC - Certified in Risk and Information Systems Control), a Professional level ISACA certification exam covering 4 domains.
The CRISC exam reports a scaled score of 450 on a scaled score. Plan for roughly 150 questions across 240 minutes, weighted by domain: 27% IT Risk Assessment, 26% Corporate IT Governance, 24% Information Technology and Security, 23% Risk Response and Reporting.
CertStud offers free CRISC practice questions with detailed explanations, plus full-length practice exams and flashcards at https://certstud.com/certifications/isaca/crisc. Start with 10 free questions at https://certstud.com/try-free.