EduDelphi global CRISC preparation

Live Online CRISC Exam Preparation for IT Risk and GRC Professionals

Prepare for the ISACA CRISC exam through 38+ guided hours of live online training, recordings, self-paced reinforcement, an AI-supported LMS, 3,000+ practice questions, mock exams and structured faculty support. EduDelphi provides CRISC exam preparation for IT-risk, GRC, security and control professionals worldwide; ISACA separately controls official examination, certification and maintenance requirements.

View Four-Domain CRISC Syllabus
38+ hourslive guided CRISC preparation
3,000+practice and revision resources
4 domainscurrent CRISC exam blueprint
Live + flexiblerecordings and self-paced support
CRISC at a glance

Know the official CRISC route before you plan your preparation

CRISC stands for Certified in Risk and Information Systems Control. It is an ISACA credential for professionals who connect enterprise objectives, technology risk, controls, risk treatment and management reporting.

150official multiple-choice questions
4 hourscurrent official exam duration
450current scaled passing score
3 yearsexperience for certification
CRISC vs ISACA: CRISC is the credential. ISACA is the credential body that sets official examination, certification and maintenance rules. EduDelphi is an independent preparation provider.
Live online CRISC training workshop for technology risk professionals
Who should take CRISC?

Choose CRISC when you want to own broader IT-risk and control decisions

This is a focused route for professionals who need to assess technology risk, shape risk treatment, evaluate control design and communicate risk decisions to the right stakeholders.

Risk and GRC

IT risk and GRC professionals

For people building risk registers, assessing scenarios, monitoring risk and supporting governance decisions.

Audit and controls

Audit, assurance and controls teams

For professionals moving from control testing toward risk ownership, response and reporting.

Security and resilience

Security and resilience leaders

For people connecting security, technology, third-party exposure and operational resilience to business priorities.

When another credential may fit better: choose CISA when IT audit and assurance are central; choose CISM for information-security management; choose CISSP for broader technical-security depth.
What you receive

What Is Included in the EduDelphi Online CRISC Course?

A structured commercial study system for working professionals who want live explanation, flexible reinforcement and exam-ready risk judgement.

38+ guided live hours

Faculty-led domain teaching, practical explanations, question debriefs and revision planning.

3,000+ practice resources

Question practice, answer explanations, mock exams, weak-area drills and structured revision.

Study LMS and recordings

AI-supported LMS access, recordings, notes, mind maps, infographics and flexible study support.

Applied risk learning

Risk scenarios, governance decisions, control logic and reporting context built into faculty discussion.

Flexible study routes

Live learning supported by recordings, self-paced reinforcement and one-to-one guidance options.

Corporate delivery

Private global cohorts for risk, security, audit, controls and technology teams across time zones.

Current official exam content

Current CRISC Exam Blueprint — Effective 3 November 2025

ISACA’s current CRISC blueprint has four domains. The November 2025 update increased Risk Assessment from 20% to 22% and reduced Technology and Security from 22% to 20%.

26%Governance
22%Risk Assessment
32%Risk Response and Reporting
20%Technology and Security
Current CRISC exam syllabus

CRISC Syllabus: Four Domains and Exam Weightings

The official domains below follow the current blueprint effective 3 November 2025. They are separate from EduDelphi’s teaching and mock methodology.

1. Governance — 26%
  • Organizational strategy, roles, culture, policies, resilience and asset management.
  • Enterprise risk management, lines of defense, risk profiles and risk appetite/tolerance.
  • Risk frameworks, legal, regulatory and contractual requirements.
2. Risk Assessment — 22%
  • Risk events, threat modelling, vulnerabilities and risk-scenario development.
  • Business-impact analysis, risk registers and risk-analysis methods.
  • Inherent and residual risk, evidence and risk-assessment judgement.
3. Risk Response and Reporting — 32%
  • Risk-response options, control and risk ownership, vendor and supply-chain risk.
  • Control design, implementation, analysis and testing methods.
  • Risk-action plans, KRIs, KPIs, KCIs, monitoring, dashboards and reporting.
4. Technology and Security — 20%
  • Technology principles, enterprise architecture, operations, SDLC and data lifecycle.
  • Resilience, disaster recovery, emerging technologies and project/portfolio context.
  • Security concepts, frameworks, privacy, data protection and awareness.
EduDelphi Exam Strategy & Mock Rehearsal
Our preparation adds scenario discussion, timed practice, question debriefs and error analysis so candidates can identify the risk decision behind a question. This is EduDelphi methodology, not an official fifth CRISC domain.
Learning through practical case studies

Build risk judgement through applied CRISC scenarios

Case-led discussion helps learners connect definitions to the business, risk and control choices that CRISC questions test.

Example: a cloud-vendor risk scenario. A business unit plans to move a customer-facing service to a vendor that will process sensitive data. The sponsor wants a fast launch, but ownership of the risk decision is unclear, the control evidence is incomplete and the existing risk register does not cover the new dependency.

Learners consider what must be clarified before a decision: business objective, risk owner, appetite and tolerance, vendor evidence, control gaps, residual exposure, treatment choices, KRIs and the right reporting route.

This is not legal advice or a real assessment. It is a structured way to practise evidence-led risk judgement before the exam and in professional work.

What the case develops

Risk judgement, not just definitions

  • Separate a risk signal from a completed assessment.
  • Identify the right owner and governance route.
  • Compare response options against appetite and evidence.
  • Connect control gaps to monitoring and reporting.
Eligibility and certification

CRISC Exam Eligibility Is Not the Same as CRISC Certification

You can take the CRISC exam before meeting the final experience requirement. ISACA makes the official determination on certification applications.

Openexam registration for interested candidates
3 yearsrelevant work experience for certification
2 domainsminimum experience coverage
5 yearsto apply after passing

What are the CRISC certification requirements?

To earn the credential, ISACA currently requires a passing exam score, at least three years of relevant professional information-systems audit, control or security experience across at least two of the four CRISC domains, a certification application and adherence to its professional-ethics and CPE requirements. The experience must be gained within the ten years before the application.

How EduDelphi supports the route

EduDelphi can explain how study timing, exam scheduling and your current professional background fit together. We do not determine your final certification eligibility; confirm it directly through ISACA before making official payments.

View official CRISC certification requirements

CRISC examination

CRISC Exam Format, Passing Score, Scheduling & Remote Testing

ISACA currently delivers CRISC as a computer-based exam at authorized PSI centres or by remote proctoring, subject to the rules and availability in force when a candidate books.

Official detailCurrent reference
Questions150 multiple-choice questions across four job-practice domains.
DurationFour hours.
Passing score450 scaled score; it is not a percentage-correct threshold.
RegistrationContinuous registration, with no fixed global testing window.
Eligibility periodSix months after exam registration.
SchedulingAppointments may be scheduled from 48 hours after payment and are displayed up to 90 days ahead.
DeliveryAuthorized PSI testing centre or remote proctoring, subject to current availability and policy.
ReschedulingCurrently without penalty when completed at least 48 hours before the appointment.
Official cost planning

CRISC Course Fees & Official ISACA Costs

EduDelphi training fees are shared on enquiry because the live, flexible and corporate support route can differ. ISACA charges are separate unless a written package says otherwise.

Current official ISACA reference

US$575 member CRISC exam fee
US$760 non-member CRISC exam fee
US$50 certification application processing fee

After certification, current maintenance is US$45/year for ISACA members or US$85/year for non-members. Membership, tax and local payment conditions can affect the final official amount.

Check current CRISC fees directly with ISACA

Your study route

38+ guided hours designed around professional work

We will recommend a live, recording-led, self-paced, one-to-one or corporate route based on your background, time zone, study deadline and intended official exam date.

  • 38+ guided live hours plus flexible independent revision.
  • Recordings, LMS support, 3,000+ practice resources and mocks.
  • Clear separation between EduDelphi tuition and official ISACA charges.
  • Study-route advice before you commit to an exam schedule.
After certification

Plan for CRISC Renewal and Ongoing Professional Development

CRISC certification is maintained through ISACA’s continuing-professional-education and annual-maintenance requirements.

20 CPEminimum each year
120 CPErequired over three years
US$45current annual member maintenance
US$85current annual non-member maintenance
Career relevance

Where CRISC Can Strengthen an IT-Risk Career

CRISC is particularly relevant where governance, risk, controls, technology and reporting decisions come together.

IT Risk AnalystGRC SpecialistTechnology Controls ProfessionalIT AuditorCyber Governance ProfessionalThird-Party Risk ManagerOperational Resilience ProfessionalRisk and Controls ManagerTechnology Risk Consultant
Choose the right credential

CRISC vs CISA vs CISM vs CISSP: Which Route Fits Your Role?

Choose the credential closest to the work you want to own next, not the acronym you see most often.

RoutePrimary focusBest fit when
CRISCIT risk, governance, control decisions, response and reporting.You work where technology risk and business accountability meet.
CISAIT audit, assurance, controls and governance.Audit and assurance are the primary responsibility.
CISMInformation-security governance, programme, risk and incident management.You are moving toward security-management leadership.
CISSPSecurity architecture, engineering and operations.You need broader technical-security depth.
Considering CGEIT? CRISC focuses on identifying, assessing and responding to IT risk through controls and reporting. CGEIT is the more senior enterprise IT-governance route for professionals directing, advising on or assuring governance of enterprise IT.
Faculty

Preparation Led by Practical IT-Risk and Controls Experience

Kashif Akhtar, CRISC faculty

Kashif Akhtar

Qualified Engineer, CSCP, PMP, CISA, CISM, CRISC, CDPSE

CRISC, IT risk, governance and controls faculty

Kashif brings a practical perspective across IT audit, information-security governance, digital trust, controls, process improvement and enterprise risk. His teaching connects governance, risk assessment, treatment, control design and reporting to the decisions professionals need to make at work.

Corporate CRISC training

Corporate CRISC & IT-Risk Training for Global Teams

Private CRISC cohorts help technology-risk, audit, controls, security and GRC teams establish a common approach to risk scenarios, control choices, ownership and reporting.

  • Needs mapping around roles, current knowledge and intended CRISC route.
  • Global time-zone planning, live teaching and recordings where agreed.
  • Practical cases, question checkpoints, mock planning and revision support.
  • Attendance and progress visibility where agreed for the cohort.
Corporate process

From needs mapping to exam planning

1. Needs mapping
Clarify roles, baseline knowledge and business context.

2. Cohort design
Set pacing, time zones, live delivery, recordings and applied examples.

3. Practice and visibility
Use question checkpoints, mock planning and progress visibility where agreed.

CRISC FAQs

Common CRISC Course and Certification Questions

What does CRISC stand for?
CRISC stands for Certified in Risk and Information Systems Control, an ISACA credential focused on IT risk, governance, controls, risk response and reporting.
Can I take the CRISC exam without experience?
Yes. ISACA states the CRISC exam is open to interested candidates, even before they meet the final experience requirement for certification.
What experience is required for CRISC certification?
ISACA currently requires at least three years of professional information-systems audit, control or security work experience across at least two of the four CRISC domains. The experience must be gained in the ten years before application.
Which CRISC study-material version should I use?
Candidates preparing for the current post-3-November-2025 exam should use materials aligned to the active CRISC blueprint. Where you use ISACA’s official resources, the current CRISC Review Manual and related preparation resources are the 8th edition. Confirm the edition and exam alignment before purchasing any material.
How many questions are on the CRISC exam?
The current CRISC exam contains 150 multiple-choice questions across four domains.
How long is the CRISC exam?
ISACA currently allows four hours to complete the CRISC exam.
What is the CRISC passing score?
The current passing score is 450 on ISACA’s scaled score range. It is not equivalent to 450 correct answers or a simple percentage-correct threshold.
Can I take CRISC remotely?
ISACA currently offers CRISC through authorized PSI testing centres and remote proctoring, subject to live availability, system requirements and policies at scheduling.
Is CRISC only available in English?
No. ISACA’s current 2026 candidate guide lists CRISC exam delivery in English, Spanish and Japanese. EduDelphi’s course language and the official ISACA exam language are separate, so confirm the current language availability for your location and appointment before registering.
How long is CRISC exam eligibility valid?
CRISC eligibility is currently valid for six months after registration. Appointments can be scheduled from 48 hours after payment and appear up to 90 days in advance.
How much does CRISC cost?
ISACA currently lists US$575 for members and US$760 for non-members for the exam, plus a US$50 certification-application fee after passing. EduDelphi training is a separate enquiry-led cost.
How long does CRISC preparation take?
EduDelphi provides 38+ guided live hours. Total preparation time depends on your background, work schedule, study mode and intended exam date; recordings and self-paced support add flexibility.
What is included in EduDelphi CRISC training?
The selected route can include live teaching, recordings, AI-supported LMS access, notes, mind maps, infographics, 3,000+ practice resources, mock exams, self-paced reinforcement, one-to-one support and corporate delivery.
CRISC vs CISA: which should I choose?
CRISC is most focused on IT risk, risk response, controls and reporting. CISA is more directly focused on IT audit and assurance. The right route depends on your current work and next responsibility.
How do I maintain CRISC after certification?
ISACA currently requires a minimum of 20 CPE annually and 120 CPE over a three-year cycle. Current annual maintenance fees are US$45 for members and US$85 for non-members, alongside the applicable ethics and renewal requirements.
Can companies arrange corporate CRISC training?
Yes. EduDelphi can scope private global cohorts for IT-risk, GRC, audit, security and controls teams, including pace, time zone, case focus and progress-support requirements.
Get course details

Get CRISC Fees, Syllabus & a Global Batch Recommendation

Share your country, preferred learning mode and study timeline. We will send current EduDelphi training options, fee guidance, package inclusions, batch recommendations and a clear explanation of the separate official ISACA process.

We respect your privacy. No spam – only relevant course information.

Live online, recordings, self-paced reinforcement, one-to-one and corporate options can be discussed based on your needs.

Local delivery context

Looking for CRISC Training in the UAE?

This page serves global online CRISC preparation. For UAE-specific delivery context, explore our CRISC course in the UAE. Learners in other countries can use the enquiry form above for a global batch recommendation.

CRISC® and Certified in Risk and Information Systems Control® are registered marks of ISACA. EduDelphi provides independent CRISC exam preparation and does not award the credential.