Live Online CRISC Exam Preparation for IT Risk and GRC Professionals
Prepare for the ISACA CRISC exam through 38+ guided hours of live online training, recordings, self-paced reinforcement, an AI-supported LMS, 3,000+ practice questions, mock exams and structured faculty support. EduDelphi provides CRISC exam preparation for IT-risk, GRC, security and control professionals worldwide; ISACA separately controls official examination, certification and maintenance requirements.
Know the official CRISC route before you plan your preparation
CRISC stands for Certified in Risk and Information Systems Control. It is an ISACA credential for professionals who connect enterprise objectives, technology risk, controls, risk treatment and management reporting.

Choose CRISC when you want to own broader IT-risk and control decisions
This is a focused route for professionals who need to assess technology risk, shape risk treatment, evaluate control design and communicate risk decisions to the right stakeholders.
Risk and GRC
IT risk and GRC professionals
For people building risk registers, assessing scenarios, monitoring risk and supporting governance decisions.
Audit and controls
Audit, assurance and controls teams
For professionals moving from control testing toward risk ownership, response and reporting.
Security and resilience
Security and resilience leaders
For people connecting security, technology, third-party exposure and operational resilience to business priorities.
What Is Included in the EduDelphi Online CRISC Course?
A structured commercial study system for working professionals who want live explanation, flexible reinforcement and exam-ready risk judgement.
38+ guided live hours
Faculty-led domain teaching, practical explanations, question debriefs and revision planning.
3,000+ practice resources
Question practice, answer explanations, mock exams, weak-area drills and structured revision.
Study LMS and recordings
AI-supported LMS access, recordings, notes, mind maps, infographics and flexible study support.
Applied risk learning
Risk scenarios, governance decisions, control logic and reporting context built into faculty discussion.
Flexible study routes
Live learning supported by recordings, self-paced reinforcement and one-to-one guidance options.
Corporate delivery
Private global cohorts for risk, security, audit, controls and technology teams across time zones.
Current CRISC Exam Blueprint — Effective 3 November 2025
ISACA’s current CRISC blueprint has four domains. The November 2025 update increased Risk Assessment from 20% to 22% and reduced Technology and Security from 22% to 20%.
CRISC Syllabus: Four Domains and Exam Weightings
The official domains below follow the current blueprint effective 3 November 2025. They are separate from EduDelphi’s teaching and mock methodology.
1. Governance — 26%
- Organizational strategy, roles, culture, policies, resilience and asset management.
- Enterprise risk management, lines of defense, risk profiles and risk appetite/tolerance.
- Risk frameworks, legal, regulatory and contractual requirements.
2. Risk Assessment — 22%
- Risk events, threat modelling, vulnerabilities and risk-scenario development.
- Business-impact analysis, risk registers and risk-analysis methods.
- Inherent and residual risk, evidence and risk-assessment judgement.
3. Risk Response and Reporting — 32%
- Risk-response options, control and risk ownership, vendor and supply-chain risk.
- Control design, implementation, analysis and testing methods.
- Risk-action plans, KRIs, KPIs, KCIs, monitoring, dashboards and reporting.
4. Technology and Security — 20%
- Technology principles, enterprise architecture, operations, SDLC and data lifecycle.
- Resilience, disaster recovery, emerging technologies and project/portfolio context.
- Security concepts, frameworks, privacy, data protection and awareness.
EduDelphi Exam Strategy & Mock Rehearsal
Build risk judgement through applied CRISC scenarios
Case-led discussion helps learners connect definitions to the business, risk and control choices that CRISC questions test.
Example: a cloud-vendor risk scenario. A business unit plans to move a customer-facing service to a vendor that will process sensitive data. The sponsor wants a fast launch, but ownership of the risk decision is unclear, the control evidence is incomplete and the existing risk register does not cover the new dependency.
Learners consider what must be clarified before a decision: business objective, risk owner, appetite and tolerance, vendor evidence, control gaps, residual exposure, treatment choices, KRIs and the right reporting route.
This is not legal advice or a real assessment. It is a structured way to practise evidence-led risk judgement before the exam and in professional work.
Risk judgement, not just definitions
- Separate a risk signal from a completed assessment.
- Identify the right owner and governance route.
- Compare response options against appetite and evidence.
- Connect control gaps to monitoring and reporting.
CRISC Exam Eligibility Is Not the Same as CRISC Certification
You can take the CRISC exam before meeting the final experience requirement. ISACA makes the official determination on certification applications.
What are the CRISC certification requirements?
To earn the credential, ISACA currently requires a passing exam score, at least three years of relevant professional information-systems audit, control or security experience across at least two of the four CRISC domains, a certification application and adherence to its professional-ethics and CPE requirements. The experience must be gained within the ten years before the application.
How EduDelphi supports the route
EduDelphi can explain how study timing, exam scheduling and your current professional background fit together. We do not determine your final certification eligibility; confirm it directly through ISACA before making official payments.
CRISC Exam Format, Passing Score, Scheduling & Remote Testing
ISACA currently delivers CRISC as a computer-based exam at authorized PSI centres or by remote proctoring, subject to the rules and availability in force when a candidate books.
| Official detail | Current reference |
|---|---|
| Questions | 150 multiple-choice questions across four job-practice domains. |
| Duration | Four hours. |
| Passing score | 450 scaled score; it is not a percentage-correct threshold. |
| Registration | Continuous registration, with no fixed global testing window. |
| Eligibility period | Six months after exam registration. |
| Scheduling | Appointments may be scheduled from 48 hours after payment and are displayed up to 90 days ahead. |
| Delivery | Authorized PSI testing centre or remote proctoring, subject to current availability and policy. |
| Rescheduling | Currently without penalty when completed at least 48 hours before the appointment. |
CRISC Course Fees & Official ISACA Costs
EduDelphi training fees are shared on enquiry because the live, flexible and corporate support route can differ. ISACA charges are separate unless a written package says otherwise.
Current official ISACA reference
US$575 member CRISC exam fee
US$760 non-member CRISC exam fee
US$50 certification application processing fee
After certification, current maintenance is US$45/year for ISACA members or US$85/year for non-members. Membership, tax and local payment conditions can affect the final official amount.
38+ guided hours designed around professional work
We will recommend a live, recording-led, self-paced, one-to-one or corporate route based on your background, time zone, study deadline and intended official exam date.
- 38+ guided live hours plus flexible independent revision.
- Recordings, LMS support, 3,000+ practice resources and mocks.
- Clear separation between EduDelphi tuition and official ISACA charges.
- Study-route advice before you commit to an exam schedule.
Plan for CRISC Renewal and Ongoing Professional Development
CRISC certification is maintained through ISACA’s continuing-professional-education and annual-maintenance requirements.
Where CRISC Can Strengthen an IT-Risk Career
CRISC is particularly relevant where governance, risk, controls, technology and reporting decisions come together.
CRISC vs CISA vs CISM vs CISSP: Which Route Fits Your Role?
Choose the credential closest to the work you want to own next, not the acronym you see most often.
| Route | Primary focus | Best fit when |
|---|---|---|
| CRISC | IT risk, governance, control decisions, response and reporting. | You work where technology risk and business accountability meet. |
| CISA | IT audit, assurance, controls and governance. | Audit and assurance are the primary responsibility. |
| CISM | Information-security governance, programme, risk and incident management. | You are moving toward security-management leadership. |
| CISSP | Security architecture, engineering and operations. | You need broader technical-security depth. |
Preparation Led by Practical IT-Risk and Controls Experience

Kashif Akhtar
Qualified Engineer, CSCP, PMP, CISA, CISM, CRISC, CDPSE
CRISC, IT risk, governance and controls faculty
Kashif brings a practical perspective across IT audit, information-security governance, digital trust, controls, process improvement and enterprise risk. His teaching connects governance, risk assessment, treatment, control design and reporting to the decisions professionals need to make at work.
Corporate CRISC & IT-Risk Training for Global Teams
Private CRISC cohorts help technology-risk, audit, controls, security and GRC teams establish a common approach to risk scenarios, control choices, ownership and reporting.
- Needs mapping around roles, current knowledge and intended CRISC route.
- Global time-zone planning, live teaching and recordings where agreed.
- Practical cases, question checkpoints, mock planning and revision support.
- Attendance and progress visibility where agreed for the cohort.
From needs mapping to exam planning
1. Needs mapping
Clarify roles, baseline knowledge and business context.
2. Cohort design
Set pacing, time zones, live delivery, recordings and applied examples.
3. Practice and visibility
Use question checkpoints, mock planning and progress visibility where agreed.
Common CRISC Course and Certification Questions
What does CRISC stand for?
Can I take the CRISC exam without experience?
What experience is required for CRISC certification?
Which CRISC study-material version should I use?
How many questions are on the CRISC exam?
How long is the CRISC exam?
What is the CRISC passing score?
Can I take CRISC remotely?
Is CRISC only available in English?
How long is CRISC exam eligibility valid?
How much does CRISC cost?
How long does CRISC preparation take?
What is included in EduDelphi CRISC training?
CRISC vs CISA: which should I choose?
How do I maintain CRISC after certification?
Can companies arrange corporate CRISC training?
Get CRISC Fees, Syllabus & a Global Batch Recommendation
Share your country, preferred learning mode and study timeline. We will send current EduDelphi training options, fee guidance, package inclusions, batch recommendations and a clear explanation of the separate official ISACA process.
Live online, recordings, self-paced reinforcement, one-to-one and corporate options can be discussed based on your needs.
Looking for CRISC Training in the UAE?
This page serves global online CRISC preparation. For UAE-specific delivery context, explore our CRISC course in the UAE. Learners in other countries can use the enquiry form above for a global batch recommendation.
CRISC® and Certified in Risk and Information Systems Control® are registered marks of ISACA. EduDelphi provides independent CRISC exam preparation and does not award the credential.





















