CGEIT IT governance certification banner showing a board room with a long table, wall screens of abstract charts and a city view, with the headline 5 years before the letters

IT Governance Certification: CGEIT Asks for 5 Years First

Passing the CGEIT exam does not make you CGEIT certified. ISACA lets anyone with an interest in the governance of enterprise IT sit the paper, and then grants the letters only to candidates who can show five or more years in an advisory or oversight role supporting IT governance, spread across at least three of the four domains, with a full year in the first one, and verified by a supervisor or manager. The exam is the smaller half of this credential.

That ordering shapes everything about how to approach the IT governance certification. This article sets out the experience rule and its deadlines, the 150 question format with its 450 out of 800 pass mark, the four domains and why the first one carries 40 percent, how COBIT relates to an exam ISACA calls framework agnostic, what the 2026 pay data says about the credential, and a preparation order that suits a paper written for people who already think like a CIO.

Table of Contents

  1. Why does passing the CGEIT exam not make you certified?
  2. What does the CGEIT exam look like?
  3. Which four domains does CGEIT test, and why is one worth 40 percent?
  4. How does COBIT fit a framework agnostic IT governance certification?
  5. Benefits Realization and Risk Optimization: the 45 percent candidates underrate
  6. Who should take the IT governance certification, and what is it worth?
  7. How should you prepare for the CGEIT exam?
  8. Frequently Asked Questions
  9. Conclusion

Why does passing the CGEIT exam not make you certified?

ISACA separates the CGEIT exam from the CGEIT certification. The exam is open to anyone interested in IT governance, but certification requires a passed exam within the last five years, a one time US$50 application fee, and a verified minimum of five years of professional experience managing, advising on or otherwise supporting the governance of the IT related contribution to an enterprise.

CGEIT IT governance certification infographic showing the 3 clocks on the credential, a 6 month exam eligibility window, 5 years to apply after passing and 120 CPE hours every 3 years

The experience rule has three parts, and all three are checked on the application. The five years must cover at least three of the four CGEIT domains. At least one of those years must relate to Domain 1, Governance of Enterprise IT. And every year counted must fall within the ten years before the date you apply. Your supervisor or manager confirms the experience, so the role you describe has to be one somebody else recognises as governance work.

The full list sits on ISACA’s page of CGEIT certification requirements, which also binds every holder to the ISACA Code of Professional Ethics and to the Continuing Professional Education policy: at least 120 CPE hours in each three year reporting period, with a minimum of 20 hours in any single year. Hours that count for another ISACA credential can count here too.

The clocks that run before and after the pass

Registration is continuous, so there is no exam window to wait for. Once you have paid, you can schedule an appointment as early as 48 hours later, and your eligibility to sit the exam lasts six months from registration. Appointments open 90 days in advance, and you can reschedule without penalty as long as you do it at least 48 hours before the booked slot. After a pass, the application clock starts: you have five years to submit the experience application, pay the US$50 fee and receive the designation.

Read together, those rules describe the intended candidate. ISACA expects you to be working in governance already, to sit the exam while you are, and to apply once your years add up. Someone early in their career can pass and bank the result, but the credential itself waits until the experience exists, and the five year application window is the limit on how long it can wait.

What does the CGEIT exam look like?

The CGEIT exam has 150 questions, a duration of 240 minutes and a passing score of 450 out of 800. It costs US$575 for ISACA members and US$760 for non members, and it is delivered at authorised PSI test centres worldwide or as a remotely proctored exam. The figures below come from the EduSum syllabus page and are matched against ISACA’s own CGEIT pages.

FieldValue
Exam nameISACA Certified in the Governance of Enterprise IT (CGEIT)
Exam codeCGEIT
Number of questions150
Duration240 minutes
Passing score450 out of 800
Exam price, ISACA memberUS$575
Exam price, non memberUS$760
DeliveryPSI test centres or remote proctoring
RegistrationContinuous; schedule as early as 48 hours after payment
Eligibility periodSix months from registration
Certification application feeUS$50, payable after a pass

Do the arithmetic once and then stop worrying about the clock. Four hours across 150 questions is 96 seconds a question, which is comfortable for a knowledge item and adequate for a scenario that asks which governance action a board should take first. The 450 mark is a scaled score rather than a percentage, so a raw count of correct answers on a practice set does not translate directly into a pass or a fail.

Member or non member

The membership gap on the exam fee alone is US$185. ISACA’s CGEIT certification page also states that members save on CPE, renewals and exam fees across the programme, and that the member only Engage study groups are part of the preparation offer. Whether joining pays for itself depends on how many ISACA credentials you intend to hold, which is a question worth settling before you pay the exam fee rather than after.

Where the exam facts come from

ISACA’s public CGEIT pages display the 150 question count, both exam fees, the US$50 application fee and the registration and scheduling rules. The 240 minute duration and the 450 out of 800 pass mark are published on the EduSum syllabus page and sit in ISACA’s exam candidate guide, which is a downloadable document rather than a web page. Nothing in the two sources disagrees, which is not something every certification can say.

Which four domains does CGEIT test, and why is one worth 40 percent?

CGEIT tests four job practice domains: Governance of Enterprise IT at 40 percent, IT Resources at 15 percent, Benefits Realization at 26 percent and Risk Optimization at 19 percent. The first domain is the largest because it holds the framework itself, the strategy that the framework must serve, and the governance of information as an asset, which are three subjects rather than one.

DomainSubtopics as publishedWeight
Governance of Enterprise ITGovernance Framework: Components of a Governance Framework; Organizational Structures, Roles and Responsibilities; Strategy Development; Legal and Regulatory Compliance; Organizational Culture; Business Ethics. Technology Governance: Governance Strategy Alignment with Enterprise Objectives; Strategic Planning Process; Stakeholder Analysis and Engagement; Communication and Awareness Strategy; Enterprise Architecture; Policies and Standards. Information Governance: Information Architecture; Information Asset Lifecycle; Information Ownership and Stewardship; Information Classification and Handling40%
IT ResourcesIT Resource Planning: Sourcing Strategies; Resource Capacity Planning; Acquisition of Resources. IT Resource Optimization: IT Resource Lifecycle and Asset Management; Human Resource Competency Assessment and Development; Management of Contracted Services and Relationships15%
Benefits RealizationIT Performance and Oversight: Performance Management; Change Management; Governance Monitoring; Governance Reporting; Quality Assurance; Process Development and Improvement. Management of IT-Enabled Investments: Business Case Development and Evaluation; IT Investment Management and Reporting; Performance Metrics; Benefit Evaluation Methods26%
Risk OptimizationRisk Strategy: Risk Frameworks and Standards; Enterprise Risk Management; Risk Appetite and Risk Tolerance. Risk Management: IT-Enabled Capabilities, Processes and Services; Business Risk, Exposures and Threats; Risk Management Lifecycle; Risk Assessment Methods19%

Forty percent of 150 is 60 questions on Domain 1 alone, and the subtopic list explains why. Sixteen named subtopics sit under three headings, from the components of a governance framework through enterprise architecture to the classification and handling of information. The EduSum page that lists the CGEIT syllabus topics carries the same four headings and the same weightings as ISACA, down to the order of the subtopics, so either source works as a checklist.

Why older guides list five domains

Search for the exam and you will still find pages describing five CGEIT domains: Framework for the Governance of Enterprise IT at 25 percent, Strategic Management at 20, Benefits Realization at 16, Risk Optimization at 24 and Resource Optimization at 15. That was the job practice before July 2020, when ISACA moved to the current four domain outline and added information governance, big data and data privacy to the first domain. Any study material built on the five domain split is describing an exam that no longer exists, and the quickest test of a resource is whether its weights add up to 40, 15, 26 and 19.

Tasks, not just topics

Beneath the subtopics, the official exam content outline publishes a list of supporting tasks, and they are written as actions: establish the objectives for the governance framework, incorporate a strategic planning process, ensure that a business case and benefits realization process exists, establish roles and accountabilities for information assets, evaluate the framework and identify improvements. The questions are built from those verbs. A candidate who can recite the components of a framework but cannot say which one to establish first is studying the topic list and missing the task list.

How does COBIT fit a framework agnostic IT governance certification?

ISACA describes CGEIT as framework agnostic and as the only IT governance certification for the individual, which means the exam does not require COBIT and does not test COBIT process references. COBIT is ISACA’s own governance framework, and its thinking is visible throughout the content outline, but a question is answered from governance principles rather than from a specific framework’s numbering.

The clearest example is in the supporting tasks. Several of them read “evaluate, direct, and monitor”, applied to IT strategic planning and to stakeholder engagement. Those three verbs are the governance cycle that COBIT uses to separate what a board does from what management does: the board evaluates options, directs management, and monitors the result. You can learn that cycle from ISACA’s COBIT framework resources or from any other governance standard that uses the same separation, and the exam will accept either route as long as you can apply it to a scenario.

Framework agnostic in practice

Look at the Risk Strategy subtopic and it says Risk Frameworks and Standards, plural. No subtopic anywhere in the four domains names a single framework. What the exam does assume is that you know what a framework is for: a governance framework defines who decides, who is accountable, how decisions are communicated and how their outcomes are measured. Questions tend to present an enterprise with a gap in one of those four things and ask what the governance body should do about it.

That is also why candidates who arrive from an audit or security background sometimes find the first domain harder than they expected. Their instinct is to look for the control that is missing. CGEIT is asking a different question: whether the structures, roles and strategy exist for the enterprise to make the right technology decisions at all, and whether those decisions are aligned with what the enterprise is trying to achieve.

Benefits Realization and Risk Optimization: the 45 percent candidates underrate

Benefits Realization and Risk Optimization together carry 45 percent of the CGEIT exam, more than Domain 1 on its own. Benefits Realization at 26 percent covers IT performance, governance monitoring and reporting, and the management of IT enabled investments through business cases and benefit evaluation. Risk Optimization at 19 percent covers risk strategy, appetite and tolerance, and the risk management lifecycle.

The business case is a lifecycle, not a document

The supporting task for investments is to ensure that IT enabled investments are managed through their economic lifecycle, and the subtopics underneath are Business Case Development and Evaluation, IT Investment Management and Reporting, Performance Metrics and Benefit Evaluation Methods. In exam terms, a business case that is approved and then filed has failed. Governance expects it to be re-evaluated as the programme runs, with benefits measured against what was promised and the investment stopped or redirected when the numbers no longer hold. Questions in this domain frequently describe a project that is on time and on budget and ask what is still wrong, and the answer is usually that nobody has checked whether the benefits are being realised.

Appetite, tolerance and the standards behind them

Risk appetite is how much risk the enterprise is willing to take in pursuit of its objectives. Risk tolerance is the acceptable variation around that appetite for a specific objective. CGEIT questions test the distinction by giving you a board that has stated one and a management team acting on the other, and asking what the governance body should do. The Risk Frameworks and Standards subtopic sits behind that: enterprise risk management frameworks, and standards such as the NIST Cybersecurity Framework, give an enterprise a shared vocabulary for appetite, tolerance and the risk lifecycle, and the exam expects you to know how a framework is used to align IT risk with enterprise risk rather than to recite any one of them.

The remaining 15 percent, IT Resources, is the domain most often skimmed and the one with the shortest subtopic list: sourcing strategies, capacity planning, acquisition, asset lifecycle, human competency development and the management of contracted services. On a 150 question paper that is still around 22 questions, which is more than enough to decide a result that sits near the 450 line.

Who should take the IT governance certification, and what is it worth?

CGEIT is built for people who already direct, manage or support the governance of IT: IT directors, heads of governance, risk and compliance, enterprise architects with a governance remit, senior consultants and the advisers who report to boards and audit committees. ISACA states that more than 8,000 people have earned CGEIT since its launch in 2007, that 70 percent of holders reported on the job improvement and 22 percent a pay increase, and quotes an average annual salary above US$141,000 for holders.

CGEIT IT governance certification infographic comparing 4 ISACA credentials, CGEIT governs IT value, CISM runs security, CRISC owns IT risk and CISA audits controls

Those are ISACA’s own figures, so the more useful signal comes from outside the programme. Writing on the ISACA Now blog in March 2026, the chief analyst of Foote Partners reported that CGEIT and CISA posted cash pay premium growth of 11 to 20 percent over the last six months of 2025, against a 6.5 percent average across the certifications his firm tracks, at a time when premiums for many vendor and tool certifications were falling. His explanation turns on exactly the experience rule this article opened with:

“The CISA and CGEIT differ because they are experience-based, requiring demonstrated professional backgrounds in audit, governance and enterprise oversight. That barrier protects their scarcity value in a way that mass-market certifications cannot.”

David Foote, Chief Analyst and Research Officer, Foote Partners

The same analysis argues that enterprise AI deployment is raising, not lowering, the value of governance roles, because regulators and insurers now ask whether controls over training data, model risk and monitoring are documented and aligned with business objectives. That is a Domain 1 and Domain 4 question in the CGEIT outline, and it is the kind of work the credential is meant to evidence.

CGEIT against CISM, CRISC and CISA

ISACA’s four established credentials divide the same enterprise between them. CISA audits whether systems and controls can be trusted. CISM runs the information security programme. CRISC owns IT risk identification and response. CGEIT sits above all three and asks whether technology is governed so that it delivers value, uses resources well and takes risk the enterprise has agreed to take. If you are weighing the audit and security routes, this site’s CISA and CISM comparison sets out how those two differ in day to day work. CGEIT is the right choice when your job is to shape the decisions those two roles then audit and secure, and the wrong one if you are still building the five years of governance experience that ISACA will ask you to prove.

How should you prepare for the CGEIT exam?

Prepare for CGEIT by confirming your experience against the three of four domain rule first, then learning the four domains from ISACA’s content outline and supporting tasks, reading the official review manual, working the question database until you can justify every answer, and sitting full length timed sets of 150 questions before you schedule. The order matters because the exam rewards judgement built on the task list, not recall of the topic list.

  1. Map your own career against the four domains and the ten year window before you pay anything, because the certification needs five years across at least three domains with one year in Governance of Enterprise IT, and a pass you cannot convert within five years is a pass wasted.
  2. Read the official exam content outline twice, once for the subtopics and once for the supporting tasks, since the tasks are the verbs the questions are built from.
  3. Work through the CGEIT Review Manual, which ISACA sells in print and digital editions, and keep a note of every subtopic you could not explain to a board member in two sentences.
  4. Subscribe to the CGEIT Questions, Answers and Explanations database, a six month subscription to a pool of 300 items that ISACA says match the difficulty of the exam, and review the explanation for every wrong answer as well as every right one.
  5. Read at least one governance framework end to end, COBIT or an equivalent, so that evaluate, direct and monitor are reflexes rather than vocabulary.
  6. Sit full timed sets of 150 questions in 240 minutes, flag anything you are unsure of, and book the exam only when your scores are stable and your weak areas have moved from Domain 1 to wherever is left.

One CGEIT holder who passed by self study, Adham Etoom, described his method on ISACA’s own blog: the review manual twice cover to cover, the question database after the first read, then VAL IT, RISK IT and COBIT, then a second round of questions until the gaps closed. His summary of what the exam asks of a candidate is the best single sentence of advice on it:

“Preparation for CGEIT is all about understanding the big picture and wearing the hat of a senior leader in an enterprise (i.e., CIO).”

Adham Etoom, Head of Policy and Compliance, National Cyber Security Center of Jordan

That sentence explains most failed attempts. A technically correct answer about a control, a project or a vendor contract is frequently the wrong answer on CGEIT, because the question wanted the governance decision above it. If you want a shorter orientation before you start, this site’s earlier CGEIT overview covers the same four domains at a lighter depth and is a reasonable first read before the content outline.

Two things not to spend time on: memorising framework process numbers, which the exam does not ask for, and any resource that still describes five domains, which is describing the exam as it was before July 2020.

Frequently Asked Questions

How many questions are on the CGEIT exam?

The CGEIT exam has 150 questions with a 240 minute time limit, which works out at 96 seconds a question.

What is the passing score for CGEIT?

The passing score is a scaled 450 out of 800. Because it is scaled, a raw count of correct answers on a practice test does not convert directly into a pass or fail on the real exam.

How much does the CGEIT exam cost?

The exam fee is US$575 for ISACA members and US$760 for non members. After a pass there is a separate one time US$50 application processing fee for the certification itself.

What experience do you need for CGEIT certification?

ISACA requires five or more years of experience managing, advising on or supporting the governance of the IT related contribution to an enterprise, across at least three of the four CGEIT domains, with at least one year related to Domain 1, Governance of Enterprise IT. All of it must fall within the ten years before you apply, and a supervisor or manager verifies it.

Can you take the CGEIT exam before you have the experience?

Yes. The exam is open to anyone with an interest in IT governance. You then have five years from the passing date to submit the certification application with the required experience.

How long is CGEIT valid, and how is it maintained?

CGEIT is maintained through continuing professional education rather than retesting: at least 120 CPE hours in each three year reporting period, with a minimum of 20 hours in any one year, plus adherence to the ISACA Code of Professional Ethics.

Does CGEIT have four domains or five?

Four. Governance of Enterprise IT at 40 percent, IT Resources at 15, Benefits Realization at 26 and Risk Optimization at 19. Pages listing five domains with a 25 percent framework domain describe the job practice ISACA retired in July 2020.

Is CGEIT harder than CISM?

They test different things rather than different difficulty levels. CISM examines how an information security programme is run; CGEIT examines whether technology as a whole is governed to deliver value, use resources well and take agreed risk. Candidates from security backgrounds often find CGEIT’s first domain the harder adjustment because it asks for governance decisions rather than controls.

How do you schedule the CGEIT exam?

Registration is continuous with no fixed exam windows. After paying the exam fee you can schedule a PSI test centre or remote proctored appointment as early as 48 hours later, appointments open 90 days ahead, your eligibility lasts six months, and you can reschedule without penalty up to 48 hours before the slot.

Conclusion

CGEIT is the one ISACA credential where the paper is not the obstacle. Anyone can register, sit 150 questions in 240 minutes and clear the 450 mark; only someone with five verified years of governance work across three of the four domains can turn that pass into the letters, and they have five years to do it.

The exam itself is weighted the way a board thinks. Forty percent on the framework, strategy and information governance that make decisions possible, 45 percent on whether investments deliver value and whether risk stays within appetite, and 15 percent on the resources that carry it all out.

Check your experience against the domains before you pay, learn the content outline by its tasks rather than its topics, practise with the official question database, and book when your timed scores hold. The letters follow the experience, not the other way round.

Rating: 0 / 5 (0 votes)