ISACA
ISACA is a global non-profit professional association founded in 1969 that provides certifications, frameworks (notably COBIT), and training for IT audit, cybersecurity, governance, and risk professionals, serving 140,000–200,000 members across 180+ countries and now holding exclusive US Department of Defense CMMC certification authority.
- Company typePrivate
- Founded1969
- HeadquartersNorth Point, Hong Kong SAR China
- Headcount1–10
- GTM typeB2B
- OfferingServices
What ISACA does
ISACA, founded in 1969 as the International Information Systems Audit and Control Association, is a global non-profit professional membership organization that sets standards and credentials for IT governance, cybersecurity, risk management, and information systems audit. The organization delivers its value through a portfolio of globally recognized certifications (CISA, CISM, CRISC, CGEIT, CDPSE, CCOA, ITCA), proprietary frameworks (COBIT for enterprise IT governance), cybersecurity resources (CSX, CIX-P, CCAK), and a recently launched AI credential family (AAIA, AAISM, AAIR). It serves a member base of 140,000–200,000 professionals across approximately 180–190 countries through more than 200 local chapters.
ISACA's core "technology" is professional credentialing infrastructure built on body-of-knowledge frameworks, examination systems, certification maintenance (CPE) programs, and content libraries. In December 2025, ISACA was appointed by the US Department of War as the exclusive global Cybersecurity Assessor and Certifier Organization (CACOS) for the Cybersecurity Maturity Model Certification (CMMC) program, providing it exclusive authority over defense supply chain cybersecurity certification for the US and AUKUS nations. Distribution operates through the chapter network, an official website (isaca.org), and partnerships with the Big Four firms (KPMG, EY, Deloitte, PwC) for chapter event delivery and enterprise training.
The business model rests on four recurring revenue streams: individual membership dues, certification exam fees and maintenance, training/workshops/conference events, and knowledge products (books, frameworks). Pricing for events is tiered and varies by chapter — Hong Kong Chapter workshop fees range from free for students and startup founders to HKD 400 for non-members. Revenue is not publicly disclosed given ISACA's non-profit status. Recent product moves emphasize AI governance (AAIA, AAISM, AAIR) and regulatory positioning (CMMC CACOS), with strategic events focused on emerging technologies, AI auditing, fintech governance, and critical infrastructure protection.
ISACA firmographics
Firmographics- Name
- ISACA
- Legal name
- International Information Systems Audit and Control Association (ISACA)
- Website
- https://isaca.org.hk
- Company type
- Private
- Founded year
- 1969
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- ISACA is a global non-profit professional association founded in 1969 that provides certifications, frameworks (notably COBIT), and training for IT audit, cybersecurity, governance, and risk professionals, serving 140,000–200,000 members across 180+ countries and now holding exclusive US Department of Defense CMMC certification authority.
- Ownership category
- akta.pro rank
ISACA industry classification
Industry- Product category
- Professional Certification and Training Services
- NAICS
- Professional Organizations (81392), Business Associations (813910)
- SIC
- Services-Membership Organizations (8600)
- akta.pro primary industry
- Identity & Access Management (IAM) (EDAOAIAF)
Keywords
Where ISACA is headquartered
LocationHeadquarters
- HQ city
- North Point
- HQ country
- Hong Kong SAR China
- HQ region
- Asia
Offices5 records
Markets served
ISACA business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D, Others
Revenue model
- Professional Certifications: ISACA offers globally recognized certifications including CISA, CISM, CRISC, CGEIT, CDPSE, CCOA, and others. Revenue is generated through exam fees, certification maintenance fees, and credentials.
- Chapter Membership: ISACA generates revenue through professional membership fees. Members receive access to knowledge resources, networking, and member discounts on certifications and events.
- Training and Events: Revenue from workshops, seminars, annual conferences, and training programs. The China Hong Kong Chapter charges fees for events ranging from free for members to HK$400 for non-members.
- Knowledge Products: Revenue from books, frameworks (COBIT), and other knowledge publications that support certification preparation and professional development.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | One time | Fintech Governance Workshop - Member (Early Bird) |
| Other | One time | Fintech Governance Workshop - Non-Member (Early Bird) |
| Freemium | One time | Fintech Governance Workshop - Student/Startup |
| Freemium | One time | CPE Seminar - Member |
| Freemium | One time | AI Maturity Webinar |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels7 records
ISACA product offering
Product offeringCore offering
ISACA is a global professional association that issues industry-recognized credentials (CISA, CISM, CRISC, CGEIT, CDPSE, AAIA, AAISM, AAIR) and proprietary frameworks (COBIT, CSX) for IT governance, cybersecurity, audit, and risk professionals. It generates revenue through certification exam fees, professional membership dues, training, conferences, and knowledge publications, and operates a worldwide network of 200+ chapters serving 140,000+ members across 180 countries.
Product overview
ISACA is a global professional association providing professional certifications, frameworks, and training for IT governance, risk management, cybersecurity, and emerging technologies. The portfolio includes flagship certifications (CISA, CISM, CRISC, CGEIT, CDPSE), governance frameworks (COBIT), cybersecurity resources (CSX, CIX-P, CCAK), and AI-focused credentials (AAIA, AAISM, AAIR). ISACA also holds the CMMC authorization role as the global Cybersecurity Assessor and Certifier Organization for the U.S. Department of Defense. The organization serves over 140,000 members across 180 countries through 200+ chapters worldwide, and offers the AI Audit Toolkit for streamlining AI auditing processes.
Differentiator
Problem solved
Functional benefit
Brands
- CISA (Certified Information Systems Auditor): Globally recognized certification for IT audit, control, and security professionals
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- CGEIT (Certified in the Governance of Enterprise IT)
- CDPSE (Certified Data Privacy Solutions Engineer)
- COBIT (Control Objectives for Information and Related Technologies)
- Cybersecurity Nexus (CSX)
- SheLeadsTech
Products and services
- CISA (Certified Information Systems Auditor) Flagship credential validating skills in auditing, control, and security of information systems, targeted at IT audit and assurance professionals.
- CISM (Certified Information Security Manager)
Quantifiable outcome
- 51% of European IT/cybersecurity professionals expect AI-driven cyber threats and deepfakes to increase concerns by 2026
- +1 more outcomes
Companies that use ISACA
Customer profileNamed customers4 records
Segments4 records
Ideal customer profiles4 records
ISACA technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability2 records
Feature4 records
ISACA partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered core, strategic and minor.
- US Department of DefensecoreISACA appointed by the US Department of War in December 2025 as the global Cybersecurity Assessor and Certifier Organization (CACOS) for the Cybersecurity Maturity Model Certification (CMMC) program, the largest cybersecurity certification initiative for defense procurement and allied supply chains including AUKUS nations.
- KPMGcoreKPMG Partner Stanley Sum leads the regulatory landscape session at the ISACA Fintech Governance Workshop, providing professional services for chapter events.
- EYcoreEY Partners Chris Barford and Winnie Cheung lead fintech risk assessment and control programme sessions at the ISACA Fintech Governance Workshop.
- DeloittecoreDeloitte Directors Chris Chui and Philip Mok lead the cyber resilience tabletop exercise at the ISACA Fintech Governance Workshop.
- ISACA London ChapterstrategicCross-chapter collaboration between ISACA London Chapter and ISACA China Hong Kong Chapter for SheLeadsTech London x Hong Kong initiative, promoting women in technology through joint webinars.
- CityU HK Tech 300 IncuHubminorCity University of Hong Kong's startup incubation program provides venue and sponsors free attendance for Tech 300 Startup Founders and students at ISACA Fintech Governance Workshop.
- Hong Kong Monetary AuthoritystrategicHKMA serves as on-site venue host for chapter events including the Privacy Enhancing Technologies seminar, supporting financial sector professional development.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
ISACA competitors and assessment
Company assessmentMarket position
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
ISACA social profiles
Digital presenceISACA financial estimates
Financial estimateRevenue estimate
Valuation estimate
ISACA leadership team
Management profileNumber of profiles
Profiles12 records
ISACA subsidiaries and ownership
Company hierarchySubsidiaries1 record
ISACA funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ISACA M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ISACA
What does ISACA do?
ISACA is a global professional association that issues industry-recognized credentials (CISA, CISM, CRISC, CGEIT, CDPSE, AAIA, AAISM, AAIR) and proprietary frameworks (COBIT, CSX) for IT governance, cybersecurity, audit, and risk professionals. It generates revenue through certification exam fees, professional membership dues, training, conferences, and knowledge publications, and operates a worldwide network of 200+ chapters serving 140,000+ members across 180 countries.
Is ISACA a public or private company?
ISACA is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was ISACA founded?
ISACA was founded in 1969. It employs 1 to 10 people.
Where is ISACA based?
ISACA is headquartered in North Point, Hong Kong SAR China, in the Asia region.
How does ISACA make money?
Four revenue lines are on record. Professional Certifications are the primary driver. The others are chapter Membership, training and Events and knowledge Products.
Does ISACA have an API?
No public API is recorded for ISACA.
What industry is ISACA in?
ISACA's product category is Professional Certification and Training Services. Its primary akta.pro industry code is EDAOAIAF, Identity & Access Management (IAM). Its NAICS code is 81392 and its SIC code is 8600.