ISACA
ISACA is a global professional association serving 185,000+ digital trust professionals across 190 countries with certifications (CISA, CISM, CRISC, CDPSE, CGEIT, AAIR), frameworks (COBIT, ITAF, CMMI), and the CMMC credentialing mandate for US defense contractors.
- Company typePrivate
- Founded1969
- HeadquartersRolling Meadows, United States
- Headcount1–10
- GTM typeB2B and B2C
- OfferingServices
What ISACA does
ISACA (Information System Audit and Control Association, Inc.) is a global, member-governed professional association founded in 1969 and headquartered in Schaumburg, Illinois. It serves more than 185,000 digital trust professionals across approximately 190 countries through a portfolio of certifications (CISA, CISM, CRISC, CDPSE, CCOA, CGEIT, and AI-focused AAIR/AAIA/AAISM), frameworks (COBIT, ITAF, the Digital Trust Ecosystem Framework), the CMMI Institute (acquired in 2016), and the recently acquired Cybersecurity Assessor and Instructor Certification Organization (CAICO) mandate for the US Department of War's CMMC program. Its technical assets include the Security Debt Index (SDI) composite scoring model, the CMMI AI Maturity (AIM) Framework, and the AI Impact Assessment Tool, delivered through an online store, learning management system, and exam proctoring platform.
ISACA generates revenue across five primary streams: recurring professional membership dues (annual, auto-renewing), certification exam registration and maintenance fees (recurring across the certification lifecycle), training and conference revenue (in-person training weeks, virtual workshops, multi-region conferences, session recordings), educational resources and publications (white papers, journals, review courses), and the CMMC credentialing program (administering CCP, CCA, CCI, and Lead CCA designations for defense industrial base assessors). Distribution runs through a direct-to-consumer online store, a global enterprise sales team, over 200 accredited training partners across Americas/Asia/China/EMEA, and a local chapter network in 190 countries. Pricing mixes subscription (membership, recording packages), freemium (member-only webinars/summits), and one-time license (exam fees) models.
Its customer base spans individual practitioners (IT audit, security, risk, privacy, governance professionals), defense industrial base organizations subject to CMMC requirements, enterprises seeking team training and CMMI appraisals, and emerging workforces (notably in India via the Nasscom MoU integrating certifications into the National Skill Qualification Framework). Recent strategic priorities have centered on AI governance credentialing, the CMMC regulatory mandate, and geographic deepening into India and the Middle East, supported by an ecosystem of training partners, online communities (Engage platform), and a foundation that has awarded over US$1.4 million in scholarships to 800+ students since 2022.
ISACA firmographics
Firmographics- Name
- ISACA
- Legal name
- Information System Audit and Control Association, Inc.
- Website
- https://isaca.org
- Company type
- Private
- Founded year
- 1969
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- ISACA is a global professional association serving 185,000+ digital trust professionals across 190 countries with certifications (CISA, CISM, CRISC, CDPSE, CGEIT, AAIR), frameworks (COBIT, ITAF, CMMI), and the CMMC credentialing mandate for US defense contractors.
- Ownership category
- akta.pro rank
ISACA industry classification
Industry- Product category
- IT Audit and Cybersecurity Professional Certifications
- NAICS
- Business Associations (813910), Professional Organizations (81392), Professional Organizations (813920)
- SIC
- Services-Membership Organizations (8600)
- akta.pro primary industry
- Finance, Accounting & Risk (CFA/CPA/FRM) Certifications (EDAAANAD)
Keywords
Where ISACA is headquartered
LocationHeadquarters
- HQ city
- Rolling Meadows
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
ISACA business model
Business model- GTM type
- B2B and B2C
- Offering type
- Services
- Cost components
- Personnel, Marketing or Sales, Technology or R&D, Operations, Infrastructure
Revenue model
- Professional Certifications: ISACA offers globally recognized certifications including CISA, CISM, CRISC, CDPSE, CGEIT, and newer AI-focused credentials (AAIR, AAIA, AAISM). Revenue generated through exam registration fees, certification maintenance fees, and renewal charges. Certifications require passing exams and ongoing CPE compliance.
- Professional Membership: Annual membership dues provide access to member benefits including free CPE opportunities, discounts on training and events, chapter networks, mentorship programs, and resources. Membership is a 12-month term with auto-renewal options.
- Training & Conferences: Revenue from in-person training weeks, virtual workshops, conference registrations (North America, Europe, GRC, Virtual), and session recordings. Enterprise team training and customized corporate programs available. Over 24,000 exams taken through ISACA Enterprise Training in 2025.
- Educational Resources & Publications: Sale of white papers, the ISACA Journal, books, exam prep materials, and digital learning content. Revenue from online review courses, on-demand CPE training, and session recording packages.
- CMMC Credentialing Program: ISACA serves as the official Cybersecurity Assessor and Instructor Certification Organization (CAICO) for the US Department of War's CMMC program, administering credential programs including CMMC Certified Professional, Certified Assessor, Certified Instructor, and Lead CCA designations.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Webinars for members |
| Freemium | Pay-as-you-go | Virtual Summits for members |
| Subscription | Annual | Professional Membership |
| One time/ perpetual license | Pay-as-you-go | Exam Registration Fees |
| Subscription | Pay-as-you-go | Session Recording Packages |
Go-to-market motion1 record
Distribution channels6 records
Marketing channels8 records
ISACA product offering
Product offeringCore offering
ISACA is a global professional association that develops, administers, and sells IT audit, cybersecurity, risk, privacy, and governance certifications (CISA, CISM, CRISC, CDPSE, CGEIT, CCOA, AAIA, AAIR, AAISM, CMMC credentials) along with foundational certificates. It delivers accompanying training (online review courses, virtual workshops, webinars, conferences) and publishes authoritative frameworks (COBIT, ITAF, Digital Trust Ecosystem Framework, CMMI) and assessment tools (CMMI Cybermaturity Platform, AI Impact Assessment Tool) for individuals and enterprises worldwide.
Product overview
ISACA is a global professional association offering a comprehensive portfolio of credentials, training, and frameworks for digital trust professionals. The portfolio includes professional certifications (CISA, CISM, CRISC, CDPSE, CCOA, CGEIT), advanced AI-specific certifications (AAIA, AAIR, AAISM), CMMC-related credentials (CCP, CCA, LCCA, CCI) for defense contractors, and foundational certificates (AI Fundamentals, Cloud Fundamentals, Cybersecurity Fundamentals, COBIT, etc.). These credentials are supported by training delivery through online review courses, virtual workshops, webinars, virtual summits, and conference session recordings. ISACA also provides enterprise solutions including CMMI Performance Solutions, CMMI Cybermaturity Platform, and governance frameworks such as COBIT and the Digital Trust Ecosystem Framework. Recent additions include the Security Debt Index (SDI) model, ITAF 5th edition, and AI governance tools like the AI Impact Assessment Tool. The organization serves over 185,000 members across approximately 190 countries.
Differentiator
Problem solved
Functional benefit
Brands
- CMMI Institute: A division of ISACA administering the Capability Maturity Model Integration framework, performance improvement solutions, and cybermaturity platform services.
Products and services
- CISA - Certified Information Systems Auditor Globally recognized certification for information systems audit professionals, validating expertise in auditing, control, monitoring, and assessing information technology and business systems.
- CISM - Certified Information Security Manager Advanced certification for information security managers covering information security governance, program development and management, and incident response.
- CRISC - Certified in Risk and Information Systems Control
- CDPSE - Certified Data Privacy Solutions Engineer
- CCOA - Certified Cybersecurity Operations Analyst
- CGEIT - Certified in the Governance of Enterprise IT
- AAIA - Advanced in AI Audit Advanced certification validating ability to audit AI systems, assess AI-related risks, and provide assurance on AI governance and compliance.
- AAIR - Advanced in AI Risk Advanced certification equipping IT risk professionals with specialized skills to manage AI-related vulnerabilities and risks across AI risk governance, lifecycle risk management, and risk program management.
- AAISM - Advanced in AI Security Management Advanced certification focusing on AI security management capabilities and securing AI systems throughout their lifecycle.
- CCP - CMMC Certified Professional Credential for professionals working within the Cybersecurity Maturity Model Certification ecosystem, demonstrating knowledge of CMMC requirements and implementation.
- CCA - CMMC Certified Assessor Credential for assessors authorized to evaluate organizations seeking CMMC certification against the U.S. Department of War's cybersecurity requirements.
- LCCA - Lead CMMC Certified Assessor Designation Advanced designation for lead assessors overseeing CMMC certification assessments of defense contractors.
- CCI - CMMC Credentialed Instructor Credential for instructors authorized to train and prepare candidates for CMMC certification assessments.
- COBIT 2019 Foundation Certificate
- COBIT 2019 Design & Implementation Certificate
- Cybersecurity Fundamentals Certificate
- Cloud Fundamentals Certificate
- AI Fundamentals Certificate
- Digital Trust Ecosystem Framework Foundation Certificate
- CMMI Performance Solutions
- CMMI Cybermaturity Platform
- Online Review Courses
- Virtual Workshops
- ISACA Webinars
- Virtual Summits
- Session Recordings
- ISACA Conferences
- COBIT Framework
- ITAF - IT Audit Framework (5th Edition) Professional practices framework for IT audit and assurance, addressing emerging technologies including AI/ML, cloud computing, and business automation with emphasis on digital trust, governance, and AI auditing.
- Digital Trust Ecosystem Framework
- CMMI AI Maturity (AIM) Framework Framework for governing AI at scale across organizations, with 157 AI context-specific additions across all 31 CMMI practice areas and two new certification courses focusing on AI concepts, ethics, and appraisal methods.
- Security Debt Index (SDI) Model Composite scoring model that evaluates organizational security debt across three dimensions: Severity (business impact), Duration (how long debt has remained unresolved), and Velocity (how quickly new issues of the same type appear).
- AI Impact Assessment Tool
- Professional Membership
Quantifiable outcome
- Over 24,000 exams taken through ISACA Enterprise Training in 2025
- +4 more outcomes
Companies that use ISACA
Customer profileNamed customers6 records
Segments9 records
Ideal customer profiles4 records
ISACA technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability3 records
Feature5 records
ISACA partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered flagship, core and regional.
- IBM GlobalflagshipIBM Global is a sponsor of the 25-member AI Working Group that developed the CMMI AI Maturity (AIM) framework. The framework is set to be unveiled at the Capability Creates 2026 conference in Washington, DC in June, designed to govern AI at scale across organizations.
- KPMGflagshipKPMG is a sponsor of the 25-member AI Working Group that developed the CMMI AI Maturity (AIM) framework. The framework includes 157 AI context-specific additions across all 31 practice areas and two new certification courses focusing on AI concepts, ethics, and appraisal methods.
- CYBER.ORGcoreCYBER.ORG announced expanded collaborations including ISACA to enhance cybersecurity and AI workforce training in the United States. The partnership aims to develop industry-relevant skills among students through certification programs, project-based modules, and nationwide educator networks, aligning education with industry needs.
- CompTIAcorePartnership with CompTIA as part of CYBER.ORG's expanded industry collaboration to strengthen cybersecurity and AI workforce training across the United States through certification programs and educational modules.
- IntelcoreIntel collaboration as part of CYBER.ORG's expanded industry partnerships to enhance cybersecurity and AI workforce training in the United States, integrating industry expertise into educational programs.
- DigitalXForceregionalKapil Matta, Middle East Region Lead at DigitalXForce, was elected as President of the ISACA UAE Chapter. DigitalXForce frames this as a milestone reinforcing the company's commitment to advancing governance standards, cybersecurity innovation, and digital trust across the META region.
- Ohio UniversityregionalThree Ohio University students received the ISACA Central Ohio Chapter Cybersecurity Fellowship, providing one-on-one coaching with ISACA professionals, a $500 scholarship, and an officially recognized cyber-related certificate upon completion.
- The Institute of Internal Auditors (IIA)flagshipISACA and IIA co-host the annual Governance, Risk, and Control (GRC) Conference, providing digital trust professionals access to up to 28 CPE credits. The partnership combines ISACA's technology governance expertise with IIA's internal audit leadership.
- NasscomcoreISACA and Nasscom signed an MoU to align ISACA certifications with India's National Skill Qualification Framework, integrating them into India's higher education and skilling ecosystem. The initiative aims to enhance digital skills of India's workforce and improve access to globally recognized credentials through platforms like FutureSkills Prime.
- US Department of War (DoW)flagshipISACA authorized as the exclusive Cybersecurity Assessor and Instructor Certification Organization (CAICO) for the US Department of War's Cybersecurity Maturity Model Certification (CMMC) program. ISACA administers credential programs including CMMC Certified Professional, Certified Assessor, Certified Instructor, and Lead CCA designations. Over 100,000 companies will eventually require Level 2 certification.
Scale indicators10 records
Recent moves7 records
Expansion highlights6 records
ISACA competitors and assessment
Company assessmentDirect peers
- (ISC)²: (ISC)² is a global non-profit membership association offering cybersecurity certifications (CISSP, CCSP, SSCP) - the closest direct competitor to ISACA in the IT/security professional credentialing space with a similar membership-based, certification-driven business model.
- SANS Institute (GIAC): SANS Institute and its GIAC certification arm deliver technical cybersecurity training and credentials that directly overlap with ISACA's CISM, CCOA, and cybersecurity fundamentals certificates - competing for the same enterprise security training budgets.
- CompTIA: CompTIA offers vendor-neutral IT certifications (Security+, CySA+, CASP+) that overlap with ISACA's fundamentals and cybersecurity credentials, and is also a CYBER.ORG partner - making it a direct peer in IT professional certification.
- EC-Council: EC-Council offers the Certified Ethical Hacker (CEH) and other cybersecurity credentials that compete with ISACA's cybersecurity and security operations certifications in the same enterprise buyer segment.
- ISACA's IIA (Institute of Internal Auditors): The IIA is a global professional association for internal auditors and ISACA's GRC Conference co-host - directly comparable membership-driven certification body serving overlapping IT audit and governance audiences.
Broad incumbents
- Project Management Institute (PMI): PMI is a large global professional membership association offering the PMP credential with a similar non-profit, membership-dues, certification-maintenance revenue model - comparable as an industry-vertical peer in the professional association category.
- AICPA: AICPA is a major US professional membership association for CPAs offering certifications and credentialing programs with a comparable governance, certification, and continuing-education revenue model to ISACA.
Emerging players
- Cloud Security Alliance (CSA): CSA is an emerging non-profit offering cloud security credentials (CCSK, CCSP co-developed with (ISC)²) that increasingly compete with ISACA's cloud fundamentals and CDPSE credentials in the cloud security governance space.
- OffSec (Offensive Security): OffSec offers the OSCP and other hands-on security credentials that compete for the technical cybersecurity practitioner's training budget, representing an emerging alternative to ISACA's more governance-focused credentials.
Others
- NIST (National Institute of Standards and Technology): NIST publishes widely adopted cybersecurity and AI risk frameworks (NIST CSF, AI RMF) that ISACA frameworks like CMMI AIM must interoperate with - making NIST an ecosystem peer whose standards shape ISACA's product roadmap.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat7 records
Key risks5 records
Key highlights7 records
Customer concentration
ISACA social profiles
Digital presenceISACA financial estimates
Financial estimateRevenue estimate
Valuation estimate
ISACA leadership team
Management profileNumber of profiles
Profiles8 records
ISACA subsidiaries and ownership
Company hierarchySubsidiaries1 record
ISACA funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ISACA M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ISACA
What does ISACA do?
ISACA is a global professional association that develops, administers, and sells IT audit, cybersecurity, risk, privacy, and governance certifications (CISA, CISM, CRISC, CDPSE, CGEIT, CCOA, AAIA, AAIR, AAISM, CMMC credentials) along with foundational certificates. It delivers accompanying training (online review courses, virtual workshops, webinars, conferences) and publishes authoritative frameworks (COBIT, ITAF, Digital Trust Ecosystem Framework, CMMI) and assessment tools (CMMI Cybermaturity Platform, AI Impact Assessment Tool) for individuals and enterprises worldwide.
Is ISACA a public or private company?
ISACA is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was ISACA founded?
ISACA was founded in 1969. It employs 1 to 10 people.
Where is ISACA based?
ISACA is headquartered in Rolling Meadows, United States, in the North America region.
How does ISACA make money?
Five revenue lines are on record. Professional Certifications are the primary driver. The others are professional Membership, training & Conferences, educational Resources & Publications and CMMC Credentialing Program.
Who are ISACA's main competitors?
Direct peers on record are (ISC)², SANS Institute (GIAC), CompTIA, EC-Council and ISACA's IIA (Institute of Internal Auditors). Broad incumbents are Project Management Institute (PMI) and AICPA. Emerging players are Cloud Security Alliance (CSA) and OffSec (Offensive Security). NIST (National Institute of Standards and Technology) is listed as an others.
Does ISACA have an API?
No public API is recorded for ISACA.
What industry is ISACA in?
ISACA's product category is IT Audit and Cybersecurity Professional Certifications. Its primary akta.pro industry code is EDAAANAD, Finance, Accounting & Risk (CFA/CPA/FRM) Certifications. Its NAICS code is 813910 and its SIC code is 8600.