Developer docs
API playgroundTry for free, no card

Search company profiles

ISACA

Full company profile

uuid000apv7

Namestring
ISACA
Legal namestring
Information System Audit and Control Association, Inc.
Websiteurl
isaca.org
Company typeenum
Private
Founded yearint
1969
Descriptiontext

ISACA (Information System Audit and Control Association, Inc.) is a global, member-governed professional association founded in 1969 and headquartered in Schaumburg, Illinois. It serves more than 185,000 digital trust professionals across approximately 190 countries through a portfolio of certifications (CISA, CISM, CRISC, CDPSE, CCOA, CGEIT, and AI-focused AAIR/AAIA/AAISM), frameworks (COBIT, ITAF, the Digital Trust Ecosystem Framework), the CMMI Institute (acquired in 2016), and the recently acquired Cybersecurity Assessor and Instructor Certification Organization (CAICO) mandate for the US Department of War's CMMC program. Its technical assets include the Security Debt Index (SDI) composite scoring model, the CMMI AI Maturity (AIM) Framework, and the AI Impact Assessment Tool, delivered through an online store, learning management system, and exam proctoring platform.

ISACA generates revenue across five primary streams: recurring professional membership dues (annual, auto-renewing), certification exam registration and maintenance fees (recurring across the certification lifecycle), training and conference revenue (in-person training weeks, virtual workshops, multi-region conferences, session recordings), educational resources and publications (white papers, journals, review courses), and the CMMC credentialing program (administering CCP, CCA, CCI, and Lead CCA designations for defense industrial base assessors). Distribution runs through a direct-to-consumer online store, a global enterprise sales team, over 200 accredited training partners across Americas/Asia/China/EMEA, and a local chapter network in 190 countries. Pricing mixes subscription (membership, recording packages), freemium (member-only webinars/summits), and one-time license (exam fees) models.

Its customer base spans individual practitioners (IT audit, security, risk, privacy, governance professionals), defense industrial base organizations subject to CMMC requirements, enterprises seeking team training and CMMI appraisals, and emerging workforces (notably in India via the Nasscom MoU integrating certifications into the National Skill Qualification Framework). Recent strategic priorities have centered on AI governance credentialing, the CMMC regulatory mandate, and geographic deepening into India and the Middle East, supported by an ecosystem of training partners, online communities (Engage platform), and a foundation that has awarded over US$1.4 million in scholarships to 800+ students since 2022.

Short descriptiontext

ISACA is a global professional association serving 185,000+ digital trust professionals across 190 countries with certifications (CISA, CISM, CRISC, CDPSE, CGEIT, AAIR), frameworks (COBIT, ITAF, CMMI), and the CMMC credentialing mandate for US defense contractors.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
1–10
akta.pro rankint
HeadquartersRolling Meadows, United States
HQ citystring
Rolling Meadows
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
IT audit certifications, cybersecurity credentials, enterprise risk management, IT governance frameworks, professional membership association
Industry1 code
1Finance, Accounting & Risk (CFA/CPA/FRM) Certifications
CodeEDAAANADPrimaryYes
NAICS code3 codes
  • Business Associations813910
  • Professional Organizations81392
  • Professional Organizations813920
SIC code1 code
  • Services-Membership Organizations8600
Product category
IT Audit and Cybersecurity Professional Certifications
GTM motion1 record

Each record includes

Type, Description, Source

Revenue model5 records
1Professional Certifications
TypeSubscription Recurring
Description

ISACA offers globally recognized certifications including CISA, CISM, CRISC, CDPSE, CGEIT, and newer AI-focused credentials (AAIR, AAIA, AAISM). Revenue generated through exam registration fees, certification maintenance fees, and renewal charges. Certifications require passing exams and ongoing CPE compliance.

isaca.org
2Professional Membership
TypeSubscription Recurring
Description

Annual membership dues provide access to member benefits including free CPE opportunities, discounts on training and events, chapter networks, mentorship programs, and resources. Membership is a 12-month term with auto-renewal options.

isaca.org
3Training & Conferences
TypeProfessional Services
Description

Revenue from in-person training weeks, virtual workshops, conference registrations (North America, Europe, GRC, Virtual), and session recordings. Enterprise team training and customized corporate programs available. Over 24,000 exams taken through ISACA Enterprise Training in 2025.

isaca.org
4Educational Resources & Publications
TypeOne Time License
Description

Sale of white papers, the ISACA Journal, books, exam prep materials, and digital learning content. Revenue from online review courses, on-demand CPE training, and session recording packages.

isaca.org
5CMMC Credentialing Program
TypeLicensing Royalties
Description

ISACA serves as the official Cybersecurity Assessor and Instructor Certification Organization (CAICO) for the US Department of War's CMMC program, administering credential programs including CMMC Certified Professional, Certified Assessor, Certified Instructor, and Lead CCA designations.

defensescoop.com
Marketing channels8 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels6 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Marketing or Sales, Technology or R&D, Operations, Infrastructure
Pricing details5 tiers
1Webinars for members
ModelFreemiumBilling cadencePay-as-you-go
Notes

Free for ISACA members. Non-members pay US$75 per webinar. Earn 1 CPE credit per webinar. Over 50 webinars available with associated CPE credits (value of US$3,750) included in membership.

isaca.org
2Virtual Summits for members
ModelFreemiumBilling cadencePay-as-you-go
Notes

Free for ISACA members. Non-members pay up to US$225. Earn 3-4 CPE credits per virtual summit. Note: Virtual Summits are not eligible for NASBA credit.

isaca.org
3Professional Membership
ModelSubscriptionBilling cadenceAnnual
Notes

Annual membership with 12-month term. Includes free CPE opportunities, discounts on training and events, chapter access, mentorship program, and career center resources. Auto-renewal available.

isaca.org
4Exam Registration Fees
ModelOne time/ perpetual licenseBilling cadencePay-as-you-go
Notes

Exam fees must be requested for refund within 30 days of purchase. No refunds for exams already taken. Certification maintenance fees apply for renewal.

isaca.org
5Session Recording Packages
ModelSubscriptionBilling cadencePay-as-you-go
Notes

Session recording packages offer 6 months unlimited access. Collections include Top Ten Sessions (up to 10 CPEs), Variety Pack, Career/Leadership Development (up to 5 CPEs), Risk Collection (up to 5 CPEs), Cybersecurity (up to 5 CPEs), and Emerging Technologies (up to 6 CPEs).

isaca.org
GTM typeB2B and B2C
B2B and B2C
Offering typeServices
Services
Brand1 record
1CMMI Institute
Description

A division of ISACA administering the Capability Maturity Model Integration framework, performance improvement solutions, and cybermaturity platform services.

isaca.org
Core offering1 text field

ISACA is a global professional association that develops, administers, and sells IT audit, cybersecurity, risk, privacy, and governance certifications (CISA, CISM, CRISC, CDPSE, CGEIT, CCOA, AAIA, AAIR, AAISM, CMMC credentials) along with foundational certificates. It delivers accompanying training (online review courses, virtual workshops, webinars, conferences) and publishes authoritative frameworks (COBIT, ITAF, Digital Trust Ecosystem Framework, CMMI) and assessment tools (CMMI Cybermaturity Platform, AI Impact Assessment Tool) for individuals and enterprises worldwide.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 5 values shown
  • Over 24,000 exams taken through ISACA Enterprise Training in 2025
+4 more records
Product overview1 text field

ISACA is a global professional association offering a comprehensive portfolio of credentials, training, and frameworks for digital trust professionals. The portfolio includes professional certifications (CISA, CISM, CRISC, CDPSE, CCOA, CGEIT), advanced AI-specific certifications (AAIA, AAIR, AAISM), CMMC-related credentials (CCP, CCA, LCCA, CCI) for defense contractors, and foundational certificates (AI Fundamentals, Cloud Fundamentals, Cybersecurity Fundamentals, COBIT, etc.). These credentials are supported by training delivery through online review courses, virtual workshops, webinars, virtual summits, and conference session recordings. ISACA also provides enterprise solutions including CMMI Performance Solutions, CMMI Cybermaturity Platform, and governance frameworks such as COBIT and the Digital Trust Ecosystem Framework. Recent additions include the Security Debt Index (SDI) model, ITAF 5th edition, and AI governance tools like the AI Impact Assessment Tool. The organization serves over 185,000 members across approximately 190 countries.

Product and service34 records
1CISA - Certified Information Systems Auditor
CategoryProfessional Certification
Description

Globally recognized certification for information systems audit professionals, validating expertise in auditing, control, monitoring, and assessing information technology and business systems.

2CISM - Certified Information Security Manager
CategoryProfessional Certification
Description

Advanced certification for information security managers covering information security governance, program development and management, and incident response.

3CRISC - Certified in Risk and Information Systems Control
4CDPSE - Certified Data Privacy Solutions Engineer
5CCOA - Certified Cybersecurity Operations Analyst
6CGEIT - Certified in the Governance of Enterprise IT
7AAIA - Advanced in AI Audit
CategoryProfessional Certification
Description

Advanced certification validating ability to audit AI systems, assess AI-related risks, and provide assurance on AI governance and compliance.

8AAIR - Advanced in AI Risk
CategoryProfessional Certification
Description

Advanced certification equipping IT risk professionals with specialized skills to manage AI-related vulnerabilities and risks across AI risk governance, lifecycle risk management, and risk program management.

9AAISM - Advanced in AI Security Management
CategoryProfessional Certification
Description

Advanced certification focusing on AI security management capabilities and securing AI systems throughout their lifecycle.

10CCP - CMMC Certified Professional
CategoryProfessional Certification
Description

Credential for professionals working within the Cybersecurity Maturity Model Certification ecosystem, demonstrating knowledge of CMMC requirements and implementation.

11CCA - CMMC Certified Assessor
CategoryProfessional Certification
Description

Credential for assessors authorized to evaluate organizations seeking CMMC certification against the U.S. Department of War's cybersecurity requirements.

12LCCA - Lead CMMC Certified Assessor Designation
CategoryProfessional Certification
Description

Advanced designation for lead assessors overseeing CMMC certification assessments of defense contractors.

13CCI - CMMC Credentialed Instructor
CategoryProfessional Certification
Description

Credential for instructors authorized to train and prepare candidates for CMMC certification assessments.

14COBIT 2019 Foundation Certificate
15COBIT 2019 Design & Implementation Certificate
16Cybersecurity Fundamentals Certificate
17Cloud Fundamentals Certificate
18AI Fundamentals Certificate
19Digital Trust Ecosystem Framework Foundation Certificate
20CMMI Performance Solutions
21CMMI Cybermaturity Platform
22Online Review Courses
23Virtual Workshops
24ISACA Webinars
25Virtual Summits
26Session Recordings
27ISACA Conferences
28COBIT Framework
29ITAF - IT Audit Framework (5th Edition)
CategoryFramework
Description

Professional practices framework for IT audit and assurance, addressing emerging technologies including AI/ML, cloud computing, and business automation with emphasis on digital trust, governance, and AI auditing.

30Digital Trust Ecosystem Framework
31CMMI AI Maturity (AIM) Framework
CategoryFramework
Description

Framework for governing AI at scale across organizations, with 157 AI context-specific additions across all 31 CMMI practice areas and two new certification courses focusing on AI concepts, ethics, and appraisal methods.

32Security Debt Index (SDI) Model
CategoryFramework/Tool
Description

Composite scoring model that evaluates organizational security debt across three dimensions: Severity (business impact), Duration (how long debt has remained unresolved), and Velocity (how quickly new issues of the same type appear).

33AI Impact Assessment Tool
34Professional Membership
Scale indicator10 records

Each record includes

Type, Value, Description, Source

Partnership10 partners
Strategic tierFlagshipTypeStrategic or Co-development PartnerAnnounced on2026-06-01
Description

IBM Global is a sponsor of the 25-member AI Working Group that developed the CMMI AI Maturity (AIM) framework. The framework is set to be unveiled at the Capability Creates 2026 conference in Washington, DC in June, designed to govern AI at scale across organizations.

Strategic tierFlagshipTypeStrategic or Co-development PartnerAnnounced on2026-06-01
Description

KPMG is a sponsor of the 25-member AI Working Group that developed the CMMI AI Maturity (AIM) framework. The framework includes 157 AI context-specific additions across all 31 practice areas and two new certification courses focusing on AI concepts, ethics, and appraisal methods.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-05-14
Description

CYBER.ORG announced expanded collaborations including ISACA to enhance cybersecurity and AI workforce training in the United States. The partnership aims to develop industry-relevant skills among students through certification programs, project-based modules, and nationwide educator networks, aligning education with industry needs.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-05-14
Description

Partnership with CompTIA as part of CYBER.ORG's expanded industry collaboration to strengthen cybersecurity and AI workforce training across the United States through certification programs and educational modules.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-05-14
Description

Intel collaboration as part of CYBER.ORG's expanded industry partnerships to enhance cybersecurity and AI workforce training in the United States, integrating industry expertise into educational programs.

Strategic tierRegionalTypeOthersAnnounced on2026-02-28
Description

Kapil Matta, Middle East Region Lead at DigitalXForce, was elected as President of the ISACA UAE Chapter. DigitalXForce frames this as a milestone reinforcing the company's commitment to advancing governance standards, cybersecurity innovation, and digital trust across the META region.

Strategic tierRegionalTypeOthersAnnounced on2026-02-28
Description

Three Ohio University students received the ISACA Central Ohio Chapter Cybersecurity Fellowship, providing one-on-one coaching with ISACA professionals, a $500 scholarship, and an officially recognized cyber-related certificate upon completion.

Strategic tierFlagshipTypeStrategic or Co-development PartnerAnnounced on2026-02-05
Description

ISACA and IIA co-host the annual Governance, Risk, and Control (GRC) Conference, providing digital trust professionals access to up to 28 CPE credits. The partnership combines ISACA's technology governance expertise with IIA's internal audit leadership.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2025-12-10
Description

ISACA and Nasscom signed an MoU to align ISACA certifications with India's National Skill Qualification Framework, integrating them into India's higher education and skilling ecosystem. The initiative aims to enhance digital skills of India's workforce and improve access to globally recognized credentials through platforms like FutureSkills Prime.

Strategic tierFlagshipTypeOthersAnnounced on2025-12-01
Description

ISACA authorized as the exclusive Cybersecurity Assessor and Instructor Certification Organization (CAICO) for the US Department of War's Cybersecurity Maturity Model Certification (CMMC) program. ISACA administers credential programs including CMMC Certified Professional, Certified Assessor, Certified Instructor, and Lead CCA designations. Over 100,000 companies will eventually require Level 2 certification.

Recent move7 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

(ISC)² is a global non-profit membership association offering cybersecurity certifications (CISSP, CCSP, SSCP) - the closest direct competitor to ISACA in the IT/security professional credentialing space with a similar membership-based, certification-driven business model.

TypeDirect peer
Description

SANS Institute and its GIAC certification arm deliver technical cybersecurity training and credentials that directly overlap with ISACA's CISM, CCOA, and cybersecurity fundamentals certificates - competing for the same enterprise security training budgets.

TypeDirect peer
Description

CompTIA offers vendor-neutral IT certifications (Security+, CySA+, CASP+) that overlap with ISACA's fundamentals and cybersecurity credentials, and is also a CYBER.ORG partner - making it a direct peer in IT professional certification.

TypeDirect peer
Description

EC-Council offers the Certified Ethical Hacker (CEH) and other cybersecurity credentials that compete with ISACA's cybersecurity and security operations certifications in the same enterprise buyer segment.

5ISACA's IIA (Institute of Internal Auditors)
TypeDirect peer
Description

The IIA is a global professional association for internal auditors and ISACA's GRC Conference co-host - directly comparable membership-driven certification body serving overlapping IT audit and governance audiences.

TypeBroad incumbent
Description

PMI is a large global professional membership association offering the PMP credential with a similar non-profit, membership-dues, certification-maintenance revenue model - comparable as an industry-vertical peer in the professional association category.

TypeBroad incumbent
Description

AICPA is a major US professional membership association for CPAs offering certifications and credentialing programs with a comparable governance, certification, and continuing-education revenue model to ISACA.

TypeEmerging player
Description

CSA is an emerging non-profit offering cloud security credentials (CCSK, CCSP co-developed with (ISC)²) that increasingly compete with ISACA's cloud fundamentals and CDPSE credentials in the cloud security governance space.

TypeEmerging player
Description

OffSec offers the OSCP and other hands-on security credentials that compete for the technical cybersecurity practitioner's training budget, representing an emerging alternative to ISACA's more governance-focused credentials.

TypeOthers
Description

NIST publishes widely adopted cybersecurity and AI risk frameworks (NIST CSF, AI RMF) that ISACA frameworks like CMMI AIM must interoperate with - making NIST an ecosystem peer whose standards shape ISACA's product roadmap.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses4 records

Each record includes

Headline, Details, Source

Competitive moat7 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers6 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment9 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile4 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

AI capability3 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature5 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles8 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

Subsidiaries1 record

Each record includes

Name, Acquired on, Relationship type, Type, Business focus

No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

ISACA

IT Audit and Cybersecurity Professional Certificationsisaca.org

ISACA is a global professional association serving 185,000+ digital trust professionals across 190 countries with certifications (CISA, CISM, CRISC, CDPSE, CGEIT, AAIR), frameworks (COBIT, ITAF, CMMI), and the CMMC credentialing mandate for US defense contractors.

What ISACA does

ISACA (Information System Audit and Control Association, Inc.) is a global, member-governed professional association founded in 1969 and headquartered in Schaumburg, Illinois. It serves more than 185,000 digital trust professionals across approximately 190 countries through a portfolio of certifications (CISA, CISM, CRISC, CDPSE, CCOA, CGEIT, and AI-focused AAIR/AAIA/AAISM), frameworks (COBIT, ITAF, the Digital Trust Ecosystem Framework), the CMMI Institute (acquired in 2016), and the recently acquired Cybersecurity Assessor and Instructor Certification Organization (CAICO) mandate for the US Department of War's CMMC program. Its technical assets include the Security Debt Index (SDI) composite scoring model, the CMMI AI Maturity (AIM) Framework, and the AI Impact Assessment Tool, delivered through an online store, learning management system, and exam proctoring platform.

ISACA generates revenue across five primary streams: recurring professional membership dues (annual, auto-renewing), certification exam registration and maintenance fees (recurring across the certification lifecycle), training and conference revenue (in-person training weeks, virtual workshops, multi-region conferences, session recordings), educational resources and publications (white papers, journals, review courses), and the CMMC credentialing program (administering CCP, CCA, CCI, and Lead CCA designations for defense industrial base assessors). Distribution runs through a direct-to-consumer online store, a global enterprise sales team, over 200 accredited training partners across Americas/Asia/China/EMEA, and a local chapter network in 190 countries. Pricing mixes subscription (membership, recording packages), freemium (member-only webinars/summits), and one-time license (exam fees) models.

Its customer base spans individual practitioners (IT audit, security, risk, privacy, governance professionals), defense industrial base organizations subject to CMMC requirements, enterprises seeking team training and CMMI appraisals, and emerging workforces (notably in India via the Nasscom MoU integrating certifications into the National Skill Qualification Framework). Recent strategic priorities have centered on AI governance credentialing, the CMMC regulatory mandate, and geographic deepening into India and the Middle East, supported by an ecosystem of training partners, online communities (Engage platform), and a foundation that has awarded over US$1.4 million in scholarships to 800+ students since 2022.

ISACA firmographics

Firmographics
Name
ISACA
Legal name
Information System Audit and Control Association, Inc.
Website
https://isaca.org
Company type
Private
Founded year
1969
Operating status
Operating
Headcount range
1–10 employees
Short description
ISACA is a global professional association serving 185,000+ digital trust professionals across 190 countries with certifications (CISA, CISM, CRISC, CDPSE, CGEIT, AAIR), frameworks (COBIT, ITAF, CMMI), and the CMMC credentialing mandate for US defense contractors.
Ownership category
akta.pro rank

ISACA industry classification

Industry
Product category
IT Audit and Cybersecurity Professional Certifications
NAICS
Business Associations (813910), Professional Organizations (81392), Professional Organizations (813920)
SIC
Services-Membership Organizations (8600)
akta.pro primary industry
Finance, Accounting & Risk (CFA/CPA/FRM) Certifications (EDAAANAD)

Keywords

  • IT audit certifications
  • Cybersecurity credentials
  • Enterprise risk management
  • IT governance frameworks
  • Professional membership association

Where ISACA is headquartered

Location

Headquarters

HQ city
Rolling Meadows
HQ country
United States
HQ region
North America

Offices1 record

Markets served

ISACA business model

Business model
GTM type
B2B and B2C
Offering type
Services
Cost components
Personnel, Marketing or Sales, Technology or R&D, Operations, Infrastructure

Revenue model

  1. Professional Certifications: ISACA offers globally recognized certifications including CISA, CISM, CRISC, CDPSE, CGEIT, and newer AI-focused credentials (AAIR, AAIA, AAISM). Revenue generated through exam registration fees, certification maintenance fees, and renewal charges. Certifications require passing exams and ongoing CPE compliance.
  2. Professional Membership: Annual membership dues provide access to member benefits including free CPE opportunities, discounts on training and events, chapter networks, mentorship programs, and resources. Membership is a 12-month term with auto-renewal options.
  3. Training & Conferences: Revenue from in-person training weeks, virtual workshops, conference registrations (North America, Europe, GRC, Virtual), and session recordings. Enterprise team training and customized corporate programs available. Over 24,000 exams taken through ISACA Enterprise Training in 2025.
  4. Educational Resources & Publications: Sale of white papers, the ISACA Journal, books, exam prep materials, and digital learning content. Revenue from online review courses, on-demand CPE training, and session recording packages.
  5. CMMC Credentialing Program: ISACA serves as the official Cybersecurity Assessor and Instructor Certification Organization (CAICO) for the US Department of War's CMMC program, administering credential programs including CMMC Certified Professional, Certified Assessor, Certified Instructor, and Lead CCA designations.

Pricing tiers

ModelBillingPrice
FreemiumPay-as-you-goWebinars for members
FreemiumPay-as-you-goVirtual Summits for members
SubscriptionAnnualProfessional Membership
One time/ perpetual licensePay-as-you-goExam Registration Fees
SubscriptionPay-as-you-goSession Recording Packages

Go-to-market motion1 record

Distribution channels6 records

Marketing channels8 records

ISACA product offering

Product offering

Core offering

ISACA is a global professional association that develops, administers, and sells IT audit, cybersecurity, risk, privacy, and governance certifications (CISA, CISM, CRISC, CDPSE, CGEIT, CCOA, AAIA, AAIR, AAISM, CMMC credentials) along with foundational certificates. It delivers accompanying training (online review courses, virtual workshops, webinars, conferences) and publishes authoritative frameworks (COBIT, ITAF, Digital Trust Ecosystem Framework, CMMI) and assessment tools (CMMI Cybermaturity Platform, AI Impact Assessment Tool) for individuals and enterprises worldwide.

Product overview

ISACA is a global professional association offering a comprehensive portfolio of credentials, training, and frameworks for digital trust professionals. The portfolio includes professional certifications (CISA, CISM, CRISC, CDPSE, CCOA, CGEIT), advanced AI-specific certifications (AAIA, AAIR, AAISM), CMMC-related credentials (CCP, CCA, LCCA, CCI) for defense contractors, and foundational certificates (AI Fundamentals, Cloud Fundamentals, Cybersecurity Fundamentals, COBIT, etc.). These credentials are supported by training delivery through online review courses, virtual workshops, webinars, virtual summits, and conference session recordings. ISACA also provides enterprise solutions including CMMI Performance Solutions, CMMI Cybermaturity Platform, and governance frameworks such as COBIT and the Digital Trust Ecosystem Framework. Recent additions include the Security Debt Index (SDI) model, ITAF 5th edition, and AI governance tools like the AI Impact Assessment Tool. The organization serves over 185,000 members across approximately 190 countries.

Differentiator

Problem solved

Functional benefit

Brands

  • CMMI Institute: A division of ISACA administering the Capability Maturity Model Integration framework, performance improvement solutions, and cybermaturity platform services.

Products and services

  • CISA - Certified Information Systems Auditor Globally recognized certification for information systems audit professionals, validating expertise in auditing, control, monitoring, and assessing information technology and business systems.
  • CISM - Certified Information Security Manager Advanced certification for information security managers covering information security governance, program development and management, and incident response.
  • CRISC - Certified in Risk and Information Systems Control
  • CDPSE - Certified Data Privacy Solutions Engineer
  • CCOA - Certified Cybersecurity Operations Analyst
  • CGEIT - Certified in the Governance of Enterprise IT
  • AAIA - Advanced in AI Audit Advanced certification validating ability to audit AI systems, assess AI-related risks, and provide assurance on AI governance and compliance.
  • AAIR - Advanced in AI Risk Advanced certification equipping IT risk professionals with specialized skills to manage AI-related vulnerabilities and risks across AI risk governance, lifecycle risk management, and risk program management.
  • AAISM - Advanced in AI Security Management Advanced certification focusing on AI security management capabilities and securing AI systems throughout their lifecycle.
  • CCP - CMMC Certified Professional Credential for professionals working within the Cybersecurity Maturity Model Certification ecosystem, demonstrating knowledge of CMMC requirements and implementation.
  • CCA - CMMC Certified Assessor Credential for assessors authorized to evaluate organizations seeking CMMC certification against the U.S. Department of War's cybersecurity requirements.
  • LCCA - Lead CMMC Certified Assessor Designation Advanced designation for lead assessors overseeing CMMC certification assessments of defense contractors.
  • CCI - CMMC Credentialed Instructor Credential for instructors authorized to train and prepare candidates for CMMC certification assessments.
  • COBIT 2019 Foundation Certificate
  • COBIT 2019 Design & Implementation Certificate
  • Cybersecurity Fundamentals Certificate
  • Cloud Fundamentals Certificate
  • AI Fundamentals Certificate
  • Digital Trust Ecosystem Framework Foundation Certificate
  • CMMI Performance Solutions
  • CMMI Cybermaturity Platform
  • Online Review Courses
  • Virtual Workshops
  • ISACA Webinars
  • Virtual Summits
  • Session Recordings
  • ISACA Conferences
  • COBIT Framework
  • ITAF - IT Audit Framework (5th Edition) Professional practices framework for IT audit and assurance, addressing emerging technologies including AI/ML, cloud computing, and business automation with emphasis on digital trust, governance, and AI auditing.
  • Digital Trust Ecosystem Framework
  • CMMI AI Maturity (AIM) Framework Framework for governing AI at scale across organizations, with 157 AI context-specific additions across all 31 CMMI practice areas and two new certification courses focusing on AI concepts, ethics, and appraisal methods.
  • Security Debt Index (SDI) Model Composite scoring model that evaluates organizational security debt across three dimensions: Severity (business impact), Duration (how long debt has remained unresolved), and Velocity (how quickly new issues of the same type appear).
  • AI Impact Assessment Tool
  • Professional Membership

Quantifiable outcome

  • Over 24,000 exams taken through ISACA Enterprise Training in 2025
  • +4 more outcomes

Companies that use ISACA

Customer profile

Named customers6 records

Segments9 records

Ideal customer profiles4 records

ISACA technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

AI capability3 records

Feature5 records

ISACA partnerships and signals

Strategic signal

Partnerships

Ten partnerships are on record, tiered flagship, core and regional.

  • IBM GlobalflagshipStrategic or Co-development Partner · 1 June 2026IBM Global is a sponsor of the 25-member AI Working Group that developed the CMMI AI Maturity (AIM) framework. The framework is set to be unveiled at the Capability Creates 2026 conference in Washington, DC in June, designed to govern AI at scale across organizations.
  • KPMGflagshipStrategic or Co-development Partner · 1 June 2026KPMG is a sponsor of the 25-member AI Working Group that developed the CMMI AI Maturity (AIM) framework. The framework includes 157 AI context-specific additions across all 31 practice areas and two new certification courses focusing on AI concepts, ethics, and appraisal methods.
  • CYBER.ORGcoreStrategic or Co-development Partner · 14 May 2026CYBER.ORG announced expanded collaborations including ISACA to enhance cybersecurity and AI workforce training in the United States. The partnership aims to develop industry-relevant skills among students through certification programs, project-based modules, and nationwide educator networks, aligning education with industry needs.
  • CompTIAcoreStrategic or Co-development Partner · 14 May 2026Partnership with CompTIA as part of CYBER.ORG's expanded industry collaboration to strengthen cybersecurity and AI workforce training across the United States through certification programs and educational modules.
  • IntelcoreStrategic or Co-development Partner · 14 May 2026Intel collaboration as part of CYBER.ORG's expanded industry partnerships to enhance cybersecurity and AI workforce training in the United States, integrating industry expertise into educational programs.
  • DigitalXForceregionalOthers · 28 February 2026Kapil Matta, Middle East Region Lead at DigitalXForce, was elected as President of the ISACA UAE Chapter. DigitalXForce frames this as a milestone reinforcing the company's commitment to advancing governance standards, cybersecurity innovation, and digital trust across the META region.
  • Ohio UniversityregionalOthers · 28 February 2026Three Ohio University students received the ISACA Central Ohio Chapter Cybersecurity Fellowship, providing one-on-one coaching with ISACA professionals, a $500 scholarship, and an officially recognized cyber-related certificate upon completion.
  • The Institute of Internal Auditors (IIA)flagshipStrategic or Co-development Partner · 5 February 2026ISACA and IIA co-host the annual Governance, Risk, and Control (GRC) Conference, providing digital trust professionals access to up to 28 CPE credits. The partnership combines ISACA's technology governance expertise with IIA's internal audit leadership.
  • NasscomcoreStrategic or Co-development Partner · 10 December 2025ISACA and Nasscom signed an MoU to align ISACA certifications with India's National Skill Qualification Framework, integrating them into India's higher education and skilling ecosystem. The initiative aims to enhance digital skills of India's workforce and improve access to globally recognized credentials through platforms like FutureSkills Prime.
  • US Department of War (DoW)flagshipOthers · 1 December 2025ISACA authorized as the exclusive Cybersecurity Assessor and Instructor Certification Organization (CAICO) for the US Department of War's Cybersecurity Maturity Model Certification (CMMC) program. ISACA administers credential programs including CMMC Certified Professional, Certified Assessor, Certified Instructor, and Lead CCA designations. Over 100,000 companies will eventually require Level 2 certification.

Scale indicators10 records

Recent moves7 records

Expansion highlights6 records

ISACA competitors and assessment

Company assessment

Direct peers

  • (ISC)²: (ISC)² is a global non-profit membership association offering cybersecurity certifications (CISSP, CCSP, SSCP) - the closest direct competitor to ISACA in the IT/security professional credentialing space with a similar membership-based, certification-driven business model.
  • SANS Institute (GIAC): SANS Institute and its GIAC certification arm deliver technical cybersecurity training and credentials that directly overlap with ISACA's CISM, CCOA, and cybersecurity fundamentals certificates - competing for the same enterprise security training budgets.
  • CompTIA: CompTIA offers vendor-neutral IT certifications (Security+, CySA+, CASP+) that overlap with ISACA's fundamentals and cybersecurity credentials, and is also a CYBER.ORG partner - making it a direct peer in IT professional certification.
  • EC-Council: EC-Council offers the Certified Ethical Hacker (CEH) and other cybersecurity credentials that compete with ISACA's cybersecurity and security operations certifications in the same enterprise buyer segment.
  • ISACA's IIA (Institute of Internal Auditors): The IIA is a global professional association for internal auditors and ISACA's GRC Conference co-host - directly comparable membership-driven certification body serving overlapping IT audit and governance audiences.

Broad incumbents

  • Project Management Institute (PMI): PMI is a large global professional membership association offering the PMP credential with a similar non-profit, membership-dues, certification-maintenance revenue model - comparable as an industry-vertical peer in the professional association category.
  • AICPA: AICPA is a major US professional membership association for CPAs offering certifications and credentialing programs with a comparable governance, certification, and continuing-education revenue model to ISACA.

Emerging players

  • Cloud Security Alliance (CSA): CSA is an emerging non-profit offering cloud security credentials (CCSK, CCSP co-developed with (ISC)²) that increasingly compete with ISACA's cloud fundamentals and CDPSE credentials in the cloud security governance space.
  • OffSec (Offensive Security): OffSec offers the OSCP and other hands-on security credentials that compete for the technical cybersecurity practitioner's training budget, representing an emerging alternative to ISACA's more governance-focused credentials.

Others

  • NIST (National Institute of Standards and Technology): NIST publishes widely adopted cybersecurity and AI risk frameworks (NIST CSF, AI RMF) that ISACA frameworks like CMMI AIM must interoperate with - making NIST an ecosystem peer whose standards shape ISACA's product roadmap.

Market position

Strengths5 records

Weaknesses4 records

Competitive moat7 records

Key risks5 records

Key highlights7 records

Customer concentration

ISACA social profiles

Digital presence

ISACA financial estimates

Financial estimate

Revenue estimate

Valuation estimate

ISACA leadership team

Management profile

Number of profiles

Profiles8 records

ISACA subsidiaries and ownership

Company hierarchy

Subsidiaries1 record

ISACA funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

ISACA M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about ISACA

What does ISACA do?

ISACA is a global professional association that develops, administers, and sells IT audit, cybersecurity, risk, privacy, and governance certifications (CISA, CISM, CRISC, CDPSE, CGEIT, CCOA, AAIA, AAIR, AAISM, CMMC credentials) along with foundational certificates. It delivers accompanying training (online review courses, virtual workshops, webinars, conferences) and publishes authoritative frameworks (COBIT, ITAF, Digital Trust Ecosystem Framework, CMMI) and assessment tools (CMMI Cybermaturity Platform, AI Impact Assessment Tool) for individuals and enterprises worldwide.

Is ISACA a public or private company?

ISACA is a private company. It is classified as nonprofit foundation owned and is currently operating.

When was ISACA founded?

ISACA was founded in 1969. It employs 1 to 10 people.

Where is ISACA based?

ISACA is headquartered in Rolling Meadows, United States, in the North America region.

How does ISACA make money?

Five revenue lines are on record. Professional Certifications are the primary driver. The others are professional Membership, training & Conferences, educational Resources & Publications and CMMC Credentialing Program.

Who are ISACA's main competitors?

Direct peers on record are (ISC)², SANS Institute (GIAC), CompTIA, EC-Council and ISACA's IIA (Institute of Internal Auditors). Broad incumbents are Project Management Institute (PMI) and AICPA. Emerging players are Cloud Security Alliance (CSA) and OffSec (Offensive Security). NIST (National Institute of Standards and Technology) is listed as an others.

Does ISACA have an API?

No public API is recorded for ISACA.

What industry is ISACA in?

ISACA's product category is IT Audit and Cybersecurity Professional Certifications. Its primary akta.pro industry code is EDAAANAD, Finance, Accounting & Risk (CFA/CPA/FRM) Certifications. Its NAICS code is 813910 and its SIC code is 8600.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
SecuritybriefEuropean cyber teams understaffed as AI threats riseISACA research found European cybersecurity teams understaffed and underfunded, with 56% saying their function lacks people and 55% lacking money. 72% of professionals reported increased job stress, and 71% of organizations have not conducted AI-related incident response exercises.BusinessLineComplex AI threats increasing stress levels of cybersecurity professionalsISACA's survey of over 1,800 cybersecurity professionals found that over 59% of Indian employees report significantly higher stress than five years ago, compared to 68% globally. The report cites AI-driven attacks as the primary stressor, with 42% of India-based teams understaffed and 66% struggling to retain talent.ITPro‘Rising threats and under-resourcing for cybersecurity is taking a toll on the people tasked with managing it’: Cyber teams are being pushed to breaking point – and AI is doing little to alleviate strISACA's survey found 38% of European IT and cyber professionals faced more attacks this year than all of 2025, while 56% remain understaffed and 55% underfunded. AI is helping teams automate threat detection and response, but 72% report increased stress, and 53% consider leaving their jobs.CXOToday.comISACA Survey: AI Adoption Outpaces Preparedness as Only 21% Test Incident ResponseISACA's 2026 survey of 1,800+ cybersecurity professionals found only 21% of Indian organizations conduct AI-specific incident response exercises, while 49% have done none. The report highlights growing AI adoption in security operations but a gap in preparedness, with 35% lacking AI incident playbooks.Punch NewspapersFCMB Gets ISACA Award for Digital ContributionsFCMB received a commemorative plaque from ISACA Lagos Chapter for contributions to technology governance and digital trust. The award was presented at the chapter's 30th anniversary celebration on August 21. FCMB continues to invest in digital capabilities and cybersecurity.Daily TrustFCMB honoured for advancing digital trustFCMB received a commemorative plaque from ISACA Lagos Chapter at its 30th anniversary celebration on August 21. The recognition highlighted FCMB's contributions to technology governance, cybersecurity, risk management, audit, assurance, and digital trust in Nigeria. FCMB's CEO Yemisi Edun said the bank remains committed to investing in digital capabilities and cybersecurity.ForbesCulture Of Quality The Key Ingredient Across Medical Device IndustryChris Dimitriadis of ISACA outlines the critical importance of integrating quality, patient safety, and regulatory compliance into a unified strategy for medical device manufacturers. The article argues that boards of directors must prioritize these operational metrics alongside financial ones to mitigate risks associated with product failures and maintain trust with regulators like the FDA. It emphasizes that a proactive culture of quality serves as a competitive advantage, accelerating innovation and reducing costs related to recalls and audits.EIN PresswireJim West Delivers Two Talks at ISACA GRC 2026 in San DiegoJim West, CEO of TopCyberPro.com, will present two sessions at ISACA GRC 2026 in San Diego, including "The Encryption Endgame: Beating the Quantum Clock." He urges organizations to secure sensitive communications now, build cryptographic inventories, and layer NSA CSfC defenses with Zero Trust. West argues Q-Day is a governance failure if organizations do not act.THISDAYLIVEISACA Lagos Marks 30 Years of Excellence, Impact – THISDAYLIVEThe ISACA Lagos Chapter is commencing a week-long celebration of its 30th anniversary, scheduled to begin on August 20, 2026. The event will feature the presence of global leadership, including Global CEO Erik Prusch and Global CFO Thomas Kyei-Boateng, alongside chapter board members and industry stakeholders. This milestone marks three decades since the chapter's establishment in 1996, highlighting its growth into a community of over 1,000 members focused on technology governance and cybersecurity.FinancialContent Business PageTrainocate Malaysia Expands ISACA Certification Pathway to Support Digital Trust and Cyber ResilienceTrainocate Malaysia has expanded its ISACA certification pathway to include specialized training in cybersecurity, AI governance, and IT risk. This initiative aims to address significant skills gaps identified by Malaysian employers and help organizations strengthen their digital trust and cyber resilience.