Most IT certifications prove you can build, secure, or audit technology. The Certified in the Governance of Enterprise IT (CGEIT)® from ISACA proves something different: that you can help an organization decide which technology to invest in, how to measure whether it paid off, and how much IT risk leadership is willing to accept. It is a credential for people who sit at the table where business strategy and IT meet.
Because CGEIT targets experienced professionals, it’s worth asking whether it fits your career before you register. In this guide, we’ll walk you through who the exam is for, ISACA’s experience requirements, how long to study, the careers and salaries it connects to, how to keep the credential, and what to consider next.
What Is the ISACA CGEIT?
CGEIT recognizes professionals who manage, advise on, or oversee the governance of enterprise IT. Governance is not the same as day-to-day IT management. Management plans, builds, runs, and monitors. Governance evaluates options, sets direction, and monitors results so that IT delivers value, uses resources wisely, and keeps risk within acceptable limits.
The exam is based on the CGEIT Exam Content Outline, effective July 2020. It has four domains:
- Domain 1, Governance of Enterprise IT (40%): Governance frameworks, organizational structures, strategic planning, enterprise and information architecture, policies, and information governance.
- Domain 2, IT Resources (15%): Sourcing strategies, capacity planning, resource acquisition, asset lifecycle management, staff competency, and vendor relationships.
- Domain 3, Benefits Realization (26%): Performance management, governance monitoring and reporting, business cases, IT investment management, and benefit evaluation methods.
- Domain 4, Risk Optimization (19%): Risk frameworks and standards, enterprise risk management, risk appetite and tolerance, and risk assessment methods.
What Is the CGEIT Exam Format?
According to the ISACA Certification Exam Candidate Guide, here is what to expect:
- Questions: 150 multiple-choice questions.
- Time: 4 hours (240 minutes), or about 96 seconds per question.
- Delivery: Computer-based at PSI testing centers worldwide or through remote proctoring.
- Languages: English and Chinese (Simplified).
- Scoring: Scaled from 200 to 800. You need 450 or higher to pass.
- Results: You see a preliminary pass/fail result on screen, and your official score arrives by email within 10 working days.
- Fees: US$575 for ISACA members and US$760 for non-members, plus a one-time US$50 application processing fee when you apply for certification.
Who Should Take the ISACA CGEIT Exam?
CGEIT is a strong fit if a meaningful part of your job involves shaping or overseeing how IT supports the enterprise, whether or not “governance” appears in your title. Consider it if you:
- Lead IT at the senior level, such as a CIO, CTO, IT director, or head of IT strategy, and want to validate your governance and portfolio skills.
- Work in IT governance, risk, and compliance (GRC) and design frameworks, policies, and oversight processes.
- Manage an IT portfolio or project management office (PMO) and build business cases, prioritize initiatives, and track benefits.
- Serve as an enterprise architect who aligns architecture decisions with business strategy.
- Audit or advise on IT as an IT audit director, management consultant, or advisory partner who evaluates governance for clients or boards.
- Already hold CISA, CISM, or CRISC and want a credential focused on enterprise-level direction rather than audit, security, or risk alone.
Who Might Want to Wait?
If you are early in your IT career or your work is mostly hands-on technical delivery, CGEIT may be premature. You can pass the exam without meeting the experience requirement, but you can’t use the designation until ISACA approves your experience. An entry-level or practitioner credential may give you more value now, with CGEIT as a longer-term goal.
What Are the CGEIT Eligibility Requirements?
ISACA separates passing the exam from earning the certification. Per the Earn a CGEIT Certification page, to become certified you must:
- Pass the CGEIT exam.
- Document at least five years of professional work experience in an advisory or oversight role supporting the governance of the IT-related contribution to an enterprise.
- Show breadth across the domains. Your experience must span at least three of the four CGEIT domains, including at least one year in Domain 1, Governance of Enterprise IT.
- Meet the time window. The experience must fall within the 10 years before your application date, and you have five years from passing the exam to apply.
- Pay the US$50 application processing fee and submit your application with supervisor or manager verification of your experience.
- Agree to follow ISACA’s Code of Professional Ethics and Continuing Professional Education (CPE) Policy.
Unlike some ISACA credentials, the CGEIT requirements page does not list education substitutions for experience, so plan on documenting the full five years. Because rules and fees can change, check the official page before you register.
Scheduling and Retake Policies
Once you register, you have a six-month eligibility period to take the exam, with one six-month extension available for a US$75 fee. You can reschedule without penalty if you do it at least 48 hours before your appointment. If you don’t pass, ISACA allows up to four attempts in a rolling 12-month period, with a 30-day wait after the first attempt and 90-day waits after the second and third.
How Long Should You Study for the CGEIT Exam?
Most candidates plan for three to six months of steady study. The right length depends on how closely your job matches the outline.
- Experienced governance leaders who already run steering committees, portfolio reviews, or risk programs may need about three months. Your main task is learning to answer the way ISACA expects, which often means choosing the most strategic, board-level response rather than the most practical technical fix.
- Candidates coming from a single specialty, such as audit, security, or project management, often need four to six months to build comfort with unfamiliar areas like sourcing strategy, investment management, or benefit evaluation.
A Sample Four-Month CGEIT Study Plan
- Month 1, Governance of Enterprise IT: Start with a mixed baseline quiz, then focus on Domain 1. At 40%, it deserves the most time. Learn the difference between governance and management, the components of a governance framework, stakeholder engagement, enterprise and information architecture, and information ownership and classification.
- Month 2, Benefits Realization: Study business case development, investment management across the full economic lifecycle, performance metrics, and benefit evaluation. Be comfortable with concepts like return on investment, net present value, and balanced scorecards.
- Month 3, Risk Optimization and IT Resources: Cover risk appetite versus risk tolerance, how IT risk ties into enterprise risk management, and risk assessment methods. Then study sourcing strategies, capacity planning, asset lifecycle management, competency development, and managing contracted services.
- Month 4, Integration and timed practice: Mix all four domains, review every missed question, and take timed sets so 96 seconds per question feels natural.
Study tip: Many CGEIT questions ask what the governing body or leader should do first or best. The strongest answer usually ties back to enterprise objectives and stakeholder needs, not to a specific tool or technical control.
What Careers Can the CGEIT Support?
CGEIT tends to support senior and advisory roles where you influence IT direction across the enterprise. Common titles include:
- Chief information officer (CIO) or chief technology officer (CTO)
- IT director or vice president of IT
- IT governance manager or GRC manager
- IT portfolio or PMO director
- Enterprise architect
- IT audit director or chief audit executive with a technology focus
- IT advisory or management consultant
You’ll find these roles in financial services, healthcare, government, consulting firms, and any large organization that needs board-level oversight of technology spending. The credential shows employers that you think about IT in terms of value, resources, and risk, which is the language executives and boards use.
What Is the Salary After Passing the CGEIT?
The closest Bureau of Labor Statistics (BLS) occupation to most CGEIT roles is computer and information systems managers. According to the BLS Occupational Outlook Handbook, the median annual pay for this group was $175,140 in May 2025. BLS projects employment to grow 16% from 2025 to 2035, much faster than the average for all occupations, with about 53,500 openings each year.
ISACA’s CGEIT page also cites an average annual salary of US$141K+ for CGEIT holders. Actual pay depends on your role, industry, location, and scope of responsibility, so treat any single figure as a benchmark, not a promise.
How Do You Maintain the CGEIT Certification?
According to ISACA’s CGEIT maintenance requirements, you must:
- Earn CPE hours: At least 20 CPE hours each year and at least 120 hours over each three-year reporting period, in activities that advance your CGEIT-related knowledge.
- Pay the annual maintenance fee: US$45 for ISACA members or US$85 for non-members, due by January 1 each year.
- Keep your records: ISACA audits a sample of holders each year, so save documentation for your CPE activities.
ISACA has announced an updated CPE policy effective January 1, 2027. The 120-hour, three-year total stays the same, but at least 90 hours must align with your certification’s domains, and up to 30 hours can come from broader professional development. If your current cycle runs into 2027, plan your activities with the new split in mind.
What Certifications Stack Well With the CGEIT?
The best next step depends on which part of governance you want to deepen:
- Certified in Risk and Information Systems Control (CRISC)®: A natural pairing with Domain 4 if you want to go deeper into IT risk identification, assessment, response, and control.
- Certified Information Security Manager (CISM)®: A good fit if your governance work increasingly centers on information security programs.
- Certified Information Systems Auditor (CISA)®: Useful if you evaluate governance and controls from an assurance perspective, or if you work closely with internal audit.
- COBIT® 2019 credentials from ISACA: COBIT’s governance objectives (evaluate, direct, and monitor) map closely to CGEIT’s focus on governance frameworks, benefits delivery, risk optimization, and resource optimization.
- Project Management Professional (PMP)® or ITIL® 4 credentials: Helpful if your role blends governance with portfolio delivery or IT service management.
Choose the credential that matches the responsibilities you want next, not simply the longest list of letters.
Start Preparing for the ISACA CGEIT Exam With Pocket Prep
Pocket Prep’s ISACA CGEIT practice questions give you 500 exam-style questions across all four domains, each with a detailed answer explanation so you understand why the best answer is best. Use Weakest Subject quizzes to target the domain that needs the most work, then build exam-day pacing with Timed Quiz sessions. With a clear plan and consistent practice, you can walk into your CGEIT exam confident and ready.