Skip to main content

Certification Decision Tool

Is this certification relevant to your route?

Five answers, one call. Everything below is composed from records TechWaymark already holds: the vendor page someone read, TechWaymark's certification intelligence, the public market verdict and the recorded ruling for your target role. There is no score and no ranking.

Free, no account, and nothing you choose here leaves your browser.

Certified Information Systems Auditor (CISA) for SOC Analyst

Relevant later

Certified Information Systems Auditor (CISA) has a place on this route, but not as the next thing you sit.

  • TechWaymark has no explicit ruling for this pairing. The Atlas places both in the security domain, so the link is inferred rather than recorded.
  • By study effort this is a professional level exam and you are earlier than the stage it is usually sat at. That is a sequencing observation, not an entry requirement: effort bands say how much ground the syllabus covers, not who is allowed to book.
  • On recruiter recognition this one does the job it is being asked to do.

This is a read on relevance, not a prediction. Nothing here is a guarantee of an interview, an offer or a salary.

Tier-one audit firms run formal CISA pipelines and reimburse the exam. Second-line technology audit teams inside FCA-regulated firms screen for it directly. The signal is narrow but heavily weighted where it applies. The Big-Four-pipeline pattern keeps the credential heavily employer-funded inside assurance practices.

  • Signal strength: High
  • TechWaymark's market call: Strong

ISACA's audit cert. The credential of choice for internal/external IT audit and audit-adjacent GRC. Hands-on depth is recorded as low.

By study effort this is a professional level exam and you are earlier than the stage it is usually sat at. That is a sequencing observation, not an entry requirement: effort bands say how much ground the syllabus covers, not who is allowed to book.

  • IT auditors inside Big Four assurance practices working FCA-regulated financial services or regulated utilities engagements
  • Second-line technology audit professionals in PRA-supervised banks, insurers and building societies where audit committee reporting is the core deliverable
  • Internal audit functions in central government, NHS arms-length bodies and large local authorities subject to NAO scrutiny

Nothing here is a hard gate unless the vendor page says so. Recommended experience is the vendor's guidance about comfort with the syllabus, not permission to sit the exam.

  • Recorded prerequisite: Audit or IT experience
  • Vendor recommended experience, not a bar to booking: ISACA requires the CISA exam to have been passed within the last five years, plus five or more years of professional information systems auditing, control or security work experience, followed by a certification application.

TechWaymark has no explicit ruling for this pairing. The Atlas places both in the security domain, so the link is inferred rather than recorded. Easiest cyber entry. Saturated by bootcamps, but real shifts thin the field fast.

  • Recorded ruling for SOC Analyst: optional
  • Basis: inferred from the Atlas domain

A certification changes what a filter does with your name. It does not change what you can show a panel.

  • Engineering or pentest roles
  • A risk credential. CRISC is the ISACA risk and control track. CISA is audit execution and IS assurance, not control design
  • A technical security signal. The exam tests audit methodology and process, not detection engineering, cloud security or vulnerability management
  • No paid experience yet. The exam will not stand in for the first role.

Roughly 200 hours of part-time study for a professional level exam, plus £455 member / £600 non-member in exam outlay. That is the same block of time as a small piece of work you could show instead, so the comparison is worth making honestly.

  • Typical study window: 3–4 months
  • Validity: 3 years

Only certifications TechWaymark has already ruled useful for this target appear here.

Most recent vendor review recorded: 2026-09.

  • Certified Information Systems Auditor (CISA). Live with ISACA. As with CISM, the exam is only the first step: the application and verified experience decide whether you hold the certification.

  • Signal, hands-on depth, prerequisites and what the exam does not unlock.

  • Market-level call "Strong", confidence High. ISACA's audit track has been the named requirement in IS audit JDs for two decades. PRA-supervised banks, Big Four assurance and NAO-adjacent work all list it explicitly. Recruiter behaviour is stable, not seasonal.

  • No recorded ruling. Relevance inferred from the Atlas domain and labelled as inferred.

  • Vendor pricing moves by region and promotion. Figures are indicative, not quotes.

No Route Brief is saved in this browser yet. A brief puts this certification in sequence with everything else the move needs.

Plot a route

Read the full page on Certified Information Systems Auditor (CISA), or compare two exams side by side at cert compare.