SecuritySeptember 2, 20267 min read

CGEIT Syllabus 2026: Four Domains and a Five-Year Gate

One domain is 40% of the paper. But the number that stops most people is not on the syllabus at all: five years of governance experience, with no education waiver.

  • 150Questions
  • 4 hoursTime
  • 4Sections
  • YesWeights published
  • 450/800Pass mark
  • $575Fee
Certified in the Governance of Enterprise IT (CGEIT) exam syllabus sections and weightings

The whole paper in one bar

The CGEIT exam content outline, effective 2020 is the exam guide ISACA publishes for Certified in the Governance of Enterprise IT (CGEIT), restated so you can see the shape of the paper before you read a word of the detail. The bar below is the entire syllabus: 4 sections, in the order the certifying body lists them.

40%
15%
26%
19%
  • §1 Governance of Enterprise IT — 40%
  • §2 IT Resources — 15%
  • §3 Benefits Realization — 26%
  • §4 Risk Optimization — 19%

Those percentages are ISACA’s own, not an estimate. That matters more than it sounds: most pages ranking for this query quote weightings the vendor never published.

The syllabus, section by section

Each block below is one section of the official outline. The bullets are the sub-objectives ISACA publishes underneath it — the actual scope statement, not a summary of it.

Governance of Enterprise IT

40%~60 questions
  • Governance framework components, structures, roles and responsibilities
  • Strategy development, legal and regulatory compliance
  • Organisational culture and business ethics
  • Governance strategy alignment with enterprise objectives
  • Stakeholder analysis, communication and awareness strategy
  • Enterprise architecture, policies and standards
  • Information architecture, asset lifecycle, ownership and stewardship
  • Information classification and handling

IT Resources

15%~22 questions
  • Sourcing strategies
  • Resource capacity planning
  • Acquisition of resources
  • IT resource lifecycle and asset management
  • Human resource competency assessment and development
  • Management of contracted services and relationships

Benefits Realization

26%~39 questions
  • Performance management and governance monitoring
  • Change management and governance reporting
  • Quality assurance, process development and improvement
  • Business case development and evaluation
  • IT investment management and reporting
  • Performance metrics and benefit evaluation methods

Risk Optimization

19%~28 questions
  • Risk frameworks and standards
  • Enterprise risk management
  • Risk appetite and risk tolerance
  • IT-enabled capabilities, processes and services
  • Business risk, exposures and threats
  • Risk management lifecycle and assessment methods
Worth knowing

The syllabus is the easy part of CGEIT. Certification also requires five years of experience in an advisory or oversight role supporting the governance of IT, spanning at least three of these four domains, including at least one year in Domain 1 - all of it earned within the previous ten years. ISACA publishes no education waiver or substitution for CGEIT, unlike CISA. You may sit the exam before you qualify, and you then have five years from passing to submit the application before the result lapses.

What the weightings really mean

A percentage in an exam guide is a promise about how many questions get drawn from a section, not about how hard those questions are. On a paper of roughly 150 items, Governance of Enterprise IT at 40% is worth about 60 questions and IT Resources at 15% is worth about 22. Missing the whole of the smallest section still leaves you a pass on paper; missing the largest one does not.

The trap is treating that arithmetic as permission to skip. Weightings are the floor of what a section costs you, because the low-weight sections on almost every blueprint are the ones that supply context for questions filed under a different heading. You lose those marks in the heavy section and never find out why.

Reading the verbs in the objectives

The verb at the front of each sub-objective is the part candidates skim and examiners take literally. It sets the depth you are tested at, and it is the difference between recognising a service name and being asked to choose between two that both look right.

VerbWhat a question at that depth looks like
Evaluate / AssessThe governance verb. You are given a scenario and asked which action a governance body should take, and the wrong answers are usually competent management actions taken at the wrong level.
Establish / DefineFrameworks, policies, risk appetite, architecture. Answers turn on who owns the decision, not on which technique is best.
Monitor / ReportDomain 3 territory. Performance metrics, benefit evaluation, governance reporting. Expect questions about what the board should see, not what the team should measure.

CGEIT is written from the perspective of someone overseeing IT rather than running it. That framing decides more questions than any single topic: the technically strongest answer is frequently the wrong one because it is a management action in a governance question.

Study it in this order, not the syllabus order

Exam guides are written to describe a job role, not to teach one. The published order is almost never the order that builds knowledge fastest. This is the sequence that front-loads the material everything else depends on.

OrderWhy here
1. Governance of Enterprise IT40% of the paper, and the domain the experience rule also singles out. Frameworks, structures, strategy, architecture and information governance.
2. Benefits Realization26%. Business cases, investment management, performance metrics and benefit evaluation. Learn it second because it applies the framework thinking from Domain 1.
3. Risk Optimization19%. Risk frameworks, appetite and tolerance, the risk management lifecycle. Compact and heavily definitional.
4. IT Resources15% and smallest. Sourcing, capacity, asset lifecycle, contracted services. Quick, and safe to leave last.
Sequencing note

Domain 1 and Domain 3 are two-thirds of the exam between them. That is also the natural learning order, which is unusual - on most blueprints the published sequence and the efficient sequence disagree. Here they broadly line up.

What changed, and how to spot the next change

Nothing has changed, and that is itself the news. The content outline is still the one marked effective 2020, making it the longest-running unrevised ISACA job practice - CISA moved in August 2024, CRISC and CDPSE in 2025, and CISM's outline updates on 3 November 2026. No CGEIT revision or retirement has been announced. Do not let a headline about the CISM update convince you your CGEIT material is stale; a refresh is plausible after six years, but it is not scheduled. What does move is cost: budget the exam fee plus the US$50 application processing fee plus the first annual maintenance fee, and plan for 20 CPE hours a year and 120 across each three-year cycle once you hold it.

Two habits keep you from studying a retired outline. First, open the official exam guide and look for its revision date before you buy anything — courses and question banks lag a syllabus change by months, and the cheapest ones never catch up. Second, re-check it the week you book. A revision announced after you started studying is still a revision you sit.

Turn the syllabus into questions

Reading an outline tells you the shape of the paper. Answering questions tells you which sections you would actually lose marks on. Start free, then $5.99 unlocks the full CGEIT bank.

Free practice testCGEIT exam page

FAQ

What are the CGEIT domains and their weightings?

Four: Governance of Enterprise IT 40%, IT Resources 15%, Benefits Realization 26% and Risk Optimization 19%. Those are ISACA's published figures from the exam content outline effective 2020, which is still current.

What is the passing score for CGEIT?

450 on a scaled score running from 200 to 800. It is not a percentage and does not convert to one - the raw-to-scaled conversion varies by exam form, so the widely repeated claim that 450 equals 56% correct is wrong. Domain-level results are reported for information only and are not used to calculate your score.

Do I need five years of experience to sit the CGEIT exam?

Not to sit it - anyone can take the exam. You need five years of IT governance advisory or oversight experience across at least three of the four domains, including one year in Domain 1, to be awarded the certification, and all of it must fall within the previous ten years. ISACA publishes no education waiver for CGEIT.

How much does CGEIT cost in total?

The exam is US$575 for ISACA members and US$760 for non-members, plus a one-off US$50 application processing fee once you pass, plus the annual maintenance fee of US$45 for members or US$85 for non-members. Pages quoting only the exam fee understate the real cost.

Sources

Every section title, sub-objective and number on this page comes from the certifying body:

Checked September 2, 2026. Exam guides are revised without notice — confirm against ISACA before you build a study plan around this page.