Most candidates need 80 to 120 hours for ISC, spread over 6 to 9 weeks. If you've worked in IT audit, cybersecurity or SOC reporting, a lot of it will feel familiar and you can land near the low end. If you haven't, the vocabulary is the first hurdle. The pass rate climbed from the high 50s in 2024 to the high 60s in 2025, second only to TCP among the three CPA Discipline sections.
Under the 2024 CPA Evolution model, you take the three Core sections (AUD, FAR and REG) and choose exactly one Discipline: ISC, BAR (Business Analysis and Reporting) or TCP (Tax Compliance and Planning). ISC is the technology and controls option, and it sits somewhere between IT audit and accounting. It assumes you understand basic financial-reporting risk, then asks you to reason about the systems, data flows and controls behind that reporting: IT general controls, application controls, information security, data management and governance, and how System and Organization Controls (SOC) engagements work.
The section is 4 hours of multiple-choice questions (MCQs) and task-based simulations (TBSs). MCQs count for 60% of your score and TBSs for 40%, which makes ISC the only CPA section that isn't split 50/50. There's no written communication task.
The three blueprint areas
| Area | Weight | What's in it |
|---|---|---|
| I. Information Systems and Data Management | 35 to 45% | System availability, change management, the system development life cycle, data governance and the data lifecycle, how transactions flow through business processes, IT general and application controls |
| II. Security, Confidentiality and Privacy | 35 to 45% | Threats and attacks, logical and physical access controls, encryption, network security, incident response, privacy versus confidentiality |
| III. Considerations for System and Organization Controls (SOC) Engagements | 15 to 25% | SOC 1 versus SOC 2 versus SOC 3, Type 1 versus Type 2 reports, the Trust Services Criteria, complementary user entity controls, how user organizations and their auditors use the reports |
SOC feels like the signature ISC topic, so people over-study it. The two larger areas make up most of the exam, and I wouldn't let SOC crowd security and data management out of your schedule. Treat the ranges as a guide, since your form can lean either way.
An 80 to 120 hour schedule
If you're working full time, 12 to 15 hours a week gets you there. Spread over 6 to 9 weeks, I'd do it in this order:
- Weeks 1 to 2: Area I. Read the material once, then start MCQs right away rather than waiting until you feel ready.
- Weeks 3 to 4: Area II. Security has a lot of discrete definitions, so this is where flashcards help most.
- Week 5: Area III (SOC). It's smaller, but the report types are easy to mix up. Build a one-page table comparing SOC 1, 2 and 3 and Type 1 and 2, and keep refining it.
- Weeks 6 to 7: task-based simulations across all three areas, plus review of your weak MCQ topics.
- Final week: two timed mixed sets under exam conditions, then light review. Don't start new material in the last 48 hours.
Steady weekly hours work better than marathon weekends, because the concepts build on each other and a two-week gap costs you more than it looks like on the calendar.
How to practice
ISC tests recognition and reasoning more than calculation. The fastest way to learn the vocabulary is to see it used in questions and answer explanations, so do MCQs early and often. I'd aim for several hundred across your study period and keep track of which sub-topics you miss.
Build comparison tables from memory for the pairs the exam likes to separate: SOC 1 versus SOC 2, Type 1 versus Type 2, preventive versus detective versus corrective controls, confidentiality versus privacy. Confidentiality and privacy are separate Trust Services categories with different meanings, so get that distinction down before exam day. Knowing that SOC 2 covers the Trust Services Criteria isn't enough on its own. You need to know who requests each report, what a user auditor does with it, and what complementary user entity controls mean in a scenario, because simulations often come down to picking the right report or control category.
ISC simulations often give you an exhibit (a policy, a report excerpt, a system description) and ask you to match, classify or evaluate. Practice them under time pressure so you learn to read an exhibit once instead of three times. If you study mostly with MCQs, you'll be slow on simulations, and since TBSs carry 40% of the score, that costs a lot. Also watch the process context. Questions often put a control inside a transaction flow and ask you where in the process it operates.
You can work all three areas for free in FreeFellow's CPA ISC question bank, which has 1,037 original practice questions with step-by-step solutions and 13 written lessons, free with an account. Mixed practice is free. Practicing one topic at a time, analytics by topic, task-based simulations and timed mock exams are part of Fellow.