The CPA Exam is composed of three Core Exam sections and one Discipline Exam, chosen from three options. The Information Systems and Controls (ISC) section is one of these three Disciplines, testing candidates on IT audit, data governance, cybersecurity, and System and Organization Controls (SOC) engagements. Understand the complete structure and content of ISC, plus tips to help you get Exam Day ReadySM, to help you succeed on ISC exam day!
Summary
The ISC CPA Exam tests information systems and data management, security and privacy, and SOC engagements—content that builds on the auditing fundamentals covered in the AUD Core section. Candidates have four hours to complete 82 multiple-choice questions (MCQs) and 6 task-based simulations (TBSs) across three content areas: Information Systems and Data Management (35–45%), Security, Confidentiality, and Privacy (35–45%), and SOC Engagement Considerations (15–25%).
Table of Contents
- What Is the ISC CPA Exam?
- ISC vs AUD: What's the Difference?
- ISC CPA Exam Format
- What's Tested on the ISC CPA Exam?
- How Is ISC Scored?
- Is the ISC CPA Exam Hard?
- 5 Tips to Pass the ISC CPA Exam
- Is ISC the Right Discipline for Me?
- ISC CPA Exam FAQs
What Is the ISC CPA Exam?
The CPA Exam consists of four separate sections that assess a CPA candidate's knowledge and skills in complex accounting topics. Passing all four sections is required to earn the Certified Public Accountant (CPA) license.
While every candidate must pass the three Core Exam sections, candidates only choose one of three Discipline sections, which go deeper into the topics covered on one corresponding Core section. ISC is one of the three Discipline options, building upon content covered in the AUD Core section.
CPA Exam Core Sections (Candidates must pass all three):
CPA Exam Discipline Sections (Candidates choose one):
- Business Analysis & Reporting (BAR)
- Information Systems & Controls (ISC)
- Tax Compliance & Planning (TCP)
The Information Systems and Controls (ISC) section tests candidates' knowledge of IT audit and advisory, data governance, cybersecurity, and SOC engagements. It's a natural fit for candidates aiming toward IT audit, data management, cybersecurity advisory, or systems consulting roles.
ISC vs AUD: What's the Difference?
The AICPA created ISC as an extension of AUD, testing the technology-focused skills that a general auditing engagement only touches on briefly. For candidates aiming to specialize in IT audit, data governance, or cybersecurity advisory, ISC offers a chance to demonstrate that deeper expertise.
ISC was built from scratch when CPA Evolution launched in 2024 and the old Business Environment and Concepts (BEC) section was retired. Some ISC content is inherited directly from BEC's former IT coverage; some comes from topics that used to live inside AUD (like SOC reporting); and a substantial portion was brand-new material created at that time to reflect how quickly technology has reshaped the accounting profession. Topics candidates will find on ISC that either didn't exist on the pre-2024 exam or lived elsewhere include:
- IT governance frameworks (COBIT) and the systems development life cycle (SDLC)
- Cloud computing models (IaaS, PaaS, SaaS) and virtualization
- Cybersecurity frameworks, including the NIST Cybersecurity Framework
- Encryption, cryptography, and network security controls
- Data governance, data lifecycle management, and data analytics
- SOC 1, SOC 2, and SOC 3 engagement types and the Trust Services Criteria
Because ISC's content goes deep into concepts, some of which are not on the AUD Exam at all, even candidates with a strong AUD foundation shouldn't assume that background alone will carry them through the exam.
ISC CPA Exam Format
The ISC CPA Exam is a four-hour exam made up of 82 multiple-choice questions (MCQs) and 6 task-based simulations (TBSs)—the highest MCQ count of any CPA Exam section. The MCQs and TBSs are broken down across five "testlets," so the format when you sit for the exam looks like this:
- Pre-exam: Complete the welcome screen to confirm your information and enter your "launch" code, then your confidentiality code. You'll have five minutes for each screen.
- Testlet 1: 41 MCQs
- Testlet 2: 41 MCQs
- Testlet 3: 1 TBS
- 15-minute break that does not count toward your exam time
- Testlet 4: 3 TBSs
- Testlet 5: 2 TBSs ISC
Content Areas
- Information Systems and Data Management: 35–45%
- Security, Confidentiality, and Privacy: 35–45%
- Considerations for SOC Engagements: 15–20%
Skill Levels
The CPA Exam uses Bloom's Taxonomy of Educational Objectives to define the skillsets candidates must demonstrate. While there are four skill levels in total, only the first three are tested on ISC:
- Remembering and Understanding (55–65%): Recalling facts and demonstrating comprehension of concepts, standards, and procedures
- Application (20–30%): Applying concepts and best practices to realistic scenarios across all three content areas
- Analysis (10–20%): Interpreting real-life scenarios to identify errors, propose solutions, and draw conclusions from the data provided
Notice that ISC skews far more heavily toward Remembering and Understanding than any other CPA Exam section, which means vocabulary and conceptual recall carry more weight here than they do on BAR or TCP.
What's Tested on the ISC CPA Exam?
ISC includes information systems and data management; IT security, confidentiality, and privacy; and SOC engagement considerations. Here's a closer look at what falls into each content area.
Content Area I: Information Systems and Data Management
- IT infrastructure, including networks, cloud computing models, and virtualization
- Enterprise and accounting information systems
- System availability and change management
- The systems development life cycle (SDLC)
- Data governance, the data lifecycle, and data analytics
- IT general controls and application controls
Content Area II: Security, Confidentiality, and Privacy
- Regulations, standards, and cybersecurity frameworks, including NIST and COBIT
- Threats and attacks, including common attack vectors
- Mitigation techniques, encryption, and network security controls
- Testing methods for security controls
- Confidentiality and privacy distinctions
- Incident response procedures
Content Area III: Considerations for SOC Engagements
- Considerations specific to planning and performing an SOC engagement
- SOC 1 vs. SOC 2 vs. SOC 3 report types and their intended users
- Type 1 vs. Type 2 reports
- The Trust Services Criteria
- Complementary user entity controls
- Considerations specific to reporting on an SOC engagement
How Is ISC Scored?
The ISC CPA Exam is graded on a scale from 0 to 99, and you must score a 75 or above to pass. ISC is unique among CPA Exam sections in how it weights question types: MCQs make up 60% of your score, while TBSs make up the other 40%. Every other CPA Exam section splits scoring evenly at 50/50, which means strong MCQ performance matters more on ISC than anywhere else.
While the AICPA does not grade on a curve, questions are weighted by difficulty, so harder questions count for more than easier ones. You can also earn partial credit on TBSs, since each scenario asks multiple questions. Once your exam is graded and weighted, your score is aggregated onto the 0–99 scale.
Is the ISC CPA Exam Hard?
When compared with the overall CPA Exam pass rate of just 51%, ISC shows a higher success rate. The cumulative 2024/2025 ISC CPA pass rate was 64% for all candidates. And while this may not seem very high, it is significantly higher than that of some other sections (BAR is just 39%, for example). Likewise, Becker's Exam Day ReadySM students achieved an 41% higher pass rate on the ISC exam than all other test takers over that same period.
That doesn't mean ISC is easy, though. It's the most unfamiliar Discipline for most accounting-trained candidates, since much of its content comes from IT and cybersecurity rather than traditional accounting coursework.
The Hardest Parts of the ISC Exam
Candidates most often report struggling with:
- SOC 1 vs. SOC 2 vs. SOC 3 distinctions and matching report types to the right use case
- The Trust Services Criteria and complementary user entity controls
- Cybersecurity frameworks like NIST and COBIT
- Encryption, cryptography, and network security terminology
- Distinguishing IT general controls from application controls
- Data governance and data lifecycle concepts
Because so much of this vocabulary is new even to experienced accountants, building in dedicated repetition for these terms—rather than assuming they'll stick after one pass—is one of the best ways to prepare before exam day.
5 Tips to Pass the ISC CPA Exam
Now that you know what's tested and how it's scored, here's how to prepare with confidence.
#1: Treat ISC like a new vocabulary, not a memory refresh.
Unlike BAR or TCP, ISC doesn't build heavily on content you've already studied. Go in expecting to learn a genuinely new set of frameworks and terms and give yourself the study time you need to learn this vocabulary profoundly.
#2: Prioritize your MCQ strategy.
Because MCQs count for 60% of your ISC score—more than any other section—it's worth spending extra practice time here specifically. Strong MCQ performance can meaningfully offset a rougher TBS testlet in a way that it can't on other sections.
#3: Learn SOC engagements by comparison, not in isolation.
SOC 1, SOC 2, and SOC 3 reports are easy to mix up if you study them one at a time. Build yourself a comparison chart of report types, Type 1 vs. Type 2, and their intended users, and quiz yourself on the differences rather than the definitions alone.
#4: Connect every topic back to a control question.
ISC can feel like an abstract list of frameworks and acronyms if you study it that way. Instead, ask yourself for each topic: what could go wrong here, what control would catch it, and what evidence would prove the control worked? That framing mirrors how the exam actually tests the material.
Becker's CPA Exam Review offers a full set of ISC-specific study and practice materials to help you build these skills, including:
- Video instruction covering every topic on the exam
- MCQ and TBS practice questions
- Unlimited, personalized practice tests that use adaptive learning to focus on your weak areas
- Unlimited use of NewtTM AI to offer instant answers, explanations of why you went wrong, additional examples, and more in all major course learning areas
- Simulated exams that mirror the actual CPA Exam in length, format, and style
- Livestreaming courses from expert CPA instructors
- 1:1 tutoring sessions
#5: Don't skip SOC just because it's the smallest content area.
At 15–20% of your score, Area III is smaller than the other two. But it's also one of the most specific and testable, since there's a limited, well-defined set of facts that you simply know or you don’t. Do not let it fall to the bottom of your study plan just because the percentage looks small.
Is ISC the Right Discipline for Me?
Choosing your CPA Exam Discipline is an important decision that can shape your career trajectory, job opportunities, and future areas of specialization.
If you're interested in how information technology, cybersecurity, and data governance intersect with accounting and finance, ISC may be the right Discipline for you. Passing this section demonstrates skills related to:
- Business processes and information systems
- Information security and privacy
- IT audits
- SOC engagements
With this proven knowledge and expertise, job opportunities include:
- IT auditor
- Financial data manager or analyst
- Cybersecurity advisory roles within public accounting
- Chief Information Officer (CIO) or Chief Technology Officer (CTO) career tracks
It's important to note that which Discipline section you take is not reflected on your CPA license, giving you the flexibility to switch focus or pursue other specializations later. You can take ISC with the intention to work in IT audit or data governance, but later decide to pursue career opportunities in a different field that more closely aligns with other newly discovered interests. However, if you already know your future goals, you can start aligning your training now to set the foundation for your career growth.
Take our 4-question quiz to find which Discipline is right for you!
Pass the ISC CPA Exam with Becker
Our CPA Exam Review includes everything you need to get Exam Day ReadySM—from livestreaming classes and lecture videos to adaptive learning-based practice tests, 1:1 tutoring sessions, and a mobile app so you can study on the go. Start with a free trial of Becker's CPA Exam Review and explore course resources including:
- Comprehensive ISC content aligned with the latest AICPA Blueprints
- Thousands of practice questions and simulations
- SkillBuilder video explanations
- Personalized study plans
- Adaptive learning technology (Adapt2U)
- Simulated exams that mirror the actual CPA Exam experience
- Expert instructor support and exam-day strategies
- 1:1 tutoring
- Newt AI study tool
Start your free trial of our leading CPA Exam Review and see how we've helped nearly 2 million students pass their exams!
ISC CPA Exam FAQs
Is ISC the easiest CPA Exam Discipline?
ISC consistently posts a higher pass rate than that of the overall CPA Exam. That said, it's also the least familiar content for most accounting-trained candidates, since much of it comes from IT and cybersecurity rather than traditional coursework. In this sense, a higher pass rate doesn't mean that it requires less preparation.
Do I have to take the ISC CPA Exam?
No. ISC is one of three Discipline options, along with BAR and TCP. All candidates must pass the three Core sections (AUD, FAR, REG), but you only need to pass one Discipline of your choice to become licensed.
How many questions are on the ISC CPA Exam?
The ISC CPA Exam consists of 82 multiple-choice questions (MCQs) and 6 task-based simulations (TBSs)—the highest MCQ count of any CPA Exam section.
How long is the ISC CPA Exam?
Candidates have four hours to complete the ISC CPA Exam.
What score do I need to pass ISC?
Like every CPA Exam section, ISC is scored on a scale of 0 to 99. You must earn a 75 or higher to pass.
How long should I study for the ISC CPA Exam?
Becker recommends at least 60–90 total study hours for ISC. If you study 10–15 hours per week, plan to begin preparing roughly one to two months before your test date. Candidates without an IT or cybersecurity background may want to budget extra time upfront, since much of the vocabulary will be unfamiliar.
What's the difference between ISC and AUD?
AUD Core section tests foundational auditing and attestation concepts required of every CPA candidate, while ISC (a Discipline you choose) goes deeper into the technology-focused topics AUD only touches on—like SOC engagements—plus substantial new material in cybersecurity, data governance, and IT systems.
Why does ISC weight MCQs and TBSs differently than other sections?
ISC is the only CPA Exam section where MCQs (60%) and TBSs (40%) aren't weighted evenly. Because ISC content leans heavily on Remembering and Understanding-level skills, the AICPA's blueprint reflects that with a heavier MCQ weighting than BAR, TCP, or the Core sections.
When should I take the ISC CPA Exam?
If you've decided on ISC as your Discipline, the next step is figuring out the best order to take the CPA Exam. Since ISC builds on AUD, many candidates take AUD first to build a foundation, then move into ISC while those concepts are still fresh. Common sequencing options include FAR → AUD → ISC → REG, or REG → AUD → ISC → FAR.
Do I need supplemental materials to pass ISC if I'm using Becker?
No. Becker's ISC CPA Exam Review course is designed to be a complete CPA Exam preparation solution, including comprehensive content coverage, practice questions, simulations, final review materials, and personalized study tools.
What should I do if I'm struggling with ISC concepts?
If you're finding ISC's terminology difficult, you're not alone. It's the most unfamiliar Discipline for most candidates. Rewatch lectures, review explanations for missed questions, and build comparison charts for concepts that are easy to confuse, like SOC report types. Becker's Adapt2U technology and Newt AI study tool can help identify and target your specific gaps. You can also explore resources like 1:1 tutoring and LiveOnline classes, which provide real-time feedback and additional concept explanation.
Which careers benefit most from choosing the ISC Discipline?
ISC is a strong fit for candidates pursuing IT audit, cybersecurity advisory, data governance, or systems consulting roles, since the exam mirrors the technical and control-focused thinking that those careers require day to day.