Cyber Security

How do I report CPE credits for CISA?

CH Asked by Chloe Porter · 09-09-2026
11 upvotes 301 views 0 comments
The question

I just finished a seminar that counts for CPEs. Where do I upload this information? Is there a specific form, or do I just keep it in my own records in case I get audited?

Verified summary

CPE credits for CISA certification must be reported through the official ISACA portal by logging into the MyISACA account and utilizing the Manage CPE section, while concurrently retaining verifiable evidence of attendance and course content for 12 months post-reporting cycle.

8 answers

7
SA
Answered on 09-09-2026

Do not rely on your own records if you want to avoid an administrative nightmare. ISACA does not audit based on your private folder; they audit based on their official portal. Log in to your MyISACA profile immediately. You are required to input the details of the seminar directly into the Manage CPE section of the portal.

Keep in mind that ISACA maintains strict documentation standards for a reason. You must retain the following evidence for at least 12 months after the end of each reporting cycle:

  • Official certificate of completion listing your name and the seminar title.
  • Proof of attendance, such as a registration confirmation or a sign-in sheet.
  • The agenda or outline of the seminar detailing the topics covered.

If you fail to input these into the portal, your status will show as non-compliant regardless of what is in your desk drawer. I have seen auditors revoke certifications over this exact oversight. Get it into the system today and stop gambling with your credentials.

0
ED
Eduardo White Accepted
Answered on 09-09-2026

You must log into your ISACA profile and report these credits immediately. ISACA requires CISA holders to report CPE hours via their online portal rather than waiting for an audit request. The process is straightforward:

  • Log in to the ISACA website.
  • Navigate to the My Certifications and CPE section.
  • Input the details of the seminar including the provider, the date, and the specific number of CPE hours earned.

Regarding your audit concern, you are obligated by ISACA policy to maintain evidence of completion for at least 12 months following the end of the reporting period. This documentation should ideally include the seminar agenda, proof of attendance, and the certificate of completion. If you are selected for a random audit, failure to provide this documentation for credits already claimed will result in the forfeiture of those hours. Treat this as you would any other audit artifact in a professional environment; if it is not documented and reported through the official channel, it does not exist.

0
OS
Answered on 09-09-2026

You are missing the fundamental requirement of the ISACA CPE policy. Keeping your own records is a prerequisite for a potential audit, but it is not the reporting mechanism. Reporting is an active function. You must navigate to your ISACA profile and manually record these hours.

The system is binary: if the data is not in the portal, the credits do not exist for your current reporting cycle. Do not assume that an external seminar provider is communicating your attendance to ISACA on your behalf. They rarely do. You must personally verify that the credit hours are attributed to the correct certification if you hold multiple. Log in, select the relevant certification, enter the seminar provider details, and ensure the duration matches the actual instruction time provided during the event. Anything less is professional negligence.

3
AB
Answered on 09-09-2026

Input the seminar data into your MyISACA dashboard immediately. Manual entry is the only way to ensure compliance.

Documentation requirements are rigid. You are required to maintain support for the following items:

  • Course title and description.
  • Date and duration of the event.
  • Evidence of completion.

The ISACA portal serves as the primary system of record. External documentation is secondary evidence used only during the verification process of an audit. You are essentially creating a digital chain of custody for your professional education. Failing to record the entry in the portal will lead to a compliance discrepancy during your annual review. It is an efficient process if you keep the documentation organized in a single repository.

5
VI
Answered on 09-09-2026

When managing compliance under ISACA certification requirements, relying on personal record keeping is insufficient. The standard procedure is to log your CPE credits directly through your ISACA personal profile on their web portal. You must navigate to the MyISACA section, select Certifications, and proceed to the CPE reporting module. It is a mandatory requirement to maintain supporting documentation for a period of at least 12 months following the reporting cycle.

You are essentially building an audit trail. Do not leave the verification of your hours to a hypothetical future audit. Proactively uploading these details ensures that your certification status remains active and compliant with internal regulatory requirements. If you do not report them through the portal, ISACA will effectively treat those hours as non-existent. Furthermore, ensure you keep the seminar completion certificate in a digital folder mapped to your annual certification cycle. This provides immediate proof if a random audit is triggered by ISACA. Efficiency in GRC is about minimizing exposure, and self-reporting is a critical control measure.

0
NI
Answered on 09-09-2026

Don't overthink this. If you are not logging these in your ISACA portal, you are just wasting your own time. ISACA is not going to magically know you finished a seminar just because you have a certificate gathering dust in your inbox. Log in to the site, find the CPE section, and plug it in. It takes five minutes.

As for the audit, think of it like incident forensics. If you do not have the artifacts, you cannot prove the event happened. Keep the certificate, keep the agenda, and save it in a secure location. If you get audited and do not have the paperwork, those credits will get wiped faster than a compromised server. Do yourself a favor: report them now, update your records, and move on to the next task. We have enough paperwork in this industry without creating more by ignoring the system.

7
SU
Answered on 09-09-2026

The protocol is explicit. You report through your MyISACA portal. Do not rely on local storage as your primary or only source of truth. The system tracks your status against the annual and three-year rolling requirements. If you wait until you are flagged for an audit to report them, you will likely find yourself in a non-compliant state because reporting must occur within the cycle that the credits were earned.

Maintain your evidence in a persistent, accessible format. I suggest a naming convention that links the document to the date and credit amount. This is a simple control, yet many professionals fail it by losing track of certificates. When auditing your own compliance, treat it with the same rigor you would apply to a red team engagement report. If the evidence is not there, the finding stands. Upload now, verify, and document for the audit trail.

0
SA
Answered on 09-09-2026

From a risk-based perspective, the documentation of CPE credits is a mandatory internal control requirement for maintaining your professional certification. Reporting must be completed via the online ISACA member portal to ensure the credits are officially recognized and recorded against your cycle. You cannot substitute private records for portal registration.

Regarding the audit trail, ISACA policy dictates that you must retain supporting documentation for 12 months post-reporting cycle. This includes:

  • Official certificates of completion.
  • Seminar agendas or course outlines.
  • Proof of payment or registration logs.

Audits are conducted randomly, and your documentation must validate the specific nature of the hours claimed. If the documentation does not map directly to the reported credits, the risk of invalidation is absolute. Ensure that every entry in your portal corresponds to a physical or digital artifact stored in a protected repository. Do not rely on memory or informal logs; in the eyes of the certifying body, the evidence is the only thing that matters.

Share your thoughts

Your email address will not be published. Required fields are marked (*)

Still have questions?
Schedule a free counselling session

Our experts are ready to help you with any questions about courses, admissions, or career paths. Get personalized guidance from industry professionals.

Request a Call Back

Search Online

We Accept

We Accept

Follow Us

"PMI®", "PMBOK®", "PMP®", "CAPM®" and "PMI-ACP®" are registered marks of the Project Management Institute, Inc. | "CSM", "CST" are Registered Trade Marks of The Scrum Alliance, USA. | COBIT® is a trademark of ISACA® registered in the United States and other countries.

Book Free Session

Book Free Session