- Why ACISE Doesn't Use a Traditional Passing Score
- How the Competency-Assessment Model Actually Works
- The Four Competency Domains Behind Certification
- Eligibility: Nine Qualifying Examinations in Three Years
- Approved Training Routes That Build Competency
- Supervisor Attestation: The Real "Passing" Mechanism
- Recertification: 63 CE Hours Every Three Years
- Building a Readiness Timeline Around the Domains
- Frequently Asked Questions
- ACISE has no numeric cut score - it's a competency- and experience-assessed certification from CSBS, not a timed multiple-choice exam.
- Candidates need nine qualifying IS/IT/cybersecurity examinations completed within three years to be eligible.
- The four domains - Technical, Conceptual, Legal/Compliance, Communications - function as competency categories, not weighted test sections.
- Approved training includes the CSBS IT Examiner School, the FDIC Information Technology Examination Course, or an accepted equivalent.
Why ACISE Doesn't Use a Traditional Passing Score
If you've searched "ACISE passing score" expecting a specific number - like 70% or a scaled score threshold - you're going to find something different, and it's important to understand why before you spend time preparing incorrectly. The Associate Certified Information Systems Examiner credential, administered by the Conference of State Bank Supervisors (CSBS), is a competency- and experience-assessed examiner certification. It is not a proctored, timed, multiple-choice examination that spits out a scaled score at the end.
Instead of a cut score, ACISE certification depends on a combination of documented examination experience, completed training, and supervisor-affirmed competency attestations across defined domain areas. That distinction matters enormously for how you prepare. If you're treating ACISE like a certification exam you can cram for the night before, you're preparing for the wrong thing. For a broader breakdown of how this differs from conventional certification testing, see our complete difficulty guide, which explains why "difficulty" here is measured in experience and competency depth rather than exam anxiety.
How the Competency-Assessment Model Actually Works
Because ACISE is built around real examiner work rather than a simulated test environment, "passing" is really a shorthand for meeting several converging requirements at once. Candidates must accumulate qualifying examination experience, complete recognized training, and have a supervisor formally attest that they've demonstrated competency in each domain area. There isn't a single moment where you sit for an exam and receive a score - there's a body of evidence that builds over time.
This is why so much of the preparation conversation around ACISE should really be a preparation conversation around documentation and readiness, not test-taking tactics. If you haven't yet mapped out what qualifies as one of the nine required examinations, or how training hours get logged and verified, that's the foundation to sort out before you worry about anything resembling a "score." Our requirements guide walks through eligibility mechanics in more detail, and our study guide translates this competency model into a practical first-attempt preparation plan.
Key Takeaway
Stop looking for a numeric threshold. Focus instead on completing nine qualifying examinations, finishing approved training, and securing supervisor attestation across all four domains.
The Four Competency Domains Behind Certification
ACISE organizes competency expectations into four domain lines. Unlike a scored exam where each domain carries a weighted percentage of total points, these domains function as categories your supervisor evaluates when attesting to your readiness. Understanding what each one actually demands is the closest thing to understanding "what you need to pass."
Domain 1: Technical
Covers the hands-on information systems and IT examination skills examiners apply in the field - assessing controls, evaluating infrastructure, and understanding the technical environment of the institutions under review.
- Ability to evaluate IT infrastructure and control environments during real examinations
- Comfort applying technical findings gained through the nine qualifying examinations
Domain 2: Conceptual
Focuses on the examiner's grasp of underlying frameworks and risk concepts - connecting technical findings to broader institutional risk posture rather than treating each finding in isolation.
- Understanding how IT risk concepts tie back to institutional soundness
- Synthesizing findings across multiple examination engagements
Domain 3: Legal/Compliance
Addresses the regulatory and compliance context examiners must operate within, including how findings map to applicable examination standards and supervisory expectations.
- Familiarity with the compliance framework surrounding IS/IT examinations
- Applying legal and regulatory context correctly in written findings
Domain 4: Communications
Covers how examiners convey findings - to institution management, to supervisory teams, and in formal documentation - clearly and professionally.
- Producing clear, defensible examination documentation
- Communicating findings effectively to varied audiences
For a deeper walkthrough of how each domain shows up in day-to-day examiner work, our exam domains guide covers all four content areas in more depth than we can fit here.
Eligibility: Nine Qualifying Examinations in Three Years
Perhaps the single most important number in the entire ACISE process isn't a passing score - it's nine. Candidates must complete nine qualifying IS/IT/cybersecurity examinations within a three-year window to become eligible for certification. This requirement does more work than any test score could, because it forces candidates to accumulate breadth of real examination experience before attestation is even considered.
Practically speaking, this means your "prep plan" is really a career-sequencing plan. You need to be actively assigned to, or participating in, qualifying examinations on a consistent cadence, and you need a way to track which examinations count and when the three-year clock started. Skipping this step, or losing track of timing, is a far more common failure point than any content gap. Our requirements article details exactly what qualifies as an eligible examination and how the three-year window is calculated.
Approved Training Routes That Build Competency
Alongside examination experience, candidates need appropriate examiner training. CSBS recognizes multiple paths to satisfy this requirement:
- The CSBS IT Examiner School
- The FDIC Information Technology Examination Course
- An accepted equivalent training program
None of these are self-paced online courses you complete in an afternoon. They're structured training programs designed to build the technical and conceptual grounding examiners need before they're trusted with independent judgment calls in the field. If you're comparing training options or trying to figure out which route fits your schedule and employer, our dedicated ACISE training resource breaks down what each path involves.
| Requirement Area | What It Involves |
|---|---|
| Examination Experience | Nine qualifying IS/IT/cybersecurity examinations within three years |
| Formal Training | CSBS IT Examiner School, FDIC IT Examination Course, or accepted equivalent |
| Competency Attestation | Supervisor sign-off across the four domain categories |
| Ongoing Standing | 63 CE hours every three years, up to 14 excess hours carried forward |
Supervisor Attestation: The Real "Passing" Mechanism
Here's the part of the process that most closely resembles "passing" ACISE: your supervisor's formal attestation that you've demonstrated competency across the Technical, Conceptual, Legal/Compliance, and Communications domains. This isn't a rubber stamp - it's an assessment built on your actual performance across the qualifying examinations you've completed and the training you've absorbed.
This changes how you should think about preparation. Instead of drilling practice questions to beat a cut score, the more useful work is making sure your day-to-day examination performance genuinely reflects competency in each domain - and that your supervisor sees that evidence clearly enough to attest to it confidently. Keeping your own documentation of completed examinations, training milestones, and specific competency examples in each domain will make this conversation with your supervisor far smoother when the time comes.
Key Takeaway
Track your own competency evidence in each domain as you go. Supervisor attestation goes faster when you can point to specific examinations and outcomes, not just a completed checklist.
Recertification: 63 CE Hours Every Three Years
Certification isn't a one-time achievement. To maintain ACISE status, certified examiners must complete 63 continuing education hours every three years, and the program allows up to 14 excess hours to be carried forward into the next cycle if you complete more than the minimum. Beyond CE hours, certified examiners are also expected to maintain continuing IT examination participation or oversight - reinforcing that this credential is meant to reflect active, ongoing examiner practice rather than a credential earned once and shelved.
This recertification structure is worth planning around early, not scrambling to satisfy in year two or three. If you're weighing whether the ongoing CE commitment fits your career trajectory, our ROI analysis and pricing breakdown both address the long-term commitment involved in holding this credential.
Building a Readiness Timeline Around the Domains
Even though ACISE isn't a single-sitting exam, structuring your preparation across a realistic timeline still helps - especially when you're trying to make sure your examination experience and training genuinely cover all four domains rather than skewing heavily toward one or two.
Map Your Eligibility Clock
- Confirm which completed examinations qualify toward the nine-examination requirement
- Identify your three-year eligibility window and any gaps to fill
Close Technical and Conceptual Gaps
- Prioritize qualifying examinations that build Technical domain depth
- Document how findings connect to broader Conceptual risk understanding
Strengthen Legal/Compliance and Communications
- Review regulatory context tied to recent examination assignments
- Practice drafting clear, well-organized examination findings
Complete Training and Prepare for Attestation
- Finish CSBS IT Examiner School, the FDIC course, or an accepted equivalent
- Compile domain-specific evidence for your supervisor's attestation conversation
If you want a condensed reference you can revisit throughout this process, our one-page review of must-know facts is designed exactly for that. And if you're still deciding whether ACISE is the right credential to pursue given your role, the ACISE jobs overview covers who typically hires for this credential and why it matters to examiners working in the state banking supervisory system.
Frequently Asked Questions
No. ACISE is a competency- and experience-assessed certification from CSBS, not a scored multiple-choice exam. There is no numeric cut score to hit; instead, candidates must complete nine qualifying examinations, finish approved training, and receive supervisor-affirmed attestation of competency across the four domains.
Technical, Conceptual, Legal/Compliance, and Communications. These function as competency categories your supervisor assesses based on your examination experience and training, not weighted sections of a timed test.
Nine qualifying IS/IT/cybersecurity examinations completed within a three-year window are required for eligibility. Losing track of this timing is one of the most common reasons candidates delay certification.
Accepted options include the CSBS IT Examiner School, the FDIC Information Technology Examination Course, or another accepted equivalent training program recognized by CSBS.
Yes. Recertification requires 63 continuing education hours every three years, with up to 14 excess hours eligible to carry forward, plus continued participation in or oversight of IT examinations.