ACISE logo
Focused certification exam prep
Start practice

ACISE Passing Score 2026: Exactly What You Need to Pass

TL;DR
  • ACISE has no numeric cut score - it's a competency- and experience-assessed certification from CSBS, not a timed multiple-choice exam.
  • Candidates need nine qualifying IS/IT/cybersecurity examinations completed within three years to be eligible.
  • The four domains - Technical, Conceptual, Legal/Compliance, Communications - function as competency categories, not weighted test sections.
  • Approved training includes the CSBS IT Examiner School, the FDIC Information Technology Examination Course, or an accepted equivalent.

Why ACISE Doesn't Use a Traditional Passing Score

If you've searched "ACISE passing score" expecting a specific number - like 70% or a scaled score threshold - you're going to find something different, and it's important to understand why before you spend time preparing incorrectly. The Associate Certified Information Systems Examiner credential, administered by the Conference of State Bank Supervisors (CSBS), is a competency- and experience-assessed examiner certification. It is not a proctored, timed, multiple-choice examination that spits out a scaled score at the end.

Instead of a cut score, ACISE certification depends on a combination of documented examination experience, completed training, and supervisor-affirmed competency attestations across defined domain areas. That distinction matters enormously for how you prepare. If you're treating ACISE like a certification exam you can cram for the night before, you're preparing for the wrong thing. For a broader breakdown of how this differs from conventional certification testing, see our complete difficulty guide, which explains why "difficulty" here is measured in experience and competency depth rather than exam anxiety.

Key Distinction: There is no ACISE "passing score" in the traditional sense. Readiness is demonstrated through nine qualifying examinations, approved training, and supervisor attestation of competency - not a percentage on an answer sheet.

How the Competency-Assessment Model Actually Works

Because ACISE is built around real examiner work rather than a simulated test environment, "passing" is really a shorthand for meeting several converging requirements at once. Candidates must accumulate qualifying examination experience, complete recognized training, and have a supervisor formally attest that they've demonstrated competency in each domain area. There isn't a single moment where you sit for an exam and receive a score - there's a body of evidence that builds over time.

This is why so much of the preparation conversation around ACISE should really be a preparation conversation around documentation and readiness, not test-taking tactics. If you haven't yet mapped out what qualifies as one of the nine required examinations, or how training hours get logged and verified, that's the foundation to sort out before you worry about anything resembling a "score." Our requirements guide walks through eligibility mechanics in more detail, and our study guide translates this competency model into a practical first-attempt preparation plan.

Key Takeaway

Stop looking for a numeric threshold. Focus instead on completing nine qualifying examinations, finishing approved training, and securing supervisor attestation across all four domains.

The Four Competency Domains Behind Certification

ACISE organizes competency expectations into four domain lines. Unlike a scored exam where each domain carries a weighted percentage of total points, these domains function as categories your supervisor evaluates when attesting to your readiness. Understanding what each one actually demands is the closest thing to understanding "what you need to pass."

Domain 1: Technical

Covers the hands-on information systems and IT examination skills examiners apply in the field - assessing controls, evaluating infrastructure, and understanding the technical environment of the institutions under review.

  • Ability to evaluate IT infrastructure and control environments during real examinations
  • Comfort applying technical findings gained through the nine qualifying examinations

Domain 2: Conceptual

Focuses on the examiner's grasp of underlying frameworks and risk concepts - connecting technical findings to broader institutional risk posture rather than treating each finding in isolation.

  • Understanding how IT risk concepts tie back to institutional soundness
  • Synthesizing findings across multiple examination engagements

Domain 3: Legal/Compliance

Addresses the regulatory and compliance context examiners must operate within, including how findings map to applicable examination standards and supervisory expectations.

  • Familiarity with the compliance framework surrounding IS/IT examinations
  • Applying legal and regulatory context correctly in written findings

Domain 4: Communications

Covers how examiners convey findings - to institution management, to supervisory teams, and in formal documentation - clearly and professionally.

  • Producing clear, defensible examination documentation
  • Communicating findings effectively to varied audiences

For a deeper walkthrough of how each domain shows up in day-to-day examiner work, our exam domains guide covers all four content areas in more depth than we can fit here.

Eligibility: Nine Qualifying Examinations in Three Years

Perhaps the single most important number in the entire ACISE process isn't a passing score - it's nine. Candidates must complete nine qualifying IS/IT/cybersecurity examinations within a three-year window to become eligible for certification. This requirement does more work than any test score could, because it forces candidates to accumulate breadth of real examination experience before attestation is even considered.

Practically speaking, this means your "prep plan" is really a career-sequencing plan. You need to be actively assigned to, or participating in, qualifying examinations on a consistent cadence, and you need a way to track which examinations count and when the three-year clock started. Skipping this step, or losing track of timing, is a far more common failure point than any content gap. Our requirements article details exactly what qualifies as an eligible examination and how the three-year window is calculated.

Timing Matters: The nine qualifying examinations must fall within a three-year period. Candidates who space engagements too far apart risk falling outside the eligible window and having to restart the count.

Approved Training Routes That Build Competency

Alongside examination experience, candidates need appropriate examiner training. CSBS recognizes multiple paths to satisfy this requirement:

  • The CSBS IT Examiner School
  • The FDIC Information Technology Examination Course
  • An accepted equivalent training program

None of these are self-paced online courses you complete in an afternoon. They're structured training programs designed to build the technical and conceptual grounding examiners need before they're trusted with independent judgment calls in the field. If you're comparing training options or trying to figure out which route fits your schedule and employer, our dedicated ACISE training resource breaks down what each path involves.

Requirement AreaWhat It Involves
Examination ExperienceNine qualifying IS/IT/cybersecurity examinations within three years
Formal TrainingCSBS IT Examiner School, FDIC IT Examination Course, or accepted equivalent
Competency AttestationSupervisor sign-off across the four domain categories
Ongoing Standing63 CE hours every three years, up to 14 excess hours carried forward

Supervisor Attestation: The Real "Passing" Mechanism

Here's the part of the process that most closely resembles "passing" ACISE: your supervisor's formal attestation that you've demonstrated competency across the Technical, Conceptual, Legal/Compliance, and Communications domains. This isn't a rubber stamp - it's an assessment built on your actual performance across the qualifying examinations you've completed and the training you've absorbed.

This changes how you should think about preparation. Instead of drilling practice questions to beat a cut score, the more useful work is making sure your day-to-day examination performance genuinely reflects competency in each domain - and that your supervisor sees that evidence clearly enough to attest to it confidently. Keeping your own documentation of completed examinations, training milestones, and specific competency examples in each domain will make this conversation with your supervisor far smoother when the time comes.

Key Takeaway

Track your own competency evidence in each domain as you go. Supervisor attestation goes faster when you can point to specific examinations and outcomes, not just a completed checklist.

Recertification: 63 CE Hours Every Three Years

Certification isn't a one-time achievement. To maintain ACISE status, certified examiners must complete 63 continuing education hours every three years, and the program allows up to 14 excess hours to be carried forward into the next cycle if you complete more than the minimum. Beyond CE hours, certified examiners are also expected to maintain continuing IT examination participation or oversight - reinforcing that this credential is meant to reflect active, ongoing examiner practice rather than a credential earned once and shelved.

This recertification structure is worth planning around early, not scrambling to satisfy in year two or three. If you're weighing whether the ongoing CE commitment fits your career trajectory, our ROI analysis and pricing breakdown both address the long-term commitment involved in holding this credential.

Building a Readiness Timeline Around the Domains

Even though ACISE isn't a single-sitting exam, structuring your preparation across a realistic timeline still helps - especially when you're trying to make sure your examination experience and training genuinely cover all four domains rather than skewing heavily toward one or two.

Weeks 1-4

Map Your Eligibility Clock

  • Confirm which completed examinations qualify toward the nine-examination requirement
  • Identify your three-year eligibility window and any gaps to fill
Weeks 5-10

Close Technical and Conceptual Gaps

  • Prioritize qualifying examinations that build Technical domain depth
  • Document how findings connect to broader Conceptual risk understanding
Weeks 11-16

Strengthen Legal/Compliance and Communications

  • Review regulatory context tied to recent examination assignments
  • Practice drafting clear, well-organized examination findings
Ongoing

Complete Training and Prepare for Attestation

  • Finish CSBS IT Examiner School, the FDIC course, or an accepted equivalent
  • Compile domain-specific evidence for your supervisor's attestation conversation

If you want a condensed reference you can revisit throughout this process, our one-page review of must-know facts is designed exactly for that. And if you're still deciding whether ACISE is the right credential to pursue given your role, the ACISE jobs overview covers who typically hires for this credential and why it matters to examiners working in the state banking supervisory system.

Practice Reinforcement: While ACISE itself isn't a multiple-choice exam, sharpening your grasp of domain concepts through structured practice questions on our practice test platform can help solidify the Technical and Conceptual knowledge your supervisor will be evaluating.

Frequently Asked Questions

Is there an official ACISE passing score or percentage?

No. ACISE is a competency- and experience-assessed certification from CSBS, not a scored multiple-choice exam. There is no numeric cut score to hit; instead, candidates must complete nine qualifying examinations, finish approved training, and receive supervisor-affirmed attestation of competency across the four domains.

What are the four ACISE domains I need to demonstrate competency in?

Technical, Conceptual, Legal/Compliance, and Communications. These function as competency categories your supervisor assesses based on your examination experience and training, not weighted sections of a timed test.

How many qualifying examinations do I need, and in what timeframe?

Nine qualifying IS/IT/cybersecurity examinations completed within a three-year window are required for eligibility. Losing track of this timing is one of the most common reasons candidates delay certification.

What training satisfies the ACISE training requirement?

Accepted options include the CSBS IT Examiner School, the FDIC Information Technology Examination Course, or another accepted equivalent training program recognized by CSBS.

Do I need to do anything after I'm certified to keep my ACISE credential?

Yes. Recertification requires 63 continuing education hours every three years, with up to 14 excess hours eligible to carry forward, plus continued participation in or oversight of IT examinations.

Ready to pass your ACISE exam?

Put this into practice with free ACISE questions across every exam domain.