- What Is ACISE and Who Certifies It
- Core ACISE Eligibility Requirements
- The Nine Qualifying Examinations Rule
- Approved Training Routes
- Supervisor Attestations and Competency Documentation
- The Four ACISE Competency Domains
- Building an Application Timeline
- Recertification and Continuing Education
- Who Typically Qualifies for ACISE
- Frequently Asked Questions
- ACISE requires nine qualifying IS/IT/cybersecurity examinations completed within three years.
- CSBS accepts training via the IT Examiner School, the FDIC IT Examination Course, or an accepted equivalent.
- Eligibility depends on supervisor-affirmed competency attestations, not a timed multiple-choice exam.
- Recertification requires 63 continuing education hours every three years, with up to 14 excess hours carried forward.
What Is ACISE and Who Certifies It
The Associate Certified Information Systems Examiner (ACISE) credential is issued through the Conference of State Bank Supervisors (CSBS) framework for financial institution IT examiners. Unlike many professional certifications, ACISE is not built around a single timed, multiple-choice certification exam. Instead, it is a competency- and experience-assessed designation: candidates demonstrate readiness through a documented track record of examination work, structured training, and supervisor attestations of competency.
If you are searching for a "test date" or "exam fee schedule" in the traditional sense, it helps to first understand what ACISE actually is and how it differs from conventional certification exams. This guide focuses specifically on the eligibility mechanics - what CSBS requires before an examiner can be considered for ACISE recognition.
Core ACISE Eligibility Requirements
At a high level, three components make up ACISE eligibility:
- Examination volume: Nine qualifying IS/IT/cybersecurity examinations completed within a rolling three-year window.
- Training completion: Successful completion of an approved examiner training program covering the technical and regulatory knowledge base examiners need.
- Attested competency: Sign-off from a supervisor confirming the candidate has demonstrated the competencies expected of a certified examiner in real assignments.
Each of these pieces requires its own documentation trail, and candidates who wait until the end of their three-year window to start organizing records often find themselves scrambling. Understanding how the ACISE certification is structured before you begin logging examinations will save considerable time later.
The Nine Qualifying Examinations Rule
The centerpiece of ACISE eligibility is participation in nine qualifying information systems, information technology, or cybersecurity examinations within three years. This is not a theoretical requirement - it means actual, on-the-job examination assignments at financial institutions, logged and traceable to specific engagements.
Because the three-year clock is fixed, timing matters. An examiner who completes only two or three qualifying examinations per year will need roughly three years just to reach the threshold, leaving little margin for gaps caused by staffing changes, examination cancellations, or role transitions. Candidates should track:
- The date and scope of each qualifying examination
- The institution type and examination type (safety and soundness IT review, standalone IT exam, cybersecurity assessment, etc.)
- Their specific role and level of responsibility on each engagement
- Any supervisory feedback or evaluation tied to that examination
Key Takeaway
Start a personal examination log on day one of your examiner career. Retroactively reconstructing nine qualifying examinations across three years is far harder than logging them as they happen.
Approved Training Routes
CSBS recognizes multiple training paths that satisfy the education component of ACISE eligibility. The most common routes are:
- CSBS IT Examiner School - the state regulatory system's dedicated training track for IT examiners.
- FDIC Information Technology Examination Course - a federally administered course covering comparable examiner competencies.
- An accepted equivalent - training programs recognized by CSBS as covering substantially the same material.
Because training acceptance criteria can be interpreted differently by different reviewing bodies, candidates pursuing an "equivalent" course should confirm acceptance before investing time and money. Those enrolled through an employer-sponsored program should also review our broader overview of ACISE training options to understand how different programs map onto the eligibility requirement.
Supervisor Attestations and Competency Documentation
Perhaps the most distinctive part of ACISE eligibility is the supervisor-affirmed competency attestation. Rather than a proctored exam score, CSBS relies on a supervisor's direct observation and sign-off that a candidate has demonstrated the necessary skills across real examination work.
This means the "exam" for ACISE is really an ongoing performance record. Supervisors are typically asked to evaluate a candidate's competency in areas that mirror the four domain categories used throughout the certification framework - technical proficiency, conceptual understanding of IT risk, legal and regulatory compliance awareness, and the ability to communicate findings clearly to bank management and fellow examiners.
Because attestations are subjective assessments made by another person, candidates benefit from proactively discussing expectations with supervisors early, requesting periodic informal feedback, and asking for specific examples of strong versus weak performance in each competency area well before a formal attestation is due.
The Four ACISE Competency Domains
Whether you are logging qualifying examinations, preparing for supervisor evaluation, or simply trying to understand what "competency" means in the ACISE context, it helps to organize your preparation around the four domain categories that structure the credential.
Domain 1: Technical
Covers the hands-on IT and cybersecurity knowledge examiners apply when reviewing an institution's systems, controls, and infrastructure.
- Network architecture and security control evaluation
- Core banking system dependencies and vendor management review
- Incident response and data protection practices
Domain 2: Conceptual
Focuses on the examiner's ability to reason about IT risk holistically, connecting technical findings to institutional risk posture.
- Risk-based examination scoping and prioritization
- Understanding how technology risk intersects with operational and strategic risk
- Applying supervisory frameworks consistently across institution types
Domain 3: Legal/Compliance
Tests familiarity with the regulatory and legal expectations that govern financial institution technology oversight.
- Applicable regulatory guidance and examination standards
- Documentation and reporting obligations tied to examination findings
- Escalation procedures for compliance deficiencies
Domain 4: Communications
Evaluates an examiner's ability to convey technical findings clearly to non-technical stakeholders, including bank boards and management teams.
- Writing clear, actionable examination reports
- Presenting findings to institution leadership
- Collaborating with fellow examiners across joint or multi-agency reviews
For a deeper breakdown of each domain and how they interconnect, see the full ACISE exam domains guide. Because these domains describe competency categories rather than a percentage-weighted test blueprint, candidates should think of them as a checklist for self-assessment and supervisor conversations rather than a scoring rubric.
Building an Application Timeline
Because ACISE eligibility depends on activity accumulated over three years, a realistic timeline should be mapped out early in an examiner's career rather than treated as a last-minute application task.
Foundation
- Complete CSBS IT Examiner School, the FDIC IT Examination Course, or an accepted equivalent
- Begin logging qualifying examinations as they occur
- Discuss competency expectations with your supervisor
Accumulation
- Continue building toward the nine qualifying examination threshold
- Request informal supervisor feedback on Technical and Conceptual domain performance
- Strengthen weaker domains through additional examination assignments
Attestation and Application
- Confirm all nine qualifying examinations fall within the eligible window
- Secure formal supervisor attestation of competency
- Compile documentation and submit the application
Candidates who want a compressed reference of the entire eligibility picture - dates, documentation, and domain expectations - often keep a one-page summary handy; our ACISE cheat sheet is built for exactly this kind of quick review.
Recertification and Continuing Education
ACISE is not a one-time credential. Recertification requires 63 continuing education hours every three years, and candidates may carry forward up to 14 eligible excess hours from one recertification cycle into the next. Beyond the hour count, CSBS also expects continuing IT examination participation or oversight - meaning the credential is tied to sustained, active involvement in examination work, not just classroom hours.
This ongoing requirement is one reason ACISE holders tend to stay closely connected to active examination assignments throughout their careers, reinforcing both the Technical and Legal/Compliance domains through real-world practice rather than periodic study alone.
Who Typically Qualifies for ACISE
Because eligibility runs through actual examination assignments, ACISE candidates are almost always working within state or federal bank supervisory structures, or in closely related IT examination roles at financial institutions. This is a very different candidate pool than general cybersecurity certification seekers.
- State banking department IT examiners building toward supervisory-recognized credentials
- Federal financial regulatory staff participating in joint or coordinated IT examinations
- Examiners transitioning from generalist safety-and-soundness roles into specialized IT examination work
If you're evaluating whether pursuing the credential fits your career path, our analysis of whether ACISE certification is worth it and the accompanying ACISE salary guide walk through the practical career considerations in more depth. For those actively searching for roles that value or require the credential, the ACISE jobs overview outlines where these positions typically appear.
Key Takeaway
ACISE eligibility is built through your day-to-day examination role - it is earned on the job, not through isolated exam-day preparation alone.
Preparing Within the Eligibility Framework
Because there is no single scored exam session, "preparation" for ACISE looks different than studying for a conventional certification test. It means deliberately building competency across all four domains through the examinations you're already assigned, and structuring your own review so gaps don't linger unaddressed.
A practical approach: after each qualifying examination, briefly note which domain areas you exercised strongly and which felt weaker. Over a few cycles, this creates a self-assessment record that mirrors what a supervisor attestation will eventually evaluate. For candidates who also want structured review material to reinforce weaker domains between assignments, the ACISE study guide offers a more detailed walkthrough, and practicing scenario-based questions on our practice test platform can help reinforce Technical and Legal/Compliance concepts between real examination assignments.
Some candidates also want a clearer sense of how demanding the overall path is compared to other credentials - that's covered in our guide on how difficult the ACISE process actually is, and questions about what "passing" even means in a competency-assessed model are addressed in our breakdown of the ACISE passing score concept. If you're budgeting for training, travel, or materials, the ACISE certification cost breakdown and general ACISE pass rate discussion round out the planning picture, while ACISE exam dates covers scheduling considerations for training courses tied to the credential.
| Requirement | What It Involves |
|---|---|
| Qualifying examinations | Nine IS/IT/cybersecurity examinations within three years |
| Training | CSBS IT Examiner School, FDIC IT Examination Course, or accepted equivalent |
| Competency attestation | Supervisor sign-off on demonstrated examiner competency |
| Recertification | 63 continuing education hours every three years (up to 14 excess hours carried forward) |
| Ongoing activity | Continued IT examination participation or oversight |
Practicing through structured domain scenarios on our ACISE practice test resource is a useful supplement while you accumulate qualifying examinations, especially for reinforcing Conceptual and Communications domain thinking that doesn't always come up naturally in every assignment.
Frequently Asked Questions
You need nine qualifying IS/IT/cybersecurity examinations completed within a three-year window, along with approved training and a supervisor-affirmed competency attestation.
No. ACISE is a competency- and experience-assessed certification. Eligibility is demonstrated through completed examinations, training, and supervisor attestation rather than a scored, timed multiple-choice test.
CSBS accepts the CSBS IT Examiner School, the FDIC Information Technology Examination Course, or another training program recognized as an accepted equivalent.
Recertification is required every three years and involves 63 continuing education hours, with up to 14 eligible excess hours carried forward, plus ongoing IT examination participation or oversight.
It is designed for state and federal financial institution IT examiners who conduct IS, IT, and cybersecurity examinations as part of their supervisory role.