ACISE logo
Focused certification exam prep
Start practice

ACISE Requirements 2026: Eligibility, Prerequisites & How to Qualify

TL;DR
  • ACISE requires nine qualifying IS/IT/cybersecurity examinations completed within three years.
  • CSBS accepts training via the IT Examiner School, the FDIC IT Examination Course, or an accepted equivalent.
  • Eligibility depends on supervisor-affirmed competency attestations, not a timed multiple-choice exam.
  • Recertification requires 63 continuing education hours every three years, with up to 14 excess hours carried forward.

What Is ACISE and Who Certifies It

The Associate Certified Information Systems Examiner (ACISE) credential is issued through the Conference of State Bank Supervisors (CSBS) framework for financial institution IT examiners. Unlike many professional certifications, ACISE is not built around a single timed, multiple-choice certification exam. Instead, it is a competency- and experience-assessed designation: candidates demonstrate readiness through a documented track record of examination work, structured training, and supervisor attestations of competency.

If you are searching for a "test date" or "exam fee schedule" in the traditional sense, it helps to first understand what ACISE actually is and how it differs from conventional certification exams. This guide focuses specifically on the eligibility mechanics - what CSBS requires before an examiner can be considered for ACISE recognition.

Not a Traditional Exam: ACISE eligibility is built on completed examinations, training completion, and attested competency - not a scored, timed test you sit for on a specific date.

Core ACISE Eligibility Requirements

At a high level, three components make up ACISE eligibility:

  • Examination volume: Nine qualifying IS/IT/cybersecurity examinations completed within a rolling three-year window.
  • Training completion: Successful completion of an approved examiner training program covering the technical and regulatory knowledge base examiners need.
  • Attested competency: Sign-off from a supervisor confirming the candidate has demonstrated the competencies expected of a certified examiner in real assignments.

Each of these pieces requires its own documentation trail, and candidates who wait until the end of their three-year window to start organizing records often find themselves scrambling. Understanding how the ACISE certification is structured before you begin logging examinations will save considerable time later.

The Nine Qualifying Examinations Rule

The centerpiece of ACISE eligibility is participation in nine qualifying information systems, information technology, or cybersecurity examinations within three years. This is not a theoretical requirement - it means actual, on-the-job examination assignments at financial institutions, logged and traceable to specific engagements.

Because the three-year clock is fixed, timing matters. An examiner who completes only two or three qualifying examinations per year will need roughly three years just to reach the threshold, leaving little margin for gaps caused by staffing changes, examination cancellations, or role transitions. Candidates should track:

  • The date and scope of each qualifying examination
  • The institution type and examination type (safety and soundness IT review, standalone IT exam, cybersecurity assessment, etc.)
  • Their specific role and level of responsibility on each engagement
  • Any supervisory feedback or evaluation tied to that examination

Key Takeaway

Start a personal examination log on day one of your examiner career. Retroactively reconstructing nine qualifying examinations across three years is far harder than logging them as they happen.

Approved Training Routes

CSBS recognizes multiple training paths that satisfy the education component of ACISE eligibility. The most common routes are:

  • CSBS IT Examiner School - the state regulatory system's dedicated training track for IT examiners.
  • FDIC Information Technology Examination Course - a federally administered course covering comparable examiner competencies.
  • An accepted equivalent - training programs recognized by CSBS as covering substantially the same material.

Because training acceptance criteria can be interpreted differently by different reviewing bodies, candidates pursuing an "equivalent" course should confirm acceptance before investing time and money. Those enrolled through an employer-sponsored program should also review our broader overview of ACISE training options to understand how different programs map onto the eligibility requirement.

Training Is Foundational, Not Sufficient: Completing a training course establishes baseline knowledge, but it does not by itself satisfy the examination-count or attestation requirements. All three components are needed together.

Supervisor Attestations and Competency Documentation

Perhaps the most distinctive part of ACISE eligibility is the supervisor-affirmed competency attestation. Rather than a proctored exam score, CSBS relies on a supervisor's direct observation and sign-off that a candidate has demonstrated the necessary skills across real examination work.

This means the "exam" for ACISE is really an ongoing performance record. Supervisors are typically asked to evaluate a candidate's competency in areas that mirror the four domain categories used throughout the certification framework - technical proficiency, conceptual understanding of IT risk, legal and regulatory compliance awareness, and the ability to communicate findings clearly to bank management and fellow examiners.

Because attestations are subjective assessments made by another person, candidates benefit from proactively discussing expectations with supervisors early, requesting periodic informal feedback, and asking for specific examples of strong versus weak performance in each competency area well before a formal attestation is due.

The Four ACISE Competency Domains

Whether you are logging qualifying examinations, preparing for supervisor evaluation, or simply trying to understand what "competency" means in the ACISE context, it helps to organize your preparation around the four domain categories that structure the credential.

Domain 1: Technical

Covers the hands-on IT and cybersecurity knowledge examiners apply when reviewing an institution's systems, controls, and infrastructure.

  • Network architecture and security control evaluation
  • Core banking system dependencies and vendor management review
  • Incident response and data protection practices

Domain 2: Conceptual

Focuses on the examiner's ability to reason about IT risk holistically, connecting technical findings to institutional risk posture.

  • Risk-based examination scoping and prioritization
  • Understanding how technology risk intersects with operational and strategic risk
  • Applying supervisory frameworks consistently across institution types

Domain 3: Legal/Compliance

Tests familiarity with the regulatory and legal expectations that govern financial institution technology oversight.

  • Applicable regulatory guidance and examination standards
  • Documentation and reporting obligations tied to examination findings
  • Escalation procedures for compliance deficiencies

Domain 4: Communications

Evaluates an examiner's ability to convey technical findings clearly to non-technical stakeholders, including bank boards and management teams.

  • Writing clear, actionable examination reports
  • Presenting findings to institution leadership
  • Collaborating with fellow examiners across joint or multi-agency reviews

For a deeper breakdown of each domain and how they interconnect, see the full ACISE exam domains guide. Because these domains describe competency categories rather than a percentage-weighted test blueprint, candidates should think of them as a checklist for self-assessment and supervisor conversations rather than a scoring rubric.

Building an Application Timeline

Because ACISE eligibility depends on activity accumulated over three years, a realistic timeline should be mapped out early in an examiner's career rather than treated as a last-minute application task.

Year 1

Foundation

  • Complete CSBS IT Examiner School, the FDIC IT Examination Course, or an accepted equivalent
  • Begin logging qualifying examinations as they occur
  • Discuss competency expectations with your supervisor
Year 2

Accumulation

  • Continue building toward the nine qualifying examination threshold
  • Request informal supervisor feedback on Technical and Conceptual domain performance
  • Strengthen weaker domains through additional examination assignments
Year 3

Attestation and Application

  • Confirm all nine qualifying examinations fall within the eligible window
  • Secure formal supervisor attestation of competency
  • Compile documentation and submit the application

Candidates who want a compressed reference of the entire eligibility picture - dates, documentation, and domain expectations - often keep a one-page summary handy; our ACISE cheat sheet is built for exactly this kind of quick review.

Recertification and Continuing Education

ACISE is not a one-time credential. Recertification requires 63 continuing education hours every three years, and candidates may carry forward up to 14 eligible excess hours from one recertification cycle into the next. Beyond the hour count, CSBS also expects continuing IT examination participation or oversight - meaning the credential is tied to sustained, active involvement in examination work, not just classroom hours.

Plan Recertification Early: With 63 hours required every three years, examiners who spread continuing education across each year - rather than cramming near the deadline - are far less likely to fall short.

This ongoing requirement is one reason ACISE holders tend to stay closely connected to active examination assignments throughout their careers, reinforcing both the Technical and Legal/Compliance domains through real-world practice rather than periodic study alone.

Who Typically Qualifies for ACISE

Because eligibility runs through actual examination assignments, ACISE candidates are almost always working within state or federal bank supervisory structures, or in closely related IT examination roles at financial institutions. This is a very different candidate pool than general cybersecurity certification seekers.

  • State banking department IT examiners building toward supervisory-recognized credentials
  • Federal financial regulatory staff participating in joint or coordinated IT examinations
  • Examiners transitioning from generalist safety-and-soundness roles into specialized IT examination work

If you're evaluating whether pursuing the credential fits your career path, our analysis of whether ACISE certification is worth it and the accompanying ACISE salary guide walk through the practical career considerations in more depth. For those actively searching for roles that value or require the credential, the ACISE jobs overview outlines where these positions typically appear.

Key Takeaway

ACISE eligibility is built through your day-to-day examination role - it is earned on the job, not through isolated exam-day preparation alone.

Preparing Within the Eligibility Framework

Because there is no single scored exam session, "preparation" for ACISE looks different than studying for a conventional certification test. It means deliberately building competency across all four domains through the examinations you're already assigned, and structuring your own review so gaps don't linger unaddressed.

A practical approach: after each qualifying examination, briefly note which domain areas you exercised strongly and which felt weaker. Over a few cycles, this creates a self-assessment record that mirrors what a supervisor attestation will eventually evaluate. For candidates who also want structured review material to reinforce weaker domains between assignments, the ACISE study guide offers a more detailed walkthrough, and practicing scenario-based questions on our practice test platform can help reinforce Technical and Legal/Compliance concepts between real examination assignments.

Some candidates also want a clearer sense of how demanding the overall path is compared to other credentials - that's covered in our guide on how difficult the ACISE process actually is, and questions about what "passing" even means in a competency-assessed model are addressed in our breakdown of the ACISE passing score concept. If you're budgeting for training, travel, or materials, the ACISE certification cost breakdown and general ACISE pass rate discussion round out the planning picture, while ACISE exam dates covers scheduling considerations for training courses tied to the credential.

RequirementWhat It Involves
Qualifying examinationsNine IS/IT/cybersecurity examinations within three years
TrainingCSBS IT Examiner School, FDIC IT Examination Course, or accepted equivalent
Competency attestationSupervisor sign-off on demonstrated examiner competency
Recertification63 continuing education hours every three years (up to 14 excess hours carried forward)
Ongoing activityContinued IT examination participation or oversight

Practicing through structured domain scenarios on our ACISE practice test resource is a useful supplement while you accumulate qualifying examinations, especially for reinforcing Conceptual and Communications domain thinking that doesn't always come up naturally in every assignment.

Frequently Asked Questions

How many qualifying examinations do I need for ACISE eligibility?

You need nine qualifying IS/IT/cybersecurity examinations completed within a three-year window, along with approved training and a supervisor-affirmed competency attestation.

Is there a timed exam I need to sit for ACISE?

No. ACISE is a competency- and experience-assessed certification. Eligibility is demonstrated through completed examinations, training, and supervisor attestation rather than a scored, timed multiple-choice test.

What training satisfies the ACISE education requirement?

CSBS accepts the CSBS IT Examiner School, the FDIC Information Technology Examination Course, or another training program recognized as an accepted equivalent.

How often do I need to recertify, and what does it require?

Recertification is required every three years and involves 63 continuing education hours, with up to 14 eligible excess hours carried forward, plus ongoing IT examination participation or oversight.

Who is the ACISE credential designed for?

It is designed for state and federal financial institution IT examiners who conduct IS, IT, and cybersecurity examinations as part of their supervisory role.

Ready to pass your ACISE exam?

Put this into practice with free ACISE questions across every exam domain.