ICAI Upgrades DISA 3.0 to DISA 4.0: New Course Structure, Fees and Transition Rules

Read Time:

ICAI Upgrades DISA 3.0 to DISA 4.0: New Course Structure, Fees and Transition Rules

Current development

 

The Institute of Chartered Accountants of India has announced a major upgrade to its Post Qualification Course on Information Systems Audit, moving from DISA 3.0 to DISA 4.0. ICAI's Digital Accounting and Assurance Board says the revised programme is intended to strengthen practical capabilities across information-systems audit, cybersecurity, IT governance, risk management and technology controls.

The change is especially important for members already enrolled under DISA 3.0 because ICAI has also laid down a transition framework. Further batches under DISA 3.0 have been discontinued, while detailed schedules for DISA 4.0 registration, batches and examinations are to be announced separately.

 

What will DISA 4.0 cover?

 

ICAI has identified a broad set of technology-risk areas for the upgraded course. These include Information Systems Audit, Cybersecurity Audit, IT Governance, Risk Management, Application Controls, Identity and Access Management, Network Security, IT Operations, Third-Party Risk, Incident Response, Business Resilience and Compliance.

The curriculum therefore moves beyond a conventional systems-audit orientation and gives greater weight to the technology risks now encountered in modern audits, regulated businesses and digitally dependent organisations.

 

New DISA 4.0 course structure

 

The revised structure broadly comprises 15 hours of self-paced e-learning, two days or 12 hours of live immersion sessions, and eight days of physical practical training.

For fresh candidates, ICAI has indicated direct admission to DISA 4.0 with a proposed fee of ₹25,000. The structure is designed to combine foundational digital learning with live interaction and a larger practical component.

 

Existing candidates who have cleared the Eligibility Test

 

Existing DISA 3.0 candidates who have passed the Eligibility Test but have not cleared the final Assessment Test will get a transition period of six attempts over two years from the launch of DISA 4.0 to complete the qualification under the old scheme.

No additional fee is proposed for this transition window. If the candidate does not complete DISA 3.0 within that period, migration to the DISA 4.0 framework will become necessary.

 

Candidates with classes completed but ET and AT pending

 

For members who have completed DISA 3.0 classes but still have the Eligibility Test and Assessment Test pending, ICAI provides an upgrade route. They may migrate to DISA 4.0 by attending an eight-day bridge programme and paying a proposed ₹10,000 fee, after which they would take the tests under the new syllabus.

Alternatively, the notification permits them to complete DISA 3.0 within the prescribed two-year period without additional fee.

 

Already-qualified DISA members

 

Members who have already qualified under DISA 3.0 are not required to redo the qualification. ICAI has instead proposed an optional DISA+ refresher course, with a proposed fee of ₹20,000, for members who want to upgrade their skills.

 

Why ICAI is making the change

 

Audit and assurance work increasingly intersects with cybersecurity, cloud and application controls, third-party technology risk, digital identity, business continuity and incident response. The revised structure reflects the fact that an information-systems auditor now needs practical familiarity with a broader technology-risk environment.

For practising CAs, the transition may also influence how firms build technology-assurance teams and plan training for members engaged in systems audit, internal audit, cyber assurance and technology-control reviews.

 

What candidates should do now

 

- Identify the exact stage of your DISA 3.0 journey.

- If the Eligibility Test is already cleared, track the six-attempt/two-year transition window after DISA 4.0 launches.

- If classes are complete but ET/AT are pending, compare the old-scheme completion route with the eight-day bridge option.

- Fresh candidates should wait for ICAI's detailed DISA 4.0 registration and batch schedule.

- Do not rely on informal batch dates until ICAI issues the operational schedule.

 

 

Key takeaway

 

ICAI is replacing DISA 3.0 with a more practical, cyber-focused DISA 4.0 programme and has stopped further DISA 3.0 batches. Existing candidates are protected through defined transition routes, while fresh candidates will enter the new structure. Members should now map their current status against ICAI's transition framework and watch for the separate registration and examination schedule.

 

 

Share your views

Please keep your views respectful and not include any anchors, promotional content or obscene words in them. Such comments will be definitely removed and your IP be blocked for future purpose.

Submit

Subscribe To Our Newsletter

Subscribe us to get updates on latest Jobs Openings, News, Articles, Notices/ Circulars

Submit

© 2026 | Copyright © CA Samaaj Pvt Ltd

Designed & Developed by AMITKK

Join Whatsapp Group of CA Samaaj