Every year when the salary surveys come out, the same pattern plays out. Someone in IT governance circles quietly mentions that the CGEIT topped the list again, and everyone else in the room looks slightly confused.
The Certified in the Governance of Enterprise IT is an ISACA credential, and according to the Global Knowledge 2018 IT Skills and Salary Report, it is the single highest-paying IT certification in the United States right now. The average salary for CGEIT holders comes in around $139,000. That is not a typo, and it is not an outlier year. The CGEIT has been at or near the top of these rankings consistently, and it almost never generates the mainstream conversation that certifications like CISSP or CISM do.
So what is it, and why has almost nobody in your office heard of it?
The CGEIT is designed for professionals who manage, advise, or oversee IT governance within an organization. It is not a technical certification in the traditional sense. It does not test your ability to configure a firewall or architect a network. What it validates is your understanding of how IT governance frameworks work, how to align IT strategy with business objectives, how to manage IT-related risk at an enterprise level, and how to ensure that technology investments actually deliver value to the organization.
The reason it pays well is the same reason it flies under the radar. The people who hold this credential are typically in senior leadership positions. Chief Information Officers, IT Directors, senior risk and governance consultants, audit committee advisors. These are not entry-level roles, which is why the certification itself requires significant professional experience before you can even sit for the exam. ISACA requires five years of experience in IT governance-related work, with at least one year in a specific domain area.
That experience requirement filters the candidate pool considerably, which keeps the credential selective and the salaries competitive. It is not a cert you earn on your way up the ladder. It is a cert that validates the expertise you have already accumulated and signals to employers and clients that you are operating at the governance level rather than the technical level.
If you are in a GRC role and you have the experience to qualify, it is worth a serious look at the requirements on the ISACA CGEIT page. The people who hold it tend to be pretty quiet about it, which may be the most on-brand thing possible for an IT governance credential.
Kim Walsh is a CISSP and seasoned cybersecurity practitioner with deep, hands-on experience in enterprise security architecture, risk management, and compliance. She is passionate about bringing the next generation into the IT and AI space, actively mentoring young people who are just finding their footing in the field. As the mother of five kids, she has both the patience and the battle-tested communication skills to explain just about anything to just about anyone.
