CISM in 2026: Exam Guide, Cost and Requirements

By Donald Korinchak, MBA, PMP, CISSP, SecurityX, ITILv3   Published: 09/26/26   Updated: 09/26/26   9 min read

Updated September 2026: ISACA is updating the CISM exam content outline effective November 3, 2026. Exams taken before that date follow the current outline; exams on or after it follow the new one, which keeps the same four domains, shifts the weights slightly, and adds enterprise architecture and information security architecture. ISACA released updated prep materials on September 1, 2026 (ISACA).

ISACA’s Certified Information Security Manager (CISM) is the certification for people who run security programs rather than configure firewalls. It tests whether you can set security strategy, manage risk, build and run a security program, and lead incident management, all in business terms. If your job is moving from “doing security” to “deciding what security the organization needs and proving it works,” CISM is built for that shift.

This guide covers who CISM is for, the exam facts, the experience rule and waivers, the four domains (current and November 2026 weights), the full cost including annual fees, a study plan, career value, and how CISM compares with CISSP, CCSP and SecurityX. For the wider picture, see Best Cybersecurity Certifications in 2026.

Who CISM is for

CISM isn’t a technical exam. Questions describe a business situation and ask what the security manager should do first, or what matters most. Candidates with deep technical backgrounds often struggle because the “most technical” answer is rarely the right one.

CISM exam facts (2026)

ItemDetails
Exam content outlineCurrent outline through November 2, 2026; updated outline from November 3, 2026
Number of questions150 multiple-choice
Time limit4 hours (240 minutes)
ScoringScaled 200 to 800; 450 or higher to pass
Where you testPSI test centers or online with remote proctoring
RegistrationContinuous; schedule as early as 48 hours after paying, and your eligibility lasts six months
Exam priceUS$575 for ISACA members, US$760 for non-members
Application feeUS$50 (one time, after you pass)
ExperienceFive years of information security management experience across at least three of the four domains; up to two years can be waived
Annual maintenance feeUS$45 for members, US$85 for non-members
CPEAt least 20 hours a year and 120 hours per three-year period

Sources: ISACA’s CISM page, certification requirements, maintenance requirements and the ISACA Exam Candidate Guide (version 1.26).

The CISM experience requirement (the five-year rule)

You can take the CISM exam without any experience. To become certified, you need to apply with verified work experience (ISACA):

A common path is to pass the exam while you’re still building management experience, then apply once you have it, as long as you stay inside the five-year window.

The four CISM domains and their weights

DomainCurrent weight (through Nov 2, 2026)From Nov 3, 2026What it covers
1. Information Security Governance17%18%Organizational culture, legal and regulatory requirements, roles and responsibilities, security strategy, governance frameworks, budgets and business cases
2. Information Security Risk Management20%20%Emerging threats, vulnerability and control deficiency analysis, risk assessment, risk treatment options, risk and control ownership, monitoring and reporting
3. Information Security Program33%33%Program resources, asset classification, standards and frameworks, policies, metrics, control design, implementation and testing, awareness training, third-party management and reporting
4. Incident Management30%29%Incident response plans, business impact analysis, BCP and DRP, incident classification, testing, investigation, containment, communications, eradication, recovery and post-incident review

Current weights and topics: ISACA CISM exam content outline. November 2026 weights and new content areas: ISACA press release, September 10, 2026. The November update adds enterprise architecture and information security architecture and puts more emphasis on security strategy and program development. If you test on or after November 3, ISACA strongly recommends the updated prep materials.

What CISM costs in 2026

A non-member who studies on their own pays US$760 plus US$50 to get certified, then US$85 a year to keep it. A member pays US$575 plus US$50, then US$45 a year, plus membership dues.

A 10-week CISM study plan

This assumes about eight hours a week and some real security experience. Check your test date first: before November 3, 2026 use the current outline; on or after it, use the updated materials.

Is CISM worth it? Jobs and salary

CISM is aimed at information security managers, and ISACA says more than 111,000 people have earned it since 2002 (ISACA). ISACA’s CISM page advertises an average annual salary of “US$149K+” for holders; that’s ISACA’s own figure for its certification, not an independent survey (ISACA).

For an independent benchmark, BLS reports a median pay of $175,140 in May 2025 for computer and information systems managers, the category that includes IT security managers, and projects 16% growth from 2025 to 2035 (BLS). Pay depends heavily on scope, industry and location; the certification helps you get considered, and your track record does the rest.

CISM vs CISSP, CCSP and SecurityX

Planning your next certification? See the full certification roadmap for the order to take them by career goal.

What I would tell a friend starting CISM

Stop thinking like the person who fixes the problem and start thinking like the person who has to explain it to the board. Read every question as the security manager of a business that has goals, a budget and a risk appetite. And keep up with real incidents: the best CISM answers look a lot like what good security leaders actually did when things went wrong.

Your board will ask about the breach in the news. Be ready. The CyberExperts Daily Brief covers what changed in security and why it matters, in five minutes, weekday mornings. Get tomorrow’s brief.

Frequently asked questions

How many questions are on the CISM exam?

150 multiple-choice questions in four hours (240 minutes).

What is the passing score for CISM?

450 on ISACA’s scaled score range of 200 to 800.

How much does the CISM exam cost?

US$575 for ISACA members and US$760 for non-members, plus a one-time US$50 application fee after you pass. Keeping CISM costs US$45 a year for members or US$85 for non-members.

What are the CISM experience requirements?

Five years of information security management experience across at least three of the four CISM domains, gained within the 10 years before you apply. You have five years after passing the exam to apply, and ISACA allows experience waivers for a maximum of two years.

Can I take CISM without experience?

Yes. Anyone can take the exam. You need the experience only when you apply for certification, within five years of passing.

What is changing on the CISM exam in November 2026?

From November 3, 2026, the exam follows an updated content outline. The four domains stay the same, but the weights become 18% governance, 20% risk management, 33% program and 29% incident management, and ISACA adds enterprise architecture and information security architecture.

Should I get CISM or CISSP first?

If you already manage a security program, CISM fits your job more directly. If you’re a senior practitioner, engineer or architect, CISSP is usually the first choice. Many security leaders eventually hold both.

Sources

Donald Korinchak, MBA, PMP, CISSP, SecurityX, ITILv3

Donald Korinchak is a Cybersecurity Professional in the Washington DC area. Donald holds an MBA from the University of Pittsburgh Katz School of Business. Donald is considered a thought leader in business, leadership, and cybersecurity issues.