Updated September 2026: ISACA is updating the CISM exam content outline effective November 3, 2026. Exams taken before that date follow the current outline; exams on or after it follow the new one, which keeps the same four domains, shifts the weights slightly, and adds enterprise architecture and information security architecture. ISACA released updated prep materials on September 1, 2026 (ISACA).
ISACA’s Certified Information Security Manager (CISM) is the certification for people who run security programs rather than configure firewalls. It tests whether you can set security strategy, manage risk, build and run a security program, and lead incident management, all in business terms. If your job is moving from “doing security” to “deciding what security the organization needs and proving it works,” CISM is built for that shift.
This guide covers who CISM is for, the exam facts, the experience rule and waivers, the four domains (current and November 2026 weights), the full cost including annual fees, a study plan, career value, and how CISM compares with CISSP, CCSP and SecurityX. For the wider picture, see Best Cybersecurity Certifications in 2026.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Who CISM is for
- Security managers, team leads and program owners who report on risk to executives
- Senior analysts and engineers moving into management or governance roles
- Aspiring CISOs and information security officers
- GRC, risk and compliance professionals who own security policy and control frameworks
CISM isn’t a technical exam. Questions describe a business situation and ask what the security manager should do first, or what matters most. Candidates with deep technical backgrounds often struggle because the “most technical” answer is rarely the right one.
CISM exam facts (2026)
| Item | Details |
|---|---|
| Exam content outline | Current outline through November 2, 2026; updated outline from November 3, 2026 |
| Number of questions | 150 multiple-choice |
| Time limit | 4 hours (240 minutes) |
| Scoring | Scaled 200 to 800; 450 or higher to pass |
| Where you test | PSI test centers or online with remote proctoring |
| Registration | Continuous; schedule as early as 48 hours after paying, and your eligibility lasts six months |
| Exam price | US$575 for ISACA members, US$760 for non-members |
| Application fee | US$50 (one time, after you pass) |
| Experience | Five years of information security management experience across at least three of the four domains; up to two years can be waived |
| Annual maintenance fee | US$45 for members, US$85 for non-members |
| CPE | At least 20 hours a year and 120 hours per three-year period |
Sources: ISACA’s CISM page, certification requirements, maintenance requirements and the ISACA Exam Candidate Guide (version 1.26).
The CISM experience requirement (the five-year rule)
You can take the CISM exam without any experience. To become certified, you need to apply with verified work experience (ISACA):
- Five years of professional information security management work experience within the CISM job practice areas, covering at least three of the four CISM domains.
- Timing: The experience must fall within the 10 years before you apply, and you have five years from the date you pass the exam to submit your application.
- Verification: A supervisor or manager verifies your experience on the application.
- Waivers: ISACA’s Exam Candidate Guide says experience waivers are available for a maximum of two years (ISACA). Check the current CISM application in MyISACA to see which substitutions qualify before you count on one.
A common path is to pass the exam while you’re still building management experience, then apply once you have it, as long as you stay inside the five-year window.
The four CISM domains and their weights
| Domain | Current weight (through Nov 2, 2026) | From Nov 3, 2026 | What it covers |
|---|---|---|---|
| 1. Information Security Governance | 17% | 18% | Organizational culture, legal and regulatory requirements, roles and responsibilities, security strategy, governance frameworks, budgets and business cases |
| 2. Information Security Risk Management | 20% | 20% | Emerging threats, vulnerability and control deficiency analysis, risk assessment, risk treatment options, risk and control ownership, monitoring and reporting |
| 3. Information Security Program | 33% | 33% | Program resources, asset classification, standards and frameworks, policies, metrics, control design, implementation and testing, awareness training, third-party management and reporting |
| 4. Incident Management | 30% | 29% | Incident response plans, business impact analysis, BCP and DRP, incident classification, testing, investigation, containment, communications, eradication, recovery and post-incident review |
Current weights and topics: ISACA CISM exam content outline. November 2026 weights and new content areas: ISACA press release, September 10, 2026. The November update adds enterprise architecture and information security architecture and puts more emphasis on security strategy and program development. If you test on or after November 3, ISACA strongly recommends the updated prep materials.
What CISM costs in 2026
- Exam: US$575 for ISACA members or US$760 for non-members. ISACA membership has its own annual dues, so compare the saving with the dues for your region before joining.
- Application processing fee: US$50, paid once when you apply for certification.
- Annual maintenance fee: US$45 a year for members or US$85 for non-members, due by January 1 each year. If you hold three or more ISACA certifications, each additional one costs less to renew.
- Prep: ISACA sells a review manual, a questions-and-answers database and an online review course. Third-party courses and books are also common.
A non-member who studies on their own pays US$760 plus US$50 to get certified, then US$85 a year to keep it. A member pays US$575 plus US$50, then US$45 a year, plus membership dues.
A 10-week CISM study plan
This assumes about eight hours a week and some real security experience. Check your test date first: before November 3, 2026 use the current outline; on or after it, use the updated materials.
- Weeks 1 to 2: the manager’s mindset. Read the exam content outline and the supporting tasks. For every topic, ask “what does the business need here?” before “how would I fix it?” This is the single biggest adjustment for technical candidates.
- Weeks 3 to 4: governance and strategy. Governance vs management, strategy aligned to business goals, frameworks, policies vs standards vs procedures, business cases and metrics that executives care about.
- Weeks 5 to 6: risk management. Risk assessment methods, risk appetite and tolerance, treatment options, control ownership and risk reporting. Know who owns a risk (the business) and who advises (security).
- Week 7: the security program. Domain 3 is a third of the exam: program resources, control design and testing, awareness, third-party risk and reporting. If you’re testing after November 3, add enterprise and security architecture.
- Week 8: incident management. IR plans vs BCP vs DRP, business impact analysis, RTO and RPO, escalation and communication, and post-incident reviews.
- Weeks 9 to 10: practice. Work through a large question bank in timed blocks and study the explanations, especially for questions you got right by luck. Book the exam when you’re consistently passing practice sets.
Is CISM worth it? Jobs and salary
CISM is aimed at information security managers, and ISACA says more than 111,000 people have earned it since 2002 (ISACA). ISACA’s CISM page advertises an average annual salary of “US$149K+” for holders; that’s ISACA’s own figure for its certification, not an independent survey (ISACA).
For an independent benchmark, BLS reports a median pay of $175,140 in May 2025 for computer and information systems managers, the category that includes IT security managers, and projects 16% growth from 2025 to 2035 (BLS). Pay depends heavily on scope, industry and location; the certification helps you get considered, and your track record does the rest.
CISM vs CISSP, CCSP and SecurityX
- CISM vs CISSP: The most common comparison. CISSP is broader and covers technical domains in more depth; CISM is narrower and fully management-focused. Both require five years of experience. Many security leaders hold both. If you manage a security program, CISM maps more directly to your job; if you’re a senior practitioner or architect, start with CISSP.
- CISM vs CCSP: CCSP is a technical cloud security certification from ISC2. CISM is about running the whole program. They complement each other well for cloud-heavy organizations.
- CISM vs SecurityX: SecurityX (formerly CASP+) is CompTIA’s hands-on advanced certification for security architects and senior engineers. It’s the technical path; CISM is the management path. If your focus is audit and assurance rather than running the program, ISACA’s CISA is the better fit.
- Coming from CompTIA? If you hold Security+ or CySA+ and want to move toward leadership, CISM is a logical long-term target once you have management experience.
Planning your next certification? See the full certification roadmap for the order to take them by career goal.
What I would tell a friend starting CISM
Stop thinking like the person who fixes the problem and start thinking like the person who has to explain it to the board. Read every question as the security manager of a business that has goals, a budget and a risk appetite. And keep up with real incidents: the best CISM answers look a lot like what good security leaders actually did when things went wrong.
Your board will ask about the breach in the news. Be ready. The CyberExperts Daily Brief covers what changed in security and why it matters, in five minutes, weekday mornings. Get tomorrow’s brief.
Frequently asked questions
How many questions are on the CISM exam?
150 multiple-choice questions in four hours (240 minutes).
What is the passing score for CISM?
450 on ISACA’s scaled score range of 200 to 800.
How much does the CISM exam cost?
US$575 for ISACA members and US$760 for non-members, plus a one-time US$50 application fee after you pass. Keeping CISM costs US$45 a year for members or US$85 for non-members.
What are the CISM experience requirements?
Five years of information security management experience across at least three of the four CISM domains, gained within the 10 years before you apply. You have five years after passing the exam to apply, and ISACA allows experience waivers for a maximum of two years.
Can I take CISM without experience?
Yes. Anyone can take the exam. You need the experience only when you apply for certification, within five years of passing.
What is changing on the CISM exam in November 2026?
From November 3, 2026, the exam follows an updated content outline. The four domains stay the same, but the weights become 18% governance, 20% risk management, 33% program and 29% incident management, and ISACA adds enterprise architecture and information security architecture.
Should I get CISM or CISSP first?
If you already manage a security program, CISM fits your job more directly. If you’re a senior practitioner, engineer or architect, CISSP is usually the first choice. Many security leaders eventually hold both.
Sources
- ISACA, CISM certification (exam pricing, registration): isaca.org
- ISACA, CISM exam content outline: isaca.org
- ISACA, How to get CISM certified (experience requirements): isaca.org
- ISACA, Maintain CISM certification (CPE and fees): isaca.org
- ISACA, Exam Candidate Guide v1.26 (format, scoring, waivers): isaca.org
- ISACA press release, ISACA updates CISM exam content outline (September 10, 2026): isaca.org
- BLS, Computer and information systems managers: bls.gov
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.