Skip to content
Getting Digital
ISACA certificationsISACA · exam CISM

Certified Information Security Manager (CISM)

CISM certifies the person accountable for an information security programme: governance, risk, programme development and incident management, judged from the chair rather than the keyboard.

Four hours, 150 questions, and five years of management experience behind it.

Exam facts

Exam code
CISM
Level
Expert
Field
Cybersecurity
Duration
240 minutes
Questions
150 multiple-choice questions
Passing score
450 on a scaled range of 200 to 800
Languages
English, German, Chinese, Japanese, Korean, SpanishLanguage list per ISACA's candidate guide as mirrored by its chapters; translated forms may be limited to certain testing windows.
Price
760 USD (read 12 September 2026)
Validity
3 years, renewable
Exam delivery
PSI (test centre or online proctored) in exam windows; registration on isaca.org, the certificate follows an application with an experience record

Prerequisites: Five years of information security management experience within the CISM job practice areas, gained in the ten years before applying (ISACA grants waivers for related credentials and degrees); the exam can be taken first.

Renewal: 120 CPE hours per three-year cycle with at least 20 a year, plus the annual maintenance fee of 45 USD (members) or 85 USD (non-members)

Source: exam page at ISACA · Price: Non-member exam fee; ISACA members pay 575 USD (isaca.org, read 2026-09-12); plus 50 USD application fee after passing and 45/85 USD annual maintenance

How to prepare

  1. 1. The vendor's free learning path

    ISACA publishes the exam objectives and a learning path free of charge — the authoritative source for scope and weighting. Open the learning path (opens in a new tab)

  2. 2. Online courses

    Courses and practice questions from the directory that target exactly this exam — details, price and the provider link (affiliate) are on the course page.

  3. 3. A practice test in the exam format

    MeasureUp sells a practice test for CISM with questions in the exam format, an explanation for every answer and a timed mode; the price shows in your currency on the shop page. Affiliate link.

    Practice test for CISM at MeasureUp (opens in a new tab)
  4. Book the exam

    Delivered by PSI (test centre or online proctored) in exam windows; registration on isaca.org, the certificate follows an application with an experience record. Schedule with ISACA (opens in a new tab)

Affiliate disclosure: the course and practice-test links above are affiliate links — buying through them may earn us a commission at no extra cost to you. The vendor's learning path and booking links carry no commission.

CISM is written from the chair, not the keyboard. Every one of its 150 questions assumes you cannot fix the problem yourself and asks what you would decide, delegate, document or escalate instead. Senior engineers find the content familiar and the stance foreign, and the stance is the exam. The candidate who reads a scenario and reaches for a technical remedy has already chosen the wrong answer, however correct the remedy.

A dated change worth planning around

  • An updated content outline takes effect on 3 November 2026. The date is published rather than speculated.
  • Material written for the current outline ages on that date, so check what any course or practice set targets before buying it.
  • A pass on either outline yields the same certification, since ISACA revises the syllabus rather than renaming the credential.
  • If you are ready before the change, sit it; should the date fall mid-preparation, switch to the revised outline once it appears.
  • The experience requirement is unaffected and remains five years of security management work with some substitutions.

Four domains, and where the weight sits

DomainRoughly what it covers
GovernanceStrategy, structures and who answers for what
Risk managementIdentifying, assessing and accepting exposure
Programme developmentBuilding and running the function, the largest share
Incident managementPreparing for and directing the response

Programme development and incident management together make up well over half the paper, and they are the domains practitioners assume they know. Running a function is not the same as being able to describe, in ISACA's terms, how a function should be built, resourced, measured and reported to a board. Incident management is examined as direction rather than response: who declares, who decides, who speaks to the regulator. Governance and risk are smaller, and they are where the exam's vocabulary is most particular, so candidates who have run programmes in organisations with their own dialect should learn ISACA's.

The certificate is claimed after the exam, not with it

Five years of information security management experience within the job practice areas, gained in the ten years before applying, is the requirement for certification, with waivers available for related credentials and degrees. The exam can be sat first. Upkeep afterwards is 120 continuing-education hours across each three-year cycle with at least 20 a year, plus an annual maintenance fee, lower for members.

How to sit it

Four hours, 150 multiple-choice questions, a scaled score from 200 to 800 with 450 to pass, delivered at PSI centres or by remote proctoring, and bookable on 48 hours' notice. English, German, Chinese, Japanese, Korean and Spanish forms exist, with translated forms sometimes limited to particular testing windows. The fee is the same as for ISACA's audit certificate and so is the maintenance schedule, which is why people who hold one often add the other later. Add them for the right reason: audit assesses what exists, management decides what should, and the two are rarely the same job.

What a question looks like

Written by us in the exam's style. It is not a real question from any question bank, and we do not publish those.

A business unit wants to deploy a system that does not meet the organisation's security standard. The unit argues the revenue opportunity outweighs the risk, and the deadline is immovable. What should the security manager do?

Blocking it and allowing it are both wrong. The exam wants the answer that puts the decision where the accountability sits, documented, with the risk articulated in terms the business owner can accept or decline. Technical candidates try to solve the security problem; the certificate is about who gets to carry the risk and whether they knew they were carrying it.

What it costs to get and to keep

ItemAmountNote
Exam fee, non-member760 USDISACA's published non-member price, identical in structure to its audit certificate (read 12 September 2026)
Exam fee, member575 USDmembership carries its own annual cost, so compare across the whole cycle rather than the sitting alone (read 12 September 2026)
Application processing fee50 USDseparate from the exam and required before certification (read 12 September 2026)
Annual maintenance, member45 USDeach year the certification is held; non-members pay more annually (read 12 September 2026)
Continuing educationnot publisheda minimum of 20 hours a year and at least 120 across three years, which rules out clearing the requirement in a single burst (read 12 September 2026)

How much preparation, from where you are

You run a security function
The exam describes your job, and the difficulty is answering as ISACA frames it rather than as your organisation operates. Programme development carries the largest share and is where practitioners assume rather than study.
You are a senior engineer moving into management
The content is learnable and the perspective is the work. Every question assumes you cannot simply fix the thing yourself, which is precisely the adjustment the role requires.
You hold the audit certificate already
Considerable overlap in vocabulary and a different stance: audit assesses what exists, management decides what should. Expect the incident and programme domains to be the genuinely new ground.

What passing this does not prove

  • Any technical capability whatsoever.
  • Whether you can win an argument with a business that has already decided.
  • Whether your programme would survive a budget round.
  • Current threats, which move faster than any content outline.

Against the alternatives

CISACertified Information Systems Auditor (CISA)
The audit counterpart from the same body, identically priced and maintained. Assess against decide: people hold both and use them in different rooms.
CISSPCertified Information Systems Security Professional (CISSP)
Broader, partly technical and more widely recognised outside governance circles. Choose this one when the work is genuinely running a programme rather than architecting one.
SC-200Microsoft Certified: Security Operations Analyst Associate
A hands-on analyst certificate on a specific platform. Beyond the shared word security there is no comparison, and mistaking one for the other wastes a considerable fee.

CISM — quick answers

Should I wait for the new outline?

Only if your preparation runs past 3 November 2026 anyway. A pass under either outline produces the same certification. What matters is that your material matches the outline you will sit, because buying a course written for the previous version shortly before the change is how people end up studying the wrong emphasis.

Is five years of management experience really required?

For the certification, yes, with substitutions available for certain qualifications and other credentials. You may sit the exam first and apply once the experience is there, which is the route many candidates take. Passing alone does not make you certified.

This or the audit credential?

Follow the job rather than the interest. If your work is assessing whether controls operate and evidencing it, take the audit one. If you are accountable for the programme and its budget, take this. Holding both is common later and rarely useful early.

How technical are the questions?

Barely. The scenarios mention systems, incidents and vulnerabilities, and the answers turn on accountability, documentation and decision rights rather than on configuration. A candidate who could not administer a server can pass this comfortably; a candidate who administers servers brilliantly can fail it by solving the wrong problem.

Can it be scheduled at short notice?

Yes. ISACA allows booking on 48 hours' notice at PSI centres or for remote proctoring, which suits candidates who want to sit soon after a practice score turns reliable rather than committing to a date months out. The translated forms are the exception: check the testing window for your language before assuming a date is available.

What comes next

Concepts this exam draws on

Glossary entries with the reason each one matters for CISM.

  • Uptime & SLA

    Incident management and business continuity are framed by service commitments.

  • Security Risk Assessment

    Information risk management is a domain of its own, and the exam wants the risk stated in business terms.

  • Incident Response

    Incident management is one of the four domains, examined as direction rather than technical response.

  • IAM

    Programme development includes governing who has access and how that is reviewed.

  • SOC

    Running the function that detects and responds is the programme-development domain's largest share.

  • Threat Modelling

    Governance decisions about what to protect rest on a structured view of what could go wrong.

A vendor certificate — not a degree and not an accredited qualification. Facts are from the vendor's exam page on the date shown; prices are list prices that vary by country and tax.

Last reviewed 12 September 2026 · Getting Digital