Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about ISACA's flagship security management certification as of 2026, covering the four domains, exam format, experience requirements, career paths, DoD 8140 status, and how CISM compares to CISSP and CISA. A complete reference guide for anyone weighing the CISM or trying to understand what it covers.
Security strategy, governance frameworks, and alignment with the business. 17% of the exam.
Identifying, assessing, treating, and reporting on information risk. 20% of the exam.
Building and running the program: resources, controls, and metrics. The heaviest domain at 33%.
Preparedness, response, recovery, and continuity. 30% of the exam.
CISM is ISACA's flagship security management certification, first administered in 2002 and held by more than 107,000 professionals worldwide today.
It validates the ability to build, lead, and govern an enterprise information security program across four domains. The point isn't proving you can configure a control. It's proving you can think like a security manager: aligning security with business goals, weighing risk against cost, and answering for the program to the people who run the organization.
The credential is ANAB-accredited under ISO/IEC 17024, approved under DoD 8140 at the Advanced level, and gated behind a five-year experience requirement that keeps it firmly in management territory. CISM is issued and maintained by ISACA, the nonprofit that has administered the program since 2002.
Four things that have made CISM the credential most often named when employers describe a security management hire.
Most security certifications test whether you can do the work. CISM tests whether you can run the program. Its questions are scenario based and management focused, asking for the right business decision rather than the right command, which is exactly why it reads as a leadership credential.
More than two decades in, CISM is the credential employers most often list when they want someone to own a security program. It reads the same in a private enterprise, a consultancy, or a federal contract, which is rare for a management-level certification.
As of 2026, CISM holders in the US commonly land in the $130,000 to $175,000 range, with directors and CISOs going higher. Our breakdown of CISM's advantages covers the career math.
CISM is an approved foundational qualification under DoD Manual 8140.03 at the Advanced proficiency level, mapped to thirteen work roles in the DoD Cyber Workforce Framework (DCWF) across the Cybersecurity, Cyberspace Enabler, and Data/AI elements.
With element-level qualification now mandatory across the department, an approved credential like CISM is what lets people fill those management roles. Current qualification matrices are published at the DoD Cyber Exchange.
Everything you need to know about the certification, the exam structure, and how to maintain CISM as of 2026.
CISM puts you on the management track. From there, professionals tend to broaden into senior security leadership or deepen into enterprise governance. These are the credentials that most often come next.
The ISC2 Certified Information Systems Security Professional adds broad technical depth across eight domains. It requires five years of experience and pairs well with CISM for people who want both the management credential and the broad security one.
The EC-Council Certified CISO is aimed at the executive seat itself, covering governance, finance, and program leadership at the top of the org chart. It expects five years of experience across its leadership domains.
ISACA's Certified in the Governance of Enterprise IT goes deep on IT governance at the enterprise level. It suits people moving from security management toward board-level governance and requires five years of related experience.
CISM is rarely a candidate's first certification. It sits at the point where a hands-on security career turns toward management, building on foundational credentials and leading into senior leadership, governance, and audit paths.
Build the baseline
The pivot point
Two questions to answer before you commit: can you certify, and should you pursue CISM specifically. Here's a straight answer to both.
You can certify in full.
You have five years of professional information security experience, with at least three of those years in security management across three or more of the four domains. An approved credential or degree can waive up to two years. Pass the exam, submit your application, and you hold the full CISM.
You can still pass now.
Sit the exam before you meet the full requirement. Once you pass, you have up to five years to submit your application as you finish earning the experience, so the exam never has to wait on your resume. Experience can count if it falls within the ten years before you apply.
CISM maps to management and leadership roles across the private sector and the federal cyber workforce. Several of these are DCWF work roles where CISM qualifies at the Advanced level.
Owns the security posture of a system or program. DCWF work role 722, one of the most common roles where DoD 8140 calls for a CISM at the Advanced proficiency level.
Evaluates whether security controls are implemented correctly and operating as intended. DCWF work role 612, where CISM qualifies at the Advanced level.
Holds the authority to accept risk and authorize a system to operate. A senior accountability role (DCWF 611) that leans on CISM-level governance and risk judgment.
Develops cyber policy and long-range strategy for an organization. DCWF work role 752, mapped to CISM at the Advanced level under the Cyberspace Enabler element.
Sets security strategy at the executive level. CISM is frequently the credential employers expect before handing someone the security program for an enterprise.
Reviews how IT programs are governed, funded, and run against policy. DCWF work role 805, where CISM qualifies at the Advanced level.
All three are senior credentials, but they aim at different work: management, broad security, and audit. Here's how they line up.
| CISM | CISSP | CISA | |
|---|---|---|---|
| Issuer | ISACA | ISC2 | ISACA |
| Focus | Security management and governance | Broad security across 8 domains | Information systems audit |
| Exam Format | 150 questions, 4 hours | Adaptive, 100 to 150 items, 3 hrs | 150 questions, 4 hours |
| Experience | 5 yrs infosec, 3 in management | 5 yrs in 2+ domains | 5 yrs in IS audit, control, or security |
| Passing Score | 450 / 800 | 700 / 1000 | 450 / 800 |
| Renewal | 120 CPEs over 3 years | 120 CPEs over 3 years | 120 CPEs over 3 years |
| DoD 8140 Approved | Yes (Advanced) | Yes (Advanced) | Yes (Advanced) |
| Best For | Security managers and governance leads | Architects and senior generalists | IT auditors and assurance pros |
Pricing and renewal details vary by region and membership status. Many practitioners eventually hold more than one of these credentials.
Our official ISACA CISM boot camp covers all four domains over four days, with your exam voucher, official courseware, and a free retake guarantee included, so experienced practitioners leave exam-ready.
Exam strategy, certification decisions, salary data, and career outcomes for CISM.
A straight answer to the question Training Camp hears most: which credential makes sense as your next step, based on where you are now and where you want your career to go.
Domains 3 and 4 make up 63% of the exam, and that is where most scores are won or lost. A look at the weighting and the spots candidates tend to underestimate.
A practical approach to the scenario-based questions that trip people up, plus study strategy and exam-day tactics for the 150-question, four-hour exam.
The concrete ways CISM changes a career, from access to management roles to higher pay, and why it has become a near-standard credential for moving into security leadership.
A deep look at CISM pay, including how role, experience, location, and industry move the numbers, and why management-focused credentials tend to command higher salaries.
Governance, risk, and compliance hiring is a maze of overlapping credentials. How CISM fits alongside CISA, CRISC, and CISSP, and when it is the right bet for a GRC track.
A full comparison of the two credentials across exams, costs, and career outcomes, with a clear read on which one fits a management track versus a broad technical one.
The CISM job practice is organized into four domains, each carrying its own weight on the exam. Click any domain for what it covers.
Establishing and maintaining an information security governance framework, building a security strategy aligned with business goals, and integrating security into enterprise governance and decision making.
Identifying, assessing, and treating information risk. Risk assessment methodologies, risk response and reporting, and the way ISACA frames risk decisions in a management context.
The heaviest domain on the exam. Building and running the security program end to end: resources, controls, metrics, third-party management, and integrating security into business operations.
Preparing for, detecting, and responding to security incidents. Incident response planning, business continuity and disaster recovery, and post-incident review and improvement.
Domains and weights reflect the ISACA CISM Exam Content Outline from the 2022 job practice, current through November 2, 2026. A new outline takes effect November 3, 2026.
The questions candidates ask most often when researching the Certified Information Security Manager certification.
CISM is ISACA's flagship security management certification. It validates the ability to build, lead, and govern an enterprise information security program across four domains, and it's built for experienced practitioners moving from hands-on security into management and leadership roles.
CISM fits experienced security professionals who are moving toward management, governance, and leadership roles rather than staying on a purely technical track. It isn't an entry-level certification. If you're starting out, Security+ or SSCP is usually the better first step.
As of 2026 the CISM exam costs $575 for ISACA members and $760 for non-members. There's also a separate certification application fee. Many candidates join ISACA before registering, since the membership fee is often less than the exam discount it unlocks.
The CISM exam is 150 multiple-choice questions over a four-hour window. The questions are scenario based and ask for the best management response rather than a single technical fact, so several answers often look plausible. You need a scaled score of 450 out of 800 to pass.
CISM requires five years of professional information security work experience, with at least three of those years in information security management across three or more of the four domains. Up to two years can be waived with an approved credential or degree. Experience must fall within the ten years before applying or within five years after passing.
Yes. You can sit and pass the exam before you have the required experience, then submit your certification application once you meet it. You have up to five years after passing to complete the application, so the exam never has to wait on your work history.
The four CISM domains are Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management. Information Security Program is the heaviest at 33 percent, and together with Incident Management at 30 percent the two make up nearly two-thirds of the exam.
CISM is maintained on a three-year cycle. You earn 120 Continuing Professional Education (CPE) credits across the cycle, with a minimum of 20 credits each year, and pay an annual maintenance fee to ISACA. You also agree to follow the ISACA Code of Professional Ethics.
Yes. CISM appears on the DoD 8140 Approved Qualifications Matrix V2.1 at the Advanced proficiency level, mapped to thirteen DCWF work roles including Information Systems Security Manager, Security Control Assessor, Authorizing Official, and Cyber Policy and Strategy Planner. See the full DoD 8140 work role paths.
CISM from ISACA focuses on security management and governance, CISSP from ISC2 is a broad security credential spanning eight domains, and CISA from ISACA focuses on information systems audit and assurance. Many professionals hold more than one and pick their first based on whether they're heading toward management, broad security, or audit.
Yes. ISACA's current CISM Exam Content Outline is in effect through November 2, 2026. A new outline takes effect November 3, 2026, with more emphasis on security strategy and program development and new content on enterprise architecture and security architecture. Exams before that date test the current four-domain outline.
For experienced professionals heading into security management or leadership, CISM remains one of the strongest credentials available in 2026. It carries broad employer recognition, satisfies DoD 8140 at the Advanced level, and is consistently tied to higher management-track pay. It's less useful for those early in their careers or committed to a purely hands-on technical role.
Whether you're weighing the certification, working out funding, or planning training for a team, tell us where you are and we'll help you map out the right path.