Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Certification Guide

The Certified Information Security Manager
Certification Explained.

Everything you need to know about ISACA's flagship security management certification as of 2026, covering the four domains, exam format, experience requirements, career paths, DoD 8140 status, and how CISM compares to CISSP and CISA. A complete reference guide for anyone weighing the CISM or trying to understand what it covers.

CISM_FAST_FACTS
Issuer: ISACA
Exam: 150 questions, 4 hours
Passing Score: 450 / 800
Experience: 5 years (3 in management)
DoD 8140 Approved (Advanced)
4 CISM Domains 5 YRS Experience Required 150 Exam Questions 4-HOUR Exam SINCE 2002 ISACA Issued
UPDATED 2026
The CISM Domains

Four Domains of Practice

01

Information Security Governance

Security strategy, governance frameworks, and alignment with the business. 17% of the exam.

02

Information Security Risk Management

Identifying, assessing, treating, and reporting on information risk. 20% of the exam.

03

Information Security Program

Building and running the program: resources, controls, and metrics. The heaviest domain at 33%.

04

Incident Management

Preparedness, response, recovery, and continuity. 30% of the exam.

Overview

What Is the Certified Information Security Manager?

CISM is ISACA's flagship security management certification, first administered in 2002 and held by more than 107,000 professionals worldwide today.

It validates the ability to build, lead, and govern an enterprise information security program across four domains. The point isn't proving you can configure a control. It's proving you can think like a security manager: aligning security with business goals, weighing risk against cost, and answering for the program to the people who run the organization.

The credential is ANAB-accredited under ISO/IEC 17024, approved under DoD 8140 at the Advanced level, and gated behind a five-year experience requirement that keeps it firmly in management territory. CISM is issued and maintained by ISACA, the nonprofit that has administered the program since 2002.

2002 First Administered
4 Domains
5 Yr Experience
Why CISM Matters

Why Is CISM So Widely Recognized?

Four things that have made CISM the credential most often named when employers describe a security management hire.

Built for the Management Track, Not the Tools

Most security certifications test whether you can do the work. CISM tests whether you can run the program. Its questions are scenario based and management focused, asking for the right business decision rather than the right command, which is exactly why it reads as a leadership credential.

A Global Management Standard

More than two decades in, CISM is the credential employers most often list when they want someone to own a security program. It reads the same in a private enterprise, a consultancy, or a federal contract, which is rare for a management-level certification.

Tied to Management-Level Pay

As of 2026, CISM holders in the US commonly land in the $130,000 to $175,000 range, with directors and CISOs going higher. Our breakdown of CISM's advantages covers the career math.

DoD 8140 Approved

CISM is an approved foundational qualification under DoD Manual 8140.03 at the Advanced proficiency level, mapped to thirteen work roles in the DoD Cyber Workforce Framework (DCWF) across the Cybersecurity, Cyberspace Enabler, and Data/AI elements.

With element-level qualification now mandatory across the department, an approved credential like CISM is what lets people fill those management roles. Current qualification matrices are published at the DoD Cyber Exchange.

Advanced Proficiency 13 DCWF Roles 3 Workforce Elements
Fast Facts

What Are the Key Facts About CISM?

Everything you need to know about the certification, the exam structure, and how to maintain CISM as of 2026.

01

The Certification

Certification Name
Certified Information Security Manager (CISM)
Issued By
ISACA
Exam Outline
2022 job practice (current to Nov 2, 2026)
First Administered
2002
Prerequisites
5 yrs infosec, 3 yrs in management
Experience Waiver
Up to 2 years (credential or degree)
Test-First Path
Pass exam, apply within 5 years
Accreditation
ANAB-accredited (ISO/IEC 17024)
DoD 8140 Status
Approved at Advanced (13 DCWF roles)
02

Exam & Maintenance

Exam Format
Multiple choice, scenario based
Number of Items
150 questions
Exam Duration
4 hours
Passing Score
450 out of 800
Exam Cost
$575 member / $760 non-member
Registration
Continuous, 365-day eligibility
Validity
3 years
CPE Requirement
120 CPEs over 3 years (20 min/yr)
Maintenance
Annual maintenance fee to ISACA
Going Deeper

What Comes After the CISM?

CISM puts you on the management track. From there, professionals tend to broaden into senior security leadership or deepen into enterprise governance. These are the credentials that most often come next.

CISSP (Breadth)

The ISC2 Certified Information Systems Security Professional adds broad technical depth across eight domains. It requires five years of experience and pairs well with CISM for people who want both the management credential and the broad security one.

CCISO (Executive)

The EC-Council Certified CISO is aimed at the executive seat itself, covering governance, finance, and program leadership at the top of the org chart. It expects five years of experience across its leadership domains.

CGEIT (Governance)

ISACA's Certified in the Governance of Enterprise IT goes deep on IT governance at the enterprise level. It suits people moving from security management toward board-level governance and requires five years of related experience.

Certification Roadmap

Where Does CISM Fit in Your Career?

CISM is rarely a candidate's first certification. It sits at the point where a hands-on security career turns toward management, building on foundational credentials and leading into senior leadership, governance, and audit paths.

STAGE 02 You Are Here

Management Credential

The pivot point

PRIMARY
CISM
ISACA · Certified Information Security Manager
Test-First Path
ISACA · Pass first, apply within 5 years
STAGE 03

Specialize

Pick your path

Leadership
Governance & Risk
Audit
Decision Point

Is CISM Right For You?

Two questions to answer before you commit: can you certify, and should you pursue CISM specifically. Here's a straight answer to both.

Q1

Do You Qualify for CISM?

Path A

5+ Years, With Management Experience

You can certify in full.

You have five years of professional information security experience, with at least three of those years in security management across three or more of the four domains. An approved credential or degree can waive up to two years. Pass the exam, submit your application, and you hold the full CISM.

Path B

Not Quite at the Experience Bar

You can still pass now.

Sit the exam before you meet the full requirement. Once you pass, you have up to five years to submit your application as you finish earning the experience, so the exam never has to wait on your resume. Experience can count if it falls within the ten years before you apply.

Q2

Is CISM the Right Certification for Your Goals?

CISM Is a Strong Fit If...

  • You have security experience and you're moving from hands-on work toward management, governance, or leadership
  • You need a DoD 8140 approved credential at the Advanced level for a management role in federal or contractor work
  • You want a credential that proves you can run a security program, not just operate the tools inside it
  • You keep seeing CISM listed as required or preferred for the manager and director roles you want
  • You're aiming at a CISO or security director track and need the credential employers expect
  • You want a globally recognized management credential with more than two decades of standing

Consider Alternatives If...

  • You're early in your career without security fundamentals yet, start with Security+ or SSCP first
  • You want broad technical depth across the whole security field, where CISSP is the wider credential
  • You want a deeply hands-on technical track and prefer performance-based exams, look at PenTest+ or CySA+
  • Your work centers on IT audit and assurance, where CISA is the tighter fit
  • Your focus is enterprise IT risk specifically, where CRISC is purpose built
  • You don't yet work in or near security management and the questions would feel abstract
Career Paths

What Jobs Can You Get With CISM?

CISM maps to management and leadership roles across the private sector and the federal cyber workforce. Several of these are DCWF work roles where CISM qualifies at the Advanced level.

Security Management

Information Systems Security Manager

Owns the security posture of a system or program. DCWF work role 722, one of the most common roles where DoD 8140 calls for a CISM at the Advanced proficiency level.

Risk and Assessment

Security Control Assessor

Evaluates whether security controls are implemented correctly and operating as intended. DCWF work role 612, where CISM qualifies at the Advanced level.

Authorization

Authorizing Official

Holds the authority to accept risk and authorize a system to operate. A senior accountability role (DCWF 611) that leans on CISM-level governance and risk judgment.

Strategy

Cyber Policy and Strategy Planner

Develops cyber policy and long-range strategy for an organization. DCWF work role 752, mapped to CISM at the Advanced level under the Cyberspace Enabler element.

Leadership

CISO / Security Director

Sets security strategy at the executive level. CISM is frequently the credential employers expect before handing someone the security program for an enterprise.

Governance

IT Program Auditor

Reviews how IT programs are governed, funded, and run against policy. DCWF work role 805, where CISM qualifies at the Advanced level.

Comparison

How Does CISM Compare to CISSP and CISA?

All three are senior credentials, but they aim at different work: management, broad security, and audit. Here's how they line up.

  CISM CISSP CISA
Issuer ISACA ISC2 ISACA
Focus Security management and governance Broad security across 8 domains Information systems audit
Exam Format 150 questions, 4 hours Adaptive, 100 to 150 items, 3 hrs 150 questions, 4 hours
Experience 5 yrs infosec, 3 in management 5 yrs in 2+ domains 5 yrs in IS audit, control, or security
Passing Score 450 / 800 700 / 1000 450 / 800
Renewal 120 CPEs over 3 years 120 CPEs over 3 years 120 CPEs over 3 years
DoD 8140 Approved Yes (Advanced) Yes (Advanced) Yes (Advanced)
Best For Security managers and governance leads Architects and senior generalists IT auditors and assurance pros

Pricing and renewal details vary by region and membership status. Many practitioners eventually hold more than one of these credentials.

Ready to Get Certified?

Train for CISM with Training Camp.

Our official ISACA CISM boot camp covers all four domains over four days, with your exam voucher, official courseware, and a free retake guarantee included, so experienced practitioners leave exam-ready.

View Boot Camp
Dive Deeper

CISM Articles and Guides.

Exam strategy, certification decisions, salary data, and career outcomes for CISM.

Featured Decision Guide

CISSP vs CISM: Which One Should I Get First?

A straight answer to the question Training Camp hears most: which credential makes sense as your next step, based on where you are now and where you want your career to go.

Read Article →
Exam Strategy

CISM Domain Breakdown: Where Candidates Actually Lose Points

Domains 3 and 4 make up 63% of the exam, and that is where most scores are won or lost. A look at the weighting and the spots candidates tend to underestimate.

Read Article →
Exam Prep

How To Pass the CISM Exam on the First Attempt

A practical approach to the scenario-based questions that trip people up, plus study strategy and exam-day tactics for the 150-question, four-hour exam.

Read Article →
Career Value

CISM Certification Advantages and Why It Is Worth It

The concrete ways CISM changes a career, from access to management roles to higher pay, and why it has become a near-standard credential for moving into security leadership.

Read Article →
Salary

CISM Certification: A Salary Guide

A deep look at CISM pay, including how role, experience, location, and industry move the numbers, and why management-focused credentials tend to command higher salaries.

Read Article →
GRC Careers

Best Certifications for GRC Careers

Governance, risk, and compliance hiring is a maze of overlapping credentials. How CISM fits alongside CISA, CRISC, and CISSP, and when it is the right bet for a GRC track.

Read Article →
Comparison

CISM vs CISSP: Which Security Certification Is Best for You?

A full comparison of the two credentials across exams, costs, and career outcomes, with a clear read on which one fits a management track versus a broad technical one.

Read Article →
Curriculum

Inside the Four CISM Domains.

The CISM job practice is organized into four domains, each carrying its own weight on the exam. Click any domain for what it covers.

Domains 01-02

Governance to Risk
01 Information Security Governance 17%

Establishing and maintaining an information security governance framework, building a security strategy aligned with business goals, and integrating security into enterprise governance and decision making.

02 Information Security Risk Management 20%

Identifying, assessing, and treating information risk. Risk assessment methodologies, risk response and reporting, and the way ISACA frames risk decisions in a management context.

Domains 03-04

Program to Incident
03 Information Security Program 33%

The heaviest domain on the exam. Building and running the security program end to end: resources, controls, metrics, third-party management, and integrating security into business operations.

04 Incident Management 30%

Preparing for, detecting, and responding to security incidents. Incident response planning, business continuity and disaster recovery, and post-incident review and improvement.

Domains and weights reflect the ISACA CISM Exam Content Outline from the 2022 job practice, current through November 2, 2026. A new outline takes effect November 3, 2026.

Frequently Asked Questions

Common Questions About CISM.

The questions candidates ask most often when researching the Certified Information Security Manager certification.

What is the CISM certification?

CISM is ISACA's flagship security management certification. It validates the ability to build, lead, and govern an enterprise information security program across four domains, and it's built for experienced practitioners moving from hands-on security into management and leadership roles.

Who should get the CISM?

CISM fits experienced security professionals who are moving toward management, governance, and leadership roles rather than staying on a purely technical track. It isn't an entry-level certification. If you're starting out, Security+ or SSCP is usually the better first step.

How much does the CISM exam cost in 2026?

As of 2026 the CISM exam costs $575 for ISACA members and $760 for non-members. There's also a separate certification application fee. Many candidates join ISACA before registering, since the membership fee is often less than the exam discount it unlocks.

What is the CISM exam like?

The CISM exam is 150 multiple-choice questions over a four-hour window. The questions are scenario based and ask for the best management response rather than a single technical fact, so several answers often look plausible. You need a scaled score of 450 out of 800 to pass.

What experience do you need for the CISM?

CISM requires five years of professional information security work experience, with at least three of those years in information security management across three or more of the four domains. Up to two years can be waived with an approved credential or degree. Experience must fall within the ten years before applying or within five years after passing.

Can you take the CISM exam without the experience?

Yes. You can sit and pass the exam before you have the required experience, then submit your certification application once you meet it. You have up to five years after passing to complete the application, so the exam never has to wait on your work history.

What are the four CISM domains?

The four CISM domains are Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management. Information Security Program is the heaviest at 33 percent, and together with Incident Management at 30 percent the two make up nearly two-thirds of the exam.

How do I maintain my CISM certification?

CISM is maintained on a three-year cycle. You earn 120 Continuing Professional Education (CPE) credits across the cycle, with a minimum of 20 credits each year, and pay an annual maintenance fee to ISACA. You also agree to follow the ISACA Code of Professional Ethics.

Is CISM approved for DoD 8140?

Yes. CISM appears on the DoD 8140 Approved Qualifications Matrix V2.1 at the Advanced proficiency level, mapped to thirteen DCWF work roles including Information Systems Security Manager, Security Control Assessor, Authorizing Official, and Cyber Policy and Strategy Planner. See the full DoD 8140 work role paths.

What is the difference between CISM, CISSP, and CISA?

CISM from ISACA focuses on security management and governance, CISSP from ISC2 is a broad security credential spanning eight domains, and CISA from ISACA focuses on information systems audit and assurance. Many professionals hold more than one and pick their first based on whether they're heading toward management, broad security, or audit.

Is the CISM exam changing in 2026?

Yes. ISACA's current CISM Exam Content Outline is in effect through November 2, 2026. A new outline takes effect November 3, 2026, with more emphasis on security strategy and program development and new content on enterprise architecture and security architecture. Exams before that date test the current four-domain outline.

Is CISM worth it in 2026?

For experienced professionals heading into security management or leadership, CISM remains one of the strongest credentials available in 2026. It carries broad employer recognition, satisfies DoD 8140 at the Advanced level, and is consistently tied to higher management-track pay. It's less useful for those early in their careers or committed to a purely hands-on technical role.

Get In Touch

Have Questions About CISM?

Whether you're weighing the certification, working out funding, or planning training for a team, tell us where you are and we'll help you map out the right path.

+1
    100% Secure. NDA Compliant.
    ISACA CISM Boot Camp 4-Day Boot Camp · Exam Voucher Included
    View Boot Camp