CISM Certification, formally Certified Information Security Manager, is ISACA’s management-focused credential for professionals who govern, design, oversee, and improve enterprise information security programs. The exam contains 150 multiple-choice questions and lasts four hours. Anyone may take the exam, but earning the certification requires five years of professional information security management experience across at least three of the four CISM domains. Current exam fees are US$575 for ISACA members and US$760 for non-members, plus a US$50 certification application fee after passing.
The CISM certification full form is Certified Information Security Manager. It is issued by ISACA and focuses on managing information security at an organizational level rather than testing only technical security skills.
When professionals ask, “What is CISM certification?”, the most useful distinction is that CISM evaluates whether you understand how security should support business objectives.
The certification covers four core areas:
Information Security Governance
Information Security Risk Management
Information Security Program
Incident Management
These areas reflect responsibilities commonly handled by security managers, information security leaders, governance professionals, risk managers and professionals moving toward senior cybersecurity management.
ISACA describes CISM as a management-focused certification for professionals involved in developing and managing enterprise information security programs.
There is an important difference between CISM exam eligibility and the requirements for becoming officially CISM certified.
Yes.
The CISM certification exam is open to anyone interested in information security. You do not have to complete the full work-experience requirement before sitting for the examination.
However, passing the exam alone does not immediately make you CISM certified.
To obtain the certification, ISACA currently requires:
Pass the CISM exam.
Have at least five years of professional information security management experience.
Your experience must cover at least three of the four CISM domains.
Relevant work experience must have been gained within the 10 years preceding your certification application.
Submit your certification application within five years of passing the exam.
Pay the US$50 application processing fee.
Agree to ISACA's Code of Professional Ethics and ongoing CPE requirements.
This distinction matters when researching CISM certification prerequisites: there is no five-year experience prerequisite merely to attempt the exam, but experience is required to receive the actual certification.
The current CISM certification exam cost depends on your ISACA membership status.
CISM Fee
ISACA Member
Non-Member
CISM Exam Registration
US$575
US$760
Certification Application
US$50
US$50
Annual CISM Maintenance Fee
US$45
US$85
ISACA currently lists the exam at US$575 for members and US$760 for non-members. After passing, candidates pay a US$50 application processing fee when applying for certification.
Once certified, professionals must also pay the annual maintenance fee. ISACA currently lists this as US$45 for members and US$85 for non-members.
Training courses, review manuals, practice-question databases and other preparation resources are separate from these certification fees.
The ISACA CISM certification exam contains:
Exam Detail
Current CISM Format
Questions
150 multiple-choice questions
Exam Duration
4 hours / 240 minutes
Delivery
Computer-based
Testing Options
PSI testing center or remote proctoring
Registration
Continuous
Main Domains
4
ISACA confirms that CISM is a 150-question, four-hour examination. It may be taken through authorized PSI testing locations or remote proctoring where available.
Candidates should avoid treating the CISM exam as a technical-memory test. Many questions are management-oriented and require identifying the action that best supports governance, risk ownership, business objectives or organizational priorities.
Candidates preparing for CISM Certification in 2026 need to pay particular attention to their planned exam date.
The current exam outline remains in effect until November 2, 2026.
CISM Domain
Current Weight
From Nov. 3, 2026
Information Security Governance
17%
18%
Information Security Risk Management
20%
20%
Information Security Program
33%
33%
Incident Management
30%
29%
Beginning November 3, 2026, ISACA will use its updated CISM Exam Content Outline. The four domains remain the same, but Governance increases from 17% to 18%, while Incident Management decreases from 30% to 29%.
The revised content also places greater emphasis on information security strategy and program development and introduces additional coverage relating to enterprise architecture and information security architecture. Updated preparation resources became available in September 2026.
Practical preparation point: if your exam is scheduled for November 3, 2026 or later, make sure your CISM training, study guide and practice questions follow the updated exam content.
Effective CISM certification training should go beyond definitions and memorization.
A strong CISM course should teach candidates how to think from the perspective of an information security manager.
This area connects security strategy with enterprise objectives, organizational structures, legal requirements, frameworks, responsibilities and strategic planning.
The key mindset is alignment: security decisions should support business objectives rather than operate independently of them.
Candidates need to understand risk assessment, threats, vulnerabilities, control deficiencies, risk response, ownership and risk reporting.
One common exam mistake is immediately choosing a technical control when the question first requires risk assessment, business impact analysis or management approval.
This is the largest CISM domain.
It covers areas such as security resources, asset classification, standards, policies, metrics, control selection, implementation, testing, security awareness, third-party management and reporting.
Candidates should understand incident readiness, response planning, business impact analysis, business continuity, disaster recovery, incident classification, investigation and post-incident improvement.
The CISM perspective is not simply “stop the attack.” It includes maintaining business resilience, coordinating stakeholders and improving controls based on lessons learned.
For professionals searching how to get CISM certification, the pathway is straightforward:
Review the applicable CISM Exam Content Outline.
Select structured CISM training and study materials.
Complete domain-based preparation and a CISM practice test program.
Register for the ISACA CISM exam.
Schedule the examination through PSI.
Pass the CISM certification exam.
Pay the US$50 application fee.
Document and verify the required professional experience.
Submit the CISM certification application within five years.
Maintain the credential through CPE and annual certification requirements.
ISACA requires certified professionals to earn at least 20 CPE hours annually and at least 120 CPE hours during each three-year reporting cycle.
A productive CISM certification course should combine conceptual knowledge with management-level scenario practice.
Start by learning each domain rather than immediately attempting hundreds of questions. Once the concepts are clear, use CISM practice tests to learn how ISACA frames management decisions.
Pay particular attention to words such as BEST, FIRST, MOST important and PRIMARY. Several answers may appear technically correct, but the examination expects the option that best fits governance and management priorities.
A useful preparation cycle is:
Learn → Review → Practice → Analyze mistakes → Retest.
Do not measure preparation simply by the number of practice questions completed. Your ability to explain why the correct answer is stronger than the alternatives is more valuable.
Candidates taking their exam after November 3, 2026 should specifically use study resources aligned with the new 2026 content outline.
The terms CISA CISM certification are sometimes searched together, but they represent different credentials.
CISA, or Certified Information Systems Auditor, is centered more heavily on information systems auditing, assurance, controls and assessment.
CISM, or Certified Information Security Manager, emphasizes security governance, risk management, security program management and incident management.
A professional working primarily in auditing may find CISA more directly connected to current responsibilities, while information security managers and professionals responsible for security programs may encounter more direct alignment with CISM.
Some professionals eventually earn both because audit assurance and security management responsibilities can overlap, but they should not be treated as interchangeable certifications.
Certified Information Security Manager training is particularly relevant for professionals working toward responsibilities such as:
Information Security Manager
Cybersecurity Manager
Security Governance Manager
Information Security Program Manager
GRC Manager
Security Risk Manager
Security Consultant
IT Risk Manager
Security Operations Leader
Technical professionals can also pursue CISM when moving from implementation-focused roles into positions that require budgeting, governance, risk decisions, policy development, program management and executive communication.
Before enrolling in a CISM course or CISM training program, establish your target exam date first.
Candidates testing before November 3, 2026 should prepare against the current CISM outline. Candidates testing on or after November 3, 2026 should use the updated ISACA CISM materials and domain coverage.
For structured CISM certification training, exam-focused preparation, practice questions and guided study support, explore the CISM training options available through NYTCC and build your study plan around the version of the examination you will actually take.
The most important preparation decision is not how many hours you study—it is whether those hours develop the management-focused judgment, risk perspective and governance mindset the CISM exam is designed to evaluate.