The short answer: CISA is ISACA's audit credential and CISM is ISACA's security management credential. CISA certifies that you can plan and execute IT audits, assess governance, and assure that controls actually work. CISM certifies that you can govern and run an information security program. Same certifying body, same exam format, two different seats at the table.
If your job is to examine systems and report on whether the controls hold up, that is the auditor's seat, and CISA fits. If your job is to own the security program, set its direction, and answer for it when something goes wrong, that is the manager's seat, and CISM fits. The rest of this post gives you the detail behind that one-line answer: what each exam covers, who each one is for, the logistics side by side, and which to take first.
What does the CISA exam cover?
CISA is built on five domains, weighted per the exam content outline effective August 2024:
| CISA domain | Weight |
|---|---|
| 1. Information Systems Auditing Process | 18% |
| 2. Governance and Management of IT | 18% |
| 3. Information Systems Acquisition, Development, and Implementation | 12% |
| 4. Information Systems Operations and Business Resilience | 26% |
| 5. Protection of Information Assets | 26% |
Domains 4 and 5 carry 52% of the exam between them, and they are technical territory: operations, backups, business continuity, identity and access management, encryption, cloud, network security. The catch, and the thing that surprises people coming from a hands-on background, is that CISA tests all of it from the auditor's seat. The question is never how to configure the control. It is how to assess whether the control exists, works, and produces evidence.
That framing runs through the whole exam. An engineer's instinct is to fix the problem; the CISA answer is usually to evaluate, report, and recommend. If you want the full picture of the exam itself, the pillar post What is the CISA exam? covers it in depth.
What does the CISM exam cover?
CISM is built on four domains. Under the current outline, effective 2022, the weights are:
| CISM domain | Weight |
|---|---|
| 1. Information Security Governance | 17% |
| 2. Information Security Risk Management | 20% |
| 3. Information Security Program | 33% |
| 4. Incident Management | 30% |
The center of gravity sits in Domains 3 and 4, which together make up 63% of the exam: building and running the security program, and managing incidents when the program is tested for real. That is a manager's job description, not an auditor's. CISM questions reward governance-over-tools thinking. The right answer tends to be the one that aligns security with business objectives, not the one that names the best technology.
One timing note if CISM is on your radar. ISACA has confirmed that the CISM exam content outline updates effective November 3, 2026, and its announcement flags new enterprise architecture and information security architecture content. The new domain-by-domain weights have not been published yet. If you plan to sit CISM after that date, check the outline in force when you book, because the table above describes the outline it replaces.
CISA has no such change pending. Its August 2024 outline is current, with no announced update.
Who is CISA for?
CISA is for people whose work is assessment and assurance. Typical titles: IT auditor, internal auditor moving into IT, IT audit manager, external audit and assurance consultant, and compliance or risk professionals whose job is to test controls rather than operate them. It is also a common move for security and operations people who want to cross into audit, because the credential signals that you can think in evidence and control objectives, not just in systems.
It is worth knowing the scale. CISA is ISACA's highest-volume credential, with more than 151,000 current holders and over 207,000 earned since 1978. That volume matters in practice: it is the certification hiring managers name in IT audit job postings, and the one audit firms treat as the baseline for the role.
Who is CISM for?
CISM is for people who own or want to own a security program. Typical titles: information security manager, aspiring CISO, GRC lead, and IT risk managers whose responsibility is running security rather than auditing it. The experience requirement makes the target explicit: CISM asks for five or more years of information security work experience, of which three or more must be in security management. You cannot waive your way past the management years.
The two credentials describe a real organizational boundary. The CISM holder builds and runs the program. The CISA holder examines it and tells the board whether it works. Plenty of careers cross that boundary, which is exactly why this comparison gets searched.
CISA vs CISM: exam logistics side by side
The mechanics are nearly identical, because both exams use ISACA's shared format:
| CISA | CISM | |
|---|---|---|
| Questions | 150 multiple choice | 150 multiple choice |
| Time | 4 hours | 4 hours |
| Scoring | Scaled 200 to 800, pass at 450 | Scaled 200 to 800, pass at 450 |
| Exam fee | USD 575 member / 760 nonmember | USD 575 member / 760 nonmember |
| Delivery | PSI test center or online proctored | PSI test center or online proctored |
| Experience | 5 years, waivers up to 3 years | 5 years, 3 in security management, waivers up to 2 years |
| Domains | 5, effective August 2024 | 4, effective 2022, updating November 3, 2026 |
The one structural difference sits in the experience rules. CISA asks for five years of IS or IT audit, control, assurance, or security experience, with education and other substitutions able to waive up to three of those years. CISM's waiver cap is two years, and the three years of security management experience cannot be substituted at all. In practice that makes CISM the harder credential to complete early in a career, even for someone who could pass the exam. Both exams let you sit first and submit the experience application after passing, so the requirement gates the certification, not the test date. The details of how the CISA experience rules work are in CISA requirements and experience.
Which should you take first?
It depends on where you are standing, so here it is by starting point.
You work in audit, or you are moving into audit. CISA, and it is not close. It is the credential the role asks for, the exam matches your daily work, and the waiver rules give a viable path earlier in a career.
You manage security, or you are a senior engineer heading toward management. CISM. The exam content is your job. The only caution is the three unwaivable management years: if you do not have them yet, you can still pass the exam and certify once the experience accrues.
You are technical and undecided between the two paths. Start with CISA. The experience rules are more forgiving, the technical Domains 4 and 5 sit closer to what you already know, and audit exposure teaches you how programs get evaluated, which is useful knowledge in either seat. CISM's unwaivable management requirement means it tends to come later anyway.
You are deciding in late 2026 specifically. CISA's outline is stable. CISM's changes on November 3, 2026, so a CISM candidate booking around that date needs to confirm which outline their exam uses and pick study material to match.
Is it worth holding both?
For some careers, yes, and the overlap makes the second exam cheaper to earn than the first. CISA's Domain 2 covers governance and management of IT; CISM's Domain 1 and 2 cover security governance and risk. CISA's Domain 5 covers protection of information assets; CISM's Domain 3 runs the program that provides that protection. You will not study the shared ground twice from scratch.
The pairing makes most sense for GRC leads, audit managers whose scope includes security, and security managers who deal with auditors constantly and want to speak the language from the inside. If you are a working IT auditor with no management ambitions, CISA alone is the defensible choice. If you run a security program and never touch audit, the same goes for CISM. Hold both only when your role genuinely spans the two seats, not for the sake of collecting letters.
Whichever order you choose, the study approach is the same: work to the weighted domains, and drill the answer pattern each exam rewards. Our 12-week CISA study plan shows what weight-matched scheduling looks like in practice, and the ISACA CISA study guide teaches all five domains from the auditor's decision lens, with four full-length practice exams where every answer is explained. A companion CISM guide does the same for the manager's seat.
FAQ
Is CISA harder than CISM?
Neither exam is harder in format: both are 150 questions in 4 hours with a 450 scaled pass mark. Difficulty depends on your background. Auditors find CISM's management framing unfamiliar; engineers and managers find CISA's assess-don't-fix answer pattern unfamiliar. The exam farther from your daily work is the harder one for you.
Can I hold CISA and CISM at the same time?
Yes. They are separate ISACA certifications with separate applications, and each carries its own continuing education obligations. Plenty of GRC and audit-adjacent professionals hold both, and the governance and protection content overlaps enough that the second exam takes less preparation than the first.
Does CISA or CISM pay more?
We do not publish salary claims, because they vary too much by market, seniority, and role to state honestly. The reliable pattern is that CISM maps to management roles and CISA to audit roles, so compensation follows the job, not the certificate.
Do CISA and CISM use the same exam format?
Yes. Both are 150 multiple-choice questions, 4 hours, scored on a 200 to 800 scale with 450 to pass, delivered through PSI test centers or online proctoring, at the same fee of USD 575 for ISACA members and USD 760 for nonmembers.
Is the CISM exam changing?
Yes. ISACA's CISM exam content outline updates effective November 3, 2026, with the announcement flagging new enterprise architecture and information security architecture content. The new domain weights had not been published when this was written. CISA's outline, effective August 2024, has no announced change.
Looking for a plain-English CISA guide? ISACA CISA: Certified Information Systems Auditor Study Guide covers all five domains with four full-length practice exams, every answer explained.
Simply Certified is an independent publisher. CISA, CISM, and ISACA are trademarks of ISACA. Our books are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.