Short answer: yes, the CISM exam changes on November 3, 2026, and no, you almost certainly should not panic-book a seat to beat the cutover. ISACA is replacing the 2022 exam content outline with a 2026 one. The four domains keep their names, the domain count stays at four, and the weights move by a single percentage point in two places. Governance goes from 17% to 18%. Incident Management goes from 30% to 29%. Risk Management stays at 20% and Program stays at 33%.
The second half of your question matters more. Material written to the 2022 outline does not become wrong on November 3, but it does become incomplete. The 2026 outline adds two content areas that were not in the old one: enterprise architecture and information security architecture. If your appointment falls on or after November 3 and your books predate the update, that gap is the thing to fix, not the domain weights. Everything below comes from ISACA's own pages, and where ISACA has not published a number, this post says so rather than filling in a plausible one.
What are the CISM exam changes in 2026?
Three things, and as far as ISACA has said publicly, only three.
First, the outline version. The CISM exam content outline in force since 2022 is replaced by a 2026 outline effective November 3, 2026. ISACA carries that notice on both its CISM certification page and its CISM exam content outline page.
Second, the domain weights, which ISACA has now published. Its support article on the 2026 job practice update includes a side-by-side table of the 2022 and 2026 percentages. When our study guide was researched in June, that table was not public, so the weights were still an open question. They are not open any more.
Third, the content emphasis. ISACA says the 2026 exam places greater emphasis on information security strategy and program development, and adds two new content areas: enterprise architecture and information security architecture. The stated reason is that a security manager is now expected to understand the technologies sitting under their remit.
Notice what is absent from that list. No new domain. No renamed domain. Nothing at all about exam format.
What are the new CISM domain weights?
| Domain | 2022 outline | 2026 outline |
|---|---|---|
| 1. Information Security Governance | 17% | 18% |
| 2. Information Security Risk Management | 20% | 20% |
| 3. Information Security Program | 33% | 33% |
| 4. Incident Management | 30% | 29% |
One point out of Incident Management, one point into Governance. Across 150 questions, a single percentage point is roughly one or two items. That is a rounding adjustment, not a redesign.
This is worth stating bluntly because the secondhand coverage has been unreliable. If you have read that Risk Management nearly doubles to 33%, or that Incident Management collapses to 17%, those figures do not match what ISACA published. Some of them were written before ISACA released the table and never corrected. Go and read ISACA's own support article before you rebuild a study plan around a number from a training vendor's blog.
The practical effect on your study time is close to nothing. Program is still the heaviest domain at a third of the exam. Program and Incident Management together are still 62% of your questions. If you want the domain-by-domain view of what each one actually tests, CISM domains explained covers it.
Do the question count and time limit change?
Not as far as ISACA has announced. The CISM exam content outline page still describes 150 questions across four domains. The current ISACA Certification Exam Candidate Guide, version 1.26, states 4 hours and 240 minutes for 150 multiple-choice questions. Scoring is unchanged as well: a scaled score from 200 to 800, with 450 to pass.
Read that carefully, though. ISACA has not issued a statement saying the format is staying the same. What it has done is say nothing about format while continuing to publish 150 questions and 4 hours on its live pages and in the current candidate guide. That is strong evidence, not a formal confirmation. If the format is load-bearing for your plan, re-download the candidate guide once the new prep materials are fully out, because that is when ISACA usually refreshes it.
Which exam dates fall under which outline?
Your appointment date decides, not your registration date and not which books you own. ISACA's wording is that starting on November 3, 2026, the exam reflects the new outline.
- Sit on or before November 2, 2026: you get the current 2022 outline.
- Sit on or after November 3, 2026: you get the 2026 outline.
One detail helps if you are cutting it fine. Registration gives you a six-month eligibility period in which to take the exam, and you can reschedule without penalty up to 48 hours before your appointment. So registering in September commits you to nothing about which outline you face. Only the date you actually sit does.
Is your study material about to go stale?
Partly, and it is worth being precise about which parts.
The structure survives. Four domains, same names, near-identical weights, and the same underlying management-decision lens that the exam has always rewarded. Governance frameworks, the risk management cycle, program development and management, incident response and recovery: nothing there was deleted. A 2022-aligned guide still maps onto the exam you will sit in December.
The gap is the two added areas. Enterprise architecture and information security architecture are new to the outline, and any book written before mid-2026 will not have chapters on them. That is a real hole, and it is a small one. You are being asked to reason about architecture as a manager, the way you already reason about everything else on this exam, rather than to design an architecture yourself.
ISACA's own supply timeline is worth knowing. The new CISM exam prep began launching on September 1, 2026, with per-product and per-language dates published on ISACA's visual timeline, and older versions of CISM exam prep were pulled from sale on the same date. If you already hold a QAE database, online review course, or eBook subscription, it stays available for the rest of your active term, but ISACA has said plainly that legacy materials will not be updated for the new content, and subscription extensions stop being available after November 3, 2026.
For the core teaching that carries across both outlines, our CISM study guide works through the four domains in plain English with three full-length practice exams where every answer, including every wrong option, is explained. Pair any pre-2026 guide with current reading on the two architecture areas and you have covered the delta.
Should you sit before or after November 3?
Here is the opinion, with the reasoning attached.
Sit before November 3 if all of these are true: you are already deep into a study plan, your full-length practice scores are steady across all four domains, and you can get an appointment before November 2 without compressing the prep you have left. In that case you sit the outline you actually studied, and you skip two topics you have not covered. Clean.
Sit after November 3 if any of those is shaky, which is most people reading this in late August. A one-point weight shift is not a reason to rush a 4-hour exam that costs USD 575 for ISACA members and USD 760 for nonmembers per attempt. The cost of arriving underprepared is far higher than the cost of adding two topics.
Two things should not drive this decision. The first is fear of an unknown exam. The 2026 outline is not a mystery: the domains and weights are published, the two additions are named, and updated official prep has been shipping since September 1. The second is the idea of an early sitting as a low-risk trial run. The retake policy is four attempts in a rolling 12-month period, with a 30-day wait before the second attempt and 90 days before each of the next two. Fail in late October and your next attempt lands well after the cutover regardless, so you would be paying full price to preview a version of the exam you will never sit again.
If you are still weighing whether CISM is the right ISACA credential at all, settle that before you settle the calendar. Start with what the CISM exam is, and if you are choosing between certifications, CISA vs CISM puts them side by side. For a read on the difficulty itself, how hard the CISM exam is goes into the question style that trips people up.
What ISACA has not published yet
The edges of what is confirmed matter as much as the confirmed part.
As of this writing, ISACA's CISM exam content outline page still displays the 2022 outline in full, with its domain descriptions, subtopics, and supporting tasks. The 2026 weights live in the support knowledge base article, not yet on the outline page. The detailed 2026 subtopics, the supporting task list, and the number of supporting tasks are not publicly posted.
ISACA has also published nothing about how the two new architecture areas are distributed across the four domains. The comparison table stops at the domain level, so anyone telling you that enterprise architecture accounts for a specific share of Domain 1 or Domain 3 is guessing.
And there is no CISM pass rate, before or after the update. ISACA does not publish one, so any percentage you find quoted is somebody's estimate presented as a fact.
Two pages are worth bookmarking: ISACA's CISM exam content outline page, and the 2026 CISM job practice update article in ISACA's support knowledge base. Both are free, both are primary, and both will carry the new detail before any third party does.
FAQ
When exactly do the CISM exam changes take effect?
November 3, 2026. ISACA has stated that starting on that date the CISM exam reflects the new exam content outline. Any appointment on or before November 2, 2026 uses the current 2022 outline. Your appointment date is what counts, not your registration date.
What are the new CISM domain weights for 2026?
Information Security Governance moves from 17% to 18%, Information Security Risk Management stays at 20%, Information Security Program stays at 33%, and Incident Management moves from 30% to 29%. ISACA published this comparison in its 2026 CISM job practice update support article. Figures you may see elsewhere claiming much larger swings do not match what ISACA released.
Does the CISM exam get longer or add questions in 2026?
ISACA has announced no change to the format. Its live pages still describe 150 questions, and the current Certification Exam Candidate Guide still gives 4 hours and 240 minutes, with scaled scoring from 200 to 800 and 450 to pass. Because ISACA has not issued an explicit statement either way, re-check the candidate guide closer to your exam date.
Will my current CISM study material still work after November 3?
Mostly. The four domains keep their names and near-identical weights, so the structure of a 2022-aligned guide still maps to the new exam. What older material will not cover is the two added content areas, enterprise architecture and information security architecture, plus the heavier emphasis on information security strategy and program development.
Should I rush to take the CISM before the outline changes?
Only if you are already prepared and can book a date before November 2 without cutting your study short. The weight change is a single percentage point in two domains, which is not worth sitting underprepared for. A failed attempt in late October cannot be retaken before the cutover anyway, given the 30-day minimum wait.
Looking for a plain-English CISM guide? ISACA CISM: Certified Information Security Manager Study Guide covers all four domains with three full-length practice exams, every answer explained.
Simply Certified is an independent publisher. CISM and ISACA are trademarks of ISACA. Our books are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.