CISM Requirements: Experience, Application, and Keeping It

CISM requirements: five years of security management experience, three of four domains, USD 50 application fee

The CISM requirements come in two halves, and the exam is only the first one. To hold the credential, ISACA asks for a minimum of five years of professional information security management work experience within the CISM job practice areas, covering at least three of the four CISM domains, gained within the ten-year period before you apply. You then submit an application, pay a one-time USD 50 application processing fee, and keep the certification alive with continuing education for as long as you hold it.

The short answer for most people searching this: you can sit and pass the exam before you have the experience, and you have five years from your passing date to apply. Passing gets you a score. The credential arrives when the application clears, and only once the experience is there.

What are the CISM requirements, start to finish?

Four stages, in this order.

Stage What ISACA asks for
Exam 150 multiple-choice questions in 4 hours, scored 200 to 800, with 450 to pass
Experience A minimum of five years of professional information security management work experience within the CISM job practice areas, across at least three of the four domains, gained within the ten years before you apply
Application Submitted within five years of your passing date, with a one-time USD 50 application processing fee
Maintenance A minimum of 20 CPE hours a year and 120 hours across each three-year cycle, plus ISACA's annual maintenance fee

Only the first stage is an exam problem. The other three are paperwork and calendar problems, and they are where people who have already passed quietly lose the credential they earned.

What counts as information security management experience?

Read ISACA's wording slowly, because one word carries the whole rule. It asks for information security management work experience within the CISM job practice areas. Not five years in information security, some of which involved leading things. Five years of the management work itself.

That is the most expensive misreading in the CISM process, and it is easy to make. A senior engineer with eight years of hands-on security work can read the requirement, count the years, and assume they qualify. The years are there. The category may not be.

The CISM job practice areas are the four domains: Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management. Under the outline in force through November 2, 2026 they weigh 17%, 20%, 33% and 30%. From November 3, 2026 they weigh 18%, 20%, 33% and 29%. The weights govern the exam paper rather than your application, but the domain names are the same vocabulary your experience gets mapped against, so it is worth knowing what sits inside each one. The CISM domains explained walks through all four.

Why does the three-of-four-domains rule catch people out?

Because a lot of good security careers are deep in one domain and thin everywhere else.

ISACA wants your five years spread across at least three of the four domains. Five years of incident response leadership is a strong record, and on its own it is one domain. So is five years of running a risk register. Where experience concentrates like that, the fix is usually documentation rather than a career change: describe the governance, program, or risk management work you did alongside the specialty instead of leaving it off the form.

The second constraint is the clock. Experience has to have been gained within the ten-year period before your application date, so older work drops out of the window as it ages. If you apply in 2026, security management work you did in 2013 no longer counts toward the five years. People returning to security after a stretch in another discipline are the ones most likely to be surprised by this.

Can you take the CISM exam before you meet the experience requirement?

Yes, and this is the part of the sequence worth planning deliberately rather than stumbling into.

The exam result and the certification application are separate transactions. Nothing stops you from registering, sitting, and passing while you are still accumulating qualifying years. ISACA gives you five years from the date you pass to submit the application, so passing early buys you a long runway.

There is a real argument for taking the exam first. Exam content is easier to hold in your head while you are actively studying it, and study momentum is a perishable thing. There is also a real argument against: if you are three years from qualifying, that passing score sits on a shelf doing nothing while ISACA revises the outline underneath it, and you carry the risk of the five-year window closing on you.

My own view is that the exam-first path is the right default when you are within about two years of meeting the experience rule, and a bad default when you are five years out. Somewhere in the middle, the deciding factor is whether the job you are in now is actually adding management experience or just adding time.

Either way, the preparation problem is the same one. Our CISM study guide covers all four domains from the manager's decision lens with three full-length practice exams and every answer explained, which is the part of the work that does not care where you are in your five years. For how much the exam itself costs, see CISM exam cost and fees, and for what you are walking into, how hard is the CISM exam.

One scheduling note if you are timing an attempt this year: the CISM moves to an updated exam content outline on November 3, 2026. That changes the blueprint you study, not the requirements on this page. CISM exam changes for November 2026 sets both outlines side by side.

Are there waivers or substitutions for the CISM experience requirement?

Be careful here, especially with what you read elsewhere.

ISACA does publish waivers for the CISM, and the cap is two years. Its Certification Exam Candidate Guide states that CISM experience waivers are available for a maximum of two years, and its support knowledge base sets out what qualifies. There are two routes and they are worth reading separately. The first is a general information security experience waiver, worth up to two years of general information security work rather than management work. The second is a substitution, and only one may be applied, with documentation. A current CISA in good standing, a current CISSP in good standing, or an MBA or master's degree in information security or a related field is each worth two years. A bachelor's degree in information security is worth one, as is a skills-based certification such as GIAC, MCSE, CompTIA Security+, CBCP, or ESL IT Security Manager. What no waiver touches is the core: ISACA's support article states that a minimum of three years must sit in three of the four CISM job practice areas, so the two years you can waive come off the top, never out of the middle.

If your five years only works with a substitution, verify that substitution before you book the exam rather than after you pass it.

What do you have to do to keep the CISM?

The credential is maintained, not owned. Two ongoing obligations, and both are annual.

First, continuing professional education. ISACA's CPE policy sets a minimum of 20 CPE hours each year and 120 hours across each three-year reporting cycle. The annual minimum is the one that trips people, because 120 over three years sounds like something you can back-load, and it is not. A year with 12 hours is a short year even if you finish the cycle at 130.

Second, the annual maintenance fee. ISACA's Maintain CISM Certification page puts it at USD 45 for members and USD 85 for nonmembers, charged separately from your CPE hours and separately from the one-time USD 50 application fee. If you hold three or more ISACA certifications, the third and each one after renews at a reduced rate. ISACA revises these amounts from time to time, so check the maintenance page in the year you renew.

Alongside both, holding the certification means adhering to ISACA's Code of Professional Ethics. That one costs nothing and is easy to forget exists until it matters.

A practical habit that costs nothing: log each CPE activity when you complete it, with the certificate or confirmation attached. Reconstructing three years of webinars, conference sessions, and vendor training from memory when someone asks for evidence is a bad afternoon that is entirely avoidable.

What happens if your CISM lapses?

The honest answer is that ISACA's CPE policy governs this, and it is the document to read rather than a paraphrase from a study blog.

What is safe to say is the shape of it. Missing the CPE hours or failing to pay the annual maintenance fee puts the certification at risk, and a certification that is not maintained does not stay valid indefinitely. Check ISACA's current CPE policy for the exact consequences, any grace period, and whatever reinstatement route exists, because those specifics change and a wrong assumption here is expensive in a way that a wrong assumption about domain weights is not.

The prevention is duller than the cure. Twenty hours a year is roughly two hours a month, which almost any working security manager clears through webinars, chapter meetings, and reading they were doing anyway. The hours are rarely the problem. The record of them is.

Which of these numbers should you confirm yourself?

One, and it is the one this post has deliberately left open rather than filling with a plausible-looking figure.

Confirm the current CPE policy before you rely on any assumption about grace periods or reinstatement, because ISACA's maintenance page states plainly that failure to comply results in revocation of the designation, and the detail of what happens next sits in the policy document rather than on the page.

The rest is stable and worth planning around: five years of information security management experience across at least three of the four domains within a ten-year window, five years from your passing date to apply, a one-time USD 50 application processing fee, and 20 CPE hours a year against 120 per three-year cycle. If you are still deciding whether this is the right ISACA credential for your record, what the CISM exam is covers the whole picture and CISA vs CISM puts the two side by side.

FAQ

Can I take the CISM exam without any experience?

You can sit and pass the exam without meeting the experience requirement, because the exam and the certification application are separate steps. You cannot hold the credential until you have a minimum of five years of professional information security management work experience within the CISM job practice areas, across at least three of the four domains, gained within the ten years before you apply. You have five years from your passing date to submit that application.

Does hands-on security work count toward the CISM experience requirement?

ISACA's wording asks for information security management work experience within the CISM job practice areas, not general information security work. That distinction is the one most likely to cost you a rejected application, so map your history against the four domains before you file rather than counting total years in the field. If your record depends on an interpretation, confirm it against ISACA's support knowledge base article on the requirements to become CISM certified.

How much does it cost to apply for CISM certification after passing?

ISACA charges a one-time USD 50 application processing fee when you apply for the certification, separate from the exam fee itself. Maintenance is separate again: an annual maintenance fee of USD 45 for members and USD 85 for nonmembers, plus the CPE requirement. Confirm the current amounts on ISACA's Maintain CISM Certification page before you budget, since they are revised from time to time.

How many CPE hours does the CISM require each year?

A minimum of 20 CPE hours per year and 120 hours across each three-year reporting cycle. Both numbers matter independently, so clearing 120 over three years does not excuse a year that came in under 20. Log activities as you complete them and keep the evidence.

What happens if I do not apply within five years of passing the CISM exam?

The application window is five years from your passing date, so a passing score that goes unused past that point stops being something you can convert into the credential. If your experience is going to take longer than five years to accumulate, plan the exam date around that rather than sitting it as early as possible. Check ISACA's current certification page for anything that has changed before you rely on the timing.


Looking for a plain-English CISM guide? ISACA CISM: Simply Certified Study Guide covers all four domains from the manager's decision lens, with three full-length practice exams, every answer explained.

Simply Certified is an independent publisher. CISM and ISACA are trademarks of ISACA. Our books are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.