The CISM exam is ISACA's test for the person who runs an information security program. CISM stands for Certified Information Security Manager. The exam is 150 multiple-choice questions in 4 hours, covering four domains, scored on a scale of 200 to 800 with 450 required to pass. It costs USD 575 for ISACA members and USD 760 for nonmembers, and you sit it either at a PSI test center or at home with a remote proctor.
That is the short answer. The part that decides whether you pass is the seat the exam puts you in. CISM is written for the person who runs the security program, not the person who configures the controls. When a question describes a problem, the credited answer is usually the governance move: align with business objectives, escalate to the right owner, update the policy, report to the steering committee. The technical fix is often sitting right there in the options, and it is often wrong.
Who is the CISM for?
CISM is aimed at people who own or want to own a security program. That means information security managers, security program leads, GRC leads, IT risk managers, and senior engineers making the step into management. The natural endpoint of the role is the CISO chair, and CISM is the credential that shows up in those job descriptions.
ISACA's own description is people who manage, design, oversee, and assess an enterprise's information security function. Those are all management verbs, and the exam follows them closely. Notice what is missing from the list: implement, configure, deploy. The experience requirement, covered further down, says the same thing in numbers. CISM expects you to already be doing some version of this work, which makes it a poor first certification.
What are the four CISM domains?
Every question maps to one of four domains. Under the exam content outline effective 2022, which is the outline in force for exams sat up to November 2, 2026, the published weights are:
| Domain | Weight |
|---|---|
| 1. Information Security Governance | 17% |
| 2. Information Security Risk Management | 20% |
| 3. Information Security Program | 33% |
| 4. Incident Management | 30% |
Domains 3 and 4 carry 63% of the exam between them. That is where the marks are, and it tells you what ISACA thinks a security manager does all day: build and run the program, then manage the incidents that test it. Governance, at 17%, is the smallest weight, which surprises people who assume a management exam is mostly governance theory. It is not, though the governance mindset runs through all four domains.
In plain terms: Domain 1 covers enterprise governance and security strategy, including governance frameworks and the business case for security spend. Domain 2 covers risk assessment and risk response, including treatment options and risk ownership. Domain 3 covers building and running the program, from asset classification and policy through control design, testing, and external service providers. Domain 4 covers incident readiness and incident operations, from business impact analysis and continuity planning through containment, recovery, and the post-incident review.
The outline also lists 37 supporting tasks underneath the four domains, and those tasks are what the questions are written against. We break all of it down in CISM domains explained.
What changes on November 3, 2026?
ISACA has confirmed that from 3 November 2026 the CISM reflects updated job practice areas. Two content areas are added, enterprise architecture and information security architecture, along with greater emphasis on information security strategy and program development.
ISACA has now published the new weights, in its CISM Job Practice Update 2026 support article. The four domain names are unchanged and the movement is small:
| Domain | 2022 outline | 2026 outline |
|---|---|---|
| 1. Information Security Governance | 17% | 18% |
| 2. Information Security Risk Management | 20% | 20% |
| 3. Information Security Program | 33% | 33% |
| 4. Incident Management | 30% | 29% |
One point moves from Incident Management to Governance. Everything else holds. That is a reassuringly dull change: a study plan weighted to the 2022 numbers is only very slightly mistuned for the 2026 exam, and Domains 3 and 4 go from 63% of the paper to 62%. The detailed subtopics and supporting tasks beneath the new weights are not published yet.
On materials: the new CISM Exam Prep began launching on September 1, 2026, older versions were pulled from sale the same day, and existing subscriptions run out their term without being updated for the new exam.
The practical rule: sit on or before November 2, 2026 and the 2022 weights apply, sit on or after November 3 and you are on the 2026 outline. If you are booking near that boundary, confirm which outline applies when you register and pick study material to match. We track the change in detail in CISM exam changes November 2026.
What is the CISM exam format and how is it scored?
The exam is 150 multiple-choice questions with a 4-hour limit, which works out to about 96 seconds per question. Every item has one stem and four options, and you pick the best answer. Some items are scenario-based, where a situation is followed by two or more questions. There are no simulations, no labs, and nothing to write.
Unscored pretest items are mixed in with the scored ones, and you cannot tell which is which. There is no penalty for a wrong answer, so leaving anything blank only costs you.
Scoring is scaled. Raw performance is converted to a score between 200 and 800, and 450 is the minimum passing score. Because the score is scaled, there is no published percentage of questions you need to get right, and no conversion table. Your domain-level results come back as information only; they play no part in the pass or fail decision. ISACA does not publish a CISM pass rate, so any specific figure you find online is somebody's estimate rather than a fact.
Delivery is through PSI, not Pearson VUE, which catches out candidates arriving from other certification families. You can test at a PSI test center or online with a remote proctor. The remote option carries the usual conditions: a webcam, a room scan, a clear desk, and a connection you trust for four hours.
Is that hard? Time is rarely the constraint. The questions are, and we give an honest assessment in how hard is the CISM exam.
How much does the CISM exam cost?
The exam fee is USD 575 for ISACA members and USD 760 for nonmembers, confirmed on ISACA's CISM page. That is registration only.
After you pass, certification costs another USD 50 as a one-time application processing fee, payable once your official score is released. Maintenance is separate again, covered below.
The USD 185 gap between the member and nonmember fee is worth arithmetic before you register, because an ISACA membership can recover a large share of itself through the exam discount alone. Whether it nets out depends on your local chapter dues, so compare the current membership price against that USD 185 saving.
What is the CISM experience requirement?
Passing the exam does not make you a CISM. ISACA's requirement is a minimum of five years of professional information security management work experience within the CISM job practice areas, and its Get CISM Certified page states it as five or more years of CISM professional work experience across at least three of the four CISM domains. The experience must have been gained within the ten-year period preceding your application date, and you must apply within five years of passing the exam.
ISACA's Certification Exam Candidate Guide states the requirement as five or more years of experience in information security management, with experience waivers available for a maximum of two years. The Get CISM Certified page itself does not set out the substitution list, so check ISACA's current CISM application requirements for exactly what qualifies as a waiver before you count on one.
Here is the rule that catches people out, and it is worth reading ISACA's wording twice. ISACA asks for five years of information security management work, spread across at least three of the four domains. General practitioner time does not fill that requirement, however long you have been doing it, and while waivers take up to two years off the total, what remains still has to be management experience. That is why CISM tends to arrive later in a career than an audit or technical credential, and it is the strongest argument for sitting CISA rather than CISM if you are early on.
You can still take the exam first. The exam result and the certification application are separate steps, and passing early while the experience accrues is a normal path.
Is the CISM accredited, and how do you keep it?
CISM is accredited under ISO/IEC 17024:2012 and is an ANSI Accredited Program, Personnel Certification #0694. The same accreditation covers CISA, CGEIT, and CRISC. That matters mostly for employers and government contracts that require accredited certification rather than vendor training.
Keeping the credential means adhering to ISACA's Code of Professional Ethics and its Continuing Professional Education policy. ISACA's maintenance page states a minimum of 20 CPE hours per year and 120 hours across each three-year cycle, plus an annual maintenance fee of USD 45 for members and USD 85 for nonmembers, with a reduced rate once you hold three or more ISACA certifications. Fees and hour totals do get revised, so check the current maintenance page in the year you renew.
What does the CISM exam actually test?
Here is the thesis that should shape your preparation: CISM rewards the manager's decision over the engineer's fix.
The domains contain plenty of technical vocabulary. Controls, containment, encryption, recovery, testing. A hands-on candidate reads that and starts thinking about implementation. The exam almost never asks how to implement anything. It asks what a security manager should do first, what they should recommend, what they should be most concerned about, and who should own the decision. Qualifier words like MOST, BEST, and FIRST appear constantly, and they exist to separate the defensible answer from the credited one.
Take an incident scenario. Malware is spreading across a business unit. The engineer's answer is to isolate the affected hosts. The exam's answer is often to activate the incident response plan or to notify the incident response team, because a manager works through the plan and the people, and the containment step happens inside that structure. Same event, different seat. Once you see the pattern, whole families of questions stop being ambiguous.
That is also why study material matters more than usual here. A reference that teaches you how controls work will not train you out of the engineer's reflex. The ISACA CISM: Simply Certified Study Guide is written from the manager's decision lens throughout, with chapters mapped to the four domains and three full-length practice exams where every answer is explained, including why each wrong option is wrong.
Should you sit CISM, or CISA?
An opinion, since you read this far.
Sit CISM if you already own security work: a program, a budget, a team, or a risk register, and the questions you answer at work are about direction and accountability rather than configuration. Sit it too if you are the senior engineer whose next move is a management title, because the exam is a decent forcing function for learning to think in that register before someone hands you the job.
Sit CISA if your work is assessment and assurance, or if you are early in your career. CISA's five years can be audit, control, assurance, or security work rather than management work, and its waivers run to three years instead of two. The full comparison is in CISA vs CISM.
And if you are booking around the outline change, sort that out first. Everything else about the CISM is stable for now. The domain structure has a date on it.
FAQ
How many questions is the CISM exam?
150 multiple-choice questions in a single 4-hour session, which is roughly 96 seconds per question. There are no simulations or written components. Some unscored pretest items are mixed in with the scored ones, so answer every question.
What score do you need to pass the CISM?
450 on a scaled range of 200 to 800. Because the score is scaled, there is no official percentage equivalent, and ISACA does not publish CISM pass rates. Domain-level results are reported for information only and do not affect the pass or fail decision.
Is the CISM exam changing in November 2026?
Yes. ISACA has confirmed that the CISM reflects updated job practice areas from 3 November 2026, adding enterprise architecture and information security architecture content. ISACA has published the new weights: Governance rises from 17% to 18% and Incident Management falls from 30% to 29%, while Risk Management stays at 20% and Program stays at 33%. The domain names do not change.
Can I take the CISM exam before I have five years of experience?
Yes. The exam and the certification application are separate steps, and you have five years from passing to submit the application. Read ISACA's wording carefully, though: it asks for five years of information security management work experience across at least three of the four CISM domains, not five years of general security work. Waivers can reduce that total by up to two years.
How much does the CISM cost in total?
The exam is USD 575 for ISACA members and USD 760 for nonmembers, plus a one-time USD 50 application processing fee after you pass. Ongoing, ISACA lists an annual maintenance fee of USD 45 for members and USD 85 for nonmembers, alongside the CPE requirement. Confirm current amounts on ISACA's pages before you budget.
Looking for a plain-English CISM guide? ISACA CISM: Simply Certified Study Guide teaches all four domains from the manager's decision lens, with three full-length practice exams, every answer explained.
Simply Certified is an independent publisher. CISM and ISACA are trademarks of ISACA. Our books are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.