Fast Track Bootcamps
 Crafted For Career-Ready Skills

CISM Exam Requirements: Eligibility, Experience, & Certification Process

Quick Insights:

CISM certification involves more than simply clearing the exam. You can take the CISM exam before completing the full experience requirement, but certification requires qualifying information security management experience and completion of ISACA’s certification process. Candidates should also keep the five-year application window in mind, prepare according to the applicable CISM Exam Content Outline, including the update effective November 3, 2026, and fulfill ongoing CPE requirements after certification.

The Certified Information Security Manager (CISM) is a globally recognized information security management credential offered by ISACA. It is designed for professionals who manage, design, oversee, or assess an organization’s information security program.

One common misconception about CISM is that candidates need five years of experience before they can take the exam. However, exam eligibility and certification eligibility are different. You can take the CISM exam before completing the full professional experience requirement, but you must meet ISACA’s applicable certification requirements before earning the CISM designation.

CISM Certification Requirements: Eligibility, Experience & Exam Guide

This guide explains CISM exam eligibility, experience requirements, certification requirements, exam format, experience substitutions, the certification process, and CPE requirements.

What is CISM Certification?

CISM stands for Certified Information Security Manager. Unlike certifications that focus heavily on configuring security technologies or performing technical security tasks, CISM approaches information security from a management and business perspective.

The certification focuses on four core areas:

This management-oriented approach makes CISM especially relevant for cybersecurity professionals moving into security management, governance, risk management, and leadership roles.

What are the CISM Certification Requirements?

Passing the CISM exam is only one part of becoming certified. Candidates must also satisfy ISACA’s applicable certification requirements.

The major requirements include:

  • Pass the CISM examination
  • Meet the required professional experience criteria
  • Ensure qualifying experience falls within ISACA’s specified timeframe
  • Submit the CISM certification application
  • Apply within five years of passing the examination
  • Pay the certification application processing fee
  • Comply with ISACA’s Code of Professional Ethics and certification policies
  • Meet ongoing Continuing Professional Education (CPE) requirements after certification

These requirements are important because exam eligibility and certification eligibility are not the same thing.

CISM Exam Eligibility: Who Can Take the CISM Exam?

Candidates do not have to complete the full CISM professional experience requirement before taking the examination. For example, a cybersecurity professional who is still building qualifying information security management experience can take and pass the exam first, complete the remaining experience afterward, and then apply for certification.

However, candidates should consider the timing carefully because ISACA requires the certification application to be submitted within five years of passing the CISM exam.

How to Become CISM Certified?

Becoming CISM certified involves more than simply passing the CISM examination. Candidates must pass the exam, meet ISACA’s applicable professional experience requirements, and submit a certification application.

Step 1: Prepare for the CISM Exam

Study the CISM domains, use official resources, and practice with exam questions and mock tests.

Step 2: Register with ISACA

Create an ISACA account and register for the CISM examination.

Step 3: Take the CISM Exam

Schedule the exam at an available testing center or through an available online testing option and complete the computer-based examination.

Step 4: Meet the Professional Experience Requirements

After passing the exam, determine whether you meet the applicable professional experience requirements. CISM certification generally requires five years of information security management experience, subject to applicable experience substitutions.

Step 5: Complete the Certification Application

Submit your CISM certification application to ISACA with the required professional experience details and supporting information.

Step 6: Continue Gaining Experience If Required

If you do not yet meet the applicable experience requirement, continue gaining qualifying information security management experience. Once you satisfy the requirements, submit your certification application to ISACA within the applicable timeframe.

Step 7: Receive Your CISM Certification

Once ISACA approves your application and all applicable requirements have been satisfied, you will receive the CISM certification.

Important: Passing the CISM examination does not automatically make you CISM certified. You must also satisfy the applicable professional experience and certification requirements and submit the required application to ISACA.

Remember: You have five years after passing the CISM examination to submit your CISM certification application.

How Much Experience is Required for CISM Certification?

ISACA currently requires candidates to demonstrate at least five years of professional information security management work experience within the CISM job practice areas, subject to its applicable experience-substitution rules.

Another important condition concerns when that experience was obtained. The qualifying professional experience must fall within the 10-year period preceding the date of the CISM certification application.

Candidates therefore need to keep two timelines in mind:

  • 10-year Experience Window: Qualifying professional experience must meet ISACA’s requirements concerning when it was earned.
  • 5-year Application Window: After passing the CISM exam, candidates have five years to apply for certification.

Candidates sometimes mix up these two requirements, so it is important to treat them separately.

What Type of Experience is Relevant to CISM?

CISM certification requires professional information security management experience aligned with the CISM job practice areas. Candidates need five or more years of qualifying experience across at least three of the four CISM domains.

1. Information Security Governance

This domain focuses on aligning information security with organizational objectives and establishing appropriate governance structures.

Relevant responsibilities may include:

  • Developing information security strategies
  • Creating security policies, standards, and frameworks
  • Defining security roles and responsibilities
  • Establishing governance structures
  • Aligning security initiatives with business requirements
  • Reporting security performance to stakeholders

2. Information Security Risk Management

This domain focuses on identifying, assessing, treating, monitoring, and communicating information security risks.

Relevant responsibilities may include:

  • Conducting information security risk assessments
  • Identifying threats, vulnerabilities, and control deficiencies
  • Evaluating the business impact of security risks
  • Recommending appropriate risk responses
  • Monitoring and reporting information security risks
  • Addressing risk and control ownership

The focus is not simply on identifying technical weaknesses but on understanding how information security risks affect organizational objectives.

3. Information Security Program

This domain covers the development, implementation, management, and continuous improvement of an organization’s information security program.

Relevant responsibilities may include:

  • Developing security policies, procedures, and guidelines
  • Managing information security resources
  • Selecting and managing security controls
  • Managing information security program requirements
  • Establishing security metrics
  • Monitoring security program performance
  • Reporting results to relevant stakeholders
  • Supporting continuous improvement

This domain connects security strategy and risk decisions with the organization’s operational security activities.

4. Incident Management

Incident Management focuses on preparing organizations to identify, respond to, recover from, and learn from information security incidents.

Relevant responsibilities may include:

  • Developing incident response plans
  • Defining incident escalation procedures
  • Coordinating incident response activities
  • Supporting incident investigations
  • Managing incident communications
  • Coordinating recovery activities
  • Conducting incident response testing
  • Performing post-incident reviews and identifying lessons learned

CISM approaches incident management from an organizational perspective rather than focusing only on the technical remediation of compromised systems.

CISM Experience Waivers and Substitutions

Some candidates may qualify for substitutions that reduce part of the professional experience requirement. For example, certain recognized certifications, qualifications, or relevant postgraduate education may qualify for experience substitution under ISACA’s applicable rules.

Examples discussed in CISM certification information include certifications such as CISA and CISSP, along with certain postgraduate information security qualifications.

However, experience-substitution policies can change, and different qualifications may receive different treatment.

Candidates should therefore review ISACA’s latest CISM certification application and experience requirements before assuming that a particular certification or qualification will reduce their required experience.

What is the CISM Exam Format?

The CISM exam currently contains 150 questions covering the four CISM domains.

The current domain distribution is:

  • Information Security Governance: 17%
  • Information Security Risk Management: 20%
  • Information Security Program: 33%
  • Incident Management: 30%

These percentages tell candidates approximately how the exam content is distributed across the CISM job practice areas. However, candidates planning to take the examination in late 2026 need to be aware of an important update.

Important CISM Exam Change from November 3, 2026

ISACA has announced an updated CISM Exam Content Outline that will become effective on November 3, 2026. The four main CISM domains will remain, but their exam weightings will change.

From November 3, 2026, the domain distribution will be:

CISM Four Domains: Key Focus Areas of the CISM Exam

The updated outline also reflects changes in modern security management responsibilities. Therefore, your preparation strategy should depend on when you plan to take the examination.

Explore the article: What is new in CISM 2026?

If your exam is scheduled on or after November 3, 2026, make sure the books, practice questions, training materials, and study plan you use align with the revised CISM Exam Content Outline.

What is the CISM Passing Score?

CISM uses a scaled scoring system rather than a simple percentage-based score. Candidates need a scaled score of 450 or higher to pass the examination. ISACA reports examination results using a scale ranging from 200 to 800.

A score of 450 should therefore not be interpreted as a direct percentage of questions answered correctly. Candidates should focus on building a strong understanding of all four CISM domains rather than trying to calculate the minimum number of correct answers needed.

CISM Certification Process: Step-by-Step

Understanding the certification process before registering can help you avoid confusion later.

Here is how the journey generally works.

CISM Certification Journey From preparation to certification and beyond

Step 1: Review the CISM Requirements

Start by reading the latest eligibility and certification requirements published by ISACA. Pay particular attention to:

  • Professional experience requirements
  • Experience substitution rules
  • Certification application deadlines
  • Examination policies
  • Current exam content outline
  • Certification maintenance requirements

This is particularly important in 2026 because of the CISM exam content update taking effect on November 3.

Step 2: Prepare for the CISM Examination

Build your study plan around all four CISM domains and focus on understanding how information security decisions support organizational objectives.

Because CISM is management-focused, preparation should go beyond memorizing terminology. Practice interpreting business and security scenarios and identifying the most appropriate management response.

Step 3: Register and Schedule the CISM Exam

Once you are prepared, register for the examination through ISACA.

Before paying, confirm:

  • Current examination fees
  • Registration requirements
  • Available testing options
  • Rescheduling and cancellation policies
  • Identification requirements
  • Exam-day procedures

Because fees and examination policies can change, always use current ISACA information rather than relying on an older article.

Step 4: Take and Pass the CISM Exam

You must complete the CISM examination and achieve the required passing score. Passing satisfies the examination component of the certification process. Candidates must then complete the remaining certification requirements.

Step 5: Complete and Verify Your Professional Experience

Before applying for certification, make sure of your professional experience.

Check:

  • How many years of qualifying experience you have
  • Whether your responsibilities align with CISM job practice areas
  • When the experience was obtained
  • Whether any eligible experience substitution applies
  • Whether your experience can be properly verified

Do this carefully rather than assuming that every cybersecurity job automatically counts toward CISM.

Step 6: Pay the Certification Application Processing Fee

Passing the examination and applying for certification are separate steps. ISACA currently lists a US$50 certification application processing fee.

Because fees may change, check ISACA’s current certification page before submitting your application.

Step 7: Submit Your CISM Certification Application

Once you meet the applicable requirements, submit your certification application according to ISACA’s instructions within the required timeframe.

Step 8: Maintain Your CISM Certification

After earning CISM, certification holders must maintain their knowledge through Continuing Professional Education (CPE). ISACA currently requires:

  • At least 20 CPE hours each year
  • At least 120 CPE hours during a three-year reporting period

CISM holders must also continue to comply with ISACA’s certification and professional ethics requirements.

Can Freshers Take the CISM Exam?

Yes. Candidates do not need to complete the full professional experience requirement before sitting for the CISM examination. However, there is an important difference between taking the exam and earning the certification.

Freshers and early-career professionals cannot receive the CISM certification until they satisfy the applicable professional experience and certification requirements.

Common Mistakes Candidates Make About CISM Requirements

Several misunderstandings repeatedly appear when professionals research CISM.

Mistake 1: Thinking You Need Five Years of Experience Just to Take the Exam

The professional experience requirement relates to becoming CISM certified. You can take the examination before satisfying the complete certification experience requirement.

Mistake 2: Assuming Passing the Exam Makes You CISM Certified

Passing the exam completes the examination requirement. Certification is awarded only after the applicable experience and application requirements are satisfied.

Mistake 3: Ignoring the Five-Year Application Window

Candidates who take the exam before completing their professional experience should pay particular attention to the certification application deadline.

Mistake 4: Assuming Your Job Title Determines Eligibility

A job title such as “Security Manager” does not automatically make all professional experience eligible. Similarly, not having “Manager” in your title does not necessarily make your experience irrelevant. The responsibilities you actually perform are what matter.

Mistake 5: Studying an Outdated Exam Outline

Candidates taking the exam from November 3, 2026 need to account for ISACA’s updated CISM Exam Content Outline. Always match your study materials to the version of the exam you are scheduled to take.

How to Prepare for the CISM Exam

CISM preparation requires a management-oriented mindset rather than relying only on technical knowledge or memorization. Focus on all four CISM domains and understand how security decisions align with business objectives, risk management, governance, security programs, and incident management.

Practice scenario-based questions regularly and review incorrect answers to understand the reasoning behind the appropriate management response. Structured CISM training can also help connect these concepts with exam-oriented business scenarios.

Conclusion

CISM has separate requirements for taking the exam and earning the certification. Candidates can take the examination before completing the full professional experience requirement, but certification requires meeting ISACA’s applicable experience, application, ethics, and maintenance requirements.
Candidates preparing in 2026 should also check their planned exam date carefully because the updated CISM Exam Content Outline takes effect on November 3, 2026.

Before registering for the exam or applying for certification, verify the latest requirements, fees, policies, and exam information directly with ISACA.

CISM Certification Training with InfosecTrain

Preparing for CISM involves more than remembering terminology. You need to understand how information security managers approach governance, risk, security programs, business priorities, and incident management.

InfosecTrain’s CISM Certification Training provides structured, instructor-led preparation across the CISM domains to help professionals:

  • Build a structured CISM preparation plan
  • Understand complex CISM concepts
  • Strengthen knowledge across weaker domains
  • Develop management-oriented thinking
  • Practice scenario-based exam questions
  • Learn from experienced instructors

Whether you are already managing security responsibilities or planning your transition toward security leadership, a structured preparation approach can help you identify gaps before the actual exam.

CERTIFIED INFORMATION SECURITY MANAGER (CISM) Training Course Page

TRAINING CALENDAR of Upcoming Batches For CISM Training

Start Date End Date Start - End Time Batch Type Training Mode Batch Status
10-Oct-2026 01-Nov-2026 19:00 - 23:00 IST Weekend Online [ Open ]
14-Nov-2026 06-Dec-2026 09:00 - 13:00 IST Weekend Online [ Open ]
05-Dec-2026 10-Jan-2027 09:00 - 13:00 IST Weekend Online [ Open ]
19-Dec-2026 17-Jan-2027 19:00 - 23:00 IST Weekend Online [ Open ]
23-Jan-2027 14-Feb-2027 09:00 - 13:00 IST Weekend Online [ Open ]
13-Feb-2027 07-Mar-2027 19:00 - 23:00 IST Weekend Online [ Open ]
20-Mar-2027 11-Apr-2027 09:00 - 13:00 IST Weekend Online [ Open ]

Frequently Asked Questions

What are the requirements for CISM certification?

Candidates must pass the CISM examination and satisfy ISACA’s applicable professional experience and certification application requirements. They must also comply with applicable professional ethics and certification maintenance requirements.

Do I need five years of experience before taking the CISM exam?

No. The full professional experience requirement does not need to be completed before taking the examination. However, applicable experience requirements must be satisfied before CISM certification can be awarded.

Can freshers take the CISM exam?

Yes. Freshers and early-career professionals can take the CISM examination before accumulating all the experience required for certification. They must complete the applicable experience requirements before becoming CISM certified.

CISM Exam Eligibility vs. Certification Eligibility: What’s the Difference?

Exam eligibility determines whether you can sit for the CISM examination. Certification eligibility includes additional requirements, particularly qualifying professional experience and the certification application.

How long do I have to apply for CISM certification after passing the exam?

Candidates have five years from the date they pass the CISM examination to apply for certification.

CISM vs. CISSP: How Do the Experience Requirements Differ?

CISM focuses on information security management experience, while CISSP requires experience across specified cybersecurity domains. Both are experience-based certifications, but their professional focus differs.

Does CISSP count toward the CISM experience requirement?

CISSP has been recognized within CISM experience substitution provisions. Because certification policies can change, candidates should verify the current substitution allowance with ISACA before applying.

CISM vs. CISA: What’s the Difference?

CISM focuses on information security management, governance, risk, and security programs, while CISA primarily focuses on IT auditing, assurance, and controls.

CISM vs. Security+: Which is More Suitable for Beginners?

Security+ is a foundational cybersecurity certification, while CISM focuses on information security management and is generally relevant to professionals progressing toward management and leadership responsibilities.

CISM vs. CRISC: What’s the Main Difference?

CISM focuses broadly on information security management, while CRISC has a stronger focus on IT risk management and information systems controls.

Is the CISM exam changing in 2026?

Yes. ISACA has announced an updated CISM Exam Content Outline effective November 3, 2026. The four domains remain, but their weightings change. Candidates taking the exam on or after this date should use preparation materials aligned with the updated outline.

How many CPE hours are required to maintain CISM certification?

CISM professionals currently need to earn and report at least 20 CPE hours annually and 120 CPE hours over a three-year reporting period.

ISACA-AAIR-Tips-Certification-event-banner
TOP