The Certified Information Security Manager (CISM)® is built for a specific career moment: the point where you stop only defending systems and start owning the security program. If you’re aiming for a role where you set strategy, manage risk, report to executives, and lead incident response, CISM is designed to prove you’re ready.
In this guide, we’ll help you decide whether CISM fits your career now, walk you through ISACA’s eligibility rules and costs, map out a realistic study plan, and look at careers, salary data, renewal, and smart next credentials.
Who Should Take the CISM Exam?
CISM is a management credential. It’s a strong fit if you already work in information security and you are moving toward, or already in, a leadership role. Common candidates include:
- Security managers and team leads who run a security function and want formal validation.
- Senior security analysts and engineers preparing for a first management role.
- IT risk, GRC, and compliance professionals who build policies, run risk assessments, and report to leadership.
- Incident response and security operations leads who own response plans and coordinate across teams.
- Aspiring CISOs and directors of information security who need an employer-recognized credential for program leadership.
Who Might Want to Wait?
If you’re new to IT or security, CISM may be early. The exam assumes you understand how governance, risk, and incident programs work inside a real organization, and certification requires years of documented experience. An entry-level credential such as ISC2 Certified in Cybersecurity (CC) or CompTIA Security+ is often a better first step. If you’re deeply technical and plan to stay that way, a hands-on certification may serve you better than a management credential.
What Are the CISM Eligibility Requirements?
With CISM, passing the exam and becoming certified are separate steps. You can take the exam before you meet the experience requirement. According to ISACA’s Get CISM Certified page and the Exam Candidate Guide, you must:
- Pass the CISM exam within the last five years.
- Document at least five years of information security management work experience.
- Cover at least three of the four CISM domains in that experience.
- Earn the experience within the 10 years before your application date.
- Apply within five years of passing the exam and pay the US$50 application processing fee.
- Agree to follow ISACA’s Code of Professional Ethics and Continuing Professional Education (CPE) Policy.
ISACA allows experience waivers for up to two of the five years. The list of qualifying waivers is in ISACA’s CISM requirements article, so check it before assuming a degree or other certification counts. Rules can change, so confirm your situation there before you pay.
How Do You Register, and What Does It Cost?
Registration is continuous. You pay online, and you can schedule as soon as 48 hours after payment. Your registration gives you a six-month window to test at a PSI center or online. ISACA lists the exam fee at $575 for members and $760 for non-members. If you plan to take the exam and maintain the credential, compare the cost of ISACA membership with the member savings.
One timing note: ISACA’s updated CISM outline applies to exams taken on or after November 3, 2026, and the previous outline applies through November 2. The four domains are the same, but the weights shift slightly, and enterprise and information security architecture are new content areas. If your six-month window spans that date, the outline you test under depends on the day you sit, so choose your test date on purpose and use study materials that match it.
How Long Should You Study for the CISM Exam?
Most candidates need about two to four months of steady study. Experienced security managers who already run risk assessments and incident response may need eight to ten weeks. Technical professionals new to governance and program management should plan for the longer end, because the hardest part is learning to choose the managerial answer.
Sample 12-Week CISM Study Plan
- Week 1: Take a mixed baseline quiz, read the content outline that matches your test date, and schedule your exam.
- Weeks 2 and 3: Domain 1, Governance (18%). Focus on strategy development, governance frameworks, roles, legal and regulatory requirements, and business cases.
- Weeks 4 and 5: Domain 2, Risk Management (20%). Cover risk assessment methods, risk appetite, treatment options, and risk reporting.
- Weeks 6 to 8: Domain 3, Information Security Program (33%). Study program development, policy structure, asset classification, control design and testing, awareness, third-party risk, and metrics. Add time for the new enterprise and information security architecture topics.
- Weeks 9 and 10: Domain 4, Incident Management (29%). Cover the incident response plan, BCP and DRP alignment, classification, handling, testing, and post-incident review.
- Week 11: Take a full-length timed practice exam and review every miss by domain.
- Week 12: Do targeted review of weak areas, then take light mixed sets and rest before test day.
For experienced managers: Compress Weeks 2 to 10 into five or six weeks and spend the saved time on practice questions. Your biggest risk is answering from your own company’s habits instead of ISACA’s framework.
For technical professionals: Keep the full 12 weeks and spend extra time on Domains 1 and 2. Your technical background is an advantage on the new architecture topics, as long as you answer from the manager’s seat. When you review a miss, ask what a manager accountable to the board would do.
What Careers Can the CISM Support?
CISM is widely requested for security leadership roles. Job titles that commonly list it include:
- Information Security Manager
- IT Risk Manager or GRC Manager
- Security Program Manager
- Director of Information Security
- Chief Information Security Officer (CISO)
- Security Consultant or Advisory Manager
These roles exist across finance, healthcare, government, technology, and consulting, and anywhere else regulators and boards expect a defined security program.
What Is the Salary for CISM Holders?
The U.S. Bureau of Labor Statistics (BLS) doesn’t track pay by certification, but two occupations cover most CISM roles. BLS reports a median annual wage of $175,140 for computer and information systems managers in May 2025, with employment projected to grow 16% from 2025 to 2035. For information security analysts, the May 2025 median was $129,180, with 21% projected growth over the same period, much faster than average.
ISACA’s CISM page lists an average salary of $149,000+ for CISM holders. Your pay will depend on your role, region, industry, and leadership scope.
How Do You Maintain the CISM?
CISM doesn’t expire on a fixed date as long as you keep up with ISACA’s maintenance requirements:
- CPE hours: At least 20 CPE hours each year and 120 hours over each three-year reporting period.
- Annual maintenance fee: US$45 for members or US$85 for non-members, due by January 1. The fee is lower if you hold three or more ISACA certifications.
- Audit readiness: Keep certificates or attendance records. ISACA randomly audits CPE reports.
- Ethics: Continue to follow the ISACA Code of Professional Ethics.
What Certifications Stack Well With the CISM?
The best next credential depends on where you want your leadership role to go:
- CRISC (Certified in Risk and Information Systems Control): Goes deeper on enterprise IT risk and controls, building on CISM Domain 2.
- CISA (Certified Information Systems Auditor): Adds the audit and assurance view, useful if you work closely with internal audit or regulators.
- CGEIT (Certified in the Governance of Enterprise IT): Moves up to enterprise IT governance for senior leadership and board-facing roles.
- CISSP (Certified Information Systems Security Professional): Adds broad technical and architectural depth, which many CISO job postings pair with CISM.
- CCSP (Certified Cloud Security Professional): Useful if your program is moving heavily to the cloud.
Start Preparing for the CISM Exam With Pocket Prep
Whether you’re a new manager or a seasoned security leader, Pocket Prep’s ISACA CISM practice questions can fit your study plan. You get 1,000 questions with detailed explanations, a full-length mock exam, and tools like Missed Questions and study reminders to keep you on track. Pick a test date, start small, and build momentum.