ISACA CISM: Cost, Exam Format, and the 5-Year Security Management Experience Requirement
Facts last verified against official sources: 2026-07-06
ISACA CISM costs $760 per exam attempt at ISACA's published price, verified 2026-07-06. Renewal: valid 3 years; 120 CPE hours (20 minimum per year) plus a mandatory Annual Maintenance Fee ($45/year members, $85/year nonmembers).
Occupation context
$129,180
BLS median, Information Security Analysts (May 2025)
190,650 people employed nationally
Salary figures are U.S. Bureau of Labor Statistics medians for the occupation shown, not a measured premium for holding this certification. No one publishes causal cert premiums; anyone quoting one is guessing.
How to prepare
Recommended resourcesSupplementary reference, not a recommendation ranking. Nothing here changes how this certification is scored or described.
Some study-resource and course links are affiliate links. If you buy through them we may earn a commission at no extra cost to you. This never affects which certification we recommend or how we describe it.
- Study guide
CISM Certified Information Security Manager Study Guide
Mike Chapple · Sybex (Wiley)
1st Edition, covering the 2022 CISM job practice, still current: ISACA's next content-outline update takes effect November 3, 2026 and updated prep material is not expected before then.
CISM is ISACA’s management-track credential, and the distinction that trips people up is that it is not a technical exam graded on tool knowledge. It tests whether you can run an information security program: govern it, size its risk, staff and fund it, and respond when something breaks. This page covers the five-year management experience requirement and how much of it can be waived, member versus nonmember pricing, the four domains and their weights, and nine years of renewal math.
Who this cert is actually for
CISM targets people who already manage information security rather than execute it hands-on: security managers, program leads, and people reporting to or aspiring to a CISO-track role. ISACA requires five years of professional information security experience, with a hard floor of three of those years spent in security management work spread across at least three of the four CISM domains, all gained within the ten years before you apply. Up to two years of the general five-year requirement can be waived through other credentials, education, or instructor experience, most notably an active CISSP, which alone accounts for the full two-year waiver. What cannot be waived under any combination is the three-year management-experience minimum; CISM is built to certify that you have actually run a program, and no substitution gets around that core requirement.
If you pass the exam before your experience clears, ISACA gives you five years from the pass date to apply for full certification once you meet the requirement, so a strong test result does not expire while you finish accumulating management time.
Skip CISM if your work is still hands-on technical security rather than program management; the exam’s governance and risk-framing questions assume you have made budget and staffing calls, not just configured controls. If audit and assurance is closer to your actual work than management, ISACA CISA is the better-fitting sibling credential, and if you are not yet at the five-year mark in any direction, CompTIA Security+ or CySA+ builds the foundation CISM assumes you already have. CISA vs CISM lays out that fork in full.
What it costs all-in
CISM shares ISACA’s membership-tiered pricing: $575 for members, $760 for nonmembers. This page uses $760 as the baseline, since most first-time candidates register before joining. As with CISA, weigh the $185 spread against current ISACA membership dues before defaulting to the nonmember rate, and remember the fee is nonrefundable once paid regardless of exam outcome.
ISACA’s own exam content outline is the free starting point for study, and a dedicated CISM study guide or question bank in the $40 to $80 range is typically enough beyond that, since the exam rewards scenario judgment more than raw memorization. A realistic self-study budget is $760 for the nonmember voucher plus $50 to $100 in prep, before any ISACA membership cost. Compare that figure against every other credential this site tracks on the ROI Index.
The exam itself
CISM runs 150 multiple-choice questions over four hours in a fixed-form exam, not a computerized-adaptive one, so every candidate sees the same question count. A passing result is a scaled score of 450 out of a possible 200-to-800 range, the same scale ISACA uses across its certification lineup. ISACA does not publish a pass rate for CISM or any of its other credentials.
Four domains make up the current job practice, and getting the count right matters since CISM’s four-domain structure is easy to confuse with CISA’s five or CISSP’s eight: Information Security Governance (17 percent), Information Security Risk Management (20 percent), Information Security Program (33 percent, the largest single domain by a wide margin), and Incident Management (30 percent). Those four weights sum to exactly 100 percent, and the fact that Information Security Program and Incident Management together account for 63 percent of the exam reflects how much of CISM is about running and defending a program day to day, versus the smaller governance and risk-framing slices most candidates expect to dominate a management exam.
Renewal math over 9 years
CISM is valid for three years, so nine years covers three renewal cycles, and the CPE structure mirrors CISA’s exactly: 120 CPE hours per cycle, with a 20-hour annual minimum so the requirement cannot be crammed into the final year.
The Annual Maintenance Fee also matches CISA’s schedule: $45 a year for members, $85 a year for nonmembers, due by January 1 to stay active for the coming year. That works out to $135 per cycle for members or $255 for nonmembers, and $405 to $765 across nine years depending on membership status. Holding CISM alongside another ISACA certification does not multiply this fee past the third credential; the rate drops to $25 (members) or $50 (nonmembers) for your third and any subsequent ISACA credential, which is worth knowing if CISA is also on your roadmap.
What it does for the occupation you are entering
CISM maps to the information security analyst occupation (BLS code 15-1212), though in practice CISM holders more often carry titles like security manager, program lead, or a step toward CISO that the BLS occupational structure does not break out separately. The panel on this page shows the current national median wage and headcount for the broader occupation; read it as a description of the field CISM sits atop, not a wage this specific credential guarantees. The Bureau of Labor Statistics projects continued strong growth in information security roles overall, and CISM’s role in that growth is as the recognized signal that a candidate can run a program rather than just execute inside one, useful on postings where governance, budget ownership, and cross-team coordination matter as much as technical depth.
Common mistakes
Assuming CISSP fully waives the CISM experience like it does for CCSP. An active CISSP only cuts two years off CISM’s five-year requirement; it does not eliminate the mandatory three years of security management experience the way it can waive an entire requirement elsewhere. Check the specific waiver rule for each credential rather than assuming they behave the same way. CISSP vs CISM covers how the two credentials actually differ beyond the waiver math.
Treating CISM as a technical certification. Candidates who study it like a hands-on security exam are often surprised that Information Security Program and Incident Management, the two largest domains, test program-level judgment: policy, staffing, escalation, and recovery decisions, not configuration steps.
Letting the five-year apply-by window slip your mind. Passing the exam without the experience yet is common and fine, but ISACA still requires the certification application within five years of your pass date. Track that date the same way you would track a renewal deadline.
Pay less for this exam
The legitimate ways to pay under list price for ISACA CISM, verified in the discounts guide. No coupon codes, no gray-market vouchers.
- Served in the military? The GI Bill reimburses approved certification tests up to $2,000 per test (check the VA's approved list before booking), and VR&E can cover costs directly for eligible veterans.
- Employed? Ask about certification reimbursement before you pay anything; many employers cover the exam outright or on a pass, and some cover renewals.
- Vendors announce price increases ahead of time and vouchers stay valid for months, so a ready candidate can buy at the old price; increases land in the price watch as we verify them.
Quick answers
- How much does ISACA CISM cost?
- ISACA CISM costs $760 per exam attempt at ISACA's published price. Legitimate ways to pay less are covered in the pay-less section on this page.
- Does ISACA CISM expire?
- Per ISACA's published terms: valid 3 years; 120 CPE hours (20 minimum per year) plus a mandatory Annual Maintenance Fee ($45/year members, $85/year nonmembers).
- How do you renew ISACA CISM?
- The verified renewal terms: valid 3 years; 120 CPE hours (20 minimum per year) plus a mandatory Annual Maintenance Fee ($45/year members, $85/year nonmembers). The renewal-costs guide compares what each model costs over nine years, and the true-cost calculator prices this certification over your own horizon.
- How long is the ISACA CISM exam?
- ISACA's published format: 150 multiple-choice questions, 4 hours, fixed-form (not adaptive); pass scaled at 450/800.
Every figure above comes from the verified facts panel on this page; see the true-cost calculator for multi-year math and renewal costs explained for the four renewal models.
General information, not career or financial advice
CertiGuard documents costs, exam mechanics, and public salary data. Whether a certification pays off for you depends on your market, employer, and experience. Treat this as a starting point, not a promise.
Official sources
- ISACA: CISM certification overview and exam fees ($575 member / $760 nonmember)
- ISACA: CISM exam content outline (4 domains and weights)
- ISACA Certification Exam Candidate Guide v1.26 (exam length, question count, fee schedule)
- ISACA: earn a CISM certification (experience requirement text, domain distribution, 5-year application window)
- ISACA: maintain CISM certification (120 CPE / 3 years, 20/year minimum, AMF)
Cite this page