Skip to content
CertiGuard

Search

Type a word like "security+" or "ccna". Search runs on the published site.

ISACA CISA vs CISM: Audit Track or Management Track?

By Mario Bailey, Editor

Facts last verified against official sources: 2026-07-06

The verdict

CISA certifies that you can audit a security program from the outside; CISM certifies that you can run one from the inside. Both cost ISACA members the same $575 (nonmembers $760) and renew the same way; the fork is in the job you do, not in what ISACA charges for it.

ISACA CISA
Vendor
ISACA
Cost
$760
Exam format
150 multiple-choice questions, 4 hours, fixed-form (not adaptive); pass scaled at 450/800
Renewal
Valid 3 years; 120 CPE hours (20 minimum per year) plus a mandatory Annual Maintenance Fee ($45/year members, $85/year nonmembers)
Associated occupation
Information Security Analysts, $129,180 median
Experience level
Advanced
ISACA CISM
Vendor
ISACA
Cost
$760
Exam format
150 multiple-choice questions, 4 hours, fixed-form (not adaptive); pass scaled at 450/800
Renewal
Valid 3 years; 120 CPE hours (20 minimum per year) plus a mandatory Annual Maintenance Fee ($45/year members, $85/year nonmembers)
Associated occupation
Information Security Analysts, $129,180 median
Experience level
Advanced

Salary figures are U.S. Bureau of Labor Statistics medians for the occupation shown, not a measured premium for holding this certification. No one publishes causal cert premiums; anyone quoting one is guessing.

CISA and CISM are ISACA’s two flagship advanced credentials, and it is easy to assume they sit on a single ladder the way, say, Network+ sits below CCNA. They do not. They are siblings built for two different jobs inside the same field, priced and renewed identically by the same vendor, but gated by two experience requirements that look alike on paper and behave differently underneath.

Same vendor, same bill

Strip away domain content and the mechanics are identical. Both cost $575 for ISACA members and $760 for nonmembers, since most first-time candidates have not joined before registering. Both run 150 multiple-choice questions over four hours in a fixed-form exam, not adaptive, so every candidate answers the same question count, scored on the same 200-to-800 scale with 450 as the pass mark. Both are valid three years, require 120 CPE hours per cycle with a 20-hour annual minimum, and carry the same Annual Maintenance Fee schedule: $45 a year for members, $85 for nonmembers, dropping to $25 or $50 for a third or later ISACA credential. None of that differs between them. What differs is the job each one describes.

The audit track: CISA

CISA’s five domains weight toward operations and asset protection after ISACA’s 2024 rebalance: Information System Auditing Process and Governance and Management of IT each carry 18 percent, Information Systems Acquisition, Development and Implementation carries 12 percent, and Information Systems Operations and Business Resilience ties with Protection of Information Assets at 26 percent apiece, the two largest slices. The prerequisite is five years of IS/IT audit, control, assurance, or security experience within the preceding ten years. Up to three of those five years can be waived through education, an associate’s degree worth one year, a bachelor’s worth two, a master’s in a related field worth three, but no combination of waivers can push the requirement below two years of real experience. ISACA’s 2025 CISA Associate designation lets you pass the exam first and take four years to convert once your experience catches up.

The management track: CISM

CISM’s four domains concentrate even harder: Information Security Governance is 17 percent, Information Security Risk Management is 20 percent, and Information Security Program and Incident Management together make up 63 percent, Program alone the single largest domain at 33 percent. The prerequisite is also five years, but shaped differently: a hard floor of three years must be actual security management work spread across at least three of the four domains. Up to two years of the general five can be waived, most notably by an active CISSP, which alone covers the full two-year allowance, but nothing waives the three-year management floor itself. Pass the exam early and ISACA gives you five years to apply once the experience requirement is met.

Where the floors actually diverge

Here is the arithmetic worth doing rather than assuming. CISA allows waiving up to three of its five years through education substitutions, 3 divided by 5, or 60 percent of the total requirement, leaving a real floor of two years, 40 percent. CISM allows waiving at most two of its five years, 2 divided by 5, 40 percent, leaving a real floor of three years, 60 percent, and that floor must specifically be management experience. The two credentials advertise the identical headline number, five years, but CISA lets you waive more of it on paper (60 percent) while CISM demands more of it stay real, unwaivable experience (60 percent floor). Assuming either one’s waiver structure applies to the other is the single easiest way to misjudge how much actual time you still owe.

Stacking both, and where CISSP fits in

Because ISACA’s AMF drops for a third ISACA credential, holding CISA and CISM together, and eventually a third ISACA badge, does not multiply your annual fee the way the base price schedule alone would suggest. And because an active CISSP covers CISM’s entire two-year waiver allowance by itself, someone sequencing CISSP, then CISM, or CISSP alongside CISA, is really optimizing across two vendors’ rules simultaneously, ISC2’s waiver feeding into ISACA’s requirement, not just working through ISACA’s system in isolation.

Which one first, honestly

If your actual work is testing and verifying controls rather than owning them, CISA fits, and CISM would misdescribe what you do day to day. If you already manage a security function or budget, or you are aiming at a CISO-track role, CISM fits for the mirror-image reason. Neither ISACA credential is designed as a stepping stone to the other; “both, eventually” only makes sense for someone whose career genuinely moves from audit work into program ownership, not as a default double-credential play for anyone who happens to work at ISACA’s advanced tier.

Common mistake

Treating the domain counts, five for CISA, four for CISM, as the only thing to keep straight is a common and forgivable slip. The costlier mistake is assuming the experience floors match because the headline “five years” does. Check which years are waivable and which are locked before you promise a hiring manager, or yourself, a shortcut that only applies to one of the two.

General information, not career or financial advice

CertiGuard documents costs, exam mechanics, and public salary data. Whether a certification pays off for you depends on your market, employer, and experience. Treat this as a starting point, not a promise.

Official sources

Cite this page