CISM
What is on the ISACA CISM exam, and what changes on 3 November 2026?

The ISACA CISM exam is 150 multiple-choice questions in 4 hours, scored from 200 to 800 with 450 to pass. Which outline it tests depends on your date. Up to and including 2 November 2026 it follows the outline effective 2022; from 3 November 2026 a new outline applies, with the same four domains, slightly different weights and two new content areas.
Every fact below comes from ISACA: the Certification Exam Candidate Guide, version 1.26, the CISM page and exam content outline, and ISACA's press release of 10 September 2026, all read on 2 October 2026.
What changes on 3 November 2026?
ISACA's outline page carries the notice: "the CISM Exam Content Outline will be updated effective 3 November 2026. Starting on that date the CISM Exam will reflect the new Exam Content Outline." The press release says the four domains stay the same, and the distribution of content "will slightly change".
| Domain | Up to 2 Nov 2026 | From 3 Nov 2026 |
|---|---|---|
| 1. Information Security Governance | 17% | 18% |
| 2. Information Security Risk Management | 20% | 20% |
| 3. Information Security Program | 33% | 33% |
| 4. Incident Management | 30% | 29% |
The updated outline "will include greater emphasis on information security strategy and program development, and will add two new content areas: enterprise architecture and information security architecture." ISACA strongly recommends updated preparation materials for anyone sitting on or after 3 November 2026.
ISACA press release, 10 September 2026
On 2 October 2026 ISACA had not yet published the full 2026 topic list on its outline page, and the Candidate Guide still printed the 2022 outline. If you sit after 2 November, check the outline page before you plan, and treat any detailed 2026 topic list from elsewhere with care until ISACA publishes its own.
What does the 2022 outline cover?
For exams up to 2 November 2026, each domain has two subdomains, and 37 tasks sit beneath them.
- Information Security Governance, 17%: enterprise governance; information security strategy
- Information Security Risk Management, 20%: risk assessment; risk response
- Information Security Program, 33%: program development; program management
- Incident Management, 30%: incident management readiness; incident management operations
The program and incident management domains are 63% of the exam between them. Governance is the smallest.
How is the CISM exam structured and scored?
150 multiple-choice questions in 4 hours, each with four options and one best answer, some after a short scenario. There is no penalty for a wrong answer. Scores run from 200 to 800 and 450 or higher passes. Pretest items are included and do not count, and the domain percentages describe the exam's content, not how your score is calculated.
ISACA Certification Exam Candidate Guide v1.26
That is about 1 minute 36 seconds a question. You sit at a PSI test center or online with a remote proctor, in English, Spanish, Simplified Chinese, Japanese, French or German. A preliminary result shows on screen, and the official score arrives within 10 working days.
What does the CISM cost, and what are the rules?
Registration is USD 575 for ISACA members and USD 760 for non-members, nonrefundable, and you have six months to sit, with one six-month extension for USD 75. You get four attempts in a rolling 12 months, waiting 30 days, then 90, then 90, and paying the full fee each time. After passing, the application costs USD 50 and annual maintenance USD 45 for members or USD 85 for non-members, with 20 CPE hours a year and 120 over three years.
CISM study planner for both outlines
ISACA CISM: study planner for both outlines
Weights come from the ISACA Certification Exam Candidate Guide, version 1.26 (the outline effective 2022), and ISACA's press release of 10 September 2026 (the outline effective 3 November 2026), read on 2 October 2026. ISACA does not recommend a number of study hours; the budgets and the split are our suggestion, in proportion to the published weights.
Which outline is yours?
| Your exam date | Outline | Domain weights |
|---|---|---|
| On or before 2 November 2026 | Effective 2022 | 17%, 20%, 33%, 30% |
| On or after 3 November 2026 | Effective 3 November 2026 | 18%, 20%, 33%, 29% |
Hours by domain
| Domain | 2022 weight | 2022, 100 hours | 2026 weight | 2026, 100 hours |
|---|---|---|---|---|
| 1. Information Security Governance | 17% | 17 | 18% | 18 |
| 2. Information Security Risk Management | 20% | 20 | 20% | 20 |
| 3. Information Security Program | 33% | 33 | 33% | 33 |
| 4. Incident Management | 30% | 30 | 29% | 29 |
| Total | 100% | 100 | 100% | 100 |
For 50 hours, halve each figure; for 150, multiply by 1.5.
2022 subdomains
| Domain | Subdomain A | Subdomain B | Read | Studied | Practiced |
|---|---|---|---|---|---|
| 1 | Enterprise Governance | Information Security Strategy | [ ] | [ ] | [ ] |
| 2 | Information Security Risk Assessment | Information Security Risk Response | [ ] | [ ] | [ ] |
| 3 | Information Security Program Development | Information Security Program Management | [ ] | [ ] | [ ] |
| 4 | Incident Management Readiness | Incident Management Operations | [ ] | [ ] | [ ] |
Sitting on or after 3 November 2026
ISACA says the four domains stay the same, with "greater emphasis on information security strategy and program development", and two new content areas: enterprise architecture and information security architecture. On 2 October 2026 ISACA had not published the full 2026 topic list on its outline page. Check it before you plan.
- 2026 outline downloaded from ISACA when published (ISACA)
- Hours added for enterprise architecture and information security architecture (our suggestion)
- ISACA's updated preparation materials, which ISACA "strongly recommended" for exams on or after 3 November 2026 (ISACA)
Pace for timed practice
| Set | Questions | Time at the exam's average pace |
|---|---|---|
| One question | 1 | 1 minute 36 seconds |
| Short timed set | 25 | 40 minutes |
| Full paper | 150 | 4 hours |
What experience do you need?
Five or more years of information security management experience, across at least three of the four CISM domains, gained within the 10 years before you apply. ISACA allows waivers for up to two of those years. You may sit the exam first, and you then have five years from passing to apply.
Which outside frameworks help?
The incident management domain maps well onto NIST SP 800-61 Rev. 3 and the UK NCSC's incident management guidance. For governance and program structure, the NIST Cybersecurity Framework 2.0 and the NCSC's Cyber Assessment Framework give a useful vocabulary. The exam tests ISACA's outline, so use them to understand it.
Are our CISM books right for your exam date?
Our CISM exam guide and CISM practice questions with rationales follow the outline effective 2022. If you sit on or before 2 November 2026, they match your exam. If you sit later, the weights move by one point in two domains and two content areas are added, so use ISACA's updated materials for those areas alongside them.
What should you do this week?
Check your exam date against 3 November 2026, take the matching column in the planner, and book your hours. Credential Press is independent of ISACA, and nothing here comes from inside the exam.
Frequently asked questions
When does the CISM exam change?
On 3 November 2026. Exams up to and including 2 November 2026 follow the outline effective 2022; from 3 November the new outline applies.
What changes in the 2026 CISM outline?
The four domains stay. Governance moves from 17% to 18% and incident management from 30% to 29%, risk management stays at 20% and the information security program at 33%. ISACA adds two content areas, enterprise architecture and information security architecture, with more emphasis on strategy and program development.
How many questions are on the CISM exam?
150 multiple-choice questions in 4 hours, each with four options and one best answer. Some are unscored pretest items, and ISACA does not publish how many.
What is the CISM passing score?
450 on a scale of 200 to 800. It is a scaled score, and ISACA publishes no conversion from raw marks, so there is no percentage pass mark.
What experience does the CISM need?
Five or more years of information security management experience, across at least three of the four CISM domains, gained within the 10 years before you apply. Waivers can cover up to two years. You can sit the exam first and have five years from passing to apply.
Which CISM domain is the largest?
Information Security Program, at 33% under both the 2022 and the 2026 outline. Incident management is next, at 30% before 3 November 2026 and 29% after.
CISM: for interviews and hiring
Which books prepare you for the CISM?

Certified Information Security Manager. 12 chapters, 342 pages.

Practice questions with full rationales, sized to the published domain weights. 213 pages.
Sources
Every figure above was read from the document itself on 2 October 2026.
- ISACA, Certification Exam Candidate Guide, version 1.26, 2026
- ISACA, CISM Exam Content Outline
- ISACA, Get CISM Certified
- ISACA, "ISACA Updates CISM Exam Content Outline, Factoring in Today's Technologies, Security Responsibilities", 10 September 2026
- NIST, SP 800-61 Rev. 3, Incident Response Recommendations and Considerations
Credential Press is not affiliated with, endorsed by or authorized by ISACA. Exam names and trademarks belong to their owners.