CISM

What is on the ISACA CISM exam, and what changes on 3 November 2026?

CISM weights before and after 3 November 2026: Governance 17% to 18%, Risk Management 20%, Program 33%, Incident Management 30% to 29%, plus two new areas, enterprise architecture and information security architecture.

The ISACA CISM exam is 150 multiple-choice questions in 4 hours, scored from 200 to 800 with 450 to pass. Which outline it tests depends on your date. Up to and including 2 November 2026 it follows the outline effective 2022; from 3 November 2026 a new outline applies, with the same four domains, slightly different weights and two new content areas.

150Questions
4 hrsTime
450To pass (200 to 800)
3 NovNew outline

Every fact below comes from ISACA: the Certification Exam Candidate Guide, version 1.26, the CISM page and exam content outline, and ISACA's press release of 10 September 2026, all read on 2 October 2026.

What changes on 3 November 2026?

ISACA's outline page carries the notice: "the CISM Exam Content Outline will be updated effective 3 November 2026. Starting on that date the CISM Exam will reflect the new Exam Content Outline." The press release says the four domains stay the same, and the distribution of content "will slightly change".

DomainUp to 2 Nov 2026From 3 Nov 2026
1. Information Security Governance17%18%
2. Information Security Risk Management20%20%
3. Information Security Program33%33%
4. Incident Management30%29%
ISACA, 10 September 2026

The updated outline "will include greater emphasis on information security strategy and program development, and will add two new content areas: enterprise architecture and information security architecture." ISACA strongly recommends updated preparation materials for anyone sitting on or after 3 November 2026.

ISACA press release, 10 September 2026

On 2 October 2026 ISACA had not yet published the full 2026 topic list on its outline page, and the Candidate Guide still printed the 2022 outline. If you sit after 2 November, check the outline page before you plan, and treat any detailed 2026 topic list from elsewhere with care until ISACA publishes its own.

What does the 2022 outline cover?

For exams up to 2 November 2026, each domain has two subdomains, and 37 tasks sit beneath them.

  • Information Security Governance, 17%: enterprise governance; information security strategy
  • Information Security Risk Management, 20%: risk assessment; risk response
  • Information Security Program, 33%: program development; program management
  • Incident Management, 30%: incident management readiness; incident management operations

The program and incident management domains are 63% of the exam between them. Governance is the smallest.

How is the CISM exam structured and scored?

ISACA rule

150 multiple-choice questions in 4 hours, each with four options and one best answer, some after a short scenario. There is no penalty for a wrong answer. Scores run from 200 to 800 and 450 or higher passes. Pretest items are included and do not count, and the domain percentages describe the exam's content, not how your score is calculated.

ISACA Certification Exam Candidate Guide v1.26

That is about 1 minute 36 seconds a question. You sit at a PSI test center or online with a remote proctor, in English, Spanish, Simplified Chinese, Japanese, French or German. A preliminary result shows on screen, and the official score arrives within 10 working days.

What does the CISM cost, and what are the rules?

Registration is USD 575 for ISACA members and USD 760 for non-members, nonrefundable, and you have six months to sit, with one six-month extension for USD 75. You get four attempts in a rolling 12 months, waiting 30 days, then 90, then 90, and paying the full fee each time. After passing, the application costs USD 50 and annual maintenance USD 45 for members or USD 85 for non-members, with 20 CPE hours a year and 120 over three years.

CISM study planner for both outlines

ISACA CISM: study planner for both outlines

Weights come from the ISACA Certification Exam Candidate Guide, version 1.26 (the outline effective 2022), and ISACA's press release of 10 September 2026 (the outline effective 3 November 2026), read on 2 October 2026. ISACA does not recommend a number of study hours; the budgets and the split are our suggestion, in proportion to the published weights.

Which outline is yours?

Your exam dateOutlineDomain weights
On or before 2 November 2026Effective 202217%, 20%, 33%, 30%
On or after 3 November 2026Effective 3 November 202618%, 20%, 33%, 29%

Hours by domain

Domain2022 weight2022, 100 hours2026 weight2026, 100 hours
1. Information Security Governance17%1718%18
2. Information Security Risk Management20%2020%20
3. Information Security Program33%3333%33
4. Incident Management30%3029%29
Total100%100100%100

For 50 hours, halve each figure; for 150, multiply by 1.5.

2022 subdomains

DomainSubdomain ASubdomain BReadStudiedPracticed
1Enterprise GovernanceInformation Security Strategy[ ][ ][ ]
2Information Security Risk AssessmentInformation Security Risk Response[ ][ ][ ]
3Information Security Program DevelopmentInformation Security Program Management[ ][ ][ ]
4Incident Management ReadinessIncident Management Operations[ ][ ][ ]

Sitting on or after 3 November 2026

ISACA says the four domains stay the same, with "greater emphasis on information security strategy and program development", and two new content areas: enterprise architecture and information security architecture. On 2 October 2026 ISACA had not published the full 2026 topic list on its outline page. Check it before you plan.

  • 2026 outline downloaded from ISACA when published (ISACA)
  • Hours added for enterprise architecture and information security architecture (our suggestion)
  • ISACA's updated preparation materials, which ISACA "strongly recommended" for exams on or after 3 November 2026 (ISACA)

Pace for timed practice

SetQuestionsTime at the exam's average pace
One question11 minute 36 seconds
Short timed set2540 minutes
Full paper1504 hours

What experience do you need?

Five or more years of information security management experience, across at least three of the four CISM domains, gained within the 10 years before you apply. ISACA allows waivers for up to two of those years. You may sit the exam first, and you then have five years from passing to apply.

Which outside frameworks help?

The incident management domain maps well onto NIST SP 800-61 Rev. 3 and the UK NCSC's incident management guidance. For governance and program structure, the NIST Cybersecurity Framework 2.0 and the NCSC's Cyber Assessment Framework give a useful vocabulary. The exam tests ISACA's outline, so use them to understand it.

Are our CISM books right for your exam date?

Our CISM exam guide and CISM practice questions with rationales follow the outline effective 2022. If you sit on or before 2 November 2026, they match your exam. If you sit later, the weights move by one point in two domains and two content areas are added, so use ISACA's updated materials for those areas alongside them.

What should you do this week?

Check your exam date against 3 November 2026, take the matching column in the planner, and book your hours. Credential Press is independent of ISACA, and nothing here comes from inside the exam.

Frequently asked questions

When does the CISM exam change?

On 3 November 2026. Exams up to and including 2 November 2026 follow the outline effective 2022; from 3 November the new outline applies.

What changes in the 2026 CISM outline?

The four domains stay. Governance moves from 17% to 18% and incident management from 30% to 29%, risk management stays at 20% and the information security program at 33%. ISACA adds two content areas, enterprise architecture and information security architecture, with more emphasis on strategy and program development.

How many questions are on the CISM exam?

150 multiple-choice questions in 4 hours, each with four options and one best answer. Some are unscored pretest items, and ISACA does not publish how many.

What is the CISM passing score?

450 on a scale of 200 to 800. It is a scaled score, and ISACA publishes no conversion from raw marks, so there is no percentage pass mark.

What experience does the CISM need?

Five or more years of information security management experience, across at least three of the four CISM domains, gained within the 10 years before you apply. Waivers can cover up to two years. You can sit the exam first and have five years from passing to apply.

Which CISM domain is the largest?

Information Security Program, at 33% under both the 2022 and the 2026 outline. Incident management is next, at 30% before 3 November 2026 and 29% after.

CISM: for interviews and hiring

Which books prepare you for the CISM?

Cover of CISM Exam Guide

CISM Exam Guide

Certified Information Security Manager. 12 chapters, 342 pages.

Cover of CISM Practice Questions

CISM Practice Questions

Practice questions with full rationales, sized to the published domain weights. 213 pages.