CISM or CISSP
CISM or CISSP: which suits a security manager?

The CISM and the CISSP both claim the security manager. ISACA says the CISM validates "a modern IT security manager", and ISC2 names "Security Manager" among the roles the CISSP suits. They test different things, in different ways, at different prices. This page puts the two side by side from each board's own pages, read on 2 October 2026.
How do the two exams compare?
| CISM (ISACA) | CISSP (ISC2) | |
|---|---|---|
| Format | 150 multiple-choice questions | Adaptive, 100 to 150 items, including advanced item types |
| Time | 4 hours | Up to 3 hours |
| Pass mark | 450 on a 200 to 800 scale | 700 of 1000 |
| Domains | 4 | 8 |
| Where | PSI test center or remotely proctored | Pearson VUE test center only |
| Exam fee | US$575 member, US$760 non-member | US$749 (EUR 719.04 in EMEA, GBP 606.69 in the UK) |
| Experience to certify | 5 years in information security management, in at least 3 of the 4 domains; waivers up to 2 | 5 years in at least 2 of the 8 domains; one year can be waived |
| Upkeep | US$45 or US$85 a year; 120 CPE hours per 3 years, at least 20 a year | US$135 a year; 120 CPE credits per 3 years |
Sources: ISACA's Exam Candidate Guide, version 1.26 and CISM page; ISC2's CISSP exam outline, adaptive testing FAQ and exam pricing. Our guides to the CISM exam and the CISSP exam have the detail.
What does each exam cover?
The CISM is management from end to end. Under the outline in force until 2 November 2026, its four domains are Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%) and Incident Management (30%). From 3 November 2026 the weights become 18, 20, 33 and 29, and ISACA adds enterprise architecture and information security architecture as content areas.
The CISSP is broader, and it is adaptive: ISC2 does not permit item review, so each answer is final. Its eight domains run from Security and Risk Management (16%) through Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, Security Assessment and Testing, and Security Operations, to Software Development Security (10%). Roughly the first domain overlaps with the CISM's governance and risk; the network, architecture, identity and software domains have no CISM equivalent.
Which suits which person?
Our reading of the two outlines and the boards' own audience statements:
- A manager who runs a security program and rarely touches the technology fits the CISM's four management domains.
- A manager, architect or engineer who needs breadth across the technical domains fits the CISSP, which ISC2 says is "ideal for experienced security practitioners, managers and executives".
- Someone sitting before 3 November 2026 should know which CISM outline applies; study material written to the 2022 outline fits exams up to 2 November 2026.
- Someone who needs to sit online can do so for the CISM, not for the CISSP.
What do they cost over three years?
Passing first time, with no course: the CISM costs a non-member US$1,065 (760 exam, 50 application, three years at 85) and an ISACA member US$760 plus membership dues. The CISSP costs US$1,154 (749 exam, three years at 135). ISACA charges the full fee again for each attempt; at ISC2 a retake is a new exam purchase unless you bought "Peace of Mind Protection", which gives two attempts within 180 days. The certification cost guide for teams has the full arithmetic and a budget sheet.
Role-to-credential matrix
Person,Current role,Main work today,Candidate credential,Board's audience statement fits (yes or no),Experience needed to certify,Experience held,Gap (years or hours),Can sit before the experience? ,Target exam date,Exam outline version and date,Book,Notes Example: GRC analyst,GRC analyst,IT risk assessments and control testing,CRISC (ISACA),yes,3 years IT risk management and IS control (no waivers),2 years,1 year,Check with ISACA before booking,2027-03-01,Check isaca.org/credentialing/crisc,CRISC Exam Guide, ,,,,,,,,,,,, ,,,,,,,,,,,, ,,,,,,,,,,,, "Experience rules read from each board's pages on 2 October 2026: ISACA (CISA 5 years, CISM 5 years, CRISC 3 years), ISC2 (CISSP and CCSP 5 years), PECB ISO Lead Implementer (5 years, 2 in the field, 300 project hours), GARP FRM (2 years full-time risk management). IAPP documents we read state no experience prerequisite for CIPP/E, CIPP/US, CIPM or CIPT. Template from credentialpress.com/guides/which-certification-for-which-role.",,,,,,,,,,,,
How should you prepare for each?
Split your hours by each board's weights. For the CISSP, our CISSP study plan by domain divides 100 or 200 hours across the eight domains and covers practice for an adaptive exam. For the CISM, check your exam date first, then use the CISM exam guide, which follows the 2022 outline for exams up to 2 November 2026. The CISSP exam guide prints each domain's weight at its head.
What should you do this week?
Write down what you do most weeks, then read both outlines against it. If most of it is program management, governance and incidents, book the CISM; if it spans architecture, networks and identity as well, book the CISSP. Credential Press is independent of ISACA and ISC2.
Frequently asked questions
Is the CISM or the CISSP better for a security manager?
Both boards name the role. ISACA describes the CISM as validating the skills of a modern IT security manager, and ISC2 lists Security Manager among the positions the CISSP suits. The CISM is management-only across four domains; the CISSP spans eight domains of security practice, so it suits a manager who also needs technical breadth.
Which is harder, the CISM or the CISSP?
We found no published pass rate from either board, so official data cannot answer it. The formats differ: the CISM is 150 fixed questions in 4 hours; the CISSP is adaptive, 100 to 150 items in up to 3 hours, with no going back to earlier items.
Which costs more, the CISM or the CISSP?
On exam fees, the CISSP at US$749 against the CISM at US$575 for ISACA members or US$760 for non-members. Over three years, passing first time, the CISM costs a non-member US$1,065 and the CISSP US$1,154, including the yearly maintenance fees.
Can I take the CISM or the CISSP online?
The CISM, yes: ISACA exams run at PSI test centers or as remotely proctored exams. The CISSP, no: ISC2 exams are taken in person at Pearson VUE test centers.
Do I need experience before I sit either exam?
No. Both let you sit first. ISACA gives you five years from passing to apply with five years of information security management experience. ISC2 makes a passer without five years of experience an Associate of ISC2, with up to six years to earn it.
Should I take both?
Some people do, and the cost and upkeep double. Both require 120 continuing education hours or credits every three years, and ISACA lets one qualifying activity count toward several ISACA certifications.
CISM: for interviews and hiring
Which books cover the CISM and the CISSP?

Certified Information Security Manager. 12 chapters, 342 pages.

Certified Information Systems Security Professional. 14 chapters, 396 pages.
Sources
Every fact above was read on ISACA's and ISC2's own pages on 2 October 2026. The three-year totals and the "which suits which person" list are our reading.
- ISACA, Certification Exam Candidate Guide, version 1.26
- ISACA, CISM certification page and CISM Exam Content Outline
- ISACA, Maintain CISM Certification
- ISC2, CISSP certification page and exam outline, effective 15 April 2024
- ISC2, Computerized Adaptive Testing FAQ
- ISC2, exam pricing and Annual Maintenance Fees
Credential Press is not affiliated with, endorsed by or authorized by ISACA or ISC2. Exam names and trademarks belong to their owners.