certification

CISM - Certified Information Security Manager

Experience stageExpertRoleMath’s grouping · the vendor’s own wording is below

A cited second opinion for choosing your next tech certification or training path.

Compare certification options for my goal

Certification details change. Always confirm final pricing, availability, and credential terms on the official provider page linked in the sources below before you pay for anything.

An experience-gated credential — the experience comes first.

The call: Take it once you already have the experience the vendor requires (5 years across at least 3 of the 4 CISM domains). a maximum of 2 years is waivable. Skip sitting it cold — the experience is the real gate here, not the exam.

CISM - Certified Information Security Manager gates full certification behind substantial work experience. You can study the domains and even sit the exam, but the honest path is to build that experience first — it is a vendor requirement, not a RoleMath judgment. Vendor-recommended experience · checked

Who this certification is designed for

The vendor’s stated audience, plus an honest fit for your starting point. No pass rates, no guarantees.

Per ISACA: 5 years of information-security management experience across at least 3 of the 4 CISM domains are required for full CISM certification; you can take the exam before meeting the experience requirement. ISACA Credentialing (CISA / CISM) · checked

General funding research checklist: vouchers, WIOA, Workforce Pell, GI Bill, and employer education assistance may be worth checking. This list is not evidence that this credential, exam, or provider qualifies; confirm eligibility with the official program before relying on funding. Compare funding options →

What ISACA asks for

Expert stage. Read ISACA's own wording below for the experience this credential asks for; our stage grouping does not describe it closely enough to repeat here.

Required to certify: 5 years across at least 3 of the 4 CISM domains [vendor page]

The exam itself
Length4 hours

Exam details read from CISM - Certified Information Security Manager — official vendor page · checked 2026-06-09T00:59:45+00:00.

Cost & upkeep

Exam fee plus what it takes to keep it — the recurring cost most pages hide.

Exam price (US)
$760 CISM - Certified Information Security Manager — official vendor page · checked verified 2026-06-09 · read from the official vendor page
Certification application fee
$50 ISACA certification application fee · checked One-time fee required to obtain the credential after passing the exam.
Renewal fee (annual)
$85 ISACA renewal fees · checked non-member annual maintenance fee; ISACA members pay US$45 a year · ISACA page states holders must report at least 120 CPE hours during a three-year reporting period, with at least 20 CPE hours per year.
3-year self-study cost
$1,065RoleMath total: the exam price and required application fee plus three-year renewal shown above, each cited in its own row

We publish no ROI or payback figure for this credential. See the full cost breakdown →

Exam at a glance

How ISACA administers the exam — the logistics only. This is format, not a pass prediction, and it says nothing about how hard the material is for your background.

Duration
4 hours
Testing provider
PSI
Delivery
ISACA certification exams are computer-based, taken at authorized PSI testing centers or as remotely-proctored PSI exams.
Online proctoring
For the PSI remote option: a government photo ID matching your registration (no digital IDs), a mandatory 360-degree room scan plus desk, floor-to-ceiling, and monitor-edge mirror checks, a quiet room with no one else present, a clear desk (no notes, electronics, food, or water), and a face-camera throughout with an English-language live-chat proctor.

Policies change; verify delivery, ID, room-scan, reschedule, and refund rules on the official page before you book or pay. See exam-day logistics →

CISM - Certified Information Security Manager — official vendor page · checked ISACA Credentialing (CISA / CISM) · checked

Skills measured

Vendor-published objective domains and exam weights, normalized for display; use the cited official objectives for exact wording. CISM - Certified Information Security Manager — official vendor page · checked

33%Information Security ProgramPlain-English orientation: use this as the topic area to study for Information Security Program. The official objectives define the exact vendor tasks.ISACA Credentialing (CISA / CISM) (CISM) · checked
30%Incident ManagementPlain-English orientation: use this as the topic area to study for Incident Management. The official objectives define the exact vendor tasks.ISACA Credentialing (CISA / CISM) (CISM) · checked
20%Information Security Risk ManagementPlain-English orientation: use this as the topic area to study for Information Security Risk Management. The official objectives define the exact vendor tasks.ISACA Credentialing (CISA / CISM) (CISM) · checked
17%Information Security GovernancePlain-English orientation: use this as the topic area to study for Information Security Governance. The official objectives define the exact vendor tasks.ISACA Credentialing (CISA / CISM) (CISM) · checked

Free ways to study for CISM - Certified Information Security Manager

4 free resources on record

  • CISM Exam Content Outline Free · official Best use: Confirm the official scope, domains, and version before studying. Limitation: Free 4-domain outline; review manual/course are paid. An updated outline is effective 3 Nov 2026. Checked 2026-06-30.
  • Destination Certification CISM MindMaps (free video series) Free · independent Best use: Seeing how the governance, risk and incident-management concepts in a domain connect, rather than memorising them as a list. It is the only independent free route currently registered for CISM. Limitation: The page states no exam outline version and no publication date, so check its coverage against ISACA's current job practice before relying on it. Downloads require an email address. Made by a provider that also sells a paid CISM course. Checked 2026-08-05.
  • CISM Practice Quiz (official, free) Free · official Best use: Check familiarity with official sample or practice questions. Limitation: Official free sample-question quiz; training products remain paid. Checked 2026-06-30.
  • ISACA Exam Candidate Guide (official) Free · official Best use: Knowing the rules before exam day — scheduling; identification; and what happens if you need to reschedule. Limitation: Process and policy only. It teaches none of the exam content and is not a study resource. Checked 2026-08-05.

Official sources control exam scope. Independent resources are reviewed for usefulness and labeled; none is a pass guarantee or affiliate recommendation.

Prerequisites

What's required vs merely recommended — stated plainly.

Hard requirement
5 years across at least 3 of the 4 CISM domains CISM - Certified Information Security Manager — official vendor page · checked
Experience for full certification
5 years across at least 3 of the 4 CISM domains ISACA Credentialing (CISA / CISM) · checked None to sit the exam. a maximum of 2 years is waivable. Second route: Pass the exam first — you then have 5 years from the passing date to apply once you have the management experience. There is no separate CISM Associate designation.

Version & change log

Which version is current — so you prepare for the exam that’s live today, not a retired one.

Version status
CISM Exam Content Outline update effective 2026-11-03; new prep materials from September 2026 — current prep materials are not final for candidates testing after that date.
CISM - Certified Information Security Manager — official vendor page · checked

What this proves — and how ISACA says to prepare

ISACA’s own framing of who earns it and what it signals, plus their free official study material. Quoted and cited — never dressed up as a job guarantee.

Who the vendor built it for
Best fit for information security managers responsible for developing and managing enterprise security programs across governance, incident response, and risk management domains.
CISM - Certified Information Security Manager — official vendor page · checked

Where the U.S. Department of Defense accepts this

The DoD lists this certification as an approved foundational qualification option for 13 cyber work roles, per the DoD 8140 qualification matrix (V2.1, effective 2025-09-19; checked 2026-08-07). These are work-role classifications, not job openings, not hiring eligibility, and not evidence that these roles are available to you.

Mapped at advanced proficiency

  • Data Analyst 422
  • Vulnerability Assessment Analyst 541
  • Authorizing Official/Designated Representative 611
  • Security Control Assessor 612
  • Security Architect 652
  • Information Systems Security Manager 722
  • COMSEC Manager 723
  • Cyber Workforce Developer and Manager 751
  • Cyber Policy and Strategy Planner 752
  • Program Manager 801
  • IT Project Manager 802
  • IT Investment/Portfolio Manager 804
  • IT Program Auditor 805

This covers the foundational step only. DoD 8140 qualification has more than one part: a foundational qualification, then a resident on-the-job qualification within the role, then continuing professional development. A certification can satisfy the foundational part. It does not by itself qualify anyone for the work role.

It is also one route, not the required one. The DoD lists a qualifying degree, approved training, or a certification as alternatives to the same foundational baseline. And a certification approved at a higher proficiency level also applies at lower proficiency levels for that same work role, so the level shown above is where the matrix maps it, not a ceiling.

The matrix sets the department-wide baseline. A component, command, or contract may set stricter foundational requirements for a particular position, and environment-specific resident requirements are left to component discretion — so this cannot tell you what one specific job will ask for. Sources: the DoD 8140 qualification matrix V2.1 (XLSX) for the mappings, and DoDM 8140.03 (PDF) for the qualification lifecycle. IAT, IAM and IASAE levels belong to DoD 8570.01-M, which DoDM 8140.03 cancelled, and are not part of 8140.

Readiness check · ~2 min · no score · no email

Not sure if CISM - Certified Information Security Manager is the right next step for you?

Answer a few quick questions and we’ll map your background against the exam’s published domains and the vendor’s recommended prep — a study order and a sequencing read, not a score or a pass prediction. Everything you need to decide is already above; open this only if you want a personalized plan.

  • Information Security Program33%
  • Incident Management30%
  • Information Security Risk Management20%
  • Information Security Governance17%
Answer blocks

Common Questions

Does ISACA CISM expire?

Yes. CISM runs on a 3-year certification cycle and must be maintained to stay active (as of 2026-06-14).

CISM requires an annual maintenance fee plus CPE credits across each three-year cycle.

Citations: ISACA - Maintain Your CISM, https://www.isaca.org/credentialing/cism/maintain-cism-certification (as of 2026-06-14).

Weighing CISM for a security-management path? RoleMath's free planner checks the fit - nobody pays us to recommend anything.

How do I renew ISACA CISM?

Maintain CISM by paying ISACA's annual maintenance fee and earning CPE credits across the 3-year cycle (as of 2026-06-14).

Renewal is ongoing: pay annually and log CPEs (minimum 20/year) toward the cycle total.

Citations: ISACA - Maintain Your CISM, https://www.isaca.org/credentialing/cism/maintain-cism-certification (as of 2026-06-14).

RoleMath maps your security-management track and the CPE commitment against your goal - free.

How much does ISACA CISM renewal cost (and how many CPEs)?

The CISM maintenance fee is $45/year for ISACA members ($85/year for non-members), and you need 120 CPE credits per 3-year cycle (minimum 20/year) (as of 2026-06-14).

Rates shown are the maintenance fee only; ISACA membership has its own separate annual cost, and the CISM exam is $575 member / $760 non-member.

Citations: ISACA - Maintain Your CISM, https://www.isaca.org/credentialing/cism/maintain-cism-certification; exam https://www.isaca.org/credentialing/cism (as of 2026-06-14).

RoleMath plans the full multi-year cost of carrying CISM, member or not - free, no upsell.

Core source records

This table lists the page’s core content records and when they were checked. Claim-specific citations appear beside the relevant text and may not be repeated here.

Show all 9 sources
IDSupportsSourceChecked
CIT-01Public official credential page for CISM - Certified Information Security Manager.ISACA Certifications2026-06-12T17:53:02+00:00
CIT-02Supports official facts for CISM - Certified Information Security Manager.Official ISACA objective-domain source2026-06-09T00:59:45+00:00
CIT-03Supports official facts for CISM - Certified Information Security Manager.Official Html And Pdf2026-06-09T00:59:45+00:00
CIT-04Supports official facts for CISM - Certified Information Security Manager.CISM maintenance requirements page2026-06-09T00:59:45+00:00
CIT-05Supports official facts for CISM - Certified Information Security Manager.CISM exam candidate guide2026-06-09T00:59:45+00:00
CIT-06Supports official facts for CISM - Certified Information Security Manager.ISACA Continuing Professional Education Policy >2026-06-09T00:59:45+00:00
CIT-07Supports official facts for CISM - Certified Information Security Manager.ISACA exam day rules guide2026-06-09T00:59:45+00:00
CIT-08Supports official facts for CISM - Certified Information Security Manager.ISACA exam scheduling guide2026-06-09T00:59:45+00:00
CIT-09Supports official facts for CISM - Certified Information Security Manager.CISM official source page2026-06-09T00:59:45+00:00

Ready to turn this decision into a plan?

Find out if CISM - Certified Information Security Manager fits your background.