Skip to content
CertMapCertMap

CISMISACA Certified Information Security Manager

ISACAPersonnel certification (ISO 17024)Leadership
Official certification page

Created per CertMap methodology · Updated 12 May 2026 · About the editorial team

Jump to …5 sections

Overview

What is CISM?

The Certified Information Security Manager (CISM) from ISACA is the leading management certification in information security, focusing on governance, risk management, and strategic oversight – not technical implementation details. It is specifically designed for experienced security professionals transitioning into leadership roles or seeking to formally demonstrate management competency. CISM is often perceived as complementary to CISSP: while CISSP emphasizes technical breadth, CISM targets the business perspective and senior management. The exam (150 questions, 4 hrs) is demanding and requires real management experience. The current exam content outline applies through 2 November 2026; from 3 November 2026 ISACA tests against an updated outline, with the matching preparation materials announced for September 2026.

Suitable for

Chief Information Security Officer (CISO)
Senior Information Security Manager
IT Security Director
Security Director
VP Information Security

Quick facts

AccreditationISO/IEC 17024 by ANSI
Languagesen · de · fr · es · ja · ko · zh · it
RecognitionGlobal

Key details

Cost, prerequisites, exam & renewal

Cost over 5 years

Exam fee (acquisition)€699
AMF (5 years)€207
CPE time value (5 years)€8,000
5-year total€8,906
CPE effort: 20 h per year · 100 h over 5 years · Valued at 80 €/h.

AMF prices are ISACA member prices. Membership adds 195 USD/year once per person (135 USD dues + 60 USD Germany chapter, varies by chapter); without membership the AMF is 85 USD per cert.

How is TCO calculated?

Classification

CertMap score and matching roles

Rating

Market recognition
3/3
Scheme quality
3/3
Practice evidence
2/3
Maintenance
2/3

Matching NICE roles

Oversee and GovernSystems Security Management
Design and DevelopCybersecurity Architecture
Design and DevelopSecure Systems Development
Implement and OperateSystems Security Analysis
Oversee and GovernCommunications Security (COMSEC) Management
Oversee and GovernCybersecurity Policy and Planning
Oversee and GovernCybersecurity Workforce Management
Oversee and GovernCybersecurity Curriculum Development
Oversee and GovernCybersecurity Instruction
Oversee and GovernExecutive Cybersecurity Leadership

Learning & preparation

Freely accessible preparation

A curated selection of freely accessible learning paths for this certification. Not exhaustive, not ranked.

Official from the provider · Guide

ISACA – offizielle CISM-Prüfungsvorbereitung

Review manual, question database and official study materials directly from ISACA.

checked on Jun 13, 2026Go to source

Provider-affiliated · Course

ISACA Germany Chapter – Schulungen & Weiterbildung

The German ISACA chapter offers preparation events and training around CISM.

checked on Jun 13, 2026Go to source

Freely accessible community content · Video

Prabh Nair – Mastering CISM: Thinking Like a Manager

Freely accessible CISM explainer videos and exam tips from Prabh Nair.

checked on Jun 13, 2026Watch on YouTube
curated, not sponsored

We only list freely accessible, factual learning paths: from the provider, a provider-affiliated non-commercial body, or established community content. No paid placements, no affiliate links.

More certifications

More certifications

This page follows CertMap methodology: editorial content is curated by hand. Score, costs and NICE mapping are aggregated from official provider documents. Score methodology · TCO methodology

Transparency: CertMap is operated by Daniel Thomas Heessel, who is also managing director of Threat‑Informed, a company specialising in Threat‑Informed Defense. CertMap currently receives no commissions from certification providers, no affiliate links, no sponsored placements. Podcast and interview guests are not paid for appearances and receive no affiliate commissions.

Daniel Heessel, CISO of the Year 2026

1:1 with the CISO

Personal strategy instead of weeks of self-research. Vendor-independent, with auditable recommendations and transparent sources.

Open consulting
CISMView in quadrant