CISMISACA Certified Information Security Manager
Created per CertMap methodology · Updated 12 May 2026 · About the editorial team → · Official page ↗

▾ Jump to …5 sections
What is CISM?
The Certified Information Security Manager (CISM) from ISACA is the leading management certification in information security, focusing on governance, risk management, and strategic oversight – not technical implementation details. It is specifically designed for experienced security professionals transitioning into leadership roles or seeking to formally demonstrate management competency. CISM is often perceived as complementary to CISSP: while CISSP emphasizes technical breadth, CISM targets the business perspective and senior management. The exam (150 questions, 4 hrs) is demanding and requires real management experience. The current exam content outline applies through 2 November 2026; from 3 November 2026 ISACA tests against an updated outline, with the matching preparation materials announced for September 2026.
Suitable for
Quick facts
Cost, prerequisites, exam & renewal
Cost over 5 years
AMF prices are ISACA member prices. Membership adds 195 USD/year once per person (135 USD dues + 60 USD Germany chapter, varies by chapter); without membership the AMF is 85 USD per cert.
How is TCO calculated? →Prerequisites
5 years of experience in information security management. Up to 2 years may be substituted by other qualifications.
Exam format
Renewal & maintenance
Valid for 3 years. 20 CPE hours/year (minimum 120 over 3 years) + annual AMF (45 USD Member / 85 USD Non-Member). A one-time application fee of 50 USD applies after passing the exam.
CertMap score and matching roles
Rating
Matching NICE roles
How to prepare
Our editorial recommendation to get started: freely accessible, no paid placement, no affiliate links.
Pete Zerger – CISM Exam Prep: The Complete Course
Free complete CISM video course by Pete Zerger (Inside Cloud and Security); the link opens the full "CISM Exam Prep 2026" playlist with all domain videos.
- CISM Exam Prep LIVE - 10 Key Topics and Strategies
- CISM Exam Prep: Series Intro and Exam Prep Strategy
Watch on YouTube ↗ · checked on Aug 19, 2026
Curated, not sponsored: the recommendation is chosen editorially and cannot be bought. Official provider materials are available via the certification page link at the top of this page.
More certifications
From the knowledge base
View all articles →CISSP or CISM? Two Careers, One Decision
Both require five years of experience, both cost roughly the same at first glance. Yet CISSP and CISM lead to different professions. The comparison with the numbers that course providers don't show.
CISM or CISA? Two ISACA paths, one directional decision
Both come from ISACA, both require five years of experience, and both cost almost the same. The difference is not the price but the role: managing or auditing. The comparison with the numbers and the role mapping.
CISM or ISO 27001 Lead Implementer? Owning the programme or building the ISMS
Both often appear in the same sentence in German job postings, yet they fill different roles: the CISM attests to steering information security from the leadership perspective, the PECB ISO/IEC 27001 Lead Implementer to building and running an ISMS along the standard. The comparison with the numbers, the entry requirements, and the role question behind it.
