VERGLEICHE
CISM or CISA? Two ISACA paths, one directional decision
Both come from ISACA, both require five years of experience, and both cost almost the same. The difference is not the price but the role: managing or auditing. The comparison with the numbers and the role mapping.
By Daniel Thomas HeesselLast updated: August 12, 20267 min read
"CISM or CISA" is one of the most common questions for security professionals pursuing an ISACA certification. The honest answer: with these two, you are not deciding on price and hardly on the exam, because those are almost identical. You are deciding on the role you want to move into.
On paper, the two look like twins: both come from ISACA, both require five years of professional experience, both are valid for three years, both have the same exam format and the same fee structure. But looking at the content reveals two different professions.
What the two stand for
The CISM (Certified Information Security Manager) looks at information security from the management perspective: governance, risk management, building and running a security programme, incident management. Technical implementation details are explicitly not the focus. The CISM is aimed at people who own and manage security, often on the way to a leadership role. Anyone concretely planning the CISM should know the cutoff date: according to ISACA, the current exam outline applies up to and including 2 November 2026; from 3 November 2026 the exam is based on an updated outline.
The CISA (Certified Information Systems Auditor) looks from the audit perspective: it covers the entire lifecycle of IS audits, from planning through execution to reporting. In German-speaking practice this role is called IT-Revision (internal IT audit). The CISA is in strong demand in regulated industries such as banking, insurance and the public sector, where independent auditing is mandatory.
In short: one manages the security programme, the other audits it.
The numbers in direct comparison
| Provider | ISACA | ISACA |
|---|---|---|
| Acquisition cost (exam, EUR) | €699 | €699 |
| Total cost over 5 years (EUR)i | €8,906 | €8,906 |
| Prerequisites | 5 years of experience in information security management. Up to 2 years may be substituted by other qualifications. | 5 years of experience in IS audit, control, or security. Up to 3 years may be substituted through education/certifications. |
| Exam format | 150 multiple-choice questions, 4 hours, proctored via PSI. Passing score: 450/800. | 150 multiple-choice questions, 4 hours, proctored via PSI. Passing score: 450/800. |
| Validity | 3 years | 3 years |
| CPE effort | 20 hrs/year | 20 hrs/year |
| CertMap scoreHow we score → | 10 / 12Market strength 6/6 Substance4/6 | 10 / 12Market strength 6/6 Substance4/6 |
Values live from the CertMap cost methodology (USD fees converted to EUR, totals include annual fees, recertification and CPE time value). Same data basis as the comparison tool.
NICE work role coverage
19 work roles mapped against the NICE framework. Overlap: 4.

CISM
13 unique
In both
4 shared

CISA
2 unique
Shared roles (4)
Cybersecurity Curriculum Development
NICE role: Cybersecurity Curriculum Development.Typical job titles: Security Curriculum Developer, Lehrplanentwickler, Trainingsentwickler Cybersicherheit
Cybersecurity Instruction
NICE role: Cybersecurity Instruction.Typical job titles: Security Trainer, Cybersicherheits-Dozent, Security Awareness Trainer, Ausbilder Informationssicherheit
Security Control Assessment
NICE role: Security Control Assessment.Typical job titles: Security Auditor, IT-Auditor, Sicherheitsauditor, Control Assessor, ISO 27001 Auditor, Compliance-Auditor
Vulnerability Analysis
NICE role: Vulnerability Analysis.Typical job titles: Pentester, Penetration Tester, Ethical Hacker, Red Teamer, Schwachstellenanalyst, Vulnerability Analyst, Offensive Security
Grey boxes appear in both. Each box = 1 work role, hover shows the name.
Source: C3 crosswalk (Cybersecurity Credentials Collaborative) against the NICE framework, NIST SP 800-181.
The most striking finding in this table is what does not differ. Because both certifications come from ISACA, the exam fee, annual fees, recertification obligation and exam format are practically identical. Price is therefore not a decision criterion here.
One detail about the annual fee that hardly any comparison mentions: the lower member rate (45 US dollars instead of 85) requires an ISACA membership, which itself costs money and mainly pays off if you use the exam discount or later hold several ISACA certifications. Anyone holding both titles pays the annual fee per certification, but can largely credit the continuing education hours towards both at the same time.
Where the table really diverges is the role mapping below it, and the finding is clear: the overlap between the two certifications is small, only a few NICE work roles are shared by CISM and CISA. Beyond that, the CISM covers noticeably more roles, broadly in the management and governance-adjacent area; the CISA is narrowly focused on the audit roles. This is exactly where the directional decision becomes visible: these are two different profiles with little in common, not two variants of the same thing.
Requirements: five years, but in different fields
Both require five years of professional experience, but not the same experience:
- CISM: Five years of experience in information security management, i.e. in a managing function. Up to two years can be substituted with other qualifications.
- CISA: Five years of experience in IS audit, control or security. Up to three years can be substituted with education or recognised certificates.
The difference matters in practice: those coming from internal audit or statutory auditing often meet the CISA requirements more easily; those who have led a security programme, the CISM requirements.
The exams
Here the two are nearly identical: 150 multiple-choice questions, four hours, proctored via PSI, passing score 450 out of 800 points. Both are also offered by ISACA in German. The exam is therefore not where the decision is made.
Our assessment
What our rating says: In the CertMap rating, the two are practically indistinguishable. Both reach the full value on market strength, i.e. market recognition and scheme quality, and they are also level on substance, i.e. practical evidence and programme maintenance. The rating thus confirms the finding from the table: between CISM and CISA, it is not the quality of the programme that decides, but the role you want to move into. How the two axes are constructed is explained in the rating methodology.
The decision becomes easy once you think about it from the target role:
- If you are heading towards security ownership, programme management or leadership, the CISM makes the fitting statement. It attests governance and management competence.
- If you are heading towards auditing, IT audit or compliance audit, especially in regulated industries, the CISA is the right choice. It attests audit competence across the entire audit lifecycle.
Because both come from ISACA and the exam and costs hardly differ, the choice is almost purely a question of role. And because the continuing education hours can largely be credited twice, it is quite common for people who need both perspectives (for instance, in the transition from internal audit to a security leadership role) to earn both one after the other.
Frequently asked questions
Can you hold CISM and CISA in parallel?
Yes. Since both come from ISACA, the ongoing effort is smaller than the sum: the 120 continuing education hours per cycle can largely be credited towards both at the same time. The annual fee, however, is due per certification.
What is the difference to statutory auditing?
The CISA is a personnel certification for IT auditors, not a professional licence like the Wirtschaftsprüfer-Examen (German statutory auditor exam). It attests professional competence in IS audit, but does not replace a legally regulated auditor role.
Which one fits the CISO path?
For a career heading towards security ownership, the CISM is the more specific statement. The CISA fits where auditing and evidence-keeping are in the foreground. In both cases, a certification does not replace leadership experience.
Read next:CISSP or CISM? Two Careers, One Decision →TCO Methodology in Portfolio Mode →