Skip to content
CertMapCertMap

VERGLEICHE

CISSP or CISM? Two Careers, One Decision

Both require five years of experience, both cost roughly the same at first glance. Yet CISSP and CISM lead to different professions. The comparison with the numbers that course providers don't show.

By Daniel Thomas HeesselLast updated: August 12, 20268 min read

"CISSP or CISM" is one of the most common questions security professionals google before a certification decision. The honest answer: it is rarely an either-or question between two similar products, but a fork between two professional profiles.


On paper, the two certifications look like competitors: both come from large American professional associations (ISC2 and ISACA), both require five years of professional experience, both are valid for three years, and the exam fees are close together (749 and 760 US dollars respectively, converted to euros in the table below). But anyone who lays the contents side by side sees two different roles.

What the two stand for

The CISSP (Certified Information Systems Security Professional) from ISC2 is a generalist certification with technical breadth. Its eight domains range from security architecture through network security and identity management to software development security. Holding it demonstrates conceptual competence across the entire technical field of information security.

The CISM (Certified Information Security Manager) from ISACA looks at the same field from the governance perspective: governance, risk management, building and operating a security programme, incident management. Technical implementation details are explicitly not the focus. The CISM is aimed at people who are responsible for and steer security, not at those who configure it. Anyone concretely planning the CISM should know the cutoff date: according to ISACA, the current exam outline applies up to and including 2 November 2026; from 3 November 2026, the exam is based on an updated outline.

The numbers in direct comparison

CISSPCISM
ProviderISC2ISACA
Acquisition cost (exam, EUR)€689€699
Total cost over 5 years (EUR)i€17,310€8,906
Prerequisites5 years cumulative work experience in at least 2 of the 8 CISSP domains. 1 year may be substituted by a college degree or approved certification. Without experience: Associate of ISC2 possible.5 years of experience in information security management. Up to 2 years may be substituted by other qualifications.
Exam formatCAT-based, 100–150 questions, 3 hours, proctored via Pearson VUE. Passing score: 700/1000 points.150 multiple-choice questions, 4 hours, proctored via PSI. Passing score: 450/800.
Validity3 years3 years
CPE effort40 hrs/year20 hrs/year
CertMap scoreHow we score11 / 12Market strength
6/6
Substance
5/6
10 / 12Market strength
6/6
Substance
4/6

Values live from the CertMap cost methodology (USD fees converted to EUR, totals include annual fees, recertification and CPE time value). Same data basis as the comparison tool.

NICE work role coverage

39 work roles mapped against the NICE framework. Overlap: 15.

CISSP

22 unique

In both

15 shared

CISM

2 unique

Shared roles (15)

  • Communications Security (COMSEC) Management

    NICE role: Communications Security (COMSEC) Management.Typical job titles: COMSEC-Manager, Kryptomanagement, Crypto Custodian, Kommunikationssicherheit

  • Cybersecurity Architecture

    NICE role: Cybersecurity Architecture.Typical job titles: Security Architect, Sicherheitsarchitekt, Cybersecurity Architect, IT-Sicherheitsarchitekt

  • Cybersecurity Curriculum Development

    NICE role: Cybersecurity Curriculum Development.Typical job titles: Security Curriculum Developer, Lehrplanentwickler, Trainingsentwickler Cybersicherheit

  • Cybersecurity Instruction

    NICE role: Cybersecurity Instruction.Typical job titles: Security Trainer, Cybersicherheits-Dozent, Security Awareness Trainer, Ausbilder Informationssicherheit

  • Cybersecurity Policy and Planning

    NICE role: Cybersecurity Policy and Planning.Typical job titles: Security Policy Manager, Sicherheitsrichtlinien-Manager, Policy Analyst, Cybersecurity Strategy, Sicherheitsstrategie

  • Cybersecurity Workforce Management

    NICE role: Cybersecurity Workforce Management.Typical job titles: Security Workforce Manager, Personalentwicklung Cybersicherheit, Security Talent Manager

  • Executive Cybersecurity Leadership

    NICE role: Executive Cybersecurity Leadership.Typical job titles: CISO, Chief Information Security Officer, Head of Security, IT-Sicherheitschef, Leiter Informationssicherheit

  • Product Support Management

    NICE role: Product Support Management.Typical job titles: Product Support Manager, Produkt-Support-Leiter

  • Program Management

    NICE role: Program Management.Typical job titles: Programm-Manager, Program Manager, IT-Programmleiter

  • Secure Project Management

    NICE role: Secure Project Management.Typical job titles: IT-Projektleiter, Security Project Manager, Projektmanager Informationssicherheit

  • Secure Systems Development

    NICE role: Secure Systems Development.Typical job titles: Secure Systems Engineer, Systems Security Developer, Sichere Systementwicklung

  • Systems Authorization

    NICE role: Systems Authorization.Typical job titles: Authorizing Official, Systemfreigabe, Accreditation Manager, Zulassungsmanager

  • Systems Security Analysis

    NICE role: Systems Security Analysis.Typical job titles: IT-Security Analyst, Security Analyst, Informationssicherheits-Analyst, Systemsicherheitsanalyst, Security Operations Analyst

  • Systems Security Management

    NICE role: Systems Security Management.Typical job titles: Informationssicherheitsbeauftragter, ISB, IT-Sicherheitsbeauftragter, Information Security Officer, Security Manager, ISSM

  • Technology Portfolio Management

    NICE role: Technology Portfolio Management.Typical job titles: IT-Portfolio-Manager, Technology Portfolio Manager

Grey boxes appear in both. Each box = 1 work role, hover shows the name.

Source: C3 crosswalk (Cybersecurity Credentials Collaborative) against the NICE framework, NIST SP 800-181.

Two things stand out in this table that hardly any vendor comparison mentions.

First: the exam fee is the smallest part of the bill. Over the entire holding period, the real costs come from annual fees and above all from the ongoing continuing-education obligation (CPE), whose working time is a real cost factor. Both programmes require 120 CPE hours per three-year cycle: ISC2 sets them at 40 hours per year, ISACA prescribes at least 20 hours per year and settles the rest over the cycle. Anyone who plans their continuing education evenly anyway should budget around 40 hours per year for both.

Second: the annual-fee models are constructed differently. ISC2 charges one annual fee (135 US dollars) that jointly covers all ISC2 certifications a person holds. ISACA charges the annual fee per certification: 45 US dollars for ISACA members, 85 US dollars for non-members. Anyone planning to hold several certifications from the same vendor later should know this structural difference.

A third point is not in the cost rows but in the role mapping below them, and it should be stated openly: the CISSP covers considerably more NICE work roles than the CISM, and almost all CISM roles also lie within the CISSP profile. Only a few roles are assigned to the CISM alone. In pure breadth, the CISSP is thus almost a superset of the CISM. The real difference is therefore not the number of roles but their emphasis: the CISM bundles the steering, governance-oriented roles, while the CISSP additionally covers the entire technical field.

Prerequisites: five years are not five years

Both require five years of professional experience, but different kinds:

  • CISSP: Five years of cumulative experience in at least two of the eight CISSP domains. One year can be replaced by a university degree or a recognised certification. Those who don't yet have the experience can still take the exam and become an "Associate of ISC2" until then.
  • CISM: Five years of experience in information security management, i.e. in a steering function. Up to two years can be replaced by other qualifications.

The difference matters in practice: an experienced security engineer often meets the CISSP prerequisites without difficulty, but may not yet have five years of management work to show for the CISM.

The exams

The CISSP exam is adaptive (CAT): 100 to 150 questions in three hours, the difficulty adapts to the answers, a pass requires 700 out of 1,000 points. The CISM exam is classically linear: 150 multiple-choice questions in four hours, passing score 450 out of 800 points. Both are taken proctored in test centers (Pearson VUE and PSI respectively), and both exams are also available in German.

Our assessment

What our rating says: In the CertMap rating, both sit in the upper range of the scale and close together. On market strength, i.e. market recognition and scheme quality, both reach the full score; on substance, i.e. practical evidence and programme upkeep, the CISSP is slightly ahead of the CISM. For the decision this means: the rating gives no clear tilt, the fork is set by the target role. How the two axes are constructed is explained in the rating methodology.

The decision becomes easier when approached from the target role:

  • Anyone heading towards architecture, engineering or technical consulting and wanting to demonstrate broad technical competence is right with the CISSP. It is the breadth signal for senior technical roles.
  • Anyone moving towards security leadership, team management or a CISO track finds the more fitting statement in the CISM: this certificate demonstrates steering and governance competence.
  • In practice, the sequence is often not an either-or question: many professionals first earn the CISSP in a technical role and add the CISM when moving into management.

Holding both, by the way, does not mean paying double upkeep: the annual continuing-education hours can largely be credited to both certifications at the same time, because both vendors accept subject-relevant security education. The annual fees, however, are due for both. How CertMap calculates overlapping CPE obligations is explained in the cost methodology.

Frequently asked questions

Can you hold CISSP and CISM in parallel?

Yes, and the combination is common, especially among security leaders with a technical background. The extra effort is smaller than the sum of both individual bills, because the CPE hours can largely be double-credited.

What happens after three years?

Both certifications run in three-year cycles. Renewal happens not through a new exam but through documented continuing education (CPE) plus annual fees. Anyone who does not meet the CPE obligation loses the title.

Is one of the two enough for the CISO path?

A certification does not replace leadership experience. In job postings for security leadership positions, both appear regularly, often as alternatives ("CISSP or CISM"). For the management track, the CISM is the more specific statement, the CISSP the broader foundation.

Read next:CISM or CISA? Two ISACA paths, one directional decisionTCO Methodology in Portfolio Mode