VERGLEICHE
CISSP or CISM? Two Careers, One Decision
Both require five years of experience, both cost roughly the same at first glance. Yet CISSP and CISM lead to different professions. The comparison with the numbers that course providers don't show.
By Daniel Thomas HeesselLast updated: August 12, 20268 min read
"CISSP or CISM" is one of the most common questions security professionals google before a certification decision. The honest answer: it is rarely an either-or question between two similar products, but a fork between two professional profiles.
On paper, the two certifications look like competitors: both come from large American professional associations (ISC2 and ISACA), both require five years of professional experience, both are valid for three years, and the exam fees are close together (749 and 760 US dollars respectively, converted to euros in the table below). But anyone who lays the contents side by side sees two different roles.
What the two stand for
The CISSP (Certified Information Systems Security Professional) from ISC2 is a generalist certification with technical breadth. Its eight domains range from security architecture through network security and identity management to software development security. Holding it demonstrates conceptual competence across the entire technical field of information security.
The CISM (Certified Information Security Manager) from ISACA looks at the same field from the governance perspective: governance, risk management, building and operating a security programme, incident management. Technical implementation details are explicitly not the focus. The CISM is aimed at people who are responsible for and steer security, not at those who configure it. Anyone concretely planning the CISM should know the cutoff date: according to ISACA, the current exam outline applies up to and including 2 November 2026; from 3 November 2026, the exam is based on an updated outline.
The numbers in direct comparison
| Provider | ISC2 | ISACA |
|---|---|---|
| Acquisition cost (exam, EUR) | €689 | €699 |
| Total cost over 5 years (EUR)i | €17,310 | €8,906 |
| Prerequisites | 5 years cumulative work experience in at least 2 of the 8 CISSP domains. 1 year may be substituted by a college degree or approved certification. Without experience: Associate of ISC2 possible. | 5 years of experience in information security management. Up to 2 years may be substituted by other qualifications. |
| Exam format | CAT-based, 100–150 questions, 3 hours, proctored via Pearson VUE. Passing score: 700/1000 points. | 150 multiple-choice questions, 4 hours, proctored via PSI. Passing score: 450/800. |
| Validity | 3 years | 3 years |
| CPE effort | 40 hrs/year | 20 hrs/year |
| CertMap scoreHow we score → | 11 / 12Market strength 6/6 Substance5/6 | 10 / 12Market strength 6/6 Substance4/6 |
Values live from the CertMap cost methodology (USD fees converted to EUR, totals include annual fees, recertification and CPE time value). Same data basis as the comparison tool.
NICE work role coverage
39 work roles mapped against the NICE framework. Overlap: 15.

CISSP
22 unique
In both
15 shared

CISM
2 unique
Shared roles (15)
Communications Security (COMSEC) Management
NICE role: Communications Security (COMSEC) Management.Typical job titles: COMSEC-Manager, Kryptomanagement, Crypto Custodian, Kommunikationssicherheit
Cybersecurity Architecture
NICE role: Cybersecurity Architecture.Typical job titles: Security Architect, Sicherheitsarchitekt, Cybersecurity Architect, IT-Sicherheitsarchitekt
Cybersecurity Curriculum Development
NICE role: Cybersecurity Curriculum Development.Typical job titles: Security Curriculum Developer, Lehrplanentwickler, Trainingsentwickler Cybersicherheit
Cybersecurity Instruction
NICE role: Cybersecurity Instruction.Typical job titles: Security Trainer, Cybersicherheits-Dozent, Security Awareness Trainer, Ausbilder Informationssicherheit
Cybersecurity Policy and Planning
NICE role: Cybersecurity Policy and Planning.Typical job titles: Security Policy Manager, Sicherheitsrichtlinien-Manager, Policy Analyst, Cybersecurity Strategy, Sicherheitsstrategie
Cybersecurity Workforce Management
NICE role: Cybersecurity Workforce Management.Typical job titles: Security Workforce Manager, Personalentwicklung Cybersicherheit, Security Talent Manager
Executive Cybersecurity Leadership
NICE role: Executive Cybersecurity Leadership.Typical job titles: CISO, Chief Information Security Officer, Head of Security, IT-Sicherheitschef, Leiter Informationssicherheit
Product Support Management
NICE role: Product Support Management.Typical job titles: Product Support Manager, Produkt-Support-Leiter
Program Management
NICE role: Program Management.Typical job titles: Programm-Manager, Program Manager, IT-Programmleiter
Secure Project Management
NICE role: Secure Project Management.Typical job titles: IT-Projektleiter, Security Project Manager, Projektmanager Informationssicherheit
Secure Systems Development
NICE role: Secure Systems Development.Typical job titles: Secure Systems Engineer, Systems Security Developer, Sichere Systementwicklung
Systems Authorization
NICE role: Systems Authorization.Typical job titles: Authorizing Official, Systemfreigabe, Accreditation Manager, Zulassungsmanager
Systems Security Analysis
NICE role: Systems Security Analysis.Typical job titles: IT-Security Analyst, Security Analyst, Informationssicherheits-Analyst, Systemsicherheitsanalyst, Security Operations Analyst
Systems Security Management
NICE role: Systems Security Management.Typical job titles: Informationssicherheitsbeauftragter, ISB, IT-Sicherheitsbeauftragter, Information Security Officer, Security Manager, ISSM
Technology Portfolio Management
NICE role: Technology Portfolio Management.Typical job titles: IT-Portfolio-Manager, Technology Portfolio Manager
Grey boxes appear in both. Each box = 1 work role, hover shows the name.
Source: C3 crosswalk (Cybersecurity Credentials Collaborative) against the NICE framework, NIST SP 800-181.
Two things stand out in this table that hardly any vendor comparison mentions.
First: the exam fee is the smallest part of the bill. Over the entire holding period, the real costs come from annual fees and above all from the ongoing continuing-education obligation (CPE), whose working time is a real cost factor. Both programmes require 120 CPE hours per three-year cycle: ISC2 sets them at 40 hours per year, ISACA prescribes at least 20 hours per year and settles the rest over the cycle. Anyone who plans their continuing education evenly anyway should budget around 40 hours per year for both.
Second: the annual-fee models are constructed differently. ISC2 charges one annual fee (135 US dollars) that jointly covers all ISC2 certifications a person holds. ISACA charges the annual fee per certification: 45 US dollars for ISACA members, 85 US dollars for non-members. Anyone planning to hold several certifications from the same vendor later should know this structural difference.
A third point is not in the cost rows but in the role mapping below them, and it should be stated openly: the CISSP covers considerably more NICE work roles than the CISM, and almost all CISM roles also lie within the CISSP profile. Only a few roles are assigned to the CISM alone. In pure breadth, the CISSP is thus almost a superset of the CISM. The real difference is therefore not the number of roles but their emphasis: the CISM bundles the steering, governance-oriented roles, while the CISSP additionally covers the entire technical field.
Prerequisites: five years are not five years
Both require five years of professional experience, but different kinds:
- CISSP: Five years of cumulative experience in at least two of the eight CISSP domains. One year can be replaced by a university degree or a recognised certification. Those who don't yet have the experience can still take the exam and become an "Associate of ISC2" until then.
- CISM: Five years of experience in information security management, i.e. in a steering function. Up to two years can be replaced by other qualifications.
The difference matters in practice: an experienced security engineer often meets the CISSP prerequisites without difficulty, but may not yet have five years of management work to show for the CISM.
The exams
The CISSP exam is adaptive (CAT): 100 to 150 questions in three hours, the difficulty adapts to the answers, a pass requires 700 out of 1,000 points. The CISM exam is classically linear: 150 multiple-choice questions in four hours, passing score 450 out of 800 points. Both are taken proctored in test centers (Pearson VUE and PSI respectively), and both exams are also available in German.
Our assessment
What our rating says: In the CertMap rating, both sit in the upper range of the scale and close together. On market strength, i.e. market recognition and scheme quality, both reach the full score; on substance, i.e. practical evidence and programme upkeep, the CISSP is slightly ahead of the CISM. For the decision this means: the rating gives no clear tilt, the fork is set by the target role. How the two axes are constructed is explained in the rating methodology.
The decision becomes easier when approached from the target role:
- Anyone heading towards architecture, engineering or technical consulting and wanting to demonstrate broad technical competence is right with the CISSP. It is the breadth signal for senior technical roles.
- Anyone moving towards security leadership, team management or a CISO track finds the more fitting statement in the CISM: this certificate demonstrates steering and governance competence.
- In practice, the sequence is often not an either-or question: many professionals first earn the CISSP in a technical role and add the CISM when moving into management.
Holding both, by the way, does not mean paying double upkeep: the annual continuing-education hours can largely be credited to both certifications at the same time, because both vendors accept subject-relevant security education. The annual fees, however, are due for both. How CertMap calculates overlapping CPE obligations is explained in the cost methodology.
Frequently asked questions
Can you hold CISSP and CISM in parallel?
Yes, and the combination is common, especially among security leaders with a technical background. The extra effort is smaller than the sum of both individual bills, because the CPE hours can largely be double-credited.
What happens after three years?
Both certifications run in three-year cycles. Renewal happens not through a new exam but through documented continuing education (CPE) plus annual fees. Anyone who does not meet the CPE obligation loses the title.
Is one of the two enough for the CISO path?
A certification does not replace leadership experience. In job postings for security leadership positions, both appear regularly, often as alternatives ("CISSP or CISM"). For the management track, the CISM is the more specific statement, the CISSP the broader foundation.
Read next:CISM or CISA? Two ISACA paths, one directional decision →TCO Methodology in Portfolio Mode →