← All certifications

Certified Information Security Manager (CISM)

ISACA

ISACA's management-focused credential validating expertise in governing, building, and managing an enterprise information security program.

We have a course for this

Built from this exam's published objectives. The first module is free.

Baseline certification levels

This certification satisfies these DoD baseline levels — the IAT / IAM / IASAE / CSSP requirement many contracts still state. It's a separate question from the 8140 work roles above, and there is no official mapping between the two.

What this qualifies you for

Listed specifically for 6 work roles — up to Advanced proficiency. Because options cascade downward, a cert listed at Advanced also satisfies Intermediate and Basic for that role.

541Vulnerability Assessment AnalystPerforms assessments of systems and networks within the NE or enclave and identifies where those systems/networks deviate from acceptable configurations, enclave policy, or local policy. Measures effectiveness of defense-in-depth architecture against known vulnerabilities.Advanced611Authorizing Official/Designated Representative (AO/DR)Senior official or executive with the authority to formally assume responsibility for operating an information system at an acceptable level of risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation (CNSSI 4009).Advanced612Security Control AssessorConducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST 800-37).Advanced652Security ArchitectDesigns enterprise and systems security throughout the development lifecycle; translates technology and environmental conditions (e.g., law and regulation) into security designs and processes.Advanced722Information Systems Security Manager (ISSM)Responsible for the cybersecurity of a program, organization, system, or enclave.Advanced723Communications Security (COMSEC) ManagerManages the Communications Security (COMSEC) resources of an organization (CNSSI No. 4009).Advanced
Also listed for 14 Cyberspace Enablers roles — but so is every other certification

The Enablers matrix isn’t role-differentiated: the same certification options are listed for all 14 roles at every proficiency level. We verified that across all 14. So this is true, and it carries no information about this credential specifically — which is why it isn’t in the count above.

Renewal

3year cycle120CPE per cycle20minimum per year

Annual maintenance fee: US$45 for ISACA members, US$85 for non-members (in addition to earning/reporting CPE).

This is the issuer’s clock. 8140 runs a second one — 20 hours of CPD a year, at every proficiency level, which applies even if you hold no certification at all. How that works

CISM job practice / Exam Content Outline update is effective 2026-11-03; the 2022 job practice (used here) remains current for all exams taken through 2026-11-02. Updated prep materials release ~September 2026. Domain weights for the new outline were not yet publicly posted by ISACA as of research date. Exam format (150 questions, 4 hours, scaled 200-800, passing 450), experience requirement, and CPE/maintenance-fee figures were confirmed via multiple secondary sources aggregating ISACA policy; ISACA's own overview page links out to policy documents rather than stating these inline.

Source: ISACA — CISM Exam Content Outline · dated 2026-07-17 · checked 2026-07-17

Verifying it

ISACA publishes a lookup a third party can use without your involvement.

Certification/credential number plus the holder's last name (verifiable by anyone, no holder login required).

CISM job practice / Exam Content Outline update is effective 2026-11-03; the 2022 job practice (used here) remains current for all exams taken through 2026-11-02. Updated prep materials release ~September 2026. Domain weights for the new outline were not yet publicly posted by ISACA as of research date. Exam format (150 questions, 4 hours, scaled 200-800, passing 450), experience requirement, and CPE/maintenance-fee figures were confirmed via multiple secondary sources aggregating ISACA policy; ISACA's own overview page links out to policy documents rather than stating these inline.

Source: ISACA — CISM Exam Content Outline · dated 2026-07-17 · checked 2026-07-17

Exam blueprint

Verified against ISACA’s published outline.

CISM · 2022 job practice

Current

150 questions · 4 hours · scaled score 200-800 · passing 450

Information Security Governance17%
Information Security Risk Management20%
Information Security Program33%
Incident Management30%

CISM job practice / Exam Content Outline update is effective 2026-11-03; the 2022 job practice (used here) remains current for all exams taken through 2026-11-02. Updated prep materials release ~September 2026. Domain weights for the new outline were not yet publicly posted by ISACA as of research date. Exam format (150 questions, 4 hours, scaled 200-800, passing 450), experience requirement, and CPE/maintenance-fee figures were confirmed via multiple secondary sources aggregating ISACA policy; ISACA's own overview page links out to policy documents rather than stating these inline.

Source: ISACA — CISM Exam Content Outline · dated 2026-07-17 · checked 2026-07-17