CISM vs CISA: Which ISACA Certification Should You Take?
CISM and CISA are ISACA's two best-known credentials, and they're often confused. They share an exam format — but they point at very different careers. Here's how to choose.
The short answer
- Choose CISA if your work is about auditing and assessing controls — you evaluate whether systems and processes are sound.
- Choose CISM if your work is about managing and building a security program — you own strategy, risk, and incident response.
Auditors and aspiring auditors take CISA. Security managers (and those moving into management) take CISM.
If that settles it, stop reading and go to the CISA or CISM prep guide. If it doesn't, the rest of this article is about the decision inputs that actually differ — and one of them is not the exam at all.
Same format, different focus
Both exams are nearly identical in structure:
| CISA | CISM | |
|---|---|---|
| Questions | 150 | 150 |
| Time | 4 hours | 4 hours |
| Scoring | 200–800 | 200–800 |
| Passing score | 450 | 450 |
| Domains | 5 | 4 |
| Answer options | 4 | 4 |
Both use ISACA's qualifier style, where a single word — BEST, MOST, FIRST, LEAST, EXCEPT — decides which of several defensible options the exam wants. If you have sat one, the mechanics of the other will feel familiar.
Where they diverge is the content blueprint.
CISA domains
CISA is built around the audit lifecycle, with the heaviest weighting on operations and protecting information assets:
- Information Systems Auditing Process — 18%
- Governance and Management of IT — 18%
- IS Acquisition, Development and Implementation — 12%
- IS Operations and Business Resilience — 26%
- Protection of Information Assets — 26%
Note the shape: more than half the exam sits in the last two domains. Candidates who budget study time evenly across five domains under-prepare for half the paper.
CISM domains
CISM is built around running a security program, with the heaviest weighting on the program itself and incident management:
- Information Security Governance — 17%
- Information Security Risk Management — 20%
- Information Security Program — 33%
- Incident Management — 30%
Here too, two domains carry nearly two-thirds of the exam.
Timing note: ISACA updates the CISM exam content outline on 3 November 2026, adding Enterprise Architecture and Information Security Architecture as content areas. Exams sat before that date use the weights above. ISACA had not published final domain-by-domain weights for the new outline at the time of writing, so treat any specific percentages quoted for it as unverified. CISA's outline, which took effect in August 2024, is unchanged.
The gate that matters more than the exam
This is the part most comparisons skip, and it is often the real decision.
Passing either exam does not make you certified. Both require five years of experience — but they are not equivalent five years.
| CISA | CISM | |
|---|---|---|
| Total experience | 5 years | 5 years |
| Specific requirement | IS audit, control, assurance or security | 3 of the 5 years in a security management role, across 3+ domains |
| Waivers | Up to 3 years, by education or credentials | Up to 2 years |
| Window after passing | 5 years to apply | 5 years to apply |
| Interim option | CISA Associate designation | — |
CISM's gate is materially harder to clear. It is not enough to have worked in security for five years; three of them must be in a role where you managed a security programme, spanning at least three of the four domains. Plenty of capable engineers pass the CISM exam and then discover they cannot yet apply.
CISA's requirement is broader — audit, control, assurance or security — and allows up to three years of waivers. Since July 2025, ISACA has also offered a CISA Associate designation for candidates who have passed but do not yet qualify, which gives you something to put on a CV in the meantime.
If you are early in your career, this asymmetry alone often decides it.
Which is harder?
Neither is objectively harder — they're hard in different ways:
- CISA is broader (five domains) and rewards the disciplined "auditor's mindset": what should the auditor do, in what order, independently.
- CISM is more conceptual and management-oriented: it rewards thinking like someone accountable for risk decisions and budgets, not just controls.
If you're technical and like concrete procedures, CISA often feels more natural. If you think in terms of strategy, risk appetite, and stakeholders, CISM does.
The trap on each is different too. On CISA, the trap is answering as the engineer who would fix the problem, rather than as the auditor who would report it — the auditor observes and reports, and does not implement the control. On CISM, the trap is answering as the practitioner who would deploy a control, when the exam wants the manager who first establishes whether there is a risk owner and a business case.
Both are answering "what would a good professional do first?" — they simply mean different professionals.
Who hires for which
- CISA is the recognised standard in internal audit, external audit and assurance practices, and in regulated industries where audit findings drive remediation budgets. It is frequently a listed requirement rather than a preference.
- CISM appears in security management job specs — security manager, ISMS owner, GRC lead, and roles reporting into a CISO. It signals that you can be accountable for a programme, not only competent within one.
A rough heuristic: if the role's success is measured by finding and reporting problems, CISA. If it is measured by owning the outcome, CISM.
Take CISA first if…
- You have less than three years in a security management role. The CISM certification gate will block you even if you pass.
- Your current job title contains "audit", "assurance", "risk" or "compliance".
- You want the credential to be immediately usable — CISA's broader experience definition and the Associate route make that likelier.
- You are unsure. CISA's blueprint covers governance and risk material that transfers directly to CISM later.
Take CISM first if…
- You already manage a security function, or will within the year.
- You are moving from a technical role into leadership and need the credential to signal the shift.
- Your organisation is building an ISMS and you own it.
- Your five years already include three in management across multiple domains — in which case there is no reason to defer.
Can you take both?
Yes — and many professionals do, usually CISA first (as auditors move toward security leadership) or CISM first (as managers add audit literacy). The overlap in governance and risk means the second exam is easier once you've passed the first.
Practical notes if you plan to: the two share ISACA's continuing professional education framework, so maintaining both is less than twice the work of maintaining one. Sitting them close together is also more efficient than spacing them years apart, because the governance and risk material is still fresh.
How to prepare for either
Both exams reward the same study approach: practice by domain, simulate the real timed exam on the 200–800 scale, and fix your weak domains before exam day.
One discipline matters more on these two than on most exams: weight your study to the blueprint. Both papers concentrate roughly two-thirds of their questions in two domains. Even study time is the most common self-inflicted wound on both.
And track readiness on the real scale. The 200–800 scale is a statistical conversion, not a percentage — 450 does not mean 56% of questions correct — so a practice percentage tells you less than you think.
CertPrepX supports both — with domain-weighted practice, full-length mock exams, and a readiness score per domain.
Dig into the details: CISA exam prep · CISM exam prep · or start free practice.
Sources
Exam and certification requirements on this page were read from ISACA's own published material. Last verified 25 August 2026.
- ISACA — CISM certification
- ISACA — CISM exam content outline
- ISACA — CISA certification
- ISACA — CISA exam content outline
Frequently asked questions
Is CISM harder than CISA? Not objectively — the exams share format, length and passing score. CISM is more conceptual and management-oriented; CISA is broader and more procedural. The CISM certification requirement is harder to satisfy, which is a different question from exam difficulty.
Which should I take first? CISA, in most cases, unless you already have three years in a security management role. Its experience requirement is broader and easier to satisfy, and its material transfers to CISM.
Do CISA and CISM overlap? Yes, in governance and risk management. That overlap is why the second exam is generally easier than the first.
Is the CISM exam changing? ISACA updates the CISM exam content outline on 3 November 2026. If you are testing before that date, you sit the current outline.