CISM vs CISA: Which ISACA Certification Should You Take?

CISM and CISA are ISACA's two best-known credentials, and they're often confused. They share an exam format — but they point at very different careers. Here's how to choose.

The short answer

Auditors and aspiring auditors take CISA. Security managers (and those moving into management) take CISM.

If that settles it, stop reading and go to the CISA or CISM prep guide. If it doesn't, the rest of this article is about the decision inputs that actually differ — and one of them is not the exam at all.

Same format, different focus

Both exams are nearly identical in structure:

CISA CISM
Questions 150 150
Time 4 hours 4 hours
Scoring 200–800 200–800
Passing score 450 450
Domains 5 4
Answer options 4 4

Both use ISACA's qualifier style, where a single word — BEST, MOST, FIRST, LEAST, EXCEPT — decides which of several defensible options the exam wants. If you have sat one, the mechanics of the other will feel familiar.

Where they diverge is the content blueprint.

CISA domains

CISA is built around the audit lifecycle, with the heaviest weighting on operations and protecting information assets:

Note the shape: more than half the exam sits in the last two domains. Candidates who budget study time evenly across five domains under-prepare for half the paper.

CISM domains

CISM is built around running a security program, with the heaviest weighting on the program itself and incident management:

Here too, two domains carry nearly two-thirds of the exam.

Timing note: ISACA updates the CISM exam content outline on 3 November 2026, adding Enterprise Architecture and Information Security Architecture as content areas. Exams sat before that date use the weights above. ISACA had not published final domain-by-domain weights for the new outline at the time of writing, so treat any specific percentages quoted for it as unverified. CISA's outline, which took effect in August 2024, is unchanged.

The gate that matters more than the exam

This is the part most comparisons skip, and it is often the real decision.

Passing either exam does not make you certified. Both require five years of experience — but they are not equivalent five years.

CISA CISM
Total experience 5 years 5 years
Specific requirement IS audit, control, assurance or security 3 of the 5 years in a security management role, across 3+ domains
Waivers Up to 3 years, by education or credentials Up to 2 years
Window after passing 5 years to apply 5 years to apply
Interim option CISA Associate designation

CISM's gate is materially harder to clear. It is not enough to have worked in security for five years; three of them must be in a role where you managed a security programme, spanning at least three of the four domains. Plenty of capable engineers pass the CISM exam and then discover they cannot yet apply.

CISA's requirement is broader — audit, control, assurance or security — and allows up to three years of waivers. Since July 2025, ISACA has also offered a CISA Associate designation for candidates who have passed but do not yet qualify, which gives you something to put on a CV in the meantime.

If you are early in your career, this asymmetry alone often decides it.

Which is harder?

Neither is objectively harder — they're hard in different ways:

If you're technical and like concrete procedures, CISA often feels more natural. If you think in terms of strategy, risk appetite, and stakeholders, CISM does.

The trap on each is different too. On CISA, the trap is answering as the engineer who would fix the problem, rather than as the auditor who would report it — the auditor observes and reports, and does not implement the control. On CISM, the trap is answering as the practitioner who would deploy a control, when the exam wants the manager who first establishes whether there is a risk owner and a business case.

Both are answering "what would a good professional do first?" — they simply mean different professionals.

Who hires for which

A rough heuristic: if the role's success is measured by finding and reporting problems, CISA. If it is measured by owning the outcome, CISM.

Take CISA first if…

Take CISM first if…

Can you take both?

Yes — and many professionals do, usually CISA first (as auditors move toward security leadership) or CISM first (as managers add audit literacy). The overlap in governance and risk means the second exam is easier once you've passed the first.

Practical notes if you plan to: the two share ISACA's continuing professional education framework, so maintaining both is less than twice the work of maintaining one. Sitting them close together is also more efficient than spacing them years apart, because the governance and risk material is still fresh.

How to prepare for either

Both exams reward the same study approach: practice by domain, simulate the real timed exam on the 200–800 scale, and fix your weak domains before exam day.

One discipline matters more on these two than on most exams: weight your study to the blueprint. Both papers concentrate roughly two-thirds of their questions in two domains. Even study time is the most common self-inflicted wound on both.

And track readiness on the real scale. The 200–800 scale is a statistical conversion, not a percentage — 450 does not mean 56% of questions correct — so a practice percentage tells you less than you think.

CertPrepX supports both — with domain-weighted practice, full-length mock exams, and a readiness score per domain.

Dig into the details: CISA exam prep · CISM exam prep · or start free practice.

Sources

Exam and certification requirements on this page were read from ISACA's own published material. Last verified 25 August 2026.

Frequently asked questions

Is CISM harder than CISA? Not objectively — the exams share format, length and passing score. CISM is more conceptual and management-oriented; CISA is broader and more procedural. The CISM certification requirement is harder to satisfy, which is a different question from exam difficulty.

Which should I take first? CISA, in most cases, unless you already have three years in a security management role. Its experience requirement is broader and easier to satisfy, and its material transfers to CISM.

Do CISA and CISM overlap? Yes, in governance and risk management. That overlap is why the second exam is generally easier than the first.

Is the CISM exam changing? ISACA updates the CISM exam content outline on 3 November 2026. If you are testing before that date, you sit the current outline.

Know exactly when you're ready to pass

Adaptive practice, full-length mock exams, and a readiness score for CISA, CISM, CISSP, PMP, ISO 27001 and AAIA.

Start free practice

Related exam guide

More from the blog