The quick answer
Pick by the job you want next. CCISO is EC-Council's exam for security executives on the CISO track. CISSP covers the whole security field, which is why technical people moving into leadership tend to pick it. If you run the security program, look at ISACA's CISM. And for architects and senior engineers who want to stay hands-on, there's SecurityX, the exam CompTIA used to call CASP+. Most people start with CISSP or CISM. Architects who want to stay technical often start with SecurityX, and CCISO usually comes later.
- $544 to $999U.S. exam prices, SecurityX lowest and CCISO highest
- 90 to 150Questions, from SecurityX's 90 maximum to 150 on CCISO and CISM
- 5 yearsExperience CCISO, CISSP and CISM all ask for
- Nov 3, 2026ISACA's updated CISM exam starts
These four get compared all the time, and a lot of the charts going around are out of date. EC-Council has renamed and reweighted the CCISO domains, ISACA changes the CISM outline on November 3, 2026, and CompTIA retired the CASP+ name. So I went back to each body's own pages, handbooks and price lists and checked every number on October 10, 2026. If I couldn't confirm something from the source, it isn't here.
One thing to know up front. The four exams test different jobs, so the right first pick depends on the work you do now and the work you want in a few years.
CCISO vs CISSP vs CISM vs SecurityX side by side
| Detail | CCISO | CISSP | CISM | SecurityX |
|---|---|---|---|---|
| Issued by | EC-Council | ISC2 | ISACA | CompTIA |
| Built for | Security executives and aspiring CISOs | Security professionals who design, engineer and manage security | Managers who run the information security program | Security architects and senior security engineers |
| Experience | 5 years in 3 of 5 domains with EC-Council Authorized Training, or in all 5 without it | 5 years in 2 or more of 8 domains | 5 years of information security management in 3 of 4 domains | None required. CompTIA recommends 10 years in IT, 5 hands-on in security |
| Experience checked | Before you can buy the exam | After you pass | After you pass | Not checked |
| Domains | 5 | 8 | 4 | 4 |
| Questions | 150 multiple choice | 100 to 150, adaptive | 150 multiple choice | Up to 90, multiple choice and performance-based |
| Time | 2.5 hours | 3 hours | 4 hours | Up to 165 minutes |
| Passing score | Cut score set per exam form, 60% to 85% | 700 out of 1000 | 450 on a 200 to 800 scale | Pass or fail, no scaled score |
| U.S. exam price | $999 voucher after eligibility approval | $749 | $575 ISACA members, $760 non-members | $544 |
| Renewal | 120 CPE credits in 3 years, $100 a year | 120 CPE credits in 3 years, $135 a year | 120 CPE hours in 3 years, at least 20 a year | 75 CEUs in 3 years |
Two rows matter more than the rest. CCISO is the only one of the four where your experience gets reviewed before you can even buy the exam. And SecurityX is the only one that never asks for proof of experience at all. CISSP and CISM sit in the middle. You can take the exam first and prove the experience afterward.
Who each one fits
CCISO
For directors, VPs and CISOs, or people a step away. EC-Council aims it at executive security leadership: governance, board communication, budgets, procurement and vendor management. If your week is mostly strategy, money and people, this is the exam that tests it.
CISSP
ISC2 says CISSP validates deep technical and managerial knowledge to design, engineer and manage an organization's security posture. That's why it fits security engineers, analysts and architects who are starting to lead. The eight domains run from risk and identity to networks and secure software.
CISM
For the person who owns the program: governance, risk, the security program itself and incident management. Questions ask what's best for the business, so the most technical answer is often the wrong one. Our CISSP vs CISM guide goes deeper on that difference.
SecurityX
CompTIA built it for security architects and senior security engineers who design and implement secure solutions across cloud, on-premises and hybrid environments. It's the only one of the four whose exam lists performance-based questions, where you work through a task instead of picking an answer.
If you're earlier in your career, none of these is the right first step yet. Start with your first cybersecurity certification, usually Security+. Our Security+ SY0-701 vs SY0-801 guide covers the version change coming in November.
Domains and weights for each exam
Here's what each exam actually spends its questions on. All four bars use the same scale, so you can compare them across exams.
CCISO, 5 domains
This one surprises people. You'll still see charts that put every CCISO domain near 20 percent, but the blueprint in EC-Council's current handbook gives Core Competencies 46 percent. That domain covers access control, physical security, network defense, wireless, malware, secure coding, encryption, vulnerability testing, incident response, forensics and business continuity, all from a leader's point of view. So an executive exam still expects you to know the technology well enough to make calls about it.
CISSP, 8 domains
No CISSP domain goes above 16 percent, so you can't skip a weak area and make it up somewhere else. ISC2 also says it now weaves AI security into all eight domains instead of giving it a domain of its own.
CISM, 4 domains, before and after November 3, 2026
| Domain | Through Nov 2 | From Nov 3 |
|---|---|---|
| 1. Information Security Governance | 17% | 18% |
| 2. Information Security Risk Management | 20% | 20% |
| 3. Information Security Program | 33% | 33% |
| 4. Incident Management | 30% | 29% |
The weights barely move. The bigger CISM change is content. ISACA adds enterprise architecture and information security architecture and puts more weight on strategy and program development. Your test date decides which version you get, and ISACA strongly recommends the updated prep materials if you test on or after November 3. I cover the details in CISM exam changes on November 3, 2026.
SecurityX, 4 domains
Architecture and engineering together make up 58 percent of SecurityX. That's cloud controls, zero trust, segmentation, automation and scripting, vulnerability management and advanced cryptography, including post-quantum. CompTIA also lists generative AI under automation and asks you to weigh how AI affects security.
Experience and eligibility
This is where the four differ the most, and where people get caught. Here's each body's rule in plain terms.
CCISO
- You apply first. EC-Council reviews and verifies your experience before you can buy a voucher.
- With EC-Council Authorized Training, you need 5 years in 3 of the 5 domains.
- Without it, you need 5 years in each of the 5 domains, plus a $100 application fee. The years can overlap.
- Some degrees and an MBA or CPA can count toward a domain.
- Not there yet? EC-Council's Associate CCISO path takes 2 years in 1 domain, or a CISSP, CISM or CISA.
CISSP
- 5 years of cumulative, full-time experience in 2 or more of the 8 domains.
- A related degree or a credential on ISC2's approved list can cover 1 year. Only 1 year can be waived.
- Part-time work and internships can count.
- Pass without the experience and you can become an Associate of ISC2, with 6 years to earn it.
CISM
- 5 years of information security management experience across at least 3 of the 4 domains.
- The experience has to fall within the 10 years before you apply.
- Anyone can sit the exam. You then have 5 years from your pass date to apply, with a $50 application fee.
SecurityX
- No experience requirement to take the exam or hold the certification.
- CompTIA recommends at least 10 years of hands-on IT experience, including 5 years of hands-on security.
- It also suggests Network+, Security+, CySA+, Cloud+ and PenTest+ level knowledge, or the equivalent.
Check your CCISO route before you pay for anything. The three-domain rule depends on the training you take, so ask EC-Council which route your training puts you on before you send the application.
Exam format and scoring
| Detail | CCISO | CISSP | CISM | SecurityX |
|---|---|---|---|---|
| Questions | 150 | 100 to 150, Computerized Adaptive Testing | 150 | Up to 90 |
| Item types | Multiple choice | Multiple choice and advanced item types | Multiple choice, one best answer | Multiple choice and performance-based |
| Time | 2.5 hours | 3 hours | 4 hours | Up to 165 minutes |
| Score | Cut score varies by exam form, 60% to 85% | 700 of 1000 points | Scaled 200 to 800, 450 to pass | Pass or fail only |
A few things worth knowing before test day.
- CISSP is adaptive in every language ISC2 offers, which are Chinese, English, German, Japanese and Spanish. The exam picks your next question based on how you're doing, so it can end anywhere from 100 to 150 items.
- CCISO doesn't have one passing percentage. EC-Council runs several exam forms and sets a cut score for each one based on how hard its questions are. That's where the 60 to 85 percent range comes from. Its questions also go up to an analysis level, where you solve a problem with several variables in play.
- CISM gives you the most time per question of the four, a little over a minute and a half each.
- SecurityX has no scaled score at all. You pass or you don't.
What each exam costs in 2026
| Exam | Exam fee | Other fees to plan for |
|---|---|---|
| CCISO | $999 voucher, bought after EC-Council approves your eligibility application | $100 application fee if you don't take EC-Council Authorized Training. EC-Council says these costs don't apply if you bought a training package. |
| CISSP | $749 standard registration in the Americas | $50 to reschedule and $100 to cancel through Pearson |
| CISM | $575 for ISACA members, $760 for non-members | $50 application fee after you pass |
| SecurityX | $544 voucher | A retake needs a new voucher |
Prices vary by region and change over time, so check the body's page before you pay. ISC2, for example, lists CISSP at EUR 719.04 in Europe and GBP 606.69 in the UK.
Which one to take first, by career path
CISSP first
It covers the whole field and matches the work you already do. Add CISM when you start owning a program.
CISM first
You already think in governance and risk. CISM tests that. Add CISSP if your team expects technical depth from you.
SecurityX first
No experience gate and the most technical content. CISSP is a natural second, since SecurityX counts toward its experience.
And if you're a director or VP aiming at the CISO chair, I'd hold CCISO until you have CISSP or CISM. You'll likely meet its experience bar by then, and holding one of those already qualifies you for EC-Council's Associate CCISO path if you don't.
Working in a government or defense role? Start with your DoD 8140 work role, then pick the credential it accepts. EC-Council lists CCISO for roles like Information Systems Security Manager and Program Manager, and CompTIA lists SecurityX for roles like security architect and security control assessor.
How they stack together
Holding one of these can help you get another. Here are the links between them.
- CISM and SecurityX are both on ISC2's approved list, so either one can cover 1 year of the 5-year CISSP requirement. Only 1 year can be waived in total.
- Holding CISSP, CISM or CISA qualifies you for EC-Council's Associate CCISO path while you build the experience for the full CCISO.
- CISM pairs well with CISA if you work near audit. See CISA vs CISM.
- If your work is mostly cloud, look at CCSP vs CISSP before you choose.
One order that works for a lot of people is CISSP for breadth, then CISM once you run a program, then CCISO when the role turns executive. Architects often go SecurityX, then CISSP. Still weighing the time and money? Read Is CISSP worth it in 2026? and our CISM salary guide.
Renewal and CPE basics
| Credential | Continuing education | Annual fee |
|---|---|---|
| CCISO | 120 CPE credits in each 3-year cycle | $100 continuing education fee |
| CISSP | 120 CPE credits in each 3-year cycle, 90 of them Group A | $135 annual maintenance fee |
| CISM | 120 CPE hours in each 3-year period, at least 20 every year | ISACA annual maintenance fee |
| SecurityX | 75 CEUs in each 3-year cycle, or pass the current exam | Not covered here |
One date to watch. From January 1, 2027, ISACA still asks for 120 CPE hours per three-year period, but at least 90 of them must line up with the certification's exam content outline. Our guide to keeping your certification active covers how renewal works across bodies.
Accumentum courses and start dates
We offer training for all four. Our CISSP, CISM and SecurityX courses are on-demand and self-paced, with new starts on the course calendar. CCISO isn't on the calendar yet, so email us for the next start.
CISSP
- Tuesday, October 13, 2026CISSP, self-pacedRegister for Oct 13
- Monday, November 2, 2026CISSP, self-pacedRegister for Nov 2
- Monday, November 16, 2026CISSP, self-pacedRegister for Nov 16
CISM
- Wednesday, October 28, 2026CISM, self-pacedRegister for Oct 28
- Wednesday, December 2, 2026CISM, self-pacedRegister for Dec 2
- Wednesday, January 6, 2027CISM, self-pacedRegister for Jan 6
SecurityX
- Tuesday, October 13, 2026SecurityX CAS-005, self-pacedRegister for Oct 13
- Monday, November 16, 2026SecurityX CAS-005, self-pacedRegister for Nov 16
- Monday, December 14, 2026SecurityX CAS-005, self-pacedRegister for Dec 14
New CISSP classes start every 2 to 3 weeks. CISM and SecurityX start about once a month. If your CISM test date lands on or after November 3, tell us when you enroll so you study for the right outline.
How we help you prepare

CISSP course
10 modules aligned to the CISSP CBK, from risk management to emerging threats.

CISM course
10 modules across ISACA's four domains, written for people who own the security program.

SecurityX course
Built on the CAS-005 objectives: governance, architecture, engineering and operations.

CCISO course
Governance, risk, program management, finance and vendor management for security leaders.
Since August 2022, 2,405 Accumentum students have certified out of about 2,435 attempts, a 98.8% pass rate.
When your exam date is set, PathPass® has practice banks for both CISSP and CISM. It's $19 a month for one exam or $39 for all banks, with a free preview.
Ways to pay for your course
Pay monthly
PathPay® spreads the course cost into monthly payments. CISM is also on the PathPay 12-Month Program at $204.17 a month, $2,450 total, with the exam voucher included. PathPay is a payment plan, not a loan.
Have your employer pay
Many employers set aside training funds. Ask before you enroll, since many want their paperwork done before the course starts. The funding page covers the options.
Army CA and Air Force COOL
Accumentum is an Army CA and Air Force COOL Approved Vendor, but the Army or the Department of the Air Force decides eligibility and payment. Get approval before you enroll. See our Army CA and Air Force COOL pages.
Questions about which course or payment option fits? Email us at info@accumentum.net.
Frequently asked questions
Which is better, CCISO, CISSP, CISM or SecurityX?
None is better across the board. CCISO fits security executives, CISSP fits technical people moving into leadership, CISM fits managers who run the security program, and SecurityX fits architects and senior engineers who stay hands-on.
Do I need experience to take these exams?
CCISO is the only one that checks experience before the exam. You can sit CISSP or CISM first and prove 5 years of experience afterward. SecurityX has no experience requirement, though CompTIA recommends 10 years in IT with 5 in hands-on security.
What is the passing score for each exam?
CISSP needs 700 out of 1000. CISM needs 450 on a 200 to 800 scale. SecurityX is pass or fail with no scaled score. CCISO sets a cut score for each exam form, between 60 and 85 percent.
How much do the exams cost in 2026?
As of October 10, 2026, U.S. prices are $999 for the CCISO voucher, $749 for CISSP, $575 for CISM with ISACA membership or $760 without, and $544 for SecurityX.
How many questions are on each exam?
CCISO has 150 questions in 2.5 hours. CISSP is adaptive, with 100 to 150 items in 3 hours. CISM has 150 questions in 4 hours. SecurityX has up to 90 questions in up to 165 minutes.
Is SecurityX the same as CASP+?
Yes. CompTIA rebranded CASP+ as SecurityX with the CAS-005 exam, which launched December 17, 2024. ISC2's approved list for the CISSP experience waiver includes both names.
What changes on the CISM exam on November 3, 2026?
ISACA keeps the four domains but moves Governance to 18 percent and Incident Management to 29 percent. It also adds enterprise architecture and information security architecture and puts more weight on strategy and program development.
Can CISSP or CISM help me get CCISO?
Yes. EC-Council says holding CISSP, CISM or CISA qualifies you for its Associate CCISO path. For the full CCISO you still need 5 years of experience in at least 3 of the 5 domains.
Sources
All checked October 10, 2026.
- EC-Council, Certified Chief Information Security Officer page: prerequisites, the five domains, exam length, Associate CCISO path, DoD 8140 work roles and renewal fee: eccouncil.org CCISO page
- EC-Council, CCISO exam information: 150 questions, 2.5 hours, cognitive levels and cut scores from 60% to 85%: ciso.eccouncil.org exam information
- EC-Council, CCISO Candidate Handbook v6.2, issued September 7, 2026: eligibility routes, $100 application fee, $999 voucher, renewal and Appendix A exam blueprint: CCISO Candidate Handbook (PDF)
- EC-Council, CCISO exam blueprint with domain weightage: CCISO Blueprint (PDF)
- ISC2, CISSP Certification Exam Outline: CAT format, length, items, passing grade, languages and domain weights: isc2.org CISSP exam outline
- ISC2, CISSP experience requirements and approved credential list: isc2.org CISSP experience requirements
- ISC2, exam pricing and reschedule and cancel fees: isc2.org exam pricing
- ISC2, member policies: CPE requirements and annual maintenance fee: isc2.org member policies
- ISACA, CISM certification page: exam fees, application fee and the November 3, 2026 outline notice: isaca.org/credentialing/cism
- ISACA, CISM Exam Content Outline: 150 questions and current domain weights: isaca.org CISM exam content outline
- ISACA press release, September 10, 2026: updated CISM outline and weights from November 3, 2026: isaca.org press release
- ISACA, How to get CISM certified: experience and CPE requirements: isaca.org get CISM certified
- ISACA Exam Candidate Guide: 4-hour exam length and the 200 to 800 scale with 450 to pass: ISACA Exam Candidate Guide (PDF)
- ISACA, CPE changes starting January 1, 2027: isaca.org/credentialing/cpe-2027
- CompTIA, SecurityX certification page: exam details, recommended experience, domain weights, DoD 8140 work roles, renewal and voucher price: comptia.org SecurityX
- CompTIA, SecurityX V5 renewal, 75 CEUs required: comptia.org SecurityX renewal
- CompTIA Blog, Introducing SecurityX, CASP+ gets an update and rebrand, December 18, 2024: comptia.org blog
- CompTIA Blog, How much does the SecurityX certification cost: a retake needs another voucher: comptia.org blog