Both CISA and CISM come from ISACA, but they certify different jobs. CISA is for people who audit and assess information systems and controls, and CISM is for people who build and run an information security program. Pick CISA if your work is testing controls and reporting findings, and pick CISM if you're the one who owns the security program those findings land on.
What is the difference between CISA and CISM?
The easiest way I know to explain it is to picture an audit finding. The CISA writes it. The CISM has to fix it and explain the risk to leadership.
ISACA calls CISA the standard for auditing, monitoring and assessing IT and business systems. Its five domains are the Information Systems Auditing Process, Governance and Management of IT, Information Systems Acquisition, Development and Implementation, Information Systems Operations and Business Resilience, and Protection of Information Assets.
CISM has four domains built around running security: Information Security Governance, Information Security Risk Management, Information Security Program and Incident Management.
How do the CISA and CISM exams compare?
Both exams share the same ISACA format, which surprises people. The difference is what's inside.
- Focus
CISA: IS audit, control and assurance
CISM: Information security management - Domains
CISA: 5
CISM: 4 - Heaviest domains
CISA: Operations and Business Resilience 26%, Protection of Information Assets 26%
CISM: Information Security Program 33%, Incident Management 30% - Questions
CISA: 150 multiple choice
CISM: 150 multiple choice - Time
CISA: 4 hours
CISM: 4 hours - Scoring
CISA: 200 to 800 scale, 450 to pass
CISM: 200 to 800 scale, 450 to pass - Exam fee (checked Sep 2026)
CISA: US$575 members, US$760 non-members
CISM: US$575 members, US$760 non-members - Work experience
CISA: 5 years in IS audit, control or security
CISM: 5 years in information security management, across at least 3 of the 4 domains - CPE
CISA: 20 hours a year, 120 over 3 years
CISM: 20 hours a year, 120 over 3 years
ISACA updates the CISM domain weights on 3 November 2026. Information Security Governance moves from 17 to 18 percent and Incident Management from 30 to 29 percent.
Every ISACA question has four answer choices and one best answer. Some come with a short scenario and two or more questions tied to it.
What experience do you need for CISA or CISM?
ISACA lets anyone sit the exam. You apply for the certification afterward, and you have five years from your pass date to do it. As of September 2026, there's a one-time US$50 application processing fee.
CISA needs five years of professional information systems auditing, control or security work. CISM needs five years of information security management work across at least three of the four CISM domains. For both, the experience has to fall within the 10 years before you apply.
Which is better for my career, CISA or CISM?
Neither one is better across the board. It depends on which side of the table you sit on.
CISA fits IT auditors, internal audit staff, compliance analysts and assurance consultants. If your week is scoping audits, sampling evidence and writing reports, CISA matches the work. It also carries a standards piece, because CISA holders agree to follow ISACA's Information Systems Auditing Standards.
CISM fits security managers, aspiring CISOs and GRC leads. If you set policy, pick controls, report risk and lead incident response, CISM matches that.
Some people move from audit into security leadership. In that case CISA first and CISM later is a common order, though nothing requires it.
Can I earn both CISA and CISM?
Yes. The same CPE hours can count toward more than one ISACA certification when the activity fits each one. So holding both doesn't double your CPE load if you pick activities that serve both.
What changes are coming for CISM and ISACA CPE?
Two dates matter. ISACA says the CISM Exam Content Outline changes on 3 November 2026, so check which outline covers your exam date. Then starting 1 January 2027, ISACA's CPE policy keeps the 120-hour, three-year total, but at least 90 of those hours must align with the certification's domains.
How can Accumentum help with CISA or CISM?
Our CISA training course covers all five job practice domains. The course page says most students finish in 4 to 8 weeks part-time, delivered as virtual instructor-led training with lifetime access to recordings. The CISM training course runs 10 modules mapped to ISACA's four domains. If risk is your lane, we also teach CRISC and CGEIT.
Both CISA and CISM are on the PathPay 12-Month Program. Each includes the exam voucher. PathPay® is a payment plan for one course. It isn't a loan and it isn't insurance.
PathPass® has ISACA practice banks for CISA and CISM at $19 a month for one exam or $39 for all banks, with a free preview. It's exam prep, not a certification body, and it has no dumps. Once you're certified, PathLock™ tracks your renewal calendar and gives you monthly activity packs mapped to CISA and CISM domains for your own self-report to ISACA. It isn't ISACA pre-approval and doesn't replace ISACA's maintenance fee. It's also unrelated to Pathlock, Inc.
Frequently asked questions
Is CISA or CISM harder?
They use the same format, 150 questions in 4 hours, scored 200 to 800 with 450 to pass. Most people find the one outside their daily work harder. Auditors struggle with CISM's management judgment and security managers struggle with CISA's audit process.
Do CISA and CISM have the same exam fee?
Yes. As of September 2026, ISACA lists both at US$575 for members and US$760 for non-members, plus a one-time US$50 application fee after you pass.
Can I take the CISA or CISM exam before I have five years of experience?
Yes. ISACA lets anyone sit the exam. You then have five years from your pass date to apply, and the experience has to fall within the 10 years before your application.
How many CPE hours do CISA and CISM require?
Each requires at least 20 CPE hours every year and 120 hours over a three-year period. Hours can count toward both when the activity fits both certifications.
Should an IT auditor get CISA or CISM?
Most IT auditors start with CISA because it matches audit work directly. CISM makes more sense once you're moving into running a security program.
Sources
Official facts checked Sep 28, 2026.
- ISACA, CISA certification page (exam fees, 5-year apply window): https://www.isaca.org/credentialing/cisa
- ISACA, CISA Exam Content Outline (domains and weights): https://www.isaca.org/credentialing/cisa/cisa-exam-content-outline
- ISACA, How to get CISA certified (experience, CPE, auditing standards): https://www.isaca.org/credentialing/cisa/get-cisa-certified
- ISACA, CISM certification page (exam fees, content outline update): https://www.isaca.org/credentialing/cism
- ISACA, CISM Exam Content Outline (domains and weights): https://www.isaca.org/credentialing/cism/cism-exam-content-outline
- ISACA, How to get CISM certified (experience, CPE): https://www.isaca.org/credentialing/cism/get-cism-certified
- ISACA Support, exam question type: https://support.isaca.org/s/article/What-type-of-questions-are-on-the-exam-1597877235317
- ISACA Support, exam scoring: https://support.isaca.org/s/article/Exams-How-is-my-Certification-exam-scored-brief-version
- ISACA Exam Candidate Guide (4-hour exam length): https://www.isaca.org/credentialing/-/media/fa494652c5f149289af38cef18328650.ashx
- ISACA, Maintain CISA certification: https://www.isaca.org/credentialing/cisa/maintain-cisa-certification
- ISACA, CPE 2027 changes: https://www.isaca.org/credentialing/cpe-2027
- ISACA, CISM exam content outline update (weights from 3 November 2026): https://www.isaca.org/about-us/newsroom/press-releases/2026/isaca-updates-cism-exam-content-outline-factoring-in-todays-technologies-security-responsibilities
Accumentum facts come from the live CISA, CISM, CRISC and CGEIT course pages, /pathpay/, /pathpay/subscription/, /pathpass/ and /pathlock/ on accumentum.net.