Cybersecurity Insights

CISM Exam Changes on November 3, 2026: What's New and How to Plan

ISACA's updated CISM exam starts on November 3, 2026. The four domains stay the same, but the weights shift slightly and ISACA adds two new content areas, enterprise architecture and information security architecture. If you test on or after November 3, ISACA strongly recommends studying with the updated materials.

Think of it as a tune-up. Most of what you already know still applies. The date you sit the exam is what decides which version you get.

When does the CISM exam change?

ISACA released updated CISM exam prep materials on September 1, 2026, and says the updated exam will be available on November 3, 2026. The CISM exam content outline page carries the same notice. Starting that date, the exam reflects the new outline.

So the rule is simple. Sit the exam before November 3 and you get the current version. On November 3 or later, you get the new one.

What are the new CISM domain weights?

ISACA kept all four domains and moved a few points between them. The comparison below uses the current outline and ISACA's September 10, 2026 announcement.

  • CISM domain: 1. Information Security Governance
    Current weight: 17%
    From November 3, 2026: 18%
  • CISM domain: 2. Information Security Risk Management
    Current weight: 20%
    From November 3, 2026: 20%
  • CISM domain: 3. Information Security Program
    Current weight: 33%
    From November 3, 2026: 33%
  • CISM domain: 4. Incident Management
    Current weight: 30%
    From November 3, 2026: 29%

Governance picks up one point and Incident Management gives one up. Risk and Program don't move. On a 150-question exam, that's a small shift, and it shouldn't change how you split your study time much.

What new topics are on the CISM exam?

This is the part that deserves your attention. ISACA says the updated exam puts greater emphasis on information security strategy and program development. It also adds two new content areas, enterprise architecture and information security architecture.

ISACA's reason is straightforward. A security manager needs to understand the technologies under their purview, and architecture is where those technology choices get made. You won't be designing the network as a CISM. What the exam expects is that you know enough to shape those decisions, spot the risk in them and explain it to leadership.

In practice, I expect this to show up as scenario questions where you're asked what a security manager should do about architecture decisions. Think about how security fits into the enterprise's structure, how a manager weighs in on design, and how architecture supports the security strategy. CISM stays a management exam, so the right answer will still be the one that serves the business and the program.

If you come from an engineering background, this part may feel familiar. People who came up through audit or GRC should give it extra time. And if you're still deciding between this exam and CISSP, our CISSP vs CISM page lays out the difference.

I'm registering now. Which version will I take?

That depends on your test date, and ISACA's scheduling rules make this worth planning. Your CISM exam eligibility starts when you register and lasts six months. Testing appointments only open 90 days in advance. You can reschedule without penalty during your eligibility period if you do it at least 48 hours before your appointment.

Put those together and a registration today could easily land you on the new exam. If you register in late September, your six-month window runs into spring 2027, and most of it falls after November 3.

Here's how I'd decide.

  1. You're nearly ready and can book a date before November 3: go for it on the current outline.
  2. You're starting now or need more than about four weeks: plan for the new exam and study with updated materials.
  3. You've booked a date before November 3 but aren't ready: know that rescheduling past November 3 means the new exam.

Does the change affect people who already hold CISM?

No. The update applies to people taking the exam, and nothing in ISACA's announcement asks current holders to retest. If you already hold CISM, you keep it by meeting the normal CPE and maintenance rules.

There's a separate change coming for holders, though. Starting January 1, 2027, ISACA still requires 120 CPE hours per three-year period, but at least 90 of them must align with the certification's exam content outline. Up to 30 can be professional or non-domain hours. I cover this in our guide on keeping your certification active.

What CISM facts stay the same?

The exam is still 150 multiple-choice questions in four hours, scored on a 200 to 800 scale with 450 needed to pass. As of September 2026, ISACA lists the fee at US$575 for members and US$760 for non-members, plus a US$50 application fee after you pass. You still need five years of information security management experience across at least three of the four domains, gained within the 10 years before you apply, and you have five years from passing to apply. What CISM holders earn is on our CISM salary page.

How can Accumentum help you prepare?

Our CISM training course runs 10 modules across the four domains, and the course page already notes the November 3, 2026 outline change. When you enroll, we'll look at your target date and make sure you're studying for the right version.

CISM is on the PathPay 12-Month Program at $204.17 a month, $2,450 total, with the exam voucher included. PathPay® is a payment plan, not a loan. For practice, PathPass® has a CISM bank at $19 a month for one exam or $39 for all banks, with a free preview.

Frequently asked questions

When does the new CISM exam start?

ISACA says the updated CISM exam will be available on November 3, 2026. Exams taken before that date use the current content outline.

What are the new CISM domain weights?

From November 3, 2026, the weights are Governance 18 percent, Risk Management 20 percent, Information Security Program 33 percent and Incident Management 29 percent.

What new topics were added to CISM?

ISACA adds two content areas, enterprise architecture and information security architecture, and puts more emphasis on information security strategy and program development.

Should I use new study materials for CISM?

If your exam is on or after November 3, 2026, ISACA strongly recommends the updated exam prep materials, which it released September 1, 2026.

Do current CISM holders need to retake the exam?

No. The update applies to new exams. Current holders keep their certification by meeting CPE and maintenance requirements, and a CPE alignment rule starts January 1, 2027.

Keep Exploring

Find your next certification advantage.

Return to Accumentum Insights or jump into related training and exam preparation.