The CISSP, from ISC2, tests broad security knowledge across eight domains, from architecture and networks to operations and secure software. CISM from ISACA covers four domains and is built for the person who runs the security program, so it leans on governance, risk, program management and incident management. If your work is still mostly technical, CISSP is usually the better first pick, and if you already own security decisions and budgets, CISM tends to fit better.
What is the difference between CISSP and CISM?
Think about who each exam is written for. ISC2 describes CISSP as proof you can design, implement and manage a security program, and its domain list runs wide: security and risk management, asset security, architecture and engineering, network security, identity and access, assessment and testing, security operations and software development security.
CISM is narrower on purpose. ISACA's four domains are Information Security Governance, Information Security Risk Management, Information Security Program and Incident Management. The questions ask what's best for the business, and the most technical answer is often the wrong one.
I tell students it this way. CISSP asks if you understand how security works across the whole shop. CISM asks if you can run it.
How do the CISSP and CISM exams compare?
- Issued by
CISSP: ISC2
CISM: ISACA - Domains
CISSP: 8
CISM: 4 - Exam format
CISSP: Computerized Adaptive Testing, 100 to 150 items
CISM: 150 multiple choice questions - Time
CISSP: 3 hours
CISM: 4 hours - Passing score
CISSP: 700 out of 1000
CISM: 450 on a 200 to 800 scale - Work experience
CISSP: 5 years in 2 or more of the 8 domains
CISM: 5 years of information security management across at least 3 of the 4 domains - Exam fee
CISSP: Not listed on the ISC2 certification page
CISM: US$575 for ISACA members, US$760 for non-members, as of September 2026 - Upkeep
CISSP: 120 CPE credits per 3-year cycle plus a US$135 annual maintenance fee (checked Sep 2026)
CISM: At least 20 CPE hours a year and 120 over 3 years, plus an annual maintenance fee
The biggest domain on CISM is Information Security Program at 33 percent, followed by Incident Management at 30 percent. ISACA updates the CISM domain weights on 3 November 2026. Information Security Governance moves from 17 to 18 percent and Incident Management from 30 to 29 percent. On CISSP, Security and Risk Management is the heaviest at 16 percent, and the rest sit between 10 and 13 percent. That spread tells you a lot. CISSP rewards breadth. CISM rewards depth in running a program.
One date to watch. ISACA says the CISM Exam Content Outline changes on 3 November 2026. If your exam date falls after that, study to the new outline.
What experience do you need for each one?
For CISSP, ISC2 wants five years of cumulative, full-time experience in two or more of the eight domains. A related degree or a credential on the ISC2 approved list can cover one year, and only one year can be waived. Part-time work and internships can count.
ISACA asks CISM candidates for five years of information security management experience, gained within the 10 years before you apply, across at least three of the four CISM domains.
Neither body makes you wait to sit the exam. If you pass CISSP without the experience, you can become an Associate of ISC2 and you get six years to earn it. With CISM, you have five years from your pass date to apply for certification.
Which one is harder, CISSP or CISM?
They're hard in different ways. CISSP is adaptive and covers a lot of ground, so people with a narrow background feel stretched. CISM has fewer topics, but the questions want the manager's answer. Engineers who've never owned a budget or a risk register tend to pick the technical fix and miss.
Should I get CISSP or CISM first?
Look at your job today and the one you want in two years. If you're an engineer, analyst or architect moving toward leadership, CISSP first makes sense. It's broad, and ISC2 lists it under U.S. DoDM 8140.03. If you already manage people, run a GRC function or report risk to executives, CISM will line up with work you already do.
Can you hold both CISSP and CISM?
Yes, and plenty of security leaders do. There's a practical link too. CISM is on ISC2's approved credential list, so holding CISM can satisfy one year of the CISSP experience requirement.
What does it cost to keep CISSP and CISM active?
ISC2 requires 120 CPE credits over each three-year CISSP cycle and a US$135 annual maintenance fee, as of September 2026. ISC2 suggests about 40 a year but doesn't make that a yearly rule unless you're an Associate.
ISACA wants at least 20 CPE hours every calendar year and 120 across the three-year period. As of September 2026, ISACA's support site lists the annual maintenance fee at US$45 for members and US$85 for non-members. Starting 1 January 2027, at least 90 of those 120 hours must line up with the certification's domains.
How can Accumentum help with CISSP or CISM?
Our CISSP training course runs 10 modules aligned to the CISSP CBK. The CISM training course runs 10 modules across ISACA's four domains and is written for people who own the security program. The course page says it isn't a pentest class. You can see the rest of the ISC2 lineup on our ISC2 training page.
If paying up front is the hard part, PathPay® spreads the course cost into monthly payments. CISM is also on the PathPay 12-Month Program, with the exam voucher included. PathPay is a payment plan for one course. It isn't a loan and it isn't insurance.
When your exam date is set, PathPass® has practice banks for both CISSP and CISM. It's $19 a month for one exam or $39 for all banks, with a free preview. PathPass is exam prep only. It isn't a certification body and it has no brain dumps.
After you pass, PathLock™ tracks your renewal dates and gives you monthly activity packs mapped to CISSP and CISM domains that you can self-report. It isn't vendor CPE pre-approval, and it doesn't replace the ISC2 or ISACA maintenance fee. PathLock is an Accumentum product and isn't connected to Pathlock, Inc.
Frequently asked questions
Is CISM easier than CISSP?
It has fewer domains, but it isn't easy. CISM questions ask for the best answer for the business, and technical people often miss them by choosing the hands-on fix.
Can I take CISSP or CISM without five years of experience?
Yes. You can sit either exam first. Pass CISSP early and you can become an Associate of ISC2 with six years to earn the experience. Pass CISM and you have five years from your pass date to apply.
Does CISM count toward the CISSP experience requirement?
Yes. CISM is on ISC2's approved credential list, which can satisfy one year of the five-year CISSP requirement. Only one year can be waived in total.
How many questions are on the CISSP and CISM exams?
CISSP uses adaptive testing with 100 to 150 items in 3 hours. CISM has 150 multiple choice questions in 4 hours.
How many CPEs do CISSP and CISM need?
CISSP needs 120 CPE credits every three years. CISM needs at least 20 CPE hours each year and 120 over three years.
Sources
Official facts checked Sep 28, 2026.
- ISC2, CISSP certification page: https://www.isc2.org/certifications/cissp
- ISC2, CISSP Certification Exam Outline (exam format, weights, experience): https://www.isc2.org/certifications/cissp/cissp-certification-exam-outline
- ISC2, CISSP Experience Requirements and approved credential list: https://www.isc2.org/certifications/cissp/cissp-experience-requirements
- ISC2, Member Policies (CPE table and annual maintenance fee): https://www.isc2.org/policies-procedures/member-policies
- ISACA, CISM certification page (exam fees, content outline update date): https://www.isaca.org/credentialing/cism
- ISACA, CISM Exam Content Outline (domains and weights): https://www.isaca.org/credentialing/cism/cism-exam-content-outline
- ISACA, How to get CISM certified (experience, CPE): https://www.isaca.org/credentialing/cism/get-cism-certified
- ISACA Support, exam question type (150 multiple choice): https://support.isaca.org/s/article/What-type-of-questions-are-on-the-exam-1597877235317
- ISACA Support, exam scoring (200 to 800 scale, 450 to pass): https://support.isaca.org/s/article/Exams-How-is-my-Certification-exam-scored-brief-version
- ISACA Exam Candidate Guide (4-hour exam length): https://www.isaca.org/credentialing/-/media/fa494652c5f149289af38cef18328650.ashx
- ISACA Support, maintenance requirements and fees: https://support.isaca.org/s/article/What-are-the-requirements-to-maintain-my-certification-1597877233626
- ISACA, CPE 2027 changes: https://www.isaca.org/credentialing/cpe-2027
- ISACA, CISM exam content outline update (weights from 3 November 2026): https://www.isaca.org/about-us/newsroom/press-releases/2026/isaca-updates-cism-exam-content-outline-factoring-in-todays-technologies-security-responsibilities
Accumentum facts come from the live course pages, /pathpay/, /pathpay/subscription/, /pathpass/ and /pathlock/ on accumentum.net.