Every Exam PrepFREE EXAM PREP
Ask AI

CISA vs CISM (2026): Differences & Which First

Written by Every Exam Prep Editorial TeamSource and review policyPublished August 16, 2026Updated August 22, 2026
Verified against the official exam documentation

The CISA and CISM are both ISACA certifications, and on paper they look almost interchangeable: 150 questions, 240 minutes, a passing score of 450 on a 200–800 scale, and identical exam fees. That symmetry is the point — ISACA has removed format from the equation, so the choice comes down entirely to career direction. CISA (Certified Information Systems Auditor) is the credential for information systems audit, assurance, and controls work. CISM (Certified Information Security Manager) is for people who run security programs — governance, risk, and incident management at the management layer. Choose the exam that matches the job you want, because the experience requirements will hold you to it.

What each exam is for

CISA is the audit credential. ISACA calls it "the standard of achievement for auditing, monitoring, and assessing IT and business systems," and its five exam domains map directly to the auditor's job: Information Systems Auditing Process; Governance and Management of Information Technology; Information Systems Acquisition, Development & Implementation; Information Systems Operations and Business Resilience; and Protection of Information Assets. If your work involves testing controls, running IT audits, or providing assurance over systems — internal audit, external audit, IT compliance — CISA is the certification those employers expect to see.

CISM sits one level up the org chart. ISACA positions it around your "ability to assess risks, implement effective governance, and proactively respond to incidents," and its four domains are pure management territory: Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management. There is no hands-on technical tooling here. CISM tests whether you can build and run a security program — set strategy, manage risk, direct incident response — which is why it fits security managers and people headed for that role.

Format, length, and cost: functionally identical

Question counts and time limits

Both exams present 150 questions in 240 minutes. Four hours is a long sitting either way, and neither exam offers a shorter path — so unlike most head-to-head certification choices, test-day logistics give you no reason to prefer one over the other.

Passing standard

Both exams are scored on a 200–800 scale, and both require 450 to pass. That is a scaled score, not a percentage, so don't translate it into "answer X percent correctly" — question difficulty factors into the scaling. The practical takeaway is the same for both exams: the bar is fixed, and it is identical across the two.

Fees

Pricing is identical too, with the same membership split on both exams: US$575 for ISACA members and US$760 for non-members, per ISACA's current published pricing. If you see one figure quoted for CISA and a different one for CISM, you're almost certainly looking at member pricing for one and non-member pricing for the other. Before registering, run the math on whether an ISACA membership pays for itself through the $185 exam discount. Both credentials also carry a one-time US$50 application processing fee when you later apply for certification.

Prerequisites and sequencing

Neither exam has a prerequisite exam — you can register and sit either one today. The gate comes after: passing the exam does not make you certified. To earn the CISA credential, ISACA requires a minimum of five years of professional information systems auditing, control, or security work experience, gained within the ten-year period preceding your application. CISM requires a minimum of five years of professional information security management work experience within its job practice areas, on the same ten-year clock. Both give you five years after passing the exam to submit your certification application.

Read those two experience definitions closely, because they answer the "which first" question for most people. CISA's qualifying experience is broad — auditing, control, or security work — the kind of experience many IT professionals accumulate early. CISM's is narrower: security management specifically, which usually arrives later in a career. A common sequence is CISA first, on the strength of hands-on audit or security experience, then CISM once your role shifts from executing the work to directing it. And because both credentials let you apply up to five years after passing, you can sit an exam before you have the full five years of experience and bank the pass while the clock runs.

The verdict, by situation

  • You work in IT audit, assurance, or compliance (or want to): CISA. Its five domains are built around the audit process, and it's the credential audit employers look for.
  • You manage — or are about to manage — a security program: CISM. Its governance, risk, program, and incident-management domains describe the security manager's job, and its experience requirement expects management-level work.
  • You're early-career and can't show management experience yet: start with CISA — its broader "auditing, control or security" experience definition is reachable sooner, and you can add CISM later when your role changes.
  • You're deciding based on format or price: don't. Both are 150 questions in 240 minutes, scored 450 on a 200–800 scale, at US$575 member / US$760 non-member. There is no easier or cheaper option here — only a different career direction.

Whichever direction you choose, the four-hour format rewards pacing and stamina as much as knowledge, and the only way to train those is a timed run. If audit is your path — or you're still deciding — take a free CISA practice test to see how the question style suits you before you commit US$575 or more to a seat.

Official facts behind this comparison

The figures below come from the official source documents linked in the table. They are included so you can make study and registration decisions from published requirements rather than an unsupported estimate.

Published detailValueOfficial source
Together Domains 4 and 5 account for 52% of the exam contentDomains 4 and 5 together account for 52% of the exam contentISACA
a scaled score of 450 or higher is required to passA scaled score of 450 or higher is required to pass the CISA examISACA
Candidates have five years from the date of passing the exam to apply for CISA certificationCandidates have 5 years from passing the exam to apply for CISA certificationISACA
Original source visualizations

What the cited data shows

Built from the official facts cited in this article. Missing values are omitted, not estimated.

Official-source update comparison
DocumentEffective dateChecked
ISACA: Certification Exam Candidate GuidesNot stated2026-07-18
ISACA: CISA Certification OverviewNot stated2026-07-18
ISACA: CISA Exam Content OutlineNot stated2026-07-18
Ready to test yourself?

Free CISA practice test — 159 questions, instant feedback. No signup required.

Start practicing →

Sources

  1. 1.CISA Exam Content OutlineISACA (accessed Jul 18, 2026)
  2. 2.Certification Exam Candidate GuidesISACA (accessed Jul 18, 2026)
  3. 3.CISA Certification OverviewISACA (accessed Jul 18, 2026)
  4. 4.ISACA CredentialsISACA
  5. 5.ISACA Certification ProgramsISACA
  6. 6.CISM — Certified Information Security ManagerISACA (accessed Aug 15, 2026)

Frequently asked questions

Are the CISA and CISM exams the same format?

Yes — both are ISACA exams with 150 questions, a 240-minute time limit, and a passing score of 450 on a 200–800 scale. Exam fees are also identical: US$575 for ISACA members and US$760 for non-members. The difference between them is content and career focus, not format.

Should I take CISA or CISM first?

Most candidates who pursue both take CISA first. Its certification experience requirement accepts auditing, control, or security work — experience many IT professionals build early — while CISM certification requires five years of information security management experience specifically, which typically comes later in a career. If you already work in security management, there is no reason CISM can't come first.

Do I need work experience before sitting the CISA or CISM exam?

No — you can register and take either exam with no prior experience and no prerequisite exams. Experience is required for certification, not for the exam itself: five years within the relevant job practice areas, gained in the ten years before you apply. ISACA gives you five years after passing the exam to submit your certification application, so you can pass first and accumulate the experience afterward.

How much do CISA and CISM cost in 2026?

Both exams cost US$575 for ISACA members and US$760 for non-members — pricing is identical across the two certifications. Each also carries a one-time US$50 application processing fee when you apply for certification after passing. If you see different prices quoted for the two exams, it is usually member pricing for one being compared against non-member pricing for the other.