CISM Pass Rate 2026: Why No Official Rate Exists
- Questions
- 150
- Time limit
- 4h
- Passing score
- 450 on a scale of 200…
- Exam fee
- $760
There is no official CISM pass rate. ISACA writes, administers and scores the Certified Information Security Manager exam, and it does not publish how many candidates pass — not on the CISM credential page, not in the CISM Exam Content Outline, and not in the 2026 ISACA Certification Exams Candidate Guide, the document that spells out scoring, rescoring and retakes in detail. The only threshold ISACA publishes is the passing score, and it states it plainly: "Candidates must receive a score of 450 or higher to pass the exam, which represents the minimum standard of knowledge." That 450 sits on a scale running from 200 to 800. It is not a percentage, and the most common CISM claim on the internet — that 450 out of 800 means you need 56% — is arithmetic that cannot be done. Every pass-rate figure circulating in 2026 comes from somewhere other than ISACA, and this page is not going to add another one.
How the CISM exam is actually scored
The CISM is a 150-question multiple-choice exam with a four-hour clock. Everything in the table below is published by ISACA, either on the credential page or in the candidate guide.
| Item | Official value |
|---|---|
| Questions | 150 multiple-choice |
| Time limit | 4 hours (240 minutes) |
| Passing score | 450, scaled |
| Score scale | 200 to 800 |
| Scoring rule | Total items answered correctly; no penalty for wrong answers |
| Exam fee | US$575 ISACA member / US$760 non-member |
| Retakes | Four attempts per rolling 12-month period, full fee each time |
| Published pass rate | None |
Why 450 out of 800 is not 56%
ISACA defines the scaled score explicitly: "A scaled score is a conversion of a candidate's raw score on an exam to a common scale. The purpose of a scaled score is to ensure that a standard way of reporting outcomes is used across disparate versions of the exam so that different versions are comparable and fair." Several things follow, and each one breaks the percentage math.
- The scale does not start at zero. ISACA states that "a score of 200 represents the lowest score possible." Dividing 450 by 800 treats 0 as the floor, which it is not. The passing point is not 56% of anything.
- Not every question counts. "ISACA exams are comprised of scored items as well as pretest items. Pretest items are not used to calculate exam scores." ISACA does not publish how many of the 150 are pretest items, so nobody outside ISACA knows the denominator.
- The conversion changes between exam versions. That is the entire point of scaling. A raw score that converts to 450 on one form will not necessarily convert to 450 on another, which is why a fixed "you need X correct answers" number cannot exist.
- You never see the underlying detail. ISACA's guide is blunt: "Question-level results are not provided." Domain-level results are reported "for informational purposes only" and are not used to calculate the score.
Why the pass rates you see online disagree
Search "CISM pass rate" and the first page of results will hand you numbers that cannot all be true at once — figures in the 40s, the 50s, the 60s and the 70s, sometimes for the same year, sometimes on the same page. What they share is that not one of them cites ISACA, because there is nothing to cite.
The incentive behind the low numbers is worth naming. A training provider that tells you the CISM has a brutal failure rate has just explained why you need its course. A bootcamp reporting its own graduates passing at a high rate has just explained why you need that bootcamp. Both numbers can be honestly measured inside their own population and still tell you nothing about your odds, because neither population is a random sample of CISM candidates.
The "you need 56%" claims are a different failure. They are not measurements at all; they are a scaled score divided by the top of its own scale. Once you know that 200 is the floor, that pretest items are excluded, and that the raw-to-scaled conversion is deliberately not published, you can see that every "% required to pass the CISM" figure was manufactured the same way. Treat any page quoting one as a page that did not read the candidate guide.
What actually separates passing from failing candidates
ISACA publishes the domain weights, and they are the closest thing to a study plan the vendor will give you.
| Domain | Weight |
|---|---|
| 1 — Information Security Governance | 17% |
| 2 — Information Security Risk Management | 20% |
| 3 — Information Security Program | 33% |
| 4 — Incident Management | 30% |
Nearly two-thirds of the exam is program and incident work. Domains 3 and 4 together carry 63%. Candidates who arrive from a hands-on security background often over-prepare governance theory and under-prepare the operational half — building, running and funding a security program, then managing the incident when it fails. The weights say where the marks are.
The exam tests judgment, not recall. ISACA's own exam-taking advice warns that "a question may require you to choose the answer based on a qualifier, such as MOST likely or BEST." Several options will be defensible; one is what a security manager should do first. Candidates who fail typically knew the material and picked the technically correct answer over the managerial one.
The clock is tighter than it looks. Four hours across 150 questions is 96 seconds each, on questions written as short scenarios. There is no reward for leaving anything blank: "There are no penalties for incorrect answers. Grades are based solely on the total number of questions answered correctly, so do not leave any questions blank."
Failing is expensive in time, not just money. ISACA allows four attempts in a rolling 12-month period, but you must wait 30 days after a first failure, then 90 days after the second attempt and 90 days after the third — and you pay the full registration fee every time. A failed first attempt costs at least US$575 and a month.
The content outline changes on 3 November 2026. ISACA states that "the CISM Exam Content Outline will be updated effective 3 November 2026" and that the exam will reflect the new outline from that date. If you are studying against the weights above, know which side of that date your exam falls on.
The bottom line
Nobody knows the CISM pass rate, including the pages quoting one with confidence. What is official is that you need a scaled 450 on a 200-to-800 scale, you get 240 minutes for 150 questions, Information Security Program and Incident Management carry 63% of the weight between them, the fee is US$575 for members and US$760 for everyone else, and you get four attempts a year with 30- and 90-day waits between them. Certification also requires five years of information security management experience, with waivers available for up to two years — but that is a separate application, not a barrier to sitting the exam. None of those decisions would change if a pass rate existed.
The useful next step is finding out where your own judgment breaks down on scenario questions, before you have paid US$575 to find out. Work through a free CISM practice test and see whether you are losing points in governance theory or in the 63% of the exam that is program and incident management.
What the cited data shows
Built from the official facts cited in this article. Missing values are omitted, not estimated.
| Document | Effective date | Checked |
|---|---|---|
| ISACA: CISM Exam Content Outline | Not stated | 2026-07-18 |
| ISACA: ISACA Certification Exam Candidate Guide | Not stated | 2026-07-18 |
Free CISM practice test — 159 questions, instant feedback. No signup required.
Sources
- 1.CISM Exam Content Outline — ISACA (accessed Jul 18, 2026)
- 2.ISACA Certification Exam Candidate Guide — ISACA (accessed Jul 18, 2026)
- 3.ISACA Credentials — ISACA
- 4.ISACA Exam Candidate Guides — ISACA
- 5.ISACA Certification Programs — ISACA
- 6.Certified Information Security Manager (CISM) — ISACA (accessed Aug 16, 2026)
Frequently asked questions
What is the CISM pass rate?
There is no official CISM pass rate. ISACA does not publish pass rates or candidate statistics for the Certified Information Security Manager exam on the CISM credential page, in the CISM Exam Content Outline, or in the ISACA Certification Exams Candidate Guide. Any percentage you see quoted is a third-party estimate, which is why competing figures for the same year can differ by thirty points or more.
Is a CISM score of 450 out of 800 the same as 56%?
No. 450 is a scaled score, not a percentage of questions answered correctly. ISACA converts your raw score onto a common 200-to-800 scale so that different versions of the exam are comparable, the scale bottoms out at 200 rather than zero, and unscored pretest items are excluded from the calculation. That makes it impossible to translate 450 into a fixed percentage or a fixed number of correct answers.
How many questions is the CISM exam and how long do you get?
The CISM exam has 150 multiple-choice questions and a time limit of four hours, or 240 minutes. That works out to about 96 seconds per question. ISACA applies no penalty for wrong answers and scores you only on the total number of items answered correctly, so leaving a question blank can never help you.
How many times can you retake the CISM exam if you fail?
ISACA allows four attempts within a rolling 12-month period. You must wait 30 days after the first attempt before retaking, then 90 days after the second attempt and 90 days after the third, and you pay the full registration fee for each attempt — US$575 for ISACA members and US$760 for non-members.