Every Exam PrepFREE EXAM PREP
Ask AI
EXAM GUIDE · CISM

Certified Information Security Manager Exam Guide

Administered by ISACAVerified against the official content outline
Written by Every Exam Prep Editorial TeamSource and review policyPublished July 18, 2026Updated July 23, 2026

At a glance

Questions
150
Time limit
4h
Passing score
450 on a scale of 200 to 800
Exam fee
$760
Governing body
ISACA

Quick answers

How much does the CISM cost?

The CISM exam fee is $760 (non-members; $575 ISACA members).

What is the passing score for the CISM?

The passing score for the CISM is 450 on a scale of 200 to 800.

How many questions is the CISM?

The CISM has 150 questions with a time limit of 4 hours.

The Certified Information Security Manager (CISM) is a globally recognized credential for IT security leaders and risk managers. ISACA designed CISM for professionals who oversee security programs, lead incident response, and align security strategy with business objectives. This certification validates your ability to govern information security across enterprise environments.

Overview

CISM exam content spans 4 job practice domains: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%). The domains reflect real-world leadership responsibilities—from establishing governance frameworks and managing risk to building security programs and handling security incidents.

Cost and registration

The CISM exam registration fee is US$575.00 for ISACA members and US$760.00 for non-members. This covers your exam registration and eligibility to schedule. Membership in ISACA offers a fee discount, making it cost-effective for committed candidates planning a multi-year certification path.

Exam format

CISM is a 150-question, 4-hour (240-minute) exam. Each question presents a stem and 4 answer options with one best answer. You'll receive a scaled score on ISACA's 200–800 scale; a score of 450 or higher is required to pass. Testing is available in-person at test centers or online via remote proctoring through PSI.

Verified facts about the CISM

19 statements, each bound to the official document it was taken from. The source link beside every line opens that document.

Requirements and rules

Cert application window years
Candidates have 5 years from passing the exam to apply for CISM certification
ISACA
Delivery modes
The CISM exam is delivered either at an In-Person Test Center or as an Online Remote Proctored exam via PSI
ISACA
Registration before scheduling
Candidates must first register and pay before being notified by email that they are eligible to schedule the CISM exam on the PSI platform
PSI
Reschedule window hours
All rescheduling and cancelling of a CISM testing appointment must be done a minimum of 48 hours prior to the scheduled appointment
ISACA
Scoring scheme
CISM scores are reported as scaled scores rather than raw or percentage scores
ISACA
Testing vendor
PSI is ISACA's exam delivery vendor for the CISM exam
PSI

Fees

Exam fee member
$The CISM exam registration fee is US$575.00 for ISACA members
ISACA
Exam fee nonmember
$The CISM exam registration fee is US$760.00 for non-members
ISACA

Numbers

Answer options per question
Every CISM question has a stem and 4 answer options with one best answer
ISACA
Domain count
The CISM exam covers 4 job practice domains
ISACA
Duration minutes
The CISM exam length is 240 minutes (4 hours)
ISACA
Passing score
Candidates must receive a scaled score of 450 or higher to pass, on ISACA's common scale from 200 to 800
ISACA
Question count
The CISM exam contains 150 questions
ISACA
Question count guide
The CISM exam consists of 150 multiple-choice questions
ISACA

What is tested

Domain1 governance weight
Domain 1, Information Security Governance, accounts for 17% of the exam%
ISACA
Domain2 risk weight
Domain 2, Information Security Risk Management, accounts for 20% of the exam%
ISACA
Domain3 program weight
Domain 3, Information Security Program, is the largest domain at 33% of the exam%
ISACA
Domain4 incident weight
Domain 4, Incident Management, accounts for 30% of the exam%
ISACA
Domains list
The four CISM domains are Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management
ISACA

How hard is the CISM?

How Hard Is the CISM Certification Exam?

The Certified Information Security Manager (CISM) exam stands as one of the information security field's most respected and rigorous certifications. Administered by ISACA, the CISM tests not just technical knowledge but strategic security management capabilities across a comprehensive body of job practice domains. Understanding the exam's difficulty requires looking at both its structure and what preparation truly demands.

Exam Structure and Format

The CISM exam is delivered either at an In-Person Test Center or as an Online Remote Proctored exam via PSI, giving candidates flexibility in how they sit for the assessment. The exam itself contains 150 multiple-choice questions, all structured with a stem and 4 answer options with one best answer. Candidates have 240 minutes (4 hours) to complete the exam.

The exam operates on a scaled scoring system rather than raw or percentage scores. Candidates must receive a scaled score of 450 or higher to pass, on ISACA's common scale from 200 to 800. This scaled approach means that the difficulty calibration of questions in any given exam administration is normalized, preventing variance in passing rates across different test dates.

Exam Element Detail
Total Questions 150
Answer Options per Question 4
Total Duration 240 minutes (4 hours)
Passing Score 450 (on 200–800 scale)
Exam Fee (ISACA Members) $575.00
Exam Fee (Non-Members) $760.00
Delivery Options In-Person Test Center or Online Remote Proctored

Domain Coverage and Weighting

The CISM exam covers 4 job practice domains, each weighted to reflect its importance in security management practice. The four domains are Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management.

Domain 1, Information Security Governance, accounts for 17% of the exam. This domain covers how organizations establish strategic direction, oversight structures, and policies. Domain 2, Information Security Risk Management, accounts for 20% of the exam, focusing on identifying, analyzing, and mitigating security risks. Domain 3, Information Security Program, is the largest domain at 33% of the exam, reflecting the breadth of activities required to build and sustain an effective security program. Finally, Domain 4, Incident Management, accounts for 30% of the exam, covering detection, response, recovery, and lessons learned from security incidents.

The dominance of Domain 3 signals that the exam prioritizes breadth of program management over depth in any single area. This means preparation requires a holistic understanding of how security functions integrate and operate together, rather than mastery of isolated technical concepts.

Difficulty Assessment

The CISM is considered one of the harder information security certifications to pass, though not for technical depth alone. The exam's difficulty stems from several factors: the breadth of domains that must be understood, the management perspective required (not just technical implementation), and the scenario-based nature of many questions. Unlike some certifications that can be passed through memorization, CISM questions often present realistic security situations and ask candidates to identify the best action or decision from imperfect options.

The scaled scoring requirement of 450 out of 800 seems approachable until you factor in the breadth of material. Few candidates can walk into the exam without deliberate preparation and pass comfortably.

The exam draws from ISACA's official CISM review manual and real-world security management practice. Questions test not just knowledge recall but judgment: whether you understand when to prioritize risk management over compliance, how to communicate security business case, and how incident response overlaps with governance. These judgment calls are harder to study for than facts.

Preparation Approach

Effective CISM preparation requires a structural approach across multiple dimensions. Begin by establishing foundational knowledge across all four domains through official ISACA materials, learning governance structures, risk frameworks, program controls, and incident response processes. The study sequence should prioritize domains by exam weight: start with Domain 3 (Information Security Program) to establish the conceptual backbone, then move to Domains 2 and 4 (Risk Management and Incident Management) concurrently. Complete your foundation with Domain 1 (Governance), which often tests conceptual thinking and executive alignment.

Hands-on experience matters significantly. Candidates with direct security management experience have an advantage because they recognize patterns from real projects. If your background is primarily technical, seek opportunities to observe risk assessments, audit preparations, or incident response activities to build intuition.

Practice questions are essential for identifying weak areas and understanding how ISACA frames questions. Work through question banks systematically, reviewing why correct answers are superior. Review weak domains repeatedly until your performance stabilizes. Readiness signals include consistently strong performance on full-length practice exams and demonstrating ability to reason through unfamiliar scenarios by applying domain principles rather than relying on recognition.

Registration and Scheduling

Candidates must first register and pay before being notified by email that they are eligible to schedule the CISM exam on the PSI platform. This means you cannot schedule until payment is confirmed. Once notified, you can schedule at an available test center or online proctoring slot. All rescheduling and cancelling of a CISM testing appointment must be done a minimum of 48 hours prior to the scheduled appointment, so plan accordingly if circumstances change.

An important detail: candidates have 5 years from passing the exam to apply for CISM certification. Passing the exam and earning the credential are two separate steps. You must also meet experience and education requirements, which are verified during certification application.

Is It Worth the Effort?

The CISM's difficulty is intentional. ISACA maintains rigorous standards because organizations hiring CISM-certified professionals expect them to drive security strategy and manage complex programs, not just execute technical tasks. The exam's breadth and judgment-based questions reflect that bar. The exam demands sustained engagement with security management concepts, strategic thinking across multiple domains, and demonstrated ability to learn from official materials and practice questions.

CISM is most valuable for security practitioners stepping into or already in management roles. If you lead security teams, make risk decisions, or report to the CISO, this credential signals to employers that you've validated your strategic security knowledge. Study materials are available through ISACA, including official guides and practice exam banks, and many candidates supplement with formal courses or bootcamps.

Difficulty is relative to preparation. Many candidates who fail did so not because the exam was impossibly hard, but because they underestimated breadth and relied on cramming. Those who passed typically invested consistent effort across all four domains, worked practice questions to mastery, and approached the exam as testing judgment, not just recall.

CISM pass rate: the reported numbersFirst-attempt versus retake rates, where each figure is published, and what it changes about a study plan.

Ways to prepare for the CISM

Weighing a paid course

Each of these is a side-by-side on what the provider does better than we do, what it charges today, and where the free path here is enough.

Frequently asked questions

How much does the CISM exam cost?

The CISM exam registration fee is US$575.00 for ISACA members and US$760.00 for non-members. Because the non-member price is US$185 higher than the member rate, weigh the cost of an ISACA membership against that difference — for many candidates, joining before registering effectively offsets much of the gap on the exam fee alone.

How many questions are on the CISM exam and how long is it?

The CISM exam consists of 150 multiple-choice questions and you have 240 minutes (4 hours) to complete it. Every question has a stem and four answer options, each designed with one best answer. That works out to an average of roughly 1.6 minutes per question, so practice pacing yourself and leave time to review flagged items.

What is a passing score on the CISM exam and how is it scored?

CISM scores are reported as scaled scores rather than raw or percentage scores. ISACA uses a common scale from 200 to 800, where 800 represents a perfect score, and you must receive a scaled score of 450 or higher to pass. Because scaling accounts for differences in question difficulty across exam forms, the 450 threshold does not map to a fixed percentage of correct answers — focus on mastering the content rather than targeting a specific raw percentage.

What domains does the CISM exam cover and how are they weighted?

The CISM exam covers four job practice domains that together comprise 100% of the 150-question exam: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%). Since Domain 3, Information Security Program, is the largest at 33% and Domain 4, Incident Management, follows at 30%, these two domains alone account for well over half the exam — prioritize them when allocating your study time.

How hard is the CISM exam?

The CISM exam is demanding because it is a four-hour, management-level test: ISACA sets the exam length at 240 minutes and includes 150 multiple-choice questions, which leaves under two minutes per item. According to ISACA, every question has a stem and four answer options designed with one best answer, so the difficulty comes less from recall and more from choosing the best managerial response among several defensible ones. ISACA spreads the exam across four job practice domains, meaning you cannot pass by mastering only the technical material.

What is the passing score for CISM, and is there a published pass rate?

You need a scaled score of 450 or higher to pass, on ISACA's common scale that runs from 200 to 800. ISACA reports results as scaled scores rather than raw or percentage scores, so 450 does not correspond to answering 450 out of 800 questions or to any fixed percentage correct. ISACA does not publish an official CISM pass rate in the exam materials cited here, so any pass-rate figure you see quoted elsewhere should be treated as unverified.

How should I study for CISM, and where should I focus?

Weight your study time to the domain weights ISACA publishes, because they are far from even. According to ISACA, Domain 3, Information Security Program, is the largest at 33% of the exam, and Domain 4, Incident Management, accounts for 30%, so those two together make up nearly two-thirds of the questions. Domain 2, Information Security Risk Management, accounts for 20% and Domain 1, Information Security Governance, for 17% — still worth solid coverage, since governance concepts underpin the answer choices in every other domain.

Where do I take the CISM exam, and can I reschedule?

You can take CISM either at an in-person test center or as an online remote proctored exam, both delivered through PSI, which is ISACA's exam delivery vendor. Rescheduling or cancelling a testing appointment must be done a minimum of 48 hours before the scheduled appointment, so put that deadline in your calendar as soon as you book. Because scheduling only opens after you register and pay, plan the payment step earlier than you think you need to.

How long do I have to get certified after passing the exam?

Candidates have five years from passing the exam to apply for CISM certification, according to ISACA. ISACA also notes that exam eligibility itself is valid for six months from the date of registration, so the clock starts running before you ever sit down to test. In practice that means two separate deadlines to track: one to take the exam after registering, and a much longer one to complete your certification application after passing.

Sources

  1. 1.CISM Exam Content OutlineISACA (accessed Jul 18, 2026)
  2. 2.CISM Certification OverviewISACA (accessed Jul 18, 2026)
  3. 3.ISACA Certification Exam Candidate GuideISACA (accessed Jul 18, 2026)
  4. 4.CISA/CRISC/CISM/CGEIT/CDPSE Exam Scheduling GuideISACA (accessed Jul 18, 2026)
  5. 5.ISACA CredentialsISACA
  6. 6.ISACA (CISA/CRISC/CISM/CGEIT) Scheduling GuidePSI (accessed Jul 18, 2026)

Official sources

Primary documents used to verify the exam details shown on this page.

Last verified against the official exam content outline: