CISM vs CISSP: the same five years, two different jobs
CISM and CISSP are not a beginner and an advanced version of the same thing. They are two credentials with almost identical experience gates and entirely different subject matter, and choosing between them is a question about your job rather than your ability.
The two experience clauses, compared
ISC2 requires for CISSP a minimum of five years cumulative, full-time experience in two or more of the eight domains, with up to one year waived by a relevant degree or an approved ISC2 credential. ISACA requires for CISM five years of professional information security management experience in at least three of the four CISM domains, earned within the ten-year period preceding the application.
Three differences matter. ISACA's clause specifies management experience, not security experience generally — running a programme, owning risk, answering for incidents. And ISACA puts a recency window on it: experience older than ten years does not count, where ISC2 publishes no such limit. ISACA also gives candidates five years from the passing date to apply for certification, which is a shorter runway than ISC2's six years for Associates.
What they actually cover
CISSP spans eight domains: risk and governance, asset security, architecture and engineering, networks, identity, assessment and testing, operations and software development security. Nothing exceeds 16% of the paper. It is deliberately broad, and it includes a great deal of technical material.
CISM has four: Information Security Governance, Information Security Risk Management, Information Security Program and Incident Management. ISACA does not publish percentage weightings for them on the pages we read, so we do not quote any. There is no cryptography domain, no network security domain and no software development domain, because CISM is not about building the controls — it is about owning the programme that decides which controls exist.
The money, both ways
ISACA lists the CISM exam at US $575.00 for members and US $760.00 for non-members, plus a US $50 application processing fee when you apply for certification. ISC2 lists CISSP at $749 across the Americas, Asia Pacific, the Middle East and Africa.
So the comparison depends entirely on membership. An ISACA member sits CISM for $174 less than CISSP; a non-member pays $810 in total for the exam and application, which is more than CISSP. Weigh that against ISACA membership costs, which we have not verified on ISACA's own page and therefore do not quote here.
Ongoing, the two bodies charge differently in kind. ISC2 takes a flat $135 annual maintenance fee and asks for 120 CPE credits per three-year cycle, at least 90 of them Group A. ISACA asks CISM holders for a minimum of 120 CPE hours across a three-year reporting period with a minimum of 20 hours per year — a harder annual floor than ISC2's, which for certified members is a recommendation rather than a requirement.
How to choose without agonising
Answer one question honestly: in the last year, did you spend more time making decisions about systems or making decisions about programmes? If your week is design reviews, architecture calls and escalations from engineers, CISSP describes you. If your week is risk registers, board papers, budget and vendor assessments, CISM does.
A second, cruder test works surprisingly well: read the four CISM domain names aloud. If none of them sounds like your job, the five years ISACA wants are probably not five years you have.
Holding both
Plenty of people do eventually, and the sequence usually runs CISSP then CISM as the work shifts from systems to programmes. There is no discount for it — the bodies are unrelated, and you will pay two sets of maintenance obligations, ISC2's annual fee and ISACA's per-year CPE floor. Do not collect them in parallel: two credentials in the same year is an expensive way to signal something a single relevant one already says.
If you are not yet at five years for either, neither is the right target this year. Compare what each certification demands before it will certify you, and look at CCSP against CISSP if your estate is mostly somebody else's data centre — that is a different fork in the same road.
What ISACA publishes, and what it does not
One practical difference between the two bodies is how much they tell you before you commit. ISC2 publishes a full CISSP exam outline: three hours, 100 to 150 questions, computerised adaptive testing, a pass mark of 700 out of 1000, and a percentage weighting for every one of the eight domains.
ISACA's public CISM pages, read on 24 September 2026, name the four domains but do not publish their weightings, the number of questions, the duration or the scaled passing score. Those figures circulate widely online, and we are not repeating them, because the pages we could open do not carry them. If you need them before deciding, ask ISACA directly rather than trusting a third-party summary — and treat that opacity as a small but real cost of choosing CISM.
The renewal obligations are shaped differently
Both bodies want 120 hours of continuing education across three years, which looks identical until you read how each enforces it. ISC2 asks for 120 CPE credits per cycle with at least 90 in Group A, and its 40-a-year figure is a recommendation for certified members rather than a requirement. ISACA sets a floor: a minimum of 20 CPE hours in every single year, as well as the 120 across the three-year reporting period.
That difference matters to anybody whose professional development comes in bursts. An ISC2 credential tolerates a quiet year followed by a conference-heavy one. An ISACA credential does not, and a year in which you logged nothing is a compliance problem regardless of how far ahead you were.
The financial shape differs too. ISC2's $135 annual maintenance fee covers every ISC2 certification you hold, so a second credential adds no recurring cost. ISACA's fee structure for maintaining CISM is not published on the pages we read, so we do not quote it — another figure to confirm before you choose.
CISM and CISSP, side by side
Is CISM harder than CISSP?
Which pays more, CISM or CISSP?
Can CISSP count towards CISM, or the other way round?
How long do I have to apply after passing?
Still deciding between credentials? Work through which cybersecurity certification fits the stage you are at, or read how every figure on this site is checked. Fees, formats and eligibility rules change without warning — open the certifying body’s page before you pay for anything.