Exam eligibility
Open before experience is completeISACA says interested candidates can take the exam before meeting the certification experience requirement.
CISM rewards managerial judgment, not technical reflexes. CertArc trains you to spot the governance-first answer when several choices look reasonable, then shows why the distractors fall short and how to avoid these traps.
Last updated:
CISM is ISACA's information security management certification. The exam tests governance, risk management, information security program, and incident management knowledge. You may take the exam before completing the experience requirement, but earning the certification requires the documented experience, application, fees, and ongoing maintenance defined by ISACA.
CertArc addresses a separate preparation problem: applying that knowledge when several answers look reasonable. Its original scenarios and CISM Lens explanations focus on managerial judgment, not copied exam items or pass prediction.
| Question | Current answer | Planning note |
|---|---|---|
| Exam eligibility | Open before experience is complete | ISACA says interested candidates can take the exam before meeting the certification experience requirement. |
| Certification eligibility | 5 years across at least 3 of 4 domains | The experience must meet the current ISACA application rules, and candidates must apply within five years of passing. |
| Current exam | 150 questions across 4 domains | The current outline covers governance, risk management, information security program, and incident management. |
| Passing score | 450 on a 200–800 scale | A scaled score is not the same as a fixed percentage of correct answers. |
| Exam fee | US$575 member; US$760 non-member | Prices were checked on 27 July 2026 and should be verified again before registration. |
| Certification application | US$50 after passing | The application fee is separate from exam registration and is paid when applying for certification. |
| Outline transition | Updated outline from 3 November 2026 | Choose preparation materials according to the date of your scheduled exam. |
ISACA says interested candidates can take the exam before meeting the certification experience requirement.
The experience must meet the current ISACA application rules, and candidates must apply within five years of passing.
The current outline covers governance, risk management, information security program, and incident management.
A scaled score is not the same as a fixed percentage of correct answers.
Prices were checked on 27 July 2026 and should be verified again before registration.
The application fee is separate from exam registration and is paid when applying for certification.
Choose preparation materials according to the date of your scheduled exam.
4 Domains • 150 Questions • Passing Score: 450
Policy, strategy, organizational roles, and accountability structures
Risk identification, assessment, treatment, and monitoring
Program development, management, and resource alignment
Planning, classification, response, and recovery capabilities
Coverage reflects ISACA's current published exam content outline.
Original CISM preparation guides focused on managerial judgment, source-backed exam information, and practical decision frameworks.
Master the ISACA boardroom perspective and decode distractor options designed to trick technical professionals.
Deep dive control, risk treatment, incident response, and GRC scenarios commonly tested on the exam.
Schedules, costs, benchmarks, and honest comparisons with official ISACA QAE platform.
Facts and concepts are one part of preparation. CertArc focuses on another need: practicing the managerial choice when several options sound reasonable.
Some question reviews stop at the correct option. CertArc also explains why a tempting technical answer felt reasonable and which management condition changes the choice.
Videos are useful for filling knowledge gaps. CertArc is active practice for the moment when the exam gives you several plausible choices and asks for the best managerial move.
Flashcards can support terminology recall. Scenarios add the decision layer: risk ownership, governance accountability, business impact, and when to escalate.
Copied or leaked items create integrity risk and encourage answer recognition. CertArc uses original scenarios and explains the decision pattern so it can be applied when the facts change.
Take a 25-question baseline assessment to generate your personalized study syllabus. Target only your weak areas.
Begin Free AssessmentNo credit card required • Free baseline review
CertArc is an independent study platform and is not affiliated with, endorsed by, or sponsored by ISACA®. CISM® is a registered trademark of ISACA. CISM available now.