CISM vs CRISC
CISM and CRISC are both issued by ISACA and both cover risk management — but they are aimed at different functions. CISM is for security managers who own the security programme. CRISC (Certified in Risk and Information Systems Control) is for professionals who specialise in IT risk assessment and control design, often in audit or compliance functions.
Source: ISACA CRISC Certification and ISACA CISM Certification.
Comparison
| Factor | CISM | CRISC |
|---|---|---|
| Issuing body | ISACA | ISACA |
| Primary focus | Security programme management | IT risk identification and controls |
| Target audience | Security managers, CISOs | Risk managers, internal auditors, IT GRC |
| Domains (count) | 4 | 4 |
| Experience for certification | 5 years across at least 3 CISM domains | 3 years across at least 2 CRISC domains |
| Exam questions | 150 | 150 |
| Exam time | 4 hours | 4 hours |
| Exam fee (member) | $575 | $575 |
| Exam fee (non-member) | $760 | $760 |
| CPE requirement | 20 annually and 120 over 3 years | 20 annually and 120 over 3 years |
Checked 8 September 2026. Passing the exam alone does not award certification. Confirm your qualifying experience and application requirements with ISACA: CISM requirements and CRISC requirements. Exam fees are in US dollars and exclude separate application and maintenance fees.
Where the content overlaps
CISM Domain 2 (Information Security Risk Management, 20% of the exam) and the CRISC curriculum share significant conceptual overlap. Both cover risk identification and assessment methodologies, risk treatment options, risk registers, and the distinction between risk appetite and tolerance.
Prior CRISC study may help with CISM risk topics, but it does not replace reviewing the CISM outline. The credentials approach overlapping concepts from different responsibilities: managing an information security programme and managing IT risk.
Where they diverge
CISM centres on managing an information security programme across governance, risk, programme development and incident management. CRISC also covers governance, enterprise architecture and incident-related operations; these are not exclusive to CISM.
CRISC organises its outline around governance, risk assessment, risk response and reporting, and technology and security. Its control-design and testing topics overlap with CISM. Compare the detailed tasks with your responsibilities rather than assuming either credential owns a topic exclusively.
Which to pursue
If your role is security management — owning the security programme, reporting to the board on security posture, managing a team of security professionals — CISM is the right primary certification.
If your role is IT risk, audit, or GRC — identifying and assessing IT risks, designing controls, working with internal audit — CRISC is more relevant.
Both in combination is a strong credential set for a Head of IT Risk or VP GRC role that straddles security management and risk assurance.