CertArcStart 21 Day Free Access

CISM vs CRISC

CISM and CRISC are both issued by ISACA and both cover risk management — but they are aimed at different functions. CISM is for security managers who own the security programme. CRISC (Certified in Risk and Information Systems Control) is for professionals who specialise in IT risk assessment and control design, often in audit or compliance functions.

Source: ISACA CRISC Certification and ISACA CISM Certification.


Comparison

FactorCISMCRISC
Issuing bodyISACAISACA
Primary focusSecurity programme managementIT risk identification and controls
Target audienceSecurity managers, CISOsRisk managers, internal auditors, IT GRC
Domains (count)44
Experience required5 years (3 in management)3 years in risk or IS control
Exam questions150150
Exam time4 hours4 hours
Exam fee (member)$575$575
Exam fee (non-member)$760$760
CPE requirement120/3 years120/3 years

Where the content overlaps

CISM Domain 2 (Information Security Risk Management, 20% of the exam) and the CRISC curriculum share significant conceptual overlap. Both cover risk identification and assessment methodologies, risk treatment options, risk registers, and the distinction between risk appetite and tolerance.

Holding CRISC before sitting CISM gives you a strong foundation for Domain 2. Similarly, a CISM holder pursuing CRISC will find the risk framework familiar. Some study groups describe them as complementary — CISM provides the programme management lens, CRISC provides the technical risk assessment depth.

Where they diverge

CISM covers governance, programme design, incident management, and security architecture at a management level. CRISC does not cover these.

CRISC goes deeper into control design, testing methodologies, and IT risk reporting to the board. It also covers IS controls (ITGC — IT General Controls) in a way that CISM does not. For audit and compliance professionals, CRISC is more directly applicable.

Which to pursue

If your role is security management — owning the security programme, reporting to the board on security posture, managing a team of security professionals — CISM is the right primary certification.

If your role is IT risk, audit, or GRC — identifying and assessing IT risks, designing controls, working with internal audit — CRISC is more relevant.

Both in combination is a strong credential set for a Head of IT Risk or VP GRC role that straddles security management and risk assurance.

CISM vs CISSP →Domain 2: Risk Management →CISM salary data →CISM FAQ →

CertArc — CISM Exam Prep

Train the reasoning, not the answer

Scenario-based CISM practice. CISM Lens explanations that show why the stronger managerial answer wins. Adaptive spaced repetition that finds your weak domains.

Start free assessment

CertArc is not affiliated with, endorsed by, or sponsored by ISACA®. CISM® is a registered trademark of ISACA.