CISM vs CRISC
CISM and CRISC are both issued by ISACA and both cover risk management — but they are aimed at different functions. CISM is for security managers who own the security programme. CRISC (Certified in Risk and Information Systems Control) is for professionals who specialise in IT risk assessment and control design, often in audit or compliance functions.
Source: ISACA CRISC Certification and ISACA CISM Certification.
Comparison
| Factor | CISM | CRISC |
|---|---|---|
| Issuing body | ISACA | ISACA |
| Primary focus | Security programme management | IT risk identification and controls |
| Target audience | Security managers, CISOs | Risk managers, internal auditors, IT GRC |
| Domains (count) | 4 | 4 |
| Experience required | 5 years (3 in management) | 3 years in risk or IS control |
| Exam questions | 150 | 150 |
| Exam time | 4 hours | 4 hours |
| Exam fee (member) | $575 | $575 |
| Exam fee (non-member) | $760 | $760 |
| CPE requirement | 120/3 years | 120/3 years |
Where the content overlaps
CISM Domain 2 (Information Security Risk Management, 20% of the exam) and the CRISC curriculum share significant conceptual overlap. Both cover risk identification and assessment methodologies, risk treatment options, risk registers, and the distinction between risk appetite and tolerance.
Holding CRISC before sitting CISM gives you a strong foundation for Domain 2. Similarly, a CISM holder pursuing CRISC will find the risk framework familiar. Some study groups describe them as complementary — CISM provides the programme management lens, CRISC provides the technical risk assessment depth.
Where they diverge
CISM covers governance, programme design, incident management, and security architecture at a management level. CRISC does not cover these.
CRISC goes deeper into control design, testing methodologies, and IT risk reporting to the board. It also covers IS controls (ITGC — IT General Controls) in a way that CISM does not. For audit and compliance professionals, CRISC is more directly applicable.
Which to pursue
If your role is security management — owning the security programme, reporting to the board on security posture, managing a team of security professionals — CISM is the right primary certification.
If your role is IT risk, audit, or GRC — identifying and assessing IT risks, designing controls, working with internal audit — CRISC is more relevant.
Both in combination is a strong credential set for a Head of IT Risk or VP GRC role that straddles security management and risk assurance.