CISM vs CISA
CISM and CISA are both ISACA certifications with the same exam format, fees, and renewal rules. CISM is for people who manage an information security program, and CISA is for auditors who assess IT systems and controls.
Side by Side
| CISM | CISA | |
|---|---|---|
| Full name | Certified Information Security Manager | Certified Information Systems Auditor |
| Issuer | ISACA | ISACA |
| Level | Advanced | Advanced |
| Exam type | Multiple choice | Multiple choice |
| Questions | 150 | 150 |
| Duration | 4 hours (240 minutes) | 4 hours (240 minutes) |
| Passing score | 450 on a scale of 200-800 | 450 on a scale of 200-800 |
| Exam fee | $760 | $760 |
| Prerequisites | Five or more years of information security management experience across at least three of the four CISM domains, gained within the 10 years before applying. Waivers can cover up to two years. | Five or more years of professional IS auditing, control or security experience, gained within the 10 years before applying. Waivers can cover up to three years, and candidates can take the exam before the experience is complete. |
| Validity | 3 years | 3 years |
| Renewal | 20 CPE hours each year and 120 CPE hours per three-year period, plus an annual maintenance fee of US$45 (members) or US$85 (non-members), reduced to US$25/US$50 for a third or later ISACA certification. | 20 CPE hours each year and 120 CPE hours per three-year period, plus an annual maintenance fee of US$45 (members) or US$85 (non-members), reduced to US$25/US$50 for a third or later ISACA certification. |
| Exam domains | Information Security Governance; Information Security Risk Management; Information Security Program; Incident Management | Information Systems Auditing Process; Governance and Management of IT; Information Systems Acquisition, Development and Implementation; Information Systems Operations and Business Resilience; Protection of Information Assets |
Main Differences
- +Focus: CISM covers security governance, risk management, program development, and incident management. CISA covers the audit process, IT governance, systems acquisition and development, operations and resilience, and protection of information assets.
- +Experience: CISM needs five years of information security management experience. CISA needs five years of IS auditing, control, or security experience and allows waivers of up to three years, compared with up to two for CISM.
- +Exam and cost: both have 150 questions in 4 hours, a passing score of 450 on a 200 to 800 scale, and a fee of $575 for members or $760 for non-members.
- +Renewal: both require 20 CPE hours a year and 120 per three-year period, with the same annual maintenance fee.
Certification Details
Frequently Asked Questions
Can you hold both CISM and CISA?→
Yes. Each certification carries its own annual maintenance fee. Once a holder has more than two ISACA certifications, the fee for the third and each later one drops to $25 for members or $50 for non-members.
Do CISM and CISA have the same passing score?→
Yes. Both exams are scored on a 200 to 800 scale and require 450 to pass.
Sources
- Get CISM Certified
- CISM Exam Content Outline
- Maintain CISM Certification
- Get CISA Certified
- CISA Exam Content Outline
- Maintain CISA Certification
- ISACA Certification Exams Candidate Guide 2026
- ISACA: CISM certification
- ISACA CPE Policy
- ISACA press release: ISACA Updates CISM Exam Content Outline (2026)
- ISACA press release: CISM exam updates launch 1 June 2022
- ISACA: CISA certification
- ISACA press release: CISA exam updated (2024)
- ISACA press release: ISACA Introduces the CISA Associate
- ISACA: CISA Associate
Exam details come from official issuer pages and are listed in the sources above. Fees and exam versions change; confirm with the issuer before registering.