ISACA Is Changing the CISM Certification Exam on November 3, 2026: What Security Managers Need to Know

ISACA has quietly set a date that matters more than most people preparing for the Certified Information Security Manager exam realize. Starting November 3, 2026, the CISM Exam Content Outline changes, and ISACA has already confirmed on its own credentialing page that candidates testing after that date will see a different exam than the one currently in circulation. Anyone weighing a CISM certification against other security management paths should treat that date as a real planning input, not background noise. If you hold CISM already, nothing about your certification changes. If you’re mid-study or just starting to plan, the timing of your exam date just became a real decision, not a formality.
ISACA isn’t the only vendor rewriting exam content this year either. ISC2 pushed a CCSP exam outline update of its own earlier in 2026, which is worth knowing if you’re weighing a cloud security credential against a governance-focused one like CISM.
Why ISACA Is Overhauling the CISM Exam Content Outline
CISM has always tested security management rather than hands-on technical skill, which is what separates it from CISSP in most hiring managers’ minds. But the job itself has shifted. Security managers today are expected to understand how identity systems, cloud architecture, and data flows actually fit together across an organization, not just how to write policy around them. Training providers tracking the update, including CertPrepNow and CISM.app, report that ISACA’s revision adds real weight to enterprise architecture and information security architecture literacy, on top of the existing emphasis on program development and strategy alignment that already dominates the exam.
That tracks with where the role has been heading for a few years. A security manager who can’t speak intelligently about zero trust network segmentation or cloud identity federation is increasingly seen as a policy writer, not a strategic partner to the CISO. ISACA’s own update notice frames the change as sharpening that gap.
What Changes on November 3, 2026, and What Doesn’t
The Exam Adds Real Weight to Architecture Literacy
The current outline, still in effect through November 2, splits 150 scored questions across four domains: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%), according to ISACA’s published exam content outline. The four domains themselves are staying in place. What’s changing is the depth of architecture-related content candidates are expected to know within them, particularly inside the Program domain that already carries a third of the exam’s weight.
The Exact New Domain Weights Aren’t Public Yet
Here’s the part worth being upfront about: ISACA has not published the finalized domain-by-domain percentages for the post-November outline. Updated study materials go on sale September 1, 2026, and that’s realistically the first point candidates will see the actual weighting rather than secondhand summaries. Anyone telling you the exact new percentages right now is guessing.
Key Dates Worth Putting on Your Calendar
- September 1, 2026: Updated CISM prep materials go on sale through ISACA
- November 2, 2026: Last day to sit the current version of the exam
- November 3, 2026: The new Exam Content Outline takes effect for every scheduled exam from that point forward
- Anyone who passes before November 3 keeps their certification unchanged. The update affects future test-takers, not existing CISM holders
Should You Sit the Exam Before or After November 3?
The Case for Testing on the Current Outline
If you’re already deep into a study plan built around the existing four-domain structure, finishing on the current outline is usually the lower-risk move. The material is stable, the practice question pools reflect it accurately, and you’re not betting your prep time on content that hasn’t been published yet.
The Case for Waiting Until After November 3
If you’re just starting from scratch, or if your day-to-day work already touches enterprise architecture and cloud security design, waiting might actually work in your favor. You’d be studying material that maps more closely to what you already do, and you’d avoid the awkward position of certifying on an outline that’s about to be considered dated in the eyes of employers evaluating your resume.
A quick way to decide which side you fall on:
- Test before November 2 if you’ve already completed most of a study plan built on the current four-domain outline
- Test before November 2 if your available exam slots and testing center availability are tight for late 2026
- Wait until after November 3 if you’re starting your study plan from zero right now
- Wait until after November 3 if enterprise architecture or cloud security design is already part of your daily work
What CISM Actually Costs, From Registration to Renewal
The certification isn’t cheap, and the sticker price is only the start. Based on ISACA’s own published fee schedule and renewal requirements:
- Exam registration: $575 for ISACA members, $760 for non-members
- Application processing fee after passing: $50, one time
- Annual certification maintenance: $45 for members, $85 for non-members, due every January 1
- Continuing education: 120 CPE hours required over a rolling three-year cycle, with a minimum of 20 hours reported each year
If you want to see exactly what the current outline covers before you commit to a study timeline, PracticeTestSoftware’s CISM practice test package is built against the exam as it stands today, which is worth checking against your planned test date given the November changeover.
Hold more than two ISACA certifications, such as CISM alongside CISA or CRISC, and the annual renewal cost on your third credential and beyond drops to $25 for members and $50 for non-members, which is a detail a lot of multi-credential ISACA holders never realize applies to them.
Who CISM Is Actually Built For
CISM requires five years of information security work experience, with at least three of those years specifically in security management spanning three or more CISM domains, per ISACA’s certification requirements. That last part trips up a surprising number of technically strong candidates who assume a CISSP will cover the gap entirely. It won’t. Here’s how the requirement actually breaks down:
- Five years of total information security experience is required, earned within 10 years before applying or within 5 years after passing the exam
- Three of those five years must be in security management work spanning at least three CISM domains, and this portion can never be waived
- Up to two years of the remaining general experience can be waived through a qualifying degree or another security certification
- Holding CISSP reduces the total requirement by one year, not the full two-year maximum
CISM vs. CISSP: Different Tracks, Not Competing Ones
CISSP tests breadth across eight technical and managerial domains and is generally the harder credential to study for cold. CISM is narrower at four domains but demands precise, ISACA-flavored thinking about governance and program management on nearly every question. Technical architects and engineers tend to lean CISSP. People aiming at a security manager, director, or CISO title lean CISM. A meaningful number of senior candidates eventually hold both, usually earning CISM first since the study window tends to run shorter.
Where CISA and CRISC Fit Around CISM
If your career path runs through governance, risk, and audit rather than pure security leadership, CISA and CRISC sit right next to CISM in ISACA’s own credential family. Our CISA exam guide covers the IT audit and assurance side of that path, while the CRISC preparation breakdown digs into enterprise risk identification and control design. None of the three substitute for each other; they cover distinct enough ground that holding more than one genuinely signals a broader skill set to employers rather than credential stacking for its own sake.
| Certification | Core Focus | Best For | Exam Fee (Member) |
|---|---|---|---|
| CISM | Security governance and program management | Aspiring security managers, directors, CISOs | $575 |
| CISSP | Broad technical and managerial security domains | Architects, engineers, technical leads | $749 (ISC2, member rate varies) |
| CISA | IT audit and assurance | Internal/external auditors, compliance leads | $575 |
| CRISC | Enterprise risk and control design | Risk officers, GRC analysts | $575 |
What the Job Market Is Actually Paying CISM Holders
Compensation data varies a fair amount depending on who’s collecting it, which is worth acknowledging rather than picking whichever number looks best. Glassdoor’s compensation data puts the average total pay for CISM-certified professionals in the United States at $201,429 a year, while ISACA’s own 2025 global salary survey reported a lower worldwide average of $149,000, a gap that mostly reflects the difference between a US-only sample and a global one that includes markets with lower baseline security salaries. Either figure sits well above the general information security analyst median, and CISO-level roles that list CISM as a preferred or required credential routinely clear $180,000 in major US metro markets.
None of that is a guarantee tied to the letters after your name. It reflects the fact that CISM candidates, by the certification’s own experience requirements, are already five years into security management work before they’re even eligible to sit the exam.
PracticeTestSoftware is an independent certification prep provider and is not affiliated with, endorsed by, or sponsored by ISACA. Exam pricing, domain weights, and prerequisite rules change on ISACA’s schedule, not ours, so confirm current details on ISACA’s own CISM certification page before you register or pay any fee.
Frequently Asked Questions About the 2026 CISM Update
{“@context”:”https://schema.org”,”@type”:”FAQPage”,”mainEntity”:[
{“@type”:”Question”,”name”:”Do I need to retake CISM if I already hold the certification?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”No. The November 3, 2026 update only affects candidates who test on or after that date. Anyone who has already passed CISM, at any point since ISACA introduced it in 2002, keeps their certification exactly as earned.”}},
{“@type”:”Question”,”name”:”How many questions are on the CISM exam, and how long do I have?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”The exam runs 150 multiple-choice questions in a 4-hour window, according to ISACA’s exam content outline. This format is not changing with the November 2026 update; only the depth of content within the existing domains is.”}},
{“@type”:”Question”,”name”:”What happens if I buy study materials now and the exam changes before I test?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”ISACA has stated that purchasing current CISM materials does not grant access to the updated versions releasing September 1, 2026. If there’s any chance you’ll test after November 3, it’s worth waiting on new material purchases until the updated version is available.”}},
{“@type”:”Question”,”name”:”Can work experience earned after I pass the CISM exam still count?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Yes. ISACA allows the five-year experience requirement to be satisfied using qualifying work completed within five years after passing the exam, not just before it, as long as it’s submitted within that window.”}},
{“@type”:”Question”,”name”:”Is CISM worth pursuing if I already hold CISSP?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”For most people the answer depends on career direction rather than redundancy. CISSP satisfies one year of CISM’s five-year experience requirement, and a fair number of security leaders eventually hold both since they signal different things: CISSP signals technical breadth, CISM signals management and governance readiness for a director or CISO track.”}}
]}