TL;DR
- ISACA’s updated CISM exam content outline takes effect November 3, 2026. November 2 is the last day to sit the current version. ISACA’s updated prep materials began launching on September 1, 2026.
- The change is real but modest. ISACA’s own wording: “The four CISM domains will remain the same, but the distribution of select exam content will slightly change.” Governance moves from 17% to 18%, Incident Management from 30% to 29%, Risk Management stays at 20%, and Information Security Program stays at 33%.
- The bigger shift is in content, not percentages. ISACA adds two new areas, enterprise architecture and information security architecture, and puts more emphasis on security strategy and program development.
- Format and price do not change: 150 questions, 4 hours, a passing score of 450 on a 200 to 800 scale, $575 for ISACA members or $760 for non-members, plus a $50 application fee after you pass.
- The date that matters most for most people is not November 3. ISACA enforces a 30-day wait between attempts. A first attempt on October 3 could still be retaken on the old outline by November 2. A first attempt on October 4 or later cannot. If you test on the current outline from now on and fail, your retake will be on the updated outline, with materials you did not study.
- Rule of thumb: sit before November 3 only if you are already well into current materials and can realistically pass on the first attempt. Anyone starting from zero should study for the new outline using ISACA’s updated materials and target January to March 2027.
- Nothing changes for existing CISM holders. The update applies to new candidates only.
Quick Facts: Old vs New CISM Outline
| Current outline (through Nov 2, 2026) | Updated outline (from Nov 3, 2026) | |
| Domain 1: Information Security Governance | 17% | 18% |
| Domain 2: Information Security Risk Management | 20% | 20% |
| Domain 3: Information Security Program | 33% | 33% |
| Domain 4: Incident Management | 30% | 29% |
| New content areas | None | Enterprise architecture, information security architecture |
| Emphasis shift | Current weighting | More emphasis on security strategy and program development |
| Questions | 150 | 150 |
| Duration | 4 hours | 4 hours |
| Passing score | 450 (scale 200 to 800) | 450 (scale 200 to 800) |
| Cost | $575 member / $760 non-member | Same |
| Application fee (after passing) | $50 | $50 |
| Wait between attempts | 30 days (as reported) | Same |
| Official ISACA prep materials | Current edition | Updated edition, launching from Sept 1, 2026 |
| Last outline update | June 2022 | November 2026 |
A Note on Conflicting Information Online
CISM search results right now contain contradictory claims, and it helps to know why before you plan around any of them.
If you read about this change before mid-August 2026, you may have seen statements that ISACA had not published the new weightings. Some pages still say so. They are out of date. ISACA’s press release now lists the new weights (18/20/33/29), the two new content areas, and the September 1 materials date. Other pages published earlier in the year predicted new areas such as AI governance, DORA, NIS2, zero trust and cloud governance as additions. Those were guesses based on industry trends. The only new areas ISACA has confirmed are enterprise architecture and information security architecture.
Two things are still not fully public in the sources reviewed: the complete revised task and knowledge statement list showing exactly which sub-topics move where, and the number of questions that will cover the new architecture content. Domain-by-domain write-ups from training providers are informed interpretation, not ISACA documentation. Use them as direction, and check ISACA’s CISM page for the outline itself.
The Calendar That Decides This
| Date | What happens | What it means for you |
| September 1, 2026 | ISACA’s updated prep products begin launching | Materials for the new outline are available (exact dates vary by product and language) |
| October 3, 2026 | Last first-attempt date that still allows a 30-day retake by November 2 | The retake safety net on the old outline is already gone |
| November 2, 2026 | Final day to test on the current outline | Last chance on the 2022 blueprint |
| November 3, 2026 | Updated outline takes effect | Every exam from here uses the new content |
| January to March 2027 | Suggested window for candidates starting from scratch | Enough runway to study the new outline with updated materials |
The January to March suggestion comes from training providers working through the study-hours math, not from ISACA. It is a practical recommendation, not a rule.
The Retake Math: Why the Real Deadline Already Passed
Most advice on this change centers on November 3. The calendar math is tighter than that, because ISACA requires a mandatory wait between failed attempts, reported as 30 days.
| If your first attempt is on | Earliest retake (30-day wait) | Retake on the current outline? |
| October 3 or earlier | November 2 or earlier | Yes, just barely |
| October 4 | November 3 | No, the new outline applies |
| Mid-October | Mid-November | No |
| Late October | Late November | No |
| November 2 | December 2 | No |
The consequence is simple. From October 4 onward, a first attempt on the old outline is effectively one shot. If it does not go well, your second attempt will be on the updated outline, studied from material that does not fully cover it. ISACA states plainly that buying current CISM material does not give you access to the updated material later, so you would be buying again.
Training providers call the worst outcome the “dangerous middle”: starting now with current material, drifting through the fall, and ending up sitting a December exam with a blueprint that expired weeks earlier. The cost of that is a second registration fee ($575 to $760), a forced repurchase of study materials, and a cooling-off period on top.
That turns the question from “which exam is easier” into “can I pass the first time, on the current outline, in the time left?”
Can You Realistically Study for the Old Outline Now?
Do the arithmetic before you decide. From October 5 to November 2 is 28 days, or four weeks.
Training providers recommend roughly 150 to 200 hours of preparation for most candidates, based on a 13-week plan at 10 to 12 hours a week. The range by background looks like this:
| Background | Typical preparation | Hours |
| Security management professionals (5+ years in governance) | 2 to 3 months | 90 to 130 |
| Compliance and audit professionals | 3 to 4 months | 120 to 160 |
| IT managers without a security background | 4 to 5 months | 150 to 180 |
| Technical security practitioners | 4 to 6 months | 160 to 200 |
At 10 to 12 hours a week, four weeks gives you about 40 to 48 hours. That is enough only for someone who has already completed most of their preparation and needs timed practice and review. For anyone who is less than roughly 60% through a full plan, the numbers do not work, and rushing is the likeliest way to turn a $575 to $760 registration into a failed attempt.
These hour figures are estimates published by training providers. ISACA does not publish a recommended study duration.
Which Profile Are You?
Already deep into current materials and scoring well on practice exams. Testing before November 3 is reasonable. You are studying against a known blueprint, and the weighting changes are small enough that your preparation largely holds. Book a date in the next two to three weeks and treat it as a single attempt, since a retake on the old outline is no longer possible. Take a full 150-question timed practice exam this week and aim for comfortably above your pass target before you book.
Studied part of the way, with gaps in program management or incident management. This is the risky middle. The two heaviest domains, Program at 33% and Incident Management at 30% (29% after), carry 62 to 63% of the exam on either outline, and they are also where the new architecture and strategy content lands. If you cannot close those gaps within four weeks, waiting is the safer choice.
Haven’t started, or still earning the required experience. Target the updated outline. ISACA’s new materials launched on September 1, and there is no benefit to learning content that is about to change. A date in January to March 2027 gives you time to work through the updated Review Manual and question database without a deadline squeeze.
Employer-funded, with a budget or fiscal-year deadline. Some training providers suggest registering before November 2 to use this year’s budget and then sitting later with updated materials. Check ISACA’s terms before relying on that. Your registration carries an eligibility period (reported as six months), and which outline applies depends on the date you actually sit, not the date you register.
What Changed, Domain by Domain
ISACA keeps four domains. Here is what each covers, with the old and new weights. The task descriptions below reflect the structure of the current outline as described by training providers, with the changes ISACA has confirmed noted separately.
Domain 1: Information Security Governance (17% to 18%)
This domain covers enterprise governance (organizational culture, legal and regulatory requirements, roles and responsibilities) and information security strategy (developing the strategy, putting governance frameworks in place, planning budgets, resources and business cases). A manager-level candidate needs to show how security initiatives align with business objectives.
ISACA confirmed more emphasis on information security strategy. Training providers describe the shift as moving from frameworks and alignment toward strategy itself. The weight rises by one point.
Domain 2: Information Security Risk Management (20%, unchanged)
Risk assessment (emerging threats, vulnerabilities, control deficiencies, formal analysis methods) and risk response (treatment options, ownership, monitoring and reporting). The test is translating risk findings into business language and choosing a response proportionate to the organization’s risk tolerance.
The weight does not change. Training providers expect more attention to risk appetite, though ISACA has not published sub-topic detail.
Domain 3: Information Security Program (33%, unchanged, largest domain)
Program development covers resource allocation, asset classification, standards and frameworks, policies and procedures, and metrics. Program management covers control design, implementation and testing, awareness training, third-party management, and communications.
This is the largest domain and the one that absorbs the new architecture content, according to training providers. ISACA confirmed more emphasis on security program development. The weight stays at 33%, but the content inside it grows.
Domain 4: Incident Management (30% to 29%)
Readiness covers incident response plans, business impact analysis, business continuity and disaster recovery planning, classification schemes, and training and testing. Operations covers investigation tools, containment, response communications, eradication and recovery, and post-incident reviews.
The weight drops by one point. Training providers describe the content as shifting from response and recovery toward a consolidated focus on resilience, which is interpretation rather than ISACA’s stated outline.
Approximate question counts
Based on 150 questions, the weights work out as follows. These are arithmetic, not ISACA statements, and they ignore any unscored questions.
| Domain | Current weight | Approx. questions | New weight | Approx. questions |
| Governance | 17% | about 26 | 18% | about 27 |
| Risk Management | 20% | about 30 | 20% | about 30 |
| Program | 33% | about 50 | 33% | about 50 |
| Incident Management | 30% | about 45 | 29% | about 44 |
The differences are one or two questions per domain. The weights alone do not explain why ISACA is making this change. The new architecture content is the real difference.
What the New Architecture Content Means
ISACA says it added enterprise architecture and information security architecture to reflect technologies now under a security manager’s responsibility, particularly in cloud and hybrid environments and wider digital transformation.
In plain language, and as an explanation rather than a quotation from ISACA’s outline: enterprise architecture is how an organization’s business processes, applications, data and technology fit together. Information security architecture is how security controls are designed into that structure. A security manager does not build the architecture, but needs to understand it well enough to make governance decisions and to communicate with the engineers who do.
Training providers who have looked at the change are consistent on one point: this does not make CISM a technical exam. The goal is architectural fluency for decision-making, not hands-on configuration. If you have mostly worked in governance, risk or audit, expect this to be the area where you have to learn something new. If you come from engineering, expect the reverse: you will probably find the architecture content easy and the governance thinking harder.
What Stays the Same
Everything about the mechanics of taking the exam stays as it is.
- 150 scenario-based multiple-choice questions in a fixed (non-adaptive) format.
- 4 hours.
- Scaled scoring from 200 to 800, with 450 required to pass. ISACA provides domain-level feedback after a failed attempt.
- Pricing: $575 for ISACA members, $760 for non-members, plus a $50 application fee after you pass.
- Delivery: Pearson VUE test centers or online proctoring, as described by training providers.
- Question style: management-level judgment, with qualifiers that change the answer.
On those qualifiers: questions use words such as FIRST (process sequence), BEST (judgment between defensible options) and MOST IMPORTANT (prioritization from a governance perspective). Reading these words carefully is as important as knowing the content.
Exam Logistics Worth Knowing
- Eligibility period. Registration carries an eligibility period, reported as six months. Confirm the exact length when you pay.
- Rescheduling. Reported as free when done at least 48 hours before the appointment and within your eligibility window.
- Booking horizon. Appointments display up to 90 days in advance, as reported.
- Retakes. A mandatory waiting period applies between unsuccessful attempts, reported as 30 days.
- Pass rates. ISACA does not publish official pass rates. Industry estimates put first-attempt pass rates somewhere between 50% and 65%. Treat that as an estimate, not a statistic.
Experience Requirements: The Part That Surprises People
Passing the exam does not make you CISM certified. You also need qualifying experience.
| Requirement | Detail |
| Total experience | 5 years of professional information security work |
| Management experience | At least 3 years in information security management, covering 3 or more of the 4 domains |
| Waivers | Up to 2 years of the 5-year total can be waived through credentials such as CISSP or CISA, or a relevant postgraduate degree |
| Waiver limit | Only one waiver applies, and the 3-year management minimum cannot be reduced |
| Experience window | Within the 10 years before you apply, or within 5 years after you pass |
| Application fee | $50 one-time, after passing |
Because you can sit the exam first and document experience afterward (within five years), the experience requirement does not block you from taking the exam. It does decide when you can use the credential. If you are early in your career, that matters for the timing decision: there is no reason to rush the old outline just because you are not yet eligible to be certified.
Confirm these details against ISACA’s CISM page before you apply. They are as reported by training providers.
A 13-Week Plan for the Updated Outline
If you are starting now and targeting January 2027, a 13-week structure at 10 to 12 hours a week fits. This plan is a training-provider framework, adapted to the new weights.
| Weeks | Focus | Practice |
| 1 to 2 | Diagnostic exam, read ISACA’s content outline, map your job to the domains, set your calendar | One diagnostic exam |
| 3 to 4 | Domain 1: Governance (18%) | 20 to 25 questions in week 3, 30 to 40 in week 4 |
| 5 to 6 | Domain 2: Risk Management (20%) | 25 to 30, then 30 to 40 plus mixed Domain 1 and 2 sets |
| 7 to 9 | Domain 3: Program (33%), including the new architecture content | 25 to 30, 30 to 40, then 40 to 50 plus timed 40-question sets |
| 10 to 11 | Domain 4: Incident Management (29%) | 25 to 30, then 30 to 40 plus timed 50-question sets |
| 12 | Integration | Two full 75-question timed exams, aiming for 65 to 70% or better |
| 13 | Final review | One full 150-question timed exam, then review weak areas and stop 24 hours before the exam |
That is roughly 525 to 630 practice questions across the content weeks. Add time for the architecture topics in Domain 3 if you do not already have an architecture background.
Why People Fail CISM
Training providers report the same pattern. Most candidates who fail the first attempt do not lack knowledge. They answer as practitioners solving a technical problem rather than as managers governing a risk. A question that asks what a security manager should do FIRST is rarely asking for the technically best fix. It is usually asking about reporting, ownership, business impact or process.
If you are a technical practitioner, practice that shift specifically. If you are a compliance or audit professional, expect the opposite challenge: Domain 4 and the new architecture content will feel less familiar.
Already Hold CISM?
Nothing changes for you. Outline updates apply to future candidates and have no retroactive effect on credentials already earned. Maintenance stays the same: 20 continuing professional education hours each year, 120 hours across each three-year cycle, and the annual maintenance fee.
Reading the updated outline is still worth an hour of your time, certified or not. It shows where ISACA thinks the security management role is heading.
Career Impact and Salary
CISM salary figures vary widely by source, and the gaps tell you something.
| Source | Figure |
| ZipRecruiter, October 4, 2026 | $94,926 average; middle 50% between $49,500 and $127,500; 90th percentile $152,500 |
| PayScale (as cited by Destination Certification) | $141,000 average across 1,300+ respondents |
| Destination Certification aggregated data | Entry-level (0 to 2 years) about $72,315; mid-career (3 to 7 years) about $104,214; senior (8+ years) about $186,697 |
Those numbers disagree because they measure different things. ZipRecruiter groups job listings that mention CISM, which includes analyst and manager titles at all seniority levels. PayScale’s respondents skew toward experienced managers who already hold the credential. The Destination Certification tiers show how much of the difference is simply experience.
Because CISM requires five years of experience to certify, most holders are mid-career or beyond, which is why the PayScale-style figure looks higher than the ZipRecruiter average. Do not read either as “what CISM adds to your salary.” They reflect the person as much as the credential.
Common job titles for CISM holders include Information Security Manager, Security Director, Risk Manager, IT Director, Compliance Manager, Security Consultant, GRC Lead and CISO. Pay at the top of that list is far higher than the averages above, but those figures depend on company size and sector, and any single number for CISOs should be treated as indicative.
No source separates the pay of holders who passed the old outline from the new one, and none can yet, since the updated exam has not launched. Nothing in the data suggests a pay difference between the two versions. Employers will see the CISM credential either way.
For how CISM compares with other credentials, see CertMage’s CRISC vs CISM comparison and CISSP vs CISM guide. In short: CISSP validates broad technical and managerial knowledge, while CISM targets management roles specifically, and many security leaders hold both.
What We Don’t Know Yet
- The full task and knowledge statements for the updated outline. ISACA’s updated outline and materials are where this will be spelled out.
- How questions will be distributed inside each domain. The domain weights are known. The sub-topic split is not.
- How many questions will cover the new architecture content. ISACA has not specified a count.
- Whether pass rates move on the new outline. The passing score is stated as unchanged at 450. Actual outcomes will only be visible after November.
How to Prepare
- Decide your target outline first, then buy materials. ISACA states current material does not convert to the updated version later.
- If you are sitting before November 3, book a date now, take a full-length practice exam this week, and spend remaining study time on Program and Incident Management, the two largest domains. Treat it as a single attempt.
- If you are targeting the updated outline, use ISACA’s updated Review Manual, question database and online review course, and add time for enterprise architecture and security architecture.
- Practice the manager mindset. For every scenario, ask what a manager accountable for the risk would do first, not what an engineer would fix.
- Read the qualifiers. FIRST, BEST and MOST IMPORTANT change which answer is correct.
- Use ISACA’s domain feedback. If you do not pass, the domain-level breakdown shows where to focus.
- Plan your longer path. CISM sits alongside other ISACA credentials. CGEIT vs CRISC and CDPSE vs CIPT show how ISACA’s governance, risk and privacy credentials relate.
Common Mistakes
- Treating November 3 as the only deadline. The 30-day retake wait means your effective deadline for a second attempt on the old outline has already passed.
- Buying current material and testing after November 3. Current material does not convert to the updated version, so you pay twice.
- Studying from old material for the new exam. The architecture content and the strategy emphasis will not be fully covered.
- Reading pre-August articles that say the weights are unpublished. They are published.
- Believing guesses about new topics. AI governance, DORA and similar lists came from trend predictions. ISACA confirmed enterprise architecture and information security architecture.
- Registering and drifting. Starting now, losing momentum through October, and testing in December on the new outline with old notes is the common failure.
- Waiting forever for a “stable” outline. ISACA refreshes the job practice every few years. Waiting for a period with no change means waiting indefinitely.
- Assuming the exam got easier or harder. Weights moved by a point. Content shifted toward architecture and strategy. The revised exam is harder mainly for people using misaligned materials.
Related Reading on CertMage
For other ISACA and security credentials, see Best Cybersecurity Certifications 2026, Top 5 Cybersecurity Certification Exams for Audit and Compliance Roles, and CIA vs CISA.
FAQS
When does the new CISM exam start?
November 3, 2026. November 2 is the last day to sit the current version.
What are the new CISM domain weights?
Governance 18%, Risk Management 20%, Program 33%, Incident Management 29%.
What new topics were added?
Enterprise architecture and information security architecture, with more emphasis on security strategy and program development.
Did ISACA publish the new weights officially?
Yes. ISACA’s press release lists them. Older articles saying they were unpublished are out of date.
Does the CISM exam format change?
No. 150 questions, 4 hours, and a passing score of 450 on a 200 to 800 scale.
How much does CISM cost?
$575 for ISACA members or $760 for non-members, plus a $50 application fee after you pass.
Can I retake the old exam if I fail now?
Not if your first attempt is on October 4 or later. With a 30-day wait between attempts, a retake would fall on November 3 or after, when the new outline applies.
Will my current study material work for the new exam?
Only partly. ISACA states that buying current material does not grant access to the updated material later, and the new architecture content will not be fully covered.
Should I take CISM before or after November 3?
Before only if you are far into current materials and can pass the first time. Otherwise study for the updated outline and target January to March 2027.
How long does it take to prepare for CISM?
Training providers recommend about 150 to 200 hours over 3 to 6 months for most candidates. Experienced security managers may need 90 to 130 hours. These are estimates, not ISACA guidance.
What is the CISM pass rate?
ISACA does not publish one. Industry estimates put first-attempt pass rates between 50% and 65%.
What experience do I need?
Five years of information security work, with at least three in security management across three or more domains. Up to two years can be waived once through certain credentials or a relevant postgraduate degree. You can sit the exam first and document experience within five years after passing.
Do I need to retake CISM if I already hold it?
No. The change applies to new candidates. Holders keep the same 20 annual and 120 three-year CPE requirements.



