CRISC and CISM both come from ISACA, but they validate different parts of an organization’s risk and security function. CRISC (Certified in Risk and Information Systems Control) validates the ability to identify, assess, respond to, and monitor IT risk, requiring just 3 years of experience across 2 of its 4 domains, with no management experience required. CISM (Certified Information Security Manager) validates the ability to run an information security program at a leadership level, requiring 5 years of experience including at least 3 years in security management roles. CRISC says “I assess, score, and treat IT risk with rigor.” CISM says “I run the information security function.” Both cost the same ($575 for ISACA members, $760 for non-members), both pay similarly well ($120,000 to $160,000+), and many professionals eventually pursue both as part of a CRISC, then CISM, then CGEIT progression toward CISO or Chief Risk Officer roles.
This guide breaks down what each certification tests, the 2026 updates affecting both, and how to decide which to pursue first.
CRISC vs CISM: Quick Comparison
| Factor | CRISC | CISM |
| Full name | Certified in Risk and Information Systems Control | Certified Information Security Manager |
| Issuing body | ISACA | ISACA |
| Experience required | 3 years across at least 2 of 4 domains, within the past 10 years | 5 years in information security, including at least 3 years in security management (waivers permitted) |
| Management experience required | No | Yes, at least 3 years |
| Cost | $575 (member) / $760 (non-member) | $575 (member) / $760 (non-member) |
| Domains | 4 | 4 |
| Pass rate (estimated) | 60-70% | 50-60% |
| Validity | 3 years | 3 years |
| CPE requirement | 120 hours over 3 years, 20 minimum per year | 120 hours over 3 years, 20 minimum per year |
| 2026 update | 2025 update added AI/ML risk management to job practice areas | New exam content outline effective November 3, 2026 |
| Average salary (US) | $128,000-$151,000+ | $120,000-$160,000+ |
| Best suited for | Mid-career risk and control professionals, no management experience required | Established security leaders, those already in or targeting management roles |
What CRISC Covers
CRISC targets mid-career professionals who design and maintain IT risk frameworks, not those who want to learn risk management from scratch. What separates CRISC from CISSP or CISM is not breadth, it is focus: CRISC owns the specific territory where IT risk assessment meets executive communication and enterprise governance.
CRISC’s Four Domains
| Domain | Focus |
| IT Risk Identification | Identifying risk factors, threats, vulnerabilities, and their potential business impact |
| IT Risk Assessment | Analyzing and evaluating risk likelihood and impact, risk scenarios |
| Risk Response and Reporting | Developing risk response strategies, communicating risk to stakeholders and leadership |
| Information Technology and Security | Designing and implementing IT controls, monitoring control effectiveness |
The 2025 update added AI and machine learning risk management to CRISC’s job practice areas, keeping the credential current with what boards are actually asking their risk teams to address as organizations adopt AI tools at scale.
CRISC Experience Requirement
Candidates must accumulate at least 3 years of qualifying work experience in IT risk management and information systems control, spanning at least 2 of the 4 CRISC domains, within the 10 years preceding application. There are no substitutions, waivers, or education equivalencies for this requirement, unlike some other ISACA and ISC2 certifications.
Who CRISC Is For
Risk management professionals, governance and compliance specialists, and IT risk analysts who design, implement, and monitor IT risk frameworks. CRISC suits professionals who want to specialize in the technical and analytical side of risk, without necessarily holding or pursuing a formal management title.
What CISM Covers
CISM targets established information security managers rather than professionals just entering the field. The scenario-driven questions reward practical governance experience over textbook memorization, and CISM is most apt for those looking for leadership positions, compared to CISSP (technical), CISA (audit), and CRISC (risk management).
CISM’s Four Domains
| Domain | Focus |
| Information Security Governance | Establishing and maintaining a security governance framework aligned with business goals |
| Information Risk Management | Identifying and managing information risk to acceptable levels |
| Information Security Program Development and Management | Building and managing the resources and structure of a security program |
| Information Security Incident Management | Planning, establishing, and managing the capability to detect, respond to, and recover from security incidents |
ISACA has announced an updated CISM Exam Content Outline effective November 3, 2026. Candidates planning to sit for the exam after that date should verify the latest domain weights and content directly on ISACA’s official CISM exam outline page before finalizing study plans.
CISM Experience Requirement
CISM requires 5 years of experience in information security, including at least 3 years in security management or leadership roles, with waivers permitted for some of this requirement under specific ISACA conditions. This makes CISM better suited for professionals already in or very close to leadership positions, compared to CRISC’s lower barrier to entry.
Who CISM Is For
Information Security Managers, Security Program Managers, GRC Managers, and professionals on a CISO track. CISM targets people who already run, or are about to run, a security program or function, not people learning security management concepts for the first time.
CRISC vs CISM: The Practical Difference With an Example
Consider a scenario: an organization is rolling out a new third-party AI vendor across several business units.
CRISC knowledge addresses: What specific IT risks does this AI vendor introduce? How likely is each risk scenario (data exposure, model bias, vendor lock-in), and what is the potential business impact? What risk response strategy should be recommended: avoid, mitigate, transfer, or accept? How will the IT controls around this vendor relationship be monitored and reported to leadership on an ongoing basis?
CISM knowledge addresses: Does the organization’s security governance framework adequately cover third-party AI vendor relationships? What security program changes are needed to manage this risk class going forward? If an incident occurs involving this vendor, does the organization have an incident management capability that covers this scenario? How does this fit into the broader security strategy being reported to the board?
The two roles complement rather than duplicate. CRISC produces the detailed risk assessment and ongoing control monitoring. CISM ensures that risk assessment connects to a coherent governance framework and security program at the organizational level. Many organizations need both functions represented, whether by the same person growing into both skill sets over time, or by separate risk and security management functions working together.
CRISC vs CISM: Which Should You Pursue First?
| Your Situation | Recommended First Certification |
| You have 3+ years in IT risk and control work, but no formal management experience | CRISC |
| You have 5+ years in information security, including 3+ years in management | CISM |
| You want the lower barrier to entry to start building ISACA credentials now | CRISC |
| Your goal is specifically a CISO or security leadership track | CISM, since it directly targets that path |
| You want to specialize deeply in risk assessment and control design | CRISC |
| You already have CISA or CISM and want the next ISACA credential | CRISC, to build out a complete GRC profile |
| Your organization operates under DORA, GDPR, or similar regulatory risk mandates | CRISC, given its direct alignment with regulatory risk framework requirements |
If you already have 5+ years with management experience, starting with CISM is perfectly valid; you can add CRISC later to deepen your risk management expertise. The common career trajectory many ISACA-credentialed professionals follow is CRISC (risk management) toward CISM (security management) toward CGEIT (enterprise IT governance), positioning toward CISO, VP of Risk, or Chief Risk Officer roles. There is no universally correct starting point; the right one depends on whether your immediate career gap is risk-specific technical depth (CRISC) or security leadership credibility (CISM).
CRISC vs CISM: Difficulty Comparison
| Factor | CRISC | CISM |
| Estimated pass rate | 60-70% | 50-60% |
| Typical prep time | Approximately 3 weeks (varies with experience) | Approximately 2-3 weeks (varies with experience) |
| Why it’s harder/easier | Narrower focus on risk domains makes it more approachable for risk specialists | Broader scope covering governance, program management, and incident response requires a wider knowledge base |
CISM is generally considered slightly more difficult given its broader scope, though difficulty is ultimately subjective. Whichever certification aligns more closely with your existing experience will feel more approachable, regardless of the general pass rate statistics.
CRISC vs CISM: Salary Comparison
| Certification | Typical US Salary Range | Notes |
| CRISC | $128,000-$151,000+, senior risk managers and directors exceeding $160,000 in major markets | Salary premium driven partly by the widening gap between qualified risk professionals and available roles |
| CISM | $120,000-$160,000+ | Premium reflects leadership scope and direct line to CISO-track compensation |
Salary differences between CRISC and CISM are generally considered negligible; both command premium compensation in similar ranges depending on role, location, and experience. Neither certification has a meaningful salary edge over the other in isolation; the bigger driver is the seniority and scope of the role each credential supports.
CRISC vs CISM: Cost and Maintenance
| Cost Item | CRISC | CISM |
| Exam fee (ISACA member) | $575 | $575 |
| Exam fee (non-member) | $760 | $760 |
| Review manual (member / non-member) | $109 / $139 | $109 / $139 |
| Annual maintenance fee | $45 (first certification), $25 for a third ISACA certification | $45 (first certification), $25 for a third ISACA certification |
| CPE requirement | 120 hours over 3 years, minimum 20 per year | 120 hours over 3 years, minimum 20 per year |
An important detail for dual-credentialed professionals: ISACA’s CPE policy treats CRISC and CISM hours as non-transferable. CPE earned for one does not count toward the other, which is a real ongoing cost consideration if you plan to hold both long-term. On the positive side, both certifications share the same ISACA infrastructure, so one ISACA membership covers both, and holding a third ISACA certification (such as CISA) reduces that certification’s annual maintenance fee.
CRISC vs CISM: How They Fit With CISSP
Both CRISC and CISM are frequently discussed alongside CISSP, ISC2’s flagship credential, since all three address overlapping but distinct territory in security and risk leadership. For the complete comparison of how CISSP and CISM complement each other, including how they target different but related career outcomes, our CISSP vs CISM guide covers that decision in full detail. For professionals deciding between project leadership and security leadership credentials more broadly, our PMP vs CISSP guide covers that adjacent decision point.
FAQS
What is the difference between CRISC and CISM?
CRISC (Certified in Risk and Information Systems Control) validates IT risk identification, assessment, response, and monitoring skills, requiring 3 years of experience with no management experience needed. CISM (Certified Information Security Manager) validates security leadership and program management skills, requiring 5 years of experience including at least 3 years in management roles.
Which is easier, CRISC or CISM?
CRISC has an estimated pass rate of 60-70%, compared to CISM’s estimated 50-60%, and CISM’s broader scope across governance, program management, and incident response requires a wider knowledge base. However, difficulty is subjective: whichever certification aligns more closely with your existing background and experience will likely feel easier.
How much do CRISC and CISM cost?
Both cost the same: $575 for ISACA members and $760 for non-members. Both also share the same annual maintenance fee structure ($45 for a first ISACA certification) and the same 120-hour CPE requirement over a 3-year certification cycle.
Which pays more, CRISC or CISM?
Salary differences are negligible. CRISC holders typically earn $128,000-$151,000+, with senior risk directors exceeding $160,000. CISM holders typically earn $120,000-$160,000+. Both fall into a similar premium compensation range depending on role, industry, and location.
Should I get CRISC or CISM first?
If you have 3+ years of IT risk experience but no formal management background, start with CRISC, since it has the lower barrier to entry. If you already have 5+ years in information security including 3+ years in management, CISM is a valid starting point, especially if your goal is a CISO-track role. Many professionals eventually pursue both, often in a CRISC-then-CISM sequence.
What changed with CRISC and CISM in 2026?
CRISC’s 2025 update added AI and machine learning risk management to its job practice areas. CISM has an updated exam content outline effective November 3, 2026; candidates testing after that date should verify the latest domain weights directly on ISACA’s official CISM exam outline page.
Can CPE hours count toward both CRISC and CISM?
No. ISACA’s CPE policy treats CRISC and CISM hours as non-transferable. CPE earned toward maintaining one certification does not count toward the other, which is an ongoing cost and time consideration for professionals who hold both.
Do I need management experience for CRISC?
No. CRISC requires 3 years of qualifying work experience in IT risk management and information systems control across at least 2 of its 4 domains, but no specific management experience is required, unlike CISM’s requirement of at least 3 years in security management roles.
What career path follows after earning CRISC or CISM?
A common ISACA career trajectory is CRISC (risk management) leading to CISM (security management) leading to CGEIT (enterprise IT governance), positioning professionals for CISO, VP of Risk, or Chief Risk Officer roles. Holding both CRISC and CISM demonstrates end-to-end GRC (Governance, Risk, and Compliance) capability.
Is CRISC or CISM better for someone already considering CISSP?
CRISC and CISM complement CISSP rather than directly competing with it. CISSP and CISM in particular are often described as complementary, with CISSP demonstrating deep technical and administrative security skills and CISM demonstrating governance and leadership skills. CRISC adds a further specialization in risk assessment and control design that neither CISSP nor CISM covers as deeply on its own.



