CISM exam guide

CISM exam format and domains in 2026

A current, source-led guide to the CISM exam: 150 questions, four hours, the four weighted domains, the 450 scaled passing score, and the official outline update taking effect on 3 November 2026.

The short answer

The current CISM exam has 150 multiple-choice questions and a four-hour time limit. It is divided across Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%) and Incident Management (30%). ISACA reports scores on a 200 to 800 scale, with 450 required to pass. This is a scaled score, not a percentage. Verify the current outline with ISACA before choosing study material or an exam date.

What is the CISM exam format in 2026?

CISM is a management-focused information-security certification. The exam tests whether you can make sound governance, risk, programme and incident-management decisions, rather than simply recall technical controls. ISACA currently states that candidates answer 150 multiple-choice questions in four hours.

Exam element Current official position What it means for candidates
Question count 150 multiple-choice questions. You need sustained decision-making accuracy, not just memorisation.
Time allowed Four hours. Build timed-question practice into your preparation rather than leaving it to the final week.
Score scale 200 to 800 scaled score. Do not translate a practice percentage directly into an ISACA result.
Passing score 450 or higher. Use domain-level review to find whether knowledge, judgement or time pressure is causing missed questions.
Delivery PSI test centre or remote proctoring where available. Confirm the route and technical requirements directly when you schedule.

An important 2026 timing point

ISACA has announced that its updated CISM Exam Content Outline takes effect on 3 November 2026, with updated preparation material expected in September 2026. If your exam is close to that date, do not assume one set of material fits both outlines. Check the official CISM certification page and confirm which outline applies to your scheduled exam.

CISM candidates reviewing the four CISM exam domains in a professional cybersecurity workshop
CISM rewards management judgement across governance, risk, programme delivery and incident-management decisions.

What are the four CISM domains and their weights?

The current outline gives the most weight to the Information Security Program domain, followed by Incident Management. Weighting is a planning tool, not permission to neglect the smaller domains: a weak governance or risk foundation can undermine decisions across the paper.

Domain Weight What the domain is really testing
Information Security Governance 17% How security strategy, policy, leadership, reporting, roles and accountability support organisational objectives.
Information Security Risk Management 20% How to identify, assess, treat, monitor and communicate information-security risk in business terms.
Information Security Program 33% How to build, resource, operate, measure and improve an information-security programme.
Incident Management 30% How to prepare for, respond to, recover from and learn from information-security incidents.

Governance and risk set the direction

These first two domains test whether you can connect security work to leadership priorities, risk appetite, policy, ownership and measurable business outcomes.

Programme and incident management test execution

Together they make up 63% of the current outline. Expect questions about prioritisation, programme performance, resources, third parties, communication and post-incident improvement.

How does CISM scoring work?

CISM does not use a simple percentage pass mark. ISACA converts candidate performance to a 200 to 800 scaled score; 450 is the passing score. ISACA’s scoring approach is designed to report performance consistently across exam forms. The practical lesson is simple: use mock results to identify patterns, but do not treat a raw practice score as an official conversion table.

Can you pass the CISM exam before you meet the experience requirement?

Passing the exam and receiving the CISM certification are separate steps. ISACA requires candidates to pass the exam, submit an application and meet its current certification requirements, including the professional experience requirement, before the certification is awarded. ISACA says candidates have up to five years from passing the exam to apply for certification. Review the current ISACA certification requirements directly, especially if you are considering an experience substitution or plan to sit the exam early.

Information security professional planning CISM study time around the 2026 exam outline
A useful CISM plan balances all four domains, then uses timed review to improve management-level judgement.

How should you build a CISM study plan?

Start with the official outline that applies to your intended exam date. Then build a plan that treats CISM as a management-decision exam, not a technical vocabulary test.

  1. Match your materials to your exam date. If your attempt is near the November 2026 transition, confirm the applicable outline first.
  2. Map strengths and gaps across all four domains. A governance professional may need more incident-response context; a technical security professional may need more work on executive decisions, programme metrics and risk communication.
  3. Practise the “best management action” mindset. Ask what a security manager should do first, who should own the decision, what business risk is being managed and how success would be measured.
  4. Add timed practice before the final stage. Four hours is generous only when question judgement and pacing are both under control.
  5. Use official documents as your final check. Requirements, delivery options, pricing and outlines can change. Before registering, confirm the current ISACA CISM registration and delivery information; provider pages should never replace it.

Choose the next question that matches your decision

This guide answers how the CISM exam works. If your immediate objective is information-systems audit, compare the role fit with CISA versus CISM. If you are deciding whether CISM fits your security-management direction, read when CISM certification may be worth it. For commercial preparation options, use the global CISM preparation page or the relevant country route below.

Need a structured CISM preparation route?

Use this guide to understand the official exam, then choose support that helps you practise management judgement, structure revision and verify your route with ISACA. EduDelphi offers guided CISM preparation for working professionals.

Explore CISM preparationSaudi Arabia delivery options

Frequently asked questions

How many questions are in the CISM exam?

The current CISM exam has 150 multiple-choice questions and candidates have four hours to complete it. Check the official ISACA outline when planning your attempt because ISACA has announced a content-outline update effective 3 November 2026.

What are the four CISM domains?

The current CISM outline is Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%).

What is the CISM passing score?

ISACA uses a scaled score from 200 to 800. A score of 450 or higher is required to pass. It is not a percentage score.

Does passing the CISM exam make me certified?

No. Passing the exam is one step. Candidates must also apply for certification and meet ISACA’s current experience and other requirements before certification is awarded.

What changes in the CISM exam on 3 November 2026?

ISACA states that an updated CISM Exam Content Outline takes effect on 3 November 2026. Updated preparation material is expected in September 2026. Candidates should use the current official outline to choose the right study material for their exam date.

Can I take CISM through remote proctoring?

ISACA states that CISM candidates may use a PSI test centre or remote proctoring where available. Availability and requirements should be verified when scheduling.

Official sources used for this guide

Kashif Akhtar, CISM technical reviewer

Technical reviewer

Kashif Akhtar

Qualified Engineer, CSCP, PMP, CISA, CISM, CRISC, CDPSE

Kashif reviews CISM preparation content through a management and governance lens, connecting security strategy, risk, controls, programme decisions and incident management to the stakeholder conversations candidates need to handle. This guide is educational. ISACA remains the final authority for eligibility, exam content, scheduling, pricing and certification requirements.

Share this article:

Leave a Reply

Your email address will not be published. Required fields are marked *