CISA and CISM both come from ISACA, both are senior credentials, and both ask for around five years of experience. The split is about role, not level. Choose CISA if you audit and assess IT systems and controls; choose CISM if you manage and govern an information security programme. One is the auditor's credential, the other the security manager's.

What each one covers

CISA (Certified Information Systems Auditor) is built around five domains: the Information Systems Auditing Process, Governance and Management of IT, Information Systems Acquisition, Development and Implementation, Information Systems Operations and Business Resilience, and Protection of Information Assets. The focus is applying a risk-based approach to audit engagements.

CISM (Certified Information Security Manager) is built around four domains: Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management. The focus is building and running a security programme, not auditing one.

If you are earlier in your security journey, get the fundamentals first. Our comparison of ISC2 CC and CompTIA Security+ covers the entry step, and CISSP vs CISM is worth reading if you are also weighing a technical breadth credential.

The exams

Both are fixed-form exams. Confirm the current figures on ISACA's pages, but as they stand each is 150 questions across four hours, scored on a scaled 200 to 800 range with 450 to pass, per ISACA. Check the live details on the ISACA CISA page and the ISACA CISM page.

A 2026 change that affects CISM, not CISA

ISACA has confirmed that the CISM Exam Content Outline will be updated with effect from 3 November 2026, with the exam following the new outline from that date and updated preparation material on sale from September 2026. CISA's outline is not flagged for the same change. So if you are choosing between them for a sitting near that window, CISM candidates should decide deliberately: study and sit against the current outline before 3 November, or prepare against the new one after it, and not mix the two.

The experience requirement

Both let you sit the exam first and satisfy the experience afterwards, and both accept certain substitutions, so check the current rules on ISACA's site.

  • CISA asks for five years of professional information systems auditing, control or security work experience, with defined waivers that can reduce the requirement.
  • CISM asks for five years of information security work experience, with at least three years in security management across the relevant domains, again with some substitutions available.

Both certifications are then maintained through continuing professional education and an annual maintenance fee, so factor in the ongoing commitment.

How to choose

Go for CISA if your role is, or is heading towards, IT audit, assurance, risk or compliance, or if you work with or inside audit functions and want the credential that names that work directly. Go for CISM if you lead or want to lead security: setting strategy, managing risk, running the programme and owning incident response. Some professionals hold both, using CISA to prove audit rigour and CISM to prove management capability, which is a strong pairing for governance and risk leadership roles.

Practise under real exam conditions

Both exams are long, scenario-driven and scored across several domains, and the usual failure mode is pacing and second-guessing rather than a single knowledge gap. Full, timed mock exams rehearse that. On CandidatesPrep you can sit complete simulations scored by domain, so you can see whether it is governance, risk, audit process or incident management dragging your score, and repeat until every domain is solid. Trainers preparing audit or security teams can track a whole cohort's domain performance in one place.

Exam-day tactics

  • Read each scenario for the role it assumes: CISA questions think like an auditor, CISM questions like a manager.
  • Manage the four-hour clock; do not sink time into one dense item.
  • Answer every question, since an unanswered one scores nothing.

The bottom line

CISA and CISM are two roles, not two rungs. Pick CISA to prove you can audit and assess IT systems, and CISM to prove you can lead a security programme. Match the credential to where your career is going, confirm the latest exam figures on ISACA's site, and if CISM is your choice, plan around the 3 November 2026 outline change.

Want to gauge your readiness before you book? Sit a full timed simulation, or book a demo if you prepare audit or security teams.