Exampractice
Careers & Salaries

What Certification Should You Take After CISM?

Governance, risk, cloud or the CISO track — how security managers holding CISM should choose their next certification, with 2026 costs and prerequisites.

Elena Rossi · 7 min read
Compass with points labelled governance, risk, cloud and AI representing certification directions after CISM

The Certified Information Security Manager (CISM) credential was probably the last certification you needed — it is the recognised proof that you can run a security programme. So the question after CISM is not "what completes my CV?" but "what does my next role require that my current one does not?" Answered that way, the field narrows fast, because each realistic next credential maps to one specific expansion of a security manager's remit.

Short answer: heading for CISO or board-level oversight, add CGEIT for enterprise IT governance. Owning risk beyond the security function, add CRISC. Leading a cloud-first security programme, add CCSP. Positioning for AI security governance, add AAISM — which lists an active CISM as a qualifying prerequisite. Wanting deeper technical credibility alongside your management standing, CISSP is the practitioner-side complement. None of these is "the" answer; each is the answer to a different next role.

Below, each track gets the same treatment: what it certifies, what it costs as of 2026, what it demands, and the manager it suits.

The governance track: CGEIT

What it certifies. Certified in the Governance of Enterprise IT (CGEIT), from ISACA, moves you from governing security to governing IT's whole contribution to the enterprise — investment, benefits, risk optimisation. Its domains tell the story: Governance of Enterprise IT (40%), IT Resources (15%), Benefits Realization (26%) and Risk Optimization (19%). Nothing in that list is about firewalls; all of it is about the conversations a CISO has with the board.

Cost and format (2026). Like CISM: 150 multiple-choice questions, 4 hours, 450 on the 200–800 scale to pass; US$575 for ISACA members, US$760 for non-members, plus a US$50 application fee after passing. Fees are in USD — confirm current figures on isaca.org.

The catch. Certification requires 5 or more years in an advisory or oversight role supporting enterprise IT governance, with no experience waivers or substitutions at all. Security management experience counts only insofar as it genuinely involved enterprise-level governance work — read ISACA's experience definitions before you register, not after.

Best for the security manager whose next role is CISO in a large organisation, or a governance advisory position, and who already sits on (or reports into) governance forums.

The risk track: CRISC

What it certifies. Certified in Risk and Information Systems Control (CRISC) formalises enterprise IT risk management — the discipline your CISM's risk domain touched but did not centre. Domains: Governance (26%), Risk Assessment (22%), Risk Response and Reporting (32%), Technology and Security (20%).

Cost and format (2026). Identical mechanics to CISM and CGEIT: 150 questions, 4 hours, 450/800, US$575/US$760 plus US$50 application fee.

The catch. Three or more years of experience in IT risk management and IS control, with no waivers. For most CISM holders the practical overlap is real — Information Security Risk Management is 20% of the CISM outline you already passed — but ISACA assesses the experience, not the adjacent credential.

Best for managers whose organisations are consolidating security under a broader risk function, or who want the second-line risk-officer route towards chief risk roles. Because both certifications live in ISACA's ecosystem, your CPE machinery — a minimum of 20 CPE hours annually and 120 per 3-year cycle — already fits.

If you came to CISM from an audit background, note that the audit-side progression is a different map with different options; we chart it separately in what to take after CISA.

The cloud track: CCSP

What it certifies. ISC2's Certified Cloud Security Professional (CCSP) covers the security of cloud architecture, data, platforms, applications, operations and compliance — six domains, with Cloud Data Security the heaviest at 20%. For a security manager, its value is less about console skills and more about credibly directing a programme whose estate now lives in other people's data centres.

Cost and format (2026). US$599 in the Americas, varying by region. Since 1 October 2025 the exam is Computerized Adaptive Testing: 100–150 items, maximum 3 hours, and you cannot return to a previous question — a genuinely different sitting experience from ISACA's linear 4-hour papers, so build timed adaptive-style practice into your preparation rather than relying on the pacing habits CISM taught you. Working through the CCSP practice questions on ExamPractice under a timer is a sensible benchmark before you book; the free samples show the question style, and subscribers get full sets plus a simulation mode.

The catch. CCSP requires 5 years of cumulative IT experience including 3 in information security and 1 in a CCSP domain. Most working CISM holders clear this comfortably (an active CISSP satisfies it outright), and ISC2's Associate pathway exists if you fall short. Budget for ISC2's separate maintenance system too: a 3-year cycle with 90 CPEs and a US$135 annual fee, alongside your ISACA obligations.

Best for security managers in organisations mid-migration, and anyone whose board asks cloud questions their current credentials do not answer. On the pay evidence, Skillsoft's 2025 data put CCSP holders at an average of US$171,524 in the US — a holder average driven by seniority and location, quoted here as context rather than promise.

The AI track: AAISM

ISACA's Advanced in AI Security Management (AAISM), launched in 2025 and billed by ISACA as the first AI security management certification, is the newest door your CISM opens — its official prerequisite is an active CISM or CISSP. It covers AI governance and programme management, AI risk management, and AI technologies and controls, and costs US$459 for members / US$599 for non-members plus the US$50 application fee, cheaper than ISACA's core certifications. ISACA had not published full exam-format details on its main page as of August 2026, so verify the candidate guide before scheduling.

The demand signal is hard to ignore: ISACA's 2025 research found 85% of digital trust professionals expecting to need greater AI skills within two years. AAISM is a low-cost, prerequisite-gated way to be early to a discipline your peers will be studying in three years — with the usual early-mover caveat that a 2025-vintage credential has less market recognition today than the established names above.

What about CISSP?

CISSP deserves a paragraph, not a section, because it expands you in a different dimension: it is ISC2's broad practitioner credential — eight domains, Computerized Adaptive Testing at 100–150 questions in up to 3 hours, US$749 in the Americas as of 2026, and a requirement of 5 years' experience across at least two domains (with a one-year waiver available and an Associate route if needed). Managers add it when their authority with engineers depends on demonstrated technical breadth, or when target employers list it by name; if you are weighing that pairing seriously, the CISSP practice questions will show you quickly how much technical depth the exam expects. How CISM and CISSP compare as credentials — overlap, market perception, which to hold first — is a separate comparison we keep out of this article's scope; the full trajectory around CISSP is mapped in our CISSP career path guide.

Choosing: match the certification to the sentence in your next job advert

A quick self-test that resolves most cases. Find the job advert for the role you want in two to three years and look for its load-bearing requirement:

  • "Reports to the board / owns technology governance" → CGEIT
  • "Owns enterprise technology risk" → CRISC
  • "Leads security for our cloud transformation" → CCSP
  • "Establishes our AI governance and security programme" → AAISM
  • "Hands-on credibility across security architecture and operations" → CISSP

Three common mistakes to avoid while deciding. First, collecting a second management-flavoured credential for comfort rather than direction — CISM already covers that ground, and employers notice redundancy. Second, registering before checking experience rules: CGEIT and CRISC allow no waivers, and an ineligible application costs time you could have spent on the right exam. Third, ignoring the calendar you already run: every option above lands inside a CPE regime you are maintaining anyway, so a well-timed exam preparation cycle can feed the 120-hour ISACA cycle instead of competing with it. If you want to survey the wider field before committing, the certification exams directory lists practice resources across providers, and our guide to certifications for IT managers covers the service-management and leadership credentials outside the security lane.

Frequently asked questions

Can I sit the CGEIT or CRISC exam before I have the required experience?

Yes. ISACA lets you sit any core exam with no prerequisites and apply for certification within 5 years of passing — but with no waivers on these two, be realistic about when the experience will actually exist.

Do I have to keep paying ISACA for both CISM and a second ISACA certification?

ISACA's maintenance model applies annual fees and CPE requirements to its certifications — verified figures on the CISA maintenance page are US$45 for members and US$85 for non-members annually — but confirm the per-certification totals for your combination on isaca.org before budgeting.

Is AAISM worth it before the market recognises it?

If your organisation is standing up AI governance now, yes — the credential's content is immediately usable and the cost is comparatively low. If you need maximum name recognition for a job search this year, the established tracks carry more weight today.

Does the CISM exam update on 3 November 2026 affect any of this?

Only if colleagues you advise are still pursuing CISM — exams taken from that date follow ISACA's new content outline. Your existing certification is unaffected; it is maintained through CPE, not re-examination.

The manager's next move

Your CISM answered "can this person run a security programme?" The next certification answers a sharper question: "what bigger thing can they run?" Choose the track whose answer matches a role that genuinely exists above you — then let the study plan follow the job, never the other way round.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like