CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingCISA and CISM compared on role focus, domains, difficulty, cost and career direction — plus who should take which, and whether holding both makes sense.

A common misconception sends people down the wrong ISACA track: that the Certified Information Security Manager (CISM) is somehow "level two" of the Certified Information Systems Auditor (CISA). It is not. These are parallel credentials aimed at different jobs — CISA certifies the person who examines an organisation's systems and controls; CISM certifies the person who runs its information security programme. Neither is a stepping stone to the other, and choosing between them is really a choice about which chair you want to sit in.
Short answer: choose CISA if your work (or intended work) is IT audit, assurance, or control testing — reviewing what others have built and reporting on it. Choose CISM if you are heading towards managing a security function — setting strategy, owning risk decisions, leading incident response. Neither is universally "better"; they lead to different desks.
Both credentials come from ISACA, both use the same exam machinery, and both are respected. That surface similarity is exactly why the decision needs a closer look at what each one actually tests and where it takes you.
Mechanically, the two exams are near twins. As of 2026, each is 150 multiple-choice questions in 4 hours, scored on a 200–800 scale with 450 to pass, delivered year-round at PSI test centres or by remote proctoring, and priced at US$575 for ISACA members or US$760 for non-members, plus a US$50 application fee after you pass. Registration gives you a six-month eligibility window, and the retake rules (up to four attempts in a rolling 12 months, with 30- and 90-day waits) are identical too.
The content is where they diverge completely.
CISA's five domains (2024 exam content outline, effective August 2024): Information Systems Auditing Process (18%), Governance and Management of IT (18%), Information Systems Acquisition, Development and Implementation (12%), Information Systems Operations and Business Resilience (26%), and Protection of Information Assets (26%). The through-line is evidence and assurance: how to plan an audit, gather and evaluate evidence, and judge whether controls actually work.
CISM's four domains (current outline): Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%). The through-line is ownership: building and running the security programme those auditors will later examine.
One timing note that matters if you are leaning CISM: ISACA has announced that the CISM exam content outline changes on 3 November 2026. Candidates testing before that date sit the current outline; ISACA had not published the new domain weights as of August 2026, so check the official CISM page before committing to study materials. CISA's outline, refreshed in 2024, has no announced change pending.
| Factor | CISA | CISM |
|---|---|---|
| Role focus | IT audit, assurance, control testing | Information security management and strategy |
| Domains | 5 (audit process, governance, acquisition/development, operations/resilience, information asset protection) | 4 (governance, risk management, security programme, incident management) |
| Exam | 150 MCQs, 4 hours, 450/800 to pass | 150 MCQs, 4 hours, 450/800 to pass (outline changes 3 Nov 2026) |
| Cost (2026) | US$575 member / US$760 non-member + US$50 application fee | Same |
| Experience for certification | 5 years IS audit/control/assurance/security; waivers up to 3 years | 5 years information security management; waivers up to 2 years |
| Difficulty character | Breadth across technology plus the audit mindset | Management judgement — choosing what the manager should do |
| Best for | Auditors, assurance and compliance professionals, control testers | Security leads, aspiring CISOs, programme and incident managers |
| Typical career direction | IT auditor → senior/lead auditor → audit management | Security analyst/engineer → security manager → head of security/CISO |
| Renewal | 20 CPE/year, 120 CPE per 3-year cycle, annual maintenance fee | Same CPE structure (confirm current fees on ISACA's CISM page) |
Neither certification requires experience to sit the exam — you can register with none and take it tomorrow, in effect, since scheduling opens 48 hours after payment. Experience is required to become certified afterwards, and you get five years from your pass date to apply.
CISA asks for a minimum of five years of professional experience in IS/IT audit, control, assurance or security, with waivers and substitutions available for up to three years. CISM asks for five or more years in information security management, with waivers capped at two years. In practice this makes CISM the harder credential to complete early in a career: genuine management experience is simply rarer at year three than audit fieldwork is. Plenty of ambitious candidates pass the CISM exam young and bank the pass while their experience accrues — legitimate, and explicitly allowed for by the five-year application window.
Full eligibility mechanics, application steps and costs for each live in the CISA Certification Guide and the CISM Certification Guide.
Neither exam publishes a pass rate — ISACA releases none, so ignore any percentage you see quoted — and both use the same scaled 450/800 bar, so "harder" is really about fit.
Candidates with hands-on technical backgrounds generally find CISA more approachable: two of its heaviest domains (operations and resilience, protection of information assets) reward technology fluency, and the audit mindset can be learned. The same candidates often find CISM slippery, because CISM questions routinely present four technically correct actions and ask which the manager should take first — a judgement style that punishes engineer instincts like "fix it yourself immediately".
Conversely, people who already operate at governance level — writing policy, briefing executives, owning budgets — often find CISM the more natural read and CISA's technical breadth the steeper climb. Deeper treatments of each exam's difficulty live in How Hard Is the CISA Exam? and How Hard Is the CISM Exam?.
ISACA's own CISA page cites a "US$149K+ average annual salary" for CISA holders (ISACA's figure, as of August 2026), and Skillsoft's IT Skills and Salary research has placed CISM among the top-paying certifications, with 2025 coverage citing a US average around US$155K — verify the current figure on Skillsoft's site before relying on it. Treat both numbers as directional, not promises: pay varies enormously by country, industry, seniority and role, and CISM figures skew higher partly because management roles pay more than the audit roles CISA maps to — the certification is not the cause. Detailed breakdowns by role and region belong to the CISA Salary Guide and CISM Salary Guide.
Two worked examples. A financial-services internal auditor with four years of fieldwork who keeps getting pulled onto IT audits is a textbook CISA candidate — the credential formalises the direction her work has already taken. A senior security engineer who has started running incident bridges and wants the security-manager vacancy opening next year is a textbook CISM candidate, even though he could probably pass CISA too.
If your fork is actually between risk work and security management rather than audit, that is a different comparison — see CRISC vs CISM: Which Should You Choose?.
Yes — ISACA imposes no rule against holding or pursuing both, and with continuous year-round registration you could sit them weeks apart. Whether you should is another matter. Each costs US$575–760 plus its own application fee and its own ongoing CPE and maintenance obligations, and their content overlap is thinner than people expect: shared governance and risk vocabulary, but different domains, different question styles, and different "correct" instincts (the auditor recommends; the manager decides).
The combination genuinely earns its keep in roles that straddle both worlds — audit managers who liaise with security leadership, consultants who both assess and advise, or auditors deliberately pivoting into security management. For most people, the better sequence is: certify in the track matching your current role, work for a year or two, and add the second credential when your career actually turns. Back-to-back exam campaigns mostly produce fatigue and duplicated fees, not doubled value. Whether the second cert justifies its cost at all is the sort of question we weigh in Is CISA Worth It? and Is CISM Worth It?.
Sequence follows career stage, not exam logic. Early in a career, CISA usually comes first for a mundane reason: audit, assurance and control-testing experience is easier to accumulate — and easier to evidence — than management experience, and CISA's waiver allowance is more generous (three years against CISM's two). An auditor can realistically be fully certified at CISA by year three or four, then add CISM once genuine programme-management responsibility arrives.
The reverse order suits people who arrive at ISACA from operational security. A security team lead with six years of hands-on and supervisory experience already has CISM-shaped evidence; CISA would mean building an audit narrative from scratch. For that person, CISM first, and CISA later only if their work turns towards assessments and assurance reviews.
Whichever order you choose, remember the credentials compound administratively as well as professionally: each carries its own CPE ledger (20 hours per year and 120 per three-year cycle each, under ISACA's CPE structure) and its own maintenance fee. Holding both is common among audit and security leaders; acquiring both within a single year is rarely the efficient route.
There is also a forward-looking wrinkle worth knowing before you sequence anything: ISACA now builds advanced credentials on top of these two. Its Advanced in AI Audit (AAIA) certification requires an active qualifying credential — all CISA holders qualify — while the Advanced in AI Security Management (AAISM) certification requires an active CISM or CISSP. If AI audit or AI security management is where you expect your field to move, the base credential you pick today also determines which of ISACA's AI tracks opens to you tomorrow.
Do I need work experience before sitting either exam?
No. Both exams can be taken with no experience at all — registration is open to anyone, and you can schedule as soon as 48 hours after paying. Experience requirements apply only at the certification-application stage, and you have five years from passing to meet them.
Can I take the exams from home?
Yes. Both CISA and CISM are delivered at PSI test centres or via online remote proctoring, with continuous year-round registration and appointments bookable up to 90 days ahead.
What happens if I fail one of them?
The retake rules are identical: up to four attempts within a rolling 12-month period, with a 30-day wait after the first attempt and 90-day waits after the second and third. Each attempt costs the full registration fee, so a genuine readiness check before booking is worth more than an optimistic date.
Does ISACA membership make sense if I am only taking one exam?
The member price saves US$185 on either exam, which typically goes a long way towards a year of membership — but dues vary by chapter, so compare the current membership cost on isaca.org against the discount before joining.
When do I get my result?
Both exams show a preliminary pass/fail on screen immediately, with the official score released online and by email within ten working days.
Preparation for both rewards the same discipline: learn the official outline, then pressure-test yourself with realistic questions under time constraints, because both exams hinge on picking ISACA's best answer among plausible ones. Timed practice is where that calibration happens — ExamPractice has free sample questions for both the CISA exam and the CISM exam, with full question sets and timed simulation for subscribers. Analyse your results by domain and let weak domains direct your revision rather than re-reading what you already know. (If you choose CISM, make sure your practice materials state which content outline they cover, given the November 2026 switchover.)
Stop asking which certification is better and ask which job is yours. CISA belongs to the examiner — the person organisations trust to look at systems independently and say what is actually true about their controls. CISM belongs to the owner — the person accountable for the security programme those examinations will judge. Pick the credential for the chair you intend to occupy in three years, sequence the other one later if your path genuinely crosses into its territory, and put your study hours into the exam that your next promotion will actually cite.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading