Exampractice
Cybersecurity

CRISC vs CISM: Which Should You Choose?

CRISC and CISM compared on focus, domains, difficulty, experience rules and career direction — with a decision framework for choosing between them.

Alexander Novak · 7 min read
Fork in a path with signs pointing to an IT risk track and a security management track

Short answer: choose Certified in Risk and Information Systems Control (CRISC) if your career is heading towards IT risk — assessing, treating and reporting risk across the whole enterprise. Choose Certified Information Security Manager (CISM) if it's heading towards running an information security function — owning the security programme, its people and its incident response. Both are ISACA certifications, both are management-level, and both cost the same to sit, so the deciding factor is not the exam. It's which job you want in five years.

That's the headline; the rest of this article earns it. The two credentials overlap just enough — CISM has an entire risk-management domain, CRISC treats security as one of its four domains — that plenty of capable people stall on the choice. Below is what actually differs, what genuinely doesn't, and a decision framework built around reader situations rather than a universal winner. This piece stays inside the ISACA family; if you're weighing either cert against non-ISACA options, that's a different question for a different article.

The core difference in one paragraph

CRISC certifies risk practice: identifying IT risk, assessing it, choosing responses, designing controls and reporting to governance bodies. Its holder is the person a business turns to when it asks "what could hurt us, how badly, and what should we do about it?" — and the answer might concern security, but equally availability, projects, third parties or compliance. CISM certifies security management: governing an information security programme, managing its risks, building and running the programme, and handling incidents. Its holder is accountable for the security function itself. Risk is CRISC's whole job and one of CISM's four domains; security is CISM's whole job and one of CRISC's four domains. That asymmetry is the entire decision.

CRISC vs CISM at a glance

As of 2026, both exams share ISACA's common machinery — the differences live in content and experience rules. Fees change, so confirm current figures on isaca.org.

FactorCRISCCISM
FocusEnterprise IT risk management and IS controlManaging an information security programme
DomainsGovernance (26%); Risk Assessment (22%); Risk Response and Reporting (32%); Technology and Security (20%)Information Security Governance (17%); Information Security Risk Management (20%); Information Security Program (33%); Incident Management (30%) — current outline; changes 3 Nov 2026
Exam format150 multiple-choice questions, 4 hours, pass at 450/800150 multiple-choice questions, 4 hours, pass at 450/800
CostUS$575 member / US$760 non-member + US$50 application feeUS$575 member / US$760 non-member + US$50 application fee
Difficulty characterScenario judgement in risk-lifecycle termsScenario judgement from an executive security-manager's seat
Experience for certification3+ years in IT risk management and IS control; no waivers5+ years in information security management; waivers up to 2 years
Best forRisk analysts, control specialists, GRC consultants, aspiring risk managersSecurity team leads, security managers, aspiring CISOs
Typical career directionHead of IT risk, enterprise risk rolesHead of information security, CISO track
Renewal20 CPE/year, 120 CPE per 3-year cycle, annual maintenance fee20 CPE/year, 120 CPE per 3-year cycle, annual maintenance fee

Note the experience asymmetry, because it surprises people in both directions: CRISC asks for fewer years (three) but allows no waivers or substitutions at all, while CISM asks for five years but will waive up to two. Neither stops you sitting the exam — ISACA lets anyone take either exam and gives you five years after passing to apply for certification.

Is CRISC or CISM harder?

Neither is reliably harder; they are hard in the same way for different people. Both exams pose workplace scenarios with four defensible answers and ask which is best or comes first, and both punish candidates who answer from a technician's chair. ISACA publishes no pass rates for either, so ignore any percentage you see quoted.

The honest difficulty question is about fit with your experience. A security engineer usually finds CISM's subject matter familiar but its perspective alien — the exam wants the answer a manager accountable to the board would give, not the strongest technical fix. The same engineer approaching CRISC faces the reverse problem: comfortable perspective-taking about controls, but an unfamiliar formal vocabulary of risk appetite, residual risk and key risk indicators that must be learned precisely. A GRC or audit-side candidate typically experiences both exams the other way round. In short: the exam that's harder for you is the one further from your daily work, which is often precisely the one worth doing. The judgement-heavy question style itself is dissected in how hard the CISM exam is, and CRISC's version in how hard the CRISC exam is.

One timing fact matters for CISM specifically: ISACA has announced that the CISM exam content outline changes on 3 November 2026, with candidates testing before that date sitting the current outline shown in the table above. If CISM is your pick and you're mid-preparation, that date should shape your booking; check isaca.org for the updated outline details before buying materials.

What about salary?

Both credentials sit at well-paid, senior levels of the market, and the difference in pay between them is driven far more by role, sector, location and seniority than by which acronym follows your name. We deliberately don't quote figures here, because a single number stripped of geography and job title misleads more than it informs — the dedicated CISM salary guide and CRISC salary guide break down pay properly by role, region and experience.

A decision framework: which fits your situation?

Work through these profiles and take the one that reads like your CV.

You work in security operations and want to lead the function

CISM. Your subject-matter foundation is already there; what the credential certifies — and what the exam trains — is the shift from doing security to governing it. CRISC would broaden you, but it points away from the security-leadership ladder you're climbing. Start with the CISM certification guide for the mechanics.

You work in GRC, audit or compliance and enjoy the risk side most

CRISC. Your day job already produces exactly the experience CRISC's certification requirement demands — and demands without waivers. The credential formalises a risk specialism that reaches beyond security into everything the business worries about, which is where GRC careers grow.

You're a risk analyst whose remit keeps drifting into security decisions

Take CRISC first, then reassess. It matches your current experience (so you can certify, not just pass) and deepens your core discipline. If your role keeps drifting until you're effectively running security controls, CISM becomes a natural second credential rather than a speculative first one.

You're an IT manager with a generalist background, aiming upward

Decide by destination, not by exam. If the upward path in your organisation runs through owning security — CISM. If it runs through enterprise risk, vendor risk or a head-of-risk seat — CRISC. If you genuinely can't say, note that CRISC's three-year experience bar is nearer than CISM's five (with the caveat that only CISM offers waivers), and that a risk grounding transfers into security management more gracefully than the reverse.

You're early-career with neither three nor five years of relevant experience

You may sit either exam today and bank the pass for up to five years while you accrue experience. In that position, pick by the job you're steering towards rather than the exam you'd pass more easily — a banked pass in the wrong discipline is a decoration. It's also worth pausing on whether a management-level ISACA cert is the right move at all yet; the wider portfolio, including more junior-friendly entry points, is mapped in ISACA certifications explained.

Should you eventually hold both?

Plenty of senior people do, because mature security leadership is substantially risk management and mature IT risk practice is substantially about security. The combination is coherent rather than redundant: one credential says you can run the security function, the other that you can run the risk process that tells the business whether the function is enough. There is no ordering rule from ISACA — sequence them by which certification requirement your experience satisfies first. What almost never makes sense is preparing for both simultaneously; the exams' vocabularies are close enough to blur and different enough to interfere.

Whichever you pick, the preparation playbook is the same shape: official ISACA materials for vocabulary, scenario practice questions for judgement, timed simulations for pacing. ExamPractice hosts free sample questions for both — CRISC practice questions and CISM practice questions — with fuller question sets and timed simulation for subscribers; a cold attempt at each sample set is a surprisingly effective tiebreaker, because the exam whose questions you enjoy arguing with is usually the right one.

Making the call

Strip away the shared machinery — same provider, same fee, same format, same renewal treadmill — and the choice reduces to a single honest question: when something goes wrong at work, do you want to be the person who owns the security response, or the person who owns the risk picture? CISM certifies the first identity, CRISC the second. Choose the credential that matches the job you're building towards, book it inside your six-month eligibility window so the decision has a deadline, and let the sibling guides above carry you into preparation. Committed to the risk track already? Go straight to how to prepare for CRISC; its CISM counterpart is how to prepare for the CISM exam.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like