Which exam?
CISM vs CISA
Both ISACA, both five years of experience, and frequently confused. CISM is for the person running security; CISA is for the person checking that it works.
ISACA
CISM: Certified Information Security Manager
10 free questions
Choose this if you own the security programme — strategy, risk, incident response, reporting to a board. CISM assumes you are accountable for outcomes rather than for evidence.
Practise CISMISACA
CISA: Certified Information Systems Auditor
10 free questions
Choose this if you audit. CISA is the standard credential for IS audit and assurance work and is frequently a hard requirement in internal audit and Big Four roles rather than a preference.
Practise CISA
Our recommendation
These are career choices, not difficulty tiers. Audit hires ask for CISA by name; security leadership hires ask for CISM. Pick the one your target job advert names.
What each exam covers
CISM: Certified Information Security Manager
CISM is ISACA's credential for the person accountable for a security programme, not the person operating it — which is why two-thirds of the marks sit in just two domains: Information Security Program 33% and Incident Management 30%, ahead of Risk Management 20% and Governance 17%. It is 150 multiple-choice questions in four hours, scored on a 200–800 scale with 450 to pass. Registration is $575 for ISACA members and $760 for non-members, plus a one-off $50 application fee. You can sit it before meeting the experience requirement: five years of security management within the preceding ten, across at least three domains, with up to two years waivable. Worth noting that ISACA updates the CISM exam content outline on 3 November 2026.
CISA: Certified Information Systems Auditor
CISA is the auditing counterpart to CISM and the standard credential for IS audit, control and assurance work. It is 150 multiple-choice questions in four hours, scored 200–800 with 450 to pass — the same format and scoring as CISM, at $575 for ISACA members and $760 for non-members plus a one-off $50 application fee. The weighting is flatter than most security exams: Operations and Business Resilience 26% and Protection of Information Assets 26% lead, then the Auditing Process 18% and Governance 18%, with Acquisition and Development 12%. ISACA asks for five years of relevant experience earned within the preceding ten, with up to three years waivable, and gives you five years from passing to apply.
Common questions
- CISM vs CISA — which is harder?
- These are career choices, not difficulty tiers. Audit hires ask for CISA by name; security leadership hires ask for CISM. Pick the one your target job advert names.
- Can I practise both CISM: Certified Information Security Manager and CISA: Certified Information Systems Auditor?
- Yes. Each opens with 10 free questions. A single exam is a one-time $19.99 for 30 days, and full access at $39.99 a month covers both and every other exam in the catalogue.
- Is there a timed practice test for each?
- Yes — 65 questions in 130 minutes on both, scored the moment you finish, so you can compare how ready you are for each before committing to one.
Practise both before you decide
10 free questions on each, no card and no account. Full access at $39.99 a month covers both and everything else.
