Which exam?
CISSP vs CISM
Different bodies, different centres of gravity. CISSP is broad security knowledge from ISC2; CISM is security management and governance from ISACA. They overlap less than the acronyms suggest.
ISC2
CISSP: Certified Information Systems Security Professional
10 free questions
Choose this if you are a practitioner or moving into architecture. CISSP spans eight domains from cryptography to physical security, and it is the more common requirement in technical security roles.
Practise CISSPISACA
CISM: Certified Information Security Manager
10 free questions
Choose this if you are moving into or already in management. CISM is about running a security programme — governance, risk, incident management — and is weighted towards business alignment rather than technical depth.
Practise CISM
Our recommendation
Follow the job you want. CISSP for technical seniority, CISM for the management track. Holding both is common at CISO level and neither is a prerequisite for the other.
What each exam covers
CISSP: Certified Information Systems Security Professional
CISSP is the credential most often named in senior security job adverts, and the one whose difficulty is usually misunderstood: it is adaptive, so the exam adjusts to your answers and ends anywhere between 100 and 150 items within a three-hour window. The pass mark is 700 out of 1000 on a scaled score, and registration is $749 in the Americas. ISC2 requires five years of paid work across at least two of the eight domains — one year waivable with a relevant degree or approved credential — and you can sit the exam first, becoming an Associate of ISC2 with six years to earn the experience. Security and Risk Management is the largest domain at 16%. Candidates consistently report the hard part is not technical depth but answering as a manager rather than an engineer.
CISM: Certified Information Security Manager
CISM is ISACA's credential for the person accountable for a security programme, not the person operating it — which is why two-thirds of the marks sit in just two domains: Information Security Program 33% and Incident Management 30%, ahead of Risk Management 20% and Governance 17%. It is 150 multiple-choice questions in four hours, scored on a 200–800 scale with 450 to pass. Registration is $575 for ISACA members and $760 for non-members, plus a one-off $50 application fee. You can sit it before meeting the experience requirement: five years of security management within the preceding ten, across at least three domains, with up to two years waivable. Worth noting that ISACA updates the CISM exam content outline on 3 November 2026.
Common questions
- CISSP vs CISM — which is harder?
- Follow the job you want. CISSP for technical seniority, CISM for the management track. Holding both is common at CISO level and neither is a prerequisite for the other.
- Can I practise both CISSP: Certified Information Systems Security Professional and CISM: Certified Information Security Manager?
- Yes. Each opens with 10 free questions. A single exam is a one-time $19.99 for 30 days, and full access at $39.99 a month covers both and every other exam in the catalogue.
- Is there a timed practice test for each?
- Yes — 65 questions in 130 minutes on both, scored the moment you finish, so you can compare how ready you are for each before committing to one.
Practise both before you decide
10 free questions on each, no card and no account. Full access at $39.99 a month covers both and everything else.
