CISM vs CISA: Which Should You Get First?
- #CISM
- #CISA
- #Certification Comparison
- #ISACA
Part of our CISSP or CISM First? A Decision Guide series on sequencing ISACA and ISC2 certifications.
“CISM or CISA, which one first” comes up constantly among security and audit professionals, and like the CISSP-vs-CISM question, I think it’s usually framed wrong. These aren’t two rungs on the same ladder ranked by prestige or difficulty — they credential two different functions. CISM validates that you can run and govern a security program. CISA validates that you can independently audit and assess information systems, controls, and governance. The right first move depends on which of those two jobs your career is actually pointed toward.
CISM vs CISA: Core Differences
CISM (Certified Information Security Manager), issued by ISACA, is built around four job practice domains as of this writing: information security governance, information security risk management, information security program, and incident management1. It’s oriented toward building and leading a security function — setting strategy, running a program, managing organizational risk, and reporting to executives and the board. Note that ISACA has announced an updated CISM Exam Content Outline effective November 3, 2026, which adds enterprise architecture and information security architecture as new content areas and reweights the existing domains2 — if you’re planning to sit for the exam on or after that date, confirm you’re studying against the updated outline rather than the one described here.
CISA (Certified Information Systems Auditor), also issued by ISACA, is built around five job practice domains: the information systems auditing process (18%), governance and management of IT (18%), information systems acquisition, development and implementation (12%), information systems operations and business resilience (26%), and protection of information assets (26%)3. It’s oriented toward independently evaluating systems and controls rather than building or running them — CISA credentials the auditor’s perspective: can you assess whether a control environment is actually working, and report that assessment credibly to stakeholders who rely on your independence.
The practical framing: CISM asks “can you own and run a security program,” CISA asks “can you independently verify that an organization’s systems and controls are sound.” A security manager and an IT auditor are both legitimate, senior security-adjacent careers, but they involve fundamentally different relationships to the systems they’re evaluated on — one builds and defends them, the other examines them from outside the reporting line that built them.
Which Fits Your Current Role (Management vs Audit)
Rather than treating this as a prestige ranking, match the credential to what you actually do day to day.
CISM fits you if:
- You’re setting security strategy, running a security program, or managing risk at an organizational level.
- Your responsibilities include reporting security posture and program maturity to executives or the board.
- Your near-term career goal is security management, director of information security, or a CISO track.
CISA fits you if:
- Your work involves auditing IT systems, controls, or governance — whether as an internal auditor, external/public accounting auditor, or IT risk and compliance reviewer.
- You need to demonstrate independence and objectivity in evaluating systems you don’t operate yourself.
- Your near-term career goal is IT audit leadership, internal audit management, or a governance, risk, and compliance (GRC) role built around independent assessment.
A useful gut check: if your job is to build and defend a security program, CISM’s domains will feel like a description of your actual work. If your job is to independently verify whether systems, controls, and processes hold up to scrutiny — regardless of who built them — CISA’s domains will feel closer to home. If you genuinely do both (common in smaller GRC teams that blend program ownership with internal audit work), look at which domains dominate your current role and start there.
Prerequisites and Cost Compared
Both certifications gate on experience, and both currently list the same headline exam registration fee, but the shape of the experience requirement differs meaningfully.
CISM requires five years of professional information security work experience, with at least three of those years specifically in information security management spanning three or more of the four CISM domains. Up to two years of the five-year total can be waived through an approved credential — CISA and CISSP both qualify, as does a relevant postgraduate degree — but only one waiver applies, it’s capped at two years, and it cannot reduce the three-year management-experience floor. Experience generally must fall within the ten years preceding application, or be earned within five years after passing the exam4.
CISA requires five years of IS audit, control, assurance, or security work experience, gained within the ten-year period preceding the application date (or within five years after passing the exam)5. ISACA allows limited substitutions and waivers for this requirement (for example, certain other certifications or academic credit can offset a portion of it), so check ISACA’s current substitution table for specifics rather than assuming a straight waiver equivalent to CISM’s.
Cost, as of this writing: both exams carry the same registration fee — US$575 for ISACA members and US$760 for nonmembers — plus a one-time US$50 application processing fee after passing, and both require ongoing CPE hours to maintain (ISACA lists annual maintenance fees around US$45 for members and US$85 for nonmembers)6. Neither is meaningfully cheaper than the other; the deciding factor is which experience requirement you can already satisfy, not price.
Format: both exams are 150 questions, delivered in a 4-hour window, scored on ISACA’s common 200–800 scale with a passing score of 4507. Unlike CISSP’s adaptive CAT format, both CISM and CISA are fixed-form — every candidate answers the same number of questions.
Can You Pursue Both?
Yes, and it’s a common pairing — but sequence them by what you’re doing now, not by trying to collect both quickly.
If you’re currently doing audit work and eventually want to move into security management, CISA first makes sense: it credentials the job you’re actually doing, and passing it can offset up to two years of CISM’s experience requirement later, potentially shortening your path to CISM once you’ve genuinely moved into a management role. If you’re already running a security program and occasionally get pulled into audit-adjacent GRC work, CISM first is the more honest sequence, with CISA added later if your role formalizes around independent assessment.
What I’d caution against: pursuing both back-to-back purely to pad a resume before you’ve done the underlying work either credential is meant to verify. ISACA’s waiver mechanism reduces the years required, not the substance of the experience — sitting for CISA without ever having done audit work, or CISM without ever having managed a security function, tends to produce a credential that doesn’t hold up well in an actual interview, even if it clears the paperwork requirement.
Where CISSP Fits Relative to Both
If you’re also weighing ISC2’s CISSP in this decision: CISSP credentials broad technical security competence across eight domains — architecture, engineering, operations, and assessment — and sits in a different lane from both CISM and CISA. It’s not a substitute for either; it’s a third axis (technical breadth) alongside CISM’s management axis and CISA’s audit axis. Holding CISSP can also offset up to two years of CISM’s experience requirement, the same way CISA does, which is one reason security professionals sometimes sequence CISSP before CISM even when their longer-term goal is a management or CISO track. For a fuller comparison of that specific pairing — including where the two overlap and where they diverge — see our CISSP vs CISM decision guide.
If your work touches all three — hands-on technical security, program management, and independent audit — there’s no rule requiring you to rank them permanently. Start with whichever credential matches the job you’re doing right now; the other two remain available as your role evolves.
Sources
- ISACA — CISM Certification
- ISACA — CISM Exam Content Outline
- ISACA — CISA Certification
- ISACA — CISA Exam Content Outline
Footnotes
-
ISACA, CISM Certification — four job practice domains: Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management (outline in effect prior to the November 3, 2026 update). ↩
-
ISACA, “ISACA Updates CISM Exam Content Outline Factoring in Today’s Technologies, Security Responsibilities” (press release, 2026) — updated outline effective for exams taken on or after November 3, 2026, adding enterprise architecture and information security architecture content areas. ↩
-
ISACA, CISA Exam Content Outline — five domains: Information System Auditing Process (18%), Governance and Management of IT (18%), Information Systems Acquisition, Development and Implementation (12%), Information Systems Operations and Business Resilience (26%), Protection of Information Assets (26%). ↩
-
ISACA, Certification Application FAQ — “What are the requirements to become CISM certified?” — five years of information security experience with at least three years in information security management across three or more CISM domains; up to two years waivable via an approved credential (e.g., CISSP, CISA) or relevant postgraduate degree, one waiver only, not reducing the three-year management floor. ↩
-
ISACA, Certification Application FAQ — “What are the requirements to become CISA certified?” — five years of IS audit, control, assurance, or security work experience within the ten-year period preceding application (or within five years after passing the exam); limited substitutions available per ISACA’s current experience substitution table. ↩
-
ISACA, “What are all of the possible costs associated with becoming CISA / CISM / CGEIT / CRISC certified?” — exam registration US$575 (member) / US$760 (nonmember); US$50 one-time application processing fee; approximate annual maintenance fees US$45 (member) / US$85 (nonmember). ↩
-
ISACA, Exam scoring FAQ — CISA and CISM exams: 150 questions, 4-hour time limit, scored on a 200–800 scale, passing score 450. ↩
FAQ
Is CISM or CISA harder to pass?
ISACA doesn't publish an official pass rate for either exam, so there's no authoritative difficulty ranking. Both are 150-question, 4-hour exams scored on the same 200-800 scale with a passing score of 450. Difficulty in practice tracks how closely the exam's assumptions match your actual work — a security manager will generally find CISM's governance questions more familiar than CISA's audit-process questions, and vice versa for an IT auditor.
Can I use CISA experience toward CISM, or CISM experience toward CISA?
ISACA allows CISM candidates to waive up to two years of the five-year experience requirement using an approved credential such as CISA or CISSP, or a relevant postgraduate degree — but only one waiver applies, it's capped at two years, and it can't reduce the three-year information-security-management floor. CISA has its own separate five-year IS audit, control, assurance, or security experience requirement, and ISACA also allows limited experience substitutions there, but neither certification's work experience is automatically credited toward the other without qualifying under ISACA's specific waiver terms.
Do I need both CISM and CISA?
Not necessarily. Many security and audit professionals hold only one, matched to their actual role. Holding both becomes useful mainly if your career spans both functions over time — for example, moving from IT audit into security leadership — or if a specific employer or regulated industry expects both credentials for a governance, risk, and compliance (GRC) role that touches both domains.
About the authors
Sekiko Jo
"Sekiko Jo" is the pen name used by Team Creative Lab’s security editorial desk. Articles are written and reviewed by an editor-in-chief who holds CISSP, CCSP and the Registered Information Security Specialist (情報処理安全確保支援士) credential, with a focus on cloud threat modeling and security governance.
Registered Information Security Specialist (情報処理安全確保支援士), Japan