CISM Eligibility: Who Can Take the Exam?
You can register for and take the CISM exam without first meeting the experience requirement.
- To earn the certification, ISACA requires five years of professional information security management experience across at least three of the four CISM domains.
- The 2026 Candidate Guide lists experience waivers of up to two years.
- You must apply within five years after passing and have qualifying work within the preceding ten years.
On this page7 sections
Two different eligibility questions
For CISM, eligibility to sit and eligibility to become certified are separate. ISACA says the exam is open to anyone with an interest in information security. You do not have to show five years of experience before registering or scheduling the exam. The experience rule applies when you apply for the credential after passing.
That distinction helps early-career candidates plan, but it can also cause an expensive misunderstanding. A passing result does not automatically confer CISM. To earn the designation, you need the required professional experience, an application with verification, the application fee, and agreement to ISACA's professional requirements. The pass remains usable for the application for five years, so note the date and plan around it.
| Stage | Requirement |
|---|---|
| Register and sit | Open to candidates with an interest in information security; no experience prerequisite to sit |
| Apply for CISM | Pass within the previous five years; five years of information security management experience across at least three domains |
| Experience recency | Qualifying experience must fall within the ten years before the application |
| Waiver limit | The 2026 ISACA Candidate Guide states that experience waivers are available up to a maximum of two years |
| Application | Supervisor or manager verifies experience; one-time US$50 processing fee |
| After certification | Follow ISACA Code of Professional Ethics and CPE requirements |
What counts as information security management experience
The requirement is professional information security management work in the CISM job practice areas, across at least three of the four domains. ISACA's description is about work performed and responsibility held, not the wording on a business card. A security manager title does not prove that the duties span the domains. Conversely, a role with another title may include relevant program, risk, governance, or incident management responsibilities.
Use the official job practice outline to map your duties. For governance, describe how you supported security strategy, oversight, policy, or accountability. For risk management, identify work assessing and treating security risk, reporting it, or helping owners make decisions. For program management, show how you established, resourced, implemented, measured, or improved security initiatives. For incident management, describe preparation, coordination, response oversight, communication, or lessons learned.
A technical task can be part of management experience when it includes management responsibility and fits a job practice area. For example, writing a control script is usually not enough by itself. Selecting the control based on risk, assigning an owner, funding its implementation, defining how to monitor it, and reporting its effectiveness may demonstrate program or risk management work. Explain your actual contribution without inflating a team outcome into personal ownership.
ISACA requires five years of professional experience across at least three domains. Keep dates, employer information, role descriptions, and examples of responsibilities. Your application needs a supervisor or manager who can verify the reported experience. If a former supervisor has left the organization, identify another appropriate manager who can substantiate the work and dates, and retain records that support your description.
How the two-year waiver maximum works
The 2026 ISACA Candidate Guide says that experience waivers are available for a maximum of two years for CISM. This is a cap, not an automatic two-year credit for every applicant. A candidate must meet the applicable ISACA waiver conditions and provide the evidence requested in the application process. The public CISM certification summary does not list every eligible qualification in the same short description, so do not assume a degree, another credential, or a particular job automatically qualifies.
Think of the rule as a total: qualifying experience plus any approved waiver credit must reach the five-year requirement. For example, a candidate with four years of qualifying CISM experience and an accepted one-year waiver could meet the total, subject to ISACA's review and the requirement to cover at least three domains. A candidate with three years of experience and a two-year waiver reaches five only if the waiver is approved and the three experience years cover at least three domains.
A candidate with two years of work and an assumed two-year waiver has only four years, so the five-year requirement is not met. A waiver does not erase the domain coverage condition. A candidate with five years of work in one domain also needs to establish coverage across at least three domains; the total number of years alone is insufficient.
ISACA has also described a one-year educational waiver associated with the Certified Cybersecurity Operations Analyst (CCOA) credential. Treat that as a specific published pathway and check the current CISM application policy for documentation and applicability. It does not change the five-year total or eliminate the need to demonstrate management experience across the required domains. Do not count a credential benefit without confirming that it applies to the application you submit.
Three qualification examples
Security analyst preparing early
A security analyst has two years investigating alerts, tuning detections, and contributing to incident reviews. The candidate can sit the exam now. For certification, the candidate should distinguish operational incident work from management experience. If the analyst has also owned risk assessments, security policy, program metrics, or response planning, those duties may support coverage across more domains; they should be described accurately and verified. If not, the candidate can pass first and continue gaining relevant experience, while tracking the five-year application deadline.
Program lead with mixed responsibilities
A program lead has four years coordinating a security roadmap, reporting risk to business owners, and overseeing incident exercises. Those duties appear to span Governance, Risk Management, Program, and Incident Management. If an eligible one-year waiver applies, the candidate may reach five total years. Before applying, the candidate should document the periods and responsibilities, confirm the waiver category, and ask a manager to verify the work. A general claim such as 'owned cybersecurity' would be less useful than concrete examples of decisions and accountability.
Long service in a narrow specialty
A specialist has seven years administering endpoint security controls but has not participated in security governance, risk decisions, program planning, or incident leadership. The candidate has enough calendar time but may lack experience across three domains. The next step is not to relabel technical work. It is to build and document genuine management responsibilities, such as contributing to risk treatment plans, advising a security steering group, managing a control improvement project, or coordinating incident readiness, if those duties are part of the real job.
Experience windows and application timing
ISACA says qualifying experience must fall within the ten-year period before the certification application. The exam pass must be within the five years before applying. These are different clocks. If you take the exam well before you have the experience, count forward from the pass date and make sure you can apply before five years elapse. At the same time, make sure the experience you claim remains within the ten-year lookback.
Suppose a candidate passes on October 10, 2026, has three years of qualifying experience, and continues working in relevant management duties. The candidate has until the five-year application deadline to complete the requirement and file the application. The exact last date should be calculated from the official pass date and confirmed in MyISACA. Do not wait until the final week: allow time to collect verifier responses, resolve application questions, and submit the processing fee.
If you already meet the experience requirement, assemble records before starting the application. List employer, role, dates, domains, specific responsibilities, and verifier contact details. For a waiver, collect the precise evidence the current form calls for. The application is easier to complete when your work history is written in the language of actual decisions and outcomes, rather than a list of tools or technologies.
What happens after a pass
After the official score is released, apply through MyISACA and pay the one-time US$50 application fee. ISACA's CISM certification page says that a supervisor or manager must verify experience. Applicants must also agree to the Code of Professional Ethics and meet continuing professional education conditions. The application should accurately distinguish directly qualifying experience from a waiver claim.
If the application is incomplete, answer ISACA's request with the supporting evidence it asks for. Keep a copy of submitted information and correspondence. A candidate who is still accumulating experience should keep records contemporaneously, including projects that show security strategy, risk decisions, program management, or incident leadership. This is particularly useful when projects cross employers or when a verifier changes roles.
Common eligibility mistakes
- Assuming five years are required before registering. ISACA allows candidates to sit the exam before meeting experience requirements.
- Treating a passing result as the certification. Experience and application approval remain necessary.
- Counting a waiver before confirming that the specific qualification is eligible and supported by evidence.
- Ignoring the requirement to cover at least three domains while focusing only on the five-year total.
- Using experience outside the ten-year lookback or applying more than five years after passing.
- Relying on a job title instead of documenting actual professional responsibilities and a verifier.
The most useful eligibility check is a timeline and domain map. Put the planned exam date and five-year pass-to-application deadline on the timeline. For every work period, write the duties, domain coverage, and verifier. Add any potential waiver only after checking the current ISACA policy. That gives you a realistic view of whether to sit now, build more management exposure first, or apply promptly after passing.
Common questions
Can I take the CISM exam with no experience?
Yes. ISACA says the exam is open to anyone interested in information security. Experience is required for certification after passing, not to sit.
How many years are required for CISM certification?
Five years of professional information security management experience across at least three of the four domains, subject to any applicable approved waiver. The 2026 Candidate Guide caps waivers at two years.
Does a CISM waiver automatically reduce the requirement to three years?
No. Two years is the maximum waiver allowance, not automatic credit. You must meet the conditions for an eligible waiver and have ISACA accept the evidence.
How long after passing can I apply for CISM?
ISACA gives candidates five years from passing to apply. Qualifying experience must be within the ten years before the application.
Does a security job title count as CISM experience?
A title alone does not establish eligibility. Document the professional information security management duties and their coverage of at least three CISM domains, with a supervisor or manager able to verify them.