CISM Certification Requirements After the Exam
To become a CISM after passing, submit an application within five years and document five years of professional information security management experience across at least three of the four domains.
- Experience must fall within the ten years before applying and be verified by a supervisor or manager.
- The one-time application fee is US$50; ethics and CPE obligations also apply.
On this page8 sections
A pass is not the CISM credential
ISACA separates the CISM exam from certification. The exam is open to anyone interested in information security, so you may sit before meeting the professional experience requirement. After passing, you still need to demonstrate qualifying work, submit the application, pay the one-time fee, and agree to ISACA's professional requirements. Do not place the CISM acronym after your name until ISACA has awarded the designation.
| Certification step | ISACA requirement |
|---|---|
| Exam | Pass CISM; the pass must be within five years of the certification application |
| Experience | At least five years of professional information security management experience across at least three of four CISM domains |
| Experience recency | Qualifying work is within the ten years preceding the application |
| Waivers | 2026 Candidate Guide lists a maximum of two years of experience waivers; approval is conditional |
| Verification | Supervisor or manager verifies reported experience |
| Application fee | One-time US$50 processing fee after official exam score release |
| Professional obligations | Adhere to the Code of Professional Ethics and Continuing Professional Education Policy |
What experience ISACA requires
The requirement is five years of professional information security management experience within the CISM job practice areas. The work must cover at least three of the four domains: Governance, Risk Management, Security Program, and Incident Management. The experience must have been gained during the ten-year period before the application date. A professional title by itself is not enough; the application should describe actual responsibilities and periods of work.
Examples of relevant responsibilities include establishing security strategy and governance, supporting risk assessment and treatment, managing a security program and its resources, and overseeing incident readiness or response. A role may touch more than one domain. Explain how your work connects to the job practice rather than simply listing tools, systems, or team names.
The experience requirement is based on professional work and coverage, not an exam score. A high result does not reduce the number of required years. Similarly, a candidate with many years in a narrow operational specialty should verify that their actual responsibilities satisfy the three-domain breadth requirement. If the experience is not yet complete, the candidate can pass and apply later within the pass window.
Understand the waiver limit without assuming credit
The 2026 Candidate Guide states that experience waivers are available for a maximum of two years for CISM. This is an upper limit, not an automatic subtraction from the five-year requirement. ISACA's public certification page gives the core five-year and three-domain criteria, while the application materials determine the qualifications and documentation accepted for a waiver. Confirm your specific basis in the current application before relying on it.
ISACA has separately announced a one-year educational waiver toward CISM for candidates who pass the Certified Cybersecurity Operations Analyst (CCOA) exam. This is a specific pathway and should be documented using current ISACA instructions. It does not make the exam prerequisite experience-based, remove the three-domain requirement, or automatically provide two years of credit. Other possible waiver categories should be checked in the live CISM application rather than assumed from rules for CISA or another credential.
For planning, calculate a conservative case with no waiver and a second case only if you have a specific, documented eligible waiver. For example, a candidate with four years of qualifying work and an approved one-year waiver could reach five years, subject to domain breadth. A candidate with three years and a two-year approved waiver may reach the total but still needs the work experience to span three domains. A candidate with two years and a one-year waiver does not yet reach five.
Do not double-count calendar time. If one role simultaneously involved governance and program work, those responsibilities can support domain coverage during the same period, but the time period is still one year, not two years. Keep a timeline and map each role to the tasks you actually performed.
Prepare evidence and a verifier
ISACA's certification page says experience should be verified by a supervisor or manager. Before opening the application, assemble employer names, role names, start and end dates, and a concise description of responsibilities. Identify a supervisor or manager with enough knowledge to confirm the dates and duties. If a former manager has left, select an appropriate person who can verify the work rather than guessing at a contact.
A useful experience record has one row per role or meaningful period. Include what you were accountable for, which CISM domain it supports, the decisions you made or advised, and evidence such as a program plan, risk report, governance committee role, exercise plan, or response procedure. You do not need to disclose confidential documents in an article or public portfolio; keep evidence securely and provide only what ISACA requests.
Write with appropriate ownership. If you contributed analysis to a risk decision made by a business owner, say that you assessed or advised; do not claim you accepted the risk unless you had authority. If you supported an incident team, distinguish coordination responsibilities from forensic work done by another team. Accurate descriptions make verification clearer and preserve professional credibility.
Apply within the two time windows
You have five years from passing the exam to submit the certification application. Separately, your qualifying work must be within the ten years before that application. If you pass before meeting the experience requirement, record the pass date, estimate when you will have the required work, and leave time to obtain verification and respond to any application question.
For example, a candidate who passes on October 20, 2026, has a five-year application window. If that person currently has three years of qualifying experience, they need to gain enough additional qualifying work and apply before the deadline. The ten-year lookback is measured from the eventual application, so sufficiently old work may eventually fall outside it. Use the dates shown in MyISACA and the current policy to calculate exact deadlines.
After the official score is released, pay the one-time US$50 fee through the certification account and submit the experience application. The fee is an application processing charge, not the exam fee or a purchase of the designation. Passing the test does not automatically trigger certification. Keep confirmation of payment and submission, and watch the account for follow-up.
Three application examples
The candidate who meets the rule
A security professional has six years of work within the last decade: two years supporting risk assessment and treatment, three years managing a security program, and one year coordinating incident readiness. They pass and apply. Their work appears to cover three domains, but the application still needs clear task descriptions and a supervisor or manager verification. The person should also confirm no interval is double-counted and complete every required professional agreement.
The candidate who passes early
A security analyst has two years of experience and passes the exam. The candidate may keep the pass and continue gaining relevant management experience, but cannot yet claim full certification. They should track the five-year application deadline and pursue responsibilities that create authentic experience across multiple domains, such as contributing to risk decisions, program metrics, governance reporting, or incident planning.
The candidate with long technical experience
An engineer has eight years deploying security controls but little evidence of management work or domain breadth. The calendar duration is substantial, yet the candidate should map actual duties to the CISM practice areas. If they only implemented configurations under another manager's direction, that may not establish the same experience as managing a program or risk decision. They should document what they really owned and ask ISACA about ambiguous application categories before relying on them.
Ethics and continuing requirements
CISM holders agree to ISACA's Code of Professional Ethics. The credential also carries continuing professional education requirements: at least 120 CPE hours over a three-year reporting period and at least 20 each year. Annual maintenance fees apply. These are ongoing conditions after certification, not experience substitutions for the initial application.
The CISM designation is an ISACA professional certification, not a jurisdiction-specific license to practise. Employers and regulators may require separate experience, background, or role qualifications. The credential signals that the holder met ISACA's requirements; it does not confer legal authority to approve risk or lead incidents at every organization.
A post-exam checklist
- Wait for the official score release and record the pass date.
- Check whether your experience spans at least three CISM domains and totals five years.
- Confirm that claimed experience falls in the ten-year window before applying.
- Use only waivers with a documented, currently eligible basis; the maximum is two years.
- Choose a supervisor or manager who can verify dates and actual duties.
- Pay the one-time US$50 application fee and submit within five years of passing.
- Read the ethics and CPE requirements so you understand what follows approval.
The credential is earned through both knowledge and professional experience. Passing demonstrates the exam standard; the application verifies that your work fits the management practice. Keep those steps distinct, provide accurate evidence, and plan the timeline before the five-year pass window becomes urgent.
Common questions
What are the CISM certification requirements after passing?
Apply within five years, show five years of professional information security management work across at least three domains, have a supervisor or manager verify experience, pay the US$50 fee, and meet ethics and CPE obligations.
How much experience is required for CISM?
ISACA requires five years across at least three of the four CISM domains. Experience must be within the ten years before applying. The 2026 Candidate Guide lists waivers up to a two-year maximum.
How long do I have to apply after passing CISM?
Candidates have five years from the passing date to apply for certification.
Does CISM passing automatically award the credential?
No. ISACA must approve the experience application and other requirements after the exam pass.
What is the CISM application fee?
ISACA lists a one-time US$50 application processing fee, payable after the official score is released.