CISM Renewal and Continuing Professional Education
CISM holders must earn and report at least 20 CPE hours each year and 120 hours over a three-year reporting period.
- The annual maintenance fee is US$45 for members and US$85 for nonmembers, due by January 1.
- Retain evidence, report activities in MyISACA, follow the Code of Professional Ethics, and respond if selected for a CPE audit.
On this page9 sections
CISM maintenance at a glance
CISM is maintained through continuing professional education, annual payment, and professional conduct. ISACA requires at least 20 CPE hours each year and at least 120 CPE hours during a three-year reporting period. The activity must relate to maintaining knowledge or ability to perform CISM-related tasks. Annual maintenance fees are US$45 for members and US$85 for nonmembers, and payment is due by January 1 for the upcoming calendar year.
| Requirement | Current rule |
|---|---|
| Annual CPE minimum | 20 hours |
| Three-year total | 120 hours related to CISM |
| Annual fee, member | US$45 |
| Annual fee, nonmember | US$85 |
| Due date | January 1 for renewal through the upcoming calendar year |
| Audit record retention | Keep evidence for 12 months after the end of each three-year reporting cycle |
| Professional conduct | Follow ISACA Code of Professional Ethics |
What counts as relevant CPE
CPE should maintain or improve the knowledge and ability needed for CISM-related work. Relevant activities can include formal training, conferences, webinars, online learning, professional reading, teaching, writing, and qualifying volunteer contributions under ISACA's CPE policy. The activity must fit a permitted category and be reported with the information the policy requires. Simply attending a general event does not make every hour relevant to the credential.
ISACA's maintenance page lists several ways to earn CPE, including conferences, webinars and online training, on-demand learning, training courses and skills-based labs, and volunteer work. Its page gives activity-specific maximums, such as up to 36 free CPE per year from webinars and online training and up to 20 free CPE per year from volunteering. These are available opportunities and category limits, not automatic credits; check the current policy for how hours are calculated and applied.
A security manager might earn CPE by studying a revised incident response standard, attending a cloud risk conference, completing a course on third-party oversight, or teaching a session on program metrics. For each activity, retain what the policy asks for and be able to explain its connection to security management. A general hobby or unrelated course should not be reported as CISM CPE simply because it was educational.
How to report CPE in MyISACA
Sign in to MyISACA and open Certifications and CPE Management. ISACA states that certain activities completed through its own systems can be preloaded, but the holder must apply the hours to the relevant certification. Activities from chapters and other providers may need to be self-reported. Enter the activity title or description, sponsoring organization, date, qualifying category, and number of hours, then save the record against CISM.
Do not assume that a preloaded CPE entry has already been applied. The maintenance page describes an Unapplied CPE section and an Apply action. Check your CISM record after reporting and resolve missing or misallocated hours before the annual deadline. If an activity is relevant to multiple ISACA certifications, hours may be used for more than one only when the activity applies to the job-related knowledge of each credential.
A calendar reminder is more dependable than a year-end scramble. Schedule a monthly or quarterly review of your CPE ledger. Record the activity while details are fresh, apply preloaded hours, and compare totals with both the annual 20-hour minimum and the rolling three-year 120-hour total. The yearly minimum matters even if your three-year sum is already high.
Pay the annual maintenance fee
The current ISACA CISM maintenance page lists US$45 per year for members and US$85 for nonmembers. The fee is due annually by January 1 and renews the designation through the upcoming calendar year. ISACA says invoice notices begin in September for the following year and a payment option appears in the certification dashboard when due.
For holders with more than two ISACA certifications, the third and each additional certification have reduced annual fees: US$25 for members and US$50 for nonmembers, according to the current page. This is a maintenance-fee rule, not a reduction in the exam registration or initial application fee. Review the account invoice because your number of active certifications and membership status affect the total.
CPE and fee payment are separate obligations. Paying the fee does not replace the 20-hour annual minimum or the 120-hour cycle total. Meeting the CPE total does not clear an unpaid annual fee. Keep both on the calendar and verify that the account shows the credential active for the coming year.
Keep records for a possible audit
ISACA randomly selects certification holders for CPE audits. If selected, you need supporting documentation for reported activities from the specified calendar year. The maintenance page says records should be kept for 12 months following the end of each three-year reporting cycle. A record should identify the attendee, sponsoring organization, activity title and description, date, and CPE hours claimed or awarded.
Acceptable records can include a completion certificate, attendance roster, provider letter, verification form, or other independent attestation. Save the original confirmation in a secure folder and maintain a simple ledger with the activity, category, date, time, connection to CISM, and file location. A calendar entry alone may not be sufficient proof of attendance or completion.
If selected, respond within ISACA's audit instructions and provide the requested evidence. The maintenance page says failure to comply with an audit can result in revocation. A well-kept record reduces the effort of answering and helps you avoid overstating hours. Report only the amount permitted under the relevant category and do not count the same hour twice within one credential.
Ethics, inactive status, and consequences
CISM holders agree to the ISACA Code of Professional Ethics. Maintenance also requires following the CPE policy and annual fee schedule. Failure to meet requirements can result in revocation, after which a person may no longer represent themselves as certified. Certification status can be reported as revoked when someone requests verification.
ISACA offers non-practicing and retired status for people who meet separate eligibility requirements. These are formal status options, not automatic exemptions for anyone taking a career break. Read the status policy and apply before assuming annual CPE or payment obligations change.
ISACA describes an appeal process for reinstatement after revocation for CPE noncompliance. If approved, the holder must pay outstanding maintenance fees and a US$50 reinstatement fee for each certification. If an appeal is denied, returning to active status requires retaking and passing the exam and reapplying with the appropriate experience. Avoiding a missed deadline is much simpler than restoring a revoked credential.
A sample annual maintenance routine
- January: confirm payment status and set the year's CPE target above the 20-hour minimum.
- Each quarter: complete one or more relevant activities, report them in MyISACA, and save independent proof.
- June or July: check the annual total and the cumulative three-year total; schedule additional learning if either is behind.
- September: watch for the following year's maintenance invoice and verify member/nonmember rate and any multi-certification discount.
- By year end: apply preloaded CPE, self-report outside activities, resolve missing records, and confirm the account shows the annual fee paid.
- At the end of the three-year period: verify 120 total hours, each annual minimum, and retain supporting records for the additional 12 months.
A holder who earns 24 hours in the first year and 40 in the second still needs at least 20 in the third year and must reach 120 across the three years. Extra hours do not erase the minimum for each year. A holder who earns 80 in one year and 20 in each of the next two reaches 120, but should still confirm that all activities qualify and are properly reported.
Career value and limits
Maintaining CISM demonstrates continued professional learning in information security management. It can help a holder keep current with changes to governance, threat, program, supplier, and incident practices. The credential does not guarantee promotion, employment, or a salary level, and CPE alone cannot substitute for practical management experience. Apply learning to actual decisions and retain evidence of professional growth.
If you hold several security credentials, build one calendar and one record system, then apply hours to each designation only where the activity meets that credential's rules. A seminar on incident leadership might be relevant to CISM and another security credential; a general finance class may not be relevant to CISM. Review each policy rather than assuming that one universal CPE bucket satisfies all obligations.
Renewal checklist
- Earn and report at least 20 qualifying CPE hours each year.
- Reach at least 120 CISM-related hours during the three-year period.
- Pay the annual fee by January 1; verify member status and multi-certification pricing.
- Apply preloaded CPE in MyISACA and self-report external activities.
- Retain independent evidence with dates, provider, activity, and hours.
- Respond to a random audit if selected and follow the Code of Professional Ethics.
- Use non-practicing or retired status only if you meet the separate policy requirements.
CISM renewal is manageable when CPE reporting, payment, and evidence are treated as routine recordkeeping. Keep the current policy nearby, check the account each quarter, and resolve gaps early. This protects the active credential and makes the learning directly useful to your security management work.
Common questions
How many CPE hours does CISM require?
At least 20 hours annually and 120 hours over each three-year reporting period, related to CISM knowledge or job tasks.
What is the CISM annual maintenance fee?
ISACA lists US$45 for members and US$85 for nonmembers, due by January 1. Reduced fees apply to third and additional ISACA certifications under its published terms.
When is the CISM maintenance fee due?
ISACA says the fee is due annually by January 1 for renewal through the upcoming calendar year.
How long should I keep CISM CPE records?
ISACA says to retain supporting documentation for 12 months after the end of each three-year reporting cycle.
What happens if I miss CISM CPE requirements?
Failure to comply can lead to revocation. ISACA provides a reinstatement appeal process, but approval, outstanding fees, a reinstatement fee, or retesting may be involved depending on the outcome.