CISSP vs CISM
The published facts of both certifications side by side. Which one fits depends on your role, experience and goals; the Plan Advisor and Role readiness weigh them against your own profile.
| CISSP ISC2 Certified Information Systems Security Professional |
CISM ISACA Certified Information Security Manager | |
|---|---|---|
| Issuer | ISC2 | ISACA |
| Level | Expert | Expert |
| Domain | Security & Risk Management | Security & Risk Management |
| Exam fee | $749 | $760 |
| Experience required | 5 years | 5 years |
| Prerequisite certifications | None | None |
| Exam | CAT, 100-150 questions, 3 hours | 150 questions, 4 hours |
| Passing score | 700/1000 | 450/800 |
| Renewal | Every 3 years · 120 CPE per cycle | Every 3 years · 120 CPE per cycle |
| Annual fee | $135 | $85 |
| Career tracks that use it | 5 | 4 |
Official relation
- Holding this credential satisfies one year of the five years of cumulative paid experience required for CISSP (maximum one year waived in total). Source: ISC2
Fees and requirements change: each certification's page links to the issuer's own terms. CertAscent lists them side by side; no issuer pays to be listed or compared.