› Certifications · compare
Compare certifications
Pick up to 3 certifications and compare them side-by-side on cost, exam format, recertification, salary signal, quality, and domain coverage.
ISACA · leadership
CISMCertified Information Security Manager
Security program management, risk, governance, and incident governance. The manager / CISO-track signal.
Official pageISC2 · expert
CISSPCertified Information Systems Security Professional
Breadth across security engineering, architecture, operations, and governance at senior-IC / manager level. The default senior-generalist signal.
Official pageComparing
ISACACISM
ISC2CISSP
› Cost
Exam fee
CISM$760
CISSP$749
Exam fee
$760
$749
Annual maintenance fee
CISM$45/yr
CISSP$135/yr
Annual maintenance fee
$45/yr
$135/yr
3-year cost of ownership
CISM$895
CISSP$1,154
3-year cost of ownership
$895
$1,154
› Exam mechanics
Pass mark
CISM450/800 (scaled)
CISSP700/1000 (CAT-derived)
Pass mark
450/800 (scaled)
700/1000 (CAT-derived)
Retake policy
CISM$575 fee · 30d wait · 4/yr cap
CISSP$749 fee · 30d wait · 4/yr cap
Retake policy
$575 fee · 30d wait · 4/yr cap
$749 fee · 30d wait · 4/yr cap
Study time
CISM100–200 hrs
CISSP150–300 hrs
Study time
100–200 hrs
150–300 hrs
Validity
CISM3 yrs
CISSP3 yrs
Validity
3 yrs
3 yrs
CPE / yr
CISM40 CPEs
CISSP40 CPEs
CPE / yr
40 CPEs
40 CPEs
Delivery
CISMtest center
CISSPtest center
Delivery
test center
test center
› Salary signal (US base)
Range
CISM$130K – $190K
CISSP$130K – $200K
Range
$130K – $190K
$130K – $200K
Median
CISM$155,000
CISSP$155,000
Median
$155,000
$155,000
Premium %
CISM+11%
CISSP+12%
Premium %
+11%
+12%
Role context
CISMInformation security manager / director, US, 5+ years.
CISSPSenior security engineer / architect, US, 5+ years experience.
Role context
Information security manager / director, US, 5+ years.
Senior security engineer / architect, US, 5+ years experience.
› Quality (4-axis rubric · 0–10)
Schema quality
CISM9.0
CISSP9.0
Schema quality
9.0
9.0
Practice evidence
CISM1.0
CISSP1.5
Practice evidence
1.0
1.5
Maintenance
CISM8.5
CISSP8.0
Maintenance
8.5
8.0
Market recognition
CISM9.0
CISSP9.5
Market recognition
9.0
9.5
Average
CISM6.9
CISSP7.0
Average
6.9
7.0
› Recognition & lifecycle
Recognition
CISMGlobal · US · EU · UK · DACH
CISSPGlobal · US · EU · UK · DACH
Recognition
Global · US · EU · UK · DACH
Global · US · EU · UK · DACH
ISO 17024 accredited
CISM✓
CISSP✓
ISO 17024 accredited
✓
✓
DoD 8140 baseline
CISM✓
CISSP✓
DoD 8140 baseline
✓
✓
Holders worldwide
CISM70,000
CISSP190,000
Holders worldwide
70,000
190,000
Current version
CISM2022 job-practice analysis (2022-06)
CISSP2024 CBK refresh (2024-04)
Current version
2022 job-practice analysis (2022-06)
2024 CBK refresh (2024-04)
› Domain coverage
A1Governance, Risk & Compliance
CISM● core
CISSP● core
A1Governance, Risk & Compliance
● core
● core
A10Security Operations
CISM·
CISSP● core
A10Security Operations
·
● core
A11Detection Engineering & Threat Hunting
CISM⚠ gap
CISSP● core
A11Detection Engineering & Threat Hunting
⚠ gap
● core
A12Data Security, Privacy & Protection
CISM○ touched
CISSP● core
A12Data Security, Privacy & Protection
○ touched
● core
A13Supply Chain Security
CISM○ touched
CISSP○ touched
A13Supply Chain Security
○ touched
○ touched
A14OT/ICS Security
CISM·
CISSP⚠ gap
A14OT/ICS Security
·
⚠ gap
A15Cryptography
CISM·
CISSP● core
A15Cryptography
·
● core
A18Security Leadership
CISM● core
CISSP○ touched
A18Security Leadership
● core
○ touched
A2Network Security
CISM·
CISSP● core
A2Network Security
·
● core
A21Malware Analysis & Reverse Engineering
CISM·
CISSP⚠ gap
A21Malware Analysis & Reverse Engineering
·
⚠ gap
A25Security Architecture & Engineering
CISM○ touched
CISSP● core
A25Security Architecture & Engineering
○ touched
● core
A3Zero Trust Architecture
CISM·
CISSP● core
A3Zero Trust Architecture
·
● core
A4Application Security
CISM⚠ gap
CISSP● core
A4Application Security
⚠ gap
● core
A5Cloud Security
CISM⚠ gap
CISSP○ touched
A5Cloud Security
⚠ gap
○ touched
A6Identity & Access Management
CISM·
CISSP● core
A6Identity & Access Management
·
● core
A7Incident Response & Forensics
CISM● core
CISSP○ touched
A7Incident Response & Forensics
● core
○ touched
A9Penetration Testing & Red Teaming
CISM⚠ gap
CISSP○ touched
A9Penetration Testing & Red Teaming
⚠ gap
○ touched
B1AI-Powered Threat Detection
CISM⚠ gap
CISSP⚠ gap
B1AI-Powered Threat Detection
⚠ gap
⚠ gap
B2AI-Driven Security Automation
CISM·
CISSP⚠ gap
B2AI-Driven Security Automation
·
⚠ gap
B3AI for Vulnerability Management
CISM·
CISSP⚠ gap
B3AI for Vulnerability Management
·
⚠ gap
C1Adversarial Machine Learning
CISM⚠ gap
CISSP⚠ gap
C1Adversarial Machine Learning
⚠ gap
⚠ gap
C11Agentic AI Security
CISM·
CISSP⚠ gap
C11Agentic AI Security
·
⚠ gap
C2LLM-Specific Attacks
CISM·
CISSP⚠ gap
C2LLM-Specific Attacks
·
⚠ gap
C5AI Red Teaming
CISM·
CISSP⚠ gap
C5AI Red Teaming
·
⚠ gap
D2Post-Quantum Cryptography
CISM·
CISSP⚠ gap
D2Post-Quantum Cryptography
·
⚠ gap
Browse the full catalog or open any one of these on its detail page for full study materials, peer comparisons, and lifecycle notes.