› Certifications · compare
Compare certifications
Pick up to 3 certifications and compare them side-by-side on cost, exam format, recertification, salary signal, quality, and domain coverage.
ISC2 · expert
CISSPCertified Information Systems Security Professional
Breadth across security engineering, architecture, operations, and governance at senior-IC / manager level. The default senior-generalist signal.
Official pageISACA · leadership
CISMCertified Information Security Manager
Security program management, risk, governance, and incident governance. The manager / CISO-track signal.
Official pageComparing
ISC2CISSP
ISACACISM
› Cost
Exam fee
CISSP$749
CISM$760
Exam fee
$749
$760
Annual maintenance fee
CISSP$135/yr
CISM$45/yr
Annual maintenance fee
$135/yr
$45/yr
3-year cost of ownership
CISSP$1,154
CISM$895
3-year cost of ownership
$1,154
$895
› Exam mechanics
Pass mark
CISSP700/1000 (CAT-derived)
CISM450/800 (scaled)
Pass mark
700/1000 (CAT-derived)
450/800 (scaled)
Retake policy
CISSP$749 fee · 30d wait · 4/yr cap
CISM$575 fee · 30d wait · 4/yr cap
Retake policy
$749 fee · 30d wait · 4/yr cap
$575 fee · 30d wait · 4/yr cap
Study time
CISSP150–300 hrs
CISM100–200 hrs
Study time
150–300 hrs
100–200 hrs
Validity
CISSP3 yrs
CISM3 yrs
Validity
3 yrs
3 yrs
CPE / yr
CISSP40 CPEs
CISM40 CPEs
CPE / yr
40 CPEs
40 CPEs
Delivery
CISSPtest center
CISMtest center
Delivery
test center
test center
› Salary signal (US base)
Range
CISSP$130K – $200K
CISM$130K – $190K
Range
$130K – $200K
$130K – $190K
Median
CISSP$155,000
CISM$155,000
Median
$155,000
$155,000
Premium %
CISSP+12%
CISM+11%
Premium %
+12%
+11%
Role context
CISSPSenior security engineer / architect, US, 5+ years experience.
CISMInformation security manager / director, US, 5+ years.
Role context
Senior security engineer / architect, US, 5+ years experience.
Information security manager / director, US, 5+ years.
› Quality (4-axis rubric · 0–10)
Schema quality
CISSP9.0
CISM9.0
Schema quality
9.0
9.0
Practice evidence
CISSP1.5
CISM1.0
Practice evidence
1.5
1.0
Maintenance
CISSP8.0
CISM8.5
Maintenance
8.0
8.5
Market recognition
CISSP9.5
CISM9.0
Market recognition
9.5
9.0
Average
CISSP7.0
CISM6.9
Average
7.0
6.9
› Recognition & lifecycle
Recognition
CISSPGlobal · US · EU · UK · DACH
CISMGlobal · US · EU · UK · DACH
Recognition
Global · US · EU · UK · DACH
Global · US · EU · UK · DACH
ISO 17024 accredited
CISSP✓
CISM✓
ISO 17024 accredited
✓
✓
DoD 8140 baseline
CISSP✓
CISM✓
DoD 8140 baseline
✓
✓
Holders worldwide
CISSP190,000
CISM70,000
Holders worldwide
190,000
70,000
Current version
CISSP2024 CBK refresh (2024-04)
CISM2022 job-practice analysis (2022-06)
Current version
2024 CBK refresh (2024-04)
2022 job-practice analysis (2022-06)
› Domain coverage
A1Governance, Risk & Compliance
CISSP● core
CISM● core
A1Governance, Risk & Compliance
● core
● core
A10Security Operations
CISSP● core
CISM·
A10Security Operations
● core
·
A11Detection Engineering & Threat Hunting
CISSP● core
CISM⚠ gap
A11Detection Engineering & Threat Hunting
● core
⚠ gap
A12Data Security, Privacy & Protection
CISSP● core
CISM○ touched
A12Data Security, Privacy & Protection
● core
○ touched
A13Supply Chain Security
CISSP○ touched
CISM○ touched
A13Supply Chain Security
○ touched
○ touched
A14OT/ICS Security
CISSP⚠ gap
CISM·
A14OT/ICS Security
⚠ gap
·
A15Cryptography
CISSP● core
CISM·
A15Cryptography
● core
·
A18Security Leadership
CISSP○ touched
CISM● core
A18Security Leadership
○ touched
● core
A2Network Security
CISSP● core
CISM·
A2Network Security
● core
·
A21Malware Analysis & Reverse Engineering
CISSP⚠ gap
CISM·
A21Malware Analysis & Reverse Engineering
⚠ gap
·
A25Security Architecture & Engineering
CISSP● core
CISM○ touched
A25Security Architecture & Engineering
● core
○ touched
A3Zero Trust Architecture
CISSP● core
CISM·
A3Zero Trust Architecture
● core
·
A4Application Security
CISSP● core
CISM⚠ gap
A4Application Security
● core
⚠ gap
A5Cloud Security
CISSP○ touched
CISM⚠ gap
A5Cloud Security
○ touched
⚠ gap
A6Identity & Access Management
CISSP● core
CISM·
A6Identity & Access Management
● core
·
A7Incident Response & Forensics
CISSP○ touched
CISM● core
A7Incident Response & Forensics
○ touched
● core
A9Penetration Testing & Red Teaming
CISSP○ touched
CISM⚠ gap
A9Penetration Testing & Red Teaming
○ touched
⚠ gap
B1AI-Powered Threat Detection
CISSP⚠ gap
CISM⚠ gap
B1AI-Powered Threat Detection
⚠ gap
⚠ gap
B2AI-Driven Security Automation
CISSP⚠ gap
CISM·
B2AI-Driven Security Automation
⚠ gap
·
B3AI for Vulnerability Management
CISSP⚠ gap
CISM·
B3AI for Vulnerability Management
⚠ gap
·
C1Adversarial Machine Learning
CISSP⚠ gap
CISM⚠ gap
C1Adversarial Machine Learning
⚠ gap
⚠ gap
C11Agentic AI Security
CISSP⚠ gap
CISM·
C11Agentic AI Security
⚠ gap
·
C2LLM-Specific Attacks
CISSP⚠ gap
CISM·
C2LLM-Specific Attacks
⚠ gap
·
C5AI Red Teaming
CISSP⚠ gap
CISM·
C5AI Red Teaming
⚠ gap
·
D2Post-Quantum Cryptography
CISSP⚠ gap
CISM·
D2Post-Quantum Cryptography
⚠ gap
·
Browse the full catalog or open any one of these on its detail page for full study materials, peer comparisons, and lifecycle notes.