CISM
CISM is ISACA's management-track security credential — the certification that signals you can run a security program, not just configure one. It is a frequent requirement on security manager, GRC, and CISO-track job descriptions, and many employers tie a promotion, raise, or contract to holding it. The exam is a single four-hour, 150-question sitting with one cut score: miss it, and you wait, re-register, and pay the fee again. This page breaks down exactly what CISM tests, how it's delivered, and how to get it done right the first time.
Pay Only After You Pass
No upfront fee — you settle only after your verified passing result. We advertise guaranteed results — 100% pass guaranteed or money back.
How the CISM exam is built — at a glance
150
Every question is four-option multiple choice with one best answer — no labs, drag-and-drop, or coding. Most items are scenario-based and ask what a security manager should do.
240
A single four-hour block, no scheduled breaks. That's roughly 96 seconds per question, so pacing and resisting the urge to overthink the "manager's best answer" matter as much as knowledge.
450
Scores are converted to a 200–800 scale; 450 is a fixed pass mark, not a percentage. ISACA equates every form so a harder question set doesn't penalize you.
The CISM is linear, not adaptive — you can flag and revisit questions throughout the four hours. The hard part is the framing: many questions have several technically correct options, and you must pick the one a security manager would prioritize first, based on governance, risk, and business alignment rather than the most hands-on technical fix.
ISACA reports a converted score from 200 to 800, with 450 required to pass. The conversion accounts for slight difficulty differences between exam forms, so your scaled score is comparable to everyone else's. You receive a preliminary pass/fail result on screen, with the official scored report available later through your ISACA account.
Four job-practice domains — bars show each domain's share of the exam
Establishing and maintaining a security governance framework, aligning security with business goals and strategy, and defining roles, policies, and an information security strategy supported by leadership.
Identifying, analyzing, and treating information risk: asset classification, risk assessment and analysis, risk response options, and ongoing monitoring and reporting to keep residual risk within tolerance.
The largest domain. Building, resourcing, and running a security program: control frameworks, security architecture, awareness, metrics, vendor and asset management, and demonstrating program value to the business.
Preparing for and responding to incidents: incident response planning, classification and escalation, business continuity and disaster recovery, communication, and post-incident review and improvement.
The two largest domains — Information Security Program (33%) and Incident Management (30%) — together make up nearly two-thirds of the exam, so candidates who can run a program and own a response, not just write policy, score best. Weights reflect ISACA's current CISM exam content outline.
Two ways to sit the exam — and what to expect on test day
ISACA delivers CISM through PSI. You sit the exam in a quiet, monitored room at a PSI center, where staff verify your ID, store your belongings, and watch the room. You get an on-screen exam plus a basic on-screen calculator; no personal materials are allowed in the test area.
You take the exam from a private room at home, monitored live by a PSI proctor for the full four hours. You'll complete a system check, a webcam room scan, and an ID verification before the exam unlocks. No one else may enter, and your desk must be clear of all materials.
Bring valid, unexpired government photo ID with your name matching your ISACA registration exactly. Online candidates show ID to the camera; the proctor captures it before the exam unlocks.
You register through ISACA, then book a slot in your eligibility window via PSI. Booking early matters — popular center and online slots fill up, especially near deadlines.
Stay in frame and on-camera the whole time online. There are no scheduled breaks in the four hours. Talking aloud, leaving the seat, or losing connection can flag or void the session.
CISM is built for the management side of security
Anyone can sit it — certification needs verified experience
Difficulty: CISM is widely rated harder to pass than it looks. The content isn't deeply technical, but the questions reward the "manager's best answer" — the response a security leader would prioritize, not the most technical fix. That mindset shift, plus a four-hour single sitting and a fixed cut score, is exactly the pressure point our help is designed to remove.
CISM is a high-stakes, four-hour single sitting with one cut score standing between you and a promotion, raise, or contract requirement. Exam Assist pairs you with a vetted ISACA specialist and works on a pay-after-you-pass model — so the risk sits with us, not you. No upfront fee, guaranteed results: Exam Assist handles the sitting end to end, and you settle only after the verified result.
Tell us your delivery method (PSI center or online), your eligibility window, your test date, and your background. Takes a couple of minutes over WhatsApp, Telegram, or Discord.
We review your timeline and target and tell you plainly whether it's realistic — before any money is discussed. If it isn't a fit, we say so.
Exam Assist handles the sitting end to end. You're matched with a CISM specialist who maps the work around the four domains, the manager's-mindset question style, and the PSI environment — discreetly and confidentially.
You only pay once your passing result is confirmed on your official report. No verified result, nothing owed.
See the full pay-after-you-pass ISACA service, pricing model, and how matching works.
Straight answers about the CISM exam
Service, booking, and sibling ISACA exams
Pair with a vetted ISACA specialist for CISM on a results-first arrangement. No upfront fee — settle only after a verified passing result.
Explore the service BookTell us your exam date, delivery method, and target. We'll send back an honest feasibility answer before anything is owed.
Start booking CISAISACA's flagship audit credential — for professionals who assess, audit, and control information systems and security.
View exam CRISCISACA's risk-focused certification for IT risk management and control professionals — a natural pairing with CISM.
View exam CGEITISACA's governance credential for professionals who manage and direct enterprise IT governance frameworks.
View examGet expert CISM help with no upfront fee — you settle only after your verified passing result. Honest feasibility answer first, results-first arrangement always.