Earning CISM CPE Credits Through Volunteer Work

Updated August 2026 · 9 min read

📋 Table of Contents

  1. Why Volunteer CPE Is Worth Pursuing
  2. Which Volunteer Activities Qualify
  3. ISACA Chapter Leadership
  4. Speaking and Presenting
  5. Mentoring and Coaching
  6. Annual Caps and Category Limits
  7. Documentation Requirements
  8. Strategy: Getting the Most from Volunteer CPE
  9. Frequently Asked Questions
🎯 Quick Answer ISACA recognizes volunteer service as a qualifying CPE activity for CISM renewal. Chapter leadership, committee membership, speaking at ISACA events, and formal mentoring all count -- claimed at actual hours spent. Documentation (a verification letter or meeting records from the chapter or organization) is required before you submit hours in the ISACA Certification Portal. Annual caps apply within specific activity categories, so planning which volunteer roles to claim matters.

Why Volunteer CPE Is Worth Pursuing

CISM holders must earn 120 Continuing Professional Education (CPE) hours over each three-year renewal cycle, with a minimum of 20 hours per calendar year. For most security managers, hitting 20 hours annually is not a problem -- conferences, webinars, and online courses fill the quota without much effort. But volunteer work adds something the typical CPE menu does not: it earns hours while simultaneously building the professional profile (chapter visibility, speaking credentials, mentoring relationships) that advances a security management career.

Volunteer CPE also tends to be "free" in the financial sense. A two-day security conference might cost $1,500-$3,000 in registration and travel; a year of serving on an ISACA chapter board costs nothing except time and contributes a comparable number of CPE hours. For professionals managing their own renewal budget, this matters.

The full CISM renewal requirements guide covers all CPE categories, fees, and deadlines. This article focuses specifically on the volunteer pathway and the mechanics ISACA applies to it.

Which Volunteer Activities Qualify

ISACA's CPE policy groups qualifying activities into categories. Volunteer work falls primarily under two of them: Volunteer Service/Activities and Professional Development/Education (when the volunteering involves teaching or speaking). Not all volunteer work qualifies -- the activity must relate to information security, risk management, IT governance, audit, or a directly adjacent discipline.

Activities ISACA has explicitly recognized include:

⚠️ Scope Requirement Generic community volunteering -- food banks, youth sports, local government boards -- does not qualify as CPE, even for highly accomplished professionals. The activity must have a direct and demonstrable connection to the information security or IT governance discipline. When in doubt, check ISACA's current CPE Policy document before claiming hours.

ISACA Chapter Leadership

Serving in a formal leadership role at an ISACA chapter is one of the most consistently productive volunteer CPE sources. Chapter officers and board members engage in recurring, documented professional activity: board meetings, program planning, membership outreach, and event coordination -- all of which relate directly to the information security profession.

How Hours Are Calculated

ISACA uses actual time spent as the basis for volunteer CPE hours. One hour of qualifying volunteer activity equals one CPE hour. There is no multiplier or bonus credit applied to leadership roles above the officer level -- a chapter president claims the same rate as a committee chair, measured by actual hours invested.

For a typical chapter board member, a realistic annual hour count might look like this:

Activity Frequency Hours per Occurrence Annual CPE Estimate
Board/committee meetings Monthly 1.5-2 hrs 18-24 hrs
Event planning and coordination Quarterly 3-5 hrs 12-20 hrs
Member communications Ongoing 1-2 hrs/month 12-24 hrs
Volunteer event day participation 4-6 events/year 4-6 hrs 16-36 hrs

An active chapter officer could reasonably accumulate 40-80 hours of qualifying volunteer activity per year. However, whether all of those hours are claimable depends on ISACA's per-category caps -- covered in the Annual Caps section below.

Non-ISACA Chapter Leadership

Leadership roles in comparable security and IT governance organizations -- ISSA (Information Systems Security Association), (ISC)2 chapters, IIA (Institute of Internal Auditors) chapters, and similar -- also qualify, provided the organization's primary focus is information security, IT risk, or governance. The documentation requirements are identical: a verification letter from the chapter on organizational letterhead describing your role and confirming the hours you served.

Speaking and Presenting

Presenting at ISACA events -- chapter meetings, conferences, webinars, and symposia -- generates CPE under a slightly different calculation than board service. ISACA distinguishes between the presentation itself and preparation time, and it treats repeat presentations differently from first-time deliveries.

Presentation CPE Rates

Activity CPE Calculation Notes
Delivering a new presentation Actual presentation time + preparation credit Preparation credit varies; ISACA typically allows up to 2 preparation hours for each 1 hour of new content
Repeat delivery of existing presentation Actual presentation time only No preparation credit for material already developed
Panel moderator or discussant Actual time in the panel session No preparation credit unless the moderator developed original content
Webinar presenter (ISACA-hosted) Same as in-person rates Must be an approved ISACA program, not a vendor webinar
Facilitating a study group Actual facilitation time Must be a formal ISACA exam preparation program

The preparation credit for new presentations is one of the most generous CPE multipliers available under ISACA's policy. A 60-minute chapter presentation on, say, third-party risk management frameworks could yield 3 CPE hours -- 1 for the talk and 2 for documented preparation -- assuming you built the material from scratch. Retaining your preparation notes and a draft outline is the documentation proof for that credit.

Speaking at non-ISACA events (industry conferences, employer lunch-and-learns, university guest lectures) can also qualify as CPE, but it falls under a different category than ISACA-specific volunteer work, and whether it counts toward volunteer CPE or professional development CPE depends on the context. Review the current ISACA CPE Policy for the category assignment rules if this applies to you.

Mentoring and Coaching

ISACA operates a formal mentoring program that pairs experienced certification holders with candidates preparing for ISACA exams or navigating early career decisions. Serving as a mentor in this program earns CPE hours for the actual time spent in mentoring sessions.

Key points about ISACA mentoring CPE:

A dedicated mentor who meets with 2-3 mentees monthly for 1-hour sessions could accumulate 24-36 hours of mentoring CPE annually -- a meaningful contribution toward the 120-hour three-year requirement.

Annual Caps and Category Limits

This is where volunteer CPE planning becomes important. ISACA places caps on certain CPE activity categories to ensure that certification holders maintain a broad base of professional development rather than relying exclusively on a single activity type.

⚠️ Always Verify Current Caps ISACA periodically revises its CPE Policy. The caps described here reflect ISACA's published guidance as of 2026, but you should download the current version of the ISACA CPE Policy from isaca.org before finalizing your renewal submission. Policy documents are available in the ISACA Certification Portal under "Certification Maintenance."

Under the current ISACA CPE Policy structure:

Volunteer Activity Category Annual Cap (approximate) Notes
ISACA chapter/committee leadership No stated cap (actual hours) Subject to overall reasonableness; all hours must be documented
Speaking/presenting (ISACA events) No stated cap (actual + prep hours) Preparation credit applies only to new content
ISACA formal mentoring program Actual session hours (no cap stated) Only formal program enrollments qualify
Non-ISACA professional organization service Check current policy May be capped or require additional justification

While ISACA does not publish a rigid per-category cap for core chapter volunteer activities (unlike some other certifying bodies that cap self-study or informal learning hours), the overall CPE submission is subject to audit. ISACA audits a sample of renewal submissions each cycle and requests supporting documentation. Claiming 80 hours of chapter volunteer work without a detailed log and verification letter is a risk; claiming 25-40 hours with solid documentation is routine and defensible.

The practical guidance most experienced CISM holders follow: use volunteer CPE to cover 20-40% of your three-year requirement (24-48 hours), and source the remainder from formal education, webinars, self-study, and conferences. This keeps your renewal profile credible and diversified. See the broader CISM CPE activities guide for the full menu of qualifying activity types.

Documentation Requirements

ISACA's CPE audit process is straightforward but unforgiving: if you cannot produce documentation for hours you claimed, those hours are disallowed, and your certification may lapse. For volunteer CPE, documentation falls into three types depending on the activity.

For Chapter Leadership and Committee Service

Best practice: request the verification letter at the end of each calendar year while the details are fresh, not when your renewal comes due three years later. Chapter leadership turns over, and the person who can write your letter may no longer be in the role.

For Speaking and Presenting

For ISACA Formal Mentoring

Retention Period

Retain all CPE documentation for the full three-year renewal cycle plus one additional year. ISACA can audit within the cycle, and having records accessible for a 4-year window protects you from any administrative delays or questions at renewal time.

Strategy: Getting the Most from Volunteer CPE

Volunteer CPE is most effective when it is planned rather than incidental. Security managers who stumble into chapter involvement and then try to reconstruct hours after the fact often undersell their actual contribution. Those who treat volunteer time like a professional development budget -- tracking hours in real time and collecting documentation as they go -- consistently file cleaner, higher-value CPE submissions.

Four practical approaches that work:

  1. Keep a running volunteer log. A simple spreadsheet with date, activity, organization, hours, and a one-line description is sufficient. Update it the same day as the activity, before memory degrades. This log is your primary defense in an ISACA audit.
  2. Sequence speaking opportunities strategically. If you are going to develop a new presentation, target events where ISACA will credit both delivery time and preparation time. Delivering the same talk at three chapter meetings in one year only earns you credit for the first delivery's preparation; the subsequent deliveries earn actual time only.
  3. Stack volunteer roles with other CPE sources. Chapter events you help organize also give you access to the speakers and content at those events -- which may qualify as separate CPE under the training/education category. Organizing an event and attending the sessions can generate two separate CPE line items from the same day.
  4. Request verification letters annually. At the end of each calendar year, send a brief email to your chapter president asking for a confirmation letter covering the year's service. This takes five minutes to request and eliminates the documentation gap that creates audit problems at renewal time.

Preparing for the CISM Exam?

Practice with thousands of expert-verified CISM-style questions and AI-powered gap analysis. Built by the team behind CISSP Study Group.

Start Free 7-Day Trial →

Frequently Asked Questions

Does all volunteer work count as CISM CPE?

No. The volunteer activity must relate directly to information security, IT risk management, IT governance, or a closely adjacent discipline. General community service, non-profit board work outside the technology sector, and similar activities do not qualify, regardless of the professional skills involved.

How many CPE hours can I earn from ISACA chapter leadership per year?

ISACA does not publish a fixed annual cap for chapter leadership CPE -- hours are claimed based on actual time spent. That said, claims should be supportable by documentation (meeting minutes, event logs, verification letters). Most active chapter officers accumulate 20-50 claimable hours per year from leadership activities alone, though all of it must be documented to survive an audit.

Can I claim CPE for mentoring someone outside ISACA's formal program?

Informal mentoring -- career conversations, resume reviews, and casual guidance offered to colleagues -- generally does not qualify as CPE under ISACA's current policy. To claim mentoring hours, you must be enrolled in ISACA's official mentoring program through your chapter or ISACA's central platform, and sessions must be logged formally.

What if I speak at a non-ISACA security conference?

Speaking at non-ISACA events can qualify as CPE, but typically falls under a different activity category (professional development or education rather than volunteer service). The key test is whether the content relates to information security or IT governance. Obtain a speaker confirmation letter from the event organizer and retain your slide deck or outline. Check the current ISACA CPE Policy for the specific category assignment.

Does writing for an ISACA publication earn volunteer CPE?

Authoring or peer-reviewing articles for ISACA's ISACA Journal, white papers, or research publications can earn CPE, but this typically falls under the self-study or professional contribution category rather than volunteer service. The hours claimed are actual writing or reviewing time. ISACA may request a copy of the publication or your contribution record as documentation.

What happens if I am audited and cannot produce documentation for volunteer CPE?

ISACA disallows undocumented hours. If disallowed hours cause your cycle total to fall below 120 (or your annual minimum to fall below 20), your certification can be suspended or revoked. The process typically involves a grace period to submit additional CPE from other activities, but the burden is on you to close the gap. Prevention -- maintaining a real-time log and collecting annual verification letters -- is far easier than remediation after an audit finding.

Can I claim CPE for attending chapter events I helped organize?

Yes, but as two separate line items under two separate categories. The time you spent organizing and staffing the event is volunteer service CPE. The time you spent attending the sessions as a participant may qualify as training or education CPE -- assuming the content meets the information security relevance standard. Document each component separately with the appropriate supporting records.

CISM Renewal Requirements 2026

Complete guide to the 120-hour CPE requirement, annual minimums, fees, and what happens if your certification lapses.

20 Ways to Earn CISM CPE Hours

Full menu of qualifying CPE activities ranked by effort and cost, including webinars, self-study, teaching, and writing.

CISM Certification Cost 2026

Exam fees, annual maintenance, study materials, and the total 3-year investment to earn and hold CISM.

CISM Salary 2026

What CISM-certified professionals earn by experience level, job title, and metro area.