đ Table of Contents
What Is CISM?
The Certified Information Security Manager (CISM) is ISACA's flagship credential for security leaders. Launched in 2002, it has become one of the most recognized management-level certifications in information security, alongside CISSP. Where CISSP tests broad technical knowledge, CISM is explicitly management-first: every question is written from the perspective of a security manager making governance, risk, and program decisions.
CISM covers four domains:
- Domain 1: Information Security Governance (17%) - Establishing and maintaining strategy, policies, and governance frameworks
- Domain 2: Information Security Risk Management (20%) - Identifying, assessing, and managing information risk in alignment with business objectives
- Domain 3: Information Security Program Development and Management (33%) - Building and managing a security program, including resource management, metrics, and awareness
- Domain 4: Information Security Incident Management (30%) - Planning, executing, and learning from security incidents
The exam is 150 scenario-based questions over 4 hours. ISACA uses scaled scoring; you need a 450 out of 800 to pass. The experience requirement is 5 years in information security, with at least 3 years in security management specifically (up to 2 years can be waived via qualifying credentials, including CISSP). See our experience requirements guide for full details.
What Is CDPSE?
The Certified Data Privacy Solutions Engineer (CDPSE) is a newer ISACA credential, launched in 2020 in direct response to the growing demand for practitioners who can operationalize privacy regulation - particularly GDPR, CCPA/CPRA, LGPD, and the broader wave of national data protection laws.
Where CISM asks "how do you govern security risk?", CDPSE asks "how do you build privacy into systems, processes, and data flows by design?" It is aimed at engineers, architects, and technical GRC practitioners who need to translate privacy requirements into technical and operational controls, not just policy documents.
CDPSE covers three domains:
- Domain 1: Privacy Governance (34%) - Privacy program frameworks, policies, data inventories, vendor risk, regulatory requirements, privacy impact assessments (PIAs/DPIAs)
- Domain 2: Privacy Architecture (36%) - Privacy-enhancing technologies (PETs), data minimization, access controls, identity management, secure development practices, cloud privacy considerations
- Domain 3: Data Lifecycle (30%) - Data classification, collection controls, retention, deletion, cross-border transfer mechanisms, data subject rights fulfillment
The exam is 120 questions over 3.5 hours with the same scaled scoring system as CISM (450/800 passing score). Experience requirement is 3 years of work experience in data privacy, across at least two of the three CDPSE domains - a lower bar than CISM's 5-year requirement. Exam fees are the same: $575 for ISACA members, $760 for non-members.
Head-to-Head Comparison
| Factor | CISM | CDPSE |
|---|---|---|
| Issuing body | ISACA | ISACA |
| Launched | 2002 | 2020 |
| Focus | Security program management and governance | Privacy by design, data governance, privacy architecture |
| Number of domains | 4 | 3 |
| Exam questions | 150 | 120 |
| Exam duration | 4 hours | 3.5 hours |
| Passing score | 450/800 (scaled) | 450/800 (scaled) |
| Experience requirement | 5 years IS experience, 3 in management | 3 years in data privacy (2 of 3 domains) |
| Exam fee (member) | $575 | $575 |
| Exam fee (non-member) | $760 | $760 |
| CPE for renewal | 120 CPE over 3 years | 120 CPE over 3 years |
| Annual maintenance (member) | $45/year | $45/year |
| Market recognition | Very high - 20+ years established | Growing - newer but regulatory tailwind |
| Primary audience | Security managers, program leads, GRC directors, CISO track | Privacy engineers, DPO-adjacent roles, GRC analysts, compliance architects |
The structural similarities are not a coincidence - ISACA deliberately built CDPSE with the same exam infrastructure, CPE model, and scoring methodology as its older credentials. If you already hold CISM, the mechanics of maintaining CDPSE will feel identical.
Career Paths: Who Each Cert Is For
CISM is built for the security management track
CISM holders tend to cluster in roles where the primary accountability is the overall health of the security program - not individual technical controls, and not privacy compliance specifically. The typical CISM career arc runs through security manager, security program manager, GRC manager, director of information security, and eventually CISO. Employers use CISM as a filter on job postings for security leadership roles the way they use CPA for accounting leadership.
If the job description includes words like "security program", "risk governance", "security strategy", or "board reporting", CISM is probably explicitly listed or strongly preferred. According to job posting analysis from LinkedIn and Indeed in 2026, CISM appears in roughly 35-40% of security manager and director job postings at mid-to-large enterprises.
CDPSE is built for the privacy engineering and data governance track
CDPSE holders tend to occupy roles that live at the intersection of privacy law, technical systems, and risk management. Common titles: Privacy Engineer, Data Privacy Manager, Privacy Architect, DPO (Data Protection Officer), Chief Privacy Officer at smaller organizations, and Compliance Architect with a privacy focus. The credential is also appearing in GRC analyst job descriptions at larger firms that have built dedicated privacy teams in response to GDPR and CCPA enforcement.
CDPSE's shorter history means it does not yet appear in job postings at the same frequency as CISM, but enforcement actions by data protection authorities in the EU, US, and UK are driving rapid adoption. Organizations that have experienced regulatory scrutiny are increasingly treating CDPSE as a hard requirement for privacy program roles.
Salary Comparison
CISM has a longer track record and clearer salary data. CDPSE is newer, so compensation benchmarks are still stabilizing, but the 2025-2026 data is instructive.
| Credential | Typical US Role | Median Total Comp (2026) | Typical Range |
|---|---|---|---|
| CISM | Information Security Manager | $155,000 | $130K - $185K |
| CISM | Director, Information Security | $215,000 | $180K - $265K |
| CISM | CISO | $285,000+ | $240K - $450K+ |
| CDPSE | Privacy Engineer | $125,000 | $100K - $155K |
| CDPSE | Data Privacy Manager | $140,000 | $115K - $170K |
| CDPSE | Data Protection Officer | $165,000 | $130K - $210K |
| CISM + CDPSE | GRC Director / Privacy Lead | $185,000 | $155K - $235K |
CISM currently commands a higher ceiling because its holders concentrate in senior security management roles where pay scales are mature and well-established. CDPSE salaries are growing: the European enforcement environment alone has created strong demand for practitioners who can demonstrate technical privacy competence via a recognized credential, and US state privacy laws are extending that demand domestically.
The dual-credential premium is real. In GRC-adjacent job postings that mention both certifications - or that describe roles spanning security governance and privacy compliance - compensation benchmarks run approximately 15-20% above single-credential peers with equivalent experience. This is consistent with what ISACA's own compensation surveys show for professionals holding multiple ISACA credentials.
Should GRC Professionals Pursue Both?
This is the question that matters most for security managers and GRC practitioners who are already on the CISM track or already hold CISM. The honest answer: yes, if your role touches privacy regulation or if your organization has a privacy program. Here is the specific reasoning:
The regulatory environment has changed the calculus
Before GDPR enforcement teeth arrived in 2018-2019, security managers could treat privacy as a legal department problem. That is no longer viable. Supervisory authorities in the EU (particularly the Irish DPC, CNIL in France, and the German state DPAs) have repeatedly fined organizations where the technical implementation of privacy controls was inadequate - not just the policy documentation. CCPA/CPRA enforcement in California follows a similar pattern. The technical gap between "we have a privacy policy" and "our systems enforce data subject rights, minimize collection, and maintain a documented data map" is exactly the gap CDPSE is designed to close.
A CISM-holding GRC director who also holds CDPSE can credibly lead both the security governance conversation with the board and the privacy architecture conversation with engineering. That combination commands a meaningful premium in GDPR-regulated industries (financial services, healthcare, ad-tech) and in organizations that are building privacy programs from the ground up.
The knowledge overlap reduces the incremental study burden
CISM Domain 1 (Governance) and CDPSE Domain 1 (Privacy Governance) cover related ground. If you understand how to build a security governance framework, adapting that knowledge to privacy governance is a lateral translation, not a from-scratch effort. Similarly, risk assessment methodology from CISM Domain 2 maps directly to Privacy Impact Assessments in CDPSE Domain 1. Experienced CISM holders typically report needing 80-120 hours of dedicated study to be ready for CDPSE, compared to the 150-200 hours a privacy-adjacent professional without CISM requires.
When not to pursue both
If your role is purely technical security (SOC operations, penetration testing, cloud security engineering) or purely security architecture with no governance accountability, CDPSE will not move the needle on your career trajectory or compensation. In that case, CISSP or a cloud security certification is a better use of study time. Similarly, if you work in a small organization with no dedicated privacy program and no regulatory exposure under GDPR or state privacy laws, the credential has limited practical value in the near term.
Preparing for CISM First?
Practice with thousands of expert-verified CISM-style questions and AI-powered gap analysis. Built by the team behind CISSP Study Group.
Start Free 7-Day Trial âDecision Framework: Which to Get First
Use this framework to pick your path:
| Your Situation | Recommended Path |
|---|---|
| 5+ years in security management, targeting CISO or security director roles | CISM first, consider CDPSE as a second credential if your org has privacy exposure |
| 3+ years in privacy-adjacent work, data governance, or compliance engineering | CDPSE first, then CISM if moving toward a security management track |
| GRC practitioner with both security and privacy responsibilities | CISM first (higher market recognition, broader management utility), then CDPSE within 18-24 months |
| DPO or Chief Privacy Officer at a regulated entity | CDPSE, pair with CIPP/E (from IAPP) for legal-regulatory coverage |
| Security manager at a company with active GDPR or CCPA obligations | CISM first for the management credential, then CDPSE for regulatory credibility |
| Early-career, under 3 years experience | Neither yet - focus on CISA or a foundation credential, then revisit |
One practical note on sequencing: ISACA's membership and CPE infrastructure is shared across all its credentials. Holding both CISM and CDPSE means maintaining one ISACA membership and earning CPE hours that count toward both credentials simultaneously, as long as the activities are relevant to the credential domains. The marginal cost of a second ISACA credential is lower than it looks on paper.
Frequently Asked Questions
Is CDPSE harder than CISM?
Most candidates who have sat both report that CISM is the harder exam - not because the material is more complex, but because CISM's management-judgment questions are more scenario-dependent and harder to prepare for through memorization. CDPSE has a stronger technical component (Privacy Architecture domain) that can be studied more systematically. That said, CDPSE is not easy: candidates without hands-on privacy engineering experience often struggle with the architecture domain specifically.
Does holding CISM help with CDPSE preparation?
Yes, meaningfully. The governance frameworks, risk assessment methodology, and policy hierarchy knowledge from CISM carry directly into CDPSE Domain 1 (Privacy Governance). CISM holders typically reduce their CDPSE prep time by 30-40% compared to candidates approaching the exam without a governance background. The ISACA exam format and question style are also identical, which removes one source of surprise.
Can CDPSE CPE hours count toward CISM renewal?
Yes. ISACA allows CPE hours earned across its credentials to count toward each credential's renewal requirement, provided the activity is relevant to that credential's domain content. Privacy governance activities will typically qualify for CISM's governance and risk domains; technical security activities will qualify for CDPSE's architecture and lifecycle domains. ISACA's CPE tracking portal handles this multi-credential allocation. See our CPE activities guide for examples of qualifying activities.
How does CDPSE compare to CIPP/E for a DPO role?
They are complementary, not competing. CIPP/E (from IAPP) tests knowledge of European privacy law - the regulatory requirements, the legal basis for processing, the supervisory authority structure. CDPSE tests the technical implementation of privacy controls. A DPO at a European-regulated entity ideally holds both: CIPP/E for legal credibility and CDPSE for demonstrating that technical controls are actually built correctly. If you can only have one, CIPP/E carries more regulatory recognition in EU contexts; CDPSE carries more weight in technical and engineering org structures.
Is CDPSE recognized in job postings the way CISM is?
Not yet, but the gap is closing. CISM appears in job postings at significantly higher frequency due to its 20-year head start. CDPSE is growing fastest in financial services, healthcare IT, and technology companies with EU operations - industries where GDPR enforcement is a live operational concern. By 2026, CDPSE appears in roughly 8-12% of privacy manager and privacy engineer job postings at enterprise organizations, and that share has been growing year-on-year since 2022.
What is the total cost to hold both CISM and CDPSE?
One-time: approximately $1,150-$1,520 in exam fees (assuming ISACA membership, which saves $185 per exam and also unlocks discounted study materials). Annual: $45/year ISACA membership plus $45/year per credential maintenance fee = $135/year total. Over a 3-year renewal cycle, the all-in cost of maintaining both credentials is approximately $455, which is a near-trivial figure compared to the compensation premium documented above. See our CISM cost breakdown for a more detailed model.
Related Guides
CISM vs CRISC (2026)
Both are ISACA credentials. CRISC focuses on IT risk and control; CISM on security management. Which to pursue first for a GRC career.
CISM vs CGEIT (2026)
CGEIT is ISACA's IT governance credential for senior leaders. How it compares to CISM for executive-track security professionals.
CISM vs CISA (2026)
CISA is ISACA's audit credential. Side-by-side comparison of exam, salary, and career paths for audit-vs-management roles.
CISM Renewal Requirements
120 CPE hours over 3 years. Full guide to qualifying activities, fees, and how to stack credit across multiple ISACA credentials.