📋 Table of Contents
Quick Comparison: CISM vs CRISC
| Factor | CISM | CRISC |
|---|---|---|
| Full Name | Certified Information Security Manager | Certified in Risk and Information Systems Control |
| Focus | Security governance and program management | IT risk identification, assessment, and control |
| Domains | 4 (Governance, Risk, Program, Incident) | 4 (Risk ID, Assessment, Response, Monitoring) |
| Exam Length | 150 questions, 4 hours | 150 questions, 4 hours |
| Passing Score | 450 / 800 (scaled) | 450 / 800 (scaled) |
| Experience Required | 5 years IS, with 3 in security management | 3 years IT/IS, with 3 in risk management/control |
| Exam Fee | $575 member / $760 non-member | $575 member / $760 non-member |
| CPE Maintenance | 120 hours / 3 years (20/year minimum) | 120 hours / 3 years (20/year minimum) |
| Annual Fee | $45 member / $85 non-member | $45 member / $85 non-member |
| Typical Salary Range | $130,000 - $195,000+ | $115,000 - $170,000 |
| Primary Career Path | CISO, Security Director, IS Manager | IT Risk Manager, GRC Manager, Risk Analyst |
| CISSP Waiver Value | Earns 1 year CISSP experience waiver | Did not survive ISC2's April 2026 waiver cut |
What CISM Covers
The Certified Information Security Manager (CISM) is ISACA's senior management credential. It certifies that a professional can build and govern an enterprise information security program - not just execute technical controls, but manage the people, processes, budgets, and board-level reporting that keep a security function running.
CISM holders are expected to answer questions like: How does our security program align with organizational risk appetite? What is the board's exposure from an unpatched critical system? How do we structure incident response when a breach hits? What governance frameworks should govern our security policy hierarchy?
The credential is explicitly managerial. ISACA designed it for people who have already moved out of individual-contributor technical roles and into leadership of a security function. It pairs naturally with job titles like Information Security Manager, Director of Security, Deputy CISO, and CISO.
What CRISC Covers
The Certified in Risk and Information Systems Control (CRISC) is ISACA's IT risk management credential. Where CISM focuses on running a security program, CRISC focuses on identifying, assessing, and controlling the IT risks that affect an enterprise - including but not limited to security risks.
CRISC holders work at the intersection of business operations and IT risk. They build risk registers, run risk assessments using frameworks like COBIT and NIST RMF, design controls to mitigate identified risks, and report on risk posture to management. The credential is more analytical and less leadership-oriented than CISM.
A useful distinction: a CRISC holder tells the organization what its IT risks are and how exposed it is. A CISM holder decides what to do about it and owns the program that does so. In practice, many senior professionals need both perspectives - which is why the two credentials appear together in many job descriptions for Director-level and above roles.
CRISC is also common in consulting, internal audit, and enterprise risk management functions outside of pure security teams. Big 4 and risk advisory professionals frequently hold it alongside CISA.
Exam Format and Structure
The exam mechanics are identical: both CISM and CRISC use 150 multiple-choice questions, a 4-hour window, and ISACA's scaled scoring system with a passing score of 450 out of 800. Both are delivered via Prometric testing centers worldwide and through remote proctoring.
The question style is also similar - ISACA writes scenario-based items that test judgment rather than memorization. Candidates are asked what a manager or risk professional would do in a given situation, not what a specific technical control does. The correct answer is usually the most conservative, governance-aligned, or stakeholder-informing choice.
The key experiential difference is what the scenarios assume about the test-taker's position. CISM scenarios place you in the role of a security manager making decisions for an organization. CRISC scenarios place you in the role of a risk analyst evaluating exposures and recommending responses. Both require reading comprehension and the ability to filter out technically correct but managerially wrong answers.
Experience Requirements
This is the most important practical difference for candidates deciding which to pursue first.
CISM Experience Requirements
CISM requires 5 years of information security work experience, with at least 3 of those years in information security management (managing security programs, teams, or functions - not general IT management). Experience must be earned within the 10 years prior to application or within 5 years of passing the exam.
ISACA allows up to 2 years of substitution toward the 5-year requirement through other credentials. A CISSP waives 1 year; combining CISSP with CRISC, a qualifying graduate degree, or another approved certification reaches the 2-year maximum. This reduces the floor to 3 years of IS experience, all of which must include the management component.
CRISC Experience Requirements
CRISC requires 3 years of cumulative work experience in IT/information systems risk management and control, spanning at least two of the four CRISC domains. At least one of those two domains must be Domain 1 (IT Risk Identification) or Domain 2 (IT Risk Assessment).
Crucially, CRISC does not require management experience. Risk analysts, GRC specialists, internal auditors, and IT professionals with relevant risk responsibilities qualify. This makes CRISC accessible to mid-career professionals who are not yet in formal management roles - typically 3-4 years into their IS career versus the 5+ that CISM demands.
| Experience Factor | CISM | CRISC |
|---|---|---|
| Total years required | 5 years (in IS) | 3 years (in IT/IS risk or control) |
| Management experience required? | Yes - 3 years in security management | No - risk/control experience qualifies |
| Minimum with waivers | 3 years (with CISSP + CRISC or equivalent) | 3 years (no waivers available) |
| Lookback window | 10 years prior to application | 10 years prior to application |
| Typical eligibility stage | Mid-to-senior security manager | Mid-career risk/GRC professional |
Domains Side-by-Side
The four domains of each certification reveal exactly what each one tests.
CISM Domains (150 questions)
| Domain | Weight | Questions (~) |
|---|---|---|
| 1. Information Security Governance | 17% | ~26 |
| 2. Information Security Risk Management | 20% | ~30 |
| 3. Information Security Program | 33% | ~50 |
| 4. Incident Management | 30% | ~45 |
CRISC Domains (150 questions)
| Domain | Weight | Questions (~) |
|---|---|---|
| 1. IT Risk Identification | 26% | ~39 |
| 2. IT Risk Assessment | 20% | ~30 |
| 3. Risk Response and Mitigation | 32% | ~48 |
| 4. Risk and Control Monitoring and Reporting | 22% | ~33 |
Both certifications dedicate a substantial domain to risk - CISM's Domain 2 (Information Security Risk Management, 20%) and CRISC's Domains 1 and 2 (IT Risk Identification and Assessment, 46% combined). The knowledge overlaps meaningfully, which is one reason holding both certifications reduces total study time: you are not starting from zero on the second credential.
The key divergence is CISM's focus on program development and incident management (63% combined) versus CRISC's focus on risk response, mitigation, and monitoring (54% combined). CISM tests how you build and run a security function. CRISC tests how you quantify, respond to, and report on risk.
Salary and Career Impact
Both credentials carry meaningful salary premiums over uncertified peers, but CISM holders consistently earn more at the median because the certification is concentrated in management roles that are structurally higher-paying.
| Certification | Median US Total Comp (2026) | Typical Range | Primary Roles |
|---|---|---|---|
| CISM | ~$170,000 | $130K - $195K+ | IS Manager, Director, Deputy CISO, CISO |
| CRISC | ~$145,000 | $115K - $175K | IT Risk Manager, GRC Manager, Risk Analyst |
| CISM + CRISC | ~$180,000+ | $155K - $220K+ | Director, VP Risk, CISO with risk governance focus |
The gap between median CISM and median CRISC compensation reflects role mix more than certification value. Senior CRISC holders in risk director or enterprise risk leadership positions earn well above $170,000 - the CRISC median is pulled down by the broader range of roles its holders occupy, including risk analyst and GRC specialist positions that are earlier-career.
In financial services, healthcare, and federal contracting - the industries that most aggressively require ISACA credentials - CRISC is often listed alongside CISM for senior risk and governance roles. A Director of IT Risk at a bank holding both credentials regularly earns $185,000 - $240,000 total compensation.
Which Should You Get First?
The decision comes down to four factors: your current experience level, your current job function, your target career destination, and how quickly you can satisfy eligibility requirements.
Get CISM First If:
- You already have 5+ years of IS experience with 3+ years in a security management role
- You are currently a security manager, IS program lead, or GRC manager who wants to move to Director or CISO
- Your employer requires or strongly prefers CISM for your current role or a role you are pursuing
- You hold CISSP and want to maximize your ISACA credential stack (CISM is the natural complement)
- Your primary goal is a security management or CISO career track rather than a risk specialist track
Get CRISC First If:
- You have 3+ years in IT risk, GRC, or audit but have not yet reached a formal management role
- You work in risk consulting, internal audit, or enterprise risk management
- You do not yet meet CISM's 5-year / 3-year-management experience requirement
- Your employer (Big 4, financial services risk function, healthcare compliance) specifically values CRISC
- You want to use CRISC as a stepping stone - it counts as a 1-year experience waiver toward CISM eligibility once you earn it
The Decision Framework
| Your Situation | Recommended First Cert |
|---|---|
| 5+ years IS, 3+ in management | CISM - you are eligible now |
| 3-5 years IS, in risk/GRC/audit role | CRISC - closer to eligibility, more relevant to current work |
| 3-5 years IS, in a security engineering or analyst role | Either: CRISC if risk-adjacent, or CISSP to build the management credential foundation |
| Already hold CISSP | CISM first (CISSP waives 1 year of CISM experience, reducing requirement to 4 years minimum) |
| Already hold CRISC | CISM next (CRISC waives 1 year of CISM experience if you combine it with another qualifying credential) |
| Targeting CISO in the next 5 years | CISM first, then CRISC to round out risk depth |
| Targeting VP/Director of IT Risk | CRISC first, then CISM to add management credential weight |
Preparing for CISM or CRISC?
Practice with thousands of expert-verified ISACA-style questions and AI-powered gap analysis. Built by the team behind CISSP Study Group.
Start Free 7-Day Trial →Can You Hold Both CISM and CRISC?
Yes - and for senior IS risk leaders, holding both is increasingly common and genuinely valuable. The certifications are complementary, not redundant. Together they demonstrate that you can both manage a security function (CISM) and rigorously assess and quantify the risk that function manages (CRISC).
The maintenance overhead is the same: 120 CPE hours per 3-year cycle for each, with a 20-hour annual minimum per certification. The annual fees are also the same. Many professionals earn their CPE hours with activities that count toward both certifications simultaneously, since the content areas overlap in risk management and governance.
Common sequences for dual holders:
- CRISC then CISM - the risk analyst path: earn CRISC as a mid-career specialist, then progress to CISM as you move into management. CRISC experience substitution reduces CISM's requirement by up to 1 year when combined with other qualifying credentials.
- CISM then CRISC - the security manager path: earn CISM on the management track, then add CRISC to deepen risk quantification skills as you move toward CISO or VP-level roles where enterprise risk governance is a primary responsibility.
- Concurrent preparation - experienced professionals who are already eligible for both sometimes study and sit for both within the same 12-18 month window, using the overlapping risk domain content efficiently. This approach works best for people with 7+ years of combined security management and risk experience.
For more on experience requirements and stacking ISACA credentials, see our CISM experience waiver guide and our CISM vs CISA comparison.
Frequently Asked Questions
Is CISM harder than CRISC?
Both exams have a similar difficulty profile: 150 scenario-based questions, 4 hours, a passing score of 450/800. ISACA does not publish official pass rates by credential, but anecdotally CISM is considered slightly harder by candidates who have sat both, primarily because CISM's scenarios assume a management decision-making context that is unfamiliar to technical professionals. Candidates who come from a risk and GRC background often find CRISC more intuitive.
Does CRISC count toward CISM experience?
Yes. ISACA allows up to 2 years of experience substitution toward CISM's 5-year requirement via other certifications and credentials. Holding CRISC contributes to that maximum when combined with another qualifying credential (such as CISSP). CRISC alone does not satisfy the management experience portion of CISM's requirement - that 3-year management component must come from actual work experience.
Which ISACA certification pays more - CISM or CRISC?
CISM holders earn a higher median total compensation than CRISC holders, primarily because CISM is concentrated in management roles that pay more structurally. However, senior CRISC holders in enterprise risk director and VP roles at financial institutions can earn above the CISM median. The better question is which credential aligns with the role you want - the salary follows the job title, not just the letters after your name.
Can I use CRISC to waive CISM experience?
Partially. CRISC is one of the credentials that can contribute to CISM's 2-year maximum experience substitution, but it must be combined with at least one other qualifying credential (CISSP, CISA, or an approved graduate degree) to reach the maximum. CRISC alone does not waive a full year on its own under current ISACA rules.
Is CRISC recognized outside of IT risk roles?
CRISC is broadly recognized in financial services, healthcare, federal contracting, and consulting. It is particularly valued in Big 4 and advisory firms where risk assessment and control evaluation are core service lines. Outside those industries, CISM carries stronger name recognition for security management roles. CRISC is less well-known in pure technology companies where CISSP, CISM, or cloud security credentials tend to dominate job postings.
What is the total cost to get both CISM and CRISC?
Exam fees are identical: $575 per exam as an ISACA member, $760 as a non-member. If you join ISACA ($135/year), you save $185 per exam - the membership pays for itself on a single exam. Annual maintenance for each active certification costs $45 (member) or $85 (non-member). Holding both costs approximately $90-$170 per year in maintenance fees, not counting CPE course costs. Many employers reimburse exam fees and CPE expenses for ISACA certifications.
Related Guides
CISM vs CISSP (2026)
Side-by-side comparison of the two most common senior security certifications - exam, salary, and career path.
CISM vs CISA (2026)
Security managers vs auditors - which ISACA credential is right for your career direction?
CISM Experience Waiver Guide
How CISSP, CRISC, and other credentials reduce CISM's 5-year experience requirement.
CISM Salary 2026
Full salary breakdown by experience, title, and geography for CISM-certified professionals.