CISM vs CRISC: Which ISACA Certification Should You Get First?

Updated July 2026 · 10 min read

📋 Table of Contents

  1. Quick Comparison Table
  2. What CISM Covers
  3. What CRISC Covers
  4. Exam Format and Structure
  5. Experience Requirements
  6. Domains Side-by-Side
  7. Salary and Career Impact
  8. Which Should You Get First?
  9. Can You Hold Both?
  10. Frequently Asked Questions
🎯 Quick Answer Get CISM first if you are a current or aspiring security manager with 5+ years in information security and at least 3 in a management role. Get CRISC first if you work in IT risk, GRC, or audit, have 3+ years of relevant experience, or are not yet at the management level that CISM requires. The two certifications are complementary - many senior IS leaders hold both, and CRISC qualifies as a 1-year experience waiver toward CISM.

Quick Comparison: CISM vs CRISC

Factor CISM CRISC
Full Name Certified Information Security Manager Certified in Risk and Information Systems Control
Focus Security governance and program management IT risk identification, assessment, and control
Domains 4 (Governance, Risk, Program, Incident) 4 (Risk ID, Assessment, Response, Monitoring)
Exam Length 150 questions, 4 hours 150 questions, 4 hours
Passing Score 450 / 800 (scaled) 450 / 800 (scaled)
Experience Required 5 years IS, with 3 in security management 3 years IT/IS, with 3 in risk management/control
Exam Fee $575 member / $760 non-member $575 member / $760 non-member
CPE Maintenance 120 hours / 3 years (20/year minimum) 120 hours / 3 years (20/year minimum)
Annual Fee $45 member / $85 non-member $45 member / $85 non-member
Typical Salary Range $130,000 - $195,000+ $115,000 - $170,000
Primary Career Path CISO, Security Director, IS Manager IT Risk Manager, GRC Manager, Risk Analyst
CISSP Waiver Value Earns 1 year CISSP experience waiver Did not survive ISC2's April 2026 waiver cut

What CISM Covers

The Certified Information Security Manager (CISM) is ISACA's senior management credential. It certifies that a professional can build and govern an enterprise information security program - not just execute technical controls, but manage the people, processes, budgets, and board-level reporting that keep a security function running.

CISM holders are expected to answer questions like: How does our security program align with organizational risk appetite? What is the board's exposure from an unpatched critical system? How do we structure incident response when a breach hits? What governance frameworks should govern our security policy hierarchy?

The credential is explicitly managerial. ISACA designed it for people who have already moved out of individual-contributor technical roles and into leadership of a security function. It pairs naturally with job titles like Information Security Manager, Director of Security, Deputy CISO, and CISO.

💡 CISM and CISSP Relationship CISM and CISSP are the two most commonly paired senior security certifications. CISM is narrower (governance and management only), while CISSP is broader (eight technical and management domains). Many CISOs hold both. CISM qualifies as a 1-year experience waiver toward CISSP eligibility. See our CISM vs CISSP guide for a full comparison.

What CRISC Covers

The Certified in Risk and Information Systems Control (CRISC) is ISACA's IT risk management credential. Where CISM focuses on running a security program, CRISC focuses on identifying, assessing, and controlling the IT risks that affect an enterprise - including but not limited to security risks.

CRISC holders work at the intersection of business operations and IT risk. They build risk registers, run risk assessments using frameworks like COBIT and NIST RMF, design controls to mitigate identified risks, and report on risk posture to management. The credential is more analytical and less leadership-oriented than CISM.

A useful distinction: a CRISC holder tells the organization what its IT risks are and how exposed it is. A CISM holder decides what to do about it and owns the program that does so. In practice, many senior professionals need both perspectives - which is why the two credentials appear together in many job descriptions for Director-level and above roles.

CRISC is also common in consulting, internal audit, and enterprise risk management functions outside of pure security teams. Big 4 and risk advisory professionals frequently hold it alongside CISA.

Exam Format and Structure

The exam mechanics are identical: both CISM and CRISC use 150 multiple-choice questions, a 4-hour window, and ISACA's scaled scoring system with a passing score of 450 out of 800. Both are delivered via Prometric testing centers worldwide and through remote proctoring.

The question style is also similar - ISACA writes scenario-based items that test judgment rather than memorization. Candidates are asked what a manager or risk professional would do in a given situation, not what a specific technical control does. The correct answer is usually the most conservative, governance-aligned, or stakeholder-informing choice.

The key experiential difference is what the scenarios assume about the test-taker's position. CISM scenarios place you in the role of a security manager making decisions for an organization. CRISC scenarios place you in the role of a risk analyst evaluating exposures and recommending responses. Both require reading comprehension and the ability to filter out technically correct but managerially wrong answers.

⚠️ Common Failure Mode on Both Exams Technical security professionals frequently fail both CISM and CRISC by applying a technical mindset to management scenarios. The "right" answer from a security engineering perspective is often not the "right" answer from ISACA's management/governance perspective. Both exams test what you should do as a decision-maker, not as a practitioner.

Experience Requirements

This is the most important practical difference for candidates deciding which to pursue first.

CISM Experience Requirements

CISM requires 5 years of information security work experience, with at least 3 of those years in information security management (managing security programs, teams, or functions - not general IT management). Experience must be earned within the 10 years prior to application or within 5 years of passing the exam.

ISACA allows up to 2 years of substitution toward the 5-year requirement through other credentials. A CISSP waives 1 year; combining CISSP with CRISC, a qualifying graduate degree, or another approved certification reaches the 2-year maximum. This reduces the floor to 3 years of IS experience, all of which must include the management component.

CRISC Experience Requirements

CRISC requires 3 years of cumulative work experience in IT/information systems risk management and control, spanning at least two of the four CRISC domains. At least one of those two domains must be Domain 1 (IT Risk Identification) or Domain 2 (IT Risk Assessment).

Crucially, CRISC does not require management experience. Risk analysts, GRC specialists, internal auditors, and IT professionals with relevant risk responsibilities qualify. This makes CRISC accessible to mid-career professionals who are not yet in formal management roles - typically 3-4 years into their IS career versus the 5+ that CISM demands.

Experience Factor CISM CRISC
Total years required 5 years (in IS) 3 years (in IT/IS risk or control)
Management experience required? Yes - 3 years in security management No - risk/control experience qualifies
Minimum with waivers 3 years (with CISSP + CRISC or equivalent) 3 years (no waivers available)
Lookback window 10 years prior to application 10 years prior to application
Typical eligibility stage Mid-to-senior security manager Mid-career risk/GRC professional

Domains Side-by-Side

The four domains of each certification reveal exactly what each one tests.

CISM Domains (150 questions)

Domain Weight Questions (~)
1. Information Security Governance 17% ~26
2. Information Security Risk Management 20% ~30
3. Information Security Program 33% ~50
4. Incident Management 30% ~45

CRISC Domains (150 questions)

Domain Weight Questions (~)
1. IT Risk Identification 26% ~39
2. IT Risk Assessment 20% ~30
3. Risk Response and Mitigation 32% ~48
4. Risk and Control Monitoring and Reporting 22% ~33

Both certifications dedicate a substantial domain to risk - CISM's Domain 2 (Information Security Risk Management, 20%) and CRISC's Domains 1 and 2 (IT Risk Identification and Assessment, 46% combined). The knowledge overlaps meaningfully, which is one reason holding both certifications reduces total study time: you are not starting from zero on the second credential.

The key divergence is CISM's focus on program development and incident management (63% combined) versus CRISC's focus on risk response, mitigation, and monitoring (54% combined). CISM tests how you build and run a security function. CRISC tests how you quantify, respond to, and report on risk.

Salary and Career Impact

Both credentials carry meaningful salary premiums over uncertified peers, but CISM holders consistently earn more at the median because the certification is concentrated in management roles that are structurally higher-paying.

Certification Median US Total Comp (2026) Typical Range Primary Roles
CISM ~$170,000 $130K - $195K+ IS Manager, Director, Deputy CISO, CISO
CRISC ~$145,000 $115K - $175K IT Risk Manager, GRC Manager, Risk Analyst
CISM + CRISC ~$180,000+ $155K - $220K+ Director, VP Risk, CISO with risk governance focus

The gap between median CISM and median CRISC compensation reflects role mix more than certification value. Senior CRISC holders in risk director or enterprise risk leadership positions earn well above $170,000 - the CRISC median is pulled down by the broader range of roles its holders occupy, including risk analyst and GRC specialist positions that are earlier-career.

In financial services, healthcare, and federal contracting - the industries that most aggressively require ISACA credentials - CRISC is often listed alongside CISM for senior risk and governance roles. A Director of IT Risk at a bank holding both credentials regularly earns $185,000 - $240,000 total compensation.

Which Should You Get First?

The decision comes down to four factors: your current experience level, your current job function, your target career destination, and how quickly you can satisfy eligibility requirements.

Get CISM First If:

Get CRISC First If:

✅ The CRISC-First Strategy for Aspiring CISMs If you are in a risk or GRC role and expect to be eligible for CISM in 2-3 years, pursuing CRISC now is a smart bridge strategy. CRISC satisfies your employer's near-term credential requirement, signals commitment to the ISACA track, and counts as a 1-year experience waiver when you eventually apply for CISM. You also reduce total study time because CISM's Domain 2 overlaps with CRISC material you will have already mastered.

The Decision Framework

Your Situation Recommended First Cert
5+ years IS, 3+ in management CISM - you are eligible now
3-5 years IS, in risk/GRC/audit role CRISC - closer to eligibility, more relevant to current work
3-5 years IS, in a security engineering or analyst role Either: CRISC if risk-adjacent, or CISSP to build the management credential foundation
Already hold CISSP CISM first (CISSP waives 1 year of CISM experience, reducing requirement to 4 years minimum)
Already hold CRISC CISM next (CRISC waives 1 year of CISM experience if you combine it with another qualifying credential)
Targeting CISO in the next 5 years CISM first, then CRISC to round out risk depth
Targeting VP/Director of IT Risk CRISC first, then CISM to add management credential weight

Preparing for CISM or CRISC?

Practice with thousands of expert-verified ISACA-style questions and AI-powered gap analysis. Built by the team behind CISSP Study Group.

Start Free 7-Day Trial →

Can You Hold Both CISM and CRISC?

Yes - and for senior IS risk leaders, holding both is increasingly common and genuinely valuable. The certifications are complementary, not redundant. Together they demonstrate that you can both manage a security function (CISM) and rigorously assess and quantify the risk that function manages (CRISC).

The maintenance overhead is the same: 120 CPE hours per 3-year cycle for each, with a 20-hour annual minimum per certification. The annual fees are also the same. Many professionals earn their CPE hours with activities that count toward both certifications simultaneously, since the content areas overlap in risk management and governance.

Common sequences for dual holders:

For more on experience requirements and stacking ISACA credentials, see our CISM experience waiver guide and our CISM vs CISA comparison.

Frequently Asked Questions

Is CISM harder than CRISC?

Both exams have a similar difficulty profile: 150 scenario-based questions, 4 hours, a passing score of 450/800. ISACA does not publish official pass rates by credential, but anecdotally CISM is considered slightly harder by candidates who have sat both, primarily because CISM's scenarios assume a management decision-making context that is unfamiliar to technical professionals. Candidates who come from a risk and GRC background often find CRISC more intuitive.

Does CRISC count toward CISM experience?

Yes. ISACA allows up to 2 years of experience substitution toward CISM's 5-year requirement via other certifications and credentials. Holding CRISC contributes to that maximum when combined with another qualifying credential (such as CISSP). CRISC alone does not satisfy the management experience portion of CISM's requirement - that 3-year management component must come from actual work experience.

Which ISACA certification pays more - CISM or CRISC?

CISM holders earn a higher median total compensation than CRISC holders, primarily because CISM is concentrated in management roles that pay more structurally. However, senior CRISC holders in enterprise risk director and VP roles at financial institutions can earn above the CISM median. The better question is which credential aligns with the role you want - the salary follows the job title, not just the letters after your name.

Can I use CRISC to waive CISM experience?

Partially. CRISC is one of the credentials that can contribute to CISM's 2-year maximum experience substitution, but it must be combined with at least one other qualifying credential (CISSP, CISA, or an approved graduate degree) to reach the maximum. CRISC alone does not waive a full year on its own under current ISACA rules.

Is CRISC recognized outside of IT risk roles?

CRISC is broadly recognized in financial services, healthcare, federal contracting, and consulting. It is particularly valued in Big 4 and advisory firms where risk assessment and control evaluation are core service lines. Outside those industries, CISM carries stronger name recognition for security management roles. CRISC is less well-known in pure technology companies where CISSP, CISM, or cloud security credentials tend to dominate job postings.

What is the total cost to get both CISM and CRISC?

Exam fees are identical: $575 per exam as an ISACA member, $760 as a non-member. If you join ISACA ($135/year), you save $185 per exam - the membership pays for itself on a single exam. Annual maintenance for each active certification costs $45 (member) or $85 (non-member). Holding both costs approximately $90-$170 per year in maintenance fees, not counting CPE course costs. Many employers reimburse exam fees and CPE expenses for ISACA certifications.

CISM vs CISSP (2026)

Side-by-side comparison of the two most common senior security certifications - exam, salary, and career path.

CISM vs CISA (2026)

Security managers vs auditors - which ISACA credential is right for your career direction?

CISM Experience Waiver Guide

How CISSP, CRISC, and other credentials reduce CISM's 5-year experience requirement.

CISM Salary 2026

Full salary breakdown by experience, title, and geography for CISM-certified professionals.