ISACA CISMChecked against ISACA 15 September 2026

The 2026 CISM exam outline: what changes on 3 November 2026

ISACA's updated CISM exam content outline takes effect on 3 November 2026. The four domains stay, two weights move by a point, and two new content areas arrive. Here is exactly what ISACA has published, side by side with the outline it replaces, and what it means for the date you sit the exam.

Every exam fact on this page comes from an ISACA page, linked in the sources at the bottom. Where ISACA has not said something, this page does not either.

Timeline

17 June 2026

Published by ISACA

ISACA's CISM job practice update notice

The date on ISACA's support article that sets out the 2022 and 2026 domain weights side by side, the effective date, and what else changes on the exam.

1 September 2026

Published by ISACA

ISACA's updated CISM Exam Prep begins launching

ISACA's own new review materials start rolling out by language and product, and older versions of its CISM Exam Prep are removed from sale.

3 November 2026

Published by ISACA

The CISM exam reflects the 2026 outline

From this date the exam follows the updated exam content outline. After it, ISACA no longer sells extensions to existing subscriptions for its older CISM prep materials.

CISM domain weights: 2022 outline vs 2026 outline

Both columns are ISACA's published weights. The 2022 outline applies to exams before 3 November 2026; the 2026 outline applies on and after it.

Domain2022 outline2026 outlineChange
Domain 1: Information Security Governance17%18%+1 point
Domain 2: Information Security Risk Management20%20%No change
Domain 3: Information Security Program33%33%No change
Domain 4: Incident Management30%29%-1 point
Total100%100%

Source: ISACA, Certification: CISM Job Practice Update 2026.

What changes

  • • Two new content areas: enterprise architecture and information security architecture, which ISACA says reflect the need to understand the technologies under a security manager's purview.
  • • Greater emphasis on information security strategy and program development.
  • • Governance gains a point (17% to 18%) and Incident Management gives one up (30% to 29%).

What stays the same

  • • The same four domains, with Risk Management (20%) and Program (33%) at unchanged weights.
  • • ISACA's update notice announces no change to exam length or scoring. Its 2026 candidate guide lists 150 multiple-choice questions in 4 hours, with 450 on a 200 to 800 scale needed to pass.

Testing before or after 3 November 2026

ISACA ties the change to the date the exam takes place, not to when you started studying.

Exam before 3 November 2026

You are tested on the 2022 outline, the one in force since 2022. If you are already deep into preparation on it, the new content areas are not on your exam, so there is no reason to split your remaining time across them.

Exam on or after 3 November 2026

You are tested on the 2026 outline. ISACA recommends preparing with up-to-date materials and notes that older materials may not reflect updated exam content or question styles. Plan time for enterprise architecture and information security architecture from the start.

If you reschedule across the boundary, prepare for the outline in force on the day you actually sit, and confirm anything unusual with ISACA support.

How to study across the transition

Keep allocating time by weight. Information Security Program and Incident Management together are 63% of the 2022 exam and 62% of the 2026 one, so a schedule built from the blueprint barely moves. Our piece on studying by domain weight rather than comfort covers how to set that schedule.

Treat the architecture content as part of the program, not a separate silo. NIST SP 800-39 places enterprise architecture, with information security architecture embedded in it, at the mission and business process tier that sits between organizational governance and individual systems. That is the layer a security program is built on, which is a useful way to anchor the new material against the Governance and Program domains you are already studying.

Practise judgment, not recall. With more emphasis on strategy and program development, expect to choose the best of several defensible actions. Timed practice questions that ask for the BEST or FIRST step train that better than definitions do.

Pick your exam date first, then your target outline. Most of the confusion around a transition comes from studying for one outline and booking for the other.

On TierOne Defense Academy, the Readiness Read ranks a weak CISM domain by what it costs at ISACA's published weight, and the free diagnostic spreads its questions across domains by that same weight. Both switch to the 2026 weights on 3 November 2026 on their own. Our longer article on the CISM changes goes further into the new architecture content.

CISM 2026 outline FAQ

When does the new CISM exam outline take effect?

On 3 November 2026. ISACA states that from that date the CISM exam reflects the updated exam content outline, and it recommends its updated review materials to anyone preparing for an exam taking place on or after that date.

What are the 2026 CISM domain weights?

Information Security Governance 18% (was 17%), Information Security Risk Management 20% (unchanged), Information Security Program 33% (unchanged) and Incident Management 29% (was 30%). The four domains are the same four as the 2022 outline.

What else is changing on the CISM exam?

ISACA says the exam will put greater emphasis on information security strategy and program development, and adds two new content areas, enterprise architecture and information security architecture, reflecting the need to understand the technologies under a security manager's purview.

Is the CISM exam getting longer or changing how it is scored?

ISACA's update notice describes changes to content and emphasis and does not announce a change to exam length or scoring. ISACA's 2026 Exam Candidate Guide (version 1.26) lists the CISM exam as 150 multiple-choice questions in 4 hours, reported on a 200 to 800 scale with 450 needed to pass. Check the candidate guide in force for your own exam date.

I am booked before 3 November 2026. Which outline will I be tested on?

ISACA ties the change to the date the exam takes place, so an exam sat before 3 November 2026 is on the 2022 outline, and one sat on or after that date is on the 2026 outline. If you reschedule across that date, prepare for the outline in force on the day you actually sit, and confirm anything unusual with ISACA support.

Can I keep using study materials written for the 2022 outline?

For an exam before 3 November 2026, yes, that is the outline you will be tested on. For an exam on or after it, ISACA recommends the most up-to-date materials and notes that older materials may not reflect updated exam content or question styles. The domain weights barely move, so most of what you have studied still counts; the gap is the two new architecture content areas and the added emphasis on strategy and program development.

Find out where you stand before the outline changes

The free tier includes 25 practice questions spread across every exam domain, per cert, each with a cited source. No credit card.

Sources and disclaimer

  • • ISACA, Certification: CISM Job Practice Update 2026 (2022 vs 2026 weights, effective date, new content areas, prep-material dates): support.isaca.org (accessed 15 September 2026)
  • • ISACA, CISM Exam Content Outline (the outline in force before 3 November 2026): isaca.org (accessed 15 September 2026)
  • • ISACA Certification Exams Candidate Guide, version 1.26 (exam length and scoring): isaca.org (accessed 15 September 2026)
  • • NIST SP 800-39, Managing Information Security Risk: csrc.nist.gov

Not affiliated with or endorsed by ISACA. CISM is a registered trademark of ISACA. Our questions are original practice questions written from public sources, not items from the exam. ISACA's pages are authoritative if any detail here changes.