All resources
CISM·6 min read

The CISM exam changes November 3, 2026: what's new and when to test

ISACA's refreshed CISM exam content outline takes effect November 3, 2026, adding enterprise and information security architecture and sharpening the exam's strategy and program focus. What is changing, and how to decide when to sit.

On November 3, 2026, ISACA's refreshed CISM exam content outline takes effect. The structure is unchanged, four domains and 150 questions, but the update adds two content areas that were not on the outline before and shifts emphasis toward program and strategy. If your test date lands anywhere near the transition, here is what changes, what does not, and how to decide when to sit the exam.

The CISM exam today

The outline that has governed the exam since June 2022 splits the 150-question exam across four domains: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%). The exam runs four hours with a scaled passing score of 450 out of 800. The authoritative reference is ISACA's CISM exam content outline page, which publishes the current outline along with notice of the November 3 change. ISACA sets out the incoming weights, and what else is changing, in its CISM job practice update.

What changes on November 3

The clearest shift is emphasis rather than arithmetic. Domain weights barely move: Information Security Governance goes from 17% to 18% and Incident Management from 30% to 29%, while Information Security Risk Management (20%) and Information Security Program (33%) hold their weight. If you have been allocating study time by weight, very little reallocation is needed; the change that matters is content.

The second change is additive: two new content areas, enterprise architecture and information security architecture, join the outline. ISACA does not assign them to a single domain, and frames them as reflecting the need to understand the technologies under a security manager's purview. This is not a stray addition. NIST SP 800-39, Managing Information Security Risk, frames enterprise risk management as a three-tier model: an organization tier that sets governance and risk tolerance, a mission and business process tier where an enterprise architecture with an embedded information security architecture gets built, and an information system tier where controls actually get implemented. ISACA's update is asking CISM candidates to own that middle tier explicitly, not just inherit its output as a given. A security manager is expected to understand how the technology architecture underneath a security program is built, not only how to govern and respond around it.

What is not changing: the exam stays 150 questions, four hours, the same 450-out-of-800 scaled passing score, and the same four top-level domain names. This is an addition and an emphasis shift within the existing structure, not a new exam format or a reset of domain weights.

Test before or after November 3?

If you are already deep into preparation on the current outline, test before November 3. Absorbing the two new architecture content areas and the shifted emphasis days before your exam window opens is not an efficient use of the time you have left, and the current outline is what your exam will measure until the change takes effect.

If you are starting now or testing in 2027, prepare against the new outline from day one. Pull the updated outline from ISACA, and confirm any study materials you buy state they cover the post-November-2026 objectives, including the two new architecture content areas. ISACA has said updated official preparation material becomes available for purchase in September 2026, which means most third-party study guides will lag the outline by weeks or months.

Either way, the credential itself does not change. A CISM earned under either outline carries the same designation and the same continuing-education requirements.

How to study the new material

Enterprise architecture and information security architecture are conceptual, cross-cutting topics rather than a discrete tool or procedure, which makes them easy to read about and hard to retain under exam pressure. That is exactly the kind of content spaced repetition is built for: each concept becomes a card that resurfaces on a schedule until it sticks, instead of fading a week after you read it once. Our explainer on why spaced repetition beats cramming covers the mechanics.

Because Information Security Program is the single largest domain and the two new architecture content areas lean on overlapping program concepts, mixing practice questions across those domains rather than drilling one at a time will also serve you better than blocked review; see our piece on why interleaved practice beats studying one domain at a time.

TierOne Defense Academy's CISM question bank and flashcards track the official ISACA outline, every question cites a public source, and the AI tutor can unpack any explanation you want to go deeper on. See the CISM prep page for one fully unlocked CISM domain free, up to 35 questions, no credit card, so you can gauge where you stand before the outline changes.

Not affiliated with or endorsed by ISACA. CISM is a registered trademark of ISACA. Outline details summarized from ISACA's published exam content outline; the ISACA page is authoritative if details change.