Certification news
Exam change

CISM exam moves to a new content outline on November 3, 2026

ISACA keeps the four CISM domains, shifts one point of weight from Incident Management to Governance, and adds enterprise architecture and information security architecture.

What changes

ISACA announced the update in a press release dated September 10, 2026. The four CISM domains stay the same. Only the share of questions per domain changes, and only slightly.

Domain 1, Information Security Governance, goes from 17 to 18 percent. Domain 2, Information Security Risk Management, stays at 20 percent. Domain 3, Information Security Program, stays at 33 percent. Domain 4, Incident Management, goes from 30 to 29 percent.

ISACA also says the exam will put greater emphasis on information security strategy and program development. It adds two new content areas: enterprise architecture and information security architecture. ISACA links this to the need to understand the technologies under a security manager's purview.

When the new outline applies

The new Exam Content Outline is effective November 3, 2026. From that date, the CISM exam reflects the new outline. If you sit the exam on or before November 2, 2026, you are tested on the 2022 outline. That is the outline ISACA still shows on its CISM Exam Content Outline page, with weights of 17, 20, 33 and 30 percent across 150 questions.

ISACA's support FAQ on the job practice update gives the same date and shows the 2022 and 2026 weights side by side.

What ISACA has not published yet

As of October 1, 2026, ISACA has not published the detailed subtopics or task statements for the 2026 outline. The CISM Exam Content Outline page still lists the 2022 subtopics and task statements, with a note that the outline will be updated on November 3, 2026. The press release and the support FAQ give the new domain weights, the two new content areas and the shift in emphasis, but no topic list.

This means nobody outside ISACA can yet say exactly where the architecture content sits within the domains or which 2022 task statements will be reworded.

What it means for your study

If your exam is on or before November 2, 2026, study the 2022 outline as published on ISACA's page. Nothing changes for you.

If your exam is on or after November 3, 2026, the structure you already know still holds. The domains are the same and the weights move by one point at most. Plan for more weight on security strategy and on building and running a security program. Add enterprise architecture and information security architecture to your plan, at the level a security manager needs to oversee them.

ISACA notes that older study materials may not reflect updated exam content or question styles, and that legacy materials will not be updated for the new outline. Check the publication date of anything you use.

How Exam Espresso handles it

Exam Espresso's CISM questions already follow the new domain weights; when ISACA publishes the detailed topic list, the question bank will be reviewed against it and an update note will be posted here.

Prepare for CISM

More updates

Topical Requirement

Third-Party Topical Requirement takes effect, CIA testing starts no earlier than March 2027

The IIA's Third-Party Topical Requirement took effect on September 15, 2026. Scored CIA questions on a new Topical Requirement appear at least six months after its effective date, so not before March 15, 2027. The IIA's CIA exam reference list says testing starts in March 2027. The CIA syllabus itself has not changed. The Cybersecurity Topical Requirement is already in scope.