Huge Changes to the ISACA CISM Graphic
If you’ve been putting off your CISM certification, or you’re mid study right now, ISACA just gave you a hard deadline to think about. The organization has confirmed a Job Practice Update to the Certified Information Security Manager exam, with new content going live on November 3, 2026. It’s the first substantive change to the CISM exam content outline since 2022, and it reflects a real shift in what ISACA thinks security managers actually need to know today.
Below is an overview of what’s changing, a domain by domain breakdown, and the key dates and considerations for deciding whether to test before or after the cutover.

What’s actually changing

The four CISM domains aren’t going anywhere. Governance, Risk Management, Program, and Incident Management remain the backbone of the certification. What’s changing is how much weight each one carries on the exam, and what’s now explicitly in scope within them.
Domain
Current
weight
New weight
(Nov 3, 2026)
Information Security Governance 17% 18%
Information Security Risk Management 20% 20%
Information Security Program 33% 33%
Incident Management 30% 29%

The bigger story isn’t the weight shifts, which are modest, it’s the new content ISACA is folding in. Per ISACA’s own announcement, the update adds enterprise architecture and information security architecture as areas security managers are now expected to understand. The stated reasoning is straightforward: security leaders increasingly have to make governance and strategy decisions about technologies they didn’t used to need architectural fluency for, from cloud and hybrid environments to the broader digital transformation happening across most enterprises. ISACA reviews the CISM job practice on a three to five year cycle, and this update is meant to keep the credential aligned with what CISOs and security managers are actually being asked to do in 2026, not what they were doing in 2022.

Domain 1: Information Security Governance (17% to 18%)

Governance is the domain gaining the most weight, even if the shift looks small on paper. Today this domain covers enterprise governance topics like organizational culture, legal and regulatory requirements, and organizational roles and responsibilities, alongside information security strategy development, governance frameworks, and strategic planning around budgets and resources, per ISACA’s own content outline.

What’s changing: ISACA and industry analysts describe the 2026 update as putting greater emphasis on information security strategy specifically, meaning security decisions that visibly connect to business objectives, risk tolerance, and regulatory requirements, plus stronger expectations around communicating security risk to senior leadership and justifying security investment in business terms. This is also where a chunk of the new enterprise architecture content is expected to land, since governance decisions increasingly require understanding how the organization’s technology landscape is actually structured. For background on how governance and architecture intersect, ISACA’s own writing on key performance indicators for security governance and the GRC journey are useful reads even outside exam prep.

 
CISM Exam Domain Weights Graphic

Domain 2: Information Security Risk Management (20%, unchanged)

Risk Management holds steady at 20%, the only domain with no weight change at all. Its current scope covers risk assessment work (emerging risk and threat landscape, vulnerability and control deficiency analysis, risk assessment and analysis) and risk response work (treatment options, risk and control ownership, and risk monitoring and reporting), again per the official content outline.

What’s changing: none of the sources tracking this update point to a structural change here, which makes sense given the domain’s weight didn’t move. That said, the broader theme of the update, understanding technology environments well enough to govern them, still touches risk work, since assessing risk in cloud, hybrid, and SaaS heavy environments increasingly requires the same architectural literacy being added elsewhere. ISACA’s IT Risk resource hub and the CRISC certification, ISACA’s dedicated risk credential, are both worth a look if risk is where you want to go deeper than CISM alone covers.

Domain 3: Information Security Program (33%, unchanged)

Program is the largest domain by weight and stays that way. It currently spans program development, resourcing, asset identification and classification, industry standards and frameworks, policies and procedures, and program metrics, plus program management topics like control design, selection, implementation, testing, awareness and training, managing external and third-party services, and program communications and reporting, per the content outline.

What’s changing: this is the other domain expected to absorb a meaningful share of the new architecture content, since ISACA frames enterprise architecture and information security architecture as fundamentally about turning strategy into an operating program across on premises infrastructure, cloud platforms, SaaS applications, and third party services. Expect more systems thinking about how the different parts of a security program interlock across hybrid environments, not just how each control works in isolation. ISACA’s writing on information security architecture and COBIT, ISACA’s framework for governing and managing enterprise IT, both speak directly to this shift.

Domain 4: Incident Management (30% to 29%)

Incident Management loses a single point, the only domain that shrinks. Its current scope covers readiness, incident response plans, business impact analysis, business continuity and disaster recovery plans, incident classification, and training and testing, plus operations, incident tools and techniques, investigation, containment, response communications, eradication and recovery, and post incident review, per the content outline.

CISM 2026 Updates Graphic

What’s changing: none of the tracking sources report new topics being added here specifically, so the one point reduction looks like it’s simply making room for the architecture content landing in Governance and Program rather than reflecting a shrinking scope of responsibility. Incident management in practice is still getting more complex, not less, particularly around resilience planning in cloud based environments. ISACA’s guidance on business continuity and disaster recovery preparedness for cloud based start ups and on whether business continuity management is still relevant are both good supplementary reading here.

An important caveat

ISACA has confirmed the new domain weightings and named enterprise architecture and information security architecture as the two new content areas. What ISACA has not yet published, as of this writing, is the full revised task and knowledge statement list showing exactly which sub topics move where. That level of detail typically arrives with the updated study materials, which ISACA says will be available starting September 1, 2026. Treat the domain by domain notes above as the best current read on direction, not a substitute for the official outline once it’s fully published.

Key dates to know

New study materials aligned to the updated outline become available starting September 1, 2026. The new exam content outline itself takes effect November 3, 2026. If your exam is scheduled before November 3, you’re tested on the current, 2022 content outline, and your existing study materials are still the right ones to use. If you sit on or after November 3, you’ll be tested on the updated outline, including the new architecture content.

Should you test before or after November 3?

There’s no wrong answer here; the CISM credential carries the same weight regardless of which outline you pass under, so this is really a question of study efficiency, not career impact.

Testing before November 3 makes sense if you’ve already started studying against the current outline and are realistically on track to be exam-ready by late October, if you’d rather not add two new technical domains to your study plan, or if exam slots are available in your area before the deadline. Waiting for the updated outline makes more sense if you’re just starting your prep and won’t be ready in time anyway, if you already have some architecture or technical background that plays to the new content, or if you’d simply rather study the version of the exam that better reflects where the role is heading. The exam format itself isn’t changing either way: still 150 questions, a four-hour window, and a 450-point passing score.

Get ahead of the change with Cyberkraft

Whether you want to sit before the November 3 cutover or prepare directly for the updated outline once materials are available, Cyberkraft has a CISM path that fits how you like to study.

If you want live instruction and a structured pace, enroll in our ISACA CISM Bootcamp for expert-led, instructor-guided training built around the CISM job practice. If you’d rather move at your own speed, our ISACA CISM self paced course gives you full access to the video training on your own schedule. And if you still need to sit for the exam, our CISM self paced course and voucher bundle pairs the self paced training with your official ISACA exam voucher in one purchase.Whichever path you choose, the sooner you start, the more control you have over which version of the exam you sit for.

ISACA’s Certified Information Security Manager (CISM) is the standard achievement certification for expert knowledge and experience in IS/IT security and control.