Certified Information Security Manager (CISM)
Renew Your Certification
To maintain your Certified Information Security Manager (CISM) certification, you must renew it annually through the ISACA Continuing Professional Education (CPE) program. Renewal requires earning and reporting a minimum of 20 CPE hours each year and a total of 120 CPE hours over a three-year period. These credits ensure that your knowledge remains current with evolving information security management practices, IT governance, risk management, incident response, and compliance frameworks. Additionally, you must pay the annual maintenance fee and adhere to ISACA’s Code of Professional Ethics and Continuing Education Policy to keep your CISM certification in good standing.
Renewal Requirements
Complete the Recertification Requirement
To maintain your Certified Information Security Manager (CISM) certification, you must renew it annually through ISACA’s Continuing Professional Education (CPE) program. Renewal requires earning a minimum of 20 CPE hours each year and a total of 120 CPE hours over a three-year period. This ensures your skills remain current with evolving standards in information security governance, risk management, incident management, compliance, and security program management.
No Automatic Free Renewal
ISACA does not offer automatic or free renewal. You must pay an annual maintenance fee and submit your CPE hours through your ISACA account to maintain your certification in good standing. Failure to meet these requirements can result in suspension or revocation of your credential.
Stay Updated with ISACA Resources
Regularly engaging with ISACA’s online learning portal, webinars, conferences, and local chapter events helps you stay informed about emerging technologies, updated frameworks, and best practices. Active participation in the ISACA community makes earning and tracking your CPE credits easier while supporting continuous professional growth.
You can begin preparing for recertification at any time before your Certified Information Security Manager (CISM) credential expires. It is recommended to start earning and recording your Continuing Professional Education (CPE) credits well in advance to ensure you meet the annual and three-year requirements. Completing your CPE activities and paying the maintenance fee before the renewal deadline helps keep your certification active and your skills current with the latest information security management practices, governance frameworks, risk management strategies, incident response, and compliance best practices.
Why Renewal Matters
Renewing your Certified Information Security Manager (CISM) certification is essential to keeping your skills aligned with the latest developments in information security management, governance, risk management, and compliance. It demonstrates your commitment to continuous learning and professional excellence—qualities highly valued by employers, security teams, and compliance-focused organizations. Maintaining an active certification preserves your professional credibility, validates your expertise, and ensures you stay current with evolving standards, frameworks, and best practices. Allowing your certification to lapse may require reinstatement or retesting, which can be time-consuming and costly. Timely renewal helps protect your credential, advance your career growth, and uphold your professional reputation within the global information security management community.