Skip to content
CISO Spotlights

Guide

CISSP vs. CISM vs. CCISO: how the three certifications actually compare

Experience bars, exam cost, domains and renewal fees for ISC2's CISSP, ISACA's CISM and EC-Council's CCISO, taken from each certifying body's own pages.

By the CISO Spotlights Desk · Published · 10 sources

This site's guide to becoming a CISO already covers why CISSP and CISM both set a five-year bar. What it doesn't cover is cost, renewal burden, or EC-Council's CCISO — the question a candidate asks once they've decided to get one of the three. The table below puts the three side by side on exactly those terms, using only what each certifying body's own site states, including where a body simply doesn't publish a figure the others do.

CISSP (ISC2)CISM (ISACA)CCISO (EC-Council)
Experience floor5 years, 2+ of 8 domains; 1 year waivable by degree or approved credential5 years in CISM job-practice areas, within the preceding 10 years5 years across all 5 domains; 5 years in 3 of 5 domains with EC-Council authorized training first
Exam100–150 questions, 3 hours, pass at 700/1000150 questions across 4 domains; time limit and passing score not stated on ISACA's own content-outline pageQuestion count and time limit not stated on EC-Council's own FAQ page
Entry exam fee$749 (Americas, standard registration)$575 member / $760 non-member, plus a $50 one-time application fee$100 eligibility-application fee (waived with authorized training), plus a separate $999 exam voucher sold through EC-Council's store
Annual renewalNot published on ISC2's exam-pricing, exam-outline or CPE-opportunities pages$45 member / $85 non-member, due every January 1$100/year continuing-education fee, per EC-Council's store listing
CPE cycleNot published on the pages above; ISC2 points to a separate Certification Maintenance Handbook120 hours over 3 years, minimum 20/yearNot stated on the FAQ page
Certification validityOngoing, subject to CPE/AMFOngoing, subject to CPE/AMF3 years, then renewed
On-ramp if under-experiencedPass the exam, become an "Associate of ISC2," finish the 5 years within 6 yearsNo lesser credential; apply within 5 years of passingInconsistent — see below

What does CCISO's five domains actually cover, compared to the other two?

CCISO reaches further into the business side of the role than either of the other two credentials. Its five domains are Governance, Risk and Compliance; Information Security Controls and Audit Management; Security Program Management and Operations; Information Security Core Competencies; and Strategic Planning, Finance, Procurement and Third-Party Management — the last of which has no direct equivalent in CISSP's eight domains or CISM's four, both of which stay closer to the security function itself.

Why does the table list EC-Council's on-ramp as "inconsistent"?

Because two parts of EC-Council's own site disagree about whether one exists. The CCISO FAQ page doesn't describe an "Associate CCISO" credential anywhere; the closest thing it names is a different program, the EC-Council Information Security Manager (EISM), which "allows students who are not yet qualified to sit for the CCISO exam to take the training course and attain an EC-Council certification," with EISM holders later able to apply to CCISO for a waived application fee and "a 50% discount from the normal CCISO Exam price." Separately, EC-Council's own store sells a product called "Associate CCISO Exam Voucher" for $999.00, plus an "Associate CCISO to CCISO Upgrade" voucher for $500.00 that requires the Associate credential to be "in good standing" first — a path the FAQ page never mentions. Rather than guess which page is the current one, this guide records both findings.

Which one is cheapest to hold, year over year?

Of the two bodies that publish an annual figure, CISM's combined $45–$85 maintenance fee is lower than CCISO's $100 continuing-education fee. ISC2 doesn't publish a comparable CISSP figure on the pages read for this guide, so a direct three-way comparison on that line isn't possible from primary sources alone — a gap worth noting on its own, since it means a prospective CISSP holder can't find their ongoing cost on ISC2's own public site the way a CISM or CCISO holder can on theirs.

Does any of this make one certification "better"?

No, and none of the three bodies claims that about its own credential either. This guide only restates what each body's own page says it requires and what it charges; it draws no conclusion about which is worth pursuing for a given career, which NETWORK-RULES' standing rule against rankings applies to here exactly as it does to the vendor directory elsewhere on the network.

Sources

  1. 1.
    ISC2, CISSP experience requirementsisc2.org · undated page · tier A
  2. 2.
    ISC2, CISSP Certification Exam Outlineisc2.org · undated page · tier A
  3. 3.
    ISC2, Exam Pricingisc2.org · undated page · tier A
  4. 4.
    ISACA, CISMisaca.org · undated page · tier A
  5. 5.
    ISACA, How to get CISM certifiedisaca.org · undated page · tier A
  6. 6.
    ISACA, CISM Exam Content Outlineisaca.org · undated page · tier A
  7. 7.
    ISACA, How do I maintain my CISM?isaca.org · undated page · tier A
  8. 8.
    EC-Council, CCISO FAQciso.eccouncil.org · undated page · tier A
  9. 9.
    EC-Council Store, CCISO Annual Continuing Education Feesstore.eccouncil.org · undated page · tier A
  10. 10.
    EC-Council Store, Associate CCISO Exam Voucherstore.eccouncil.org · undated page · tier A

Tier A: the organization itself, a regulator or a government page. Tier B: established trade or business press.

See an error? Request a correction.