MYCPE ONE

Certified Information Security Manager® (CISM®) CPE Requirements

Know Your Requirement

Overview

Last Reviewed on: 31 Oct, 2025

CPE Requirements
A minimum of 20 CPE hours annually and 120 hours over a three-year reporting cycle.
License Renewal Period
Certification must be renewed annually by December 31 with reporting of CPE hours and payment of the maintenance fee.
CPE Reporting Cycle
The annual reporting period begins January 1 each year. For new CISMs, the cycle begins January 1 of the year after certification.
Ethics Requirement
No minimum ethics requirement for CISM® designation holders, but required to comply with ISACA’s Code of Professional Ethics. 
Carry Over Credits
No credit may be carried over from excess hours earned during a reporting period.
Subject Area Restriction
No minimum content requirement.

Need guidance with compliance requirements?

Speak with our Compliance Advisor

compliance requirements

Simplifying Regulations for 2026

CPE Requirement
CISMs are required to complete 20 CPE hours annually, and 120 CPE hours over three years are required.
Initial CPE Hours
Newly certified CISMs begin their cycle on January 1 of the following year. Hours attained between the date of certification and 31 December of that year can be used and reported as hours earned in the initial reporting period.
Ethics Requirement
There is no minimum ethics requirement for CISM® designation holders, but they are required to comply with ISACA’s Code of Professional Ethics.
Subject Areas
Approved subject areas include Information security governance, information security risk assessment, information security risk response, information security program development, information security program management, incident management readiness, and more.
Learning Modes
All CPE can be completed through self-study.
Eligible Learning Activities
Activities include ISACA & Non-ISACA Professional activities & meetings (no limit), self-study courses (no limit), Vendor sales/marketing presentations (10-hour annual limitation), Publication of articles, monographs, and books (no limit), and more.
CPE Deadline
All CPE hours and maintenance fees must be submitted by December 31 each year.
Reporting PeriodAnnual reporting runs from January 1 to December 31. The three-year cycle is also tracked. 
License Renewal
The cost of the annual maintenance fee is US$45 for ISACA members and US$85 for non-members.

Do MYCPE ONE Courses Qualify for CPE in CISM®?

Yes, MYCPE ONE offers Continuing Professional Education courses for CISM® with a focus on quality learning across approved subject areas. While providers are not required to be NASBA-approved, it is recommended since NASBA certification signals adherence to industry standards. MYCPE ONE also specializes in various learning formats, including -    

  • Group Live Programs,   
  • Group Internet-based, and   
  • QAS Self-Study

You can verify our NASBA sponsorship under MY-CPE LLC on the NASBA Registry. For convenient access to our courses, click here to explore the MY-CPE course catalog. We offer an all-inclusive subscription model, similar to Netflix, where a single subscription gives you access to the most extensive online course catalog. Plus, our subscription rates are 60% lower than those of other platforms. Subscribe today!

Contact Information for ISACA

ISACA
1700 E. Golf Road, Suite 400
Schaumburg, Illinois 60173, USA
Phone: +1-847-253-1545
Toll-Free: +1-855-549-2047
Customer Support: https://support.isaca.org/s/
Website: https://www.isaca.org/ 

We Review CPE Compliance Requirements Every Twelve Months

At MYCPE ONE, we are committed to providing professionals across all designations with the most accurate and up-to-date continuing education information. Our team reviews and updates the CPE requirement information for Certified Information Security Manager (CISM) every Twelve months to reflect the latest standards and policies set by the Information Systems Audit and Control Association (ISACA).

While we work diligently to ensure accuracy, we encourage professionals to confirm the requirements directly with their respective boards or credentialing authorities through the official links provided here.

Get Started with Unlimited Learning

Select your plan, complete your payment, and access a world of knowledge.

NEW YEAR
Sale Ends Soon!

Get Started Today

Start your journey towards learning and compliance.

card

$299$199 For 12 Months

Your information is securely encrypted using SSL

Get Started Today

Click Here

More Reasons to Subscribe

  • true true

    80% of Content Rated 4.5+ Stars

    High-quality content rated by professionals.
  • true true

    4X More Content at 1/3rd the Price

    Serious value compared to your regular provider!
  • true true

    Non-Sponsored Content

    Purely educational, unbiased content for your learning.
  • true true

    Monthly & Quarterly Updates

    Keeping you ahead of trends and changes.
  • true true

    Podcasts with Industry Leaders

    Learn and Earn CPE from experts on the go.
More Reasons

Frequently Asked Questions

CISMs must attain and report a minimum of 20 CPE hours annually and 120 CPE hours over a three-year reporting period.

Newly certified CISMs begin their CPE cycle on January 1 of the year following certification. Hours earned between certification and December 31 can be carried into the first cycle.

There is no minimum ethics requirement for CISM® designation holders.

Approved subject areas include Information security governance, information security risk assessment, information security risk response, information security program development, information security program management, incident management readiness and more.

Yes, CISMs can complete 100% of their CPE requirement through self-study. View more.

ISACA & Non-ISACA Professional activities & meetings (no limit), self-study courses (no limit), Vendor sales/marketing presentations (10-hour annual limitation), Publication of articles, monographs and books (no limit), and more.

The annual reporting period runs from January 1 through December 31 each year. The three-year reporting cycle is also tracked.

Yes. MYCPE ONE courses align with ISACA’s requirements and include formats such as group live, group internet-based, and QAS self-study. View More.

All CPE hours and the annual maintenance fee must be submitted by December 31.

The Annual reporting runs from January 1 through December 31.

Yes. CPE must directly apply to the management, design, or assessment of an enterprise’s information security.

CPE can be reported as they are earned on the website.

Can Certified Information Security Manager® (CISM®) professionals carry over unused CPE hours?

CISMs must retain documentation for twelve months following the end of each three-year reporting cycle.


Failure to comply with CPE requirements results in revocation of certification. Revoked individuals must retake the CISM exam to regain certification.

Yes. A random sample of CISMs is audited each year, requiring submission of supporting documentation for reported CPE activities.

CISMs may apply for retired status (age 55+ or permanently disabled) or non-practicing status.  

  • Retired CISM Status: Certified Information Security Manager (CISM®) is entitled to apply for retired CISM status if over 55 years of age and permanently retired from the CISM profession, or unable to perform the duties of an information security professional because of permanent disability. CISM granted this status is no longer required to obtain CPE hours.  
  • Non-practicing: Certified Information Security Manager (CISM®) who is no longer working in the information security profession are entitled to apply for nonpracticing CISM status. CISM granted this status are not required to obtain CPE hours but are required to pay the annual maintenance fee. Once the individual has returned to the profession, they are required to return to active status.

Non-practicing CISMs must notify ISACA and resume CPE reporting and payment to return to active status.

CPE hours are not accepted for on-the-job activities unless they fall into a specific qualifying professional education activity. Training in basic office productivity software, such as Microsoft Word or Excel, does not qualify as CPE.

Yes, MYCPE ONE courses align with ISACA’s requirements by covering subject areas related to the management, design, and assessment of enterprise information security. They are offered in multiple formats, including group live, group internet-based, and QAS self-study.

Here is a Link to the state board website to access FAQs on CPE requirements and Regulations for ERPAs