The question arrives in every study group and career thread: which one should I do? The honest answer is that CISSP, CISM, CRISC and CCSP are not four ranks on one ladder — they are four different jobs. Choose by the work you want to be doing in three years, and the decision usually makes itself.
The one-line identities
- CISSP (ISC2): the broad security practitioner-leader credential. Eight domains spanning the whole field; the default signal for senior security roles.
- CISM (ISACA): the security program manager's credential. Governance, risk, program development, incident management — running security as a business function.
- CRISC (ISACA): the risk practitioner's credential. Assessing technology risk, designing responses and controls, reporting to decision-makers.
- CCSP (ISC2): the cloud security specialist's credential. Vendor-neutral depth across cloud architecture, data, operations and the legal layer.
Side by side
| CISSP | CISM | CRISC | CCSP | |
|---|---|---|---|---|
| Body | ISC2 | ISACA | ISACA | ISC2 |
| Center of gravity | Breadth across security | Managing the program | Managing the risk | Securing the cloud |
| Exam | CAT (English), 100–150 items, ~3 h | 150 q, 4 h | 150 q, 4 h | CAT, 100–150 items, ~3 h |
| Pass mark | 700/1000 | 450/800 | 450/800 | 700/1000 |
| Experience | 5 yrs (1 waivable) | 5 yrs incl. management | 3 yrs across 2 domains | 5 yrs incl. 3 in cloud¹ |
| Typical next title | Security architect, senior engineer, CISO track | Security manager, head of security | Risk manager, GRC lead, TPRM | Cloud security architect/engineer |
¹ CISSP holders get the CCSP experience requirement waived entirely — the single most useful interaction in the whole set.
A decision framework that actually works
Start from the sentence you want on your next job description.
"Owns security architecture and decisions across the organisation" → CISSP. Its breadth is the point: it certifies that you can reason across identity, networks, software, operations and governance at once. It is also the most recognised by recruiters and HR filters, which matters early in a senior-role search.
"Builds and runs the information security program" → CISM. If your week is strategy documents, budgets, steering committees and incident governance — or you want it to be — CISM speaks that language natively. It overlaps CISSP's Domain 1 heavily but goes deeper on program management than CISSP ever does.
"Tells the business which technology risks matter and what to do about them" → CRISC. The most underrated of the four. Risk practice is its own discipline — appetite, scenarios, KRIs, registers, treatment — and regulation keeps expanding demand for people who can evidence it.
"Secures workloads, data and contracts in the cloud" → CCSP. The specialist play. Unlike vendor certifications it tests reasoning that survives a provider switch: shared responsibility, data lifecycle, cross-jurisdiction compliance. Note the August 2026 outline refresh adds explicit AI/ML security — book deliberately on one side of that date.
Then sanity-check against experience requirements. All four expect real years in the field; CRISC's three-year bar is the lowest. Every one of them lets you pass the exam first and certify when the experience completes — a legitimate strategy for career-changers.
Common sequencing patterns
The most efficient pairing in the set: CISSP first, then CCSP with the experience requirement fully waived — broad credibility plus cloud depth for one exam's extra effort.
Other patterns that work: CRISC → CISM for the governance track (same examining body, heavily overlapping worldview, escalating seniority); CISSP → CISM for practitioners moving into management who want both bodies represented; CRISC + CCSP for cloud-risk specialisation, currently scarce in the market.
The pattern that doesn't work: collecting all four quickly for the wall. Each certification's value is the role it signals; four signals at once mostly says "studies well."
The honest bottom line
If you must have one rule: choose CISSP for breadth and recognition, CISM to run programs, CRISC to run risk, CCSP to run cloud. Pick the job first. The acronym follows.