- What "Exam Dates" Actually Means for the C)ISMS
- How Delivery Works: Mile2 Online Testing
- What Is Confirmed and What You Must Check Yourself
- Version Timing: ISO/IEC 27001:2022 and the 2026 Question
- Choosing Your Exam Date Around the Eight Modules
- Course Dates Versus Exam Dates
- What to Expect on Exam Day
- After You Pass: The Three-Year Clock
- Frequently Asked Questions
- The C)ISMS Lead Auditor exam is delivered online through the Mile2 Learning Management System, so scheduling is not tied to a physical test center.
- The exam has 100 multiple-choice questions, runs about two hours, and requires a minimum 70% to pass.
- Buying the course is not required to purchase the exam, so your exam date can be independent of any training calendar.
- No formal 2026 exam version is verified; the current outline references ISO/IEC 27001:2022.
What "Exam Dates" Actually Means for the C)ISMS
Many certification exams run on fixed testing windows: a quarter-based calendar, a registration deadline, and a late-fee cutoff. If you came to this article looking for a published list of 2026 sitting dates for the Certified Information Security Management Systems: Lead Auditor/Lead Implementer credential, the honest answer is that the reviewed public Mile2 materials do not present the exam that way. The exam is administered online through the Mile2 Learning Management System, which changes what "dates" means for you in practical terms.
Instead of asking "which Saturday in 2026 can I sit?", the more useful questions are these: when will you be ready, when does your access to the exam become available after purchase, and how do you want your three-year certification cycle to line up with your professional calendar? This article walks through each of those, and it flags clearly which details are confirmed and which you should verify directly with Mile2 before committing to a plan.
A quick identity note before going further. This site covers the Mile2 credential whose preparation scope is the Lead Auditor track: an ISO/IEC 27001 audit methodology covering planning, control evaluation, substantive testing, and completion. If you are unsure how the acronym maps to the credential, our explainers on what C)ISMS certification is and what C)ISMS stands for cover the naming in detail.
How Delivery Works: Mile2 Online Testing
According to the current-linked Lead Auditor outline, the exam is delivered through the Mile2 LMS. That has several scheduling consequences worth understanding before you pick a target week.
No Dependence on a Test-Center Calendar
Because testing is online, you are not competing for seats at a physical location, and you do not need to plan travel. That generally gives candidates more flexibility than a fixed-window exam, but the exact mechanics of when the exam attempt is released, how long access remains open after purchase, and any retake conditions are not detailed in the sources reviewed. Treat those as items to confirm on your account page or with Mile2 support at the time of purchase.
The Format You Are Scheduling Around
Whatever date you choose, the format is the same for the Lead Auditor exam:
- Questions: 100 multiple-choice items
- Duration: approximately two hours
- Passing standard: minimum 70%
- Delivery: online via the Mile2 LMS
The split between scored and unscored questions is not stated, and conditions such as open-book rules, calculator use, adaptive behavior, and proctoring are not verified in the reviewed materials. Do not assume any of those; check the instructions presented at purchase or launch. For a deeper look at the scoring bar, see our breakdown of the C)ISMS passing score.
What Is Confirmed and What You Must Check Yourself
A reliable scheduling plan starts with separating facts from assumptions. The table below reflects what the reviewed Mile2 public sources support for the Lead Auditor exam, and what remains unverified.
| Item | Status | What to Do |
|---|---|---|
| Delivery platform | Online via Mile2 LMS | Confirm browser and system requirements before exam day |
| Question count | 100 multiple-choice | Practice at this volume |
| Duration | Approximately two hours | Rehearse timed sessions |
| Minimum score | 70% | Aim well above the minimum in practice |
| Fixed 2026 sitting calendar | Not verified | Ask Mile2 about availability and access windows |
| Registration deadlines and late fees | Not verified | Check at purchase |
| Exam-only fee and member/nonmember split | Not verified | See our certification cost guide and confirm with Mile2 |
| Proctoring, open-book, calculator rules | Not verified | Read the exam instructions before starting |
| Candidate pass rate | Not publicly disclosed in reviewed materials | See our pass rate discussion for context |
The practical takeaway: do not build a plan around a registration deadline or retake waiting period that you have not seen in writing from Mile2. If a third-party site quotes you a specific testing window or late-registration date for this credential, ask where it came from.
Version Timing: ISO/IEC 27001:2022 and the 2026 Question
One reason candidates search for dated information is concern about whether the exam content will change in 2026. The current linked outline references ISO/IEC 27001:2022 in its module list. However, no formal "2026 exam version" is verified in the reviewed sources. In other words, you should not expect to find an announced cutover date, and you should not assume the exam will be revised on a particular calendar day.
What this means for scheduling:
- Study to ISO/IEC 27001:2022. That is the standard the outline references, including its structure for the management system requirements and its control set.
- Re-check the outline before you sit. If you are planning a date several months out, revisit the Mile2 outline page shortly before the exam to see whether the module list has changed.
- Avoid outdated materials. Study resources built around the older edition of ISO/IEC 27001 may organize controls differently, which can cost you on questions built around the current edition.
Key Takeaway
Because no formal 2026 version change is verified, there is little reason to rush your sitting out of fear of a deadline. Pick a date based on readiness, and verify the outline one more time in the final weeks.
Choosing Your Exam Date Around the Eight Modules
This is the one place where a study timeline earns its keep, and it is tied directly to the eight preparation modules in the Lead Auditor course outline. Note that these modules are unweighted preparation headings, not an official weighted exam blueprint. No official domain weights or "largest domain" are verified, so do not build your timeline on a guess about which module carries the most points. Instead, sequence the modules in the order they build on each other.
Foundation: Intro and the Standard
- Lead Auditor Intro: the role, mindset, and scope of auditing
- The ISO/27001:2022: clauses, structure, and terminology you will need for every later module
Controls and Risk Vocabulary
- Information Security and Key Controls: the control families and what each is meant to achieve
- Risk Management: identification, analysis, and evaluation concepts
Treatment and Audit Fundamentals
- Risk Treatment: options, residual risk, and how treatment links back to controls
- Audits and Auditors: audit types, auditor responsibilities, and principles
Applied Auditing and Rehearsal
- Auditing the Information Security Management System: evaluating evidence against requirements
- Planning and Conducting an Audit: planning, control evaluation, substantive testing, and completion
- Full 100-question timed practice sets
The reasoning behind this order: the final two modules, which cover auditing the management system and planning and conducting an audit, depend on your command of the ISO/IEC 27001:2022 clauses, the control set, and risk concepts from earlier modules. Candidates who skip ahead to audit procedure without that grounding tend to struggle with scenario questions that ask them to judge evidence against a specific requirement. If you want to see how each content area is described, our exam domains guide goes through all eight, and the study guide covers preparation approaches in more depth.
How Long Should You Allow?
A four-week layout is an editorial illustration, not an official requirement. Your own timeline depends on your background. Someone who already works with ISO/IEC 27001 documentation, internal audits, or risk registers may compress the foundation weeks. Someone newer to information security management may stretch each module across more time. If you are weighing the effort involved, how hard the C)ISMS exam is offers a candid view of where candidates tend to need extra time.
Course Dates Versus Exam Dates
A common point of confusion is mixing up training calendars with the exam itself. Mile2 describes a three-day course worth 24 CEUs. Those are training values: they describe the length and continuing-education credit of the course, not the exam duration and not any kind of exam weighting. The exam is a separate event of about two hours.
Equally important, the Mile2 FAQ indicates that purchasing the course is unnecessary to buy the certification exam. That means two valid paths exist:
- Course first, exam after. You attend or complete training, then sit the exam when you feel prepared. Your exam date is whenever you choose to start the attempt after the course.
- Self-study and exam only. You prepare independently using the published module list and practice questions, then purchase the exam without the course. Your timeline is entirely your own.
Suggested background for the Lead Auditor track includes information-systems experience and an interest in auditing, but these are not verified as mandatory prerequisites. The exact requirements around degrees, work hours, training, and references are not confirmed in the reviewed materials. Our requirements article lays out what is and is not established, and the training overview compares ways to prepare.
What to Expect on Exam Day
Because the exam is multiple choice and built around the audit methodology, expect questions that test applied judgment rather than simple recall. Here are the kinds of topics the eight modules point toward.
Domain 2: The ISO/27001:2022
Expect questions that require you to know what the standard requires of an organization's management system.
- Distinguishing mandatory requirements from supporting guidance
- Understanding how context, leadership, planning, support, operation, evaluation, and improvement fit together
- Recognizing the 2022 edition's framing of controls
Domains 4 and 5: Risk Management and Risk Treatment
Risk concepts underpin both the standard and the audit. Know how risk is identified and evaluated, and how treatment decisions connect to controls.
- Risk treatment options and when each is appropriate
- The relationship between risk assessment output and control selection
- What an auditor looks for as evidence that treatment is actually applied
Domains 7 and 8: Auditing the ISMS and Planning and Conducting an Audit
These modules reflect the Lead Auditor identity of the credential, covering the methodology of planning, control evaluation, substantive testing, and completion.
- How an audit is planned and scoped
- How controls are evaluated and evidence is tested
- How findings are concluded and the audit is completed
Because the unscored/pretest split is unstated, treat every question as if it counts. And because proctoring and reference-material rules are not verified, do not plan on having notes available. For a compact refresher the night before, the C)ISMS cheat sheet is designed for last-pass review.
After You Pass: The Three-Year Clock
Your exam date matters beyond the day itself, because it starts your certification cycle. Under the current dedicated renewal policy, the credential carries a three-year validity period. Renewal involves:
- Earning 60 qualifying CEUs within the cycle
- Agreeing to Mile2's policies and ethics requirements
- Paying the applicable renewal fee, the amount of which is not verified in the reviewed sources
A note of caution: older Mile2 course PDFs contain recertification wording that mentions retaking the current exam and earning 20 CEUs per year. That wording appears outdated relative to the dedicated renewal policy. Follow the current renewal program page rather than the older course documents, and do not assume you need both a retake and annual CEUs.
Practically, this means that if you plan a career move or promotion tied to the credential, you should note your pass date and set a reminder well ahead of the three-year mark. If you are weighing whether the credential is worth maintaining, see our analysis of whether the C)ISMS certification is worth it, and for the employment side, the C)ISMS jobs overview describes the roles where audit and ISO/IEC 27001 skills are relevant.
Frequently Asked Questions
The reviewed public Mile2 materials do not present a fixed calendar of 2026 sitting dates. The Lead Auditor exam is delivered online through the Mile2 LMS, so confirm availability, access duration, and any deadlines directly with Mile2 at the time of purchase.
It consists of 100 multiple-choice questions and runs approximately two hours. The minimum passing grade is 70%. The split between scored and unscored questions is not stated in the reviewed materials.
No. The Mile2 FAQ indicates that purchasing the course is unnecessary to buy the certification exam. The three-day course and its 24 CEUs are training values, separate from the exam itself.
The current outline references ISO/IEC 27001:2022, but no formal 2026 exam version is verified. Study to the 2022 edition and re-check the Mile2 outline shortly before your sitting in case the module list has been updated.
Under the current renewal policy, certification is valid for three years. Renewal requires 60 qualifying CEUs, agreement to policies and ethics, and payment of the applicable renewal fee, whose amount is not verified. Use the renewal program page rather than older course PDFs that mention a retake and 20 CEUs per year.
Because the exam is online and not tied to a published sitting calendar in the sources reviewed, the best "date" is the one supported by your practice results. Work through the eight modules in sequence, rehearse the 100-question, two-hour format, verify the open details with Mile2, and then schedule. To build and measure that readiness, start with the full C)ISMS practice test site and confirm your timing against the details in our exam dates resource.