C)ISMS logo
Focused certification exam prep
Start practice

C)ISMS Exam Domains 2026: Complete Guide to All 8 Content Areas

TL;DR
  • The eight domains are unweighted course modules from the Lead Auditor outline, not an official weighted exam blueprint.
  • The Lead Auditor exam has 100 multiple-choice questions, about two hours, and a 70% minimum, delivered via the Mile2 LMS.
  • Domains 4 and 5 (risk management and risk treatment) feed directly into how you audit controls in Domains 7 and 8.
  • The linked outline references ISO/IEC 27001:2022; no formal 2026 exam version has been verified.

What the Eight Content Areas Actually Are

Candidates searching for "C)ISMS exam domains" often expect a tidy table of official percentages. That is not what the issuer publishes. The eight headings covered here reproduce the module list of the currently linked Mile2 Lead Auditor course outline. They are unweighted preparation headings, not a formal, weighted or exhaustive examination blueprint. Anyone quoting a "largest domain" or a precise percentage per area for this credential is guessing.

That distinction matters for how you study. Without published weights, the safe strategy is breadth first: be competent across all eight areas, then deepen the ones where your background is thin. If you are new to the credential itself, the explainers on what C)ISMS is and what C)ISMS certification involves give useful context before you dive into the module list.

Scope note: The umbrella name covers a combined Lead Auditor / Lead Implementer course page, but the verified exam details here apply to Lead Auditor only. The outline explicitly prepares candidates for the C)ISMS-LA examination. Do not assume identical content or exam specifications for Lead Implementer; confirm those separately with the issuer.

Exam Format at a Glance

Before the domains, anchor yourself in the logistics, because they shape how deeply you must know each area. The table below summarizes only what the reviewed issuer materials state for Lead Auditor.

ItemLead Auditor (verified in reviewed sources)
Question formatMultiple choice
Number of questions100 (scored/unscored split not stated)
Time allowedApproximately 2 hours
Minimum passing grade70%
DeliveryOnline through the Mile2 Learning Management System
Standard referencedISO/IEC 27001:2022 (no formal 2026 exam version verified)
Public pass rateNot disclosed in reviewed official materials

Several details remain unverified: whether the exam is open-book, whether calculators are permitted, whether it is adaptive, and what proctoring conditions apply. Check these with the issuer before booking rather than relying on forum chatter. For the scoring threshold specifically, see our breakdown of the C)ISMS passing score, and for scheduling mechanics visit C)ISMS exam dates and scheduling.

On cost: the current USD exam-only fee and any member/nonmember split have not been verified, so this article will not quote a number. The issuer FAQ indicates that purchasing the course is not required to buy the certification exam, which is useful if you already have audit training elsewhere. Our C)ISMS certification cost guide tracks the pricing picture as it is confirmed.

Domains 1 to 3: Foundations and the Standard

Domain 1: Lead Auditor Intro

Lead Auditor Intro

This opening module orients you to the role itself: what a lead auditor is accountable for and how the ISO/IEC 27001 audit methodology unfolds. The outline describes that methodology as planning, control evaluation, substantive testing and completion.

  • Memorize the four-phase flow: planning, control evaluation, substantive testing, completion.
  • Understand the difference between being a participant on an audit and leading one.
  • Expect scene-setting questions about purpose and scope rather than deep technical detail.

Do not skip this because it feels introductory. The four-phase structure reappears as the backbone of Domains 7 and 8, and questions often test whether you can place an activity in the correct phase.

Domain 2: The ISO/27001:2022

The ISO/27001:2022

This is the standard itself. The module list explicitly references ISO/IEC 27001:2022, so study the current edition, not older material that still circulates in used course packs and blog posts.

  • Know the structure of the management system clauses and what each requires of an organization.
  • Understand how scope, policy, leadership commitment, objectives and documented information fit together.
  • Be able to explain how the management system improves over time through monitoring and corrective action.
  • Distinguish requirements (what must be done) from guidance (what is suggested).

A common trap is studying a superseded edition. If a practice question or study note refers to controls grouped in a way that does not match the 2022 edition, treat it with suspicion. Our C)ISMS study guide covers how to build a reliable resource list.

Domain 3: Information Security and Key Controls

Information Security and Key Controls

Here you move from management-system clauses to the controls that protect information. Auditors do not need to implement every control, but they must recognize what a control is meant to achieve and what evidence shows it operating.

  • Link each control category to the risk it mitigates.
  • Know what evidence would demonstrate that a control exists, is documented and actually works.
  • Understand the difference between organizational, people, physical and technological safeguards at a conceptual level.

Domains 4 and 5: Risk Management and Risk Treatment

These two modules form the intellectual center of an ISO/IEC 27001 audit. The standard is risk-driven: controls exist because risks were assessed and treatment decisions were made. An auditor who cannot follow that chain cannot judge whether the control set is appropriate.

Domain 4: Risk Management

Risk Management

Focus on how an organization identifies assets, threats and vulnerabilities, then evaluates the resulting risk against defined criteria.

  • Understand risk assessment as a repeatable, documented process, not a one-off exercise.
  • Know why consistent criteria matter: results should be comparable and reproducible.
  • Be ready to identify weaknesses in how an organization has documented its risk method.

Domain 5: Risk Treatment

Risk Treatment

Once risks are evaluated, the organization chooses how to respond. The auditor checks that the decision is reasoned, approved and traceable to the controls actually in place.

  • Recognize the standard treatment options: modify, retain, avoid and share.
  • Understand the role of the statement of applicability in connecting risks to selected controls.
  • Know what residual risk means and why management acceptance of it should be explicit.
Why these two domains compound: In a real audit you will trace from a risk, to a treatment decision, to a control, to evidence. Exam scenarios mirror that trace. If you study Domains 4 and 5 as isolated vocabulary lists, scenario questions in Domains 7 and 8 will feel disconnected. Study them as one continuous thread.

Domains 6 to 8: The Audit Craft

The last three modules are where the "Lead Auditor" identity of this credential becomes concrete. Candidates with a purely technical security background often find these the least familiar, while experienced auditors may find the ISO/IEC 27001 specifics newer than the audit principles.

Domain 6: Audits and Auditors

Audits and Auditors

This module covers the nature of audits and the qualities and responsibilities expected of those who conduct them.

  • Understand audit types and who typically performs them.
  • Know the principles that underpin credible auditing, including integrity, impartiality and evidence-based conclusions.
  • Recognize conflicts of interest and how they threaten objectivity.

Domain 7: Auditing the Information Security Management System

Auditing the Information Security Management System

Here the audit methodology meets the standard. You apply the control-evaluation and substantive-testing ideas to a management system as a whole.

  • Distinguish evaluating the design of a control from testing whether it operates effectively.
  • Know how to gather evidence through interviews, document review and observation.
  • Understand how findings are classified and what makes a nonconformity well supported.

Domain 8: Planning and Conducting an Audit

Planning and Conducting an Audit

The practical, end-to-end module: defining objectives and scope, preparing the plan, opening and running the audit, reporting, and closing out.

  • Sequence audit activities correctly from preparation through completion.
  • Understand what belongs in an audit plan and an audit report.
  • Know the purpose of opening and closing meetings and follow-up of corrective actions.

How to Read Lead Auditor Questions

With 100 multiple-choice questions in roughly two hours, you have a little over a minute per question. That is enough time to read carefully but not to agonize. Because the issuer has not disclosed how many questions are scored versus unscored, treat every question as if it counts.

  • Role-framing questions: Expect stems that ask what the lead auditor should do next. The correct answer usually follows audit principles (objectivity, evidence, documented process) rather than a technical shortcut.
  • Phase-placement questions: You may be asked which activity belongs in planning versus substantive testing versus completion.
  • Standard-reading questions: These test whether you know what ISO/IEC 27001:2022 actually requires of an organization, as distinct from common practice.
  • Risk-chain questions: Scenarios that move from an identified risk to a treatment choice to a supporting control and the evidence you would seek.

Key Takeaway

When two answers both seem plausible, prefer the one that is evidence-based, documented and consistent with audit independence. Lead Auditor questions reward procedural discipline over technical heroics.

For a candid look at what makes the exam demanding, read how hard the C)ISMS exam really is. Note that no public pass rate is disclosed in the reviewed official materials, so be wary of any specific figure; our page on the C)ISMS pass rate explains what can and cannot be said.

Sequencing the Domains in Your Preparation

Because the domains are unweighted, an editorial sequence based on dependency makes more sense than one based on guessed importance. Below is a suggested order that follows the logic of the audit itself. The week count is editorial, not an issuer recommendation, and the course's three-day, 24-CEU length reflects training delivery, not exam duration or weighting.

Week 1

Orientation and the Standard

  • Domain 1: learn the four-phase audit methodology.
  • Domain 2: read through ISO/IEC 27001:2022 clause by clause.
Week 2

Controls and Risk

  • Domain 3: map control categories to the risks they address.
  • Domains 4 and 5: study assessment and treatment as one continuous chain.
Week 3

Audit Craft

  • Domain 6: audit principles and auditor conduct.
  • Domain 7: auditing the management system and classifying findings.
Week 4

Integration and Practice

  • Domain 8: plan and conduct a mock audit on paper.
  • Run timed question sets across all eight areas and revisit weak modules.

When you reach the final week, a one-page recap helps; our C)ISMS cheat sheet is built for that purpose, and timed drills on the C)ISMS practice test site let you rehearse the 100-question, two-hour rhythm. If you want to see the whole picture of how these areas fit together, our companion piece on the C)ISMS exam domains offers a second angle.

Validity, Renewal and Where the Credential Is Used

Eligibility signals

The issuer materials suggest an information-systems background and an interest in auditing, but a mandatory degree, specific work hours, a required training course or references have not been verified as hard prerequisites. Review C)ISMS requirements and eligibility and confirm current conditions with Mile2 before you register.

Renewal under the current policy

For current administration, use the dedicated renewal policy rather than older wording in legacy course PDFs. Under that policy the certification carries a three-year validity period, renewal requires 60 qualifying CEUs, agreement to the issuer's policies and ethics, and payment of the applicable renewal fee (the amount has not been verified). Older course PDFs mention a current-exam retake and 20 CEUs per year; do not combine those with the current policy, and do not confuse CEUs with exam weights.

Career context

A Lead Auditor credential aligned to ISO/IEC 27001 is most relevant to roles that assess or assure information security management systems: internal audit, compliance, governance and risk functions, and consultancies supporting certification readiness. This site does not publish unsourced earnings claims; see the C)ISMS salary guide for what can be said responsibly, the overview of C)ISMS jobs, and the worth-it analysis if you are weighing the investment.

Frequently Asked Questions

Are the eight C)ISMS domains weighted?

No official weights have been verified. The eight headings are unweighted modules from the Lead Auditor course outline, so treat them as a preparation scope and aim for balanced coverage rather than chasing a guessed highest-weight area.

How many questions are on the Lead Auditor exam and what score do I need?

The issuer outline states 100 multiple-choice questions, approximately two hours, and a minimum grade of 70%, delivered online through the Mile2 LMS. The scored versus unscored split is not stated.

Does the exam cover ISO/IEC 27001:2022?

The current linked module list explicitly references ISO/IEC 27001:2022. A formal 2026 exam version has not been verified, so study the 2022 edition and check the issuer for any updates before testing.

Do I need to take the course before sitting the exam?

The issuer FAQ indicates that course purchase is not necessary to buy the certification exam. A suggested information-systems background and interest in auditing are mentioned, but mandatory prerequisites have not been verified, so confirm current rules with Mile2.

Does this domain list apply to Lead Implementer?

No. The module list supports Lead Auditor only. The combined Lead Auditor / Lead Implementer page does not establish identical Lead Implementer content or exam specifications, which require separate confirmation.

Working through all eight areas in dependency order, from audit orientation through to planning and conducting a full audit, is the most reliable way to cover an unweighted scope. Pair that structure with timed practice, and use the C)ISMS training overview if you want to compare course-based and self-study routes.

Ready to pass your C)ISMS exam?

Put this into practice with free C)ISMS questions across every exam domain.