C)ISMS logo
Focused certification exam prep
Start practice

C)ISMS Passing Score 2026: Exactly What You Need to Pass

TL;DR
  • The Lead Auditor exam has 100 multiple-choice questions and a minimum passing grade of 70%.
  • Testing runs online through the Mile2 Learning Management System, with roughly two hours allotted.
  • Official domain weights, the scored/unscored split and the candidate pass rate are not publicly disclosed.
  • Eight unweighted course modules define your preparation scope, anchored to ISO/IEC 27001:2022.

The Number: 70% on 100 Questions

If you are preparing for the Certified Information Security Management Systems: Lead Auditor exam (the C)ISMS-LA, issued by Mile2), the headline figure is straightforward: the issuer's outline states a minimum passing grade of 70%. The exam consists of 100 multiple-choice questions and runs for approximately two hours.

That is the complete set of numerical specifications confirmed in the reviewed official materials. Everything else candidates often want to know, such as how many questions are scored, whether the passing line is adjusted between exam forms, or what share of candidates clear it, is simply not stated publicly. This article separates what is confirmed from what is not, so you can plan around real information rather than forum folklore.

For a broader view of how the credential is structured, see our overview of what the C)ISMS certification is, and for the difficulty side of the equation, read How Hard Is the C)ISMS Exam?

What 70% Actually Means in Practice

On a 100-question exam, 70% translates to 70 correct answers if every item counts toward your score. That is the clean arithmetic, and it is the safest planning assumption. However, the issuer's materials do not say whether all 100 questions are scored or whether some are unscored pretest items. If a portion of the exam is unscored, the raw number of correct answers needed could differ from 70, and you would have no way of knowing which questions were which during the sitting.

ScenarioInterpretationPractical Takeaway
All 100 questions scored70 correct answers neededPlan for a margin above 70 to absorb careless misses
Some questions unscoredThreshold applies to scored items onlyTreat every question as if it counts; you cannot tell the difference
Split unstated (current reality)Not verifiable from public materialsBuild readiness well above the minimum rather than targeting it exactly
Plan Around the Gap: Because the scored/unscored split is not published, the only sound strategy is to treat all 100 items as scored and aim comfortably above 70% in your practice results. Do not rely on any claim that you can "afford to skip" a set number of questions.

What Is and Isn't Publicly Confirmed

Many sites blur the line between confirmed specifications and guesswork. For the Lead Auditor exam, here is an honest accounting based on the issuer's current-linked materials.

Confirmed

  • 100 multiple-choice questions
  • Approximately two hours
  • Minimum passing grade of 70%
  • Delivery through the Mile2 Learning Management System (online)
  • Course content referencing ISO/IEC 27001:2022
  • Course purchase is not required to buy the certification exam, per the issuer's FAQ

Not Verified or Not Disclosed

  • Official weighted exam domains and which domain carries the highest weight
  • The scored versus unscored question split
  • The candidate pass rate (see our discussion in C)ISMS Pass Rate 2026: What the Data Shows)
  • Whether the exam is open-book, whether calculators are permitted, whether it is adaptive, and what proctoring conditions apply
  • The current exam-only fee and any member/nonmember price difference (our C)ISMS certification cost breakdown covers what can and cannot be stated)
  • A formal 2026-specific exam version

One more caution: the combined Lead Auditor/Lead Implementer web presence does not establish that the Lead Implementer exam shares these specifications. The numbers in this article apply to the Lead Auditor exam only. If you are considering the Lead Implementer track, confirm its specifications directly with the issuer before assuming anything carries over.

Format and Delivery Through the Mile2 LMS

The exam is administered online through the Mile2 Learning Management System. For candidates, this has a few practical implications even where detailed proctoring rules are not published:

  • Test your environment early. Browser compatibility, stable connectivity and a quiet workspace matter more in a roughly two-hour online sitting than in a short quiz.
  • Confirm conditions before exam day. Because open-book status, calculator policy and proctoring requirements are not verified in public materials, check your candidate instructions inside the LMS rather than assuming.
  • Pace yourself. With 100 questions in approximately 120 minutes, you have a little over a minute per item on average. Scenario-style audit questions take longer to read than definition recall, so bank time on the easy ones.

For registration timing and scheduling considerations, our guide to C)ISMS exam dates and scheduling explains what can be confirmed. Eligibility questions are covered in C)ISMS Requirements 2026; in short, the issuer suggests an information-systems background and an interest in auditing, but exact mandatory prerequisites are not verified.

Where the Points Come From: Eight Preparation Modules

Since official exam weights are not published, you cannot know how many of the 100 questions come from each area. What the issuer does provide is an eight-module course structure, which should be treated as unweighted preparation scope, not a formal exam blueprint. The outline describes its ISO/IEC 27001 audit methodology as planning, control evaluation, substantive testing and completion, which hints at the audit-process orientation of the exam.

Domain 1: Lead Auditor Intro

The orientation layer: what a lead auditor does and how the course frames the role.

  • Role expectations and audit mindset
  • How the engagement of an ISMS audit is framed

Domain 2: The ISO/27001:2022

The standard itself, in its 2022 edition, is the reference point for everything an auditor tests against.

  • Clause structure and management system requirements
  • How the 2022 edition shapes audit criteria

Domain 3: Information Security and Key Controls

The controls an auditor must recognize, evaluate and test.

  • What each control intends to achieve
  • Evidence an auditor would expect to see for a control

Domain 4: Risk Management

Risk is the engine of an ISMS, so auditors must understand how it is identified and assessed.

  • Risk identification and assessment concepts
  • How risk drives scope and control selection

Domain 5: Risk Treatment

What organizations do with assessed risk, and how an auditor verifies it.

  • Treatment options and their documentation
  • Linking treatment decisions to controls

Domain 6: Audits and Auditors

The profession of auditing: principles, conduct and the auditor's responsibilities.

  • Auditor competence and ethical conduct
  • Types of audits and their purposes

Domain 7: Auditing the Information Security Management System

Applying audit technique specifically to an ISMS.

  • Evaluating management system effectiveness
  • Testing controls and documenting findings

Domain 8: Planning and Conducting an Audit

The end-to-end audit lifecycle, from preparation through completion.

  • Audit planning and scoping
  • Fieldwork, substantive testing and closing activities

For a deeper treatment of each area, see C)ISMS Exam Domains 2026: Complete Guide to All 8 Content Areas.

Turning 70% Into a Practice Target

Knowing the pass mark is only useful if you convert it into a measurable readiness threshold. Because the passing line is a percentage of a 100-question exam and the real item distribution is unknown, the most defensible approach is to build breadth first and depth second.

  • Do not gamble on a favorite domain. With no published weights, you cannot safely neglect any of the eight modules. A strong showing in risk topics will not rescue a weak showing in audit process questions if the exam leans the other way.
  • Set your own buffer. Aim to consistently score well above 70% on full-length timed practice, so that nerves, an unfamiliar question style or an unscored-item surprise does not push you under the line.
  • Review misses by module. Tag every wrong answer to one of the eight modules. Patterns reveal where your real gaps are, which is more valuable than a single overall percentage.
  • Practice scenario reasoning. Lead Auditor questions reward knowing what an auditor would do or conclude in a situation, not just reciting definitions.

Key Takeaway

Treat 70% as the floor, not the goal. Because the scored/unscored split and domain weights are undisclosed, readiness means consistent timed practice results clearly above 70% across all eight modules, not just your strongest ones. Our C)ISMS practice tests are built to help you measure exactly that.

A Module-Driven Preparation Sequence

Rather than a generic schedule, sequence your preparation by how the modules depend on each other. The standard comes first because every later topic references it; audit execution comes last because it synthesizes everything else. The allocation below is an editorial suggestion, not an official weighting.

Week 1

Foundations and the Standard

  • Lead Auditor Intro and the role of the auditor
  • Read through ISO/IEC 27001:2022 structure and clauses
Week 2

Controls and Risk

  • Information Security and Key Controls
  • Risk Management, then Risk Treatment, in that order
Week 3

Audit Practice

  • Audits and Auditors
  • Auditing the Information Security Management System
  • Planning and Conducting an Audit
Week 4

Timed Simulation

  • Full 100-question practice runs inside roughly two hours
  • Re-study the modules where misses cluster

For a fuller planning framework, our C)ISMS Study Guide 2026 goes into more depth, and the C)ISMS cheat sheet gives you a compact final review before test day.

After You Pass: Validity and Renewal

Clearing 70% earns a credential with a defined lifespan. Under the issuer's current dedicated renewal policy, certification is valid for three years, and renewal involves 60 qualifying CEUs, agreement to the issuer's policies and ethics requirements, and payment of the applicable renewal fee (the amount is not verified here).

Watch for Outdated Wording: Older Mile2 course PDFs contain recertification language referencing a current-exam retake and 20 CEUs per year. Use the dedicated renewal policy as the current administrative reference, and do not assume you must satisfy both the old and new requirements. Also note that the three-day course's 24 CEUs are a training value, not an exam duration or weighting.

If you are weighing whether the investment makes sense for your career, see Is the C)ISMS Certification Worth It? and the C)ISMS salary guide for what can responsibly be said about earning potential.

Frequently Asked Questions

What is the passing score for the C)ISMS Lead Auditor exam?

The issuer's outline states a minimum passing grade of 70%. The exam has 100 multiple-choice questions and runs for approximately two hours, delivered online through the Mile2 Learning Management System.

Do all 100 questions count toward my score?

The reviewed official materials do not state whether the exam includes unscored pretest items. The safest approach is to treat every question as scored and prepare to perform comfortably above 70%.

Which domain carries the most weight on the exam?

No official weights are published, so the highest-weighted area is unverified. The eight modules are unweighted preparation headings, so study all of them rather than betting on a single area.

What is the C)ISMS Lead Auditor pass rate?

The candidate pass rate is not publicly disclosed in the reviewed official materials. Any specific percentage you encounter online should be treated skeptically unless it cites a verifiable source.

Does the Lead Implementer exam use the same passing score?

The verified numbers in this article apply to the Lead Auditor exam only. Lead Implementer specifications require separate confirmation with the issuer, since the combined course page does not establish identical exam details.

Ready to pass your C)ISMS exam?

Put this into practice with free C)ISMS questions across every exam domain.