- The Number: 70% on 100 Questions
- What 70% Means in Practice
- What the Published Sources Do Not Tell You
- How the Four Domains Feed Your Score
- Exam Format and Testing Rules to Confirm
- Registration Mechanics: The Exam Combo
- Is Your Practice Score Predictive?
- A Domain-Ordered Prep Sequence
- After You Pass: Validity and Renewal
- Frequently Asked Questions
- The Certified Information Systems Risk Manager exam is 100 multiple-choice questions with a two-hour window and a 70% passing score.
- Mile2 Cybersecurity Institute administers the exam through an online account with LearnDash delivery.
- No separate weighted exam blueprint is verified, so prepare evenly across all four published course domains.
- Proctoring and open-book details conflict between Mile2 sources; get C)ISRM-specific instructions before test day.
The Number: 70% on 100 Questions
If you are searching for the Certified Information Systems Risk Manager passing score, the short answer is 70%. The exam consists of 100 multiple-choice questions delivered within a two-hour window. It is offered by Mile2 Cybersecurity Institute, and candidates take it through an online Mile2 account using LearnDash delivery.
That is the complete set of score-related facts that Mile2's published materials support. Anything beyond it, such as a scaled scoring range, a per-domain minimum, or a published pass rate, is not something we can responsibly state. This article explains what the 70% threshold means for how you prepare, what remains unconfirmed, and what you should verify directly with Mile2 before you sit the exam.
What 70% Means in Practice
Mile2 publishes the passing score as a percentage and the exam as 100 questions. Reading those two facts together, a candidate should plan around answering roughly 70 questions correctly. Mile2 does not publish whether every question carries equal weight, whether any items are unscored, or how partial results are reported, so treat "70 out of 100" as a planning target rather than a guaranteed mechanical rule.
| Exam Element | What Mile2 Sources Support |
|---|---|
| Question count | 100 multiple-choice questions |
| Time allowed | Two-hour window |
| Passing score | 70% |
| Delivery | Online Mile2 account, LearnDash delivery |
| Weighted blueprint | Not verified |
| Retake waiting period | Requires confirmation with Mile2 |
The pacing math
Two hours across 100 questions works out to a little over a minute per question, with no spare time if you spend it evenly. Risk management questions are often scenario-based: a short paragraph describes an organization, a threat, or a control gap, and you choose the best response. Those take longer to read than definition recall. Plan to move quickly through questions you know cold so you can bank time for the scenario items.
Why the margin matters
Because the bar is 70% rather than a lower threshold, you cannot rely on a single strong domain to carry you. A candidate who is excellent at risk assessment but weak on control design can still fall short if the weak domain contributes enough questions. This is why we recommend measuring readiness across all four domains rather than watching one overall number.
What the Published Sources Do Not Tell You
A good passing-score article should be honest about gaps. Based on the sources we reviewed (the Mile2 course outline, FAQ, Policies and Procedures document, and renewal pages), the following items are not verified and should be confirmed with Mile2 before exam day:
- Per-domain weighting. The course outline lists four numbered domains, but a separate weighted exam blueprint is not verified. Do not assume the questions split evenly or follow any particular percentage.
- Exam version. The current linked outline is undated, and no numbered exam version is verified.
- Calculator and adaptive rules. Whether a calculator is permitted, and whether the exam adapts to your answers, is unverified.
- Retake waiting periods. The policy details need confirmation.
- Score reporting details. Whether you receive a domain-level breakdown is not something the sources confirm.
How the Four Domains Feed Your Score
Mile2's course outline organizes the content into four numbered domains. Since no weighted blueprint is verified, your safest assumption is that each domain can appear meaningfully on the exam. Here is what each domain asks of you and the kinds of competencies that tend to show up as test questions. For a deeper breakdown, read our complete guide to the four C)ISRM exam domains.
Domain 1: Risk Identification Assessment and Evaluation
This is the foundation. Expect questions on how risks are found, described, and ranked before anyone decides what to do about them.
- Distinguishing assets, threats, vulnerabilities, and the risk that results when they combine
- Qualitative versus quantitative evaluation, and when each is appropriate
- Interpreting likelihood and impact to prioritize risks for decision-makers
- Maintaining a risk register and documenting risk scenarios clearly
Domain 2: Risk Response
Once risk is evaluated, the question becomes what to do. This domain tests judgment about choosing among response options.
- Mitigate, transfer, avoid, and accept as distinct strategies, and the circumstances that favor each
- Residual risk and how it relates to organizational risk appetite and tolerance
- Aligning response decisions with business objectives rather than technical preference
- Recognizing who owns a risk decision and who simply advises
Domain 3: Risk Monitoring
Risk is not a one-time exercise. This domain covers keeping the picture current after decisions are made.
- Defining and tracking indicators that show risk is changing
- Reporting risk status to management in a form that supports decisions
- Reviewing whether risk responses are still effective over time
- Handling changes in the environment, such as new systems, vendors, or threats
Domain 4: IS Control Design and Implementation
This domain connects risk decisions to concrete safeguards and tests whether you can choose and apply appropriate controls.
- Matching control types (preventive, detective, corrective) to the risk they address
- Evaluating whether a control is designed well and whether it operates as intended
- Balancing control cost against the risk reduction it delivers
- Integrating controls into projects and operations rather than bolting them on
Key Takeaway
The four domains form a loop: identify and evaluate, respond, monitor, and design controls that make the response real. Questions often blend two domains at once, so study them as a connected lifecycle rather than four isolated lists.
Exam Format and Testing Rules to Confirm
Knowing the score is only half the picture. The testing conditions affect how you should prepare, and this is an area where Mile2's published sources do not fully agree.
Open-book and proctoring: confirm before you test
Mile2's general policy document, dated May 26, 2026, describes open-book testing. However, the Mile2 FAQ and the policy document conflict on proctoring. Because of that conflict, we cannot tell you definitively whether your attempt will be proctored, how, or what reference materials are permitted. Obtain C)ISRM-specific instructions from Mile2 and follow those over any general statement, including ours.
Even if open-book testing applies to your attempt, do not treat it as a reason to under-prepare. A two-hour limit across 100 questions leaves very little time to look things up. Open-book access helps most with confirming a detail you mostly remember, not with learning a topic from scratch mid-exam.
Other conditions
- No pause. Under Mile2's general security guidance, you cannot pause the exam. Plan a distraction-free two-hour block and handle everything else beforehand.
- Calculator and adaptive behavior. Unverified. Ask Mile2 rather than assuming.
- Retakes. Waiting periods require confirmation. Your Exam Combo includes two attempts, but confirm the retake rules before relying on a quick second try.
Registration Mechanics: The Exam Combo
You register and take the exam through your online Mile2 account. The Exam Combo bundles the exam guide, a quiz or simulator, and two exam attempts. Full Mile2 training is not mandatory to sit the exam, which matters for candidates who already work in risk management and prefer to self-study.
The Mile2 course itself runs four days and carries 24 CEUs. That describes the training course, not the exam duration, so do not confuse the two: the exam is a two-hour assessment.
On prerequisites, Mile2 suggests the C)SP credential and 12 months of IT experience as preparation. These are suggestions, and we could not verify that they are mandatory. We also could not verify any required degree or references. For the full picture, see our guide to C)ISRM requirements and eligibility, and for pricing context, our C)ISRM certification cost breakdown.
Is Your Practice Score Predictive?
The Exam Combo includes a quiz or simulator, and many candidates will also use third-party practice tests. Used well, these tell you where you stand against the 70% bar. Used carelessly, they create false confidence.
Reading your practice results
- Score by domain, not just overall. An overall 75% hiding a 55% in Risk Response is a warning, not a pass.
- Aim above the line. Since real-exam difficulty can differ from any practice set, a cushion above 70% is wise. We do not claim a specific practice-to-real conversion, because none is published.
- Review why you missed items. A wrong answer caused by misreading a scenario needs a different fix than one caused by not knowing a concept.
- Watch for memorized answers. If you are recognizing questions rather than reasoning through them, your score overstates your readiness.
For realistic expectations about difficulty, read how hard the C)ISRM exam really is, and use the C)ISRM Exam Prep practice tests to check your performance domain by domain.
A Domain-Ordered Prep Sequence
Because the domains build on each other, sequencing matters more than total hours. This outline orders your effort the way the risk lifecycle works. It is a template, so adjust the length to your experience. Our full C)ISRM study guide goes deeper on resources.
Domain 1: Risk Identification Assessment and Evaluation
- Master core vocabulary: asset, threat, vulnerability, likelihood, impact
- Practice ranking sample risks qualitatively and quantitatively
Domain 2: Risk Response
- Work scenarios that force a choice among mitigate, transfer, avoid, accept
- Tie each choice to risk appetite and business objectives
Domains 3 and 4: Risk Monitoring and IS Control Design and Implementation
- Study indicators and reporting, then control types and effectiveness
- Connect controls back to the risks they were chosen to address
Integration and timed practice
- Take full 100-question sets against the two-hour clock
- Re-study your weakest domain based on domain-level scores
Front-loading Domain 1 pays off because every later domain assumes you can describe and rank risk correctly. Leaving integration for the end matches how the real exam blends domains within a single scenario.
After You Pass: Validity and Renewal
Passing earns a credential that is valid for three years. Planning for renewal early prevents a lapse.
- Standard renewal: 60 documented CEUs, plus a fee and an ethics acknowledgment.
- Alternative: an approved exam path.
- U.S. CEU renewal fee: currently $200, with regional eligibility varying.
- No annual membership is required.
If you are weighing whether the investment pays off, our analysis of whether the C)ISRM certification is worth it covers the broader picture, and the C)ISRM salary guide addresses earnings. Professionals who hold the credential tend to work in risk, governance, and security roles, which we explore in C)ISRM jobs.
Key Takeaway
Your target is 70% on 100 questions in two hours, but your real preparation target should be consistent competence across all four domains, plus written confirmation from Mile2 on proctoring and retake rules.
Frequently Asked Questions
The passing score is 70%. The exam has 100 multiple-choice questions and a two-hour window. Mile2 does not publish a scaled scoring range in the sources we reviewed, so plan around answering about 70 questions correctly.
Mile2's general policy dated May 26, 2026 describes open-book testing, but the FAQ and the policy conflict on proctoring. Confirm the rules for your specific C)ISRM attempt with Mile2 before test day, and do not rely on open-book access to replace preparation.
No. Full training is not mandatory. The Exam Combo includes the exam guide, a quiz or simulator, and two attempts. The four-day, 24-CEU course is optional, and its length is unrelated to the two-hour exam.
It is valid for three years. Standard renewal requires 60 documented CEUs plus a fee and ethics acknowledgment, or an approved exam path. The U.S. CEU renewal fee is currently $200, regional eligibility varies, and there is no annual membership.
A separate weighted exam blueprint is not verified. Mile2 lists four numbered course domains: Risk Identification Assessment and Evaluation, Risk Response, Risk Monitoring, and IS Control Design and Implementation. Prepare for all four rather than assuming an uneven split.