Eligibility

AAISM™ eligibility requirements

AAISM™ eligibility is simple to state and easy to check: you need one of two credentials, active, before you can register. Here's exactly how it works.

The two paths

One of these two, active

  • An active CISSP® (ISC2), or
  • An active CISM® (ISACA).

"Active" means the credential is currently valid and in good standing, not expired or revoked. Either credential qualifies on its own; you don't need both.

No alternate path

There's no work-experience-only route

Some ISACA credentials offer a path based on years of relevant work experience in place of a prerequisite exam. AAISM™ doesn't. Eligibility is entirely dependent on already holding an active CISSP® or CISM®, no exceptions based on experience, education, or other certifications.

Why it's designed this way

AAISM™ assumes a foundation, deliberately

AAISM™ is scoped narrowly to AI governance, risk, and controls because it assumes you already have the broader security-management or security-practitioner foundation a CISSP® or CISM® provides. That's why prep for AAISM™ focuses on AI-specific scenarios rather than re-teaching security fundamentals you've already proven you know.

See how that shapes an effective study plan →

Questions

Eligibility questions, answered

Can I qualify for AAISM™ through work experience alone?

No. There's no independent work-experience path. You need an active CISSP® or CISM® to register, regardless of how much AI or security experience you have otherwise.

Do I need both CISSP® and CISM®?

No, either one qualifies on its own. You only need one of the two.

Does a lapsed or inactive CISSP®/CISM® still qualify?

Eligibility is based on holding an active credential, one that's currently valid and in good standing, not lapsed.

Ready to prep for AAISM™?

Certifi360 targets your gaps from minute one: 177 exam-style questions with rationale, 102 concepts, 115 flashcards, a 13-section cram sheet, and full timed exam simulations across all three weighted domains.