PM GRC

Roadmap · R10

R10: Comprehensive Role Roadmaps — Project Management & GRC Tracks

Status: Deep Dive Research Phase 8
Date: 30 April 2026
Scope: Dual-track career progressions with salary benchmarks, certification milestones, and lateral pivot options.


TABLE OF CONTENTS

  1. PM Track Overview
  2. GRC Track Overview
  3. Lateral Pivots & Cross-Track Transitions
  4. Key Role Distinctions
  5. Regional Salary Data
  6. Conference & Community Resources
  7. 2026 Updates & Certification Changes
  8. Sources

PM TRACK OVERVIEW

The Project Management career track follows a linear progression from tactical execution (Project Coordinator) through strategic portfolio leadership. Each tier builds on the previous, with distinct skill requirements and certification expectations.

ENTRY (0–3 years) — Project Coordinator / Junior PM / Business Analyst

Day-in-the-Life:

  • Scheduling stakeholder meetings and sending status reports
  • Maintaining RACI matrices and updating project schedules
  • Collecting project artifacts (requirements, scope docs, risk registers)
  • Learning to distinguish scope creep from legitimate changes
  • First exposure to vendor management and escalation ladders

Required Core Skills:

  • Scope, schedule, and budget estimation basics
  • Stakeholder mapping and communication planning
  • Risk register creation and basic mitigation strategies
  • Document management and change control fundamentals
  • Conflict resolution within a project team

Recommended Certifications:

CertificationVendorURLNotes
CAPM (Certified Associate in Project Management)PMIhttps://www.pmi.org/certifications/certified-associate-capmEntry-level; no hours required; $555 exam fee; 3-year validity
PSM I (Professional Scrum Master I)Scrum.orghttps://www.scrum.org/professional-scrum-master-i-certificationAgile alternative; no prerequisites; $150 exam fee
CSM (Certified ScrumMaster)Scrum Alliancehttps://www.scrumalliance.org/get-certified/scrum-master-track/certified-scrummaster2-day course required; $85 exam fee; 2-year validity
PRINCE2 FoundationAXELOShttps://www.axelos.com/certifications/prince2UK/EU standard; entry-level; no prerequisites; £98 exam fee
ITIL 4 FoundationAXELOShttps://www.axelos.com/certifications/itilIT-focused; no prerequisites; £105 exam fee

Salary (2026 US):
Entry-level Project Coordinator: $51,000–$83,000 per year (Invensis Learning)

Free Resources:


ASSOCIATE (3–5 years) — Project Manager (PMP)

Day-in-the-Life:

  • Running weekly status meetings and escalation reviews
  • Managing earned value metrics (BCWS, BCWP, ACWP)
  • Handling vendor RFP processes and contract negotiation
  • Managing project budgets and forecasting to completion
  • Difficult stakeholder conversations and scope negotiations
  • Leading root-cause analysis on schedule slips

Required Core Skills:

  • PMBOK 6th or 7th Edition lifecycle management (Initiating, Planning, Executing, Monitoring, Closing)
  • Earned Value Management (EVM) basics and variance analysis
  • Vendor evaluation and procurement management
  • Risk register at scale (20+ identified risks, mitigation ownership)
  • RACI matrix enforcement and escalation paths
  • Stakeholder management across competing priorities

Recommended Certifications:

CertificationVendorURLNotes
PMP (Project Management Professional) — NEW EXAM JULY 9, 2026PMIhttps://www.pmi.org/certifications/project-management-pmp/new-examNew format: 185 questions, 240 min; Business Environment 26%, Predictive 40%, Adaptive/Agile 60%; AI & sustainability focus; Early registration Dec 15, 2025; Pilot Jan 5–30, 2026; Live July 9, 2026. Current exam retires July 8, 2026.
PSM II (Professional Scrum Master II)Scrum.orghttps://www.scrum.org/professional-scrum-master-ii-certificationAdvanced Scrum; PSM I prerequisite; $150 exam fee
A-CSM (Advanced Certified ScrumMaster)Scrum Alliancehttps://www.scrumalliance.org/get-certified/scrum-master-track/advanced-certified-scrummaster1-day workshop; Scrum Alliance membership $39/year
SSM (Scaled Agile SAFe Scrum Master)Scaled Agile Inc.https://scaledagile.com/certification/scrum-master/8-hour course; $495; SAFe Level 2; salary bump 15–25% (StarAgile)
PRINCE2 PractitionerAXELOShttps://www.axelos.com/certifications/prince2Advanced; Foundation prerequisite; £168 exam fee
ITIL 4 Specialist (Create, Deliver & Support / Drive Stakeholder Value)AXELOShttps://www.axelos.com/certifications/itilMulti-path specialization; £79–99 per module

Salary (2026 US):
Project Manager (non-certified): $65,000–$109,000
Project Manager (PMP-certified): $120,000–$135,000 median; 29% premium over non-certified (Glassdoor; PMI 14th Edition Earning Power)

Senior PM (5–8 yrs exp): $115,000–$139,000 (Invensis Learning)

Salary (2026 UK):
PM (PRINCE2/PMP-certified): £42,000–£57,000; London: £62,000–£92,750 (Robert Half; APM Survey)

Salary (2026 South Africa):
IT Project Manager: R494,324–R1,078,473 (~USD $26,500–$58,000); Senior (8+ yrs): R1,245,907 (PayScale ZA; ERI SalaryExpert)


PROFESSIONAL (5–8 years) — Senior PM / Program Manager (PgMP)

Day-in-the-Life:

  • Managing cross-project dependencies and resource conflicts
  • Portfolio-level prioritization and benefit realization tracking
  • Mentoring 2–3 junior PMs and team leads
  • Executive steering committee presentations (CFO, CIO, board delegates)
  • Program roadmap alignment with organizational strategy
  • Managing $5M–$50M+ budgets across multiple teams

Required Core Skills:

  • Program-scale dependency mapping (critical path across teams)
  • Cross-functional team coordination and matrix org dynamics
  • Benefits realization and value tracking (pre/post-project ROI)
  • Portfolio prioritization and go/no-go governance
  • Advanced stakeholder management (C-suite, business units, vendors)
  • Risk and issue management at program scope

Recommended Certifications:

CertificationVendorURLNotes
PgMP (Program Management Professional)PMIhttps://www.pmi.org/certifications/program-management-professional-pgmp23 yrs PM exp or 16 yrs + Master's; median salary $135,000 (higher than PMP per PayScale); 4 hrs, 170 Q
RTE (Release Train Engineer, SAFe)Scaled Agilehttps://scaledagile.com/certification/safe-release-train-engineer/16-hour course; $2,000–$2,500; salary bump $12,000–$24,000 (StarAgile)
SPC (Solutions Practice Consultant, SAFe)Scaled Agilehttps://scaledagile.com/certification/safe-practice-consultant/5-day workshop; coach/consultant track; $4,500–$6,500
TOGAF (The Open Group Architecture Framework)The Open Grouphttps://www.opengroup.org/togafEnterprise architecture; 9.1 standard; cross-over with Program/Portfolio roles

Key Books (Program Perspective):

  • Project to Product (Mik Kersten, IT Revolution Press, 2018) – flow/value stream at scale
  • Making Things Happen (Scott Berkun, O'Reilly, 2008) – stakeholder management & prioritization
  • The Phoenix Project (Kim, Behr, Spafford, IT Revolution Press, 2013) – DevOps/Lean for IT ops
  • Accelerate (Forsgren, Humble, Kim, IT Revolution Press, 2018) – metrics-driven delivery

Salary (2026 US):
Program Manager (PgMP-certified): $122,062–$162,803 median $135,000 (10% premium over PMP only) (PayScale)


EXPERT (8+ years) — Portfolio Manager / Director PMO / VP Delivery

Day-in-the-Life:

  • Quarterly/annual portfolio review with board/C-suite
  • Strategic alignment of all in-flight programs with business objectives
  • Organizational restructuring and resource model design
  • Benefits portfolio tracking (aggregate value realization)
  • PMO governance policy and standard updates
  • Talent development and succession planning for PM leaders

Required Core Skills:

  • Portfolio-level governance and executive steering
  • Strategic roadmap alignment and business case evaluation
  • Organizational change management and capability building
  • Budget/resource allocation across competing initiatives
  • Stakeholder management at board level
  • PMO operations and metrics design

Recommended Certifications:

CertificationVendorURLNotes
PfMP (Portfolio Management Professional)PMIhttps://www.pmi.org/certifications/portfolio-management-professional-pfmp15 yrs PM + 5 yrs portfolio exp or equiv.; median salary $130,000–$140,000; 10–15% premium over PMP (Invensis Learning)
TOGAF 9 Certified (Advanced)The Open Grouphttps://www.opengroup.org/togafArchitecture governance; enterprise-level strategic fit
Executive MBA (Finance + Strategy track)Various UniversitiesCommon for Director PMO / VP progression; $60K–$120K total cost

Key Books (Portfolio + Executive Perspective):

  • Project to Product (re-read for strategy section)
  • Inspired (Marty Cagan, Wiley, 2017) – product strategy & portfolio thinking
  • Empowered (Cagan & Jones, Wiley, 2020) – building high-performing delivery orgs
  • The Lean Startup (Eric Ries, Crown Business, 2011) – iterative value delivery

Salary (2026 US):
Director PMO: $155,000–$230,000 (Glassdoor)
Senior Portfolio Manager: $180,000–$300,000+ (Invensis Learning)
VP Delivery: $200,000–$350,000+ (market-dependent)


GRC TRACK OVERVIEW

The Governance, Risk & Compliance career track progresses from technical audit execution through strategic compliance leadership. Certification is mandatory at every tier.

ENTRY (0–3 years) — IT Auditor (Junior) / Compliance Analyst

Day-in-the-Life:

  • Preparing audit workpapers and evidence collection matrices
  • Performing control testing (interviews, document review, test samples)
  • Writing observations and rating findings (High/Medium/Low/Informational)
  • Learning frameworks: NIST 800-53, ISO 27001, SOC 2, PCI-DSS, HIPAA
  • Shadowing managers in client meetings and audit presentations

Required Core Skills:

  • NIST SP 800-53 control mapping and assessment methodology
  • ISO/IEC 27001 ISMS (Information Security Management System) structure
  • SOC 2 Trust Services Criteria (CC, C, A, CO, SI, PO principals)
  • PCI-DSS compliance scope and control testing
  • HIPAA Security Rule and Breach Notification Rule basics
  • GDPR awareness (scope, processor/controller, DPA, data subject rights)
  • Audit workpaper organization and evidence standards
  • Report writing and finding substantiation

Recommended Certifications:

CertificationVendorURLNotes
CISA (Certified Information Systems Auditor)ISACAhttps://www.isaca.org/credentialing/cisa5 yrs IT audit exp (waivable with degree + 3 yrs); median salary $107,619–$115,600 (22% premium over non-cert) (ISACA 2025 Survey; ZipRecruiter); $325 exam
CGRC (Certified in Governance, Risk and Compliance)(ISC)²https://www.isc2.org/certifications/cgrcEntry-level GRC; no prerequisites; $225 exam; ISACA membership $75/yr
CIA (Certified Internal Auditor)The IIA (Institute of Internal Auditors)https://www.theiia.org/certifications/certified-internal-auditor-cia/General audit (not IT-specific); 7 yrs audit exp (waivable with degree); $250 exam per part (3 parts)
HCISPP (Healthcare Certified Information Security Professional)(ISC)²https://www.isc2.org/Certifications/HCISPPHealthcare-specific; CISSP or equivalent required first

Salary (2026 US):
Compliance Analyst (entry): $59,957–$72,853 (ZipRecruiter; Glassdoor)
IT Auditor (CISA-cert): $70,000–$130,000 depending on exp (Infosec Institute)
Median CISA holder: $107,619$115,600 (ISACA)

Free Resources:

  • ISACA Online Review Courses (member benefit)
  • AuditBoard / Drata Academy – free SOC 2 & ISO 27001 training modules
  • NIST.gov SP 800-53 PDF (free, comprehensive)
  • SANS Institute whitepapers on GRC fundamentals

ASSOCIATE (3–6 years) — Senior IT Auditor / GRC Analyst

Day-in-the-Life:

  • Leading audit engagements for multiple clients/business units
  • Mapping controls across 3–5 frameworks simultaneously (NIST, ISO, SOC 2, PCI, HIPAA)
  • Writing audit reports and presenting findings to Audit Committee
  • Developing remediation roadmaps with IT/Security teams
  • Evidence management using GRC tools (Drata, Vanta, AuditBoard, etc.)
  • Policy development and policy gap analysis
  • Preparing organizations for external audit readiness

Required Core Skills:

  • Multi-framework control mapping (NIST → ISO → SOC 2 → HIPAA alignment)
  • Risk-based audit prioritization and sample selection
  • Policy authoring and control design assistance
  • Audit readiness planning and timeline management
  • GRC tool proficiency (spreadsheet-based or software like Drata/Vanta)
  • Root-cause analysis and remediation tracking
  • Stakeholder communication across IT, security, and business

Recommended Certifications:

CertificationVendorURLNotes
CRISC (Certified in Risk and Information Systems Control)ISACAhttps://www.isaca.org/credentialing/crisc3 yrs exp in risk + controls; median salary $147,000–$151,000 (ZipRecruiter; Invensis Learning); $225 exam
CISM (Certified Information Security Manager)ISACAhttps://www.isaca.org/credentialing/cism5 yrs info security mgmt exp (waivable); salary $125,000–$160,000 global, $149,000 USD avg per ISACA (Knowledge Hut; iCert Global)
ISO/IEC 27001 Lead Implementer (PECB or BSI)PECB / BSIhttps://pecb.com/en/education-and-certification-for-individuals/iso-iec-27001/iso-iec-27001-lead-implementer5-day course; £3,000–$4,500; salary $102,886–$135,000 USA (ZipRecruiter)
ISO/IEC 27001 Lead Auditor (PECB or BSI)PECB / BSIhttps://pecb.com/en/education-and-certification-for-individuals/iso-iec-27001/iso-iec-27001-lead-auditor5-day course; £3,000–$4,500; leads ISO audits; 10–15% salary premium (ReadyNez)
ISO/IEC 27701 (Privacy)PECBhttps://pecb.com/en/education-and-certification-for-individuals/iso-iec-27701/iso-iec-27701-lead-auditorGDPR-aligned privacy management; 3-day course; £2,500–$3,500
CIPM (Certified Information Privacy Manager)IAPP (International Association of Privacy Professionals)https://iapp.org/certify/cipm/Privacy management (GDPR/CCPA); 3 yrs exp; $400 exam

Key Books (GRC Manager Perspective):

Salary (2026 US):
Senior IT Auditor (CISA + CRISC): $100,000–$140,000
GRC Analyst: $94,037–$123,117 (Glassdoor)


PROFESSIONAL (6–10 years) — IT Audit Manager / GRC Manager

Day-in-the-Life:

  • Managing audit teams (3–8 auditors) and external auditor relationships
  • Interpreting regulations for C-suite (board compliance updates)
  • Building risk dashboards for audit committee
  • Leading policy & procedure updates at organizational scope
  • Vendor risk assessment and third-party GRC program
  • Preparing Statement on Standards for Attestation Engagements (SSAE-18 SOC 2)
  • Incident investigation and breach notification coordination

Required Core Skills:

  • Audit team leadership and performance management
  • Regulatory landscape monitoring (new rules, standards, guidance)
  • Risk quantification at organizational scope
  • Governance & control documentation at portfolio level
  • Executive communication and board-level reporting
  • Third-party audit management (vendor assessments, auditor engagement)
  • Incident response and breach procedures

Recommended Certifications:

CertificationVendorURLNotes
CGEIT (Certified in the Governance of Enterprise IT)ISACAhttps://www.isaca.org/credentialing/cgeitEnterprise IT governance; 5 yrs IT exp + governance focus; high-earners tier per ISACA (ISACA Now Blog)
FAIR Practitioner (Open FAIR, FAIR Institute)FAIR Institutehttps://www.fairinstitute.org/Risk quantification and factor analysis; 3-day course; ~$3,000
IAPP Fellow Information Privacy Professional (FIP)IAPPhttps://iapp.org/certify/fip/Privacy leadership; 10+ yrs exp; $2,500 exam + prerequisites

Salary (2026 US):
IT Audit Manager: $107,550–$160,689 (PayScale; Glassdoor)
GRC Manager: $109,560–$204,511 national average $146,080 (Glassdoor)
San Francisco GRC Manager: $210,957 (+44% premium) (Glassdoor)


EXPERT (10+ years) — Director GRC / Chief Compliance Officer (CCO) / Chief Risk Officer (CRO) / CISO via GRC Route

Day-in-the-Life (Director GRC):

  • Quarterly regulatory landscape brief for Board Audit Committee
  • Executive risk dashboard and governance scorecard
  • Building compliance roadmap aligned to 3-year business strategy
  • Leading enterprise-wide incident response and crisis management
  • Third-party risk program oversight (vendor assessments, audits)
  • Talent pipeline for GRC leadership and specialist roles

Day-in-the-Life (Chief Compliance Officer):

  • Regulatory affairs and government agency liaison
  • Anti-corruption, FCPA, and sanctions compliance programs
  • Policy council chair and control framework evolution
  • Board-level reporting on compliance risk and maturity
  • Whistleblower program and non-retaliation oversight
  • Mergers & Acquisitions compliance due diligence

Day-in-the-Life (Chief Risk Officer):

  • Enterprise risk register and aggregated risk appetite framework
  • Business continuity and disaster recovery oversight
  • Risk committee meetings with board
  • Emerging risk identification (AI, geopolitics, supply chain)
  • Insurance and captive management strategy
  • ERM (Enterprise Risk Management) system selection and deployment

Day-in-the-Life (CISO via GRC Route):

  • Information security strategy aligned to audit findings
  • Security architecture and control design at enterprise scale
  • CISO-level vendor risk assessment (software supply chain, cloud providers)
  • Security awareness program and phishing campaign metrics
  • Executive incident response and breach notification
  • Cybersecurity budget and team capability roadmap

Required Core Skills (All Expert Roles):

  • C-suite communication and board reporting
  • Strategic planning at enterprise scope
  • Regulatory interpretation and compliance modeling
  • Organizational change management
  • P&L ownership (budget, FTE, tools)
  • Executive team collaboration (CIO, CFO, COO, CHRO)

Recommended Certifications (Expert Tier):

CertificationVendorURLNotes
CCSK (Certificate of Cloud Security Knowledge)Cloud Security Alliancehttps://cloudsecurityalliance.org/education/ccsk/Cloud-specific compliance; ~$250 exam; 8 hrs study
CRISK (Certified in Risk and Information Systems Control)ISACANo current offering (CRISC available at Associate tier)
Certified Compliance & Ethics Professional (CCEP)SCCE/Compliance Certification Boardhttps://www.sccecompliancecertification.org/CCO-focused; 5 yrs compliance exp; $500 exam
CISSP (Certified Information Systems Security Professional)(ISC)²https://www.isc2.org/Certifications/CISSPCISO-track; 5 yrs cybersecurity exp; $749 exam; also CISSP-CCSK bundle available
Executive MBA (Compliance, Risk, or Governance specialization)Major universitiesStanford GSB, Harvard Kennedy School, Kellogg (all offer compliance/risk tracks)

Salary (2026 US):
Director of GRC: $150,000–$220,000+
Chief Compliance Officer (F500): $181,021–$304,820 median $255,401 (Glassdoor; PayScale; Salary.com)
Chief Risk Officer (F500): $250,000–$400,000+ (market-dependent)
CISO via GRC route (US median): $321,000–$385,000 (Glassdoor); top enterprises $500,000–$1,000,000+ with equity (Cybersecurity Ventures; RSA Conference Report)


Lateral Pivots & Cross-Track Transitions

PM ↔ Program Manager ↔ Portfolio Manager (Linear Progression)

All three roles are mutually reinforcing within PMI's canon:

  • PM → PgM: Focus moves from single-project delivery to multi-project coordination and dependency management.
  • PgM → PfM: Scope expands to portfolio-level strategic alignment and benefit realization across the entire initiative portfolio.

Earn PMP first, then add PgMP (3–5 years later), then PfMP (3–5 years after PgMP). No lateral pivots required; each builds on the previous tier.

Scrum Master → Agile Coach → SAFe SPC → Enterprise Agile Coach

  • CSM/PSM I → Technical Scrum Master (1-team scope)
  • PSM II/A-CSM → Agile Coach (3–5 teams)
  • SAFe RTE or SPC → Program-level agile (ART, SAFe Release Train; salary bump $12K–$24K StarAgile)
  • SAFe SPC → Enterprise agile transformation consultant; highest Agile track compensation

IT Auditor → Risk Manager → Chief Risk Officer

Common transition in regulated orgs:

  • Start as CISA-certified IT Auditor (technical audit)
  • Move to CRISC (Risk & Control focus) as risk analyst
  • Add CGEIT (Governance) for IT director roles
  • Promotion to CRO (Chief Risk Officer) at C-suite level

GRC Manager → Chief Compliance Officer (CCO)

  • GRC Manager (CRISC + CGEIT)Chief Compliance Officer is a natural pipeline in regulated industries (finance, insurance, healthcare, pharma).
  • Requires business acumen (P&L, strategy) + regulatory depth + board communication.
  • Salary jump: GRC Manager $146K → CCO $255K–$305K (Glassdoor).

GRC Manager → Chief Information Security Officer (CISO) via GRC Route

Less traditional than security-first path, but increasingly common as:

  • Boards demand governance expertise in CISO roles
  • CISO role expands to include compliance (security controls = compliance controls)
  • GRC background brings audit/control rigor to security architecture

Path:
IT Auditor (CISA) → GRC Manager (CRISC) → CISO (add CISSP for credibility)

Salary differential:
CISO background in GRC: $300K–$500K vs. pure security background: $250K–$400K (depends heavily on org size & maturity).


Key Role Distinctions

PM vs. PgM vs. PfM (per PMI PMBOK 7th Edition)

DimensionProject ManagerProgram ManagerPortfolio Manager
ScopeSingle projectMultiple related projectsAll projects in organization
TimelineWeeks–monthsMonths–yearsYear+ (ongoing)
FocusSchedule, budget, scope, qualityCross-project dependencies, benefits realizationStrategic alignment, resource allocation, ROI
Team Size5–50 people50–200 peopleIndirect (oversees portfolio)
Key MetricOn-time, on-budget deliveryProgram benefits achieved, milestone cadenceStrategic value, organizational goal alignment
GovernanceProject steering committeeProgram steering & governance boardBoard/exec steering committee

CCO vs. CRO vs. CISO (Executive Risk Leadership)

RolePrimary FocusReports ToSalary Range (US 2026)
Chief Compliance Officer (CCO)Regulatory compliance (GDPR, SOX, HIPAA, FCPA, sanctions, AML)General Counsel or CEO$181K–$305K (Glassdoor)
Chief Risk Officer (CRO)Enterprise risk management (operational, financial, strategic, supply chain)CFO or CEO$250K–$400K+ (market-dependent)
Chief Information Security Officer (CISO)Cybersecurity strategy, incident response, security architectureCIO or CEO$321K–$385K median; top enterprises $500K–$1M+ (Cybersecurity Ventures)

Overlap:
All three roles manage risk, but in different domains. In smaller orgs, a single person may hold CCO + CRO duties; in F500s, these are separate leadership positions.


Regional Salary Data

United States (2026)

RoleEntry (0–2 yrs)Mid (3–6 yrs)Senior (7+ yrs)Director+
Project Coordinator$51K–$83K$65K–$109K$115K–$139K$155K–$230K
Project Manager (non-cert)$65K–$109K$115K–$139K
Project Manager (PMP-cert)$120K–$135K$135K–$173K
Program Manager (PgMP)$122K–$162K (median $135K)
Portfolio Manager (PfMP)$130K–$140K median$180K–$300K+
IT Auditor$60K–$90K$100K–$140K
CISA-certified Auditor$70K–$130K$100K–$150K
GRC Manager$109K–$204K (median $146K)
GRC Manager (SF)$210K (+44% premium)
IT Audit Manager$117K–$160K
Compliance Analyst$60K–$72K$72K–$123K
Director GRC$150K–$220K+
Chief Compliance Officer$181K–$305K
Chief Risk Officer$250K–$400K+
CISO$321K–$385K median (F500: $500K–$1M+)

United Kingdom (2026)

RoleEntryMidSenior
Project Manager£32K–£55K£42K–£57K£62K–£92.75K (London)
PMP-certified PM£42K–£57K£50K–£100K+
Programme Manager£50K–£70K£70K–£120K+

(Robert Half; APM Survey)

South Africa (2026)

RoleEntryMid (3–5 yrs)Senior (8+ yrs)
IT Project ManagerR494K–R1.07M (~USD $26.5K–$58K)R1.24M (~USD $67K)

(Bonus: R94,043 average)

(PayScale ZA; ERI SalaryExpert)


Conference & Community Resources

Project Management Conferences

GRC & Audit Conferences

Online Communities & Free Resources


2026 Updates & Certification Changes

PMI PMP Exam Update — July 9, 2026 (CRITICAL)

Current Timeline:

  • Pilot Registration: December 15, 2025 opens
  • Pilot Exam Window: January 5–30, 2026 (in-person only, Pearson VUE centers, English)
  • Pilot Takers: Receive full PMP certification if passed; free retake at official launch if failed
  • Current PMP Exam Retirement: July 8, 2026 (final day)
  • New PMP Exam Launch: July 9, 2026

New Exam Format:

  • Question Count: 185 questions (up from 180)
  • Duration: 240 minutes (4 hours)
  • Domain Weightings (Major Change):
    • Business Environment: 26% (up from 8% — major expansion)
    • Predictive (Waterfall) Approaches: 40% (down from ~50%)
    • Adaptive/Agile Approaches: 30% (up from ~25%)
    • Hybrid Approaches: 30% (up from ~25%)
  • New Content Focus: AI, sustainability, value delivery
  • Question Types: New graphic-based items, deeper scenario blocks, revised eligibility rules

Candidate Action:

  • Take current PMP before July 8, 2026 OR register for pilot and attempt Jan 5–30, 2026
  • PMBOK 8th Edition aligns with new exam; PMBOK 6 still acceptable until July 8, 2026

(PMI Official Announcement; PMI Blog)

ITIL 5 (Rumored 2026 Update)

Status: Verify with AXELOS — no confirmed 2026 launch date as of April 2026. Current ITIL 4 remains the active standard.

ISACA AAIR — Advanced in AI Risk (New 2026)

Status: Under development; expect launch mid-to-late 2026. Will complement CISM and CGEIT for AI governance and risk topics.

IAPP CIPP/E Updates (2026)

Status: GDPR, UK DPA 2018, and other privacy laws continue to evolve. IAPP updates exam domain weightings regularly. Check IAPP site for latest changes: https://iapp.org/


Sources

Certification & Exam Information

Salary & Compensation Data

Books & Academic Resources

Communities & Events


Appendix: Certification Prerequisite Summary

PM Track Prerequisites

CertExperience ReqHours/StudyCostNotes
CAPMNone60–80 hrs$555Entry-level; high pass rate
PMP3 yrs (4500 hrs) or equiv. w/ degree120–150 hrs$555Changes July 9, 2026
PgMP23 yrs or 16 yrs + Master's150–200 hrs$555Higher salary tier
PfMP15 yrs PM + 5 yrs portfolio150–200 hrs$555Executive tier

GRC Track Prerequisites

CertExperience ReqHours/StudyCostNotes
CISA5 yrs (waivable w/ degree + 3 yrs)150–200 hrs$325Gold standard; high ROI
CGRCNone50–80 hrs$225Entry-level GRC
CIA7 yrs (waivable w/ degree)200+ hrs (3 exams)$750 (3×$250)General audit
CRISC3 yrs exp in risk + controls120–150 hrs$225Risk focus; high salary
CISM5 yrs info security mgmt (waivable)150–200 hrs$225Security management
ISO 27001 Lead Impl.2 yrs info security120 hrs course$3K–$4.5K5-day course
ISO 27001 Lead Auditor3 yrs audit/management120 hrs course$3K–$4.5K5-day course; audit focus

Document History

VersionDateAuthorNotes
1.030 April 2026Deep Dive Research Phase 8Initial comprehensive dual-track roadmap. All URLs and salary data current as of April 30, 2026.

Last Updated: 30 April 2026
Next Review: Q3 2026 (annual salary survey updates, Q4 certification launches)

Rate this article
Was this helpful?
Comments ()
0/2000