- The Four SISA Price Points at a Glance
- What Each Option Actually Buys You
- How Eligibility Routes Change Your Total Spend
- Choosing the Right Package for Your Situation
- Fees and Charges Beyond the Sticker Price
- Where Your Prep Money Should Go: The Six Exam Topics
- A Budget-Conscious Preparation Sequence
- Weighing the Cost Against Career Value
- Frequently Asked Questions
- SISA's store lists $249 for certification only, including the application, with no training attached.
- Training plus certification is listed at $549; training alone is $480; the super bundle is $600 with one retake.
- The exam is 50 questions in 60 minutes with a 66% passing score, delivered online with a proctor.
- Eligibility needs one route: one year of security work, SISA's 16-hour workshop, or equivalent 16-hour formal training.
The Four SISA Price Points at a Glance
The Certified Payment Industry Security Implementer (CPISI) credential is issued by SISA, and SISA's own training and certification store is the authoritative place to read current prices. The store lists four purchase options for the base CPISI. Two things to know before you read the numbers: the store reproduces amounts with a dollar sign but does not display an explicit currency code, so check the currency shown at checkout before you commit a budget. Prices can also change, so treat the table below as a snapshot of the store listing rather than a permanent rate card.
| Option | Listed Price | Training Included? | Exam Included? | Retake Included? |
|---|---|---|---|---|
| Certification only (application included) | $249 | No | Yes | No |
| Training only | $480 | Yes | No | Not applicable |
| Training plus certification | $549 | Yes | Yes | No |
| Super bundle | $600 | Yes | Yes | One retake |
Notice how small the gaps are once training enters the picture. Training alone is $480, while training plus certification is $549, so the exam attempt effectively costs about $69 on top of the course when you buy them together. The super bundle adds roughly $51 more than the standard training-plus-certification package and brings a retake with it. That arithmetic matters when you decide whether to self-study or enroll in a course, and we will return to it below.
What Each Option Actually Buys You
Certification only: $249
This is the exam attempt with the application included. It suits candidates who already qualify through verifiable work history or through equivalent formal training taken elsewhere. You supply your own preparation. The cost is lowest, but you carry the full risk of an unprepared first attempt, because this tier does not list a retake. For a detailed look at what qualifies, see our guide to CPISI requirements, eligibility and prerequisites.
Training only: $480
This covers SISA's preparation program without the exam. It is a niche choice, mostly useful for a team lead who wants staff to absorb the PCI DSS material without every person sitting the exam immediately, or for someone who plans to buy the exam separately later. Since the combined package costs only $69 more, most individual candidates who want the course will find the bundled option more sensible.
Training plus certification: $549
This is the straightforward all-in package for a candidate who needs the course to qualify and wants to sit the exam on the same account. The hybrid preparation currently references PCI DSS 4.0.1, which is worth noting because your study materials should match the standard version that the course teaches. The preparation program is organized into eighteen hybrid modules, but treat that as training structure, not as a count of exam domains or a measure of exam time.
Super bundle: $600
The top tier adds one retake. Its value is insurance. If you fail once, you do not pay the $249 certification-only rate again to try a second time. Given that the whole difference from the standard package is a modest amount, the bundle is the lowest-regret choice for candidates who are new to payment security and uneasy about a 66% threshold.
Key Takeaway
A retake bought separately would cost you the certification-only price again. Compared with that, the super bundle's retake coverage is inexpensive protection if there is any real chance you will need a second attempt.
How Eligibility Routes Change Your Total Spend
SISA's current certification page requires you to meet at least one of three routes before sitting the exam:
- At least one year of verifiable full-time information-security-related work experience.
- Completion of SISA's 16-hour CPISI workshop.
- Equivalent formal training of at least 16 hours that covers the exam topics.
Your route largely determines which price you actually pay. A candidate with a year of full-time security work (a SOC analyst, network security engineer or compliance associate, for example) can qualify on experience and pay only the $249 certification-only price. A candidate without that history needs either SISA's workshop or comparable training, which moves the realistic spend toward the $549 or $600 packages.
For the exact scoring threshold and how it is applied, read our breakdown of the CPISI passing score.
Choosing the Right Package for Your Situation
Profile A: Experienced security practitioner
You have at least a year of verifiable full-time security work and are comfortable with firewalls, logging, vulnerability scanning and access control.
- Certification only at $249 is the natural fit.
- Budget extra time, not extra money, for mapping your experience to payment-specific requirements.
- Consider the super bundle only if you want the retake safety net.
Profile B: Career changer or early-career professional
You are moving into payment security from IT support, development, audit or general compliance, without a full year of directly relevant work.
- Training plus certification at $549 satisfies eligibility and preparation together.
- The super bundle at $600 is worth serious thought because the retake covers a first-attempt miss.
- Do not buy certification-only unless you have equivalent training from elsewhere to document.
Profile C: Team or employer sponsorship
A manager is funding several people at once.
- Training only at $480 can be used to build shared knowledge before deciding who sits the exam.
- Ask about the sponsoring organization's own invoicing and any bulk arrangements directly with SISA; the public store does not describe group pricing, so do not assume discounts exist.
If you are still deciding whether the credential suits your path at all, our overview of what CPISI certification is explains the credential's purpose and audience.
Fees and Charges Beyond the Sticker Price
The store notes that additional convenience charges are nonrefundable. The public pages do not itemize what those charges are in every case, so read the checkout screen carefully and treat any line item added there as final once paid. Beyond that, the sources do not give us a verified figure for retake fees outside the super bundle, rescheduling fees, or exam-fee changes, so do not budget against numbers you have not seen at checkout.
Several cost items are also unverified in the public material, and you should confirm them with SISA directly rather than assume:
- Renewal and continuing education: The validity period, renewal interval and any CPE requirements are not confirmed in the retrievable public sources, so we cannot state a renewal cost. Check SISA's certification policy hub before assuming the credential is a one-time expense.
- Proctoring requirements: The exam is described as online and proctor-driven in SISA's hybrid-program FAQ. Plan for a quiet room, a working webcam and a stable connection so you do not lose an attempt to a technical problem.
- Study materials outside SISA: Any third-party books, practice tests or the PCI DSS documents themselves are optional extras that you should price separately.
Where Your Prep Money Should Go: The Six Exam Topics
SISA publishes six exam-topic headings for the base CPISI. They are exam objectives rather than weighted domains, and the sources do not provide an official percentage distribution, so spend your preparation effort across all six rather than gambling on a favorite. Here is what each topic demands of you as a candidate. For a deeper walk-through, see our complete guide to all six CPISI content areas.
1. Background of Payment Security
The foundation: how card payments flow, who the parties are, and why cardholder data attracts attackers.
- Understand the roles of merchants, acquirers, issuers and service providers.
- Know why a standard like PCI DSS exists and what data it protects.
- Be ready for scenario questions that ask which party bears which responsibility.
2. Building and Maintaining a Secure Network and Systems
Network and system hardening controls that keep the cardholder data environment defensible.
- Firewall and network security control configuration concepts.
- Secure configuration of systems and removal of vendor defaults.
- Network segmentation as a way to limit scope.
3. Protecting Account Data
How stored and transmitted account data is kept unreadable and minimized.
- What data may and may not be retained after authorization.
- Rendering stored account data unreadable through approaches such as encryption, truncation, masking or tokenization.
- Protecting data in transit over open, public networks.
4. Maintaining a Vulnerability Management Program
Keeping systems free of known weaknesses over time.
- Protection against malware and the processes that keep protections current.
- Patching and secure development practices for systems and software.
- Identifying and ranking vulnerabilities so remediation is prioritized.
5. Implementing a Strong Access Control Measures
Limiting who can reach cardholder data and proving who they are.
- Need-to-know access and least privilege.
- Unique user identification and authentication, including multi-factor concepts.
- Physical access restrictions to areas holding cardholder data.
6. Regularly Monitoring and Testing Networks
Detecting problems and validating that controls actually work.
- Logging and log review to trace access to systems and data.
- Periodic vulnerability scanning and penetration testing.
- Detecting unauthorized changes and responding to findings.
Because the $249 certification-only tier includes no course, candidates on that route must supply all six topics themselves. That is the real hidden cost of the cheapest option: your time. Candidates who find that daunting should read our assessment of how hard the CPISI exam is before deciding.
A Budget-Conscious Preparation Sequence
Since the exam is 50 questions in 60 minutes, you have roughly a minute and a bit per question, so speed with the PCI DSS material matters as much as recall. The sequence below ties each phase to the six topics and to a spending decision. It is a planning aid, not an official syllabus.
Background of Payment Security
- Learn the payment ecosystem and vocabulary first; every later topic assumes it.
- Decide your package now, since eligibility must be satisfied before the exam.
Secure Networks and Protecting Account Data
- These are the most technical and concept-dense topics, so give them the longest block.
- Practice distinguishing protection methods for stored versus transmitted data.
Vulnerability Management and Access Control
- Pair patching and malware concepts with authentication and least-privilege ideas.
Monitoring and Testing, then full review
- Finish with logging, scanning and testing, then run timed practice sets of 50 questions in 60 minutes.
- Schedule only when you pass practice sets comfortably above the 66% line.
For a fuller approach to sequencing your preparation, see our CPISI study guide, and when you are ready to test yourself under timed conditions, try the practice questions on the CPISI Exam Prep practice test site.
Weighing the Cost Against Career Value
At a few hundred dollars, CPISI sits at the accessible end of security credentials. Its value depends on whether your work touches payment environments: merchants, payment processors, banks, fintechs and the consultancies that serve them all need people who can implement PCI DSS controls day to day. The credential signals applied implementation knowledge across the six topics rather than a broad management-level security overview.
We do not have verified salary or pass-rate figures for this credential, and we will not invent them. If you want to explore the career side, our articles on whether the CPISI is worth it, CPISI earnings and CPISI jobs discuss the role types and how to evaluate the return for your situation qualitatively.
Key Takeaway
The cost question is really a gap question. If you already meet an eligibility route, the $249 price is small relative to a security professional's earning potential. If you do not, the $549 or $600 package is the price of both qualifying and preparing, and the super bundle's retake lowers your downside.
Frequently Asked Questions
The certification-only option at $249 is the lowest listed price and includes the application. It only works if you already meet an eligibility route, such as one year of verifiable full-time information-security work or equivalent formal training of at least 16 hours. Confirm the checkout currency before budgeting, since the store does not show an explicit currency code.
Training is not strictly required if you qualify another way. You need to satisfy one route: a year of verifiable full-time information-security work, SISA's 16-hour CPISI workshop, or equivalent formal training of at least 16 hours covering the exam topics. If none applies to you, a training-bearing package is the practical choice.
The super bundle at $600 includes one retake. The certification-only, training-only and training-plus-certification listings do not mention a retake. If you are uneasy about the 66% passing score, the extra spend over the standard $549 package buys meaningful insurance.
The store states that additional convenience charges are nonrefundable. Beyond that, the public pages we reviewed do not lay out a full refund policy, so read the terms at checkout and consult SISA's certification policy hub before paying if refund flexibility matters to you.
We could not verify the credential's validity period, renewal interval or any continuing-education requirements from the retrievable public sources, so we cannot quote a renewal cost. Check SISA's certification policy pages directly before assuming the credential is a one-time purchase, and read our exam dates and scheduling guide for how to plan your sitting.