- The base CPISI exam is 50 questions in 60 minutes, with a 66% passing score.
- Six published exam topics define scope; SISA does not publish percentage weights for them.
- Eligibility needs just one route: one year of security work, SISA's 16-hour workshop, or equivalent 16-hour training.
- Certification-only costs $249 in the official store; training plus certification costs $549.
Identity Check: Which CPISI This Cheat Sheet Covers
The acronym CPISI gets reused across the credential world, so start by confirming you are studying the right one. This cheat sheet covers Certified Payment Industry Security Implementer, the base-level certification issued by SISA (SISA Institute). It does not cover CPISI Advanced or CPISI-D, and nothing here applies to similarly abbreviated credentials from other bodies.
If you are still orienting yourself, these companion pieces cover the basics: What Is CPISI?, What Does CPISI Stand For?, and CPISI Certification. This page is for candidates who already know what the credential is and want a single-sitting review of the facts that matter on exam day.
The Exam at a Glance
These are the verified logistics for the base CPISI examination:
| Item | What to Know |
|---|---|
| Number of questions | 50 |
| Time allowed | 60 minutes |
| Passing score | 66% |
| Delivery | Online and proctor-driven, per SISA's hybrid-program FAQ |
| Published scope | Six exam-topic headings (listed below) |
| Published domain weights | None verified; treat all six topics as fair game |
Run the arithmetic now so it is not a surprise later. Sixty minutes across 50 questions leaves roughly 72 seconds per question, with no slack for lingering. At a 66% threshold on 50 items, you need to answer a little over two-thirds correctly. For a deeper look at what that threshold means in practice, see CPISI Passing Score 2026: Exactly What You Need to Pass, and for a realistic read on difficulty, How Hard Is the CPISI Exam?
Eligibility: Three Ways In
SISA's current certification page requires you to meet one of the following routes, not all of them:
- Work experience: at least one year of verifiable, full-time, information-security-related work.
- SISA's own training: the 16-hour CPISI workshop.
- Equivalent formal training: at least 16 hours of training that covers the blueprint topics.
This matters because older material still circulating online describes a two-day course requirement and a 60% pass mark. That language comes from a legacy issuer-owned Credly badge listing and conflicts with the current certification page. Use the current page (66% passing score, three eligibility routes) as your source of truth. The full qualification picture is in CPISI Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Fee and Registration Mechanics
SISA's official store lists these price points:
| Package | Listed Price | What It Includes |
|---|---|---|
| Certification only | $249 | Exam, including the application |
| Training plus certification | $549 | Training bundled with the exam |
| Training only | $480 | Training without the exam |
| Super bundle | $600 | Includes one retake |
Two caveats belong on your cheat sheet. First, the store shows dollar notation without an explicit currency code, so confirm the currency at checkout before budgeting. Second, additional convenience charges are nonrefundable. If you already satisfy a work-experience or equivalent-training eligibility route, certification-only is the lean option; if you want a safety net, the super bundle is the only listed package that includes a retake. A full breakdown lives in CPISI Certification Cost 2026: Complete Pricing Breakdown.
Key Takeaway
Decide your eligibility route first, then pick the package. Candidates with a year of full-time security work may only need the $249 certification-only option, while those relying on SISA's training should compare the $549 and $600 bundles, especially if a retake feels likely.
The Six Exam Topics, Domain by Domain
SISA publishes six exam-topic headings. They are exam objectives, not an editorial allocation of PCI DSS requirements, and no official percentage distribution is available. Do not assume equal weighting, and do not invent a seventh domain by mapping the entire PCI DSS requirement list onto this exam. For the extended walkthrough, see CPISI Exam Domains 2026: Complete Guide to All 6 Content Areas.
Domain 1: Background of Payment Security
The foundation topic. Expect questions that test whether you understand the payment ecosystem and why card-data security standards exist.
- Who the participants in a card payment are and where cardholder data flows between them
- Why a data security standard exists and what risk it addresses
- Vocabulary of the field, since later questions assume you speak it fluently
- The relationship between the standard, assessors, and the organizations being assessed
Domain 2: Building and Maintaining a Secure Network and Systems
The infrastructure topic. This is where network protection and secure configuration live.
- Network security controls and how they restrict traffic to and from the cardholder data environment
- Secure configuration of systems, including removing vendor defaults
- How segmentation shapes the scope of what must be protected
- Implementer-level thinking: not just what a control is, but how you would put it in place
Domain 3: Protecting Account Data
The data-handling topic, and one candidates should expect to be practical. The focus is on keeping stored and transmitted account data from being exposed.
- What account data is, and which elements may or may not be retained
- Protecting data at rest versus data in transit
- Cryptographic protection concepts and sound key handling
- Minimizing storage so there is less to protect in the first place
Domain 4: Maintaining a Vulnerability Management Program
The ongoing-hygiene topic. It covers how an organization finds and fixes weaknesses over time.
- Protecting systems against malicious software
- Patching and the processes that keep systems current
- Secure development and change practices for in-scope systems
- Why vulnerability management is a continuous program rather than a one-time task
Domain 5: Implementing a Strong Access Control Measures
The who-can-touch-what topic. Note that the published heading uses this exact phrasing.
- Restricting access to account data on a business need-to-know basis
- Identifying and authenticating users, including stronger authentication concepts
- Controlling physical access to systems and data
- How individual accountability ties into access design
Domain 6: Regularly Monitoring and Testing Networks
The verification topic. It covers how an organization proves its controls work and notices when they do not.
- Logging and monitoring access to network resources and account data
- Regular security testing, including scanning and penetration-style assessment concepts
- Detecting unauthorized changes and responding to what monitoring reveals
- How testing results feed back into the vulnerability management program
Known Conflicts and Unverified Items
Part of exam readiness is knowing what you do not know. A good cheat sheet flags the gaps rather than papering over them.
Resolved conflict: pass mark and eligibility
The legacy Credly badge listing describes a 60% pass mark and a two-day course requirement. The current SISA certification page states 66% and three alternative eligibility routes. Go with the current page.
Unverified: blueprint and handbook details
- The exam blueprint label on SISA's page does not lead to a retrievable linked document, and a separate candidate handbook was not located.
- The six topics are the verified public list, not a confirmed exhaustive blueprint.
- No official percentage distribution across topics exists in the public sources.
Unverified: validity and renewal
Certification validity, renewal intervals, and CPE numbers could not be confirmed. A legacy CPE policy page is indexed by search engines, but its full text was not retrievable, so no figures should be taken from search excerpts or borrowed from another SISA credential. Check SISA's certification-policy hub directly before making any career-planning assumption.
Training structure is not exam structure
SISA's hybrid program includes eighteen modules and workshop hours. Those describe how training is delivered. They do not equal eighteen exam domains, and they do not tell you anything about exam length. The exam is six topics, 50 questions, 60 minutes.
Key Takeaway
When a number you find online conflicts with SISA's current certification page, trust the current page. When no number exists at all, such as for domain weights or renewal, write "unknown" on your cheat sheet instead of guessing.
Sequencing the Six Domains in Your Prep
Since no weighting is published, an even spread with a deliberate order is the sensible approach. The sequence below builds vocabulary first, then controls, then verification. For fuller planning, see the CPISI Study Guide 2026: How to Pass on Your First Attempt.
Domain 1 plus Domain 2
- Learn the payment ecosystem and terminology first; everything else builds on it
- Study network controls and segmentation while the scope concept is fresh
Domain 3 plus Domain 5
- Pair account data protection with access control, since both revolve around who sees what data and how it is shielded
- Practice distinguishing data-at-rest from data-in-transit scenarios
Domain 4 plus Domain 6
- Study vulnerability management and monitoring/testing together, since testing results feed remediation
- Finish with timed mixed-domain sets at roughly 72 seconds per question
Adjust the order if your background tilts one way: a network engineer may breeze through Domain 2 and need more time on Domain 3, while an auditor may know Domains 1 and 6 cold and need hands-on intuition for Domains 2 and 4. Timed practice at the real pace is the best way to find your weak spots, and you can drill them on the CPISI practice test site. Training options are summarized in CPISI Training.
Who Values This Credential
The CPISI sits in the payment-security implementation space, so it fits people whose work touches cardholder data environments. Typical audiences include:
- Security and compliance staff at merchants, payment processors, and service providers who help implement card-data controls
- IT and network engineers responsible for in-scope systems
- Consultants and assessors' support teams who need a recognized baseline in payment-security implementation
- Career changers entering information security who want a payments-focused credential with a modest entry route
No verified salary or pass-rate figures are available for this credential, so treat any specific number you see online with suspicion. For a qualitative treatment, see CPISI Salary Guide 2026, CPISI Pass Rate 2026: What the Data Shows, CPISI Jobs, and the broader Is the CPISI Certification Worth It? Complete ROI Analysis.
Quick-Fire FAQ
The base CPISI examination has 50 questions and a 60-minute time limit, with a passing score of 66%. It is delivered online with a proctor, according to SISA's hybrid-program FAQ.
Background of Payment Security; Building and Maintaining a Secure Network and Systems; Protecting Account Data; Maintaining a Vulnerability Management Program; Implementing a Strong Access Control Measures; and Regularly Monitoring and Testing Networks. SISA does not publish percentage weights for them.
No. You need to meet only one eligibility route: at least one year of verifiable full-time information-security-related work, SISA's 16-hour CPISI workshop, or equivalent formal training of at least 16 hours covering the blueprint topics.
The current SISA certification page states 66%. A legacy Credly badge listing shows 60% and a two-day course requirement, but that conflicts with the current page, so use 66% and the current eligibility routes.
Validity, renewal intervals, and CPE requirements could not be verified from retrievable sources. Check SISA's certification-policy hub directly rather than relying on search snippets or details from other credentials.