CPISI logo
Focused certification exam prep
Start practice

CPISI Exam Domains 2026: Complete Guide to All 6 Content Areas

TL;DR
  • SISA publishes six unweighted CPISI exam topics; no official percentage distribution per domain has been verified.
  • The base CPISI exam has 50 questions in 60 minutes, with a 66% passing score.
  • Domains 2 through 6 follow the familiar PCI DSS goal-style headings; Domain 1 covers payment security background.
  • Eligibility needs one route: one year of security work, SISA's 16-hour workshop, or equivalent 16-hour training.

How SISA Publishes the Six CPISI Domains

The Certified Payment Industry Security Implementer (CPISI) is a SISA Institute credential. On its current certification page, SISA lists six exam topics. Those six headings are the verified public scope of the exam, and they are the backbone of this guide. Before going further, a few clarifications matter because they affect how you should study.

  • The topics are unweighted. SISA does not publish a percentage split across the six areas on the page we could verify. Anyone quoting "Domain 3 is 30% of the exam" for this credential is guessing.
  • They are exam objectives, not a requirement-by-requirement map. The headings echo the PCI DSS goal structure, but SISA presents them as exam topics. Do not assume every individual PCI DSS requirement is tested, and do not assume a seventh hidden domain exists.
  • The list is unversioned. SISA's current hybrid preparation references PCI DSS 4.0.1, but that curriculum reference does not amount to a dated exam-outline release. Treat it as the best available guide to what the training emphasizes.
  • The scope here is the base CPISI. This article does not cover CPISI Advanced or CPISI-D, which are separate offerings.
A note on the blueprint document: The certification page displays an "Exam Blueprint" label, but no linked, retrievable blueprint document or separate candidate handbook was available when this guide was prepared. Re-check SISA's page before you commit your study plan to any sub-topic list you find elsewhere.

For a broader introduction to the credential itself, see What Is CPISI Certification?. If you want a structured plan built around these domains, pair this article with the CPISI Study Guide 2026.

Exam Format and Registration Mechanics

Knowing the shape of the exam tells you how deeply to study each domain. With only 50 questions in 60 minutes, you have roughly a minute and a bit per question, which rewards confident recall of core payment-security concepts over slow derivation.

ItemVerified detail
Questions50
Time limit60 minutes
Passing score66%
DeliveryOnline, proctor-driven, per SISA's hybrid-program FAQ
Eligibility (meet one)At least one year of verifiable full-time information-security work; or SISA's 16-hour CPISI workshop; or equivalent formal training of 16+ hours covering the blueprint topics
Certification only$249, including application
Training plus certification$549
Training only$480
Super bundle$600, including one retake

Two caveats on the numbers. First, the store shows dollar notation without an explicit currency code, so confirm the currency at checkout. Second, additional convenience charges are nonrefundable. For the full money picture, read the CPISI Certification Cost 2026 breakdown.

On the passing score, you may see a legacy issuer-owned Credly badge that cites a 60% pass mark and a two-day course requirement. The current certification page states 66% and lists alternative eligibility routes. Plan around the current page: 66%, which on a 50-question exam means you should aim to answer comfortably more than 33 questions correctly. Our CPISI Passing Score guide covers this conflict in more detail, and CPISI Requirements 2026 explains the three eligibility routes.

Also note the 18 hybrid modules in SISA's training program. Those are a training structure, not a count of exam domains and not an indication of exam length. The exam topics remain six.

Domain 1: Background of Payment Security

Background of Payment Security

This is the orientation domain. It establishes why card-data protection exists and who the players are, which gives context to every later domain.

  • How card payments flow between cardholders, merchants, acquirers, issuers, and payment brands
  • What cardholder data and sensitive authentication data are, and why they attract attackers
  • The role of the PCI Security Standards Council and the purpose of the PCI DSS
  • Who must comply, and how scope is determined by where account data is stored, processed, or transmitted
  • Why a security implementer, rather than an assessor, is the intended audience of this credential

Candidates with a security background often underestimate this domain because it feels like vocabulary. That is a mistake. Scoping questions, such as which systems fall into the cardholder data environment, depend on the payment-flow concepts introduced here. If you cannot distinguish a merchant from an acquirer or explain what sits in scope, later domain questions become harder.

One independence point is worth knowing: SISA states that its training and certification are independent of PCI SSC endorsement. CPISI is a SISA credential, not a PCI Council qualification. For how it differs from a general definition, see What Is CPISI? and What Does CPISI Stand For?.

Domain 2: Building and Maintaining a Secure Network and Systems

Building and Maintaining a Secure Network and Systems

The perimeter and configuration domain. It covers the controls that keep the environment hardened from the start.

  • Network security controls such as firewalls and segmentation that isolate the cardholder data environment
  • Documenting and reviewing network diagrams and data-flow diagrams
  • Replacing vendor-supplied default passwords and settings on systems and devices
  • Secure configuration standards and the removal of unnecessary services and functions
  • Securing administrative access that crosses networks

Expect scenario-style thinking here: given a flat network where a point-of-sale system shares a segment with office workstations, what control reduces scope and risk? Segmentation is a recurring theme because it can shrink the number of systems that must meet full controls. Know the reasoning, not just the definition.

Domain 3: Protecting Account Data

Protecting Account Data

The data-centric domain, and for many implementers the one with the most hands-on consequences.

  • What account data may and may not be stored, and for how long
  • Why sensitive authentication data must not be retained after authorization
  • Masking and truncation of the primary account number when displayed
  • Rendering stored account numbers unreadable through techniques such as strong cryptography, tokenization, or hashing
  • Cryptographic key management: generation, storage, rotation, and retirement
  • Protecting account data in transit across open, public networks

This is where precision pays off. Questions in this area tend to turn on a distinction: storage versus transmission, masking versus encryption, tokenization versus truncation. Build a one-page comparison of these techniques and what each protects. Our CPISI Cheat Sheet is a good place to consolidate that kind of quick-reference material.

Why Domain 3 deserves extra time: Even without an official weighting, protecting stored and transmitted account data is the heart of why payment-security standards exist. Misunderstanding what can be retained is a classic way candidates lose points, so treat the retention rules as must-memorize material.

Domain 4: Maintaining a Vulnerability Management Program

Maintaining a Vulnerability Management Program

The ongoing-hygiene domain: keeping systems resilient against known threats.

  • Protecting systems and networks from malicious software with anti-malware solutions
  • Identifying, ranking, and remediating security vulnerabilities, including patching timelines for critical fixes
  • Secure software development practices for bespoke and custom applications
  • Managing changes to systems so security is not undermined
  • Protecting public-facing web applications

The conceptual thread is lifecycle: find, rank, fix, verify. Questions often present a vulnerability finding and ask what the appropriate next step or priority is. Understand how risk ranking drives remediation order, and how secure development practices prevent flaws from reaching production in the first place.

Domain 5: Implementing Strong Access Control Measures

Implementing Strong Access Control Measures

The people-and-identity domain. It answers the question: who can reach cardholder data, and how is that proven?

  • Restricting access to system components and cardholder data by business need to know
  • Identifying users and authenticating access with unique IDs
  • Multi-factor authentication and password or passphrase strength expectations
  • Managing user lifecycles: provisioning, review, and prompt removal of access
  • Restricting physical access to cardholder data and systems, including visitor handling and media protection

Note that this domain spans both logical and physical access. Candidates who revise only digital controls are sometimes caught off guard by questions about badge systems, visitor logs, or secure handling of media. Treat the physical side as first-class material.

Domain 6: Regularly Monitoring and Testing Networks

Regularly Monitoring and Testing Networks

The assurance domain. It covers how you detect problems and prove that controls actually work.

  • Logging and monitoring access to system components and cardholder data
  • Audit log protection, review, and retention
  • Time synchronization so log events can be correlated
  • Vulnerability scanning and penetration testing, including internal versus external distinctions
  • Intrusion detection or prevention and change-detection mechanisms
  • Maintaining an information security policy and incident response readiness

Know the difference between scanning and penetration testing and when each is expected; this is a favorite area for distinguishing questions. Also be ready to reason about what a good log entry contains and why integrity of logs matters.

Sequencing the Domains in Your Preparation

Rather than a generic schedule, here is a domain-aware order that follows how the topics build on each other. Adjust durations to your own background; someone with years of firewall work can compress Domain 2, while a newcomer to payments should expand Domain 1.

Week 1

Domain 1 and scoping

  • Learn the payment flow and the players
  • Practice deciding what is in scope and why
Week 2

Domains 2 and 3

  • Segmentation and secure configuration
  • Retention rules, masking, tokenization, and key management
Week 3

Domains 4 and 5

  • Vulnerability lifecycle and secure development
  • Logical and physical access control
Week 4

Domain 6 and full review

Because the exam is only 60 minutes, practice under a clock. A set of 50 questions answered in a single sitting will expose which domains slow you down. The practice questions on the main site are built for exactly that kind of timed drilling.

Key Takeaway

Without published weightings, do not skip a domain. Spread your effort evenly at first, then shift extra time toward whichever domain your timed practice shows is weakest.

Where the Credential Gets Used

CPISI targets people who implement payment-security controls: security engineers, IT and network administrators, compliance analysts, and consultants who support merchants and service providers working toward PCI DSS alignment. Because SISA is a payment-security training and assessment organization, the credential is most visible among those operating in or around that ecosystem. If you are weighing whether it suits your path, the ROI analysis, the salary guide, and the CPISI jobs overview go further. Be cautious about any specific earnings claim; this guide does not cite one because none is verified for this credential.

A final point on longevity: certification validity, renewal intervals, and continuing-education numbers for CPISI are not verified from retrievable SISA text. Check SISA's certification-policy hub directly for current renewal rules rather than relying on secondhand figures.

Frequently Asked Questions

How many domains does the CPISI exam cover?

SISA publishes six exam topics: Background of Payment Security; Building and Maintaining a Secure Network and Systems; Protecting Account Data; Maintaining a Vulnerability Management Program; Implementing Strong Access Control Measures; and Regularly Monitoring and Testing Networks.

Are the CPISI domains weighted by percentage?

No official percentage distribution has been verified. The six headings are published as unweighted exam topics, so avoid any source that assigns specific percentages to each one.

What is the format and passing score of the base CPISI exam?

The exam has 50 questions in 60 minutes with a 66% passing score, delivered online with proctoring per SISA's hybrid-program FAQ. A legacy badge page cites 60%, but the current certification page governs. See the difficulty guide for what that means in practice.

Do I have to take SISA's training to sit the exam?

Not necessarily. You need to meet one route: a year of verifiable full-time information-security work, SISA's 16-hour CPISI workshop, or equivalent formal training of at least 16 hours covering the blueprint topics.

Which PCI DSS version should I study?

SISA's current hybrid preparation references PCI DSS 4.0.1, though the public exam topic list itself is unversioned. Study the 4.0.1 material while treating the six published topics as your scope. For pass-rate context, see what the data shows.

Ready to pass your CPISI exam?

Put this into practice with free CPISI questions across every exam domain.