CPISI logo
Focused certification exam prep
Start practice

CPISI Passing Score 2026: Exactly What You Need to Pass

TL;DR
  • The base CPISI passing score is 66%, per SISA's current certification page.
  • The exam has 50 questions in 60 minutes, delivered online and proctor-driven.
  • An older Credly badge lists 60%; treat SISA's current 66% as the operative threshold.
  • SISA publishes six unweighted exam topics, so no official percentage split by domain exists.

The Number: 66% on a 50-Question Exam

If you are searching for the Certified Payment Industry Security Implementer passing score, the answer is short: 66%. SISA's current Certification - CPISI page lists a 50-question examination, a 60-minute time limit, and a passing score of 66%. That is the configured threshold for the base CPISI credential, not the CPISI Advanced or CPISI-D variants, which are separate programs with their own details.

This article is written for the base Certified Payment Industry Security Implementer, issued by SISA (SISA Institute). Because the acronym is easy to confuse with other credentials, every figure below comes from SISA's own published material. For a broader orientation on the credential itself, see What Is CPISI Certification? and the main CPISI Certification overview.

Source of truth: The 66% threshold comes from SISA's current, undated CPISI certification page. When any third-party listing, badge, or forum post disagrees, defer to SISA's current page and check it again before you book your sitting.

What 66% Means in Practical Terms

With 50 questions, converting the percentage into a question count is straightforward arithmetic, but two caveats matter. First, SISA does not publish whether every question carries equal weight, whether any items are unscored, or how fractional results are rounded. Second, the public materials do not explain the scoring method (for example, whether the score is a raw percentage or a scaled value).

Working from the plain reading of the published figures, 66% of 50 questions is 33 correct answers. Treat that as a planning estimate rather than an official cut line, since SISA has not published a rounding or weighting rule in the sources reviewed. A sensible preparation goal is to aim comfortably above that figure so a handful of misread questions does not decide the outcome.

Exam ParameterPublished ValueWhat It Implies
Number of questions50Each question is a meaningful share of the result
Time limit60 minutesRoughly one minute and twelve seconds per question on average
Passing score66%About 33 correct answers as a planning estimate
DeliveryOnline, proctor-driven (per SISA's hybrid-program FAQ)Remote sitting with supervision

The pacing math is worth internalizing. At roughly 72 seconds per question, you cannot afford to deliberate for minutes over a single item about a requirement you half-remember. Flagging and moving on is a skill you should rehearse. Our difficulty guide discusses how that time pressure interacts with the question style.

60% vs. 66%: Resolving the Conflicting Figures

You may run into a second number. An older, issuer-owned Credly badge for the Certified Payment Industry Security Implementer lists a 60% pass mark and describes a two-day course requirement. SISA's current certification page, by contrast, lists 66% and describes alternative eligibility routes (covered below). The two sources disagree, and the disagreement is real rather than a typo on our end.

The most reasonable interpretation is that the badge description reflects an earlier version of the program and has not been updated, while the certification page reflects the current configuration. SISA has not published a changelog explaining the shift, so we cannot date the change. The practical guidance is simple:

  • Plan for 66%, because that is what the current certification page states.
  • Do not plan around 60%, even if you see it quoted on a badge, a profile, or a reseller listing.
  • If your exam confirmation email or candidate portal shows a different threshold, trust the portal and contact SISA to reconcile the difference.
Why the conflict matters: Planning to a lower number can lull you into an under-prepared attempt. Planning to the higher number costs nothing if the lower one turns out to be correct. When two credible sources disagree, prepare for the stricter one.

Exam Format and What Is Actually Verified

It helps to separate what is verified from what is not. The verified facts are the 50-question count, the 60-minute limit, the 66% threshold, and the description of an online, proctor-driven delivery model in SISA's hybrid-program FAQ. What the public materials do not provide is equally important to know:

  • The Exam Blueprint label on SISA's page does not lead to a retrievable linked document, so there is no downloadable blueprint to study from.
  • A separate Candidate Handbook was not retrievable, so detailed rules about question types, scoring, and exam-day procedures are not publicly confirmed.
  • The six published topic headings are unweighted. There is no official percentage distribution across them.
  • The public topic list is unversioned, and no dated exam-outline release has been published.

In other words, anyone who tells you "Domain 3 is 25% of the exam" is inventing a number. We will not do that here. For the full breakdown of the published topics, see our complete guide to all six content areas.

Preparation Version Versus Exam Version

SISA's current CPISI hybrid preparation references PCI DSS 4.0.1. That tells you which version of the standard the training material is built around, but it does not establish a dated release of the exam outline. In practice, you should study against PCI DSS 4.0.1 as the reference standard for your preparation while recognizing that SISA has not formally tied the exam to a specific outline date.

Also note that SISA identifies its training and certification as independent of PCI SSC endorsement. The credential is a SISA credential, not a PCI Security Standards Council qualification, and employers should read it accordingly.

Training Structure Is Not Exam Structure

The hybrid program is organized into eighteen modules, and the workshop spans sixteen hours. Those numbers describe the training, not the exam. Eighteen modules do not mean eighteen exam domains, and sixteen workshop hours are not exam time. Keep these figures separate in your mind so you do not misjudge the exam's scope.

Where Your Points Come From: The Six Topic Areas

SISA publishes six exam-topic headings. Because they are explicitly exam objectives and not weighted allocations, the right strategy is balanced competence: you need roughly two-thirds of the questions right across the whole paper, and you do not know in advance how the 50 questions distribute across these headings. Neglecting any one area is a gamble.

Domain 1: Background of Payment Security

The foundation: how the payment ecosystem works and why cardholder data attracts attackers.

  • Roles of merchants, acquirers, issuers, and service providers
  • Why a security standard for card data exists and who it applies to
  • Core terminology you will see throughout every other topic

Domain 2: Building and Maintaining a Secure Network and Systems

Protective technical baselines for the environments that touch card data.

  • Network security controls and segmentation concepts
  • Secure configuration and avoiding vendor-supplied defaults
  • Scoping the environment that stores, processes, or transmits card data

Domain 3: Protecting Account Data

Often the most conceptually dense area, centered on what may be stored and how it must be protected.

  • Which account data elements may and may not be retained
  • Rendering stored data unreadable and protecting data in transit
  • Cryptographic key management at a conceptual level

Domain 4: Maintaining a Vulnerability Management Program

Keeping systems resilient against known weaknesses.

  • Anti-malware and patching expectations
  • Secure development and change-control concepts
  • How vulnerabilities are identified, ranked, and remediated

Domain 5: Implementing a Strong Access Control Measures

Who gets access to what, and how that access is proven and limited.

  • Need-to-know restriction of access to system components and data
  • User identification and authentication, including multi-factor concepts
  • Physical access restrictions to areas with card data

Domain 6: Regularly Monitoring and Testing Networks

Detecting problems and proving controls actually work.

  • Logging and monitoring of access to systems and card data
  • Vulnerability scanning and penetration-testing concepts
  • Change-detection and security-testing cadence

Note that these six headings should not be expanded into the full requirements list of the PCI DSS standard. They are SISA's published exam topics, and the exam is built around them. Use PCI DSS 4.0.1 as your reference text, but let the six headings define your study scope. Our one-page cheat sheet condenses the most testable facts from each.

Key Takeaway

Because no weighting is published, treat all six topics as equally likely to appear. A candidate who masters four topics and skips two is betting that the skipped topics will not supply 17 or more of the 50 questions. That is a poor bet when the passing line is only 66%.

Eligibility Routes and Fee Mechanics

Passing the exam is only half the story; you must also qualify to sit it. SISA's current certification page allows you to satisfy one of three eligibility routes:

  1. At least one year of verifiable full-time information-security-related work experience.
  2. Completion of SISA's 16-hour CPISI workshop.
  3. Equivalent formal training of at least 16 hours that covers the blueprint topics.

This replaces the older two-day course requirement associated with the legacy badge listing. For the full qualification walkthrough, see CPISI Requirements: Eligibility, Prerequisites & How to Qualify.

What the Store Lists

SISA's official store lists the following options. The prices appear in the store's dollar notation, but an explicit currency code was not displayed, so confirm the checkout currency before budgeting.

OptionListed PriceWhat It Covers
Certification only$249Exam, including the application
Training plus certification$549Training and the exam together
Training only$480Training without the exam
Super bundle$600Training and certification, including one retake

Additional convenience charges are nonrefundable. The retake detail is the one that bears directly on your passing-score strategy: only the super bundle is listed as including a retake, so if you buy certification-only at $249, a failed attempt means purchasing again under whatever retake terms SISA applies. That retake policy is not detailed in the sources reviewed, so confirm it with SISA before you pay. For a fuller financial picture, read our pricing breakdown.

Budget decision: If you are already confident in your preparation and meet the experience route, certification-only is the cheaper entry. If you are less certain, the bundle that includes a retake is effectively insurance against a missed 66%. Weigh that against your honest read of the exam's difficulty.

A Domain-Ordered Prep Sequence

Rather than a generic schedule, order your preparation around how the six topics build on each other. This is the one place we will suggest a timeline, and it is tied directly to the CPISI topic list.

Week 1

Background of Payment Security

  • Learn the ecosystem roles and vocabulary first, since every later topic assumes it
  • Read the scope concept for the card data environment
Week 2

Secure Networks and Account Data Protection

  • Pair network and system baselines with data protection, since they overlap in scoping
  • Spend extra time on what may be stored versus what must never be retained
Week 3

Vulnerability Management and Access Control

  • Work through patching, secure development, and access restriction together
  • Focus on authentication concepts and need-to-know logic
Week 4

Monitoring and Testing, Then Timed Practice

  • Cover logging, scanning, and testing concepts
  • Finish with full 50-question sets under a 60-minute clock

The reasoning: Topic 1 supplies vocabulary, Topics 2 and 3 share scoping logic, Topics 4 and 5 are control-oriented, and Topic 6 verifies the rest. Finishing with timed sets matters because the 60-minute limit is a real constraint. For a deeper plan, see the CPISI study guide, and when you are ready to measure your readiness against the 66% line, try the CPISI practice tests.

Using Practice Scores to Judge Readiness

Because the real passing line is 66%, a practice score hovering right at 66% is not a comfortable margin. Real exams introduce unfamiliar phrasing and nerves. Consistently scoring well above the threshold on realistic practice questions, across all six topics rather than only your favorites, is a far better signal that you are ready than a single lucky high score.

After the Exam: Retakes, Careers, and Unknowns

Several downstream details are simply not confirmed in the public materials, and we would rather say so than guess. Certification validity period, renewal intervals, and continuing-education (CPE) requirements are unverified. SISA's certification-policy hub exists, and a legacy CPE policy page was search-indexed, but its full text could not be retrieved. Check SISA's current policy pages directly before making any plan that depends on how long the credential lasts or what maintaining it requires.

On the career side, the credential suits professionals who help organizations implement card-data security controls, such as security analysts, compliance and risk staff, and IT personnel at merchants, service providers, and financial institutions. For how this translates into roles and pay, see CPISI jobs, the salary guide, and the ROI analysis. If you are still working out what the credential is, what CPISI stands for is a quick primer. For scheduling, see exam dates and scheduling.

A final note on pass rates: SISA does not publish an official pass rate in the sources reviewed, so any specific percentage you encounter should be treated skeptically. Our pass rate article explains what can and cannot be said responsibly.

Frequently Asked Questions

What is the CPISI passing score?

The base Certified Payment Industry Security Implementer requires a 66% passing score on a 50-question, 60-minute exam, according to SISA's current certification page. As a planning estimate, that is about 33 correct answers, though SISA has not published a rounding or weighting rule.

Why do some sources say 60% instead of 66%?

An older issuer-owned Credly badge lists a 60% pass mark and a two-day course requirement. SISA's current certification page lists 66% and alternative eligibility routes. Use the current page's 66% for planning, and confirm with SISA if your candidate portal shows something different.

Are the six exam topics weighted?

No official weighting has been published. SISA lists six unweighted exam-topic headings, so there is no verified percentage distribution. Prepare all six areas evenly rather than relying on any claimed breakdown.

Is the CPISI exam taken online?

SISA's hybrid-program FAQ describes an online, proctor-driven examination. Because a separate candidate handbook was not retrievable, confirm technical and environment requirements with SISA when you register.

What do I need to qualify to take the exam?

You must meet one of three routes: at least one year of verifiable full-time information-security-related work, SISA's 16-hour CPISI workshop, or equivalent formal training of at least 16 hours covering the blueprint topics. The certification-only option is listed at $249 including the application, but confirm the checkout currency first.

Ready to pass your CPISI exam?

Put this into practice with free CPISI questions across every exam domain.