CPISI logo
Focused certification exam prep
Start practice

CPISI Requirements 2026: Eligibility, Prerequisites & How to Qualify

TL;DR
  • CPISI has no single gate: meet one of three eligibility routes, each published on SISA's current certification page.
  • The three routes are one year of verifiable full-time infosec work, SISA's 16-hour workshop, or equivalent 16-hour formal training.
  • The exam is 50 questions in 60 minutes with a 66% passing score, delivered online and proctored.
  • The certification-only price is $249 including the application; confirm your checkout currency before paying.

Which CPISI This Article Covers

The acronym CPISI is shared by several unrelated credentials in the wider market, so it is worth pinning down exactly what this article describes. Here, CPISI means the Certified Payment Industry Security Implementer, issued by SISA through its SISA Institute training and certification arm. Everything below concerns the base CPISI only. It does not describe the advanced tier, the CPISI-D variant, or any other certification that happens to abbreviate to the same four letters.

If you are still orienting yourself, our explainers on what CPISI is and what CPISI stands for cover the naming and scope in more detail. This page is narrower: it answers the practical question of who may sit the exam and how to get there.

One framing point matters before the details. SISA describes its training and certification as independent of any endorsement by the PCI Security Standards Council. That does not make the credential less relevant to payment security work, but it does mean you should read it as a vendor-issued professional certification rather than an official council qualification.

The Three Ways to Meet Eligibility

SISA's current CPISI certification page sets out an either/or structure. You do not need to satisfy all of the conditions below; you need to satisfy one. That is the single most important thing to understand about CPISI requirements, because a surprising number of candidates assume that work experience and training are both mandatory.

Eligibility RouteWhat You Must ShowBest Suited To
Work experienceAt least one year of verifiable, full-time, information-security-related workPractitioners already in security, audit, risk, or infrastructure roles
SISA workshopCompletion of SISA's 16-hour CPISI workshopCandidates who want structured instruction from the issuer itself
Equivalent formal trainingAt least 16 hours of formal training covering the blueprint topicsCandidates who completed comparable coursework elsewhere

Route one: verifiable full-time experience

The wording that matters is verifiable, full-time, and information-security-related. Part-time or incidental exposure to security tasks is a weaker fit. Keep documentation that could back up your claim: an employment letter, a role description, or a manager reference. The page does not enumerate which job titles count, so interpret "information-security-related" sensibly and be ready to explain how your duties touched security rather than assuming a title alone settles it.

Route two: SISA's 16-hour workshop

The workshop route is the most direct way to satisfy the requirement if you lack a qualifying year of experience. It is issuer-run, so the content is aligned to what SISA expects. Note that the sixteen hours describe the training, not the exam. They are not a count of exam domains and they say nothing about how long the test itself lasts. For the training side of the ecosystem, see our overview of CPISI training.

Route three: equivalent formal training

The third path accepts formal training of at least sixteen hours that covers the blueprint topics. The qualifier is important: the training must actually cover the subject matter, not merely be security-adjacent. If you intend to rely on this route, compare your course syllabus against the six topic headings listed later in this article and keep the certificate of completion and syllabus together.

One route is enough: Experience, the SISA workshop, or equivalent training each independently satisfies eligibility. You do not need to stack them. Choose the route you can document most cleanly, and keep the evidence ready in case SISA asks for it during application.

Choosing the Route That Fits Your Background

Because the routes are interchangeable for eligibility purposes, the decision comes down to your starting point, your budget, and how much structure you want. The comparison below frames the trade-offs without implying any route is "better" for passing.

If you already work in security or compliance

Candidates with a year or more of verifiable full-time security work can take the certification-only path and skip formal instruction altogether. This is the cheapest route on the official store, but it places the full burden of exam preparation on you. If your day job rarely touches payment card environments specifically, budget extra time for Domains 1 and 3, where payment-specific vocabulary dominates. Our CPISI study guide maps how to close those gaps.

If you are moving into payment security from another field

A network engineer, developer, or IT auditor who has not held a security-titled role may not meet the experience route cleanly. For these candidates, the workshop or an equivalent course is the safer way to establish eligibility, and it doubles as structured preparation. The trade-off is cost, which we cover in the fees section below and in our CPISI certification cost breakdown.

If you are a student or early-career professional

With no qualifying experience yet, training is effectively your only route. The question then becomes whether to buy SISA's own program or document a comparable external course. If you choose an outside course, confirm before paying that it genuinely addresses the blueprint topics and clears the sixteen-hour minimum.

Key Takeaway

Decide your route first, then buy. Purchasing a bundle before confirming whether your experience already qualifies is the most common way candidates spend more than necessary.

What You Sit Once You Qualify

Meeting eligibility only unlocks the exam; it is worth knowing what you are qualifying for. The base CPISI examination consists of 50 questions to be completed in 60 minutes, with a passing score of 66%. SISA's hybrid-program FAQ describes the delivery as an online, proctor-driven examination, so plan for a monitored session rather than a walk-in test center appointment.

Those numbers set the pace: roughly a minute and a bit per question, with little room to stall on a single item. For a deeper look at the threshold, see CPISI passing score, and for how demanding the content tends to feel, how hard the CPISI exam is. For scheduling realities, CPISI exam dates explains what to look for when booking.

Training hours are not exam hours: The eighteen modules and sixteen workshop hours that appear in SISA's program descriptions describe how instruction is structured. They are not exam-domain counts and they do not indicate how long the exam runs. The exam itself is the 50-question, 60-minute session described above.

The Six Topic Areas You Should Be Ready For

SISA publishes six exam-topic headings on its CPISI page. These are listed as exam objectives. SISA does not give percentage weightings for them, and the exam blueprint label shown on the page did not resolve to a retrievable linked document, so treat this list as the verified public topic outline rather than an exhaustive, weighted blueprint. For a fuller walk-through, read our complete guide to the six CPISI content areas.

Domain 1: Background of Payment Security

Foundational context for why payment data is protected and how the payment ecosystem is organized.

  • Terminology and roles in card payment environments
  • Why cardholder data attracts attackers and drives regulation
  • How a security standard fits into an organization's obligations

Domain 2: Building and Maintaining a Secure Network and Systems

The infrastructure layer: how networks and system configurations are secured and kept that way.

  • Network segmentation and protective controls
  • Secure configuration of systems and removal of insecure defaults
  • Maintaining those controls over time, not just establishing them once

Domain 3: Protecting Account Data

Safeguarding the data itself, wherever it is stored or transmitted.

  • Limiting what account data is kept and for how long
  • Protecting stored data and data in transit
  • Recognizing which data elements carry the most risk

Domain 4: Maintaining a Vulnerability Management Program

Ongoing identification and remediation of weaknesses.

  • Defending systems against malicious software
  • Developing and maintaining secure systems and software
  • Applying fixes and managing change responsibly

Domain 5: Implementing a Strong Access Control Measures

Who and what can reach systems and data.

  • Restricting access on a business need-to-know basis
  • Identifying and authenticating users
  • Restricting physical access to sensitive environments

Domain 6: Regularly Monitoring and Testing Networks

Verifying that controls work and detecting when they do not.

  • Logging and monitoring access to systems and data
  • Testing security systems and processes on a regular basis
  • Using results to drive corrective action

One caution: do not assume the six headings mirror the full structure of the underlying payment card standard requirement by requirement. SISA's headings are exam topics, and the exam is organized around them rather than around an editorial reshuffling of the standard. Current CPISI hybrid preparation references PCI DSS 4.0.1, but that describes the curriculum version used in training, not a dated release of the exam outline.

Fees, Bundles and Enrollment Mechanics

SISA's official store lists four purchase options. The figures are shown in dollar notation; because the store did not display an explicit currency code, confirm the currency at checkout before committing to a budget.

OptionListed PriceWhat It Covers
Certification only$249Exam, with the application included
Training plus certification$549Instruction and the certification exam together
Training only$480Instruction without the exam
Super bundle$600Training and certification, including one retake

Reading the pricing logic

The gap between certification-only and training-plus-certification is the price of the instructional component. The super bundle costs a modest amount more than training plus certification and adds one retake, which makes it attractive if you are nervous about a first attempt or expect to be close to the 66% line. If you already qualify through experience and feel confident, the certification-only option avoids paying for instruction you do not need.

Additional convenience charges, where they apply, are nonrefundable. Read the checkout summary carefully before confirming. For a fuller treatment of what you will actually pay and when, see our CPISI certification cost guide, and for whether the spend makes sense, whether CPISI is worth it.

Match the purchase to your eligibility route: If you intend to qualify through the SISA workshop, the training-inclusive options are the natural fit. If you qualify through experience, the certification-only option may be all you need. Buying before settling your route is the easiest way to overspend.

Conflicting Public Information

If you search for CPISI requirements, you may encounter an older issuer-owned badge listing on Credly. That listing states a 60% pass mark and a two-day course requirement. SISA's current certification page instead gives a 66% passing score and three alternative eligibility routes, including the experience route that requires no course at all.

DetailLegacy Credly BadgeCurrent SISA Certification Page
Passing mark60%66%
EligibilityTwo-day courseExperience, 16-hour workshop, or equivalent 16-hour training

The practical guidance is to rely on the current certification page for both the threshold and the eligibility routes. Plan around 66%, not 60%. The legacy listing is a reminder that third-party badge descriptions can lag behind the issuer's present rules. See our CPISI pass rate discussion for why qualitative framing is safer than quoting numbers that cannot be verified.

A Domain-Ordered Preparation Sequence

Once you know which route you are using, the remaining question is how to prepare efficiently for a 60-minute exam. Rather than a generic template, order your effort by domain, starting with the vocabulary that everything else depends on. A compact four-week arrangement works for many candidates who already hold some security background.

Week 1

Domain 1 and Domain 2

  • Learn payment ecosystem terminology first; later domains assume it
  • Cover network and system security fundamentals as they apply to cardholder environments
Week 2

Domain 3 and Domain 4

  • Concentrate on account data protection, the most payment-specific material
  • Add vulnerability management and secure development concepts
Week 3

Domain 5 and Domain 6

  • Work through access control and authentication measures
  • Cover logging, monitoring, and testing practices
Week 4

Timed practice across all six

  • Sit full-length 50-question sets inside the 60-minute limit
  • Revisit whichever domain produces the most misses

Why this order? Domain 1 supplies the language, and Domain 3 is where payment-specific knowledge is densest, so front-loading them reduces confusion later. Timed practice in the final week matters because the exam allows little time per item. You can run realistic sets on our CPISI practice test platform, and our CPISI cheat sheet is a handy final-review companion.

What Remains Unverified

Honest requirements coverage includes noting what is not publicly confirmed. Several details that candidates often ask about could not be verified from retrievable official sources:

  • Certification validity and renewal: The validity period, renewal intervals, and continuing professional education numbers are not confirmed. The legacy CPE policy was indexed by search engines, but its full text could not be retrieved, and figures should not be borrowed from other SISA credentials.
  • A formal exam blueprint: The page displays an exam blueprint label, but it did not lead to a retrievable document. A separate candidate handbook was likewise not retrieved.
  • Domain weightings: No official percentage distribution across the six topics was found.
  • Exam outline versioning: The public topic list is unversioned, so there is no dated release to cite.

Before you pay, check the SISA certification policy hub for the latest terms, and rely on SISA directly for anything that affects your decision. For the career side of the question, our guides to CPISI jobs and the CPISI salary guide explain the typical roles and how to think about earnings without leaning on invented figures.

Key Takeaway

Verify at the source. Eligibility routes, the 66% threshold, and pricing come from SISA's current pages. Treat anything older or third-party as a prompt to double-check rather than a rule to follow.

Frequently Asked Questions

Do I need both work experience and training to take the CPISI exam?

No. SISA's current certification page requires you to meet only one eligibility route: at least one year of verifiable full-time information-security-related work, SISA's 16-hour CPISI workshop, or equivalent formal training of at least 16 hours covering the blueprint topics.

What is the passing score and format of the exam?

The base CPISI exam has 50 questions, a 60-minute time limit, and a passing score of 66%. SISA's hybrid-program FAQ describes it as an online, proctor-driven examination.

How much does it cost to qualify and sit the exam?

SISA's store lists $249 for certification only including the application, $549 for training plus certification, $480 for training only, and $600 for the super bundle including one retake. Confirm the checkout currency, since no explicit code was displayed, and note that convenience charges are nonrefundable.

Why do some sources say 60% and a two-day course?

An older issuer-owned Credly badge lists a 60% pass mark and a two-day course requirement. SISA's current certification page states 66% and the three alternative eligibility routes, so you should follow the current page.

How long does the certification last and how is it renewed?

The validity period, renewal intervals, and continuing education requirements could not be verified from retrievable official text. Check SISA's certification policy hub directly, and read our overview at CPISI certification for broader context.

Ready to pass your CPISI exam?

Put this into practice with free CPISI questions across every exam domain.