- What the Certification Actually Is
- Who Issues It and What That Means
- Exam Format at a Glance
- The Six Published Exam Topics
- Eligibility: Three Ways In
- Fees and Registration Mechanics
- Conflicting Information You May Find Online
- Who Benefits from This Credential
- Sequencing Your Preparation by Topic
- What Is Not Publicly Confirmed
- Frequently Asked Questions
- CPISI stands for Certified Payment Industry Security Implementer, offered by SISA Institute.
- The base exam has 50 questions, 60 minutes, and a 66% passing score.
- Eligibility needs one of three routes: one year of security work, SISA's 16-hour workshop, or equivalent 16-hour training.
- SISA publishes six unweighted exam topics, from payment security background to monitoring and testing networks.
What the Certification Actually Is
CPISI stands for Certified Payment Industry Security Implementer. It is a credential aimed at professionals who need to put payment-card security controls into practice: the people who configure, operate, and evidence the safeguards that protect cardholder data, rather than those who only write policy about them. If you have searched for this acronym and landed on unrelated credentials, note that this article covers the SISA Institute certification only.
The "Implementer" wording is the clue to the exam's flavour. The six published topics track the familiar goals of the PCI Data Security Standard, so a candidate is expected to understand what each control family is for and how it is applied in a real cardholder data environment. For a short definitional primer, see our pages on what CPISI stands for and CPISI meaning.
This article focuses on the base CPISI exam. SISA also markets related, more advanced credentials, but those are separate products with their own requirements and are not covered here.
Who Issues It and What That Means
The certification is issued by SISA, through its SISA Institute training arm. Two points are worth understanding before you invest time or money:
- The program is SISA's own. Curriculum, exam, workshop, and certification policy all come from SISA. Its current hybrid preparation materials reference PCI DSS 4.0.1.
- It is not a PCI SSC credential. SISA identifies its training and certification as independent of PCI SSC endorsement. That does not make it worthless, but you should describe it accurately on a résumé and avoid implying it is an official PCI Security Standards Council qualification.
Exam Format at a Glance
The base CPISI examination is short by professional-certification standards, which shapes how you should prepare. SISA's hybrid-program FAQ describes it as an online, proctor-driven examination.
| Attribute | Base CPISI |
|---|---|
| Number of questions | 50 |
| Time allowed | 60 minutes |
| Passing score | 66% |
| Delivery | Online, proctor-driven (per SISA's hybrid-program FAQ) |
| Published topics | Six, unweighted |
Sixty minutes for fifty questions averages a little over a minute per item. That pace rewards candidates who know the material cold rather than those who reason it out from scratch. For a deeper look at how the threshold works, read our guide to the CPISI passing score, and for an honest take on difficulty, see how hard the CPISI exam is.
One caution: the workshop and hybrid program describe eighteen modules and a number of instructional hours. Those figures describe training structure only. They are not exam-domain counts and they are not exam time.
The Six Published Exam Topics
SISA's current certification page lists six topic headings. They are explicitly exam objectives, not weighted allocations, so there is no official percentage split to plan around. Treat all six as testable and avoid assuming any one is lightly examined. The sections below summarise what each heading signals. For a fuller walkthrough, see our complete guide to the CPISI exam domains.
Domain 1: Background of Payment Security
The foundation topic. Candidates should be comfortable with how card payments work and why cardholder data attracts attackers.
- Participants in the payment ecosystem and where card data travels
- Why a security standard for cardholder data exists
- Scoping: which systems, people, and processes fall inside the cardholder data environment
- The vocabulary used throughout every other topic
Domain 2: Building and Maintaining a Secure Network and Systems
The infrastructure topic, covering the technical perimeter and the configuration of the systems inside it.
- Network security controls and how they restrict traffic to and from the cardholder data environment
- Secure configuration and hardening, including replacing vendor defaults
- Network segmentation as a way to reduce scope
Domain 3: Protecting Account Data
The data-centric topic, and often the one candidates associate most strongly with payment security.
- Limiting what account data is stored and for how long
- Rendering stored data unreadable through approaches such as encryption, truncation, and masking
- Protecting data in transit across open, public networks
- Key management responsibilities
Domain 4: Maintaining a Vulnerability Management Program
The ongoing-hygiene topic: finding and fixing weaknesses before they are exploited.
- Protection against malicious software
- Identifying and applying security patches in a timely way
- Secure development and change practices for systems and software
Domain 5: Implementing a Strong Access Control Measures
The people-and-identity topic. SISA's heading is worded exactly this way, and it concerns who may reach cardholder data and how.
- Restricting access to a need-to-know basis
- Identifying and authenticating users, including stronger authentication for sensitive access
- Restricting physical access to systems and data
Domain 6: Regularly Monitoring and Testing Networks
The assurance topic: proving the controls work and spotting problems early.
- Logging and monitoring access to network resources and cardholder data
- Regular security testing, including scanning and penetration testing concepts
- Maintaining evidence so controls can be demonstrated, not merely asserted
Eligibility: Three Ways In
You do not need to attend a specific course to sit the exam, but you do need to satisfy at least one route. According to SISA's current certification page, you must meet one of the following:
- Work experience: at least one year of verifiable, full-time work in information security or a related area.
- SISA's workshop: completion of SISA's 16-hour CPISI workshop.
- Equivalent formal training: at least 16 hours of formal training that covers the blueprint topics.
The flexibility is useful. An experienced security practitioner can qualify on work history alone, while someone newer to the field can qualify through the workshop or equivalent coursework. For the full picture, see our breakdown of CPISI requirements. If you are weighing instructor-led options, our overview of CPISI training covers what to look for.
Fees and Registration Mechanics
SISA's official store lists several purchase options. Figures below are reproduced exactly as the store displays them, in dollar notation.
| Option | Listed price | What it includes |
|---|---|---|
| Certification only | $249 | Exam, including the application |
| Training plus certification | $549 | Preparation training and the exam |
| Training only | $480 | Training without the exam |
| Super bundle | $600 | Training and certification, including one retake |
Two practical details deserve attention. First, the store does not display an explicit currency code, so confirm the currency at checkout before you budget. Second, additional convenience charges are nonrefundable, so read the checkout summary carefully before paying. A candidate who already meets the work-experience route may find the certification-only option sufficient, while someone relying on the workshop route should compare the bundles. Our CPISI certification cost breakdown goes through the trade-offs in more detail, and the exam dates and scheduling guide covers timing.
Key Takeaway
The super bundle is the only option that explicitly includes a retake. If you are newer to PCI concepts and expect a possible second attempt, compare the bundle against the certification-only price plus the cost of a standalone retake before deciding.
Conflicting Information You May Find Online
Candidates researching this credential sometimes encounter inconsistent figures. The clearest example is an older, issuer-owned Credly badge listing for the certification, which states a 60% pass mark and a two-day course requirement. SISA's current certification page instead states a 66% passing score and offers alternative eligibility routes (work experience, the 16-hour workshop, or equivalent training).
The sensible approach is to treat the current certification page as authoritative for the passing threshold and eligibility, and to regard the badge text as legacy wording that has not kept pace. When you register, confirm the details displayed at that moment. Our page on the CPISI pass rate explains what is and is not publicly known about outcomes.
Who Benefits from This Credential
The certification fits roles where payment-card security controls must be implemented and evidenced. Typical beneficiaries include:
- Security analysts and engineers at merchants, payment processors, and service providers who maintain controls inside a cardholder data environment.
- IT and infrastructure administrators responsible for firewalls, system hardening, patching, and logging.
- Compliance and risk staff who coordinate assessments and need to speak the technical language of the controls they track.
- Consultants and assessors' support teams who help organisations prepare for PCI DSS assessments.
Because the standard applies wherever card data is stored, processed, or transmitted, demand is not limited to one sector; retail, banking, fintech, hospitality, and managed service providers all have payment security obligations. Salary and job-market specifics vary widely and are not quantified here; see our discussions of CPISI jobs, the CPISI salary guide, and whether the credential is worth it for a balanced view.
Sequencing Your Preparation by Topic
Because the exam is only 60 minutes long, breadth and recall matter more than deep specialisation. A topic-ordered plan keeps the dependencies sensible: scoping and vocabulary first, then the controls that build on them, then the assurance activities that verify them.
Background of Payment Security
- Learn the payment ecosystem and scoping concepts first; every later topic assumes them
- Build a personal glossary of terms
Secure Network and Systems, then Protecting Account Data
- Study network controls and hardening together, since segmentation and configuration are linked
- Move to storage, encryption, masking, and data-in-transit protections
Vulnerability Management, then Access Control
- Cover malware protection, patching, and secure development practices
- Study need-to-know access, authentication, and physical access
Monitoring and Testing, plus full review
- Cover logging, scanning, and testing concepts
- Run timed 50-question sets to rehearse the 60-minute pace
For a fuller plan, see our CPISI study guide and the one-page CPISI cheat sheet. When you are ready to test yourself under realistic conditions, try the CPISI practice tests.
What Is Not Publicly Confirmed
Honest preparation includes knowing where the public information stops. As of this writing, the following items could not be verified from retrievable official sources:
- Certification validity and renewal. The renewal interval and any continuing-education requirements are unverified. SISA's legacy CPE policy was indexed but its text could not be retrieved, and figures should not be borrowed from other SISA credentials. Check SISA's certification-policy hub directly.
- Official topic weighting. The six headings are unweighted. No official percentage distribution is available.
- A dated exam-outline release. The topic list is unversioned. Current preparation materials reference PCI DSS 4.0.1, but that is a curriculum version and does not establish an exam-outline release date.
- Pass-rate data. No official pass-rate statistic is published that we can cite.
Verify any of these directly with SISA before relying on them for planning or for claims on a résumé. For additional background on the certification overall, you can also read our pages on CPISI certification and what CPISI is.
Frequently Asked Questions
CPISI stands for Certified Payment Industry Security Implementer. It is a SISA Institute certification focused on implementing payment-card security controls, and it should not be confused with other credentials that happen to share the acronym.
The base CPISI exam has 50 questions to be answered in 60 minutes, with a passing score of 66%. SISA's hybrid-program FAQ describes it as an online, proctor-driven examination.
No. You must meet one eligibility route: at least one year of verifiable full-time information-security-related work, SISA's 16-hour CPISI workshop, or equivalent formal training of at least 16 hours covering the blueprint topics.
SISA's store lists $249 for certification only, $549 for training plus certification, $480 for training only, and $600 for the super bundle that includes one retake. Convenience charges are nonrefundable, and you should confirm the checkout currency before paying.
No. SISA states that its training and certification are independent of PCI SSC endorsement. Describe it accurately as a SISA Institute certification rather than as an official council credential.