CPISI-D logo
Focused certification exam prep
Start practice

CPISI-D Certification

TL;DR
  • CPISI-D is SISA's developer-focused credential, separate from CPISI and CPISI Advanced.
  • The exam has 50 questions, 60 minutes, and a 62% passing score.
  • Seven exam topics are published without official weights, so prepare evenly across all of them.
  • "PA-DSS and S3 Standards" is the official heading even though PCI SSC retired PA-DSS on October 28, 2022.

What the CPISI-D Credential Actually Is

CPISI-D stands for Certified Payment Industry Security Implementer - Developer. It is issued by SISA (the SISA Institute) and is aimed at people who build payment-related software rather than those who assess or manage compliance programs. It sits alongside, but is distinct from, the base CPISI and CPISI Advanced credentials, so facts about those programs should never be assumed to carry over. If you are still orienting yourself, the explainers on what CPISI-D is and what the acronym stands for cover the naming in more detail.

The "Developer" label matters. The exam topics lean toward secure design, coding vulnerabilities, threat modelling, and application security standards. That makes it a natural fit for engineers, secure-coding reviewers, and application security staff working near cardholder data, instead of generalist security managers.

Exam Format at a Glance

The Developer examination is compact. Here is what the issuer publishes:

ItemCPISI-D Detail
Number of questions50
Time allowed60 minutes
Passing score62%
Published exam topicsSeven headings, unweighted
Separate practical examNone established; workshop exercises are not a scored practical

Do the arithmetic: 60 minutes across 50 questions leaves roughly a minute and a bit per question, so you cannot afford to deliberate at length over any single item. A 62% threshold means you can miss a meaningful number of questions, but because the blueprint is not weighted, you cannot safely skip an entire topic and hope the others compensate. Note that the base CPISI uses a different pass mark (66%); do not mix the two up. For a deeper look at the threshold, see the CPISI-D passing score breakdown.

Workshop length is not exam length: SISA's two-day live-online offering is a training course. It tells you nothing about how long the examination lasts or how it is delivered. Treat the 60-minute, 50-question figures as the exam facts and the two-day course as preparation only.

The Seven Exam Topics, One by One

SISA publishes seven exam-topic headings. They are objectives, not a weighted blueprint, and no detailed sub-blueprint or percentage split has been published in a retrievable form. That means any claim that one topic is "worth 30%" is guesswork. The broader walkthrough lives in the CPISI-D exam domains guide; below is how to think about each heading as a developer.

Domain 1: Background of Payment Industry

Before you can secure payment code, you need to know how money and card data move.

  • Who the participants are in a card transaction and where data is exposed along the flow
  • Why cardholder data attracts attackers and what that implies for application design
  • The role of industry standards bodies in setting expectations for software that touches card data

Domain 2: Security By Design

This topic is about building security in from the start rather than bolting it on after testing.

  • Applying secure design principles during requirements and architecture
  • Reducing attack surface and limiting how much sensitive data an application ever handles
  • Connecting design decisions to verifiable security requirements

Domain 3: PA-DSS and S3 Standards

This is the application security standards heading. See the dedicated section below for the terminology caveat, because it affects how you should study it.

  • Expect questions framed around secure payment software expectations
  • Know the legacy PA-DSS framing and how the newer software security standards relate to it

Domain 4: Payment Card Industry Security Standards

The broader PCI landscape that surrounds application development.

  • How PCI requirements shape what a development team must do and document
  • The relationship between application-level controls and wider environment obligations

Domain 5: OWASP Web and Mobile Security

Industry-recognized application security guidance applied to both web and mobile payment apps.

  • Common web application risk categories and how they manifest in payment flows
  • Mobile-specific concerns such as insecure local storage and weak transport protections

Domain 6: Common Coding Vulnerabilities

The most hands-on topic for developers: recognizing and preventing recurring flaw classes.

  • Injection, broken authentication, improper session handling, and similar defects
  • Reading a short code or scenario description and spotting the weakness
  • Knowing the corresponding secure coding remedy, not just the flaw name

Domain 7: Threat Modelling

Systematically identifying what can go wrong before attackers do.

  • Decomposing an application, identifying trust boundaries, and enumerating threats
  • Prioritizing threats and mapping them to mitigations

What the workshop adds on top

SISA's published preparation material also covers cryptography and key management, hashing and tokenization, application authorization and access control, audit logging, OWASP web and mobile security, and secure deployment and production support. These are preparation subjects. They do not create extra official exam domains, set weights, or prove that the exam covers every item exhaustively. Still, they are a sensible lens for understanding what a payment-focused developer should know, and they overlap naturally with Domains 2, 5, and 6.

The PA-DSS Heading: Legacy Terminology, Current Exam

This is the single most confusing detail in the blueprint. The official exam-topic heading reads "PA-DSS and S3 Standards." Meanwhile, the PCI Security Standards Council states that PA-DSS retired on October 28, 2022, and SISA's current workshop curriculum emphasizes PCI-SSF and OWASP.

Preserve the heading, study the transition: The mismatch between a retired standard in the exam heading and a newer framework in the workshop does not mean the heading was renamed or dropped. Do not assume the issuer has changed its exam topics. Instead, study both the legacy PA-DSS concepts and the modern PCI software security framework so you can answer questions framed either way.

Practically, this means you should be comfortable reading a question that uses older terminology and recognizing the underlying secure-software requirement, then connecting it to its current-generation equivalent. Because the public topic list is unversioned, you cannot tell exactly which vintage of terminology a given question draws on, so fluency in both is the safe approach.

Eligibility Routes and What Is Still Unclear

There are verified alternatives for qualifying to sit the exam:

  • SISA's 16-hour CPISI-D workshop, or
  • Equivalent formal training of at least 16 hours that covers the blueprint topics.

The issuer also displays an experience route requiring a minimum of one year of verifiable full-time experience. However, the page refers to qualifying areas and then omits them. Do not assume that any developer experience qualifies, and do not reconstruct the criteria from the recommended job-role list. If you plan to use the experience route, ask SISA directly which areas count before you apply. The CPISI-D requirements guide tracks the eligibility picture in more detail.

Fees and Registration Mechanics

SISA's official store lists four purchase options:

OptionListed Price
Certification only (includes application)$199
Training plus certification$449
Training only$430
Super bundle (includes one retake)$500

Two cautions apply. First, the store uses dollar notation without an explicit currency code, so confirm the checkout currency before labeling any figure as USD in a budget request. Second, additional convenience charges are nonrefundable, so read the checkout summary before paying. Notice the arithmetic: the training-plus-certification bundle costs only slightly more than buying training alone, which makes the combined option attractive if you lack equivalent formal training. If you expect to need a second attempt, the super bundle's included retake is worth weighing. The CPISI-D certification cost breakdown goes through the scenarios in full.

Renewal intervals and continuing-education requirements for the Developer credential have not been verified, and the base CPISI renewal rules should not be assumed to apply. Check SISA's certification policy page before planning long-term maintenance.

Who Benefits: Roles and Employers

The credential is most relevant where software meets payment data. Think of organizations that build or maintain payment applications, fintech products, mobile wallets, merchant-facing software, and the internal development teams of banks and processors. Within those teams, the logical audience includes application developers, secure code reviewers, application security engineers, and technical leads responsible for threat modelling and design reviews.

No salary or hiring-demand numbers are published for this credential, so treat any specific earnings claim you encounter with skepticism. For a qualitative view, see the CPISI-D jobs overview and the worth-it analysis. The honest value proposition is signaling: it shows an employer that you have been tested on payment-specific secure development, which is narrower and more targeted than a generic secure-coding certificate.

Key Takeaway

CPISI-D rewards candidates who connect payment-industry context to concrete coding practice. If you can explain why a flaw matters for cardholder data and how to fix it, you are studying the right way.

Sequencing Your Preparation

Since no topic weights are published, spread effort across all seven headings, but order them deliberately. Start with context and design, then move to standards, then to hands-on vulnerabilities and modelling, which tie everything together. A compact four-week plan:

Week 1

Context and Design

  • Domain 1: map the payment flow and where card data lives
  • Domain 2: principles of security by design and data minimization
Week 2

Standards Landscape

  • Domain 3: legacy PA-DSS concepts and the modern software security framework
  • Domain 4: PCI security standards that shape development work
Week 3

Application Security Core

  • Domain 5: OWASP web and mobile guidance
  • Domain 6: coding vulnerability classes and their fixes
Week 4

Modelling and Timed Practice

  • Domain 7: threat modelling walkthroughs on a sample payment app
  • Full 50-question timed runs at about a minute per question

Why this order? Domains 3 and 4 give you the vocabulary that questions in Domains 5 through 7 assume, and threat modelling works best once you can already name the vulnerability classes you are modelling for. For a fuller schedule, the CPISI-D study guide expands on this, and the cheat sheet is useful for last-day review.

When you are ready to test yourself under realistic timing, run full-length sets on the CPISI-D practice test platform, and revisit weak topics identified there rather than rereading everything. If you are unsure how demanding the exam is relative to your background, the difficulty guide offers perspective, and you can find more preparation resources throughout CPISI-D Exam Prep.

Frequently Asked Questions

How many questions are on the CPISI-D exam and how long do I have?

The Developer examination has 50 questions and a 60-minute time limit. The passing score is 62%, which differs from the base CPISI pass mark, so do not use that number for this credential.

Are the seven exam domains weighted?

No official weights are published. SISA lists seven topic headings without percentages, and no detailed sub-blueprint is available. Prepare evenly across all seven rather than guessing at emphasis.

Why does the exam list PA-DSS if it was retired?

The official heading is "PA-DSS and S3 Standards," and it has been preserved even though PCI SSC retired PA-DSS on October 28, 2022. The workshop emphasizes PCI-SSF and OWASP, so study both the legacy concepts and the current framework.

How can I qualify to take the exam?

Verified routes are SISA's 16-hour CPISI-D workshop or equivalent formal training of at least 16 hours covering the blueprint topics. An experience route of at least one year of full-time experience is displayed, but its qualifying areas are not specified, so confirm with SISA first.

How much does CPISI-D cost?

The store lists $199 for certification only, $449 for training plus certification, $430 for training only, and $500 for a super bundle that includes one retake. Convenience charges are nonrefundable, and you should confirm the checkout currency before assuming USD.

Ready to pass your CPISI-D exam?

Put this into practice with free CPISI-D questions across every exam domain.