- The Developer exam has 50 questions, a 60-minute limit, and a 62% passing score, not the base CPISI's 66%.
- SISA publishes seven unweighted exam topics; no official percentage weights exist, so study all seven evenly.
- The heading "PA-DSS and S3 Standards" is preserved as-is, even though PCI SSC retired PA-DSS on October 28, 2022.
- Certification-only costs $199; training plus certification is $449; the super bundle at $500 includes one retake.
Identity Check: Which CPISI-D This Sheet Covers
"CPISI-D" is used by more than one credential in the wider industry. This cheat sheet covers exactly one: the Certified Payment Industry Security Implementer - Developer, offered by SISA (SISA Institute). It is a separate credential from the base CPISI and from CPISI Advanced, and the facts below belong only to the Developer track. If you are comparing numbers you found elsewhere, such as a pass mark, a fee, or a renewal rule, confirm they were written about this credential before you trust them.
For a plain-language definition and background, see What Is CPISI-D?, and for the acronym itself, What Does CPISI-D Stand For?.
The Exam at a Glance
| Item | CPISI-D Fact |
|---|---|
| Issuer | SISA / SISA Institute |
| Number of questions | 50 |
| Time limit | 60 minutes |
| Passing score | 62% |
| Published topics | Seven, unweighted |
| Separate practical exam | None established; workshop exercises are not a timed or scored practical |
Do the arithmetic early: 60 minutes across 50 questions leaves roughly a minute and a bit per item. That pace rewards recognition over derivation. You will not have time to reason from first principles on every question, so the facts in this sheet should be reflexive before exam day.
The Seven Official Exam Topics
SISA's current Certification - CPISI-D page lists seven topic headings. They are exam objectives, not a weighted blueprint. The page's "Exam Blueprint" label does not link to a retrievable file, so there is no official detail below these headings and no published percentages. Anyone quoting domain weights for this exam is guessing. Here are the seven topics and what a developer-focused candidate should be ready to explain for each.
Domain 1: Background of Payment Industry
The context everything else hangs on. Know who the participants in a card payment are and why cardholder data attracts attackers.
- Roles of merchants, acquirers, issuers, processors, and card brands
- Why payment data is a high-value target and what that means for application design
- How standards bodies and card brands shape developer obligations
Domain 2: Security By Design
Building security in from the start of the lifecycle rather than bolting it on before release.
- Embedding security requirements early in the development lifecycle
- Least privilege, defense in depth, and minimizing stored sensitive data
- Why late-stage fixes cost more than design-stage decisions
Domain 3: PA-DSS and S3 Standards
The legacy-named heading covering payment application security standards. See the next section for how to handle the terminology.
- Purpose of payment application security standards
- How the modern PCI-SSF approach relates to the older PA-DSS framing
- Expect the heading text to appear as SISA wrote it
Domain 4: Payment Card Industry Security Standards
The broader PCI family from a developer's viewpoint.
- What PCI requirements imply for code, configuration, and data handling
- Which obligations land on development teams versus infrastructure teams
- Protecting stored and transmitted cardholder data in application logic
Domain 5: OWASP Web and Mobile Security
The practical attack-and-defense knowledge base for application developers.
- Recognizing common web and mobile application risks
- Matching each risk to the control that mitigates it
- Differences in the threat surface between web and mobile apps
Domain 6: Common Coding Vulnerabilities
The flaw-level topic: what goes wrong in code and how to write it correctly.
- Injection, broken authentication and session handling, and insecure data exposure
- Input validation and output encoding as default habits
- Spotting a vulnerable snippet and identifying the fix
Domain 7: Threat Modelling
A structured way to find design-level weaknesses before attackers do.
- Identifying assets, entry points, trust boundaries, and threats
- Turning identified threats into concrete mitigations
- Connecting threat modelling back to Security By Design
For a deeper domain-by-domain treatment, see CPISI-D Exam Domains 2026: Complete Guide to All 7 Content Areas.
The PA-DSS Terminology Trap
This is the single most useful nuance on the sheet. SISA's exam-topic list retains the heading "PA-DSS and S3 Standards." Meanwhile, the PCI Security Standards Council states that PA-DSS retired on October 28, 2022. SISA's current workshop curriculum emphasizes PCI-SSF and OWASP.
What this means for you:
- Do not expect the heading to be renamed. It is the issuer's official topic wording, and the retirement of PA-DSS does not authorize rewriting it.
- Study the modern framing too. Because the workshop leans on PCI-SSF, understanding the shift from the older payment-application standard to the newer software security framework protects you if a question approaches the topic from either side.
- Do not assume the topic means "PA-DSS only." The heading is a label; the preparation material points at current software security practice.
Key Takeaway
Treat Domain 3 as a "legacy name, current substance" topic: know what PA-DSS was, know it retired on October 28, 2022, and be fluent in the PCI-SSF and OWASP emphasis of the current workshop.
Workshop Preparation Subjects to Master
SISA's published workshop coverage lists several subjects that make good revision anchors. These are preparation subjects. They do not add official exam domains, they do not carry weights, and they are not proof of exhaustive exam coverage. Use them to deepen your understanding of the seven official topics.
- Cryptography and key management: why strong algorithms still fail when keys are poorly handled, and what safe key lifecycle practice looks like.
- Hashing and tokenization: the difference between irreversible hashing and tokenization that substitutes sensitive values, and when each fits.
- Application authorization and access control: enforcing who may do what on the server side, not just hiding UI elements.
- Audit logging: recording security-relevant events usefully without writing sensitive data into the logs.
- OWASP web and mobile security: the attack classes and defenses already covered under Domain 5.
- Secure deployment and production support: keeping security intact after code ships, including configuration and operational handling.
Eligibility and Fee Cheat Sheet
Eligibility routes
- SISA's 16-hour CPISI-D workshop is a verified route.
- Equivalent formal training of at least 16 hours covering the blueprint topics is also a verified alternative.
- Minimum one year of verifiable full-time experience is displayed by the issuer, but the qualifying areas are referenced and then omitted. Do not assume all developer experience counts. If you plan to use this route, ask SISA to clarify before you pay.
Full details live in CPISI-D Requirements 2026.
Official store prices
| Package | Price |
|---|---|
| Certification only (includes application) | $199 |
| Training plus certification | $449 |
| Training only | $430 |
| Super bundle (includes one retake) | $500 |
Two cautions. First, the store uses dollar notation without an explicit currency code, so confirm the currency at checkout before assuming the amounts are USD. Second, additional convenience charges are nonrefundable. A full cost walkthrough is in CPISI-D Certification Cost 2026.
A Domain-Ordered Study Sequence
Because no domain weights are published, an even spread is the safe default. The ordering below is built around how the topics depend on each other: context first, then design thinking, then standards, then attack-level detail, then synthesis through threat modelling.
Context and Design
- Domain 1: Background of Payment Industry, so later standards make sense
- Domain 2: Security By Design, the principle that frames everything after it
Standards
- Domain 3: PA-DSS and S3 Standards, including the PA-DSS retirement and PCI-SSF emphasis
- Domain 4: Payment Card Industry Security Standards
Attacks and Flaws
- Domain 5: OWASP Web and Mobile Security
- Domain 6: Common Coding Vulnerabilities, paired with the cryptography, hashing, tokenization, and access control subjects
Synthesis and Timed Practice
- Domain 7: Threat Modelling, tying design to attack knowledge
- Full timed runs of 50 questions in 60 minutes to rehearse the pacing
Practicing under the real clock matters more here than on a longer exam, because the pace is tight. Use the CPISI-D practice tests to simulate the 50-question, 60-minute format, and revisit weak domains afterward. For a fuller plan, see the CPISI-D Study Guide 2026, and if you are weighing effort against reward, How Hard Is the CPISI-D Exam? sets expectations.
What Is Still Unverified
A trustworthy cheat sheet says what it does not know. As of the issuer's current, undated pages:
- No official domain percentages. The seven topics are unweighted; any weighting you see is inference.
- No detailed blueprint below the headings. The Exam Blueprint label does not provide a retrievable linked file.
- No confirmed renewal interval or CPE requirement for the Developer credential. Do not apply the base CPISI's renewal rules to this one; ask SISA directly.
- No official pass rate to cite. Treat any specific percentage you encounter skeptically and read CPISI-D Pass Rate 2026: What the Data Shows for how to interpret the limits of available data.
- Unversioned topic list. Re-check SISA's page shortly before you sit the exam, since the public topics are undated.
Likewise, avoid unsourced earnings claims. If compensation is on your mind, CPISI-D Salary Guide 2026 and Is the CPISI-D Certification Worth It? discuss the question qualitatively.
Key Takeaway
Before booking, verify three things directly with SISA: your eligibility route (especially the experience route), the checkout currency, and the current topic list. Everything else on this sheet is stable enough to memorize.
Quick-Fire FAQ
The Developer exam has 50 questions and a 60-minute time limit, with a passing score of 62%. Do not confuse this with the base CPISI's 66% pass mark.
Background of Payment Industry; Security By Design; PA-DSS and S3 Standards; Payment Card Industry Security Standards; OWASP Web and Mobile Security; Common Coding Vulnerabilities; and Threat Modelling. They are published without official weights.
No. PCI SSC states PA-DSS retired on October 28, 2022. SISA nonetheless keeps the heading "PA-DSS and S3 Standards" for the exam topic, and its current workshop emphasizes PCI-SSF and OWASP, so study both the legacy framing and the modern one.
SISA's store lists $199 for certification only, $449 for training plus certification, $430 for training only, and $500 for the super bundle that includes one retake. Convenience charges are nonrefundable, and you should confirm the checkout currency since no explicit currency code is shown.
Nothing in the issuer's published material establishes a separate timed or scored practical exam. Workshop exercises and the two-day live-online training are preparation, not examination components.
Keep this sheet beside you during revision, then test your recall on the CPISI-D practice exam site. For role and career context after you pass, see CPISI-D Jobs.