- What the Seven Headings Actually Are
- Exam Format and Eligibility at a Glance
- Domains 1 and 2: Payment Industry Background and Security by Design
- Domains 3 and 4: PA-DSS, S3 Standards and PCI Security Standards
- Domains 5, 6 and 7: OWASP, Coding Vulnerabilities and Threat Modelling
- Preparation Subjects Beyond the Seven Headings
- Sequencing the Domains in Your Study Plan
- Fees and Registration Mechanics
- Frequently Asked Questions
- SISA publishes seven unweighted exam topics for CPISI-D; no official percentage weights exist, so study every heading.
- The Developer exam has 50 questions, 60 minutes, and a 62% passing score, not the base CPISI 66%.
- Domain 3 keeps the legacy heading "PA-DSS and S3 Standards," even though PCI SSC retired PA-DSS on October 28, 2022.
- Workshop topics like cryptography and tokenization are preparation coverage, not extra official exam domains.
What the Seven Headings Actually Are
The Certified Payment Industry Security Implementer - Developer credential, issued by SISA, is built around seven exam-topic headings published on SISA's current CPISI-D certification page. They are listed in the order below, and the wording is exactly what the issuer displays:
- Background of Payment Industry
- Security By Design
- PA-DSS and S3 Standards
- Payment Card Industry Security Standards
- OWASP Web and Mobile Security
- Common Coding Vulnerabilities
- Threat Modelling
Two limits are worth stating plainly. First, the list is unweighted. SISA does not publish percentages per heading, so any article claiming "Domain 5 is 25% of the exam" is inventing a number. Second, the public topic list is unversioned and the page's "Exam Blueprint" label does not lead to a retrievable linked file. That means there is no exhaustive sub-objective list to memorize, and you should be cautious about anyone selling one as official.
If you are new to the credential itself, our explainer on what CPISI-D certification is covers the basics, and the CPISI-D requirements guide goes deeper on eligibility. This article focuses on the content areas.
Exam Format and Eligibility at a Glance
Before diving into the domains, it helps to anchor them to the exam that tests them. The facts below come from SISA's published materials.
| Item | CPISI-D Detail |
|---|---|
| Questions | 50 |
| Time allowed | 60 minutes |
| Passing score | 62% |
| Eligibility route 1 | SISA's 16-hour CPISI-D workshop |
| Eligibility route 2 | Equivalent formal training of at least 16 hours covering the blueprint topics |
| Eligibility route 3 | Minimum one year of verifiable full-time experience (qualifying areas not specified publicly; clarify with SISA) |
A few clarifications prevent common mix-ups. The 62% pass mark applies to the Developer exam specifically; do not confuse it with the 66% pass mark of the base CPISI. The two-day live-online offering is a training course, not the length of the exam, and training exercises do not create a separate timed or scored practical exam. For the arithmetic behind the cutoff, see our CPISI-D passing score guide.
On the experience route, the issuer refers to qualifying areas but does not list them publicly. Do not assume all developer experience automatically qualifies; email SISA before relying on that route.
Domains 1 and 2: Payment Industry Background and Security by Design
Domain 1: Background of Payment Industry
Background of Payment Industry
This opening heading establishes the context in which a payment application developer works. Developers who skip it often struggle later, because the security standards in Domains 3 and 4 only make sense once you understand who handles card data and why.
- How card payments flow between the parties involved in a transaction
- Where cardholder data lives, moves, and is exposed in a payment ecosystem
- Why the industry has security standards and who enforces them
- How a developer's code fits into the larger compliance picture
Candidates from pure software backgrounds should invest here. Candidates from payments or fintech operations may find this domain familiar but should still verify that their vocabulary matches the standards-based terminology used in the exam.
Domain 2: Security By Design
Security By Design
This domain is about building security in from the start rather than bolting it on. For a developer-focused certification, expect it to connect directly to how you structure, review, and ship payment code.
- Embedding security requirements into design and development phases
- Reducing attack surface through deliberate architectural decisions
- Applying defensive principles consistently rather than only at release time
- Linking design choices to the standards covered in Domains 3 and 4
Security By Design is the conceptual bridge in the exam. It tells you why the later, more technical domains matter, and scenario-style questions often reward candidates who can reason about design decisions rather than recall a definition.
Domains 3 and 4: PA-DSS, S3 Standards and PCI Security Standards
Domain 3: PA-DSS and S3 Standards
This is the heading most likely to confuse modern candidates, so read it carefully. The issuer's exam topic is titled PA-DSS and S3 Standards, and that is the wording you should expect. At the same time, the PCI Security Standards Council states that PA-DSS was retired on October 28, 2022. SISA's current workshop curriculum emphasizes PCI-SSF and OWASP.
PA-DSS and S3 Standards
Study this domain as a standards-transition topic: what the older payment application standard addressed, what replaced it in practice, and how S3-style secure software requirements apply to the code you write.
- The purpose and history of PA-DSS and why it was retired
- How the software security framework approach differs from the older model
- What secure software lifecycle expectations mean for a payment application developer
- The vocabulary a candidate must recognize when both legacy and current terms appear
Domain 4: Payment Card Industry Security Standards
Payment Card Industry Security Standards
Where Domain 3 focuses on application-level software standards, this domain covers the broader PCI security standards landscape that surrounds payment environments.
- The role of PCI standards in protecting cardholder data
- How broader PCI requirements relate to application development responsibilities
- Distinguishing which standard applies to which party or component
- Connecting standards language to practical developer obligations
A smart approach is to study Domains 3 and 4 together and build a one-page map of which standard governs what. Our CPISI-D cheat sheet is a good place to consolidate that map once you have drafted it yourself.
Domains 5, 6 and 7: OWASP, Coding Vulnerabilities and Threat Modelling
The final three headings are the most hands-on and most directly relevant to day-to-day secure coding. They also overlap heavily, which works in your favor: understanding one reinforces the others.
Domain 5: OWASP Web and Mobile Security
OWASP Web and Mobile Security
The heading covers both web and mobile, so do not prepare for only one. Payment applications commonly span both surfaces, and the workshop curriculum specifically emphasizes OWASP.
- Common web application risk categories and how they manifest in payment flows
- Mobile application security concerns distinct from web concerns
- How OWASP guidance maps to the secure development expectations in the PCI standards
- Recognizing risky patterns in code or design descriptions
Domain 6: Common Coding Vulnerabilities
Common Coding Vulnerabilities
This is where the exam gets closest to actual code. Expect to recognize vulnerability classes and understand the defensive coding practice that addresses each one.
- Identifying how typical vulnerabilities arise from unsafe coding practices
- Matching a vulnerability to its appropriate mitigation
- Understanding input handling, error handling, and data protection at the code level
- Reading short scenarios and spotting the flaw
Domain 7: Threat Modelling
Threat Modelling
Threat modelling closes the list and ties many earlier themes together. It is the structured practice of anticipating how a system can be attacked before it is built or shipped.
- Identifying assets, entry points, and trust boundaries in a payment application
- Reasoning about who might attack and how
- Prioritizing threats and linking them to countermeasures
- Connecting threat modelling back to Security By Design (Domain 2)
Key Takeaway
Domains 2, 5, 6 and 7 form a loop: design securely, know the common risk categories, recognize the coding flaws, and model the threats. Studying them as one connected workflow is more efficient than treating them as four separate memorization lists.
Preparation Subjects Beyond the Seven Headings
SISA's workshop page publishes preparation coverage that goes beyond the seven exam headings. These subjects include:
- Cryptography and key management
- Hashing and tokenization
- Application authorization and access control
- Audit logging
- OWASP web and mobile security
- Secure deployment and production support
This distinction matters. These are preparation subjects, not additional official exam domains. They do not add headings to the exam, they do not establish domain weights, and they do not prove that the exam covers each of them exhaustively. They are, however, useful scaffolding. A solid grasp of cryptography, tokenization, and access control will make Domains 4, 5 and 6 far easier, because payment security standards lean heavily on protecting stored and transmitted data.
For a broader look at how the training relates to the exam, see our page on CPISI-D training.
Sequencing the Domains in Your Study Plan
Since the exam is unweighted, sequence by dependency rather than by rumor. This is the only study-planning section in this article, and it is tied strictly to the domain order. For a fuller preparation framework, see the CPISI-D study guide.
Context and principles
- Domain 1: Background of Payment Industry
- Domain 2: Security By Design
- Why first: these give you the vocabulary every later domain assumes
Standards
- Domain 3: PA-DSS and S3 Standards (with the PA-DSS retirement context)
- Domain 4: Payment Card Industry Security Standards
- Why second: the standards explain what the technical domains are protecting
Technical depth
- Domain 5: OWASP Web and Mobile Security
- Domain 6: Common Coding Vulnerabilities
- Why third: easiest to retain once the standards framework is in place
Synthesis and timed practice
- Domain 7: Threat Modelling
- Full-length timed sets at 50 questions in 60 minutes
- Revisit your weakest heading
Timed practice matters here because 60 minutes for 50 questions leaves roughly a minute and a bit per question. You can rehearse that pacing with the CPISI-D practice tests, and our guide on how hard the CPISI-D exam is discusses where candidates tend to feel pressure.
Fees and Registration Mechanics
SISA's official store lists several purchase options. The store uses dollar notation without an explicit currency code, so confirm the currency at checkout before assuming the figures are USD.
| Option | Listed Price | What It Includes |
|---|---|---|
| Certification only | $199 | Certification including application |
| Training plus certification | $449 | Workshop and certification |
| Training only | $430 | Workshop without the exam |
| Super bundle | $500 | Training and certification, including one retake |
Additional convenience charges are nonrefundable. If you already meet eligibility through equivalent formal training of at least 16 hours covering the blueprint topics, the certification-only option may fit; if you need the workshop, a bundle is the usual route. The super bundle's included retake is the main differentiator for candidates who want a safety net. A fuller breakdown is in our CPISI-D certification cost guide.
One item remains unverified: the exact renewal interval and CPE requirements for the Developer credential. Base CPISI renewal rules should not be assumed to apply here, so check SISA directly before planning long-term maintenance.
Candidates weighing the investment can read our analysis of whether CPISI-D is worth it, and those exploring career angles can look at CPISI-D jobs.
Frequently Asked Questions
SISA publishes seven exam-topic headings: Background of Payment Industry, Security By Design, PA-DSS and S3 Standards, Payment Card Industry Security Standards, OWASP Web and Mobile Security, Common Coding Vulnerabilities, and Threat Modelling.
No official weights are published. The seven headings are unweighted, so any percentage breakdown you see elsewhere is not from the issuer. Prepare for all seven.
PCI SSC states PA-DSS retired on October 28, 2022, but SISA's exam topic is still titled "PA-DSS and S3 Standards." The heading is preserved as published, while the workshop curriculum emphasizes PCI-SSF and OWASP.
The exam has 50 questions in 60 minutes with a 62% passing score. This differs from the base CPISI pass mark of 66%, which does not apply to the Developer exam.
No. Cryptography, key management, hashing, tokenization, and similar topics appear in SISA's workshop preparation coverage, but they are not additional official exam domains and do not establish weights or exhaustive coverage.