CPISI-D logo
Focused certification exam prep
Start practice

CPISI-D Exam Domains 2026: Complete Guide to All 7 Content Areas

TL;DR
  • SISA publishes seven unweighted exam topics for CPISI-D; no official percentage weights exist, so study every heading.
  • The Developer exam has 50 questions, 60 minutes, and a 62% passing score, not the base CPISI 66%.
  • Domain 3 keeps the legacy heading "PA-DSS and S3 Standards," even though PCI SSC retired PA-DSS on October 28, 2022.
  • Workshop topics like cryptography and tokenization are preparation coverage, not extra official exam domains.

What the Seven Headings Actually Are

The Certified Payment Industry Security Implementer - Developer credential, issued by SISA, is built around seven exam-topic headings published on SISA's current CPISI-D certification page. They are listed in the order below, and the wording is exactly what the issuer displays:

  1. Background of Payment Industry
  2. Security By Design
  3. PA-DSS and S3 Standards
  4. Payment Card Industry Security Standards
  5. OWASP Web and Mobile Security
  6. Common Coding Vulnerabilities
  7. Threat Modelling

Two limits are worth stating plainly. First, the list is unweighted. SISA does not publish percentages per heading, so any article claiming "Domain 5 is 25% of the exam" is inventing a number. Second, the public topic list is unversioned and the page's "Exam Blueprint" label does not lead to a retrievable linked file. That means there is no exhaustive sub-objective list to memorize, and you should be cautious about anyone selling one as official.

Why the lack of weights matters: Without published percentages, you cannot safely skip a domain on the theory that it is "light." Treat each of the seven headings as fair game and balance your study time by your own weaknesses, not by a rumored weighting.

If you are new to the credential itself, our explainer on what CPISI-D certification is covers the basics, and the CPISI-D requirements guide goes deeper on eligibility. This article focuses on the content areas.

Exam Format and Eligibility at a Glance

Before diving into the domains, it helps to anchor them to the exam that tests them. The facts below come from SISA's published materials.

ItemCPISI-D Detail
Questions50
Time allowed60 minutes
Passing score62%
Eligibility route 1SISA's 16-hour CPISI-D workshop
Eligibility route 2Equivalent formal training of at least 16 hours covering the blueprint topics
Eligibility route 3Minimum one year of verifiable full-time experience (qualifying areas not specified publicly; clarify with SISA)

A few clarifications prevent common mix-ups. The 62% pass mark applies to the Developer exam specifically; do not confuse it with the 66% pass mark of the base CPISI. The two-day live-online offering is a training course, not the length of the exam, and training exercises do not create a separate timed or scored practical exam. For the arithmetic behind the cutoff, see our CPISI-D passing score guide.

On the experience route, the issuer refers to qualifying areas but does not list them publicly. Do not assume all developer experience automatically qualifies; email SISA before relying on that route.

Domains 1 and 2: Payment Industry Background and Security by Design

Domain 1: Background of Payment Industry

Background of Payment Industry

This opening heading establishes the context in which a payment application developer works. Developers who skip it often struggle later, because the security standards in Domains 3 and 4 only make sense once you understand who handles card data and why.

  • How card payments flow between the parties involved in a transaction
  • Where cardholder data lives, moves, and is exposed in a payment ecosystem
  • Why the industry has security standards and who enforces them
  • How a developer's code fits into the larger compliance picture

Candidates from pure software backgrounds should invest here. Candidates from payments or fintech operations may find this domain familiar but should still verify that their vocabulary matches the standards-based terminology used in the exam.

Domain 2: Security By Design

Security By Design

This domain is about building security in from the start rather than bolting it on. For a developer-focused certification, expect it to connect directly to how you structure, review, and ship payment code.

  • Embedding security requirements into design and development phases
  • Reducing attack surface through deliberate architectural decisions
  • Applying defensive principles consistently rather than only at release time
  • Linking design choices to the standards covered in Domains 3 and 4

Security By Design is the conceptual bridge in the exam. It tells you why the later, more technical domains matter, and scenario-style questions often reward candidates who can reason about design decisions rather than recall a definition.

Domains 3 and 4: PA-DSS, S3 Standards and PCI Security Standards

Domain 3: PA-DSS and S3 Standards

This is the heading most likely to confuse modern candidates, so read it carefully. The issuer's exam topic is titled PA-DSS and S3 Standards, and that is the wording you should expect. At the same time, the PCI Security Standards Council states that PA-DSS was retired on October 28, 2022. SISA's current workshop curriculum emphasizes PCI-SSF and OWASP.

Legacy terminology, current exam heading: The retirement of PA-DSS does not change the name of SISA's exam topic. Learn the heading as published, understand that PA-DSS is a legacy standard, and study how the newer PCI Software Security Framework (the PCI-SSF the workshop emphasizes) relates to it. Do not assume the heading will be renamed for your exam sitting.

PA-DSS and S3 Standards

Study this domain as a standards-transition topic: what the older payment application standard addressed, what replaced it in practice, and how S3-style secure software requirements apply to the code you write.

  • The purpose and history of PA-DSS and why it was retired
  • How the software security framework approach differs from the older model
  • What secure software lifecycle expectations mean for a payment application developer
  • The vocabulary a candidate must recognize when both legacy and current terms appear

Domain 4: Payment Card Industry Security Standards

Payment Card Industry Security Standards

Where Domain 3 focuses on application-level software standards, this domain covers the broader PCI security standards landscape that surrounds payment environments.

  • The role of PCI standards in protecting cardholder data
  • How broader PCI requirements relate to application development responsibilities
  • Distinguishing which standard applies to which party or component
  • Connecting standards language to practical developer obligations

A smart approach is to study Domains 3 and 4 together and build a one-page map of which standard governs what. Our CPISI-D cheat sheet is a good place to consolidate that map once you have drafted it yourself.

Domains 5, 6 and 7: OWASP, Coding Vulnerabilities and Threat Modelling

The final three headings are the most hands-on and most directly relevant to day-to-day secure coding. They also overlap heavily, which works in your favor: understanding one reinforces the others.

Domain 5: OWASP Web and Mobile Security

OWASP Web and Mobile Security

The heading covers both web and mobile, so do not prepare for only one. Payment applications commonly span both surfaces, and the workshop curriculum specifically emphasizes OWASP.

  • Common web application risk categories and how they manifest in payment flows
  • Mobile application security concerns distinct from web concerns
  • How OWASP guidance maps to the secure development expectations in the PCI standards
  • Recognizing risky patterns in code or design descriptions

Domain 6: Common Coding Vulnerabilities

Common Coding Vulnerabilities

This is where the exam gets closest to actual code. Expect to recognize vulnerability classes and understand the defensive coding practice that addresses each one.

  • Identifying how typical vulnerabilities arise from unsafe coding practices
  • Matching a vulnerability to its appropriate mitigation
  • Understanding input handling, error handling, and data protection at the code level
  • Reading short scenarios and spotting the flaw

Domain 7: Threat Modelling

Threat Modelling

Threat modelling closes the list and ties many earlier themes together. It is the structured practice of anticipating how a system can be attacked before it is built or shipped.

  • Identifying assets, entry points, and trust boundaries in a payment application
  • Reasoning about who might attack and how
  • Prioritizing threats and linking them to countermeasures
  • Connecting threat modelling back to Security By Design (Domain 2)

Key Takeaway

Domains 2, 5, 6 and 7 form a loop: design securely, know the common risk categories, recognize the coding flaws, and model the threats. Studying them as one connected workflow is more efficient than treating them as four separate memorization lists.

Preparation Subjects Beyond the Seven Headings

SISA's workshop page publishes preparation coverage that goes beyond the seven exam headings. These subjects include:

  • Cryptography and key management
  • Hashing and tokenization
  • Application authorization and access control
  • Audit logging
  • OWASP web and mobile security
  • Secure deployment and production support

This distinction matters. These are preparation subjects, not additional official exam domains. They do not add headings to the exam, they do not establish domain weights, and they do not prove that the exam covers each of them exhaustively. They are, however, useful scaffolding. A solid grasp of cryptography, tokenization, and access control will make Domains 4, 5 and 6 far easier, because payment security standards lean heavily on protecting stored and transmitted data.

How to use this list: Treat it as background reading that supports the seven official headings, not as a replacement syllabus. If a topic from this list helps you understand a heading, study it; if you are short on time, prioritize the seven headings first.

For a broader look at how the training relates to the exam, see our page on CPISI-D training.

Sequencing the Domains in Your Study Plan

Since the exam is unweighted, sequence by dependency rather than by rumor. This is the only study-planning section in this article, and it is tied strictly to the domain order. For a fuller preparation framework, see the CPISI-D study guide.

Week 1

Context and principles

  • Domain 1: Background of Payment Industry
  • Domain 2: Security By Design
  • Why first: these give you the vocabulary every later domain assumes
Week 2

Standards

  • Domain 3: PA-DSS and S3 Standards (with the PA-DSS retirement context)
  • Domain 4: Payment Card Industry Security Standards
  • Why second: the standards explain what the technical domains are protecting
Week 3

Technical depth

  • Domain 5: OWASP Web and Mobile Security
  • Domain 6: Common Coding Vulnerabilities
  • Why third: easiest to retain once the standards framework is in place
Week 4

Synthesis and timed practice

  • Domain 7: Threat Modelling
  • Full-length timed sets at 50 questions in 60 minutes
  • Revisit your weakest heading

Timed practice matters here because 60 minutes for 50 questions leaves roughly a minute and a bit per question. You can rehearse that pacing with the CPISI-D practice tests, and our guide on how hard the CPISI-D exam is discusses where candidates tend to feel pressure.

Fees and Registration Mechanics

SISA's official store lists several purchase options. The store uses dollar notation without an explicit currency code, so confirm the currency at checkout before assuming the figures are USD.

OptionListed PriceWhat It Includes
Certification only$199Certification including application
Training plus certification$449Workshop and certification
Training only$430Workshop without the exam
Super bundle$500Training and certification, including one retake

Additional convenience charges are nonrefundable. If you already meet eligibility through equivalent formal training of at least 16 hours covering the blueprint topics, the certification-only option may fit; if you need the workshop, a bundle is the usual route. The super bundle's included retake is the main differentiator for candidates who want a safety net. A fuller breakdown is in our CPISI-D certification cost guide.

One item remains unverified: the exact renewal interval and CPE requirements for the Developer credential. Base CPISI renewal rules should not be assumed to apply here, so check SISA directly before planning long-term maintenance.

Candidates weighing the investment can read our analysis of whether CPISI-D is worth it, and those exploring career angles can look at CPISI-D jobs.

Frequently Asked Questions

How many exam domains does CPISI-D have?

SISA publishes seven exam-topic headings: Background of Payment Industry, Security By Design, PA-DSS and S3 Standards, Payment Card Industry Security Standards, OWASP Web and Mobile Security, Common Coding Vulnerabilities, and Threat Modelling.

Are the CPISI-D domains weighted by percentage?

No official weights are published. The seven headings are unweighted, so any percentage breakdown you see elsewhere is not from the issuer. Prepare for all seven.

Why does the exam still list PA-DSS if it was retired?

PCI SSC states PA-DSS retired on October 28, 2022, but SISA's exam topic is still titled "PA-DSS and S3 Standards." The heading is preserved as published, while the workshop curriculum emphasizes PCI-SSF and OWASP.

What is the CPISI-D format and passing score?

The exam has 50 questions in 60 minutes with a 62% passing score. This differs from the base CPISI pass mark of 66%, which does not apply to the Developer exam.

Do cryptography and tokenization count as separate exam domains?

No. Cryptography, key management, hashing, tokenization, and similar topics appear in SISA's workshop preparation coverage, but they are not additional official exam domains and do not establish weights or exhaustive coverage.

Ready to pass your CPISI-D exam?

Put this into practice with free CPISI-D questions across every exam domain.