CPISI-D logo
Focused certification exam prep
Start practice

CPISI-D Requirements 2026: Eligibility, Prerequisites & How to Qualify

TL;DR
  • Verified eligibility routes: SISA's 16-hour CPISI-D workshop, or equivalent formal training of at least 16 hours covering the blueprint topics.
  • SISA also displays a one-year full-time experience route, but the qualifying areas are not stated; get written clarification first.
  • The Developer exam has 50 questions, 60 minutes, and a 62% passing score, not the base CPISI mark of 66%.
  • Certification-only costs $199 on SISA's store; confirm the checkout currency before assuming US dollars.

What Actually Qualifies You for the CPISI-D

The Certified Payment Industry Security Implementer - Developer (CPISI-D) is SISA's credential for people who build payment software and need to prove they can build it securely. It is a separate certification from the base CPISI and from CPISI Advanced, which matters more than it sounds. Eligibility rules, passing marks, and renewal terms for those credentials do not automatically carry over to the Developer track. If you read a forum post that quotes a pass mark or a prerequisite, check which CPISI variant it describes before trusting it.

On SISA's current certification page, there are two eligibility alternatives. The first is training: complete SISA's 16-hour CPISI-D workshop, or equivalent formal training of at least 16 hours that covers the blueprint topics. The second is experience: a minimum of one year of verifiable full-time experience. The first route is clean and well defined. The second is displayed but incomplete, and that gap is covered in detail below.

If you want the broader picture of what the credential is before digging into requirements, start with What Is CPISI-D Certification? and then return here for the qualification mechanics.

Why the distinction from base CPISI matters: The Developer exam uses a 62% passing score. The base CPISI uses 66%. Candidates who prepare to the wrong number, or assume the wrong renewal cycle, are working from another credential's rulebook. Anchor everything you plan to SISA's Developer-specific pages.

The Training Route: 16 Hours of Formal Instruction

The most defensible way to qualify is through training. SISA offers a CPISI-D workshop of 16 hours, and the training offering is described as a two-day live-online course. That format detail is worth separating from the exam itself: a two-day live-online workshop is a training delivery arrangement. It tells you nothing about how the exam is delivered or how long it runs.

What counts as equivalent training

SISA's wording allows for "equivalent formal training of at least 16 hours covering the blueprint topics." Two conditions are embedded there. The training must be formal, and it must cover the blueprint topics. A single conference talk or a self-directed reading list is unlikely to meet that bar. A structured secure-development course that spans PCI standards, OWASP material, common coding vulnerabilities, and threat modelling plausibly could, provided it totals at least 16 hours and you can document it.

Because the issuer does not publish a detailed list of accepted third-party providers, treat equivalence as something to confirm rather than assume. Keep your syllabus, attendance record, and completion certificate. If SISA asks you to demonstrate coverage, those documents are your evidence.

What the workshop emphasizes

SISA's published workshop curriculum emphasizes PCI-SSF and OWASP. It also lists preparation coverage of cryptography and key management, hashing and tokenization, application authorization and access control, audit logging, OWASP web and mobile security, and secure deployment and production support. These are useful preparation subjects, but they are not additional official exam domains and they do not establish weights. Think of them as the practical muscle behind the seven formal exam topics.

Training exercises and workshop hours also do not create a separate timed or scored practical exam. Nothing in the issuer's public materials describes a hands-on lab component that is graded as part of certification.

The Experience Route: What Is Verified and What Is Not

SISA's page displays a route based on a minimum of one year of verifiable full-time experience. Here is the problem: the page refers to qualifying areas for that experience and then does not list them. That leaves a real ambiguity, and the responsible response is to resolve it with the issuer, not to guess.

It is tempting to infer the qualifying areas from the recommended job roles listed elsewhere on SISA's materials, or to assume that any year of developer work counts. Neither inference is supported. A year writing front-end code for a retail site with no payment handling is not obviously the same as a year building or securing cardholder-data flows. Until SISA states the qualifying areas, you cannot know which side of the line your experience falls on.

Before you rely on the experience route: Email SISA and ask three things in writing. Which specific areas of experience qualify? What form of verification is accepted (employer letter, reference, documentation)? Does part-time or contract work count toward the one-year minimum? Save the reply. A written answer protects you if your application is reviewed.

If you cannot get a clear answer quickly, the training route is the safer choice. It removes interpretation from the equation and gives you structured exposure to the blueprint topics at the same time. For many working developers, the workshop is also the faster path to a well-organized mental map of the exam scope.

The Exam You Are Qualifying For

Eligibility only makes sense in light of what you are eligible to sit. The Developer examination is 50 questions in 60 minutes, with a passing score of 62%. That works out to roughly a minute and a few seconds per question, which rewards candidates who recognize concepts quickly over those who need to reason from first principles on each item.

ItemCPISI-D (Developer)
Number of questions50
Time allowed60 minutes
Passing score62%
Eligibility16-hour CPISI-D workshop or equivalent formal training of 16+ hours; or one year of verifiable full-time experience (qualifying areas require issuer clarification)
Separate scored practical examNone established in public materials

For a deeper treatment of the scoring threshold, see CPISI-D Passing Score 2026: Exactly What You Need to Pass. If you are weighing how demanding the sitting is, How Hard Is the CPISI-D Exam? covers difficulty in more depth.

Registration Paths and Fee Mechanics

SISA's training and certification store lists several purchase options, and the one you choose interacts directly with how you meet eligibility. The listed prices use dollar notation without an explicit currency code, so confirm the currency at checkout before treating any figure as US dollars.

OptionPriceWhat it covers
Certification only$199Certification including the application
Training plus certification$449Workshop and the certification exam
Training only$430Workshop without the exam
Super bundle$500Training and certification, including one retake

A few practical readings of that table. The certification-only option at $199 makes sense if you already have qualifying formal training or have confirmed that your experience qualifies. The $449 training-plus-certification bundle is the natural fit if you need the workshop to satisfy eligibility. The gap between $430 for training alone and $449 for training plus certification is small, so buying training alone and certification separately later rarely saves money. The $500 super bundle adds one retake, which is a form of insurance for a 50-question, 60-minute exam with a 62% bar.

Additional convenience charges are nonrefundable. Read the checkout summary line by line before paying. For a fuller financial picture, including how to think about total spend, see CPISI-D Certification Cost 2026: Complete Pricing Breakdown.

Key Takeaway

Match your purchase to your eligibility situation. If you need the workshop to qualify, buy a bundle that includes training. If you already hold qualifying formal training, certification-only at $199 avoids paying for instruction you do not need. Confirm the currency and any convenience charges before you click pay.

The Seven Exam Topics You Must Be Ready For

SISA's current certification page lists seven exam topics. They are published without weights, the list is unversioned, and the displayed Exam Blueprint label does not provide a retrievable linked file. That means you should not assume a percentage breakdown, and you should not assume hidden sub-headings beyond what the issuer lists. Study all seven with roughly balanced attention, adjusted for your own weak spots.

Background of Payment Industry

The foundation: how card payments move, who the participants are, and where sensitive data lives along the way.

  • Roles of merchants, acquirers, issuers, and processors
  • Where cardholder data is stored, processed, and transmitted
  • Why developers sit directly in the line of fire for data exposure

Security By Design

Building protection into the application from the first design decision rather than bolting it on at the end.

  • Least privilege, defense in depth, and secure defaults
  • Authorization and access control decisions at design time
  • Planning for logging, key handling, and secure deployment early

PA-DSS and S3 Standards

The heading as SISA publishes it. Expect questions framed around payment-application security expectations and secure software lifecycle thinking.

  • Understand the legacy PA-DSS context and how it relates to newer secure software standards
  • Recognize the PCI-SSF emphasis in SISA's current workshop material

Payment Card Industry Security Standards

The broader PCI framework that governs how payment data must be protected.

  • How PCI requirements translate into developer responsibilities
  • Protection of stored and transmitted cardholder data

OWASP Web and Mobile Security

Application-layer risks across both web and mobile platforms.

  • Common web and mobile risk categories and their mitigations
  • Authentication, session handling, and input validation concerns

Common Coding Vulnerabilities

The recurring mistakes that turn into breaches, and the coding practices that prevent them.

  • Injection flaws, insecure data handling, and weak error handling
  • Safe use of cryptography, hashing, and tokenization in code

Threat Modelling

Systematically identifying what can go wrong with a payment application before attackers do.

  • Mapping data flows and trust boundaries
  • Identifying threats and prioritizing mitigations

For a section-by-section walk through each area, read CPISI-D Exam Domains 2026: Complete Guide to All 7 Content Areas.

The PA-DSS Terminology Trap

One of the seven headings, "PA-DSS and S3 Standards," deserves its own warning. PCI Security Standards Council states that PA-DSS retired on October 28, 2022. Yet SISA's exam topic still carries the PA-DSS label, while its current workshop curriculum emphasizes PCI-SSF and OWASP.

The right way to handle this is to hold both facts at once. The retirement is a real fact about the PCI Council's standards landscape. The heading is also the real wording of SISA's exam topic. You do not get to rename the topic in your head and skip it, and you should not dismiss the older material as irrelevant either. Study the legacy framework as context, understand how newer secure software standards replaced it, and be prepared for questions that use SISA's terminology.

Practical consequence: When you take practice questions, notice whether they use older or newer terminology and map each to the same underlying concept. A candidate who understands that the secure-development intent persisted through the standards transition will handle either phrasing.

Who Should Apply and Who Hires for This Skill Set

The Developer credential is aimed at people who write, review, or maintain payment-related software. That includes application developers, mobile developers, and engineers on teams that handle cardholder data or integrate with payment gateways. Secure code reviewers and technical leads responsible for the security of a payment application also fit naturally.

Organizations that care about this skill set tend to be those that either build payment applications or process card data inside their own systems: payment solution vendors, fintech companies, banks and their technology partners, e-commerce platforms, and security consultancies that serve them. The credential signals that a developer understands PCI expectations and common vulnerability classes, which reduces the burden on security teams during assessments.

Be careful about reading too much into job-role lists. Roles recommended by an issuer indicate who the credential is aimed at; they do not define what experience counts toward eligibility. For market-facing questions, see CPISI-D Jobs, CPISI-D Salary Guide 2026, and Is the CPISI-D Certification Worth It? for a balanced view of return on investment.

A Qualification Plan Built Around the Topic List

Once you have decided on a route, sequence your preparation so the foundational topics come before the applied ones. Here is one way to lay out the weeks if you are using the workshop route and have a few weeks around it.

Week 1

Confirm eligibility and learn the landscape

  • Decide between the workshop route and the experience route; get any clarification from SISA in writing
  • Cover Background of Payment Industry so later topics have context
  • Confirm checkout currency before purchasing
Week 2

Standards and design

  • Work through Payment Card Industry Security Standards and PA-DSS and S3 Standards together
  • Study Security By Design alongside them, since standards expectations drive design decisions
  • Note the PA-DSS retirement and PCI-SSF emphasis as you read
Week 3

Application-layer security and threats

  • Cover OWASP Web and Mobile Security and Common Coding Vulnerabilities as a pair
  • Finish with Threat Modelling to tie risks back to design
  • Run timed sets of 50 questions in 60 minutes to rehearse the pace

That ordering is deliberate: payment context and standards first, design principles next, then the code-level and threat-level material that builds on them. For a longer preparation framework, see the CPISI-D Study Guide 2026: How to Pass on Your First Attempt, and use the CPISI-D practice tests to check readiness against the 62% bar. A compact revision aid is available in the CPISI-D Cheat Sheet.

What this article cannot give you is renewal information. Exact Developer renewal intervals and CPE requirements remain unverified, and the base CPISI renewal rules should not be transplanted onto this credential. Before you pay, review SISA's certification policy page and confirm the current terms directly with the issuer.

Frequently Asked Questions

Do I have to take SISA's own workshop to qualify for the CPISI-D?

Not necessarily. SISA's verified alternatives include its 16-hour CPISI-D workshop or equivalent formal training of at least 16 hours that covers the blueprint topics. If you use outside training, keep the syllabus and completion records in case you need to show it covers the exam topics.

Does one year of developer experience automatically qualify me?

Not automatically. SISA displays a minimum one-year verifiable full-time experience route but does not state the qualifying areas on the page. Do not assume all developer work counts; ask SISA to confirm which experience qualifies and how it must be verified.

What score do I need to pass, and how long is the exam?

The Developer exam has 50 questions, 60 minutes, and a passing score of 62%. Do not confuse this with the base CPISI pass mark of 66%, which applies to a different credential.

How much does it cost to get certified?

SISA's store lists $199 for certification only, $449 for training plus certification, $430 for training only, and $500 for a super bundle that includes one retake. Prices use dollar notation without a stated currency code, so confirm the currency at checkout. Additional convenience charges are nonrefundable.

Is PA-DSS still part of the exam if the PCI Council retired it?

SISA's published exam topic is still titled "PA-DSS and S3 Standards," even though PCI SSC states PA-DSS retired on October 28, 2022. Study the heading as published, understand the legacy context, and note that SISA's workshop emphasizes PCI-SSF and OWASP.

Ready to pass your CPISI-D exam?

Put this into practice with free CPISI-D questions across every exam domain.