- What "CPISI-D Training" Actually Covers
- The 16-Hour Workshop and Equivalent Training
- The Seven Exam Topics Your Training Must Address
- Hands-On Preparation Subjects in the Curriculum
- Reading "PA-DSS and S3 Standards" Correctly
- Training Pricing and Bundle Options
- Sequencing Your Training Around the Exam Topics
- Who Gets the Most From This Training
- Frequently Asked Questions
- SISA's CPISI-D workshop is 16 hours, and equivalent formal training of at least 16 hours covering the blueprint topics is also accepted.
- The exam has 50 questions, 60 minutes, and a 62% passing score, not the 66% used by base CPISI.
- Seven official exam topics are listed without weights, so train evenly rather than chasing guessed percentages.
- Training plus certification is priced at $449; certification-only is $199. Confirm checkout currency first.
What "CPISI-D Training" Actually Covers
The Certified Payment Industry Security Implementer - Developer credential, issued by SISA, is aimed at people who build payment software rather than audit or administer it. "Training" for this credential therefore has a specific meaning: instruction that equips developers to write, review, and deploy code that protects cardholder data in line with payment-industry expectations. It is distinct from the base CPISI and from CPISI Advanced, which serve different audiences and carry different exam parameters.
If you are still orienting yourself, start with What Is CPISI-D? for the credential overview, then return here for the training specifics. This article focuses on what the training involves, how it maps to the exam, and how to decide between SISA's own workshop and an equivalent alternative.
The 16-Hour Workshop and Equivalent Training
SISA's CPISI-D workshop runs 16 hours and is offered as a two-day live-online course. That delivery format describes the training only. It tells you nothing about how the exam is delivered, and you should not assume the two-day structure applies to the test itself.
Two verified ways to satisfy the training expectation
- SISA's own 16-hour CPISI-D workshop: The issuer's direct offering, built around the secure application development curriculum.
- Equivalent formal training: At least 16 hours of formal instruction that covers the blueprint topics. The key phrase is "covers the blueprint topics": a generic secure-coding course that never touches payment standards or threat modelling would not obviously qualify.
SISA also displays a route based on a minimum of one year of verifiable full-time experience. However, the issuer refers to qualifying areas without spelling them out publicly, so you should not assume that any developer experience counts. If you plan to rely on experience rather than coursework, contact SISA for clarification before paying for anything. Our CPISI-D requirements guide walks through the eligibility logic in more detail.
| Route | What it involves | What to confirm |
|---|---|---|
| SISA 16-hour workshop | Two-day live-online course on secure payment application development | Session schedule and checkout currency |
| Equivalent formal training | At least 16 hours covering the blueprint topics | That the syllabus maps to all seven topics |
| One-year experience route | Verifiable full-time experience | Which experience areas qualify; the issuer must clarify |
The Seven Exam Topics Your Training Must Address
SISA's current certification page lists seven exam topics. They are published without percentage weights and without a linked, retrievable blueprint document, so any claim about how heavily a given topic is tested is speculation. The sensible response is to build competence across all seven. For a deeper breakdown, see the CPISI-D exam domains guide.
Domain 1: Background of Payment Industry
Context that makes the rest of the material make sense. Developers who skip this tend to memorize controls without understanding why they exist.
- How card transactions flow between participants
- Who holds responsibility for protecting cardholder data at each stage
- Why payment applications attract attackers
Domain 2: Security By Design
Building protection into the application from the first design decision rather than bolting it on after testing.
- Least privilege and defense in depth applied to application architecture
- Minimizing the data an application stores or transmits
- Secure defaults and fail-safe behavior
Domain 3: PA-DSS and S3 Standards
The official topic heading, preserved as SISA words it. See the dedicated section below on how to read this heading against the current standards landscape.
Domain 4: Payment Card Industry Security Standards
The broader family of PCI requirements that shape how payment software and its environment are expected to behave.
- How software-level expectations relate to wider PCI obligations
- What developers are responsible for versus infrastructure and operations teams
Domain 5: OWASP Web and Mobile Security
Application-layer risk categories for both web and mobile front ends, which matter because payment flows increasingly begin on a phone.
- Recognizing common web and mobile risk categories
- Mapping a risk to the secure coding practice that mitigates it
Domain 6: Common Coding Vulnerabilities
The concrete flaws that appear in real code, and how to spot and prevent them during development and review.
- Input handling and output encoding failures
- Weak session, authentication, and error-handling patterns
- Insecure handling of sensitive data in memory, logs, and storage
Domain 7: Threat Modelling
A structured way to anticipate how an attacker would target the application before a line of code ships.
- Identifying assets, entry points, and trust boundaries in a payment application
- Turning identified threats into design and testing requirements
Hands-On Preparation Subjects in the Curriculum
Beyond the seven exam headings, SISA's published workshop curriculum highlights a set of preparation subjects. These describe what you will practice in class. They do not add official exam domains, establish weights, or prove that the exam covers each one exhaustively, so treat them as useful support for the seven topics rather than a replacement syllabus.
- Cryptography and key management: Choosing appropriate protection for sensitive data and handling keys across their lifecycle.
- Hashing and tokenization: Understanding when each technique fits and what each does and does not protect.
- Application authorization and access control: Designing who can do what inside the application, and enforcing it server-side.
- Audit logging: Recording security-relevant events without leaking the very data you are trying to protect.
- OWASP web and mobile security: Applying the application-risk lens to both platform types.
- Secure deployment and production support: Keeping a payment application safe after release, including how it is configured, released, and supported.
Key Takeaway
Use the preparation subjects as the practical layer under each exam topic. For example, tokenization and key management give you concrete material to reason about when a question touches Security By Design or PCI standards, even though neither is an official exam heading.
Reading "PA-DSS and S3 Standards" Correctly
This is the one exam heading that can confuse candidates. PCI Security Standards Council states that PA-DSS retired on October 28, 2022, and SISA's current workshop curriculum emphasizes PCI-SSF and OWASP. Yet the exam topic is still titled "PA-DSS and S3 Standards" on the issuer's certification page.
The right approach is to hold both facts at once:
- Keep the official heading exactly as SISA publishes it. Do not rename the topic in your notes as though the exam had changed.
- Study the current secure software expectations that the workshop emphasizes, since that is where the live curriculum has moved.
- Understand the legacy PA-DSS terminology well enough to recognize it, because a question or reference may still use the older language.
This legacy-terminology distinction does not authorize you to treat the exam topic as something other than what the issuer lists. When in doubt, favor the issuer's wording for exam preparation and the PCI Council's guidance for real-world accuracy.
Training Pricing and Bundle Options
SISA's store lists four options. Prices appear in dollar notation without an explicit currency code, so confirm the currency at checkout before assuming US dollars. Additional convenience charges are nonrefundable.
| Option | Listed price | What it includes |
|---|---|---|
| Certification only | $199 | Exam, including application |
| Training plus certification | $449 | Workshop and exam |
| Training only | $430 | Workshop without the exam |
| Super bundle | $500 | Training, certification, and one retake |
The arithmetic is worth a moment. Training only costs $430, while training plus certification costs $449, so adding the exam to the workshop is a small step up. If you already have qualifying equivalent training, certification-only at $199 is the leaner path. If you want a safety net on the first attempt, the super bundle includes one retake. For a fuller treatment, read the CPISI-D certification cost breakdown.
Sequencing Your Training Around the Exam Topics
You do not need a generic study template here, only a sensible order that follows how the topics build on each other. The exam is 50 questions in 60 minutes, so you have roughly a minute and a bit per question; fluency with terminology matters more than deriving answers from scratch. The passing score is 62%, which you can review in the CPISI-D passing score guide.
Foundations: Domains 1 and 4
- Learn the payment ecosystem and the PCI standards family first
- These give vocabulary that every later topic depends on
Design and standards: Domains 2 and 3
- Study Security By Design alongside the PA-DSS and S3 heading
- Reconcile the retired PA-DSS terminology with current PCI-SSF emphasis
Code-level risk: Domains 5 and 6
- Pair OWASP web and mobile categories with specific coding vulnerabilities
- Practice linking each flaw to its preventive control
Anticipation and review: Domain 7
- Finish with Threat Modelling, since it draws on everything above
- Take timed practice questions to build pacing for 60 minutes
Timed practice is where the format becomes real. Our CPISI-D practice tests let you rehearse the 50-question, 60-minute rhythm, and the CPISI-D study guide covers how to fold that practice into a broader plan.
Who Gets the Most From This Training
The Developer track is built for people who write and maintain payment-related code. That includes application developers, mobile developers, and engineers who review code or support payment applications in production. Security-minded team leads who need to evaluate their developers' work will also find the curriculum useful, though the credential is oriented toward hands-on implementation.
If your role is primarily assessment, governance, or infrastructure, the base CPISI or another track may fit better, since the Developer credential is deliberately separate. To weigh the career side, see CPISI-D jobs and the CPISI-D ROI analysis.
Frequently Asked Questions
SISA's CPISI-D workshop is 16 hours, delivered as a two-day live-online course. Equivalent formal training of at least 16 hours that covers the blueprint topics is also accepted as a verified alternative.
No. The workshop is a training course. The exam is a separate 50-question, 60-minute test with a 62% passing score. Workshop exercises do not create a scored practical examination.
Not necessarily. Verified alternatives include equivalent formal training of at least 16 hours covering the blueprint topics. SISA also displays a one-year experience route, but the qualifying areas are not spelled out publicly, so confirm with the issuer before relying on it.
SISA's store lists training only at $430 and training plus certification at $449. Certification only is $199, and a super bundle with one retake is $500. The store does not state a currency code, so confirm it at checkout.
The exam topic is still titled "PA-DSS and S3 Standards," but PCI Security Standards Council says PA-DSS retired on October 28, 2022. The current workshop emphasizes PCI-SSF and OWASP, so study the modern expectations while recognizing the legacy terminology.