CPISI-D logo
Focused certification exam prep
Start practice

What Is CPISI-D?

TL;DR
  • CPISI-D means Certified Payment Industry Security Implementer - Developer, issued by SISA and separate from CPISI and CPISI Advanced.
  • The Developer exam has 50 questions, a 60-minute limit, and a 62% passing score.
  • SISA publishes seven unweighted exam topics, from payment industry background through threat modelling.
  • The certification-only price is $199; training plus certification is $449 on SISA's store.

What the Credential Actually Is

CPISI-D stands for Certified Payment Industry Security Implementer - Developer. It is a developer-focused certification from SISA, built around the idea that the people who write payment application code are the ones who decide, line by line, whether cardholder data stays protected. Where many payment security credentials speak to auditors, assessors, and compliance managers, this one speaks to the engineer holding the keyboard.

If you have seen the acronym elsewhere, be careful. This article covers only the SISA Developer credential. For other angles on the name itself, see our explainers on what CPISI-D stands for and the broader CPISI-D certification overview.

Scope reminder: Everything below is drawn from SISA's own published pages. Where SISA does not publish a detail, this article says so rather than guessing. That matters in a niche where several similarly named credentials circulate.

Who Issues It and Where It Sits in the SISA Family

The credential is issued by SISA through its SISA Institute training and certification arm. SISA positions the Developer credential as a distinct certification, separate from the base CPISI and from CPISI Advanced. That separation is more than branding. The Developer exam has its own question count, its own time limit, and its own passing mark, so none of the base CPISI parameters can be assumed to carry over.

The practical consequence for candidates: do not borrow numbers from forum posts about other SISA exams. The Developer passing score is 62%, and the base CPISI mark is different. If you are comparing the two tracks, treat them as two separate exams that happen to share a family name.

Exam Format at a Glance

AttributeCPISI-D Detail
Full nameCertified Payment Industry Security Implementer - Developer
IssuerSISA (SISA Institute)
Number of questions50
Time allowed60 minutes
Passing score62%
Published topicsSeven headings, unweighted
Separate practical examNot established by public sources

Fifty questions in sixty minutes works out to a little over a minute per question. That pace rewards candidates who recognize concepts quickly rather than reasoning from scratch every time. At a 62% threshold, you need a bit over thirty correct answers out of fifty, so a handful of weak topics will not necessarily sink you, but a blind spot across a whole topic area can. For a deeper look at the arithmetic, read our guide to the CPISI-D passing score and our difficulty breakdown.

Training is not the exam: SISA offers a two-day live-online training course. That describes the length of the workshop, not the length of the examination, and workshop exercises do not constitute a separate timed or scored practical test. The exam itself is the 50-question, 60-minute assessment.

The Seven Exam Topics

SISA's current certification page lists seven exam topics. They are published as headings only: no percentage weights, no sub-objectives, and no version label. The page's "Exam Blueprint" label does not point to a retrievable file, so any claim about how many questions come from each topic would be invention. What follows is what each heading plausibly asks a developer to know, framed as study direction rather than a claimed blueprint. For a topic-by-topic walkthrough, see our CPISI-D exam domains guide.

Domain 1: Background of Payment Industry

Developers who do not understand how card payments move cannot judge where sensitive data lives. This topic is the context layer.

  • Learn the flow of a card transaction and the parties involved
  • Understand what makes cardholder data valuable to attackers
  • Know why payment software attracts a distinct regulatory regime

Domain 2: Security By Design

Security as an architectural property rather than a late-stage patch.

  • Build protections into requirements and design, not just testing
  • Think in terms of minimizing data exposure and attack surface
  • Recognize design decisions that make later compliance harder

Domain 3: PA-DSS and S3 Standards

The payment application security standards heading, preserved exactly as SISA words it. See the next section for the terminology caveat.

  • Understand what secure payment software standards aim to enforce
  • Be able to distinguish legacy terminology from current standards

Domain 4: Payment Card Industry Security Standards

The broader PCI landscape that governs how payment data is handled.

  • Know how the PCI standards relate to one another
  • Understand which obligations land on software developers
  • Connect secure development expectations to PCI-SSF

Domain 5: OWASP Web and Mobile Security

The application-layer threat knowledge most developers will use daily.

  • Study web and mobile risk categories and how they manifest in payment apps
  • Understand why mobile payment apps add their own exposure

Domain 6: Common Coding Vulnerabilities

The recurring mistakes that turn into breaches.

  • Recognize vulnerable code patterns, not just vulnerability names
  • Know the corresponding secure coding responses

Domain 7: Threat Modelling

A structured way of asking what can go wrong before it does.

  • Identify assets, entry points, and trust boundaries in a payment application
  • Connect identified threats to design-level mitigations

The PA-DSS Heading and Why It Still Appears

The third topic is titled PA-DSS and S3 Standards, and this is the one that confuses careful readers. The PCI Security Standards Council states that PA-DSS retired on October 28, 2022. Yet SISA's exam topic list still carries the heading in that form.

Both facts can be true at once. SISA's current workshop curriculum emphasizes PCI-SSF (the Software Security Framework family) and OWASP, which reflects where the industry has moved. But the exam heading is the issuer's wording, and a legacy label on an exam topic does not authorize anyone to rename it. Treat the heading as published, and when you study, learn both the retired standard's role and the current framework that supersedes it.

Key Takeaway

Do not skip the third topic because PA-DSS is retired. Study it as the historical foundation and pair it with PCI-SSF, so you can answer questions framed in either the legacy or current vocabulary.

Preparation Subjects Beyond the Topic List

Separately from the exam topics, SISA's published workshop coverage names several preparation subjects: cryptography and key management, hashing and tokenization, application authorization and access control, audit logging, OWASP web and mobile security, and secure deployment and production support. These are valuable for any developer working on payment code, and they overlap naturally with several exam topics.

One caution: these preparation subjects do not add official exam domains, do not establish weights, and do not prove that the exam covers each of them exhaustively. Use them to deepen your practical grounding, but organize your study around the seven published topics. Our CPISI-D study guide shows one way to combine the two.

Eligibility Routes

SISA presents more than one way to qualify to sit the exam:

  1. SISA's 16-hour CPISI-D workshop. The straightforward route, delivered as the two-day live-online course.
  2. Equivalent formal training. Training of at least 16 hours that covers the blueprint topics.
  3. Experience. SISA displays a route based on a minimum of one year of verifiable full-time experience.
Read the experience route carefully: The issuer's page refers to qualifying areas for that experience but omits them. Do not assume that any developer role counts, and do not reconstruct the requirement from the recommended job roles listed elsewhere. If you plan to qualify through experience, ask SISA directly before paying. More detail on prerequisites is in our CPISI-D requirements guide.

Pricing and Purchase Options

SISA's training and certification store lists four options:

OptionListed Price
Certification only (includes application)$199
Training plus certification$449
Training only$430
Super bundle (includes one retake)$500

Two details are easy to miss. First, additional convenience charges are nonrefundable. Second, the store uses dollar notation without an explicit currency code, so confirm the checkout currency before assuming these are US dollars. Note too how the numbers interact: training-plus-certification costs only $19 more than training alone, which makes the bundle the natural pick for anyone who needs the workshop anyway. The super bundle's value is the included retake, which matters most if you expect the 50-question pace to be a challenge. For a full cost analysis, see our CPISI-D certification cost breakdown.

Who Benefits From This Credential

The Developer designation is aimed at people who build and maintain software that touches payment data. Typical fits include:

  • Application developers working on payment gateways, checkout flows, or card-handling services
  • Mobile developers shipping wallet or in-app payment features
  • Engineers responsible for secure deployment and production support of payment systems
  • Technical leads who review code and architecture for security and PCI alignment

Employers that hire for these roles include payment processors, fintech companies, banks with in-house development teams, and consultancies serving regulated clients. SISA lists recommended job roles on its pages, but the exact list should be checked there rather than assumed. If you are weighing the career value, our ROI analysis and CPISI-D jobs article explore that question, and no specific salary figures are claimed here.

Sequencing Your Preparation Around the Topics

Because the seven topics build on each other, order matters more than intensity. One sensible arrangement:

Week 1

Context and Design

  • Background of Payment Industry, to anchor every later concept
  • Security By Design, so later vulnerabilities read as design failures
Week 2

Standards

  • PA-DSS and S3 Standards, including the retirement caveat
  • Payment Card Industry Security Standards, linking PCI-SSF to developer duties
Week 3

Attack Surface and Code

  • OWASP Web and Mobile Security
  • Common Coding Vulnerabilities, paired with the secure alternatives
Week 4

Threat Modelling and Timed Practice

  • Threat Modelling as a synthesis of everything prior
  • Timed sets of 50 questions in 60 minutes to rehearse the pace

The logic: standards and design vocabulary come before vulnerabilities so you understand why a control exists, and threat modelling comes last because it asks you to combine every earlier topic. Finish with full-length timed practice using the CPISI-D practice tests so the 62% threshold feels familiar before exam day, and keep our cheat sheet handy for last-minute review.

What Is Not Publicly Verified

Honest preparation includes knowing what you cannot know. As of SISA's current pages:

  • Topic weights are not published, so you cannot prioritize by percentage.
  • A detailed blueprint beyond the seven headings is not retrievable.
  • Renewal intervals and CPE requirements for the Developer credential remain unverified, and the base CPISI renewal rules should not be applied to it.
  • Pass rates are not published by the issuer, so any figure you encounter should be treated skeptically. See what the data actually shows.
  • Exam dates and scheduling specifics should be confirmed with SISA directly; our exam dates guide explains what to check.

Because the topic list is also undated and unversioned, check SISA's certification page again shortly before you register, in case the wording has changed.

Frequently Asked Questions

What does CPISI-D stand for?

It stands for Certified Payment Industry Security Implementer - Developer, a certification from SISA focused on secure development of payment applications. It is distinct from the base CPISI and CPISI Advanced credentials.

How many questions are on the exam and what score do I need?

The Developer exam has 50 questions with a 60-minute time limit, and the passing score is 62%. Do not substitute the base CPISI pass mark, which is different.

Why does an exam topic still mention PA-DSS if it was retired?

PCI SSC retired PA-DSS on October 28, 2022, but SISA's published exam heading still reads "PA-DSS and S3 Standards." The heading is preserved as issued, while SISA's workshop emphasizes PCI-SSF and OWASP. Study both the legacy standard and its current successor.

How much does the certification cost?

SISA's store lists $199 for certification only, $449 for training plus certification, $430 for training only, and $500 for a super bundle including one retake. Convenience charges are nonrefundable, and you should confirm the checkout currency since no code is displayed.

Can I qualify without taking the SISA workshop?

Equivalent formal training of at least 16 hours covering the blueprint topics is listed as an alternative. An experience route of at least one year of verifiable full-time experience is also displayed, but its qualifying areas are not specified, so confirm with SISA before relying on it.

Ready to pass your CPISI-D exam?

Put this into practice with free CPISI-D questions across every exam domain.