- What the Credential Actually Is
- Who Issues It and How It Differs From CPISI
- Exam Format: 50 Questions, 60 Minutes, 62%
- The Seven Published Exam Topics
- The PA-DSS Heading in a Post-PA-DSS World
- What the Workshop Teaches
- Eligibility Routes
- Fees and Bundles
- Who Should Pursue It
- Sequencing Your Preparation
- Frequently Asked Questions
- CPISI-D is SISA's Certified Payment Industry Security Implementer - Developer credential, separate from CPISI and CPISI Advanced.
- The Developer exam has 50 questions, 60 minutes, and a 62% passing score, not the base CPISI's 66%.
- SISA publishes seven exam topics without percentage weights, so do not assume any domain counts more than another.
- Eligibility includes a 16-hour workshop or equivalent training; the one-year experience route needs issuer clarification.
What the Credential Actually Is
CPISI-D stands for Certified Payment Industry Security Implementer - Developer. It is a role-focused certification aimed at the people who actually write and ship software that touches payment data: application developers, secure-coding practitioners, and engineers responsible for building security into payment applications from the first design decision.
Because several credentials in the security world share similar-looking acronyms, precision matters here. This article covers only the SISA credential named above. If you have seen CPISI-D mentioned elsewhere with different fees, dates, or pass rates, those details belong to something else and should not be used to plan your preparation. For the short-form definitions, you can also read What Is CPISI-D? and What Does CPISI-D Stand For?.
The credential's emphasis is practical secure development in a payments context. That means understanding how the payment industry works, how security is designed into applications rather than bolted on, how card-industry standards apply to software, and how common coding flaws and threat modelling shape real engineering decisions.
Who Issues It and How It Differs From CPISI
The credential is issued by SISA (through SISA Institute). It sits alongside two related certifications: CPISI and CPISI Advanced. The Developer track is its own certification with its own exam parameters, so you should not carry assumptions from one to another.
| Item | CPISI-D (Developer) |
|---|---|
| Issuer | SISA / SISA Institute |
| Exam length | 50 questions |
| Time allowed | 60 minutes |
| Passing score | 62% |
| Published topics | Seven, unweighted |
| Relationship to CPISI | Separate certification; do not substitute base CPISI rules |
Exam Format: 50 Questions, 60 Minutes, 62%
The examination consists of 50 questions to be completed in 60 minutes, with a passing score of 62%. Simple arithmetic shows you have a little over a minute per question, which rewards candidates who recognize concepts quickly rather than reasoning from scratch each time. Questions come from the seven published topic areas, so breadth of familiarity matters as much as depth in any single subject.
Two clarifications prevent common misunderstandings:
- The two-day live-online offering is a training course. It is not the length of the exam, and it is not evidence of how the exam is delivered.
- Training exercises and workshop hours do not establish a separate timed or scored practical examination. The credential's published assessment is the 50-question, 60-minute exam.
For a realistic sense of how demanding this format is, see How Hard Is the CPISI-D Exam?. For exam-day logistics, CPISI-D Exam Dates is the place to look.
The Seven Published Exam Topics
SISA's current certification page lists seven exam-topic headings. They are unweighted and the public list is unversioned, which means you should not assume any topic carries more questions than another. The displayed blueprint label does not link to a retrievable file, so there is no further official breakdown to lean on. Treat all seven as fair game and prepare evenly. A deeper walkthrough lives in the CPISI-D exam domains guide.
Domain 1: Background of Payment Industry
Context for everything else. Developers who understand how card transactions flow and who the participants are make better security decisions.
- Know the players and data flows in a payment ecosystem
- Understand why cardholder data attracts attackers
- Be able to explain where application code fits in the chain
Domain 2: Security By Design
The principle that protection is built into architecture and code from the start.
- Apply secure design thinking before implementation begins
- Recognize design-level choices that reduce attack surface
- Connect design decisions to later testing and deployment
Domain 3: PA-DSS and S3 Standards
The exam heading for payment-application and secure-software standards. See the next section for an important terminology note.
- Know the intent behind payment-application security standards
- Understand how this heading relates to current secure-software standards
Domain 4: Payment Card Industry Security Standards
The broader standards landscape that governs how payment data must be protected.
- Understand how card-industry standards bear on application development
- Relate requirements to concrete engineering practices
Domain 5: OWASP Web and Mobile Security
Community-driven guidance on the most common web and mobile application risks.
- Recognize major web and mobile risk categories
- Map risks to practical mitigations in code and configuration
Domain 6: Common Coding Vulnerabilities
The flaws that repeatedly show up in real applications and how developers prevent them.
- Identify typical insecure coding patterns
- Know the defensive coding technique that addresses each
Domain 7: Threat Modelling
A structured way to anticipate how a system could be attacked before it is attacked.
- Identify assets, entry points, and trust boundaries
- Use threat thinking to prioritize design and testing effort
The PA-DSS Heading in a Post-PA-DSS World
This is the detail that trips up careful candidates. The exam topic is titled PA-DSS and S3 Standards, and that is the heading SISA publishes, so that is the name to use when you map your preparation. At the same time, the PCI Security Standards Council states that PA-DSS retired on October 28, 2022. SISA's current workshop curriculum emphasizes PCI-SSF and OWASP.
Practically, this means you should be able to explain what the legacy payment-application standard was for, understand that it has been superseded in the PCI SSC's program, and be comfortable discussing the secure-software standards that now carry that intent. When wording on a practice question looks dated, read for the concept being tested.
What the Workshop Teaches
SISA's published training material for the Developer track covers a set of preparation subjects. These are useful for building real skill, but they are not additional exam domains and they do not establish weights or prove exhaustive exam coverage. Think of them as the hands-on territory behind the seven headings.
- Cryptography and key management
- Hashing and tokenization
- Application authorization and access control
- Audit logging
- OWASP web and mobile security
- Secure deployment and production support
If you are a working developer, much of this will feel familiar, but payment contexts raise the stakes. Key management mistakes, weak authorization checks, and missing audit trails are exactly the kinds of defects that turn into reportable incidents. Study them as a developer who has to answer for the code, not as a spectator. More on the training itself is available at CPISI-D Training.
Key Takeaway
Use the workshop subjects to build depth, but organize your revision around the seven official exam topics. That way you never mistake a useful skill area for a tested domain, or miss a tested domain because it was not emphasized in training.
Eligibility Routes
The verified alternatives are straightforward on the training side. You can qualify through SISA's 16-hour CPISI-D workshop, or through equivalent formal training of at least 16 hours that covers the blueprint topics. The training should map to the same seven areas, so keep your syllabus or certificate of attendance handy.
The issuer also displays a route based on a minimum of one year of verifiable full-time experience. However, the page refers to qualifying areas without actually listing them, so you should not assume that any developer role qualifies, and you should not reconstruct the criteria from the separately listed recommended job roles. If you plan to use the experience route, contact SISA and get the qualifying areas confirmed in writing before you apply.
Fees and Bundles
SISA's official store lists four purchase options. Prices appear in dollar notation without an explicit currency code, so confirm the currency at checkout before treating any figure as US dollars.
| Option | Listed Price | What It Covers |
|---|---|---|
| Certification only | $199 | Certification including application |
| Training plus certification | $449 | Workshop and certification |
| Training only | $430 | Workshop without the certification |
| Super bundle | $500 | Includes one retake |
Note that additional convenience charges are nonrefundable. If you already hold qualifying training, the certification-only option is the leanest path; if you need the workshop, the combined offer costs only a little more than training alone, which is worth weighing. If you want to think about the broader financial picture, see CPISI-D Certification Cost and Is the CPISI-D Certification Worth It?.
One caution on renewal: the exact renewal interval and continuing-education requirements for the Developer credential remain unverified. Do not borrow the base CPISI renewal rules. Confirm directly with SISA, and review the issuer's certification policy before you budget for long-term maintenance.
Who Should Pursue It
The credential is built for people whose daily work shapes how payment applications are built and maintained. Typical candidates include application developers, secure-coding specialists, software engineers on payment platforms, and technical leads who review code or design for security. Employers in fintech, payment processing, banking technology, and software vendors serving merchants are the natural audience for the signal this certification sends.
It is less obviously suited to someone who never touches code or architecture. If your work is audit, policy, or governance, a different credential in the CPISI family may be a better fit; the developer track assumes you care about implementation detail. For a look at the roles and employers in this space, see CPISI-D Jobs, and for compensation context without invented numbers, the CPISI-D salary guide.
Sequencing Your Preparation
Because the seven topics are unweighted, a sensible approach is to move from context to technique to synthesis. This sequence is tied to how the topics build on each other rather than to generic study habits.
Context and Design
- Background of Payment Industry
- Security By Design
Standards
- PA-DSS and S3 Standards, noting the retirement caveat
- Payment Card Industry Security Standards
Code-Level Risk
- OWASP Web and Mobile Security
- Common Coding Vulnerabilities
Synthesis and Timing
- Threat Modelling
- Timed sets of 50 questions in 60 minutes via the practice tests
Threat modelling comes last because it draws on everything before it: you need to know the payment context, the standards, and the common flaws to model threats well. Finish with timed runs so the 60-minute limit feels routine rather than rushed. For a fuller plan, read the CPISI-D study guide, keep the CPISI-D cheat sheet handy for last-minute review, and check what is known about pass rates before drawing conclusions from anecdotes. You can also sharpen recall with the question banks at cpisidexam.com.
Frequently Asked Questions
It stands for Certified Payment Industry Security Implementer - Developer. It is issued by SISA and is separate from the CPISI and CPISI Advanced certifications.
The Developer exam has 50 questions to be completed in 60 minutes, with a passing score of 62%. Do not confuse this with the base CPISI pass mark of 66%.
SISA publishes seven topic headings without percentage weights, and the blueprint label does not link to a retrievable file. Treat all seven topics as important and prepare evenly.
The official exam heading is still "PA-DSS and S3 Standards," so keep that name in your notes. PCI SSC retired PA-DSS on October 28, 2022, and the workshop emphasizes PCI-SSF and OWASP, so study the concepts through current secure-software standards.
Not necessarily. Eligibility includes SISA's 16-hour workshop or equivalent formal training of at least 16 hours covering the blueprint topics. An experience route of at least one year is also displayed, but its qualifying areas are not specified, so ask SISA to clarify before relying on it.