Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about ISACA's technical privacy certification as of 2026, covering the four domains, the 120-question exam, the experience requirement, career paths, and how CDPSE compares to the IAPP privacy credentials. A complete reference guide for anyone weighing the CDPSE or trying to understand what it covers.
Privacy principles, laws, documentation, and operations. 20% of the exam.
Risk process, PIAs, frameworks, and program metrics. 18%.
Collection, classification, retention, and destruction. 23%.
Technology stacks, controls, PETs, and AI considerations. The heaviest domain at 39%.
CDPSE is ISACA's technical data privacy certification, launched in May 2020 and now held by more than 16,000 professionals worldwide.
It validates the skills to assess, build, and implement privacy solutions: embedding privacy by design into systems, networks, and applications rather than treating privacy as a purely legal exercise. Where most privacy credentials test knowledge of the law, CDPSE tests whether you can turn those requirements into working controls, data flows, and architecture.
The credential is experience-verified: passing the exam is only step one, and ISACA grants the certification after you document three or more years of relevant work. CDPSE is issued and maintained by ISACA, the association behind CISA, CISM, and CRISC.
Four things that set CDPSE apart as privacy shifts from a legal checkbox to an engineering discipline in 2026.
ISACA built CDPSE for the people who actually implement privacy: the engineers, architects, and developers who partner with legal teams to make privacy by design real in production systems. Because certification requires verified work experience, holding a CDPSE signals you have done the work, not just passed a test.
Privacy Engineering alone carries 39 percent of the exam, covering PETs, anonymization, consent tagging, and AI considerations. Our CIPT vs CDPSE comparison breaks down how that focus differs from the IAPP approach.
As of 2026, privacy engineers in the US commonly earn in the $125,000 to $160,000 range, with senior roles climbing higher. Our honest take on whether CDPSE is worth it runs the full ROI math.
CDPSE does not appear on the DoD 8140 Approved Qualifications Matrix V2.1, so it is not a qualification path for DoD cyber workforce roles. If you need an ISACA credential on the Matrix, that is CISM or CISA territory.
CDPSE's recognition instead comes from privacy regulation itself: GDPR Article 25 makes privacy by design and by default a legal obligation, US state privacy laws keep multiplying, and frameworks like the NIST Privacy Framework and ISO/IEC 27701 give organizations structures that CDPSE holders are trained to implement.
Everything you need to know about the certification, the exam structure, and how to maintain CDPSE as of 2026.
CDPSE holders usually broaden in one of three directions: security leadership, cloud depth, or the fast-growing AI governance space. Each of these builds naturally on a privacy engineering foundation, though CISM and CCSP carry five-year experience requirements of their own.
ISACA's Certified Information Security Manager moves you from implementing privacy controls to running the security program they live in. It requires five years of security management experience, and your CDPSE CPE activity can count toward both.
ISC2's Certified Cloud Security Professional goes deep on the environments where most personal data now lives. It pairs well with CDPSE for architects securing cloud-native data platforms, with a five-year IT experience requirement including three in security.
The IAPP's Artificial Intelligence Governance Professional extends privacy expertise into AI oversight: the EU AI Act, NIST AI RMF, and responsible deployment. With AI and ML considerations already inside the CDPSE Privacy Engineering domain, it is a natural next step.
CDPSE sits at the intersection of security and privacy. It builds on a security or privacy foundation and opens paths into privacy leadership, governance and audit, or the emerging AI governance specialty.
Build the baseline
The pivot point
Two questions to answer before you commit: can you certify, and should you pursue CDPSE specifically. Here's a straight answer to both.
You can certify in full.
You have three or more years of experience performing the work covered by the CDPSE domains, from privacy governance and risk assessment to data life cycle management and privacy engineering. Pass the exam, submit your experience application with the $50 fee, and you hold the full CDPSE.
You can still pass now.
There is no prerequisite to sit the exam itself. Register any time, pass, and you then have five years from your exam date to earn the required experience and submit your certification application, so the exam never has to wait on your resume.
CDPSE maps to the roles where privacy requirements become working systems. Demand for these positions keeps growing as regulators shift enforcement from paperwork to implementation.
Builds privacy controls directly into products and systems: data minimization in pipelines, consent handling in applications, anonymization in analytics. The role the 39 percent Privacy Engineering domain was written for.
Designs the data architecture that makes privacy by design real: where personal data lives, how it flows, and which technical controls protect it at each stage of the life cycle.
Owns privacy compliance with enough technical depth to verify that controls actually exist in production, not just in policy documents. CDPSE pairs naturally with a legal privacy credential here.
Extends an existing security engineering role into privacy: encryption, access management, logging, and monitoring applied specifically to personal data and regulatory obligations.
Runs privacy impact assessments, maps data flows, monitors program metrics, and translates regulatory requirements into control requirements the engineering teams can implement.
Helps organizations stand up or mature privacy programs, from GDPR and state law readiness to implementing privacy enhancing technologies. The experience-verified CDPSE signals hands-on credibility to clients.
All three are respected privacy credentials, but they aim at different work. Here's how they line up.
| CDPSE | CIPT | CIPM | |
|---|---|---|---|
| Issuer | ISACA | IAPP | IAPP |
| Focus | Implementing privacy in systems | Privacy concepts for technologists | Managing a privacy program |
| Experience | 3 yrs to certify (exam first allowed) | None required | None required |
| Exam Format | 120 questions, 3.5 hours | 90 questions, 2.5 hours | 90 questions, 2.5 hours |
| Passing Score | 450 on a 200 to 800 scale | 300 on a 100 to 500 scale | 300 on a 100 to 500 scale |
| Renewal | 20 CPEs yearly, 120 per 3-yr cycle | 20 CPEs per 2-yr term | 20 CPEs per 2-yr term |
| DoD 8140 Approved | No | No | No |
| Best For | Engineers who build privacy in | Technologists learning privacy | Privacy program managers |
Pricing and renewal details vary by membership status and can change. Many privacy professionals eventually pair CDPSE with an IAPP credential to cover both the build side and the law side.
Our official ISACA CDPSE boot camp covers all four domains over three days, with your exam voucher and a first-attempt pass guarantee included, so experienced practitioners leave exam-ready.
Certification strategy, privacy career paths, and how CDPSE fits the broader ISACA portfolio.
A straight look at when the CDPSE pays off: the salary math for privacy engineers, the total cost of earning it, and why it fits technologists but not pure policy roles.
The two leading technical privacy credentials aim at different professionals. Here is how they differ in approach, depth, and who each one actually serves.
Where CDPSE sits in the full ISACA portfolio alongside CISA, CISM, CRISC, and CGEIT, and how the credentials build on one another across a governance career.
How privacy fits into a governance, risk, and compliance career, and why layering CDPSE on top of a CISA or CRISC foundation signals readiness for emerging regulatory work.
AI governance is the next frontier for privacy professionals. What to consider before adding an AI credential on top of your privacy foundation.
The same ROI math applied to ISACA's risk credential, useful context for anyone deciding which ISACA certification to pursue first or next.
The audit credential versus the management credential. How the two flagship ISACA certifications differ and which one fits your current role.
The CDPSE job practice is organized into four domains, each carrying its own weight on the exam. Click any domain for what it covers.
Personal information, privacy principles such as privacy by design, consent, and transparency, privacy laws and regulations, and privacy documentation. Also covers privacy operations: organizational structure and responsibilities, vendor and supply chain management, incident management, and data subject rights and requests.
The risk management process and policies, privacy-focused assessments such as Privacy Impact Assessments (PIAs), privacy training and awareness, threats and vulnerabilities, and risk response. The compliance side covers privacy frameworks, evidence and artifacts, and program monitoring and metrics.
Data collection and processing: inventory, dataflow diagrams, classification, data quality, use limitation, and data analytics including aggregation and AI. Data persistence and destruction: minimization, disclosure and transfer, storage, retention, archiving, and destruction.
The heaviest domain by a wide margin. Technology stacks from infrastructure and cloud to devices, APIs, and the secure development life cycle. Privacy-related security controls including IAM, encryption, and logging. Privacy controls: consent tagging, tracking technologies, anonymization and pseudonymization, privacy enhancing technologies (PETs), and AI and machine learning considerations.
Domains and weights reflect the ISACA CDPSE Exam Content Outline currently in effect, the four-domain job practice that replaced the original three-domain structure. ISACA updates the job practice on a regular cycle.
The questions candidates ask most often when researching the Certified Data Privacy Solutions Engineer certification.
CDPSE is ISACA's Certified Data Privacy Solutions Engineer certification, launched in May 2020. It validates the technical skills to assess, build, and implement privacy solutions, embedding privacy by design into systems, networks, and applications rather than treating privacy as a purely legal exercise.
CDPSE fits technologists who build or secure systems that handle personal data: security engineers, solution architects, software developers, and IT or GRC professionals implementing the technical side of privacy. It's a weaker fit for people whose privacy work is purely legal or policy oriented.
The CDPSE exam costs $575 for ISACA members and $760 for non-members, plus a $50 application processing fee once you pass and apply for certification. ISACA membership runs about $135, so joining before you register usually saves money outright.
The CDPSE exam is 120 multiple-choice questions delivered over 3.5 hours, computer-based at authorized PSI testing centers or as a remotely proctored exam. Scores are reported on a scale from 200 to 800, and you need a scaled score of 450 to pass.
ISACA requires three or more years of experience performing the work described in the CDPSE exam content outline domains, spanning areas like privacy governance, risk management, data life cycle work, and privacy engineering. The experience is verified through an application after you pass the exam.
Yes. You can register and sit the exam at any time, then earn the required experience afterward. ISACA gives you five years from the date you pass the exam to submit your certification application, so the exam never has to wait on your resume.
The four CDPSE domains are Privacy Governance at 20 percent, Privacy Risk Management and Compliance at 18 percent, Data Life Cycle Management at 23 percent, and Privacy Engineering at 39 percent. Privacy Engineering carries by far the heaviest weight on the exam.
Yes. ISACA restructured the CDPSE job practice from the original three domains (Privacy Governance, Privacy Architecture, Data Lifecycle) into four: Privacy Governance, Privacy Risk Management and Compliance, Data Life Cycle Management, and Privacy Engineering. Much of the older content online still describes the three-domain version, so verify any prep material against the current ISACA exam content outline.
CDPSE holders earn a minimum of 20 Continuing Professional Education (CPE) hours annually and 120 CPE hours over each three-year reporting cycle, pay an annual maintenance fee to ISACA, and adhere to the ISACA Code of Professional Ethics. CPE activities can count toward multiple ISACA certifications at once.
No. CDPSE does not appear on the DoD 8140 Approved Qualifications Matrix V2.1. If you need an ISACA credential for DoD 8140 qualification, CISM and CISA are the ones that appear on the Matrix. See the full DoD 8140 work role paths. CDPSE's recognition instead rests on privacy regulation: GDPR Article 25, the growing body of US state privacy laws, and frameworks like the NIST Privacy Framework.
CDPSE from ISACA is the experience-verified credential for engineers who implement privacy in systems. CIPT from the IAPP teaches privacy professionals how technology supports privacy, and CIPM from the IAPP covers managing a privacy program. Many privacy leaders eventually pair a technical credential like CDPSE with an IAPP credential covering law or program management.
Most candidates spend one to three months preparing, depending on how much of the four domains their day-to-day work already covers. Practitioners with strong privacy engineering experience can compress the instruction into a focused boot camp week plus review.
For technologists who build or secure systems handling personal data, yes. Demand for privacy engineering keeps growing as GDPR enforcement matures and US state privacy laws multiply, privacy engineer pay commonly runs from about $125,000 to $160,000, and the all-in certification cost lands under roughly $1,000 before training. It's less useful for purely legal or policy privacy roles.
Whether you're weighing the certification, working out funding, or planning training for a team, tell us where you are and we'll help you map out the right path.