Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Certification Guide

The Certified Information Privacy Manager (CIPM)
Certification Explained.

Everything you need to know about the IAPP's privacy program management certification as of 2026, covering the six BoK v4.2.0 domains, the 90-question exam, costs, maintenance, career paths, and how the CIPM compares to the CIPP/US, ISACA's CDPSE and the AIGP. A complete reference for anyone weighing the CIPM or trying to understand what it covers.

CIPM_FAST_FACTS
Issuer: IAPP
Exam: 90 questions, 2.5 hrs
Passing Score: 300 / 500
Prerequisites: None
DoD 8140: Not a matrix credential
6 BoK v4.2.0 Domains 90 Exam Questions 2.5 HRS Exam Time NO Prerequisites ANAB Accredited
UPDATED 2026
Overview

What Is the Certified Information Privacy Manager (CIPM)?

CIPM is the IAPP's privacy program management certification, the credential for people who establish, maintain and manage a privacy program across all stages of its life cycle.

The IAPP describes it as the first and only privacy certification for professionals who manage day-to-day operations, and sums it up in two words: operationalizing privacy. The CIPP credentials test whether you know the law. This one tests whether you can build the governance model, run the assessments, protect the data, measure the program and respond when a request or an incident lands, the way a privacy program manager or data protection officer has to.

The credential is ANAB accredited under ISO/IEC 17024:2012, carries no experience or education prerequisite, and is one of the credentials that count toward the IAPP's Fellow of Information Privacy designation. CIPM is issued and maintained by the IAPP, the same body behind the CIPP, CIPT and AIGP credentials.

6 Domains
0 Prerequisites
2 Yr Certification Term
The CIPM Domains

Six Domains of the BoK v4.2.0

I

Developing a Framework

Program scope, strategy, governance model, and the laws in scope. The heaviest domain at 14 to 18 scored questions.

II

Establishing Program Governance

Policies, roles and responsibilities, oversight metrics, and training.

III

Assessing Data

Data inventories and flows, vendor and control evaluation, M&A data risk.

IV

Protecting Personal Data

Classification, security controls, Privacy by Design, and data use guidelines.

V

Sustaining Program Performance

Metrics, program audits, and continuous assessment (PIA, DPIA, TIA, LIA, PTA).

VI

Responding to Requests and Incidents

Data subject rights, incident handling, and post-incident review.

Why CIPM Matters

Why Do Privacy Teams Hire for the CIPM?

Four things that set the credential apart as organizations move from writing privacy policies to running privacy programs.

The Privacy Credential Built Around Running the Program

The IAPP positions the CIPM as the first and only privacy certification for professionals who manage day-to-day operations. The CIPP credentials test law and the CIPT and CDPSE test technology. This one tests the operational framework that connects them: governance, assessment, protection, measurement and response, across the full life cycle of a program.

No Prerequisite Barrier

ISACA's CDPSE asks for three years of verified experience before it grants the credential. The CIPM has no experience or education prerequisite. You agree to the IAPP's certification policies, buy the exam, and you have a year to sit it.

Half of the Fellow Requirement

The IAPP's Fellow of Information Privacy needs a CIPP plus a CIPM, CIPT or AIGP, and three years of work where privacy is at least half the job. For program managers the CIPM is the natural second credential. Our CPE comparison covers what holding several IAPP credentials costs to maintain.

Where CIPM Recognition Comes From

The CIPM is not a DoD 8140 matrix credential, so it will not satisfy a cyber-coded position requirement on its own. If you need an 8140 qualification, check the current Approved Qualifications Matrix at public.cyber.mil before you commit.

Its weight comes from two other places: ANAB accreditation under ISO/IEC 17024:2012, the international standard for personnel certification bodies, and the privacy laws in the EU, US states and elsewhere that now expect organizations to operate documented programs with named people accountable for them.

ANAB Accredited ISO/IEC 17024 Standard FIP Eligible
Fast Facts

What Are the Key Facts About CIPM?

Everything you need to know about the certification, the exam structure, and how to maintain the CIPM as of 2026.

01

The Certification

Certification Name
Certified Information Privacy Manager (CIPM)
Issued By
IAPP
Exam Blueprint
BoK v4.2.0, effective September 1, 2025
Domains
6, weighted as scored-question ranges
Prerequisites
None (no experience or education requirement)
Recommended Background
Privacy, compliance, legal, risk, or security
Credential Type
Vendor-neutral, privacy program management
Accreditation
ANAB, ISO/IEC 17024:2012
DoD 8140 Status
Not a DoD 8140 matrix credential
02

Exam & Maintenance

Exam Format
Multiple choice, some scenario-based
Number of Items
90 (75 scored + 15 unscored)
Item Types
One or more correct answers per question
Exam Duration
2.5 hrs, with a 15-min break
Passing Score
300 on a 100 to 500 scale
Exam Cost
$550 (members and non-members)
Delivery
Pearson VUE test center or online via OnVUE
Term
2 years
Maintenance
20 CPE hours per term, $250 fee (covered by membership)
Going Deeper

What Comes After the CIPM?

The CIPM covers how to run the program. The IAPP's other credentials each add a different dimension, and holding the right pair, plus the experience, qualifies you for the Fellow of Information Privacy designation.

CIPP/US (Practicing Privacy)

The IAPP's US privacy law credential: the federal and state laws, government and court access, and workplace privacy your program has to comply with. Same exam format as the CIPM, and the CIPP half of the FIP requirement. A CIPP/E covers the same ground for European law.

CIPT or AIGP (Engineering Privacy, Governing AI)

The CIPT covers how technology delivers privacy, useful for managers who work closely with engineering teams. The AIGP covers responsible AI governance, and Domain I of the CIPM already asks you to understand the privacy risks of AI in the business. Either one, like the CIPM, satisfies the second half of the FIP requirement.

Fellow of Information Privacy (FIP)

The IAPP's senior designation. It requires a CIPP plus a CIPM, CIPT or AIGP, and three years of work experience in which privacy is at least half the job. For someone who runs a program, CIPM plus a CIPP is the shortest route.

Certification Roadmap

Where Does CIPM Fit in Your Career?

With no prerequisites, the CIPM can be a first credential. In practice most candidates arrive from legal, compliance, audit or security work, earn the CIPM once they are handed a program to run, and then add a law credential or a specialty.

STAGE 01

Foundation

Common starting points, none required

CIPP/US
IAPP ยท US privacy law
CIPT
IAPP ยท Privacy in technology
Legal, Audit or Security Role
Work experience near a privacy program
STAGE 02 You Are Here

Core Credential

The privacy program management anchor

PRIMARY
CIPM
IAPP ยท Certified Information Privacy Manager
Open Entry
No experience or education prerequisite
STAGE 03

Specialize

Pick your path

Privacy Law
AI Governance
Privacy Engineering
Decision Point

Is CIPM Right For You?

Two things to settle before you commit: can you certify, and should you pursue the CIPM specifically. Here's a straight answer to both.

Q1

Do You Qualify for CIPM?

Short Answer

Yes. Anyone Can Sit the Exam.

No experience or education prerequisite.

The IAPP states no experience or education requirement for the CIPM. You agree to its certification policies, purchase the exam, and you have one year to schedule and sit it at a Pearson VUE test center or online through OnVUE. Membership is not required to take the exam, though keeping the credential active later needs either a membership or the Certification Maintenance Fee.

Honest Caveat

Background Still Matters

Open entry doesn't mean easy entry.

Some questions are scenario-based and some have more than one correct answer, and the scenarios assume you can reason like someone who has sat in on a breach response or a vendor review. Candidates with no exposure to how a privacy program actually operates can still pass, but they should expect to spend more prep time on the operational context the questions take for granted, and to plan around the seven-day wait before any retake.

Q2

Is CIPM the Right Certification for Your Goals?

CIPM Is a Strong Fit If...

  • You have been handed a privacy program to run, or you are building one from scratch
  • You are the data protection officer or the named privacy contact, and regulators and data subjects come to you
  • You need to turn privacy law into policies, data inventories, assessments and metrics that hold up in an audit
  • You already hold a CIPP and want the second credential toward the Fellow of Information Privacy
  • You want a privacy credential without an experience prerequisite standing in the way
  • You manage vendors, incident response or data subject requests and want the shared vocabulary the privacy profession uses for that work

Consider Alternatives If...

  • Your work is interpreting privacy law rather than operating a program, where the CIPP/US or CIPP/E sits closer to the job
  • You design and build the technical controls, where the CIPT or ISACA's CDPSE is the better match
  • Your organization's pressing gap is AI oversight rather than privacy operations, where the AIGP is built for exactly that
  • You need a DoD 8140 approved qualification, since the CIPM isn't a matrix credential and won't satisfy a cyber-coded position
  • You want a security management credential, since the CIPM never covers security operations beyond the controls that protect personal data
  • You have no exposure to privacy at all and want a gentler on-ramp, where a law credential like the CIPP/US builds the base first
Career Paths

What Jobs Can You Get With CIPM?

The CIPM maps to the roles that own a privacy program rather than advise on it, the positions organizations create as privacy laws require named, accountable people and documented operations.

Program Leadership

Privacy Program Manager

Owns the privacy program day to day: the governance model, the policies and procedures, the assessment calendar, and the metrics that show leadership whether the program is working.

Compliance

Data Protection Officer

The accountable contact for regulators and data subjects where the law requires one, monitoring compliance, advising on impact assessments, and keeping the incident register and the breach response plan current.

Executive

Chief Privacy Officer

Sets privacy strategy at the organizational level, decides the governance model, secures budget and stakeholders, and reports program performance to the board and the executive team.

Compliance

Privacy Compliance Manager

Tracks the laws and regulations in scope across jurisdictions, translates them into internal policy and controls, and runs the audits and gap analyses that prove the program meets them.

Advisory

Privacy Consultant

Builds or assesses privacy programs for client organizations, from data inventories and vendor evaluations to Privacy by Design reviews and post-incident plan revisions.

Risk and Governance

GRC Manager

Brings privacy into the broader governance, risk and compliance function, aligning privacy risk assessments, third-party risk and control monitoring with the rest of the enterprise risk program.

Comparison

How Does CIPM Compare to CIPP/US, CDPSE and AIGP?

Shortest version: CIPM is for the people who run the privacy program, CIPP/US is for the people who interpret the law, CDPSE is for the engineers who build the controls, and AIGP is for the people who govern AI.

  CIPM CIPP/US CDPSE AIGP
Issuer IAPP IAPP ISACA IAPP
Focus Privacy program management US privacy law Privacy engineering AI governance
Prerequisites None None 3 years of experience, verified after the exam None
Exam Format 90 items (75 scored), 2.5 hours 90 items (75 scored), 2.5 hours 120 items, 3.5 hours 100 items (85 scored), about 3 hours
Passing Score 300 (scaled 100 to 500) 300 (scaled 100 to 500) 450 (scaled 200 to 800) 300 (scaled 100 to 500)
Exam Cost $550 $550 $575 member / $760 non-member $649 member / $799 non-member
Renewal 20 CPE hours per 2-year term 20 CPE hours per 2-year term 20 CPE hours per year, 120 per 3-year cycle 20 CPEs over 2 years
Current Blueprint BoK v4.2.0, effective September 1, 2025 BoK v2.6.1, effective September 1, 2025 4-domain job practice BoK v2.1, effective February 2, 2026
DoD 8140 Matrix Not a matrix credential Not a matrix credential Not listed Not listed
Best For Program managers, DPOs, privacy officers Privacy counsel, compliance, advisors Security engineers, architects, developers AI governance, compliance and risk leads

CIPM and CIPP/US exam facts are from the IAPP. CDPSE and AIGP facts are from our CDPSE guide and AIGP guide. Training Camp also runs a CIPP/US boot camp. None of the four is a DoD 8140 matrix credential as far as we can verify; check the current Approved Qualifications Matrix at public.cyber.mil before relying on any of them for a cyber-coded position.

Ready to Pursue the CIPM?

Train for CIPM with Training Camp.

Our IAPP CIPM boot camp runs two days with official IAPP courseware, exam prep review sessions, the $550 exam voucher and a free retake included. Training Camp is an Official IAPP Training Partner, and you can browse the full IAPP course lineup if you are planning more than one credential.

View Boot Camp
Dive Deeper

CIPM Articles and Guides.

Privacy fundamentals, GRC career strategy, maintenance costs, and how the CIPM stacks up against the other privacy and governance credentials.

Featured Foundations

What Is Data Privacy and Why It Matters

The concept the whole CIPM program is built to operationalize: what data privacy actually means, how it differs from data security, and why organizations now treat it as a program rather than a policy.

Read Article โ†’
Career Decision

Best Certifications for GRC Careers in 2026

Where privacy program credentials like the CIPM sit next to the audit, risk and security management certifications GRC teams hire for, and how to sequence them.

Read Article โ†’
Maintenance

CPE Requirements by Certification Body: A Complete Comparison

How the IAPP's 20 hours per two-year term compares with ISACA, ISC2 and CompTIA renewal rules, useful if you plan to hold a CIPM alongside other credentials.

Read Article โ†’
Comparison

Is the CDPSE Worth It? Who the Certification Is Actually For

The ISACA privacy engineering credential many CIPM holders consider next, and an honest read on which roles benefit from it and which do not.

Read Article โ†’
Comparison

IAPP CIPT vs ISACA CDPSE: How to Pick the Best Privacy Engineering Certification

A practitioner's comparison of the two technical privacy credentials, and where the manager-focused CIPM fits for people who run the program rather than build the controls.

Read Article โ†’
Next Credential

IAPP AIGP Certification: What It Covers and Whether It's Worth Pursuing

The IAPP's AI governance credential explained. It counts toward the Fellow of Information Privacy designation alongside the CIPM, and privacy managers are increasingly asked to cover AI risk too.

Read Article โ†’
In Practice

What the ChatGPT Privilege Ruling Means for Your Enterprise Data

A real case that lands squarely in CIPM territory: vendor data retention, legal holds, and what a privacy program has to document when a court order changes how personal data is kept.

Read Article โ†’
Curriculum

Inside the Six CIPM Domains.

The CIPM Body of Knowledge v4.2.0 is organized into six domains. The IAPP publishes a minimum and maximum number of scored questions per domain out of 75, not percentage weights, and the badges below show those scored-question ranges from the Exam Blueprint. Click any domain for what it covers.

Domains I-III

Framework to Assessment
I Privacy Program: Developing a Framework 14-18 Qs

The groundwork for a privacy program: identifying where personal information comes from and how the organization uses it, understanding the business model and risk appetite, choosing a governance model, and defining the privacy team and its stakeholders. It also covers communicating the program's vision, and mapping the territorial, sectoral and industry laws in scope, including the privacy risks that come with using AI in the business.

II Privacy Program: Establishing Program Governance 12-16 Qs

How privacy requirements get implemented across the organization: the reporting structure, the policies for the data being processed, and the plans for breach management, complaints, data subject rights, and retention and disposal. It also covers clarifying who is responsible for what, defining metrics for oversight, monitoring changes in privacy law across jurisdictions, and running training and awareness activities.

III Privacy Program Operational Life Cycle: Assessing Data 12-16 Qs

Finding and reducing privacy risk in systems, processes and products: mapping data inventories, data flows and system integrations, measuring policy compliance, and running gap analyses against applicable laws and standards. It also covers evaluating processors and third-party vendors, physical and environmental controls, technical controls including data location and cross-border flows, and the data risks in mergers, acquisitions and divestitures.

Domains IV-VI

Protection to Response
IV Privacy Program Operational Life Cycle: Protecting Personal Data 9-13 Qs

Protecting data assets during use through privacy and security controls: classifying data, understanding the purposes and limits of information security practices, and applying technical, administrative and organizational measures to reduce risk. It also covers integrating Privacy by Design into the system development life cycle and business processes, verifying that guidelines for secondary data use are followed, and working with privacy technologists on obfuscation, minimization and other privacy enhancing technologies.

V Privacy Program Operational Life Cycle: Sustaining Program Performance 7-9 Qs

Keeping the program working once it exists: choosing metrics for different objectives, analyzing the collected data and linking it to program goals such as PIAs performed, rights request response rates, complaint volume and breach metrics. It also covers auditing privacy policies, controls and standards, and managing continuous assessment through the full range of assessment types, including PIA, DPIA, TIA, LIA and PTA.

VI Privacy Program Operational Life Cycle: Responding to Requests and Incidents 10-14 Qs

The activities involved in responding to data subjects and to privacy incidents: transparent privacy notices, handling consent withdrawals, rectification requests, objections, access requests and complaints, and complying with global legislation on individuals' rights over their data. It also covers executing incident handling procedures (assessment, containment, remediation), communicating with stakeholders, keeping an incident register, and running post-incident reviews that improve the response plan.

Domains and scored-question ranges reflect the IAPP CIPM Body of Knowledge and Exam Blueprint v4.2.0, approved January 16, 2025 and effective September 1, 2025. The IAPP reviews the BoK every year and announces changes at least 90 days before they reach the exam. No 2026 change had been announced when this page was written.

Frequently Asked Questions

Common Questions About CIPM.

The questions candidates ask most often when researching the Certified Information Privacy Manager certification.

What is the CIPM certification?

The Certified Information Privacy Manager (CIPM) is the IAPP's credential for people who establish, maintain and manage a privacy program across all stages of its life cycle. The IAPP calls it the first and only privacy certification for professionals who manage day-to-day privacy operations. Where the CIPP credentials test knowledge of privacy law, the CIPM tests whether you can run the program that delivers it.

Who should get the CIPM?

Anyone accountable for a privacy program in practice: privacy program managers, data protection officers, chief privacy officers, compliance managers, privacy consultants, and GRC leads who own privacy risk. It also suits people moving into privacy from legal, audit or security roles who now have to operate the program rather than advise on it.

What are the six CIPM exam domains?

Under Body of Knowledge v4.2.0, effective September 1, 2025, the six domains are Privacy Program: Developing a Framework (14 to 18 scored questions), Privacy Program: Establishing Program Governance (12 to 16), Privacy Program Operational Life Cycle: Assessing Data (12 to 16), Protecting Personal Data (9 to 13), Sustaining Program Performance (7 to 9), and Responding to Requests and Incidents (10 to 14). The IAPP publishes these as scored-question ranges, not percentages.

How much does the CIPM exam cost?

The CIPM exam costs $550, and the IAPP shows a single price for members and non-members. You must take the exam within one year of purchase, and a retake can't be scheduled sooner than seven days after the prior attempt. Retakes are discounted. Training Camp's 2-day CIPM boot camp includes the exam voucher and a free retake.

What does the CIPM exam look like?

The CIPM exam has 90 multiple-choice questions, 75 scored and 15 unscored, delivered over 2.5 hours with a 15-minute break. Some questions have more than one correct answer and some are scenario-based. Scores are scaled from 100 to 500, and 300 or above passes. It's delivered at Pearson VUE test centers or online through OnVUE.

Are there prerequisites for the CIPM?

No. The IAPP states no experience or education prerequisite for the CIPM; you agree to the IAPP's certification policies, purchase the exam, and schedule it. IAPP membership isn't required to sit the exam, though keeping the certification active does require either a membership or the Certification Maintenance Fee.

How long is the CIPM valid and how do I renew it?

The CIPM runs on a two-year term. To keep it active you earn 20 hours of continuing privacy education per credential per term and pay a $250 Certification Maintenance Fee per term, which is covered if you hold an active IAPP membership.

Is the CIPM approved for DoD 8140?

We don't claim it. The CIPM is not a DoD 8140 matrix credential, so it won't satisfy a cyber-coded position requirement on its own. If you need an 8140 qualification, check the current DoD 8140 Approved Qualifications Matrix at public.cyber.mil and see the full DoD 8140 work role paths. The CIPM's recognition comes from privacy regulation and from ANAB accreditation instead.

Is the CIPM accredited?

Yes. The CIPM, along with the CIPP/E, CIPP/US and CIPT, is accredited by the ANSI National Accreditation Board (ANAB) under ISO/IEC 17024:2012, the international standard for bodies that certify people. The AIGP is not on that accredited list at the time of writing.

CIPM or CIPP/US, which should I take first?

They answer different questions. The CIPP/US tells you what US privacy law requires; the CIPM tells you how to run a program that meets it. If your role is legal or advisory, start with the CIPP/US. If you've been handed a privacy program to operate, start with the CIPM. Both exams share the same format: 90 questions, 2.5 hours, 300 to pass, $550, two-year term.

What is the Fellow of Information Privacy (FIP)?

The FIP is the IAPP's designation for senior privacy professionals. It requires a CIPP credential plus a CIPM, CIPT or AIGP, and three years of work experience in which privacy is at least half the job. The CIPM is the most direct route to the second half of that requirement for people who manage programs.

Did the CIPM exam change recently?

Yes. Body of Knowledge v4.2.0 was approved on January 16, 2025 and took effect on September 1, 2025, replacing v4.1.0. The IAPP reviews the BoK every year and announces changes at least 90 days before they reach the exam, and says roughly 10 to 15 percent of content changes in an annual update. No specific 2026 change has been announced as of this writing.

Is the CIPM worth it in 2026?

For people who run privacy programs, yes. Privacy laws in the EU, US states and elsewhere now expect organizations to operate documented programs, not just interpret statutes, and the CIPM is the IAPP credential built squarely for that operational work. It's ANAB accredited, has no prerequisite, and counts toward the FIP. It's a weaker fit if your work is purely legal interpretation or hands-on engineering.

Get In Touch

Have Questions About CIPM?

If you're weighing the certification, comparing IAPP credentials, or planning privacy training for a team, tell us where you are and we'll help you map out the right path.

+1
    100% Secure. NDA Compliant.
    IAPP CIPM Boot Camp 2 Days ยท Exam Voucher Included
    View Boot Camp