Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about the IAPP's privacy program management certification as of 2026, covering the six BoK v4.2.0 domains, the 90-question exam, costs, maintenance, career paths, and how the CIPM compares to the CIPP/US, ISACA's CDPSE and the AIGP. A complete reference for anyone weighing the CIPM or trying to understand what it covers.
CIPM is the IAPP's privacy program management certification, the credential for people who establish, maintain and manage a privacy program across all stages of its life cycle.
The IAPP describes it as the first and only privacy certification for professionals who manage day-to-day operations, and sums it up in two words: operationalizing privacy. The CIPP credentials test whether you know the law. This one tests whether you can build the governance model, run the assessments, protect the data, measure the program and respond when a request or an incident lands, the way a privacy program manager or data protection officer has to.
The credential is ANAB accredited under ISO/IEC 17024:2012, carries no experience or education prerequisite, and is one of the credentials that count toward the IAPP's Fellow of Information Privacy designation. CIPM is issued and maintained by the IAPP, the same body behind the CIPP, CIPT and AIGP credentials.
Program scope, strategy, governance model, and the laws in scope. The heaviest domain at 14 to 18 scored questions.
Policies, roles and responsibilities, oversight metrics, and training.
Data inventories and flows, vendor and control evaluation, M&A data risk.
Classification, security controls, Privacy by Design, and data use guidelines.
Metrics, program audits, and continuous assessment (PIA, DPIA, TIA, LIA, PTA).
Data subject rights, incident handling, and post-incident review.
Four things that set the credential apart as organizations move from writing privacy policies to running privacy programs.
The IAPP positions the CIPM as the first and only privacy certification for professionals who manage day-to-day operations. The CIPP credentials test law and the CIPT and CDPSE test technology. This one tests the operational framework that connects them: governance, assessment, protection, measurement and response, across the full life cycle of a program.
ISACA's CDPSE asks for three years of verified experience before it grants the credential. The CIPM has no experience or education prerequisite. You agree to the IAPP's certification policies, buy the exam, and you have a year to sit it.
The IAPP's Fellow of Information Privacy needs a CIPP plus a CIPM, CIPT or AIGP, and three years of work where privacy is at least half the job. For program managers the CIPM is the natural second credential. Our CPE comparison covers what holding several IAPP credentials costs to maintain.
The CIPM is not a DoD 8140 matrix credential, so it will not satisfy a cyber-coded position requirement on its own. If you need an 8140 qualification, check the current Approved Qualifications Matrix at public.cyber.mil before you commit.
Its weight comes from two other places: ANAB accreditation under ISO/IEC 17024:2012, the international standard for personnel certification bodies, and the privacy laws in the EU, US states and elsewhere that now expect organizations to operate documented programs with named people accountable for them.
Everything you need to know about the certification, the exam structure, and how to maintain the CIPM as of 2026.
The CIPM covers how to run the program. The IAPP's other credentials each add a different dimension, and holding the right pair, plus the experience, qualifies you for the Fellow of Information Privacy designation.
The IAPP's US privacy law credential: the federal and state laws, government and court access, and workplace privacy your program has to comply with. Same exam format as the CIPM, and the CIPP half of the FIP requirement. A CIPP/E covers the same ground for European law.
The CIPT covers how technology delivers privacy, useful for managers who work closely with engineering teams. The AIGP covers responsible AI governance, and Domain I of the CIPM already asks you to understand the privacy risks of AI in the business. Either one, like the CIPM, satisfies the second half of the FIP requirement.
The IAPP's senior designation. It requires a CIPP plus a CIPM, CIPT or AIGP, and three years of work experience in which privacy is at least half the job. For someone who runs a program, CIPM plus a CIPP is the shortest route.
With no prerequisites, the CIPM can be a first credential. In practice most candidates arrive from legal, compliance, audit or security work, earn the CIPM once they are handed a program to run, and then add a law credential or a specialty.
Common starting points, none required
The privacy program management anchor
Two things to settle before you commit: can you certify, and should you pursue the CIPM specifically. Here's a straight answer to both.
No experience or education prerequisite.
The IAPP states no experience or education requirement for the CIPM. You agree to its certification policies, purchase the exam, and you have one year to schedule and sit it at a Pearson VUE test center or online through OnVUE. Membership is not required to take the exam, though keeping the credential active later needs either a membership or the Certification Maintenance Fee.
Open entry doesn't mean easy entry.
Some questions are scenario-based and some have more than one correct answer, and the scenarios assume you can reason like someone who has sat in on a breach response or a vendor review. Candidates with no exposure to how a privacy program actually operates can still pass, but they should expect to spend more prep time on the operational context the questions take for granted, and to plan around the seven-day wait before any retake.
The CIPM maps to the roles that own a privacy program rather than advise on it, the positions organizations create as privacy laws require named, accountable people and documented operations.
Owns the privacy program day to day: the governance model, the policies and procedures, the assessment calendar, and the metrics that show leadership whether the program is working.
The accountable contact for regulators and data subjects where the law requires one, monitoring compliance, advising on impact assessments, and keeping the incident register and the breach response plan current.
Sets privacy strategy at the organizational level, decides the governance model, secures budget and stakeholders, and reports program performance to the board and the executive team.
Tracks the laws and regulations in scope across jurisdictions, translates them into internal policy and controls, and runs the audits and gap analyses that prove the program meets them.
Builds or assesses privacy programs for client organizations, from data inventories and vendor evaluations to Privacy by Design reviews and post-incident plan revisions.
Brings privacy into the broader governance, risk and compliance function, aligning privacy risk assessments, third-party risk and control monitoring with the rest of the enterprise risk program.
Shortest version: CIPM is for the people who run the privacy program, CIPP/US is for the people who interpret the law, CDPSE is for the engineers who build the controls, and AIGP is for the people who govern AI.
| CIPM | CIPP/US | CDPSE | AIGP | |
|---|---|---|---|---|
| Issuer | IAPP | IAPP | ISACA | IAPP |
| Focus | Privacy program management | US privacy law | Privacy engineering | AI governance |
| Prerequisites | None | None | 3 years of experience, verified after the exam | None |
| Exam Format | 90 items (75 scored), 2.5 hours | 90 items (75 scored), 2.5 hours | 120 items, 3.5 hours | 100 items (85 scored), about 3 hours |
| Passing Score | 300 (scaled 100 to 500) | 300 (scaled 100 to 500) | 450 (scaled 200 to 800) | 300 (scaled 100 to 500) |
| Exam Cost | $550 | $550 | $575 member / $760 non-member | $649 member / $799 non-member |
| Renewal | 20 CPE hours per 2-year term | 20 CPE hours per 2-year term | 20 CPE hours per year, 120 per 3-year cycle | 20 CPEs over 2 years |
| Current Blueprint | BoK v4.2.0, effective September 1, 2025 | BoK v2.6.1, effective September 1, 2025 | 4-domain job practice | BoK v2.1, effective February 2, 2026 |
| DoD 8140 Matrix | Not a matrix credential | Not a matrix credential | Not listed | Not listed |
| Best For | Program managers, DPOs, privacy officers | Privacy counsel, compliance, advisors | Security engineers, architects, developers | AI governance, compliance and risk leads |
CIPM and CIPP/US exam facts are from the IAPP. CDPSE and AIGP facts are from our CDPSE guide and AIGP guide. Training Camp also runs a CIPP/US boot camp. None of the four is a DoD 8140 matrix credential as far as we can verify; check the current Approved Qualifications Matrix at public.cyber.mil before relying on any of them for a cyber-coded position.
Our IAPP CIPM boot camp runs two days with official IAPP courseware, exam prep review sessions, the $550 exam voucher and a free retake included. Training Camp is an Official IAPP Training Partner, and you can browse the full IAPP course lineup if you are planning more than one credential.
Privacy fundamentals, GRC career strategy, maintenance costs, and how the CIPM stacks up against the other privacy and governance credentials.
The concept the whole CIPM program is built to operationalize: what data privacy actually means, how it differs from data security, and why organizations now treat it as a program rather than a policy.
Where privacy program credentials like the CIPM sit next to the audit, risk and security management certifications GRC teams hire for, and how to sequence them.
How the IAPP's 20 hours per two-year term compares with ISACA, ISC2 and CompTIA renewal rules, useful if you plan to hold a CIPM alongside other credentials.
The ISACA privacy engineering credential many CIPM holders consider next, and an honest read on which roles benefit from it and which do not.
A practitioner's comparison of the two technical privacy credentials, and where the manager-focused CIPM fits for people who run the program rather than build the controls.
The IAPP's AI governance credential explained. It counts toward the Fellow of Information Privacy designation alongside the CIPM, and privacy managers are increasingly asked to cover AI risk too.
A real case that lands squarely in CIPM territory: vendor data retention, legal holds, and what a privacy program has to document when a court order changes how personal data is kept.
The CIPM Body of Knowledge v4.2.0 is organized into six domains. The IAPP publishes a minimum and maximum number of scored questions per domain out of 75, not percentage weights, and the badges below show those scored-question ranges from the Exam Blueprint. Click any domain for what it covers.
The groundwork for a privacy program: identifying where personal information comes from and how the organization uses it, understanding the business model and risk appetite, choosing a governance model, and defining the privacy team and its stakeholders. It also covers communicating the program's vision, and mapping the territorial, sectoral and industry laws in scope, including the privacy risks that come with using AI in the business.
How privacy requirements get implemented across the organization: the reporting structure, the policies for the data being processed, and the plans for breach management, complaints, data subject rights, and retention and disposal. It also covers clarifying who is responsible for what, defining metrics for oversight, monitoring changes in privacy law across jurisdictions, and running training and awareness activities.
Finding and reducing privacy risk in systems, processes and products: mapping data inventories, data flows and system integrations, measuring policy compliance, and running gap analyses against applicable laws and standards. It also covers evaluating processors and third-party vendors, physical and environmental controls, technical controls including data location and cross-border flows, and the data risks in mergers, acquisitions and divestitures.
Protecting data assets during use through privacy and security controls: classifying data, understanding the purposes and limits of information security practices, and applying technical, administrative and organizational measures to reduce risk. It also covers integrating Privacy by Design into the system development life cycle and business processes, verifying that guidelines for secondary data use are followed, and working with privacy technologists on obfuscation, minimization and other privacy enhancing technologies.
Keeping the program working once it exists: choosing metrics for different objectives, analyzing the collected data and linking it to program goals such as PIAs performed, rights request response rates, complaint volume and breach metrics. It also covers auditing privacy policies, controls and standards, and managing continuous assessment through the full range of assessment types, including PIA, DPIA, TIA, LIA and PTA.
The activities involved in responding to data subjects and to privacy incidents: transparent privacy notices, handling consent withdrawals, rectification requests, objections, access requests and complaints, and complying with global legislation on individuals' rights over their data. It also covers executing incident handling procedures (assessment, containment, remediation), communicating with stakeholders, keeping an incident register, and running post-incident reviews that improve the response plan.
Domains and scored-question ranges reflect the IAPP CIPM Body of Knowledge and Exam Blueprint v4.2.0, approved January 16, 2025 and effective September 1, 2025. The IAPP reviews the BoK every year and announces changes at least 90 days before they reach the exam. No 2026 change had been announced when this page was written.
The questions candidates ask most often when researching the Certified Information Privacy Manager certification.
The Certified Information Privacy Manager (CIPM) is the IAPP's credential for people who establish, maintain and manage a privacy program across all stages of its life cycle. The IAPP calls it the first and only privacy certification for professionals who manage day-to-day privacy operations. Where the CIPP credentials test knowledge of privacy law, the CIPM tests whether you can run the program that delivers it.
Anyone accountable for a privacy program in practice: privacy program managers, data protection officers, chief privacy officers, compliance managers, privacy consultants, and GRC leads who own privacy risk. It also suits people moving into privacy from legal, audit or security roles who now have to operate the program rather than advise on it.
Under Body of Knowledge v4.2.0, effective September 1, 2025, the six domains are Privacy Program: Developing a Framework (14 to 18 scored questions), Privacy Program: Establishing Program Governance (12 to 16), Privacy Program Operational Life Cycle: Assessing Data (12 to 16), Protecting Personal Data (9 to 13), Sustaining Program Performance (7 to 9), and Responding to Requests and Incidents (10 to 14). The IAPP publishes these as scored-question ranges, not percentages.
The CIPM exam costs $550, and the IAPP shows a single price for members and non-members. You must take the exam within one year of purchase, and a retake can't be scheduled sooner than seven days after the prior attempt. Retakes are discounted. Training Camp's 2-day CIPM boot camp includes the exam voucher and a free retake.
The CIPM exam has 90 multiple-choice questions, 75 scored and 15 unscored, delivered over 2.5 hours with a 15-minute break. Some questions have more than one correct answer and some are scenario-based. Scores are scaled from 100 to 500, and 300 or above passes. It's delivered at Pearson VUE test centers or online through OnVUE.
No. The IAPP states no experience or education prerequisite for the CIPM; you agree to the IAPP's certification policies, purchase the exam, and schedule it. IAPP membership isn't required to sit the exam, though keeping the certification active does require either a membership or the Certification Maintenance Fee.
The CIPM runs on a two-year term. To keep it active you earn 20 hours of continuing privacy education per credential per term and pay a $250 Certification Maintenance Fee per term, which is covered if you hold an active IAPP membership.
We don't claim it. The CIPM is not a DoD 8140 matrix credential, so it won't satisfy a cyber-coded position requirement on its own. If you need an 8140 qualification, check the current DoD 8140 Approved Qualifications Matrix at public.cyber.mil and see the full DoD 8140 work role paths. The CIPM's recognition comes from privacy regulation and from ANAB accreditation instead.
Yes. The CIPM, along with the CIPP/E, CIPP/US and CIPT, is accredited by the ANSI National Accreditation Board (ANAB) under ISO/IEC 17024:2012, the international standard for bodies that certify people. The AIGP is not on that accredited list at the time of writing.
They answer different questions. The CIPP/US tells you what US privacy law requires; the CIPM tells you how to run a program that meets it. If your role is legal or advisory, start with the CIPP/US. If you've been handed a privacy program to operate, start with the CIPM. Both exams share the same format: 90 questions, 2.5 hours, 300 to pass, $550, two-year term.
The FIP is the IAPP's designation for senior privacy professionals. It requires a CIPP credential plus a CIPM, CIPT or AIGP, and three years of work experience in which privacy is at least half the job. The CIPM is the most direct route to the second half of that requirement for people who manage programs.
Yes. Body of Knowledge v4.2.0 was approved on January 16, 2025 and took effect on September 1, 2025, replacing v4.1.0. The IAPP reviews the BoK every year and announces changes at least 90 days before they reach the exam, and says roughly 10 to 15 percent of content changes in an annual update. No specific 2026 change has been announced as of this writing.
For people who run privacy programs, yes. Privacy laws in the EU, US states and elsewhere now expect organizations to operate documented programs, not just interpret statutes, and the CIPM is the IAPP credential built squarely for that operational work. It's ANAB accredited, has no prerequisite, and counts toward the FIP. It's a weaker fit if your work is purely legal interpretation or hands-on engineering.
If you're weighing the certification, comparing IAPP credentials, or planning privacy training for a team, tell us where you are and we'll help you map out the right path.