Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about the IAPP's U.S. privacy law certification as of 2026, covering the five BoK v2.6.1 domains, the 90-question exam, costs, maintenance, career paths, and how CIPP/US compares to CIPM, CDPSE, and AIGP. A complete reference for anyone weighing the CIPP/US or trying to understand what it covers.
CIPP/US is the IAPP's certification in U.S. private-sector privacy law, the concentration of the CIPP built for professionals whose work is governed by American federal and state rules.
It validates that you know the law well enough to apply it. The five domains run from the structure of U.S. government and the regulators who enforce privacy, through the federal statutes for healthcare, finance, education, and marketing, to government access to private data, workplace privacy, and the state laws that now change every legislative session. The exam asks you to reason through scenarios the way a privacy analyst or counsel has to, not to recite section numbers.
The credential has no prerequisites, is accredited by the ANSI National Accreditation Board under ISO/IEC 17024:2012, and is issued and maintained by the IAPP, the International Association of Privacy Professionals, the same body behind the CIPM, CIPT, and AIGP. The IAPP's one-line summary of the CIPP is "practicing privacy," and it calls the CIPP the premier global credential for privacy and data protection.
Legal structure, regulators, enforcement, and information management. The heaviest domain at 27 to 33 scored questions.
The FTC, HIPAA, FCRA and GLBA, FERPA, and the telecommunications and marketing rules.
Law enforcement, national security, and civil litigation access to personal data.
Employee privacy before, during, and after employment, and the agencies that police it.
Comprehensive state laws, health and biometric rules, AI bias laws, and breach notification.
Four things that set the credential apart as state privacy laws multiply and federal enforcement keeps expanding.
The CIPP/US comes from the IAPP, the association the privacy profession built for itself, and it carries ANSI National Accreditation Board accreditation under ISO/IEC 17024:2012 alongside the CIPM, CIPP/E, and CIPT. Employers writing privacy job postings ask for it by name.
The IAPP sets no experience or education requirement for the exam, and membership is optional. A paralegal, an HR generalist, or a security analyst can register the same day as a practicing attorney, which is why the credential turns up across so many job functions.
The IAPP's Fellow of Information Privacy designation requires a CIPP plus a CIPM, CIPT, or AIGP, and three years of work in which privacy is at least half the job. Every FIP holds a CIPP concentration, and for U.S. practitioners that usually means CIPP/US. See how the IAPP maintenance cycle compares once you hold more than one.
The CIPP/US is a privacy law credential, not a cybersecurity work role qualification, so it isn't the kind of certification DoD 8140 work roles call for. Before relying on any credential for a cyber-coded position, check the current Approved Qualifications Matrix at public.cyber.mil.
Its weight comes from the law itself: HIPAA, GLBA, FCRA, COPPA, and the other federal statutes it covers are permanent fixtures, and the comprehensive state privacy laws in Domain V are where new compliance work keeps arriving.
Everything you need to know about the certification, the exam structure, and how to maintain the CIPP/US as of September 2026.
The CIPP/US covers what the law requires. The IAPP's other credentials cover how to run the program, how to build privacy into technology, and how to govern AI, and any one of them paired with a CIPP completes the credential half of the FIP designation.
The IAPP's "operationalizing privacy" credential: six domains under BoK v4.2.0 on building, running, and measuring a privacy program. Same exam shape as CIPP/US, 90 questions in 2.5 hours for $550, and the natural second credential for privacy managers. Training Camp runs a CIPM boot camp as well.
The IAPP's "engineering privacy" credential, for the people who have to build what the law requires into systems and products. For CIPP/US holders on the IT or security side, the CIPT is the natural pairing, and it is one of the three credentials that completes a FIP.
The IAPP's "executing responsible AI governance" credential. Domain V of the CIPP/US already touches automated decision-making and AI bias laws; the AIGP takes that into a full governance program covering the EU AI Act, the NIST AI RMF, and ISO/IEC 42001, with no prerequisites of its own.
With no prerequisites, the CIPP/US is usually the first privacy credential someone earns. Candidates arrive from legal, compliance, IT, security, HR, and marketing roles, use it as the anchor, and then specialize by what their job asks of them next.
Where candidates come from, none required
The U.S. privacy law anchor
Two questions to answer before you commit: can you certify, and should you pursue the CIPP/US specifically. Here's a straight answer to both.
No prerequisites, no experience requirement, no membership requirement.
The IAPP sets no experience or education prerequisite for the CIPP/US, and you do not need to join the IAPP to register. Purchase the exam for $550, and you have one year to schedule and take it at a Pearson VUE test center or online through OnVUE. Once you pass, keeping the credential active does require either a membership or the Certification Maintenance Fee.
Open entry doesn't mean easy entry.
Some questions are scenario-based and some have more than one correct answer, and the IAPP's own blueprint says the exam tests application and analysis, not just recall. Candidates who have never read a statute or an FTC consent order can pass, but they spend more prep time building the habit of working from the text of the law to the right answer.
The CIPP/US maps to the roles that interpret and apply U.S. privacy law, from the analyst answering data subject requests to the executive who answers to the board for regulatory exposure.
Handles the day-to-day of a privacy program: data subject requests, privacy notices, vendor questionnaires, and the record keeping that shows regulators the program actually runs the way the policy says.
Builds and runs the privacy program across an organization, translating HIPAA, GLBA, CCPA, and the other applicable laws into training, assessments, and controls that business teams can follow.
Advises the business on federal and state privacy obligations, reviews data processing agreements and marketing practices, and manages the response when a subpoena, breach, or regulator inquiry arrives.
Owns privacy compliance inside a broader regulatory function, mapping the sector rules that apply, tracking new state laws as they take effect, and keeping evidence ready for audits and enforcement inquiries.
Sets privacy strategy and accountability at the executive level, reports to the board on regulatory exposure, and decides how the organization approaches consent, data sharing, and new state requirements.
Helps client organizations assess where they stand against U.S. privacy law, stand up or mature a privacy program, and prepare for the state comprehensive laws that now apply to them.
Shortest version: CIPP/US is for the people who know what the law requires, CIPM is for the people who run the program, CDPSE is for the engineers who build the controls, and AIGP is for the people who govern AI.
| CIPP/US | CIPM | CDPSE | AIGP | |
|---|---|---|---|---|
| Issuer | IAPP | IAPP | ISACA | IAPP |
| Focus | U.S. private-sector privacy law | Privacy program management | Implementing privacy in systems | AI governance, law, lifecycle oversight |
| Prerequisites | None | None | 3 yrs experience to certify (exam first allowed) | None |
| Exam Format | 90 questions (75 scored), 2.5 hours | 90 questions (75 scored), 2.5 hours | 120 questions, 3.5 hours | 100 questions (85 scored), about 3 hours |
| Passing Score | 300 (scaled 100 to 500) | 300 (scaled 100 to 500) | 450 (scaled 200 to 800) | 300 (scaled 100 to 500) |
| Exam Cost | $550 | $550 | $575 member / $760 non-member | $649 member / $799 non-member |
| Renewal | 20 CPE per 2-year term, $250 maintenance | 20 CPE per 2-year term, $250 maintenance | 20 CPE yearly, 120 per 3-year cycle | 20 CPE per 2-year term |
| DoD 8140 Matrix | Not a matrix credential | Check the current matrix | Not listed in Matrix V2.1 | Not listed in Matrix V2.1 |
| Best For | Privacy analysts, counsel, compliance leads | Privacy program managers | Privacy engineers and architects | AI governance and compliance leads |
Pricing and renewal details can change and vary by membership status. CIPM figures reflect BoK v4.2.0, effective September 1, 2025, and Training Camp runs a CIPM boot camp. CDPSE and AIGP figures come from our CDPSE guide and AIGP guide. Confirm any DoD 8140 status against the current Approved Qualifications Matrix at public.cyber.mil.
As an Official IAPP Training Partner, we run the IAPP CIPP/US Boot Camp over two days with official IAPP courseware, the $550 exam voucher included, and a free retake if you need a second attempt, so you leave exam-ready.
Privacy fundamentals, career strategy, maintenance, and how the CIPP/US sits alongside the other privacy and governance credentials.
The foundation under the whole credential: what data privacy means in practice, who controls personal information, and why the question now reaches every department, not just legal.
Where a privacy law credential fits in a governance, risk, and compliance career, and how it stacks with the audit, risk, and security certifications GRC teams tend to hire for.
How the IAPP two-year term and 20-hour requirement compares with ISACA, ISC2, and the other bodies, useful once you hold more than one credential and the renewal calendars start to overlap.
A look at the ISACA privacy engineering credential, who it serves, and why its experience requirement and technical focus put it on a different track from a law-focused certification.
The two technical privacy credentials compared side by side, and how each one pairs with a CIPP for professionals who want to cover both the law and the systems that have to comply with it.
The IAPP credential many CIPP/US holders add next: what the AI governance exam tests, who it fits, and how it extends a privacy foundation into automated decision-making and AI oversight.
A live example of the Domain III material at work: how court access, privilege, and e-discovery reach the data your organization hands to AI tools, and what privacy teams should do about it.
The CIPP/US Body of Knowledge v2.6.1 is organized into five domains. The badge on each row is the blueprint's published range of scored questions for that domain, out of 75 scored items; the IAPP publishes these as minimum and maximum counts rather than percentages. Click any domain for what it covers.
The legal groundwork: branches of government, sources of law, and concepts like jurisdiction, preemption, and private right of action, plus the roles of regulators such as the FTC, FCC, HHS, the banking regulators, and state attorneys general. The domain also covers the enforcement framework (liability theories, UDAP laws, self-regulation) and information management practice, from data inventories and vendor risk to international transfer mechanisms like Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.
How the FTC polices consumer privacy under the FTC Act and COPPA, and where federal enforcement is heading on data brokers, IoT, AI, and biometrics. The domain then works sector by sector: HIPAA and HITECH in healthcare, FCRA, GLBA, the Red Flags Rule, and Dodd-Frank in finance, FERPA in education, and the TSR, TCPA, CAN-SPAM, and VPPA in telecommunications and marketing.
What happens when a subpoena, court order, or law enforcement request reaches private-sector data: the Right to Financial Privacy Act and Bank Secrecy Act for financial records, and ECPA and CALEA for communications. It also covers national security access under FISA and Section 702, the USA-PATRIOT Act, the USA Freedom Act, and the Cybersecurity Information Sharing Act, plus e-discovery and the Privacy Protection Act in civil litigation.
Workplace privacy concepts and the anti-discrimination laws around them, including the Civil Rights Act, the ADA, and GINA, along with the agencies that regulate the employment relationship, from the EEOC and Department of Labor to the NLRB. The domain follows the employment lifecycle: automated employment decision tools and background screening before hiring, monitoring and internal investigations during employment, and records retention and reference requests after.
The second-heaviest domain: how state authority relates to federal law, and the common requirements of comprehensive state privacy laws, such as applicability thresholds, exemptions, data subject rights, data protection assessments, and enforcement concepts like cure periods. It covers the CCPA as amended by the CPRA, the California Age-Appropriate Design Code and Delete Act, state health data laws like Washington's My Health My Data Act, biometric and facial recognition rules, AI bias and automated decision-making laws, and state data breach notification requirements.
Domains and scored-question ranges reflect the IAPP CIPP/US Body of Knowledge and Exam Blueprint v2.6.1, approved March 3, 2025 and effective September 1, 2025. The IAPP reviews the BoK annually, changes roughly 10 to 15 percent of exam content each year, and announces changes at least 90 days before they reach the exam. As of September 2026 no specific 2026 blueprint change has been announced.
The questions candidates ask most often when researching the Certified Information Privacy Professional/United States certification.
The Certified Information Privacy Professional/United States (CIPP/US) is the IAPP's certification in U.S. private-sector privacy law. It covers the U.S. legal and regulatory environment, the federal sector laws for healthcare, finance, education, and marketing, government and court access to private-sector data, workplace privacy, and state privacy laws. The IAPP describes the CIPP as the premier global credential for privacy and data protection, and CIPP/US is the concentration for professionals whose work is governed by U.S. law.
Under Body of Knowledge v2.6.1, effective September 1, 2025, the five domains are The U.S. Privacy Environment (27 to 33 scored questions), Federal Privacy Laws (15 to 19), Government and Court Access to Private-sector Information (3 to 5), Workplace Privacy (4 to 6), and State Privacy Laws (17 to 21). The IAPP publishes these as minimum and maximum scored-question counts, not percentages.
The CIPP/US exam costs $550 for a first attempt, and the price is the same for IAPP members and non-members. Retakes are discounted, though the IAPP does not publish the retake amount on its main pricing pages. You must schedule and take the exam within one year of purchase. Training Camp's 2-day CIPP/US boot camp includes the $550 exam voucher.
The CIPP/US exam has 90 multiple-choice questions, 75 scored and 15 unscored, delivered over 2.5 hours with a 15-minute break. Some questions have more than one correct answer and some are scenario-based. Scores are scaled from 100 to 500, and 300 passes; the IAPP notes that 300 does not mean 60 percent correct. The exam is delivered year-round at Pearson VUE test centers or online through OnVUE.
No. The IAPP sets no experience or education prerequisite for the CIPP/US exam, and you don't need to be an IAPP member to sit it. Comfort reading statutes and regulations helps, because the exam asks you to apply the law to scenarios rather than recite it, but candidates arrive from legal, compliance, IT, security, HR, and marketing roles.
The CIPP/US has a two-year certification term. To keep it active you earn 20 hours of continuing privacy education per credential per term and pay either the $250 Certification Maintenance Fee or hold an IAPP membership, which runs $295 per year and includes the maintenance fee.
The CIPP/US is a privacy law credential, not a cybersecurity work role qualification, so it isn't the kind of certification the DoD 8140 work roles call for. Before relying on it for a cyber-coded position, check the current DoD 8140 Approved Qualifications Matrix at public.cyber.mil. If you need an 8140 path, see the full DoD 8140 work role paths.
Start with the one that matches your job. CIPP/US covers what U.S. privacy law requires, the IAPP's "practicing privacy" credential. CIPM covers how to build and run a privacy program, the "operationalizing privacy" credential, with six domains under BoK v4.2.0. Both are 90-question, 2.5-hour, $550 exams with no prerequisites. Holding a CIPP plus a CIPM, CIPT, or AIGP is also the credential half of the Fellow of Information Privacy designation.
The difficulty is breadth. Five domains span constitutional structure, a dozen or more federal statutes, government access rules, employment law, and a fast-moving set of state laws, and the scenario questions expect you to pick the strongest answer among several defensible ones. Candidates who study from the current BoK v2.6.1 and practice applying the laws to fact patterns, rather than memorizing acronyms, tend to find it manageable.
It depends on how much of the material you already work with. Attorneys and compliance professionals who deal with HIPAA, GLBA, or CCPA daily need less time than someone new to privacy law. A focused boot camp compresses the instruction into two days by working straight from the official IAPP courseware, with self-study for review before and after.
Yes. The current Body of Knowledge and Exam Blueprint is version 2.6.1, approved March 3, 2025 and effective September 1, 2025. The IAPP updates its exams annually, changing roughly 10 to 15 percent of content, and announces body of knowledge changes at least 90 days before they reach the exam. As of September 2026 no specific 2026 blueprint change has been announced, so verify any prep material against v2.6.1.
FIP is the IAPP's designation for experienced, multi-credentialed privacy professionals. It requires a CIPP concentration such as CIPP/US plus a CIPM, CIPT, or AIGP, and three years of work experience in which privacy is at least half the job. For most people, CIPP/US is the first of the two credentials.
For anyone whose work touches U.S. personal data, yes. State comprehensive privacy laws keep taking effect, federal sector rules like HIPAA and GLBA aren't going anywhere, and employers use the CIPP/US as the standard signal that a candidate knows the law. It's ANAB accredited under ISO/IEC 17024:2012, has no prerequisites, and costs $550 to sit, which makes the return straightforward for privacy, legal, and compliance roles.
Weighing the certification, comparing the IAPP credentials, or planning privacy training for a team: tell us where you are and we'll help you map out the right path.