Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Certification Guide

The Certified Information Privacy Professional/United States (CIPP/US)
Certification Explained.

Everything you need to know about the IAPP's U.S. privacy law certification as of 2026, covering the five BoK v2.6.1 domains, the 90-question exam, costs, maintenance, career paths, and how CIPP/US compares to CIPM, CDPSE, and AIGP. A complete reference for anyone weighing the CIPP/US or trying to understand what it covers.

CIPP_US_FAST_FACTS
Issuer: IAPP
Exam: 90 questions, 2.5 hrs
Passing Score: 300 / 500
Prerequisites: None
DoD 8140: Not a matrix credential
5 BoK v2.6.1 Domains 90 Exam Questions 2.5 HRS Plus 15-Min Break NO Prerequisites ANAB Accredited
UPDATED 2026
Overview

What Is the Certified Information Privacy Professional/United States (CIPP/US)?

CIPP/US is the IAPP's certification in U.S. private-sector privacy law, the concentration of the CIPP built for professionals whose work is governed by American federal and state rules.

It validates that you know the law well enough to apply it. The five domains run from the structure of U.S. government and the regulators who enforce privacy, through the federal statutes for healthcare, finance, education, and marketing, to government access to private data, workplace privacy, and the state laws that now change every legislative session. The exam asks you to reason through scenarios the way a privacy analyst or counsel has to, not to recite section numbers.

The credential has no prerequisites, is accredited by the ANSI National Accreditation Board under ISO/IEC 17024:2012, and is issued and maintained by the IAPP, the International Association of Privacy Professionals, the same body behind the CIPM, CIPT, and AIGP. The IAPP's one-line summary of the CIPP is "practicing privacy," and it calls the CIPP the premier global credential for privacy and data protection.

5 Domains
75 Scored Questions
0 Prerequisites
The CIPP/US Domains

Five Domains of the BoK v2.6.1

I

The U.S. Privacy Environment

Legal structure, regulators, enforcement, and information management. The heaviest domain at 27 to 33 scored questions.

II

Federal Privacy Laws

The FTC, HIPAA, FCRA and GLBA, FERPA, and the telecommunications and marketing rules.

III

Government and Court Access to Private-sector Information

Law enforcement, national security, and civil litigation access to personal data.

IV

Workplace Privacy

Employee privacy before, during, and after employment, and the agencies that police it.

V

State Privacy Laws

Comprehensive state laws, health and biometric rules, AI bias laws, and breach notification.

Why CIPP/US Matters

Why Is CIPP/US the Standard U.S. Privacy Credential?

Four things that set the credential apart as state privacy laws multiply and federal enforcement keeps expanding.

An Accredited Credential From the Privacy Profession's Own Body

The CIPP/US comes from the IAPP, the association the privacy profession built for itself, and it carries ANSI National Accreditation Board accreditation under ISO/IEC 17024:2012 alongside the CIPM, CIPP/E, and CIPT. Employers writing privacy job postings ask for it by name.

No Prerequisite to Sit

The IAPP sets no experience or education requirement for the exam, and membership is optional. A paralegal, an HR generalist, or a security analyst can register the same day as a practicing attorney, which is why the credential turns up across so many job functions.

The First Half of a FIP

The IAPP's Fellow of Information Privacy designation requires a CIPP plus a CIPM, CIPT, or AIGP, and three years of work in which privacy is at least half the job. Every FIP holds a CIPP concentration, and for U.S. practitioners that usually means CIPP/US. See how the IAPP maintenance cycle compares once you hold more than one.

Where CIPP/US Stands on DoD 8140

The CIPP/US is a privacy law credential, not a cybersecurity work role qualification, so it isn't the kind of certification DoD 8140 work roles call for. Before relying on any credential for a cyber-coded position, check the current Approved Qualifications Matrix at public.cyber.mil.

Its weight comes from the law itself: HIPAA, GLBA, FCRA, COPPA, and the other federal statutes it covers are permanent fixtures, and the comprehensive state privacy laws in Domain V are where new compliance work keeps arriving.

HIPAA / GLBA / FCRA Covered CCPA / CPRA Covered ECPA / FISA Covered
Fast Facts

What Are the Key Facts About CIPP/US?

Everything you need to know about the certification, the exam structure, and how to maintain the CIPP/US as of September 2026.

01

The Certification

Certification Name
Certified Information Privacy Professional/United States (CIPP/US)
Issued By
IAPP (International Association of Privacy Professionals)
Exam Blueprint
BoK v2.6.1, approved March 3, 2025, effective September 1, 2025
Domains
Five
Prerequisites
None (no experience or education requirement)
IAPP Membership
Not required to sit the exam
Accreditation
ANAB, ISO/IEC 17024:2012
Path to FIP
CIPP plus CIPM, CIPT, or AIGP, plus 3 years experience
DoD 8140 Status
Not a DoD 8140 matrix credential
02

Exam & Maintenance

Exam Format
Multiple choice, some scenario-based, one or more correct answers
Number of Items
90 (75 scored + 15 unscored)
Exam Duration
2.5 hours plus a 15-minute break
Passing Score
300 on a 100 to 500 scale
Exam Cost
$550 first attempt (members and non-members); retakes discounted
Delivery
Pearson VUE test centers or online via OnVUE; take within 1 year of purchase
Certification Term
2 years
CPE Requirement
20 hours per credential per term
Maintenance
$250 Certification Maintenance Fee per term, or IAPP membership ($295 per year)
Going Deeper

What Comes After the CIPP/US?

The CIPP/US covers what the law requires. The IAPP's other credentials cover how to run the program, how to build privacy into technology, and how to govern AI, and any one of them paired with a CIPP completes the credential half of the FIP designation.

CIPM (Privacy Program Management)

The IAPP's "operationalizing privacy" credential: six domains under BoK v4.2.0 on building, running, and measuring a privacy program. Same exam shape as CIPP/US, 90 questions in 2.5 hours for $550, and the natural second credential for privacy managers. Training Camp runs a CIPM boot camp as well.

CIPT (Privacy in Technology)

The IAPP's "engineering privacy" credential, for the people who have to build what the law requires into systems and products. For CIPP/US holders on the IT or security side, the CIPT is the natural pairing, and it is one of the three credentials that completes a FIP.

AIGP (AI Governance)

The IAPP's "executing responsible AI governance" credential. Domain V of the CIPP/US already touches automated decision-making and AI bias laws; the AIGP takes that into a full governance program covering the EU AI Act, the NIST AI RMF, and ISO/IEC 42001, with no prerequisites of its own.

Certification Roadmap

Where Does CIPP/US Fit in Your Career?

With no prerequisites, the CIPP/US is usually the first privacy credential someone earns. Candidates arrive from legal, compliance, IT, security, HR, and marketing roles, use it as the anchor, and then specialize by what their job asks of them next.

STAGE 01

Background

Where candidates come from, none required

Legal and Compliance
Attorneys, paralegals, compliance analysts
IT and Security
Security analysts, GRC staff, data governance
HR, Marketing, Operations
Anyone handling employee or customer data
STAGE 02 You Are Here

Core Credential

The U.S. privacy law anchor

PRIMARY
CIPP/US
IAPP ยท Certified Information Privacy Professional/United States
Open Entry
No prerequisite credential, experience, or membership requirement
STAGE 03

Specialize

Pick your path, and complete a FIP

Privacy Management
Privacy Technology
AI Governance
Decision Point

Is CIPP/US Right For You?

Two questions to answer before you commit: can you certify, and should you pursue the CIPP/US specifically. Here's a straight answer to both.

Q1

Do You Qualify for CIPP/US?

Short Answer

Yes. Anyone Can Sit the Exam.

No prerequisites, no experience requirement, no membership requirement.

The IAPP sets no experience or education prerequisite for the CIPP/US, and you do not need to join the IAPP to register. Purchase the exam for $550, and you have one year to schedule and take it at a Pearson VUE test center or online through OnVUE. Once you pass, keeping the credential active does require either a membership or the Certification Maintenance Fee.

Honest Caveat

Reading Law Still Matters

Open entry doesn't mean easy entry.

Some questions are scenario-based and some have more than one correct answer, and the IAPP's own blueprint says the exam tests application and analysis, not just recall. Candidates who have never read a statute or an FTC consent order can pass, but they spend more prep time building the habit of working from the text of the law to the right answer.

Q2

Is CIPP/US the Right Certification for Your Goals?

CIPP/US Is a Strong Fit If...

  • You work in privacy, legal, or compliance for an organization that handles U.S. personal data and need to know which laws apply and what they require
  • Your employer or clients are subject to HIPAA, GLBA, FCRA, COPPA, or the comprehensive state privacy laws and you are the one who has to interpret them
  • You handle data subject requests, privacy notices, vendor agreements, or breach response and want the legal grounding behind the procedures
  • You are in HR, marketing, or IT and privacy questions keep landing on your desk without a credential to back your answers
  • You want the first half of a Fellow of Information Privacy designation
  • You want an accredited, recognized privacy credential without an experience requirement standing in the way

Consider Alternatives If...

  • Your organization's data is governed mainly by European law, where the CIPP/E concentration covers the GDPR instead of U.S. statutes
  • You run the privacy program rather than interpret the law, which is what the CIPM was written for
  • You build or secure the systems that process personal data, where CIPT or the experience-verified CDPSE sits closer to the work
  • You need a DoD 8140 matrix credential for a cyber-coded position, which a privacy law certification is not designed to satisfy
  • Your focus is AI oversight rather than privacy law, where the AIGP is the direct route
  • You want a general security foundation before any specialization, where Security+ builds the base first
Career Paths

What Jobs Can You Get With CIPP/US?

The CIPP/US maps to the roles that interpret and apply U.S. privacy law, from the analyst answering data subject requests to the executive who answers to the board for regulatory exposure.

Analysis

Privacy Analyst

Handles the day-to-day of a privacy program: data subject requests, privacy notices, vendor questionnaires, and the record keeping that shows regulators the program actually runs the way the policy says.

Program Management

Privacy Program Manager

Builds and runs the privacy program across an organization, translating HIPAA, GLBA, CCPA, and the other applicable laws into training, assessments, and controls that business teams can follow.

Legal

Privacy Counsel

Advises the business on federal and state privacy obligations, reviews data processing agreements and marketing practices, and manages the response when a subpoena, breach, or regulator inquiry arrives.

Compliance

Compliance Manager

Owns privacy compliance inside a broader regulatory function, mapping the sector rules that apply, tracking new state laws as they take effect, and keeping evidence ready for audits and enforcement inquiries.

Leadership

Chief Privacy Officer

Sets privacy strategy and accountability at the executive level, reports to the board on regulatory exposure, and decides how the organization approaches consent, data sharing, and new state requirements.

Advisory

Privacy Consultant

Helps client organizations assess where they stand against U.S. privacy law, stand up or mature a privacy program, and prepare for the state comprehensive laws that now apply to them.

Comparison

How Does CIPP/US Compare to CIPM, CDPSE, and AIGP?

Shortest version: CIPP/US is for the people who know what the law requires, CIPM is for the people who run the program, CDPSE is for the engineers who build the controls, and AIGP is for the people who govern AI.

  CIPP/US CIPM CDPSE AIGP
Issuer IAPP IAPP ISACA IAPP
Focus U.S. private-sector privacy law Privacy program management Implementing privacy in systems AI governance, law, lifecycle oversight
Prerequisites None None 3 yrs experience to certify (exam first allowed) None
Exam Format 90 questions (75 scored), 2.5 hours 90 questions (75 scored), 2.5 hours 120 questions, 3.5 hours 100 questions (85 scored), about 3 hours
Passing Score 300 (scaled 100 to 500) 300 (scaled 100 to 500) 450 (scaled 200 to 800) 300 (scaled 100 to 500)
Exam Cost $550 $550 $575 member / $760 non-member $649 member / $799 non-member
Renewal 20 CPE per 2-year term, $250 maintenance 20 CPE per 2-year term, $250 maintenance 20 CPE yearly, 120 per 3-year cycle 20 CPE per 2-year term
DoD 8140 Matrix Not a matrix credential Check the current matrix Not listed in Matrix V2.1 Not listed in Matrix V2.1
Best For Privacy analysts, counsel, compliance leads Privacy program managers Privacy engineers and architects AI governance and compliance leads

Pricing and renewal details can change and vary by membership status. CIPM figures reflect BoK v4.2.0, effective September 1, 2025, and Training Camp runs a CIPM boot camp. CDPSE and AIGP figures come from our CDPSE guide and AIGP guide. Confirm any DoD 8140 status against the current Approved Qualifications Matrix at public.cyber.mil.

Ready to Pursue the CIPP/US?

Train for CIPP/US with Training Camp.

As an Official IAPP Training Partner, we run the IAPP CIPP/US Boot Camp over two days with official IAPP courseware, the $550 exam voucher included, and a free retake if you need a second attempt, so you leave exam-ready.

View Boot Camp
Dive Deeper

CIPP/US Articles and Guides.

Privacy fundamentals, career strategy, maintenance, and how the CIPP/US sits alongside the other privacy and governance credentials.

Featured Foundations

What Is Data Privacy and Why It Matters

The foundation under the whole credential: what data privacy means in practice, who controls personal information, and why the question now reaches every department, not just legal.

Read Article โ†’
Career Strategy

Best Certifications for GRC Careers in 2026

Where a privacy law credential fits in a governance, risk, and compliance career, and how it stacks with the audit, risk, and security certifications GRC teams tend to hire for.

Read Article โ†’
Maintenance

CPE Requirements by Certification Body: A Complete Comparison

How the IAPP two-year term and 20-hour requirement compares with ISACA, ISC2, and the other bodies, useful once you hold more than one credential and the renewal calendars start to overlap.

Read Article โ†’
Comparison

Is the CDPSE Worth It? Who the Certification Is Actually For

A look at the ISACA privacy engineering credential, who it serves, and why its experience requirement and technical focus put it on a different track from a law-focused certification.

Read Article โ†’
Comparison

IAPP CIPT vs ISACA CDPSE: How to Pick the Best Privacy Engineering Certification

The two technical privacy credentials compared side by side, and how each one pairs with a CIPP for professionals who want to cover both the law and the systems that have to comply with it.

Read Article โ†’
Next Step

IAPP AIGP Certification: What It Covers and Whether It's Worth Pursuing

The IAPP credential many CIPP/US holders add next: what the AI governance exam tests, who it fits, and how it extends a privacy foundation into automated decision-making and AI oversight.

Read Article โ†’
Court Access

What the ChatGPT Privilege Ruling Means for Your Enterprise Data

A live example of the Domain III material at work: how court access, privilege, and e-discovery reach the data your organization hands to AI tools, and what privacy teams should do about it.

Read Article โ†’
Curriculum

Inside the Five CIPP/US Domains.

The CIPP/US Body of Knowledge v2.6.1 is organized into five domains. The badge on each row is the blueprint's published range of scored questions for that domain, out of 75 scored items; the IAPP publishes these as minimum and maximum counts rather than percentages. Click any domain for what it covers.

Domains I-III

Legal Environment to Government Access
I The U.S. Privacy Environment 27-33 questions

The legal groundwork: branches of government, sources of law, and concepts like jurisdiction, preemption, and private right of action, plus the roles of regulators such as the FTC, FCC, HHS, the banking regulators, and state attorneys general. The domain also covers the enforcement framework (liability theories, UDAP laws, self-regulation) and information management practice, from data inventories and vendor risk to international transfer mechanisms like Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.

II Federal Privacy Laws 15-19 questions

How the FTC polices consumer privacy under the FTC Act and COPPA, and where federal enforcement is heading on data brokers, IoT, AI, and biometrics. The domain then works sector by sector: HIPAA and HITECH in healthcare, FCRA, GLBA, the Red Flags Rule, and Dodd-Frank in finance, FERPA in education, and the TSR, TCPA, CAN-SPAM, and VPPA in telecommunications and marketing.

III Government and Court Access to Private-sector Information 3-5 questions

What happens when a subpoena, court order, or law enforcement request reaches private-sector data: the Right to Financial Privacy Act and Bank Secrecy Act for financial records, and ECPA and CALEA for communications. It also covers national security access under FISA and Section 702, the USA-PATRIOT Act, the USA Freedom Act, and the Cybersecurity Information Sharing Act, plus e-discovery and the Privacy Protection Act in civil litigation.

Domains IV-V

Workplace to State Law
IV Workplace Privacy 4-6 questions

Workplace privacy concepts and the anti-discrimination laws around them, including the Civil Rights Act, the ADA, and GINA, along with the agencies that regulate the employment relationship, from the EEOC and Department of Labor to the NLRB. The domain follows the employment lifecycle: automated employment decision tools and background screening before hiring, monitoring and internal investigations during employment, and records retention and reference requests after.

V State Privacy Laws 17-21 questions

The second-heaviest domain: how state authority relates to federal law, and the common requirements of comprehensive state privacy laws, such as applicability thresholds, exemptions, data subject rights, data protection assessments, and enforcement concepts like cure periods. It covers the CCPA as amended by the CPRA, the California Age-Appropriate Design Code and Delete Act, state health data laws like Washington's My Health My Data Act, biometric and facial recognition rules, AI bias and automated decision-making laws, and state data breach notification requirements.

Domains and scored-question ranges reflect the IAPP CIPP/US Body of Knowledge and Exam Blueprint v2.6.1, approved March 3, 2025 and effective September 1, 2025. The IAPP reviews the BoK annually, changes roughly 10 to 15 percent of exam content each year, and announces changes at least 90 days before they reach the exam. As of September 2026 no specific 2026 blueprint change has been announced.

Frequently Asked Questions

Common Questions About CIPP/US.

The questions candidates ask most often when researching the Certified Information Privacy Professional/United States certification.

What is the CIPP/US certification?

The Certified Information Privacy Professional/United States (CIPP/US) is the IAPP's certification in U.S. private-sector privacy law. It covers the U.S. legal and regulatory environment, the federal sector laws for healthcare, finance, education, and marketing, government and court access to private-sector data, workplace privacy, and state privacy laws. The IAPP describes the CIPP as the premier global credential for privacy and data protection, and CIPP/US is the concentration for professionals whose work is governed by U.S. law.

What are the five CIPP/US exam domains?

Under Body of Knowledge v2.6.1, effective September 1, 2025, the five domains are The U.S. Privacy Environment (27 to 33 scored questions), Federal Privacy Laws (15 to 19), Government and Court Access to Private-sector Information (3 to 5), Workplace Privacy (4 to 6), and State Privacy Laws (17 to 21). The IAPP publishes these as minimum and maximum scored-question counts, not percentages.

How much does the CIPP/US exam cost?

The CIPP/US exam costs $550 for a first attempt, and the price is the same for IAPP members and non-members. Retakes are discounted, though the IAPP does not publish the retake amount on its main pricing pages. You must schedule and take the exam within one year of purchase. Training Camp's 2-day CIPP/US boot camp includes the $550 exam voucher.

How many questions are on the CIPP/US exam?

The CIPP/US exam has 90 multiple-choice questions, 75 scored and 15 unscored, delivered over 2.5 hours with a 15-minute break. Some questions have more than one correct answer and some are scenario-based. Scores are scaled from 100 to 500, and 300 passes; the IAPP notes that 300 does not mean 60 percent correct. The exam is delivered year-round at Pearson VUE test centers or online through OnVUE.

Do I need a law degree or experience to take the CIPP/US?

No. The IAPP sets no experience or education prerequisite for the CIPP/US exam, and you don't need to be an IAPP member to sit it. Comfort reading statutes and regulations helps, because the exam asks you to apply the law to scenarios rather than recite it, but candidates arrive from legal, compliance, IT, security, HR, and marketing roles.

How long is the CIPP/US valid and how do I maintain it?

The CIPP/US has a two-year certification term. To keep it active you earn 20 hours of continuing privacy education per credential per term and pay either the $250 Certification Maintenance Fee or hold an IAPP membership, which runs $295 per year and includes the maintenance fee.

Is the CIPP/US approved for DoD 8140?

The CIPP/US is a privacy law credential, not a cybersecurity work role qualification, so it isn't the kind of certification the DoD 8140 work roles call for. Before relying on it for a cyber-coded position, check the current DoD 8140 Approved Qualifications Matrix at public.cyber.mil. If you need an 8140 path, see the full DoD 8140 work role paths.

CIPP/US or CIPM, which should I earn first?

Start with the one that matches your job. CIPP/US covers what U.S. privacy law requires, the IAPP's "practicing privacy" credential. CIPM covers how to build and run a privacy program, the "operationalizing privacy" credential, with six domains under BoK v4.2.0. Both are 90-question, 2.5-hour, $550 exams with no prerequisites. Holding a CIPP plus a CIPM, CIPT, or AIGP is also the credential half of the Fellow of Information Privacy designation.

How hard is the CIPP/US exam?

The difficulty is breadth. Five domains span constitutional structure, a dozen or more federal statutes, government access rules, employment law, and a fast-moving set of state laws, and the scenario questions expect you to pick the strongest answer among several defensible ones. Candidates who study from the current BoK v2.6.1 and practice applying the laws to fact patterns, rather than memorizing acronyms, tend to find it manageable.

How long does it take to prepare for the CIPP/US?

It depends on how much of the material you already work with. Attorneys and compliance professionals who deal with HIPAA, GLBA, or CCPA daily need less time than someone new to privacy law. A focused boot camp compresses the instruction into two days by working straight from the official IAPP courseware, with self-study for review before and after.

Did the CIPP/US exam change recently?

Yes. The current Body of Knowledge and Exam Blueprint is version 2.6.1, approved March 3, 2025 and effective September 1, 2025. The IAPP updates its exams annually, changing roughly 10 to 15 percent of content, and announces body of knowledge changes at least 90 days before they reach the exam. As of September 2026 no specific 2026 blueprint change has been announced, so verify any prep material against v2.6.1.

What is the Fellow of Information Privacy (FIP) designation?

FIP is the IAPP's designation for experienced, multi-credentialed privacy professionals. It requires a CIPP concentration such as CIPP/US plus a CIPM, CIPT, or AIGP, and three years of work experience in which privacy is at least half the job. For most people, CIPP/US is the first of the two credentials.

Is the CIPP/US worth it in 2026?

For anyone whose work touches U.S. personal data, yes. State comprehensive privacy laws keep taking effect, federal sector rules like HIPAA and GLBA aren't going anywhere, and employers use the CIPP/US as the standard signal that a candidate knows the law. It's ANAB accredited under ISO/IEC 17024:2012, has no prerequisites, and costs $550 to sit, which makes the return straightforward for privacy, legal, and compliance roles.

Get In Touch

Have Questions About CIPP/US?

Weighing the certification, comparing the IAPP credentials, or planning privacy training for a team: tell us where you are and we'll help you map out the right path.

+1
    100% Secure. NDA Compliant.
    IAPP CIPP/US Boot Camp 2 Days ยท Exam Voucher Included ยท Free Retake
    View Boot Camp