1.2 BoK 2.6.1, Scoring, Activation, CPE, and 2026 Updates

Key Takeaways

  • Body of Knowledge 2.6.1, approved 3 March 2025 and effective 1 September 2025, is the current official CIPP/US outline; IAPP has not posted an autumn-2026 replacement
  • Official blueprint ranges are Domain I 27–33, II 15–19, III 3–5, IV 4–6, and V 17–21 questions
  • Scaled scores run 100–500 with a 300 pass; domain percentages cannot be averaged into the overall score
  • Passing does not activate CIPP/US until you hold IAPP membership or pay the $250 two-year Certification Maintenance Fee; FAQ membership is USD 295 annually and includes the CMF
  • Each certification needs 20 CPE credits per two-year term; know 1 January 2026 IN/KY/RI laws, CPPA regs effective that day with ADMT significant-decision compliance on 1 January 2027, DROP’s 1 January 2026 consumer launch, and the 1 August 2026 broker processing duty
Last updated: August 2026

BoK 2.6.1 Is the Current Official Outline

The CIPP/US exam is built from the CIPP/US Body of Knowledge and Exam Blueprint, not from a vendor syllabus and not from last year’s blog outline. The current official version is 2.6.1. The CIPP/US Exam Development Board approved it on 3 March 2025. It became effective 1 September 2025 and supersedes 2.6.

As of mid-August 2026, IAPP has not posted an autumn-2026 replacement. There is no public BoK 2.7 on the CIPP/US designation page. IAPP’s handbook says body-of-knowledge and exam updates are announced at least 90 days before new content appears. Until a new PDF is posted on that page, 2.6.1 is the outline you study.

The BoK does two jobs. First, it lists competencies (clusters of tasks) and performance indicators (the discrete abilities those clusters contain). Exam items measure those indicators. Verbs such as identify, evaluate, and apply tell you the item will not stop at a definition. Second, it publishes blueprint minimum and maximum question counts for each domain. Those ranges are the only official statement of how the 90-item form is carved up.

Nothing appears on the exam that is not on the BoK. IAPP training, the U.S. Private-Sector Privacy textbook, and third-party courses are tools for learning the BoK. They are not a second outline. ANAB/ISO 17024 separation means instructors cannot confirm that a particular item will appear.

IAPP also expects candidates to know important new privacy changes that may modify the texts of the laws and regulations the BoK names. The outline can stay 2.6.1 while statutes, regulations, and enforcement platforms change. That is how 1 January 2026 developments stay in scope even though the PDF’s version number did not increment.

Five Domains and the Official Min–Max Ranges

Blueprint numbers are ranges, not a promise that your form will hit the midpoint. A form may sit at the low end of Domain III and the high end of Domain I on the same day.

DomainOfficial titleMinMaxWhat the domain actually tests
IThe U.S. Privacy Environment2733Legal structure, enforcement theory, and information-management principles, including international transfers
IIFederal Privacy Laws1519Federal Trade Commission (FTC) consumer privacy plus sectoral federal statutes in health, finance, education, and telecom/marketing
IIIGovernment and Court Access to Private-sector Information35Law-enforcement, national-security, and civil-litigation access to private-sector data
IVWorkplace Privacy46Pre-employment screening, monitoring, investigations, and post-employment records
VState Privacy Laws1721Federal/state authority, comprehensive state frameworks, sectoral state rules, and breach notification

Domain I is the largest sitting. Inside it, the BoK further allocates I.A 3–5, I.B 5–7, and I.C 18–22. Information management (I.C)—inventories, vendors, notices, tracking, Schrems transfer case law, Standard Contractual Clauses (SCCs), the EU-U.S. Data Privacy Framework (DPF), and intersections with the General Data Protection Regulation (GDPR) and Switzerland’s Federal Act on Data Protection (FADP)—is the heavy lift inside the already-largest domain.

Domain V is the second-largest block and the fastest-moving. Most of those items sit in competency V.B (13–17): applicability thresholds, consumer rights, assessments, sale/sharing, health-data statutes, biometrics, automated decisionmaking technology (ADMT) / AI-bias rules, California’s California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) / Delete Act stack, and the other comprehensive state laws. Domain III is only 3–5 questions, but those items are dense—Right to Financial Privacy Act (RFPA), Bank Secrecy Act (BSA), Electronic Communications Privacy Act (ECPA), Foreign Intelligence Surveillance Act (FISA) Section 702, and e-discovery. A four-question domain can still decide a close sitting because there is no separate section pass mark; every scored item feeds one scale.

Use the ranges to budget study hours, not to skip “small” domains. If you are strong on California and weak on FISA 702, you are leaving cheap Domain III points on the table while over-investing in a domain that already dominates the form.

How Scaled Scoring Works — And How It Does Not

Raw correct answers on scored items are converted to the 100–500 scale so forms of slightly different difficulty remain comparable. 300 passes. A perfect scored performance is 500. A 100 is the floor for very low raw scores. Do not treat 300 as 60%.

The handbook’s conversion table—50 correct maps to 300, 75 correct maps to 500—is labeled a fictional scale example. It teaches the shape of a one-to-one conversion. It is not CIPP/US’s live scoring key, and it is not a claim that your form has 75 scored items.

Your score report shows percent correct by blueprint domain. Use those percentages as a retake map: a 40% in Domain V means you restudy state thresholds, rights, and California’s 2026 regulations, not that you “almost averaged to a pass.” You cannot average domain percentages into the overall scaled score. Domains are unequal. A 90% on a 4-question domain and a 50% on a 30-question domain are not “70% overall.” IAPP also does not give you the raw number of questions answered correctly.

There is no per-domain passing requirement. Weak Domain III does not automatically fail you if the scored total still maps to 300 or higher. The reverse is also true: a strong Domain I cannot rescue you if the remaining scored items fall short of the cut. Guessing on an unanswered item is always better than leaving it blank, because only correct scored answers add to the raw total that the scale converts.

Passing Does Not Activate the Credential

A 300+ result means you passed the exam. It does not, by itself, put CIPP/US on IAPP’s public listing or trigger a certificate. IAPP’s store, FAQ, and handbook all say the same thing: you must hold IAPP membership or pay a Certification Maintenance Fee (CMF) before the certification is valid.

The store CMF is $250 per two-year certification term. The Certification FAQ lists professional membership at USD 295 annually. Membership includes the CMF and adds member benefits (KnowledgeNet chapter meetings, Resource Center access, event and training discounts). A standalone CMF does not include those benefits. Non-members are encouraged to buy the CMF with the exam so activation is automatic on a pass. If you pass with neither membership nor a CMF on file, you wait: no public credential, no Accredible digital certificate, no right to use the letters.

Think of three separate purchases. The $550 exam proves knowledge. The membership or $250 CMF turns a pass into an active certification. The next term’s CMF (or continued membership) plus CPE keeps it active. Do not tell an employer you “are CIPP/US” on the strength of an on-screen 300 if the CMF is still in the cart.

CPE: 20 Credits Per Certification Per Term

Activation starts a two-year term. To stay in good standing you must do both of the following:

  1. Pay the CMF again for the new term, or keep IAPP membership current (which covers the CMF).
  2. Earn 20 Continuing Privacy Education (CPE) credits per certification per term.

If you later add CIPM, CIPT, or another IAPP certification, the 20-credit requirement applies per certification, not once for your whole IAPP portfolio. IAPP events and webinars often post automatically to your MyIAPP account. Other activities are self-reported on the CPE submission form. Failure to pay or to meet CPE suspends the credential and requires reinstatement under the CPE policy.

The exam sitting is not 20 CPE. A January 2026 pass does not waive maintenance. Build a two-year plan the week you activate: IAPP KnowledgeNet sessions, documented reading, teaching, or work projects that the CPE policy accepts.

2026 Legal Developments You Must Know Under BoK 2.6.1

Because IAPP expects knowledge of important changes that modify the texts, treat these 2026 events as live exam content even though the posted outline is still 2.6.1. Separate effective dates from compliance dates. Collapsing them is a common Domain V miss.

Indiana, Kentucky, and Rhode Island comprehensive privacy laws became applicable. Indiana and Kentucky follow a Virginia-style coverage threshold: control or process personal data of 100,000 consumers, or derive 50% of revenue from selling the data of more than 25,000 consumers. Both include data-protection assessments, opt-outs for targeted advertising and sales, and a 30-day cure. Rhode Island is different on purpose. It covers entities that control or process personal information of more than 35,000 residents, or more than 10,000 residents while generating 20% of gross revenue from personal-data sales. It has data-subject rights and assessment duties, but it omits a cure period and does not require recognition of universal opt-out mechanisms.

California Privacy Protection Agency (CPPA) regulations on risk assessments, cybersecurity audits, and automated decisionmaking technology (ADMT) became effective 1 January 2026. Effective is not the same as fully operational. Businesses that use ADMT to make significant decisions—employment, housing, financial services, education, or healthcare—must comply beginning 1 January 2027. Do not treat pre-use notice, ADMT opt-out, and ADMT-access rights as if they were already mandatory on New Year’s Day 2026. Risk-assessment duties are prospective from 1 January 2026: new covered processing after that date must be assessed. Assessments of legacy processing come later. First risk-assessment submissions to CPPA—an attestation that required assessments were completed, plus a summary—are due 1 April 2028. Cybersecurity-audit certifications are later still and staggered by revenue: 1 April 2028 if the business makes over $100 million, 1 April 2029 for $50–$100 million, and 1 April 2030 if it makes less than $50 million. The substance of the ADMT rules remains exam-relevant: opt-outs when the technology replaces or substantially replaces human decision-making, and a human reviewer who can interpret the output and change or correct the decision. Risk-assessment triggers still include selling or sharing personal information, processing sensitive personal information, using ADMT for a significant decision, using personal information to train ADMT for certain uses, and using automated processing to infer attributes in education, job-seeking, employment, or independent-contracting contexts. Cybersecurity-audit rules define when a “significant risk” requires an audit and what “reasonable” security measures look like. Keep the calendar straight: regs effective 1 January 2026; ADMT significant-decision compliance 1 January 2027; risk-assessment work starts 1 January 2026 with first filings 1 April 2028.

The California Delete Act Delete Request and Opt-out Platform (DROP) is a two-date story. On 1 January 2026, DROP launched for California consumers, who can submit a single deletion request aimed at every registered data broker. That launch does not mean brokers had to process deletions the same day. Beginning 1 August 2026, data brokers must access DROP at least every 45 days and process deletion requests (Cal. Civ. Code § 1798.99.86(c)). CPPA’s broker page is explicit: registering brokers were not required to begin processing consumer deletion lists until August 2026, and the first 45-day access window starts on 1 August. Annual broker registration still runs 1–31 January (2026 fee $6,000 plus processing), and brokers must register their own trade names and sites rather than hide behind a parent. Per-violation Delete Act penalties can dwarf a simple failure-to-register fine once the August processing duty attaches.

Do not invent a posted autumn-2026 BoK that retires these topics or replaces 2.6.1. If IAPP publishes a new version, it will appear on the CIPP/US page with a 90-day runway. Until that posting exists, the correct study set is BoK 2.6.1 + these 2026 legal developments.

Lifecycle sequence to memorize

  • Study the five 2.6.1 domain ranges; do not wait for an unpublished 2.7.
  • Pass at 300 on the 100–500 scale; do not average section percentages.
  • Activate with membership (FAQ: USD 295/year, includes CMF) or a $250/two-year CMF.
  • Maintain 20 CPE credits per certification per term.
  • Keep 1 January 2026 IN/KY/RI laws, CPPA regs effective that day (ADMT significant-decision compliance 1 January 2027; risk assessments prospective from 2026 with first filings 1 April 2028), DROP’s 1 January consumer launch, and the 1 August 2026 broker processing duty in your Domain V working memory.
Test Your Knowledge

Which statement correctly describes CIPP/US Body of Knowledge 2.6.1?

A
B
C
D
Test Your Knowledge

After you pass the CIPP/US exam, when does the credential become active?

A
B
C
D
Test Your Knowledge

Which statement correctly describes the 2026 U.S. privacy changes CIPP/US candidates must know even though BoK 2.6.1 remains the posted outline?

A
B
C
D