1.1 CIPT Exam Facts, Blueprint, and Study Plan
Key Takeaways
The CIPT has 90 multiple-choice questions in 2.5 hours with a 15-minute break that splits the exam into two halves you cannot revisit once submitted.
IAPP reports scores on a 100–500 scale and 300 passes; 300 is not 60 percent, and there are no per-domain minimums.
The exam fee is $550; IAPP's store lists $375 for candidates who have attempted the CIPT before or hold another IAPP certification, and a retake cannot be scheduled sooner than seven days after the prior attempt.
Body of Knowledge 4.0.0 (effective September 1, 2025) allots 15–19 questions to Domain I, 19–23 to Domain II, 17–21 to Domain III, 7–9 to Domain IV, and 9–11 to Domain V.
Keeping the credential requires 20 CPE credits per two-year term plus either IAPP membership ($295 a year) or the $250 Certification Maintenance Fee.
1.1 CIPT Exam Facts, Blueprint, and Study Plan
Quick Answer: The Certified Information Privacy Technologist (CIPT) exam from the IAPP has 90 multiple-choice questions, a 2.5-hour time limit with a 15-minute break, and a passing score of 300 on a 100–500 scale. It costs $550. The current Body of Knowledge (version 4.0.0) took effect on September 1, 2025 and covers five domains, from the privacy technologist's role to privacy engineering governance.
The CIPT tests whether you can turn privacy requirements into technical decisions: what to collect, how to protect and de-identify it, how to spot tracking and surveillance risks, how to design privacy into products, and how to verify that controls keep working. The credential is accredited by the ANSI National Accreditation Board (ANAB) under ISO/IEC 17024:2012, the international standard for personnel certification bodies, alongside the IAPP's CIPM, CIPP/E, and CIPP/US.
Exam Format and Logistics
| Item | Current Detail (IAPP, checked October 2026) |
|---|---|
| Questions | 90 multiple-choice questions, some based on scenarios |
| Time | 2.5 hours, with a 15-minute break offered halfway |
| Scoring | Scaled score from 100 to 500; 300 or higher passes |
| Fee | $550 (same for members and non-members) |
| Repeat or second IAPP certification | IAPP's store lists $375 if you have attempted the CIPT before or already hold another IAPP certification |
| Delivery | Pearson VUE test centers or OnVUE online proctoring |
| Purchase window | Schedule and sit the exam within one year of purchase |
| Scheduling | At least 24 hours in advance; in-person changes need 48 hours' notice |
| Results | Pass/fail and scaled score shown immediately, with a percentage breakdown by domain |
| Recommended preparation | IAPP advises a minimum of 30 hours of study |
How the Break Works
Halfway through the exam you are offered a 15-minute break. The break divides the exam into two halves, each with half the questions and half the time. Whether or not you take the break, you must submit the first half before starting the second, and you cannot return to the first half afterward. Flag and review questions inside each half.
Question Formats
IAPP exams use single-answer questions and some multiple-select questions. A multiple-select question tells you exactly how many options to choose (for example, "Select 2 of the 5 options"), and you must pick exactly that number to earn credit; there is no partial credit. Scenario questions give you a short case, often about a product team or data pipeline, followed by several questions.
Scored and Unscored Questions
IAPP exams include unscored pretest questions that look identical to scored ones. The CIPT blueprint ranges add up to 67–83 scored questions, and the remaining items on the 90-question form are unscored. IAPP's handbook says the exact split is listed on each designation's page, and its sample scoring table uses 75 scored questions. Treat every question as if it counts.
What a Score of 300 Means
Raw scores (the number of scored questions answered correctly) are converted to a common 100–500 scale so that harder and easier exam forms are treated fairly. The cut score is set through beta testing and psychometric review, then fixed at 300 on the scale. IAPP stresses that 300 does not mean 60 percent, that questions are not weighted differently, and that there is no minimum score per domain. You cannot calculate your result by averaging the domain percentages, because domains have different numbers of questions.
Retakes and Maintenance
If you do not pass, you can buy a new attempt once the result appears in MyIAPP, but you cannot schedule a date sooner than seven days after the prior attempt. After passing, the certification becomes active only when you hold IAPP membership ($295 a year) or buy the Certification Maintenance Fee ($250, covering a two-year term). You must also earn 20 continuing privacy education (CPE) credits per two-year term; up to 10 surplus credits earned in the last six months of a term can carry over.
The CIPT Blueprint: Body of Knowledge 4.0.0
The Body of Knowledge (BoK) is the exam's source of truth: IAPP says nothing appears on the exam that is not in it. Version 4.0.0 was approved on March 25, 2025, became effective on September 1, 2025, and replaced version 3.2.0. IAPP reviews each BoK annually and announces changes at least 90 days before they appear on the exam.
| Domain | Questions (min–max) | Competencies (min–max) | Guide Chapters |
|---|---|---|---|
| I. The privacy technologist's role in the context of the organization | 15–19 | I.A legal and procedural roles (5–7); I.B technical roles (5–7); I.C risk models and frameworks (1–3); I.D data ethics (2–4) | 2–5 |
| II. Data collection, use, dissemination and destruction | 19–23 | II.A collection (8–10); II.B use (6–8); II.C dissemination (4–6) | 6–8 |
| III. Privacy risk management | 17–21 | III.A intrusion and decisional interference (2–4); III.B software security (3–5); III.C tracking and surveillance (4–6); III.D workplace technologies (2–4); III.E monitoring and managing risk (3–5) | 9–13 |
| IV. Privacy by design | 7–9 | IV.A implementing PbD principles (4–6); IV.B privacy risks in user experiences (2–4) | 14–15 |
| V. Privacy engineering and privacy governance | 9–11 | V.A privacy engineering objectives (6–8); V.B managing and monitoring controls (2–4) | 16–17 |
Domains II and III together account for roughly half of the scored questions, so give them the most practice time. Domain IV is small but conceptually dense: expect questions that ask you to name the privacy by design principle or design strategy behind an engineering choice.
How Questions Are Written
The BoK lists performance indicators that begin with verbs such as understand, implement, apply, and conduct. IAPP maps these verbs to Bloom's taxonomy. "Remember/understand" questions test definitions (for example, what pseudonymization means), while "apply/analyze" questions give you a scenario and ask for the best technical choice among plausible options. Most CIPT distractors are real techniques applied to the wrong problem, so learn when each control fits, not just what it is.
A 30–45 Hour Study Plan
| Week | Focus | Guide Chapters | Hours |
|---|---|---|---|
| 1 | Roles, legal-to-technical translation, risk concepts, incident response, frameworks, ethics | 2–5 | 8–10 |
| 2 | Collection, retention, minimization, segregation, PETs, secondary use, dissemination controls | 6–8 | 10–12 |
| 3 | Dark patterns, software risk, tracking and surveillance, AI and workplace tech, audits and PIAs | 9–13 | 8–12 |
| 4 | Privacy by design, UX, NIST objectives, lineage and transfers, SDLC, inventories, code review, monitoring; timed practice | 14–17 | 6–10 |
Exam-day tactics:
- Budget about 1 minute 40 seconds per question (150 minutes ÷ 90 questions), and finish each half with a few minutes to review flagged items.
- In scenario questions, identify the data action first (collection, use, disclosure, retention, or destruction), then pick the control that addresses that action most directly.
- Prefer answers that reduce risk at the source (not collecting, minimizing, de-identifying) over answers that only add policy or paperwork, unless the question asks about governance.
A candidate finishes the CIPT and sees a scaled score of 300. What does this result mean?
The candidate answered exactly 60 percent of the scored questions correctly, which is the cut score.
The candidate passed, because 300 is the minimum passing score on IAPP's 100–500 scale.
The result is provisional until IAPP averages the domain percentages to confirm the outcome.
The candidate failed, because the CIPT also requires a minimum score in every domain.
During the CIPT, a candidate takes the 15-minute break and then realizes an answer from question 20 is wrong. What can the candidate do?
Nothing; the first half was already submitted and cannot be reopened.
Ask the proctor to reopen the first half for the remaining time.
Change the answer during the break, because the exam timer is paused while the break runs.
Return to question 20 from the final review screen before submitting the second half.
Under CIPT Body of Knowledge 4.0.0, which domain has the largest published question range?
Domain III, privacy risk management (17–21 questions)
Domain I, the privacy technologist's role in the context of the organization (15–19 questions)
Domain V, privacy engineering and privacy governance (9–11 questions)
Domain II, data collection, use, dissemination and destruction (19–23 questions)
Sections you finish are checked off in the contents.