CIPT
What is on the IAPP CIPT exam, and where should your study hours go?
The IAPP's CIPT exam is 90 multiple-choice questions in 2.5 hours, scored from 100 to 500 with 300 to pass. Its Body of Knowledge, version 4.0.0, effective 1 September 2025, has five domains, down from seven in the version before it, and two carry most of the weight: data collection, use, dissemination and destruction (19 to 23 questions) and privacy risk management (17 to 21).
The facts below come from the IAPP's Privacy Candidate Handbook, version 5.3.2, its certification FAQs, the CIPT page and its Body of Knowledge, and the IAPP Store, all read on 2 October 2026. The study hours are ours.
Which version of the CIPT blueprint applies?
Version 4.0.0, approved on 25 March 2025 and effective 1 September 2025, which replaced version 3.2.0. The change matters because 3.2.0 had seven domains, including foundational principles, privacy engineering and evolving technologies as separate blocks, and 4.0.0 has five.
On 2 October 2026 the IAPP's CIPT page still carried a second, unlabeled link to the old 3.2.0 file, while its visible "Learn more" button went to 4.0.0. If a course, a summary or an AI answer gives you seven CIPT domains, it was built from the superseded file.
How is the CIPT exam structured?
90 questions in 2.5 hours averages 1 minute 40 seconds each. Halfway through you are offered a 15-minute break, which splits the exam into two halves of 45 questions and 75 minutes; once you submit the first half, you cannot return to it.
All IAPP exams are multiple choice with one or more correct answers. A multi-select question says how many to choose, such as "Select 3 of the 5 options below", and there is no partial credit. Some questions follow a scenario. Scores run from 100 to 500, 300 passes, and the IAPP's FAQ says 300 "does not represent 60%".
IAPP Privacy Candidate Handbook v5.3.2; IAPP Certification FAQs
The CIPT is offered in English, at a Pearson VUE test center or online through OnVUE. The result shows on screen when you finish, with the percentage you scored in each domain.
Which CIPT domains carry the most questions?
| Domain | Questions |
|---|---|
| I. The privacy technologist's role in the context of the organization | 15 to 19 |
| II. Data collection, use, dissemination and destruction | 19 to 23 |
| III. Privacy risk management | 17 to 21 |
| IV. Privacy by design | 7 to 9 |
| V. Privacy engineering and privacy governance | 9 to 11 |
Below the domains sit 16 competencies. The largest is II.A, minimizing privacy risk during personal data collection, with 8 to 10 questions. Minimizing risk during data use (II.B) and the privacy engineering objectives (V.A) follow at 6 to 8 each. Privacy by design looks small as a domain, but its first competency, implementing the principles, carries 4 to 6 on its own. The competency ranges do not add up to the domain ranges, so read each figure as printed.
What does the current Body of Knowledge name?
Version 4.0.0 is specific about the models it expects you to know. Under privacy risk models it names Nissenbaum's contextual integrity, Calo's harms dimensions, the FAIR model, the NIST/NICE framework, the FIPPs and the OECD principles, and the threat models LINDDUN and MITRE PANOPTIC. Under data use it names anonymization, pseudonymization and differential privacy. The workplace technologies competency asks you to minimize privacy risks when "using artificial intelligence, machine learning and deep learning", and the engineering competency names the NIST privacy engineering objectives: predictability, manageability and dissociability.
Read the primary texts for the engineering and design domains: the NIST Privacy Framework, and the European Data Protection Board's Guidelines 4/2019 on data protection by design and by default. The IAPP's own textbook for the CIPT is "An Introduction to Privacy for Technology Professionals".
How should you split your CIPT study hours?
The IAPP recommends at least 30 hours. Split them by the midpoint of each domain's range; the midpoints add up to 75, so on 30 hours each is worth 24 minutes.
| Domain | Midpoint | 30-hour plan |
|---|---|---|
| I. The privacy technologist's role | 17 | 6 h 45 min |
| II. Data collection, use, dissemination and destruction | 21 | 8 h 30 min |
| III. Privacy risk management | 19 | 7 h 30 min |
| IV. Privacy by design | 8 | 3 h 15 min |
| V. Privacy engineering and privacy governance | 10 | 4 h |
| Total | 75 | 30 h |
Each figure is rounded to the nearest quarter hour, and the column still adds up to 30. The planner has the same split for 45 and 60 hours and a checklist of all 16 competencies. Our suggestion: start with II.A, II.B and V.A, which can supply up to 26 questions between them.
CIPT study planner
IAPP CIPT: study planner
Question ranges come from the IAPP CIPT Body of Knowledge, version 4.0.0, effective 1 September 2025, read on 2 October 2026. The 30-hour minimum is the IAPP's recommendation (IAPP Certification FAQs). The hours are our suggestion: each domain gets a share in proportion to the midpoint of its published range. Check the IAPP's CIPT page before you start in case the Body of Knowledge has changed.
Hours by domain
The midpoints add up to 75, so on 30 hours each midpoint question is worth 24 minutes.
| Domain | Range | Midpoint | 30 hours | 45 hours | 60 hours |
|---|---|---|---|---|---|
| I. The privacy technologist's role in the context of the organization | 15 to 19 | 17 | 6.75 | 10.25 | 13.5 |
| II. Data collection, use, dissemination and destruction | 19 to 23 | 21 | 8.5 | 12.5 | 16.75 |
| III. Privacy risk management | 17 to 21 | 19 | 7.5 | 11.5 | 15.25 |
| IV. Privacy by design | 7 to 9 | 8 | 3.25 | 4.75 | 6.5 |
| V. Privacy engineering and privacy governance | 9 to 11 | 10 | 4 | 6 | 8 |
| Total | 75 | 30 | 45 | 60 |
Hours are in quarter hours: 0.25 is 15 minutes, 0.5 is 30 minutes and 0.75 is 45 minutes. Domains are rounded to quarter hours so that every column adds up to its budget.
Pace for timed practice
| Set | Questions | Time at the exam's average pace |
|---|---|---|
| One question | 1 | 1 minute 40 seconds |
| Short timed set | 18 | 30 minutes |
| One half of the exam | 45 | 75 minutes |
| Full exam | 90 | 2.5 hours |
Competencies, largest first
The IAPP prints a range for each competency as well as each domain. The competency ranges do not add up to the domain ranges, so read each figure on its own.
| Competency | Range | Read | Studied | Practiced |
|---|---|---|---|---|
| II.A Demonstrate how to minimize privacy risk during personal data collection | 8 to 10 | [ ] | [ ] | [ ] |
| II.B Demonstrate how to minimize privacy risk during personal data use | 6 to 8 | [ ] | [ ] | [ ] |
| V.A Understand and implement privacy engineering objectives | 6 to 8 | [ ] | [ ] | [ ] |
| I.A Identify and implement legal and procedural roles and responsibilities | 5 to 7 | [ ] | [ ] | [ ] |
| I.B Identify and implement technical roles and responsibilities | 5 to 7 | [ ] | [ ] | [ ] |
| II.C Demonstrate how to minimize privacy risk during personal data dissemination | 4 to 6 | [ ] | [ ] | [ ] |
| III.C Understand the privacy risks and impact of techniques that enable tracking and surveillance | 4 to 6 | [ ] | [ ] | [ ] |
| IV.A Implement privacy by design principles | 4 to 6 | [ ] | [ ] | [ ] |
| III.B Identify privacy risks related to software security | 3 to 5 | [ ] | [ ] | [ ] |
| III.E Demonstrate how to monitor and manage privacy risk | 3 to 5 | [ ] | [ ] | [ ] |
| I.D Understand the connection between data ethics and data privacy | 2 to 4 | [ ] | [ ] | [ ] |
| III.A Demonstrate how to minimize the threat of intrusion and decisional interference | 2 to 4 | [ ] | [ ] | [ ] |
| III.D Understand the privacy risks and impact involved when using workplace technologies | 2 to 4 | [ ] | [ ] | [ ] |
| IV.B Evaluate privacy risks in user experiences | 2 to 4 | [ ] | [ ] | [ ] |
| V.B Manage and monitor privacy-related functions and controls | 2 to 4 | [ ] | [ ] | [ ] |
| I.C Demonstrate knowledge of privacy risk models and frameworks and their roles in legal requirements and guidance | 1 to 3 | [ ] | [ ] | [ ] |
Before exam day
- Hours booked in the calendar for your column (our suggestion)
- At least one timed half: 45 questions in 75 minutes (our suggestion)
- Multi-select questions practiced: the exam asks for an exact number of answers and gives no partial credit (IAPP)
- Exam booked at least 24 hours ahead, inside one year of purchase (IAPP rule)
What does the CIPT cost, and what are the rules?
The exam is USD 550 on the IAPP Store for members and non-members alike, or USD 375 if you have attempted it before or hold another IAPP certification. You must sit within one year of buying it, and book at least 24 hours ahead. After passing, the certification is activated by a USD 250 maintenance fee per two-year term or by IAPP membership at USD 295 a year, and you need 20 CPE credits per term. If you do not pass, you can book again no sooner than seven days after the previous attempt.
How should you prepare?
The CIPT exam guide maps to all five domains and 16 competencies of the September 2025 Body of Knowledge, and it is written for engineers rather than lawyers. For practice, the 200 CIPT practice questions with rationales are weighted to the published ranges. They are single-answer questions, so add multi-select practice from the IAPP's own materials before the day.
What should you do this week?
Download the Body of Knowledge from the CIPT page's visible button and check that it says version 4.0.0. Then take the planner's column for your budget and book your hours. Credential Press is independent of the IAPP, and nothing here comes from inside the exam.
Frequently asked questions
How many questions are on the CIPT exam?
90 multiple-choice questions in 2.5 hours, according to the IAPP's certification FAQ and exam store page. Some ask for more than one answer and say so, with no partial credit.
What is the CIPT pass mark?
300 on a scale of 100 to 500. The IAPP says 300 does not represent 60%.
How many domains does the CIPT have?
Five, in Body of Knowledge version 4.0.0, effective 1 September 2025. The superseded version 3.2.0 had seven, so material that lists seven domains is out of date.
Which CIPT domain has the most questions?
Domain II, Data collection, use, dissemination and destruction, with 19 to 23 questions. Its competency on minimizing privacy risk during collection (8 to 10) is the largest on the blueprint.
How should I split my CIPT study hours?
By the midpoint of each domain's range: 17, 21, 19, 8 and 10, which add up to 75. On 30 hours that is 6 h 45 min, 8 h 30 min, 7 h 30 min, 3 h 15 min and 4 h.
How much does the CIPT cost?
USD 550 on the IAPP Store, the same for members and non-members, or USD 375 if you have attempted the exam before or hold another IAPP certification.
CIPT: test yourself in five minutes
Which books prepare you for the CIPT?

Certified Information Privacy Technologist. 17 chapters, 450 pages.

Practice questions with full rationales, weighted to the published blueprint. 216 pages.
Sources
Every IAPP figure above was read from the document itself on 2 October 2026. The study hours are our arithmetic on those figures.
- IAPP, CIPT certification page and Body of Knowledge, version 4.0.0, effective 1 September 2025
- IAPP, Privacy Candidate Handbook, version 5.3.2
- IAPP, Certification FAQs
- IAPP Store, CIPT exam
- NIST, Privacy Framework
- European Data Protection Board, Guidelines 4/2019 on Article 25, Data Protection by Design and by Default
Credential Press is not affiliated with, endorsed by or authorized by the IAPP. Exam names and trademarks belong to their owners.