The CIPP certification exam costs $550. That is the number the IAPP store shows, and it is the number almost every article quotes. It is also not what you will actually pay, because a CIPP is not active until you have either an IAPP membership or a paid certification maintenance fee sitting behind it.
This guide gives you the real 2026 cost of a CIPP certification, the difference between the CIPP/US and CIPP/E exams as their blueprints actually define them, and a straight answer on who should bother.
What CIPP Certification Actually Is
CIPP stands for Certified Information Privacy Professional. It is issued by the IAPP, the International Association of Privacy Professionals, and it is a law-and-regulation credential rather than a technical one. You are being tested on what the rules require, not on how to configure anything.
The important structural point is that CIPP is not one exam. The IAPP offers five regional concentrations, covering Asia, Canada, China, Europe and the United States. You sit the one that matches the jurisdiction you work in, and the letters after the slash tell people which body of law you were tested on.
Three other IAPP credentials sit alongside it and get confused with it constantly:
- CIPM (Certified Information Privacy Manager) covers running a privacy programme rather than knowing the law.
- CIPT (Certified Information Privacy Technologist) is the engineering-side credential.
- AIGP (Artificial Intelligence Governance Professional) covers AI governance, and is the newest of the set.
The CIPM, CIPP/E, CIPP/US and CIPT credentials are accredited by the ANSI National Accreditation Board (ANAB). That accreditation is a reasonable proxy for whether a certification body is running a defensible exam programme.
Exam Tip: Watch out for the acronym collision when you research this. CFA Institute runs a completely unrelated CIPM in investment performance measurement, and there are procurement and HR credentials using both CIPP and CIPM. If a search result is talking about portfolio returns, you are on the wrong page.
CIPP Certification Cost in 2026: The Full Breakdown
Here is every fee involved, taken from the IAPP store and the IAPP's certification policies.
| Item | Cost (USD) | Notes |
|---|---|---|
| CIPP exam (any concentration) | $550 | Same price for CIPP/US, CIPP/E, CIPP/A, CIPP/C and CIPP/CN |
| CIPM exam | $550 | Same price point |
| CIPT exam | $550 | Same price point |
| AIGP exam | $799 | The outlier, and the newest credential |
| Certification Maintenance Fee (CMF) | $250 | Covers one two-year certification term |
| IAPP membership | $295 per year | Includes the CMF as a membership benefit |
The catch is in the last two rows. Before you buy an exam, note that either IAPP membership or a certification maintenance fee is required for your certification to become active when you pass. Passing alone does not give you an active credential.
That produces two realistic first-year figures:
- $800 if you pay the exam fee plus a standalone $250 CMF for your first two-year term.
- $845 if you pay the exam fee plus a year of IAPP membership at $295, which absorbs the CMF.
Membership looks like the worse deal on a single certification in year one, and it is, by $45. It stops being the worse deal the moment you hold more than one IAPP credential or want the member pricing and resources, because the CMF is charged per certification term while membership covers you as a person.
The Cost People Forget
Two smaller things catch candidates out.
All IAPP exams must be scheduled and taken within one year of purchase. Expired exams are closed and the fees are forfeited. Buying an exam voucher during a promotion and then letting your study slip is a $550 mistake, not a delay.
Retakes are a second full purchase, and you cannot schedule a retake sooner than seven days after your prior attempt. Budget for one attempt and study properly rather than treating the first sitting as a reconnaissance run.
CIPP/US vs CIPP/E: What Actually Differs
Both exams are 90 questions in 2.5 hours, both cost $550, and both are scored identically. The difference is entirely in the body of law and how the blueprint distributes questions across it.
The IAPP publishes minimum and maximum question counts per domain rather than percentage weightings, which is more useful than it sounds because it tells you exactly how many marks are genuinely at stake.
CIPP/US domains and question ranges:
| Domain | Questions |
|---|---|
| I. The U.S. Privacy Environment | 27 to 33 |
| II. Federal Privacy Laws | 15 to 19 |
| III. Government and Court Access to Private-sector Information | 3 to 5 |
| IV. Workplace Privacy | 4 to 6 |
| V. State Privacy Laws | 17 to 21 |
CIPP/E domains and question ranges:
| Domain | Questions |
|---|---|
| I. Introduction to European Data Protection | 7 to 13 |
| II. European Data Protection Law and Regulation | 18 to 28 |
| III. European Data Processing | 13 to 21 |
| IV. European Data Protection: Scope and Accountability | 8 to 18 |
| V. Compliance with European Data Protection Law and Regulation | 8 to 16 |
Read those tables as a study plan rather than a description.
On CIPP/US, Domains I and V together account for up to 54 of the questions. The US privacy environment and state privacy laws are the exam. Domain III, government and court access to private-sector information, tops out at five questions, so a candidate who spends a fortnight on subpoena law and skims state privacy statutes has optimised backwards.
On CIPP/E, Domain II can reach 28 questions on its own, and the GDPR-based processing content in Domain III can reach 21. The European exam is also noticeably less lopsided than the US one, with every domain capable of carrying at least eight questions. There is less scope to write off a domain.
Pick by jurisdiction, not by difficulty. If your work touches US federal and state privacy law, sit CIPP/US. If you are handling pan-European and national data protection law and the GDPR, sit CIPP/E. Holding both is common in multinational privacy teams and is usually a sequencing question rather than an either-or.
How the CIPP Exam Is Scored
This trips up more candidates than the content does.
All core IAPP exams are scored on a scale from 100 to 500, with a passing score of 300 or above. The IAPP is explicit that 300 does not represent 60 percent.
The passing score is set by beta testing, psychometric analysis and review by an exam development board, and that standard is then anchored to 300 on the reporting scale. Answering every scored question correctly produces a 500. A score of 100 represents a range of low scores below the scope of the scale.
The practical consequence: do not try to back-calculate your result by averaging the section percentages in your score report. The IAPP says so directly, and candidates who do it panic over nothing.
Exam Tip: Your Pass or Fail result and your score appear on screen immediately when you finish. Allow up to two business days for the result to reflect in the IAPP system before you go looking for your credential.
The exam also contains unscored questions alongside the scored ones, which is why the blueprint's maximum question counts do not add up to 90. The number of scored and unscored questions is published on each designation's page.
Requirements, Renewal and What It Costs to Keep
There are no formal prerequisites. You do not need a law degree, a privacy job title or a set number of years in the field to sit a CIPP exam. The IAPP recommends a minimum of 30 hours of study time, which is a floor rather than a realistic target for anyone new to the subject matter.
Renewal is where the ongoing cost lives:
- The certification term is two years.
- You need 20 CPE credits per certification over that two-year term.
- You must pay the $250 CMF for the term, or hold active IAPP membership, which includes it.
- You may carry over a maximum of 10 surplus credits per certification, and only for credits earned in the final six months of the term.
The genuinely good news for anyone stacking IAPP credentials: individuals with more than one IAPP certification can apply CPE credits to all of their IAPP certifications. One qualifying webinar counts once per credential rather than needing to be repeated. That changes the maths on adding a CIPM or CIPT later far more than the exam fee does.
If your membership lapses mid-term, or the CMF for the next term goes unpaid, the certification is suspended. A term that reaches its end date in suspended status is revoked.
Is CIPP Certification Worth It?
It is worth it in one specific situation: your role requires you to know what a privacy law obliges your organisation to do, and you need a credential that a regulator, a client or a hiring manager recognises without explanation. Privacy counsel, DPOs, compliance leads, in-house lawyers moving into privacy and GRC analysts covering data protection all sit squarely in that group.
It is a poor fit if you were hoping for a technical credential. CIPP does not test tooling, architecture or engineering controls. CIPT exists for that, and a security professional looking to broaden into governance is often better served by a GRC certification or, if the work is AI-facing, by AIGP.
The honest limitation is jurisdictional. A CIPP/US tells an employer you know US federal and state privacy law. It says very little about your ability to run a GDPR compliance programme, which is what the separate CIPP/E exists to prove. Buying the wrong concentration is the most expensive mistake available here, and it costs $550 to correct.
For a side-by-side of all five IAPP credentials, see our guide to which IAPP certification to take in 2026.
Frequently Asked Questions
Is the CIPP certification worth it?
It is worth it if privacy law is part of your job description and you need recognised proof that you know it. The credential is ANAB-accredited for CIPP/E and CIPP/US, and it is the default privacy qualification that privacy teams, law firms and regulators recognise. It is not worth it as a general cybersecurity credential, because it tests law rather than technical controls.
Is the CIPP exam difficult?
It is difficult in a specific way: the content is dense legal material, and the blueprint is lopsided, so candidates who study evenly across all five domains waste effort. The IAPP recommends a minimum of 30 hours of study. Passing requires 300 on a 100 to 500 scale, which is a criterion-referenced standard set by an exam development board, not a 60 percent pass mark.
How much does it cost to get CIPP certified?
The exam is $550. On top of that you need either a $250 certification maintenance fee or IAPP membership at $295 a year for the certification to become active. Realistically, budget $800 to $845 for your first two-year term, and $250 per term afterwards if you are not a member.
Which is better, CIPP or CIPM?
Neither is better, they test different things. CIPP tests what a body of privacy law requires. CIPM tests how to build and run a privacy programme. Both are 90-question, 2.5-hour, $550 exams. If you advise on what the rules say, take CIPP. If you own the programme that implements them, take CIPM. Holding both is common, and CPE credits count towards both once you do.
Do CIPP exam objectives change?
Yes. The body of knowledge is reviewed and, if necessary, updated every year, and any changes are communicated to candidates at least 90 days before the new content appears in the exam. Check the current body of knowledge and exam blueprint on the IAPP site before you buy, especially if you are working from a study guide bought more than a year ago.
Ready to Start Practising?
Reading the body of knowledge tells you what is on the exam. Answering questions under time pressure tells you whether you actually know it, and on an exam where 90 questions arrive in 2.5 hours, pacing is a skill in itself.
CertCrush builds practice exams, study guides and flashcards for privacy, governance and security certifications, including the IAPP's AIGP credential. Browse the full course catalogue to see what is covered, or create a free account and start practising today.
