CIPP/US (Certified Information Privacy Professional/United States)

IAPP (International Association of Privacy Professionals)

Complete guide to passing the CIPP/US (Certified Information Privacy Professional/United States) exam on your first attempt.

HardHigh Search Volume
Key Information at a Glance
Cost

$550

Pass Rate

Not published

Validity

2 years (20 CPEs plus a maintenance fee or IAPP membership)

Region

USA

Provider

IAPP (International Association of Privacy Professionals)

Salary Impact

$81k-$160k

Are you ready for CIPP/US (Certified Information Privacy Professional/United States)?

Loading quiz...

Complete Overview

The Certified Information Privacy Professional/United States (CIPP/US) is the US concentration of the IAPP CIPP credential, and it tests knowledge of US privacy law across federal statutes, state statutes, workplace privacy and government access to private-sector data. The exam is 90 multiple-choice questions with an allotted time of 2.5 hours and a 15-minute break, and it costs 550 USD at the same price for IAPP members and non-members. Candidates must schedule and complete the exam within one year of purchase or forfeit the fee.

IAPP publishes an exam blueprint rather than percentage weights. The blueprint gives a minimum and maximum question count for each of the five domains: Domain I, The U.S. Privacy Environment, at 27 to 33 questions; Domain II, Federal Privacy Laws, at 15 to 19; Domain III, Government and Court Access to Private-sector Information, at 3 to 5; Domain IV, Workplace Privacy, at 4 to 6; and Domain V, State Privacy Laws, at 17 to 21. The minimums total 66 questions and the maximums total 84 across the 90 question paper. Domains I and V together account for at least 44 of the questions.

All questions are multiple choice and some are scenario-based. Multi-select items name the number of responses required, for example select three of the five options, and no partial credit is awarded for a partly correct selection. Halfway through the exam the candidate is offered a 15-minute break, which splits the paper into two halves of 45 questions each. The first half must be submitted before the break and cannot be revisited afterwards.

Scoring runs on a scale of 100 to 500 with a passing score of 300. IAPP states plainly that 300 does not represent 60 percent. The cut score is set by an exam development board after beta testing and psychometric analysis, then mapped to 300, and raw scores are converted to the common scale so that forms of slightly different difficulty stay comparable. Questions are not weighted differently from one another and there is no minimum requirement for any individual section. Results appear on screen immediately, an email follows, and results take up to two business days to reflect in the IAPP system. Candidates receive a section breakdown showing the percentage correct per blueprint domain, which IAPP warns cannot be averaged into an overall score because domains hold different question counts.

The CIPP/US is accredited by the ANSI National Accreditation Board under ISO/IEC 17024:2012, alongside the CIPM, CIPP/E and CIPT credentials. IAPP reports that more than 41,000 professionals worldwide hold an IAPP certification. The exam is delivered through Pearson VUE, at more than 6,000 test centres or online through OnVUE remote proctoring, and IAPP lists translated exams only for CIPP/E and CIPM, not for CIPP/US.

A certification becomes active only once the holder pays a certification maintenance fee of 250 USD per term or holds IAPP membership at 295 USD annually. The certification term runs two years and ends on the last day of the month two years after activation. Holders must submit 20 hours of continuing professional education per term for each certification held, or retest instead. A term that ends in suspended status results in revocation, after which the exam must be passed again.

Why Get CIPP/US (Certified Information Privacy Professional/United States) Certified?

The blueprint puts 27 to 33 of the 90 questions in Domain I alone, so a single well-studied domain covers up to a third of the paper.

State privacy law now carries 17 to 21 questions, reflecting CCPA and CPRA, Washington My Health My Data, the Illinois GIPA class actions and NYC automated employment decision rules.

CIPP/US is ANAB-accredited under ISO/IEC 17024:2012, one of four IAPP credentials holding that accreditation.

The pass mark is a scaled 300 out of 500, and IAPP states explicitly that 300 does not correspond to 60 percent of questions.

Results appear on screen immediately, so candidates leave the test centre knowing the outcome rather than waiting days.

Recertification costs 20 CPE hours per two-year term plus a 250 USD maintenance fee, with no requirement to resit unless the holder chooses to.

Holding a CIPP plus a CIPM or CIPT opens the Fellow of Information Privacy designation, and US attorneys with a CIPP plus one other IAPP credential can pursue the Privacy Law Specialist designation.

Exam Format & Structure

Duration

2.5 hours (150 minutes)

Questions

90

Passing Score

300 on a scale of 100 to 500

Question Types

  • Multiple choice with one correct answer
  • Multi-select, where the question names how many responses to pick and no partial credit is given
  • Scenario-based items where several questions follow one fact pattern

Delivery Method

Pearson VUE test centres, more than 6,000 worldwide, or OnVUE online proctoring

  • A 15-minute break is offered halfway through, splitting the exam into two halves of 45 questions.
  • The first half must be submitted before the break and cannot be revisited.
  • IAPP publishes a minimum and maximum question count per domain rather than percentage weights.
  • IAPP lists translated exams for CIPP/E and CIPM only, so CIPP/US is taken in English.
  • The exam must be scheduled and completed within one year of purchase or the fee is forfeited.
  • IAPP updates its exams annually, changing approximately 10 to 15 percent of content, announced at least 90 days ahead.

How scoring works

Score scale

100 to 500 scaled score

Score needed to pass

300

Roughly what that means raw

IAPP does not publish a raw score to scaled score table and does not tell candidates how many questions they answered correctly.

When results arrive

Pass or fail with the scaled score appears on screen immediately, an email follows, and results reflect in the IAPP system within two business days.

How the scale is built

An exam development board sets the minimum number of scored questions a candidate must answer correctly, after beta testing and psychometric analysis. That cut is mapped to 300 and the remainder of the scale is built around it, so raw scores convert to a common 100 to 500 range across forms of differing difficulty. Questions are not weighted differently and no section carries its own minimum.

  • IAPP states that 300 does not represent 60 percent of the questions.
  • The score report gives the percentage correct per blueprint domain, which IAPP warns cannot be averaged into an overall score because domains hold different question counts.
  • A score of 100 represents a range of low scores below the scope of the scale.
  • Answering every scored question correctly produces a score of 500.
  • IAPP does not release incorrect answers for review, since exam questions are treated as secure material.

Pacing and time budget

90 questions in 150 minutes gives you About 100 seconds per question per question.

At this pointYou should have answered
25 min15
50 min30
75 min45
120 min72
145 min90
  • The 75 minute mark is the hard boundary, because the first 45 questions are submitted before the break and cannot be revisited.
  • Clear every flagged item in the first half before accepting the break rather than saving it for later.
  • Scenario clusters take longer than standalone items, so read the fact pattern once and answer all its questions together.
  • Multi-select items need a second read to count the required responses, which is worth the extra 15 seconds.
  • The break is offered rather than required, and the second half carries its own 75 minutes for its 45 questions whether you take it or skip it.

Where the marks are

TopicWeightWhy it scores
Domain I: US legal framework, regulators and information management27-33 of 90 questionsThe largest block on the paper by a wide margin. Sources of law, preemption, private right of action, the regulator map and the information management competency alone can supply a third of the exam.
Domain V: state privacy laws17-21 of 90 questionsSecond largest and the fastest changing. CCPA as amended by CPRA, applicability thresholds, data subject rights, health data rules, biometric restrictions and AI bias frameworks all sit here.
Domain II: federal sector statutes15-19 of 90 questionsConcentrated recall across healthcare, finance, education and marketing. HIPAA, GLBA, FCRA, FERPA, TCPA and CAN-SPAM are individually named in the body of knowledge, so questions are direct.
Domain IV: workplace privacy4-6 of 90 questionsSmall but self-contained. Pre-employment screening, monitoring technologies and post-employment retention cover almost every question, and the enforcing agencies are a short list to memorise.
Domain III: government and court access3-5 of 90 questionsThe smallest block, worth a focused weekend rather than a month. ECPA, FISA Section 702, the USA PATRIOT Act and the USA Freedom Act carry most of it.
International data transfers and the Schrems decisionsWithin the 27-33 question Domain INamed explicitly under competency I.C, covering Standard Contractual Clauses, the EU-U.S. Data Privacy Framework and conflicts between EU data protection and US e-discovery.
State data breach notification elementsWithin the 17-21 question Domain VThe body of knowledge asks for the common elements across state statutes, including the definitions of personal information and security breach. Pattern recognition beats memorising 50 statutes.
FTC enforcement theory and priority areasWithin the 15-19 question Domain IICompetency II.A asks candidates to identify priority areas in future federal enforcement, naming data brokers, IoT, AI, biometrics and unregulated data. Those five terms are worth memorising verbatim.

The numbers

90 multiple-choice questions, 2.5 hours

Exam format

Source: IAPP Certification FAQs, iapp.org/certify/faqs

$550 for members and non-members

Exam fee

Source: IAPP Store, CIPP/US Exam product page

100 to 500, pass at 300

Scoring scale and cut score

Source: IAPP Certification Candidate Handbook, Version 5.3.2

Domain I 27-33, II 15-19, III 3-5, IV 4-6, V 17-21

Blueprint question ranges

Source: IAPP CIPP/US Body of Knowledge, Version 2.6.1

7 days after the prior attempt

Retake wait

Source: IAPP Certification Candidate Handbook, Version 5.3.2

20 CPEs per two-year term plus a $250 fee or $295 annual membership

Maintenance requirement

Source: IAPP Continuing Professional Education Policy, Version 3.3.1

If you fail

Wait before retaking

Seven days. Retake candidates cannot schedule an appointment for a date sooner than seven days after their prior attempt, and the new exam can only be purchased once the previous result reflects in the MyIAPP profile.

Attempt limit

IAPP does not publish a cap on the number of attempts.

Retake fee

A new exam purchase is required. IAPP states that previously failed exams receive a discounted retake price on subsequent attempts at the same certification, with the amount shown in the IAPP store.

A missed appointment is recorded as a no-show, consumes the purchased attempt and cannot be rescheduled, so a new exam must be bought. IAPP will consider reopening a no-showed exam only for unavoidable circumstances such as a medical emergency, handled case by case through Pearson VUE. An exam ended by a proctor for a rules violation is permanently closed and all fees are forfeited, though Pearson VUE will review a dismissal the candidate believes was made in error and will reopen the exam if no rule was broken.

Exam Domains & Topics

Domain I: The U.S. Privacy Environment
27-33 of 90 questions (IAPP blueprint range)

The largest domain. It covers the branches of government, sources of law from constitutions through common law and contract law, scope, jurisdiction, preemption and private right of action, the major regulators, liability theories, UDAP, the enforcement framework including state attorneys general and the CPPA, information management practices, and international data transfers shaped by the Schrems decisions.

Key Topics to Master:

  • Branches of government and their roles
  • Sources of law: constitutions, legislation, regulations, case law, common law, contract law
  • Scope and application, jurisdiction, preemption, private right of action
  • FTC, FCC, DoC, HHS, banking regulators, state attorneys general, state insurance departments
  • Contract, tort and civil enforcement liability, criminal against civil, fiduciary duty
  • Negligence and unfair and deceptive acts and practices
  • Global Privacy Enforcement Network and cross-border enforcement
  • Self-regulatory enforcement: PCI and trust marks
  • Data inventory, classification, flow mapping, sharing and transfers
  • Vendor risk management, data processing agreements, cloud requirements, incident response
  • Records retention and disposal, user preferences, privacy notices
  • Standard Contractual Clauses and the EU-U.S. Data Privacy Framework
  • GDPR and FADP intersections, EU data protection against e-discovery conflicts
Domain II: Federal Privacy Laws
15-19 of 90 questions (IAPP blueprint range)

Sector-by-sector federal statute recall. It covers FTC authority and enforcement priorities including data brokers, IoT, AI and biometrics; healthcare through HIPAA privacy and security rules, HITECH, the 21st Century Cures Act and 42 CFR Part 2; finance through FCRA, FACTA, Gramm-Leach-Bliley, the Red Flags Rule, Dodd-Frank and the CFPB; education through FERPA; and telecommunications and marketing.

Key Topics to Master:

  • FTC Act and COPPA, and the purpose of FTC privacy and security enforcement
  • Future federal enforcement priorities: data brokers, IoT, AI, biometrics, unregulated data
  • HIPAA privacy rule, HIPAA security rule, online tracking by covered entities
  • HITECH Act of 2009, 21st Century Cures Act, 42 CFR Part 2
  • FCRA of 1970 and FACTA of 2003
  • Gramm-Leach-Bliley privacy rule and safeguards rule and state exemptions
  • Red Flags Rule and identity theft mitigation
  • Dodd-Frank and the Consumer Financial Protection Bureau
  • Privacy in mergers, acquisitions and divestitures
  • FERPA and education technology risk
  • TSR, TCPA, CAN-SPAM, JFPA, Telecommunications Act, Cable Act, VPPA, Driver's Privacy Protection Act
  • Do-Not-Call registry and the Wireless Domain Registry
  • Digital advertising, web scraping and data ethics in marketing
Domain III: Government and Court Access to Private-sector Information
3-5 of 90 questions (IAPP blueprint range)

The smallest domain, covering how government and courts reach private-sector data. It spans financial access under the Right to Financial Privacy Act and the Bank Secrecy Act, communications access under ECPA and CALEA, national security authority under FISA Section 702, the USA PATRIOT Act and the USA Freedom Act, the Cybersecurity Information Sharing Act, and civil litigation issues including electronic discovery.

Key Topics to Master:

  • Right to Financial Privacy Act of 1978 and Bank Secrecy Act of 1970
  • Electronic Communications Privacy Act and wiretaps, subpoenas and warrants
  • Communications Assistance to Law Enforcement Act
  • Foreign Intelligence Surveillance Act and Section 702
  • National security letters
  • USA PATRIOT Act of 2001 and USA Freedom Act of 2015
  • Cybersecurity Information Sharing Act of 2015
  • Privacy Protection Act of 1980 and compelled disclosure of media information
  • Electronic discovery in civil litigation
Domain IV: Workplace Privacy
4-6 of 90 questions (IAPP blueprint range)

Employee privacy across the employment lifecycle. It covers notice and expectations of privacy, anti-discrimination statutes including the Civil Rights Act, the ADA and GINA, the enforcing agencies, pre-employment screening including automated employment decision tools and their bias risk, monitoring during employment across biometrics, location services and communications, internal investigations, and post-employment records retention.

Key Topics to Master:

  • Notice and reasonable expectations of privacy at work
  • Civil Rights Act of 1964, Americans with Disabilities Act, GINA
  • FTC, Department of Labor, EEOC, NLRB and OSHA roles
  • Automated employment decision tools and bias
  • Background checks, personality and psychological evaluations, polygraph, drug and alcohol testing
  • Social media monitoring and unionised worker issues
  • Employee monitoring: computer use, biometrics, location-based services, wellness programmes, mobile, email, postal mail, photography, telephony, video
  • Employer obligations under the ECPA of 1986
  • Internal investigations, third parties and documenting performance issues
  • Termination, transition management, records retention and reference requests
Domain V: State Privacy Laws
17-21 of 90 questions (IAPP blueprint range)

The fastest-moving domain and the second largest. It covers state authority against federal authority, the roles of state attorneys general and the California Privacy Protection Agency, applicability thresholds and exemptions, data subject rights, data protection assessments, state health data rules, biometric and facial recognition restrictions, AI bias frameworks, comprehensive state statutes and breach notification law.

Key Topics to Master:

  • Federal against state authority, state attorneys general, the CPPA
  • Applicability thresholds: resident counts and annual revenue, plus exemptions
  • Access, deletion, correction, portability, opt-out, consent and verifiable parental consent
  • Privacy notices and other customer-facing documents
  • Data protection assessments and risk assessments
  • Selling and sharing personal information, data protection agreements
  • State health data rules including Washington My Health My Data and Nevada SB 370
  • Illinois Genetic Information Privacy Act class actions
  • Cure periods and penalties for non-compliance
  • Cookie and online tracking regulation at state level
  • Biometric and facial recognition restrictions in Illinois, Washington and Texas
  • NAIC AIS Governance Guidelines, the NYC automated employment decision tool law, Colorado insurance discrimination law
  • CCPA as amended by CPRA, the California Age-Appropriate Design Code Act, the Delete Act
  • State breach notification elements: definitions, triggers and timing

Recommended Study Plan

Week 1: US legal framework foundations
6-8 hours
  • 1Download the CIPP/US Body of Knowledge and Exam Blueprint and mark the question range beside each domain
  • 2Learn the three branches of government and how each produces privacy obligations
  • 3Distinguish constitutions, legislation, regulations, case law, common law and contract law as sources of privacy duty
  • 4Define scope and application, jurisdiction, preemption and private right of action with one example each
  • 5Read the IAPP Certification Candidate Handbook so exam-day rules never become a surprise
Week 2: Regulators and the enforcement framework
7-9 hours
  • 1Build a table of the FTC, FCC, DoC, HHS, the Federal Reserve Board and the Comptroller of the Currency with what each regulates
  • 2Add state attorneys general, state insurance departments and the California Privacy Protection Agency to the table
  • 3Separate contract, tort and civil enforcement liability, and criminal from civil liability
  • 4Learn what makes an act or practice unfair or deceptive under UDAP analysis
  • 5Read three FTC privacy enforcement summaries and note the theory used in each
Week 3: Information management and international transfers
7-9 hours
  • 1Work through data inventory, classification, flow mapping and transfer controls as a sequence
  • 2List the components of a privacy programme: training, vendor risk, processing agreements, cloud requirements, incident response
  • 3Learn what the Schrems decisions changed about transfers out of the EU
  • 4Compare Standard Contractual Clauses with the EU-U.S. Data Privacy Framework on when each applies
  • 5Practise 25 Domain I questions and log every miss by competency
Week 4: FTC authority and healthcare privacy
7-9 hours
  • 1Learn the FTC Act and COPPA obligations, including the age threshold and parental consent mechanics
  • 2Study the HIPAA privacy rule and security rule as two separate rule sets with different requirements
  • 3Learn what HITECH added, especially breach notification and business associate liability
  • 4Read the HHS guidance on online tracking technologies used by covered entities
  • 5Add the 21st Century Cures Act and 42 CFR Part 2 to your healthcare notes
Week 5: Financial and education sector privacy
7-9 hours
  • 1Separate FCRA from FACTA and learn what a consumer report is and who may obtain one
  • 2Study the Gramm-Leach-Bliley privacy rule and safeguards rule and the exemptions that state laws grant
  • 3Learn the Red Flags Rule and the identity theft programme it requires
  • 4Note the CFPB role created by Dodd-Frank
  • 5Learn FERPA basics including directory information and the education technology risks that follow
Week 6: Telecommunications and marketing
6-8 hours
  • 1Build a single table of TSR, TCPA, CAN-SPAM, JFPA, the Telecommunications Act, the Cable Act and VPPA
  • 2Add the Driver's Privacy Protection Act and note what makes it distinct
  • 3Learn how the Do-Not-Call registry and the Wireless Domain Registry work in practice
  • 4Study the privacy implications of digital advertising and of web scraping
  • 5Answer 25 Domain II questions and rewrite every miss as a one-line rule
Week 7: Government and court access
5-7 hours
  • 1Learn the Right to Financial Privacy Act and the Bank Secrecy Act as the financial access pair
  • 2Study ECPA and CALEA on communications access through wiretaps, subpoenas and warrants
  • 3Learn FISA Section 702, national security letters, the USA PATRIOT Act and the USA Freedom Act as a chain
  • 4Note what the Cybersecurity Information Sharing Act of 2015 permits
  • 5Study the Privacy Protection Act of 1980 and the role of electronic discovery in civil litigation
Week 8: Workplace privacy
6-8 hours
  • 1Map the Civil Rights Act, the ADA and GINA to the workplace privacy issues each creates
  • 2Learn which of the FTC, DoL, EEOC, NLRB and OSHA enforces which workplace obligation
  • 3Study pre-employment screening: background checks, polygraph limits, drug testing, social media review
  • 4Learn how automated employment decision tools create bias exposure
  • 5Cover employee monitoring across computer use, biometrics, location services, email, telephony and video
Week 9: State law fundamentals
8-10 hours
  • 1Learn the applicability thresholds that bring a business under a state privacy statute
  • 2List the data subject rights common to state laws: access, deletion, correction, portability, opt-out, consent
  • 3Study what a data protection assessment must contain and when it is triggered
  • 4Learn the difference between selling and sharing personal information
  • 5Note cure periods and penalty structures as a state enforcement pattern
Week 10: California and comprehensive state statutes
8-10 hours
  • 1Study the CCPA as amended by the CPRA, including sensitive personal information and the CPPA role
  • 2Learn the California Age-Appropriate Design Code Act and the Delete Act
  • 3Compare Virginia and Colorado against California on rights, exemptions and enforcement
  • 4Build a comparison grid across the major comprehensive state laws rather than reading them separately
  • 5Answer 30 Domain V questions and score them by competency
Week 11: Specialised state regimes
7-9 hours
  • 1Study Washington My Health My Data and the Nevada Consumer Health Data Privacy Act
  • 2Learn why the Illinois Genetic Information Privacy Act produced class action exposure
  • 3Cover biometric and facial recognition restrictions in Illinois, Washington and Texas
  • 4Study the NAIC AIS Governance Guidelines and the NYC automated employment decision tool law
  • 5Learn the common elements of state data breach notification statutes and how the triggers differ
Week 12: Full-length practice and gap repair
8-10 hours
  • 1Sit a 90 question practice test under a 150 minute timer, submitting the first 45 before the break
  • 2Score by blueprint domain and rank the five domains by weakness
  • 3Rework Domain I and Domain V first, since they can supply up to 54 of the 90 questions
  • 4Drill multi-select items specifically, because partial credit is not awarded
  • 5Rebuild your statute table from memory rather than rereading it
Week 13: Recency and exam logistics
5-7 hours
  • 1Check the effective date on your Body of Knowledge copy, since IAPP updates content annually
  • 2Review the IAPP state privacy legislation tracker for laws passed since your study materials were written
  • 3Buy the exam and schedule the appointment, allowing at least 24 hours notice
  • 4Confirm the name on your government-issued photo ID matches your IAPP registration exactly
  • 5If testing with OnVUE, close every other program and clear the room of paper before the check-in window opens

Ready to pass CIPP/US (Certified Information Privacy Professional/United States)?

Get 500+ practice questions, video walkthroughs, and a pass guarantee.

94% pass rate on first attempt
$275$138

Best Study Resources

CIPP/US Body of Knowledge and Exam Blueprint

Official syllabus

The controlling document. IAPP states nothing appears on the exam that is not in it, and it publishes the minimum and maximum question count for each of the five domains plus every competency and performance indicator.

Free

IAPP Certification Candidate Handbook

Policy document

Covers the 100 to 500 scale, the 300 cut score, the 15-minute break rule, the seven day retake wait, OnVUE conduct rules, identity verification and the accommodations request process.

Free

CIPP/US free study guide

Study guide

IAPP downloadable guide covering the exam format, recommended preparation steps and example questions, requested through a short form on the CIPP/US certification page.

Free

IAPP Glossary of Privacy Terms

Reference glossary

IAPP definitions for the vocabulary the exam uses. Worth reading early, because several questions turn on the precise IAPP meaning of a term rather than a general usage.

Free

IAPP US State Privacy Legislation Tracker

Legislative tracker

IAPP Westin Research Center tracker of comprehensive state privacy bills and enacted laws. The best defence against a Domain V question about a statute passed after your textbook went to print.

Free

U.S. Private-Sector Privacy textbook

Official textbook

The IAPP textbook written against the CIPP/US body of knowledge. IAPP is explicit that no paid resource is required to pass and that none works as a catch-all guide.

Priced in the IAPP store

IAPP U.S. Private-Sector Privacy training

Instructor-led or online course

The principal IAPP training for CIPP/US. ISO accreditation requires separation between IAPP training and certification, so instructors cannot see the exam or confirm whether an item is on it.

Priced in the IAPP store

FTC business guidance on privacy and security

Regulator guidance

Federal Trade Commission guidance and enforcement summaries covering COPPA, the Red Flags Rule, data security and deceptive practice theory, which is the backbone of Domain II.

Free

HHS HIPAA for Professionals

Regulator guidance

Department of Health and Human Services source material on the HIPAA privacy rule, security rule, breach notification rule and online tracking technologies used by covered entities.

Free

IAPP Continuing Professional Education Policy

Policy document

Sets the 20 CPE hours per two-year term, the 250 USD certification maintenance fee, the credit values for each activity type, the audit process and the suspension and revocation rules.

Free

Common Mistakes to Avoid

Treating the five domains as equally sized because there are five of them.

The blueprint gives Domain I 27 to 33 questions and Domain V 17 to 21, while Domain III gets 3 to 5 and Domain IV gets 4 to 6. Domains I and V can supply up to 54 of the 90 questions between them.

Studying an older edition of the body of knowledge.

IAPP reviews the body of knowledge annually and changes roughly 10 to 15 percent of exam content each update, announced at least 90 days ahead. Check the effective date printed on your copy before you start.

Guessing part of a multi-select answer and expecting partial credit.

IAPP awards no partial credit. A multi-select item names the exact number of responses to pick, and you get the item right only by selecting exactly that number correctly.

Planning to revisit early questions at the end of the exam.

The 15-minute break splits the paper in half, and the first 45 questions must be submitted before the break with no return afterwards. Finish every flagged item in the first half before you accept the break.

Reading 300 out of 500 as 60 percent and studying to that target.

IAPP states directly that 300 does not represent 60 percent. The cut score is set by an exam development board through psychometric analysis and then mapped to 300, so no percentage target can be derived from the scale.

Learning federal statutes and treating state law as background reading.

Domain V carries 17 to 21 questions and covers CCPA as amended by CPRA, the Delete Act, Washington My Health My Data, Nevada SB 370, the Illinois GIPA class actions, biometric restrictions and AI bias rules. It is nearly as large as the whole federal domain.

Confusing the HIPAA privacy rule with the HIPAA security rule.

The privacy rule governs use and disclosure of protected health information. The security rule governs administrative, physical and technical safeguards for electronic PHI. Questions frequently name one and test the other.

Passing the exam and assuming the certification is active.

IAPP requires either a 250 USD certification maintenance fee for the term or IAPP membership at 295 USD annually before the certification counts as valid. Until one is paid, no certificate is issued and the credential does not appear.

Booking the exam and then trying to reschedule inside two days.

Pearson VUE requires at least 48 hours notice to cancel or reschedule an in-person appointment. Remote appointments can be rescheduled up to 15 minutes after the scheduled start. Missing an appointment consumes the attempt and cannot be rescheduled.

Averaging the domain percentages on a failed score report to work out how close you were.

IAPP warns against this explicitly. Blueprint domains hold different question counts, so their percentages cannot be averaged into an overall score. Use the breakdown only to rank domains for restudy.

Exam Day Tips

  • 1

    Pace the first half at 45 questions in about 75 minutes, because the halfway submission is final and there is no returning to those items.

  • 2

    Budget roughly 100 seconds per question, which is 150 minutes divided by 90 questions.

  • 3

    Read multi-select items twice to count how many responses are demanded, since selecting the wrong number scores zero.

  • 4

    For scenario items, read every question attached to the fact pattern before answering the first one.

  • 5

    Bring the two qualifying forms of ID a test centre requires, with the name matching your IAPP registration exactly, because being turned away for improper identification forfeits all exam fees.

  • 6

    Arrive 15 minutes early at a test centre, since arriving late counts as a no-show and consumes the purchased attempt.

  • 7

    For OnVUE, expect to photograph your face, your ID and four views of your surroundings, and to close every other program before the software will run.

  • 8

    Take the offered 15-minute break rather than pushing through, because the second half is the same length as the first.

  • 9

    One beverage is permitted under OnVUE rules, but food, headphones, external monitors, talking aloud and leaving the webcam view are not.

  • 10

    Expect a pass or fail result on screen straight away, with the section breakdown emailed afterwards and IAPP records updated within two business days.

Career Paths & Salary Ranges

Privacy compliance officer

Runs privacy assessments, vendor reviews and breach response against federal and state obligations. BLS reports a May 2025 median annual wage of $80,730 for compliance officers, with the 90th percentile at $133,720.

$81k-$134k

Privacy consultant

Advises multiple clients on state law applicability, data mapping and cross-border transfer mechanisms. BLS reports a May 2025 median annual wage of $101,860 for management analysts, with the 90th percentile at $171,640.

$102k-$172k

Information security analyst with privacy remit

Owns the security rule side of HIPAA, GLBA safeguards and state data security requirements alongside incident response. BLS reports a May 2025 median annual wage of $129,180 for information security analysts, with the 90th percentile at $199,850.

$129k-$200k

Privacy programme manager

Owns the privacy programme across policy, training, records retention and data subject rights operations. BLS reports a May 2025 median annual wage of $141,900 for the managers, all other category, with the 90th percentile at $238,270.

$142k-$238k

Privacy counsel

Advises on regulatory exposure, drafts data processing agreements and handles enforcement inquiries. BLS reports a May 2025 median annual wage of $159,670 for lawyers, with the 90th percentile at $351,600. US attorneys holding a CIPP plus a CIPM or CIPT can pursue the IAPP Privacy Law Specialist designation.

$160k-$352k

Prerequisites & Requirements

  • No education, experience or prior certification is required to purchase and sit the CIPP/US exam.
  • The exam must be purchased through the IAPP store before it can be scheduled with Pearson VUE.
  • The exam must be scheduled and completed within one year of purchase or the fee is forfeited.
  • Appointments must be scheduled at least 24 hours in advance and are subject to availability.
  • Two qualifying forms of ID are required at a test centre, and the name must match the exam registration exactly.
  • IAPP recommends a minimum of 30 hours of study time for each certification.
  • IAPP membership or a certification maintenance fee is required after passing before the credential becomes active.
  • The exam is delivered in English, since IAPP lists translations only for CIPP/E and CIPM.

Frequently Asked Questions

How much does the CIPP/US exam cost?

550 USD, and IAPP lists the same price for members and non-members. The fee covers one attempt, which must be scheduled and completed within one year of purchase or the fee is forfeited. IAPP states that candidates who already hold an IAPP certification receive a discounted price on a first-time exam in another designation, and that previously failed exams receive a discounted retake price on later attempts at the same certification.

What is the passing score?

300 on a scale of 100 to 500. IAPP states explicitly that 300 does not represent 60 percent. Raw scores, meaning the number of scored questions answered correctly, are converted to the common 100 to 500 scale so that forms of slightly different difficulty remain comparable.

How long is the exam and how many questions?

90 multiple-choice questions with an allotted time of 2.5 hours and a 15-minute break. IAPP publishes the same 90 question, 2.5 hour format for CIPP/A, CIPP/C, CIPP/CN, CIPP/E, CIPM and CIPT, while AIGP runs 100 questions in 2.75 hours.

What happens if I fail?

You purchase a new exam once the result reflects in your MyIAPP profile, and you cannot schedule an appointment sooner than seven days after the prior attempt. IAPP provides a section breakdown showing the percentage correct per blueprint domain so you can target restudy, but it does not tell you how many questions you answered correctly.

How long is the certification valid?

Two years. The term begins on the date the exam is passed and a maintenance fee is paid or membership is active, and ends on the last day of the month two years later. Holders must submit 20 hours of continuing professional education per term for each certification, or retest instead.

What does it cost to keep the certification active?

Either a certification maintenance fee of 250 USD for the term, or IAPP membership at 295 USD annually, which covers the fee and adds member benefits. Without one of the two, the certification is not considered valid, no certificate is issued and the credential does not appear on the IAPP site.

What happens if I miss my CPEs?

The certification is placed in suspended status at the end of the term. CPEs earned in the prior term cannot cover the deficiency, so the shortfall is added to the new term. IAPP gives the example of a CIPP/US holder eight CPEs short who must then earn 28 in the new term. A term that reaches its end date while still suspended results in revocation, after which the exam must be passed again.

How is identity verified?

By government-issued photo ID. For OnVUE, the candidate photographs their face and their ID, and Pearson software checks that the ID is legal and current and that the name matches the registration, then compares the ID photo to the candidate. If the automated check fails, a human greeter performs the match. Candidates turned away for improper identification forfeit all exam fees.

Can I opt out of the AI identity check?

Yes. Candidates can contact Pearson VUE to arrange identity verification by a person instead. IAPP notes this may cause delays in scheduling and testing. IAPP also states that OnVUE does not use candidate data to train or fine-tune AI models and that data processed by those systems is deleted after 30 days by default.

What are the rules for online proctored testing?

No external monitors, no headphones, no food, no talking or whispering, no one else in the room, and no leaving the webcam view outside the scheduled 15-minute break. All other programs must be closed before OnVUE runs. One beverage is permitted. The candidate photographs four views of their surroundings, and a work area scan may also be requested.

What materials am I allowed to bring?

None. The exam is closed book and no study materials may be within the testing area, which the greeter verifies through room photographs for online sittings. IAPP supplies an on-screen translation dictionary throughout its Brazilian Portuguese, French and German translated exams, and bars outside word-to-word dictionaries for exam security. Neither applies to CIPP/US, which is English only.

Are accommodations available?

Yes. Candidates complete the IAPP Special Testing Accommodation Request Form, whose second page must be completed by a licensed health care provider. IAPP lists extra time, frequent breaks, a glucose testing meter, hard candy, a separate room, a separate room with a reader or recorder, and water among typical accommodations, and adds that not all can be implemented on OnVUE. Requests can take up to 30 days to process.

When do I get my result?

Immediately. The screen displays pass or fail with your score on the 100 to 500 scale, an email follows with instructions for accessing the section breakdown, and results take up to two business days to reflect in the IAPP system. Test centre candidates also receive a confirmation printout.

Does IAPP publish a pass rate?

No. IAPP does not publish pass rates or score distributions for the CIPP/US or any other designation. It also does not tell candidates how many questions they answered correctly, only the percentage correct within each blueprint domain.

How does CIPP/US compare with CIPP/E?

Both are 90 question, 2.5 hour exams on the same 100 to 500 scale with a 300 cut score, and both are ANAB accredited. CIPP/US covers US federal and state law, workplace privacy and government access to private-sector data. CIPP/E covers European data protection and the GDPR. CIPP/E is offered in French and German translations while CIPP/US is English only.

Should I take CIPP/US or CIPM?

CIPP/US tests knowledge of US privacy law, while CIPM tests how to build and run a privacy programme regardless of jurisdiction. IAPP positions CIPP for legal, compliance, information management, data governance and human resources roles, and CIPM for risk management, privacy operations, accountability, audits and privacy analytics. Holding a CIPP plus a CIPM or CIPT qualifies for the Fellow of Information Privacy designation.

Can I cancel or reschedule my appointment?

Yes, as many times as needed, provided you still complete the exam within one year of purchase. Pearson VUE requires at least 48 hours notice for an in-person appointment. Remotely proctored exams can be rescheduled up to 15 minutes after the scheduled start time. A missed appointment is recorded as a no-show, consumes the attempt and cannot be rescheduled.

How current does my state law knowledge need to be?

Current to the body of knowledge version you are studying. IAPP reviews the body of knowledge annually and changes approximately 10 to 15 percent of exam content in each update, communicated to candidates at least 90 days before new content appears. Check the effective date on the front of the blueprint you downloaded.

How long should I study?

IAPP recommends a minimum of 30 hours per certification. Candidates without a legal background usually need considerably more, because Domains I and II are statute-recall heavy and Domain V changes every year. Plan 80 to 110 hours over 12 to 13 weeks if US privacy law is new to you.

Is CIPP/US accredited?

Yes. The CIPP/US, along with CIPM, CIPP/E and CIPT, is accredited by the ANSI National Accreditation Board under ISO/IEC 17024:2012. IAPP reports that more than 41,000 professionals worldwide hold an IAPP certification.

50% OFF

Pass CIPP/US (Certified Information Privacy Professional/United States) — Guaranteed

94% pass rate on first attempt

500+ Real QuestionsUpdated weekly
Video Walkthroughs20+ hours
Pass or Full RefundGuaranteed
Lifetime AccessFree updates
SAVE $137
$138
$27550% OFF

One-time • Lifetime access

Secure Instant
4.9/5 (2,847 reviews)
30-Day Guarantee — Pass or get 100% refund