CDPSE
Certified Data Privacy Solutions Engineer
ISACA certification for Privacy Engineering. Focus on technical implementation of privacy requirements: Privacy Governance, Privacy Architecture, and Data Lifecycle Management. Bridge between privacy and technology.
› Quality score
Four-axis SecProve rubric, each 0–10. SecProve editorial assessment — each axis carries a written justification so you can push back on any single call without dismissing the whole score.
› Market signals
public, citable inputs to the recognition score› Built for these roles
› Exam format
150 questions, 3.5 hours, 450/800
ISACA member $575 / non-member $760. 4 attempts per rolling 12-month window.
› Recertification
120 CPEs per 3-year cycle, $45/$85 AMF
› 3-year cost of ownership
Excludes study materials, training, retake risk, and lost-wage opportunity. Use as a floor estimate.
› NICE Framework work roles
The NIST NICE work-role IDs this cert maps to. NICCS lookup.
› Core domains covered
The 3 domains this cert is centrally about. Passing the exam demonstrates working knowledge of each.
Data classification, encryption-at-rest/in-transit, DLP, tokenization, privacy-by-design, plus the regulatory stack (GDPR, CCPA, HIPAA) that sets the bar.
OWASP Top 10, secure SDLC, SAST/DAST/IAST, API security, code review, DevSecOps.
AuthN/AuthZ, SSO, MFA, PAM, RBAC/ABAC, identity governance, FIDO2/passkeys, plus non-human identity: service accounts, workload identity, agent / plugin identities.
› Prerequisites
3 years privacy experience (4 without relevant degree)
› Progression
requiredrecommendedWhere this cert fits in the typical learning path. Required edges are vendor-gated; recommended edges reflect de facto industry progression.
No vendor-gated prereqs.
No certs require this one.
No follow-on certs reference this one yet.
› Study materials
Curated starting points. Not exhaustive — vet each against your learning style and the current exam version.
- CDPSE Review Manual, 2nd Ed. — ISACA
- ISACA Official CDPSE Online Course
- ISACA CDPSE QAE
› Version & lifecycle
› Salary signal
Privacy engineer / data-protection lead, US, 5+ years.
ISACA Salary Survey + IAPP Privacy Salary Survey · 2024 · US base only · p25–p75 range
› How it compares
CDPSE is governance-engineering heavy; CIPT is technical privacy implementation.
↔ Compare side-by-sideCDPSE focuses on engineering controls; CIPP/E focuses on regulatory knowledge.
↔ Compare side-by-side› Careers that commonly pursue this cert
Build privacy into systems by design. Navigate GDPR, CCPA, and emerging AI privacy regulations.
See this cert’s domains highlighted on the interactive map, or compare it against the rest of the catalog.