CIPM
Certified Information Privacy Manager
Running a privacy program end-to-end.
› Quality score
Four-axis SecProve rubric, each 0–10. SecProve editorial assessment — each axis carries a written justification so you can push back on any single call without dismissing the whole score.
› Market signals
public, citable inputs to the recognition score› Built for these roles
› Exam format
90 multiple-choice questions over 2.5 hours, English plus several other languages. Online proctored via IAPP/Pearson. Often paired with CIPP/E or CIPP/US for the full IAPP designation.
30-day wait. IAPP member discounts available.
› Recertification
20 CPE credits over two years (avg 10/yr) plus the $250/yr IAPP membership fee that bundles certification renewal.
› 3-year cost of ownership
Excludes study materials, training, retake risk, and lost-wage opportunity. Use as a floor estimate.
› NICE Framework work roles
The NIST NICE work-role IDs this cert maps to. NICCS lookup.
› Core domains covered
The 2 domains this cert is centrally about. Passing the exam demonstrates working knowledge of each.
Data classification, encryption-at-rest/in-transit, DLP, tokenization, privacy-by-design, plus the regulatory stack (GDPR, CCPA, HIPAA) that sets the bar.
Risk frameworks (NIST RMF, ISO 31000, FAIR), policy development, audit, regulatory compliance, third-party risk.
› Also touched
Present in the blueprint but not the primary focus — you’ll be introduced but shouldn’t expect depth.
› Prerequisites
Privacy-program operations experience recommended. No hard prerequisite — legal/compliance professionals often sit without prior certs.
- Privacy program frameworks
- Privacy impact assessments
- Incident response for privacy events
› Progression
requiredrecommendedWhere this cert fits in the typical learning path. Required edges are vendor-gated; recommended edges reflect de facto industry progression.
No vendor-gated prereqs.
No de facto priors typically expected.
No certs require this one.
› Study materials
Curated starting points. Not exhaustive — vet each against your learning style and the current exam version.
- IAPP CIPM Practice Exam
› Version & lifecycle
› Salary signal
Privacy program manager / DPO, US, 5+ years.
IAPP Privacy Salary Survey + Robert Half Salary Guide · 2024 · US base only · p25–p75 range
› How it compares
CIPM is privacy-program management; CIPT is privacy-engineering / technical implementation.
↔ Compare side-by-sideCIPM is the program / operations cert; CIPP/E is the regulatory-knowledge cert. Often paired.
↔ Compare side-by-side› Careers that commonly pursue this cert
Build privacy into systems by design. Navigate GDPR, CCPA, and emerging AI privacy regulations.
See this cert’s domains highlighted on the interactive map, or compare it against the rest of the catalog.