CIPP/US
Certified Information Privacy Professional / United States
US federal and state privacy-law expertise.
› Quality score
Four-axis SecProve rubric, each 0–10. SecProve editorial assessment — each axis carries a written justification so you can push back on any single call without dismissing the whole score.
› Market signals
public, citable inputs to the recognition score› Built for these roles
› Exam format
90 multiple-choice questions over 2.5 hours, English. Online proctored via IAPP/Pearson. Covers US federal privacy law, sector-specific regimes (HIPAA, GLBA, COPPA), state laws (CCPA/CPRA), and workplace privacy.
30-day wait between attempts. IAPP member discounts available.
› Recertification
20 CPE credits over two years (avg 10/yr) plus the $250/yr IAPP membership fee that bundles certification renewal.
› 3-year cost of ownership
Excludes study materials, training, retake risk, and lost-wage opportunity. Use as a floor estimate.
› Core domains covered
The 1 domain this cert is centrally about. Passing the exam demonstrates working knowledge of each.
› Also touched
Present in the blueprint but not the primary focus — you’ll be introduced but shouldn’t expect depth.
› Prerequisites
Legal, compliance, or privacy-program background preferred. The US privacy stack is fragmented across federal sector laws and 15+ state laws — heavy reading.
- HIPAA, GLBA, COPPA, FCRA, FERPA
- CCPA / CPRA and other state privacy laws
- FTC enforcement and Section 5 unfairness/deception
› Progression
requiredrecommendedWhere this cert fits in the typical learning path. Required edges are vendor-gated; recommended edges reflect de facto industry progression.
No vendor-gated prereqs.
No de facto priors typically expected.
No certs require this one.
› Study materials
Curated starting points. Not exhaustive — vet each against your learning style and the current exam version.
- IAPP Practice Exam
› Version & lifecycle
Updated annually to track US state privacy laws (CCPA/CPRA, CO/VA/CT/UT/etc.).
› Salary signal
US privacy professional / counsel-adjacent role, US, 3–7 years.
IAPP Privacy Salary Survey + Robert Half Salary Guide · 2024 · US base only · p25–p75 range
› How it compares
Regional twin — CIPP/US for US state laws (CCPA/CPRA, CO/VA/CT/UT/etc.); CIPP/E for EU/GDPR.
↔ Compare side-by-sideCIPM is privacy-program management; CIPP/US is regulatory knowledge. Often paired.
↔ Compare side-by-side› Careers that commonly pursue this cert
Build privacy into systems by design. Navigate GDPR, CCPA, and emerging AI privacy regulations.
See this cert’s domains highlighted on the interactive map, or compare it against the rest of the catalog.