CDPSE Eligibility and Experience Requirements
Anyone interested in information security may take the CDPSE exam before completing the experience requirement.
- Certification requires three years of cumulative CDPSE-related work across the domains, experience from the preceding ten years, supervisor or manager verification, and an application within five years of passing.
On this page7 sections
- You can sit before you meet the experience requirement
- What experience qualifies
- Examples of relevant and nonqualifying work
- Prepare the application evidence
- Three timing examples
- What certification adds beyond the exam
- Map experience to work performed, not job title A privacy-related title is not the test for qualifying experience. Describe the work itself: which privacy activity you performed, what decision or control it supported, and how it connects to the CDPSE domains. A software engineer may have relevant privacy engineering experience when designing access, retention or deletion controls. A lawyer may work in governance or risk, depending on responsibilities. A general IT role does not qualify automatically if its duties have no meaningful privacy connection. Build a project inventory before starting the application. For each role, record dates, supervisor, major responsibilities, and examples tied to the four domains. A data inventory project might support lifecycle management; a privacy review process could support governance and risk; an API control that limits personal data disclosure could support engineering. The examples should describe your own work and be verifiable by the person asked to confirm it. Cumulative experience can come from more than one employer or project, but dates must not be counted twice for overlapping full-time work. If two qualifying roles occurred during the same year, that does not create two years of elapsed experience. Keep evidence that makes the timeline understandable rather than relying on job titles alone. Three application examples A privacy analyst who has spent three years reviewing product data flows, documenting risk, and coordinating remediation may be able to show relevant experience across domains. The application still needs the required verification and accurate dates. Organize project examples before applying so the verifier can review specific responsibilities. A security engineer who has worked on access controls and deletion workflows may have relevant work even without “privacy” in the title. Explain the privacy purpose: what personal information was involved, what requirement the control addressed, and how your contribution fits. A broad statement such as “worked on security” gives a reviewer little to verify. A candidate with less than three years can sit for the exam but cannot claim the full designation until meeting the experience requirement. Passing can help the candidate understand the framework, but it does not convert unrelated future work into prior experience. Track qualifying work as it accrues and submit once the requirements can be supported. Keep the five-year post-pass application window visible. If experience is incomplete, save the pass result and set reminders to review the deadline before it becomes urgent. Do not wait until the last month to identify a verifier or clarify work descriptions. The application is an evidence process, so give the verifier time to confirm responsibilities and respond if ISACA requests clarification.
You can sit before you meet the experience requirement
ISACA does not require CDPSE candidates to complete professional experience before taking the exam. The exam is open to people interested in information security. However, passing does not grant the designation by itself. To become certified, you must document at least three years of cumulative work experience performing CDPSE professional tasks, meet application rules, and obtain experience verification.
This allows someone early in a privacy career, a student, or an engineer moving into privacy to demonstrate knowledge while building experience. Until the experience application is accepted, the person should describe the exam result accurately without presenting themselves as certified.
What experience qualifies
ISACA requires three or more years of cumulative work experience performing tasks of a CDPSE professional. Qualifying experience must fall within the ten years before the certification application. Relevant work can span privacy governance, privacy risk management and compliance, data life cycle management, and privacy engineering.
Examples may include maintaining data inventories and flow maps, conducting privacy impact assessments, evaluating vendor practices, translating requirements into system controls, implementing consent tags, reviewing retention and deletion, or measuring privacy program performance. The application should describe work actually performed and relate it to CDPSE tasks. A job title containing “privacy” or “engineer” does not by itself prove that the work qualifies.
Cumulative experience can come from changing roles, but the timeline and duties should be understandable. If a mixed technology job included privacy responsibilities alongside general development or operations work, describe the relevant periods and tasks rather than treating every duty as privacy experience. A supervisor or manager should be able to verify the account.
ISACA states there are no experience waivers or substitutions for CDPSE. A degree, training course, another certification, or passing a different exam does not replace the three-year experience requirement. These may build knowledge, but they do not satisfy the stated work requirement.
Examples of relevant and nonqualifying work
A systems engineer spends two years redesigning access controls for personal information, mapping system flows, and testing deletion behavior, then one year coordinating privacy assessments and vendor reviews. Those tasks can be described against the four domains, with dates and a verifier. The application still depends on ISACA’s review of the complete record.
A marketing analyst has three years of employment and a privacy certificate, but the role only analyzed campaign performance and never involved privacy responsibilities. The duration and course alone do not show qualifying experience. The candidate should not relabel ordinary analytics as privacy engineering without a real connection to the official task areas.
A developer implements consent preferences and access checks across product releases. This may be relevant, but the application should explain systems, responsibilities, decisions, and time spent. Working as a developer does not automatically qualify every year, and one feature release does not establish three years.
Prepare the application evidence
After the official score is released, candidates can pay the US$50 application processing fee and submit the certification application. ISACA asks for experience verification by a supervisor or manager. Keep a record of employer and role, dates, responsibilities, examples of privacy work, the domains those tasks touch, and a person who can verify the work.
Describe actions and evidence concretely: mapped a data flow, documented a retention decision, evaluated control evidence, or supported an incident response. Vague claims such as “managed privacy” make it difficult to understand what the candidate actually did. Do not claim planned tasks as completed experience.
The application is due within five years of passing. Separately, qualifying work must have been gained within the ten years preceding the application date. The five-year rule limits how long a passed exam can support a future application; the ten-year rule defines how recent the experience must be.
Three timing examples
Candidate A already has three qualifying years, all within the last decade. After passing and receiving the official score, they can submit the application and ask a supervisor or manager to verify their experience.
Candidate B passes with one qualifying year. They may build the remaining experience and apply later if the full three years remain within the allowed experience window and they submit within five years of passing. Passing does not create an exception to the experience rule.
Candidate C has three years of relevant work, but it ended more than ten years before the planned application. Duration alone is not enough because the experience window is not met. They need qualifying experience within the period ISACA allows.
What certification adds beyond the exam
Certification also carries ethics and maintenance obligations. Holders agree to ISACA’s Code of Professional Ethics and maintain the credential through CPE reporting and annual fees. These obligations are separate from permission to register for the exam and should be included in a candidate’s plan.
A passing score shows that you met the exam standard at that sitting. The certification application evaluates experience and other requirements. If the application is pending, keep the status distinction clear when describing the result to an employer or client.
Map experience to work performed, not job title A privacy-related title is not the test for qualifying experience. Describe the work itself: which privacy activity you performed, what decision or control it supported, and how it connects to the CDPSE domains. A software engineer may have relevant privacy engineering experience when designing access, retention or deletion controls. A lawyer may work in governance or risk, depending on responsibilities. A general IT role does not qualify automatically if its duties have no meaningful privacy connection. Build a project inventory before starting the application. For each role, record dates, supervisor, major responsibilities, and examples tied to the four domains. A data inventory project might support lifecycle management; a privacy review process could support governance and risk; an API control that limits personal data disclosure could support engineering. The examples should describe your own work and be verifiable by the person asked to confirm it. Cumulative experience can come from more than one employer or project, but dates must not be counted twice for overlapping full-time work. If two qualifying roles occurred during the same year, that does not create two years of elapsed experience. Keep evidence that makes the timeline understandable rather than relying on job titles alone. Three application examples A privacy analyst who has spent three years reviewing product data flows, documenting risk, and coordinating remediation may be able to show relevant experience across domains. The application still needs the required verification and accurate dates. Organize project examples before applying so the verifier can review specific responsibilities. A security engineer who has worked on access controls and deletion workflows may have relevant work even without “privacy” in the title. Explain the privacy purpose: what personal information was involved, what requirement the control addressed, and how your contribution fits. A broad statement such as “worked on security” gives a reviewer little to verify. A candidate with less than three years can sit for the exam but cannot claim the full designation until meeting the experience requirement. Passing can help the candidate understand the framework, but it does not convert unrelated future work into prior experience. Track qualifying work as it accrues and submit once the requirements can be supported. Keep the five-year post-pass application window visible. If experience is incomplete, save the pass result and set reminders to review the deadline before it becomes urgent. Do not wait until the last month to identify a verifier or clarify work descriptions. The application is an evidence process, so give the verifier time to confirm responsibilities and respond if ISACA requests clarification.
Map experience to work performed, not job title A privacy-related title is not the test for qualifying experience. Describe the work itself: which privacy activity you performed, what decision or control it supported, and how it connects to the CDPSE domains. A software engineer may have relevant privacy engineering experience when designing access, retention or deletion controls. A lawyer may work in governance or risk, depending on responsibilities. A general IT role does not qualify automatically if its duties have no meaningful privacy connection. Build a project inventory before starting the application. For each role, record dates, supervisor, major responsibilities, and examples tied to the four domains. A data inventory project might support lifecycle management; a privacy review process could support governance and risk; an API control that limits personal data disclosure could support engineering. The examples should describe your own work and be verifiable by the person asked to confirm it. Cumulative experience can come from more than one employer or project, but dates must not be counted twice for overlapping full-time work. If two qualifying roles occurred during the same year, that does not create two years of elapsed experience. Keep evidence that makes the timeline understandable rather than relying on job titles alone. Three application examples A privacy analyst who has spent three years reviewing product data flows, documenting risk, and coordinating remediation may be able to show relevant experience across domains. The application still needs the required verification and accurate dates. Organize project examples before applying so the verifier can review specific responsibilities. A security engineer who has worked on access controls and deletion workflows may have relevant work even without “privacy” in the title. Explain the privacy purpose: what personal information was involved, what requirement the control addressed, and how your contribution fits. A broad statement such as “worked on security” gives a reviewer little to verify. A candidate with less than three years can sit for the exam but cannot claim the full designation until meeting the experience requirement. Passing can help the candidate understand the framework, but it does not convert unrelated future work into prior experience. Track qualifying work as it accrues and submit once the requirements can be supported. Keep the five-year post-pass application window visible. If experience is incomplete, save the pass result and set reminders to review the deadline before it becomes urgent. Do not wait until the last month to identify a verifier or clarify work descriptions. The application is an evidence process, so give the verifier time to confirm responsibilities and respond if ISACA requests clarification.
Common questions
Do I need experience before registering?
No. You may take the exam first, but three years of qualifying work are required for certification.
Can a degree waive CDPSE experience?
No. ISACA states there are no experience waivers or substitutions for CDPSE.
How long do I have to apply after passing?
You must submit your certification application within five years after passing.
How recent must the work experience be?
Qualifying experience must fall within the ten years preceding the application date.
Who verifies CDPSE experience?
ISACA requests experience verification by a supervisor or manager.