Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

CDPSE Certification Requirements After the Exam

Updated 9 min read
Key takeaway

Passing the CDPSE exam is only the first step.

  • Certification requires at least three years of cumulative CDPSE professional experience across the four domains, gained within the ten years before application, supervisor or manager verification, a US$50 fee, and an application within five years of passing.
  • ISACA allows no experience waivers.
On this page6 sections
  1. Exam pass and certification are different outcomes
  2. Three years of qualifying work
  3. Application timing and verification
  4. What happens after approval
  5. Turn a work history into verifiable examples Before submitting, make a role-by-role record of dates, responsibilities, supervisors and projects. For each project, identify the domain and explain what you personally did. “Supported privacy compliance” is too broad to help a verifier. A stronger description states that you mapped personal data in a customer workflow, assessed the risk of unnecessary collection, and coordinated a control change with the product team, if those are duties you actually performed. Use the four domains to check relevance. Governance work can include policy ownership, roles and oversight. Risk and compliance work may involve assessing exposures and tracking obligations. Lifecycle work can include collection, use, retention and deletion. Engineering work can involve designing or testing privacy controls in systems. These examples illustrate categories; the application must accurately describe your own work and meet ISACA's rules. The supervisor or manager verification step is separate from the experience claim. Contact the person before submitting and explain the dates and responsibilities you plan to report. If a manager has left, identify someone who can legitimately verify the work and ask ISACA what evidence is acceptable. Do not list a verifier who has not agreed or who cannot confirm the claims. Application timing and common scenarios If you have the three years when you pass, organize the application promptly and keep the five-year window in view. If you are short by several months, passing does not waive that time. Continue qualifying work, preserve the pass record, and apply once the experience exists. The exam and professional experience answer different questions. If your years come from several roles, create a timeline with non-overlapping dates. A year spent concurrently in two relevant projects remains one elapsed year, even though it may show work across multiple domains. Explain the responsibilities from both projects without counting the same calendar time twice. If a role spans privacy and general information technology, separate the relevant duties. A broad systems job may include privacy engineering tasks, but only those tasks should support the application rationale. Keep role records or project artifacts to help a verifier recall the work, while following employer confidentiality rules. After approval, note certification status and the maintenance cycle in your records. Keep contact information current and retain application confirmations. If ISACA requests clarification, answer with dates and specific responsibilities rather than repeating a job title. A careful application ties the designation to work that can be verified.
  6. Keep an evidence file that is easy to verify An application is stronger when a verifier can connect a responsibility to dates and a real project. Prepare a short evidence file with role dates, the manager who can confirm each role, and examples tied to the four domains. Avoid sensitive personal data or confidential system details. The purpose is to make the work understandable, not to export protected records from an employer. If a manager asks what they are being asked to verify, share the scope and dates you entered and let them check it against their knowledge. Do not ask a verifier to approve duties they did not oversee. If an organization uses a formal HR record for dates, keep that information ready. ISACA may request clarification, so retain contact information and application confirmation. A candidate who changes jobs before completing the experience requirement should continue tracking the qualifying work already completed. When a role ends, record the dates and projects while details are fresh. A new supervisor may verify new work, while a former supervisor may need to confirm the prior period. Keep the chronology clear and avoid counting overlapping assignments twice. Passing the exam before experience is complete can be a useful milestone, but it does not award the designation early. Set a reminder well before the five-year window closes and review the experience inventory periodically. Once the requirement is met, complete the application, verifier step, and fee together so the award process is not delayed by missing administrative details.

Exam pass and certification are different outcomes

The CDPSE exam is open to anyone interested in information security. You can pass before you have the required experience, but ISACA will not grant the certification until you complete the experience application and satisfy the other requirements. Keep these milestones separate in your plans: permission to sit, passing the test, and approval of the professional designation.

Three years of qualifying work

ISACA requires a minimum of three cumulative years performing tasks of a CDPSE professional across privacy governance, privacy risk management and compliance, data life cycle management, and privacy engineering. Experience must fall within the ten years preceding the application date. ISACA states no experience waivers or substitutions apply.

The duties matter more than a title. Qualifying work may include assessing privacy impact, mapping personal information, defining retention and deletion, reviewing vendors, implementing access or consent controls, supporting privacy incidents, or monitoring a privacy program. The application should connect actual responsibilities to the professional work rather than merely listing a job name or course.

For example, a developer who spent several years implementing privacy controls can explain the systems and tasks. A person who attended a privacy course but never performed privacy-related work cannot count the course as employment experience. A mixed role may include relevant work, but the candidate should distinguish it from unrelated duties and provide a verifiable timeline.

Application timing and verification

Candidates have five years from the passing date to apply. The experience window and application deadline are separate. The work must be recent enough when the application is submitted, and the application must be filed before the five-year pass window closes.

After the official score is released, pay the one-time US$50 processing fee and submit the online application. ISACA asks a supervisor or manager to verify the experience. Prepare employer names, roles, dates, responsibilities, and examples that the verifier can confirm. Be direct about the work performed and avoid overstating responsibility for decisions that belonged to another role.

If you do not yet have three years, keep a record while gaining experience. Note dates and specific tasks such as maintaining data flow records, assessing a new processing purpose, reviewing an access design, or testing deletion. At application time, organize those examples under the four domains and ensure the verifier has enough knowledge to confirm them.

What happens after approval

Certification holders agree to ISACA’s Code of Professional Ethics and must meet the CPE policy. Maintenance requires a minimum of 20 related CPE hours each year and 120 over a three-year reporting period, plus the annual maintenance fee. The application is therefore the start of an ongoing professional commitment rather than an administrative step that ends all obligations.

Do not use CDPSE as a post-nominal while the application is incomplete or pending. A passing result can be described as an exam pass, but the credential follows ISACA’s approval of the experience application. This distinction matters on a resume, profile, proposal, and client engagement.

Turn a work history into verifiable examples Before submitting, make a role-by-role record of dates, responsibilities, supervisors and projects. For each project, identify the domain and explain what you personally did. “Supported privacy compliance” is too broad to help a verifier. A stronger description states that you mapped personal data in a customer workflow, assessed the risk of unnecessary collection, and coordinated a control change with the product team, if those are duties you actually performed. Use the four domains to check relevance. Governance work can include policy ownership, roles and oversight. Risk and compliance work may involve assessing exposures and tracking obligations. Lifecycle work can include collection, use, retention and deletion. Engineering work can involve designing or testing privacy controls in systems. These examples illustrate categories; the application must accurately describe your own work and meet ISACA's rules. The supervisor or manager verification step is separate from the experience claim. Contact the person before submitting and explain the dates and responsibilities you plan to report. If a manager has left, identify someone who can legitimately verify the work and ask ISACA what evidence is acceptable. Do not list a verifier who has not agreed or who cannot confirm the claims. Application timing and common scenarios If you have the three years when you pass, organize the application promptly and keep the five-year window in view. If you are short by several months, passing does not waive that time. Continue qualifying work, preserve the pass record, and apply once the experience exists. The exam and professional experience answer different questions. If your years come from several roles, create a timeline with non-overlapping dates. A year spent concurrently in two relevant projects remains one elapsed year, even though it may show work across multiple domains. Explain the responsibilities from both projects without counting the same calendar time twice. If a role spans privacy and general information technology, separate the relevant duties. A broad systems job may include privacy engineering tasks, but only those tasks should support the application rationale. Keep role records or project artifacts to help a verifier recall the work, while following employer confidentiality rules. After approval, note certification status and the maintenance cycle in your records. Keep contact information current and retain application confirmations. If ISACA requests clarification, answer with dates and specific responsibilities rather than repeating a job title. A careful application ties the designation to work that can be verified.

Turn a work history into verifiable examples Before submitting, make a role-by-role record of dates, responsibilities, supervisors and projects. For each project, identify the domain and explain what you personally did. “Supported privacy compliance” is too broad to help a verifier. A stronger description states that you mapped personal data in a customer workflow, assessed the risk of unnecessary collection, and coordinated a control change with the product team, if those are duties you actually performed. Use the four domains to check relevance. Governance work can include policy ownership, roles and oversight. Risk and compliance work may involve assessing exposures and tracking obligations. Lifecycle work can include collection, use, retention and deletion. Engineering work can involve designing or testing privacy controls in systems. These examples illustrate categories; the application must accurately describe your own work and meet ISACA's rules. The supervisor or manager verification step is separate from the experience claim. Contact the person before submitting and explain the dates and responsibilities you plan to report. If a manager has left, identify someone who can legitimately verify the work and ask ISACA what evidence is acceptable. Do not list a verifier who has not agreed or who cannot confirm the claims. Application timing and common scenarios If you have the three years when you pass, organize the application promptly and keep the five-year window in view. If you are short by several months, passing does not waive that time. Continue qualifying work, preserve the pass record, and apply once the experience exists. The exam and professional experience answer different questions. If your years come from several roles, create a timeline with non-overlapping dates. A year spent concurrently in two relevant projects remains one elapsed year, even though it may show work across multiple domains. Explain the responsibilities from both projects without counting the same calendar time twice. If a role spans privacy and general information technology, separate the relevant duties. A broad systems job may include privacy engineering tasks, but only those tasks should support the application rationale. Keep role records or project artifacts to help a verifier recall the work, while following employer confidentiality rules. After approval, note certification status and the maintenance cycle in your records. Keep contact information current and retain application confirmations. If ISACA requests clarification, answer with dates and specific responsibilities rather than repeating a job title. A careful application ties the designation to work that can be verified.

Keep an evidence file that is easy to verify An application is stronger when a verifier can connect a responsibility to dates and a real project. Prepare a short evidence file with role dates, the manager who can confirm each role, and examples tied to the four domains. Avoid sensitive personal data or confidential system details. The purpose is to make the work understandable, not to export protected records from an employer. If a manager asks what they are being asked to verify, share the scope and dates you entered and let them check it against their knowledge. Do not ask a verifier to approve duties they did not oversee. If an organization uses a formal HR record for dates, keep that information ready. ISACA may request clarification, so retain contact information and application confirmation. A candidate who changes jobs before completing the experience requirement should continue tracking the qualifying work already completed. When a role ends, record the dates and projects while details are fresh. A new supervisor may verify new work, while a former supervisor may need to confirm the prior period. Keep the chronology clear and avoid counting overlapping assignments twice. Passing the exam before experience is complete can be a useful milestone, but it does not award the designation early. Set a reminder well before the five-year window closes and review the experience inventory periodically. Once the requirement is met, complete the application, verifier step, and fee together so the award process is not delayed by missing administrative details.

Keep an evidence file that is easy to verify An application is stronger when a verifier can connect a responsibility to dates and a real project. Prepare a short evidence file with role dates, the manager who can confirm each role, and examples tied to the four domains. Avoid sensitive personal data or confidential system details. The purpose is to make the work understandable, not to export protected records from an employer. If a manager asks what they are being asked to verify, share the scope and dates you entered and let them check it against their knowledge. Do not ask a verifier to approve duties they did not oversee. If an organization uses a formal HR record for dates, keep that information ready. ISACA may request clarification, so retain contact information and application confirmation. A candidate who changes jobs before completing the experience requirement should continue tracking the qualifying work already completed. When a role ends, record the dates and projects while details are fresh. A new supervisor may verify new work, while a former supervisor may need to confirm the prior period. Keep the chronology clear and avoid counting overlapping assignments twice. Passing the exam before experience is complete can be a useful milestone, but it does not award the designation early. Set a reminder well before the five-year window closes and review the experience inventory periodically. Once the requirement is met, complete the application, verifier step, and fee together so the award process is not delayed by missing administrative details.

Common questions

Can I take the exam before I have three years of work?

Yes, but you must complete the experience requirement before certification.

Can another credential waive experience?

No. ISACA states no experience waivers or substitutions apply to CDPSE.

Who verifies experience?

A supervisor or manager verifies the work experience.

How much is the application fee?

The one-time processing fee is US$50.

How long after passing can I apply?

Within five years, with qualifying work from the preceding ten-year period.