CDPSE Renewal and Continuing Education
CDPSE holders must earn and report at least 20 related CPE hours each year and 120 over each three-year reporting period.
- ISACA also charges an annual maintenance fee of US$45 for members or US$85 for nonmembers.
- Keep supporting records and comply with the CPE audit if selected.
On this page7 sections
- The CDPSE maintenance minimums
- Plan CPE across the cycle
- Keep records as you go
- Example three-year plan
- What if you hold multiple ISACA certifications
- Career value depends on the work
- Make the CPE plan fit actual privacy work The annual minimum is 20 related CPE hours, and the three-year total is 120. Plan for both conditions. A candidate who earns 120 hours in the first year but none later may still miss the annual minimum. A steady plan distributes learning across the reporting period and leaves time to record and report activities. Choose activities connected to privacy governance, risk, data lifecycle, or engineering. A privacy impact workshop, a relevant technical session, or structured learning about data retention may fit when the activity meets ISACA's policy. A general management class should not be counted automatically simply because it is professional development. Keep the agenda, completion record, date and hours, and a short note about its privacy relevance. A schedule of 25 related hours each year would meet the 20-hour annual minimum, but totals only 75 over three years. The cycle total is a separate requirement, so the holder needs additional eligible learning to reach 120. This arithmetic catches a common planning error: meeting each year's floor is not enough to satisfy the full cycle. Evidence and reporting examples Suppose you attend a two-day privacy engineering seminar. Save the agenda and proof of attendance, then record the eligible hours and subjects covered. If an audit selects the activity, these records help show that learning occurred. A calendar entry alone may not prove participation or subject matter. If you hold multiple ISACA certifications, review the policy on activities reported across credentials. Do not assume that a single hour can be counted multiple times unless the policy allows it. Maintain a ledger by date, activity, subject, hours, and certification application, then reconcile it before reporting. If your duties include privacy, normal work hours do not automatically count as CPE. Look for a learning activity or qualifying contribution under the policy and retain evidence. The goal is professional development, not relabeling routine tasks as education. Create a reminder before the annual reporting date. Review accumulated hours, verify each activity's relevance, pay the applicable maintenance amount, and keep records through the policy's retention period. This routine is easier than rebuilding a year's evidence during an audit notice. Use your credential account and current policy for the applicable cycle.
The CDPSE maintenance minimums
To maintain CDPSE, earn and report at least 20 CPE hours each year and at least 120 over the three-year reporting period. The activities need to relate to CDPSE knowledge or professional tasks. Meeting the three-year total does not erase the yearly minimum; plan for both requirements throughout the cycle.
ISACA lists an annual maintenance fee of US$45 for members and US$85 for nonmembers. The fee is separate from earning and reporting the CPE hours. Payment alone does not satisfy continuing education, and education alone does not replace the fee.
Plan CPE across the cycle
A steady plan is easier to manage than collecting most hours at the end of the cycle. For example, aim for a little more than the 20-hour annual floor by attending privacy engineering training, studying current regulations, presenting a privacy topic, or participating in qualifying professional development. Keep a buffer in case an activity does not meet the policy or its documentation is incomplete.
Choose activities that advance knowledge or ability to perform CDPSE-related tasks. A technical workshop on identity controls for personal information, an updated privacy assessment method, or a structured course on data governance may fit when it is relevant and documented. General professional activity should not be assumed to qualify without a clear connection to the policy.
The ISACA Online Review Course page states that completing it earns 12 CPE. That may contribute to maintenance if the holder meets the reporting policy and timing rules. It does not by itself satisfy the annual 20-hour minimum or the three-year 120-hour total.
Keep records as you go
Record the activity, date, duration, provider or organizer, learning objective, and evidence of completion. Keep certificates, agendas, attendance records, or other supporting documentation. A short description should make it clear how the activity relates to privacy governance, risk, data handling, engineering, or another CDPSE task.
ISACA may select certification holders for an annual CPE audit. If selected, you need to produce supporting evidence for reported hours. Maintain records according to the current policy rather than relying on memory or a calendar entry. If an activity’s qualification is uncertain, consult the policy before reporting it.
Example three-year plan
| Year | Example activity mix | Running total |
|---|---|---|
| 1 | Privacy engineering course, vendor review workshop, and relevant professional reading | 40 hours |
| 2 | Assessment training, privacy program metrics seminar, and approved conference sessions | 80 cumulative hours |
| 3 | Data life cycle workshop, AI privacy training, and policy update study | 120 cumulative hours |
The example meets the three-year total while exceeding the annual floor. A holder needs an average of 40 hours a year to reach 120; three years at the 20-hour annual minimum would add up to only 60. Keep both the current-year count and cumulative cycle total visible.
If an unexpected workload interrupts development in year one, do not wait until year three to catch up. Check the annual minimum, identify qualifying activities with adequate evidence, and schedule them early. A dashboard or spreadsheet can show both the current-year minimum and the reporting-period total.
What if you hold multiple ISACA certifications
ISACA says CPE hours may count for more than one designation when they satisfy the requirements for each certification. This does not mean every hour automatically applies to all credentials. Keep the activity relevant to each credential and report it under the applicable maintenance records.
When a course supports both privacy and security responsibilities, record the learning outcomes that connect to each credential. If the same event has distinct sessions, retain attendance or completion evidence for the sessions claimed. This makes the report easier to substantiate if reviewed.
Career value depends on the work
CDPSE is intended for professionals implementing privacy by design across systems, networks, and applications. It can help demonstrate structured knowledge for work such as privacy engineering, product privacy, technical privacy assessments, or data life cycle controls. The designation does not guarantee a role, promotion, salary, or authority to make legal decisions.
The credential is most useful when paired with practical evidence: a well-designed data flow, a tested consent mechanism, a defensible retention process, or a privacy assessment that changed a product decision. Continuing education helps keep those skills current as architectures, threats, and expectations change.
Make the CPE plan fit actual privacy work The annual minimum is 20 related CPE hours, and the three-year total is 120. Plan for both conditions. A candidate who earns 120 hours in the first year but none later may still miss the annual minimum. A steady plan distributes learning across the reporting period and leaves time to record and report activities. Choose activities connected to privacy governance, risk, data lifecycle, or engineering. A privacy impact workshop, a relevant technical session, or structured learning about data retention may fit when the activity meets ISACA's policy. A general management class should not be counted automatically simply because it is professional development. Keep the agenda, completion record, date and hours, and a short note about its privacy relevance. A schedule of 25 related hours each year would meet the 20-hour annual minimum, but totals only 75 over three years. The cycle total is a separate requirement, so the holder needs additional eligible learning to reach 120. This arithmetic catches a common planning error: meeting each year's floor is not enough to satisfy the full cycle. Evidence and reporting examples Suppose you attend a two-day privacy engineering seminar. Save the agenda and proof of attendance, then record the eligible hours and subjects covered. If an audit selects the activity, these records help show that learning occurred. A calendar entry alone may not prove participation or subject matter. If you hold multiple ISACA certifications, review the policy on activities reported across credentials. Do not assume that a single hour can be counted multiple times unless the policy allows it. Maintain a ledger by date, activity, subject, hours, and certification application, then reconcile it before reporting. If your duties include privacy, normal work hours do not automatically count as CPE. Look for a learning activity or qualifying contribution under the policy and retain evidence. The goal is professional development, not relabeling routine tasks as education. Create a reminder before the annual reporting date. Review accumulated hours, verify each activity's relevance, pay the applicable maintenance amount, and keep records through the policy's retention period. This routine is easier than rebuilding a year's evidence during an audit notice. Use your credential account and current policy for the applicable cycle.
Make the CPE plan fit actual privacy work The annual minimum is 20 related CPE hours, and the three-year total is 120. Plan for both conditions. A candidate who earns 120 hours in the first year but none later may still miss the annual minimum. A steady plan distributes learning across the reporting period and leaves time to record and report activities. Choose activities connected to privacy governance, risk, data lifecycle, or engineering. A privacy impact workshop, a relevant technical session, or structured learning about data retention may fit when the activity meets ISACA's policy. A general management class should not be counted automatically simply because it is professional development. Keep the agenda, completion record, date and hours, and a short note about its privacy relevance. A schedule of 25 related hours each year would meet the 20-hour annual minimum, but totals only 75 over three years. The cycle total is a separate requirement, so the holder needs additional eligible learning to reach 120. This arithmetic catches a common planning error: meeting each year's floor is not enough to satisfy the full cycle. Evidence and reporting examples Suppose you attend a two-day privacy engineering seminar. Save the agenda and proof of attendance, then record the eligible hours and subjects covered. If an audit selects the activity, these records help show that learning occurred. A calendar entry alone may not prove participation or subject matter. If you hold multiple ISACA certifications, review the policy on activities reported across credentials. Do not assume that a single hour can be counted multiple times unless the policy allows it. Maintain a ledger by date, activity, subject, hours, and certification application, then reconcile it before reporting. If your duties include privacy, normal work hours do not automatically count as CPE. Look for a learning activity or qualifying contribution under the policy and retain evidence. The goal is professional development, not relabeling routine tasks as education. Create a reminder before the annual reporting date. Review accumulated hours, verify each activity's relevance, pay the applicable maintenance amount, and keep records through the policy's retention period. This routine is easier than rebuilding a year's evidence during an audit notice. Use your credential account and current policy for the applicable cycle.
Common questions
How many CPE hours are required each year?
At least 20 related hours each year.
How many are required over three years?
At least 120 hours over the reporting period.
What is the annual maintenance fee?
US$45 for members and US$85 for nonmembers.
Can CPE count for more than one ISACA credential?
It may count when the activity meets the requirements for each credential.
Can ISACA audit CPE records?
Yes. Holders may be selected for an annual audit and should retain supporting documentation.