CIPP/E and CIPM cover almost entirely non-overlapping territory, which surprises people who assume they're just two flavors of the same privacy exam. CIPP/E tests whether you know GDPR. CIPM tests whether you can actually run a privacy program day to day — and the exam questions reflect that: less "what does Article 6 say," more "what should a privacy manager do about this specific operational problem."

Quick answer

The CIPM exam is 90 multiple-choice questions in 2.5 hours, scored 100-500 with a passing threshold of 300, same format as CIPP/E. It's organized around privacy program governance and the operational lifecycle: assess, protect, sustain, and respond to requests and incidents. Questions are heavily scenario-based, testing program management judgment rather than legal memorization.

The single most important thing to understand before you start studying: CIPM questions usually ask what a privacy manager should design, measure, communicate, document, or improve inside an organization — not what a specific law says. You still need working knowledge of major privacy laws and cross-border transfer mechanisms, but the exam's center of gravity is program management judgment. A CIPM question is more likely to present a scenario and ask which process improvement addresses a stated risk than to ask you to recite a legal definition.

The Domain Structure

The CIPM Body of Knowledge uses a competency-and-performance-indicator structure — the same format the IAPP later extended to the CIPP/C and AIGP exams — organized around six practical areas: privacy program framework and governance as the foundational layer, followed by the operational lifecycle of assess, protect, sustain, and finally requests and incidents — the operational muscle of responding to data subject requests and privacy incidents once a program is running. This sequencing isn't arbitrary: it mirrors the actual lifecycle a privacy program manager works through, from initial framework design through ongoing operational response.

Know when a privacy manager should reach for a PIA, DPIA, TIA, LIA, or PTA, and what question each one is actually designed to answer — this single cluster of near-identical acronyms accounts for a disproportionate share of missed CIPM questions, precisely because they're easy to confuse under exam time pressure and the exam frequently tests the distinction directly.

What's Current for the 2026 Testing Cycle

The Body of Knowledge effective September 1, 2025 introduced essentially no new tested content compared to the prior version — the IAPP's own release notes describe the changes as "clarifying language," with content relocated or combined rather than added. That said, candidates preparing in 2026 should still track current operational context the exam's scenario questions increasingly reflect: newly effective state privacy laws (Indiana, Kentucky, and Rhode Island took effect January 1, 2026), and California-specific operational developments around automated decision-making technology rules, mandatory risk assessments, cybersecurity audits, and the Delete Act's centralized deletion platform.

Translation Availability

CIPM is available in more languages than most other IAPP core exams — French, German, Chinese, and Brazilian Portuguese, compared to CIPP/E's French and German only. If English isn't your first language and you're weighing which core certification to prioritize, this broader translation support is a genuine, practical factor worth considering.

Format, Cost, and Logistics

Same structural format as the other IAPP core exams: 90 multiple-choice questions, 2.5 hours with a built-in break, delivered through Pearson VUE in person or via OnVUE remote proctoring. Scoring follows the same 100-500 scale with a 300 passing threshold. No prior work experience or formal training is required to register.

How CIPM Pairs With Other IAPP Credentials

CIPM is most commonly paired with CIPP/E or CIPP/US — the combination is widely regarded as the standard qualification pathway for Data Protection Officer roles, since CIPP establishes legal knowledge and CIPM establishes the operational capability to run a program built on that knowledge. Holding both a CIPP and CIPM (or CIPT, or AIGP) qualifies you for the Fellow of Information Privacy designation — the IAPP's recognition for professionals who've built genuinely cross-functional privacy expertise rather than depth in a single area.

Study Approach

  • Work through the domains in operational order — framework and governance first, then assess, protect, sustain, and requests/incidents — since later domains build conceptually on earlier ones rather than standing independently.
  • Drill the PIA/DPIA/TIA/LIA/PTA distinction specifically, with timed mixed practice sets near the end of your prep — most CIPM wrong-answer options are designed to sound plausible rather than obviously incorrect.
  • Practice choosing the most scalable process, not just the fastest immediate fix — CIPM scenario questions often present a quick-but-narrow option alongside a slower-but-program-wide option, and the "manager" answer is usually the latter.
  • Layer in current state-law and California operational updates even though they're not formally new Body of Knowledge content — they sharpen your ability to answer realistic, current-feeling scenario questions.

Frequently Asked Questions

How is the CIPM exam different from CIPP/E?

CIPP/E tests legal knowledge of GDPR specifically; CIPM tests the operational skills of running a privacy program day to day, with heavily scenario-based questions asking what a privacy manager should design, measure, or improve.

What are the six CIPM domain areas?

Privacy program framework and governance form the foundational layer, followed by the operational lifecycle of assess, protect, sustain, and requests and incidents.

What languages is the CIPM exam available in?

English, French, German, Chinese, and Brazilian Portuguese — broader translation support than CIPP/E, which is only available in French and German.

Did the CIPM Body of Knowledge change significantly for 2026?

No. The version effective September 1, 2025 introduced no substantively new tested content, consisting mainly of clarifying language and reorganization of existing material.

Related reading: the CIPP/E exam guide, CIPP/E vs. CIPM: which to take first, and the Fellow of Information Privacy designation explained.