PCI CPSA_P_New Exam Overview:
| Certification Vendor: | PCI Security Standards Council (PCI SSC) |
|---|---|
| Exam Name: | Card Production Security Assessor CPSA Physical New Exam |
| Exam Number: | CPSA_P_New |
| Exam Duration: | 90 minutes |
| Available Languages: | English |
| Passing Score: | 75% |
| Related Certifications: | CPSA-L (Logical) QSA ISA |
| Exam Format: | Scenario-Based, Multiple Choice, Closed-Book |
| Certificate Validity Period: | 12 months (annual requalification required) |
| Real Exam Qty: | 50 |
| Exam Price: | Included with New Card Physical Training: $1,650 USD (as of Jan 2026) |
| Recommended Training: | Official CPSA-P Instructor-Led Training PCI Card Production Physical Security Standard |
| Exam Registration: | PCI SSC CPSA Program Portal Pearson VUE Testing |
| Sample Questions: | PCI CPSA_P_New Sample Questions |
| Exam Way: | Proctored via Pearson VUE; requalification: non-proctored remote online |
| Pre Condition: | Must be full-time employee of active CPSA Company; complete mandatory CPSA-P training; prior physical security experience recommended |
| Official Syllabus URL: | https://www.pcisecuritystandards.org/program_training_and_qualification/cpsa_qualification/ |
PCI CPSA_P_New Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Production & Material Security | - Waste, spoilage and secure destruction - PIN mailers and sensitive output protection - Card stock, blanks and pre-personalized inventory - Storage and inventory reconciliation |
| PCI Card Production Physical Security Standard Framework | - Standard scope and definitions - Roles and responsibilities - High Security Area (HSA) classification |
| Assessment Methodology & Reporting | - Gap identification and remediation - ROC (Report on Compliance) preparation - AOC (Attestation of Compliance) completion - Evidence gathering and validation |
| Personnel & Visitor Management | - Background checks and vetting - Dual control and segregation of duties - Visitor escort and entry protocols - Security awareness training |
| Facility & Perimeter Security | - Access control systems & mantraps - Building construction and exterior protection - Security control room operations - CCTV, surveillance & intrusion detection |
PCI Card Production Security AssessorCPSA Physical NewExam Sample Questions:
Question 1
A vendor hosts virtual secure elements holding cardholder information in their data center. When a cardholder makes a purchase, the vendor creates a payment token which is sent to the cardholder's mobile device. Which of the following best describes the vendor's activities?
A. Card personalization
B. Host Card Emulation (HCE) provisioning
C. Over-the-air (OTA) provisioning
D. Secure Element (SE) provisioning
Question 2
The vendor's technical documentation shows that the alarm system does not send alerts to the security control room. After a discussion you learn that the alarm works perfectly, and sends a clear signal to summon the local police every time an emergency exit is opened. Why might this cause a problem for their assessment?
A. During busy times, the local police may not be able to respond
B. If the local police have not been issued with an exterior key. they will not be able to investigate the cause of the alarm and reset it
C. If the local police receive too many false-positive alerts, they may not respond within 15 minutes of the alarm
D. During working hours, the alarm should be managed in the security control room, or by a central monitoring service
Question 3
For how long must a vendor retain all applicant and employee background information on file?
A. For at least 18 months after termination of the contract of employment
B. For at least 24 months after termination of the contract of employment
C. It is not a requirement to store this information beyond termination of the contract
D. For at least 12 months after termination of the contract of employment
Question 4
A vendor wants to know if they will be penalized if their vault is not compliant. Who should they ask?
A. Payment brands
B. Assessor
C. Issuing banks
D. PCI SSC
Question 5
Which of the following must every assessor do to maintain their CPSA certification?
A. Earn and document at least 20 hours of Continuing Professional Education (CPE) over 3 years
B. Submit evidence of internal training in a relevant area (as per the QRs)
C. Earn an additional professional certification from List A or B of the Qualification Requirements (QRs)
D. Complete annual requalification training or complete 3 assessments for different facilities each year
Solutions:
| Question 1 Answer: B | Question 2 Answer: D | Question 3 Answer: D | Question 4 Answer: A | Question 5 Answer: D |
We're so confident of our products that we provide no hassle product exchange.


By Wade

