CITP logo
Focused certification exam prep
Start practice

CITP Certification

TL;DR
  • CITP is the Certified Information Technology Professional credential, awarded by the AICPA within AICPA & CIMA, and built for CPAs.
  • The Standard Pathway requires AICPA membership, a valid CPA license or certificate, and 1,000 relevant business-experience hours within five years.
  • The exam covers three content areas: security and cyber risk, data and analytics, and IT governance, risks and controls.
  • Passing the CISA exam waives the CITP exam requirement, but not the credential's other requirements.

What the CITP Credential Actually Is

CITP stands for Certified Information Technology Professional, a specialty credential issued by the American Institute of Certified Public Accountants (AICPA), operating within AICPA & CIMA. It is not a general IT certification open to any technologist. It is a designation for CPAs who want to formalize their expertise at the intersection of accounting, technology, risk, and assurance.

That positioning shapes everything about the credential: who can sit for the exam, what the questions emphasize, and who recognizes the letters after your name. If you are new to the terminology, our explainers on what CITP is and what CITP stands for cover the basics, and the overview at CITP certification provides additional context. This article goes deeper into mechanics: eligibility, exam structure, pathway choice, and how to prepare sensibly.

Why the identity matters: Several unrelated credentials share the CITP acronym. Everything on this page refers only to the AICPA's Certified Information Technology Professional. If you are researching a different credential with the same letters, the fees, eligibility rules, and exam content discussed here will not apply to it.

Who Qualifies: Eligibility Mechanics

Eligibility is where many candidates stumble, because CITP is gated more tightly than most vendor-neutral IT certifications. For the Standard Pathway, you need all of the following:

  • AICPA membership in good standing. Membership is a prerequisite, not an optional extra.
  • A valid and unrevoked qualifying CPA license or certificate. Active or inactive CPA status can qualify.
  • 1,000 hours of relevant business experience within the preceding five years. The hours must be relevant to the technology-and-assurance scope of the credential.

An academic experience alternative exists for eligible full-time professors, which recognizes teaching and research as a route to the experience requirement. A separate path, covered below, applies to candidates with much longer experience histories.

One notable rule: passing the CISA examination waives the CITP examination requirement. It does not waive the remaining credential requirements, so you would still need to meet the membership, licensure, and experience conditions. For a fuller walkthrough of each prerequisite, see our guide to CITP requirements and how to qualify.

Key Takeaway

Audit your eligibility before you spend a dollar on study materials. Confirm your CPA status, your AICPA membership standing, and that you can document 1,000 relevant hours inside the five-year window. Discovering a gap after paying for registration is an avoidable and expensive mistake, since registration is nonrefundable and nontransferable.

The Three Exam Domains in Practice

The Standard Pathway organizes its content into three headings, as listed on the AICPA's exam registration page. Underneath them sit nine underlying areas: information security governance, cybersecurity risk management, SOC for Cybersecurity, data management, data analysis and reporting, business intelligence management, IT governance and strategy, IT risks and controls, and SOC reporting. A deeper treatment lives in our complete guide to all three CITP content areas; here is the practical view.

Domain 1: Information Security & Cyber Risks

This domain asks you to think like an advisor or assurance provider evaluating how an organization protects information, not like a hands-on security engineer configuring firewalls.

  • Information security governance: roles, policies, accountability, and how security programs are structured and overseen.
  • Cybersecurity risk management: identifying, assessing, and responding to cyber risks in business terms.
  • SOC for Cybersecurity: the AICPA's reporting framework that lets organizations communicate the effectiveness of their cybersecurity risk management program. Know what it is, who uses it, and how it differs from other SOC offerings.

Domain 2: Business Intelligence, Data Management and Analytics

This is the domain where accounting professionals often feel most at home, but the framing is data stewardship and decision support rather than pure financial reporting.

  • Data management: how data is governed, stored, quality-controlled, and kept reliable for downstream use.
  • Data analysis and reporting: turning raw data into defensible, decision-useful information.
  • Business intelligence management: how BI capabilities are planned, governed, and aligned to organizational needs.

Domain 3: IT Governance, Risks & Controls

This domain connects the technology function to enterprise oversight and internal control, which is familiar territory for anyone with audit or controls experience.

  • IT governance and strategy: aligning technology investment and direction with business objectives and oversight structures.
  • IT risks and controls: identifying technology risks and evaluating the controls designed to address them.
  • SOC reporting: understanding service organization reporting, including what the reports cover and how users rely on them.

Notice that SOC topics appear in two places: SOC for Cybersecurity under the first domain and SOC reporting under the third. Candidates frequently conflate them. Build a clean mental distinction between cybersecurity-program reporting and service-organization controls reporting, because scenario questions can test whether you pick the right framework for a stated situation.

Standard Pathway vs. Experienced Pathway

CITP offers two examination routes, and they should not be prepared for interchangeably. The Standard Pathway is the primary route and is built around multiple-choice questions. The Experienced Pathway is designed for seasoned professionals and uses a different exam design.

FeatureStandard PathwayExperienced Pathway
Experience requirement1,000 relevant hours within the preceding 5 yearsAt least 7,000 relevant hours and 7 years of relevant experience
Question formatMultiple-choiceCase-study-based and standalone multiple-choice
Exam lengthPer official exam details60 questions in 2 hours
Registration fee rangeUSD $400-$500USD $165-$220
RetakeOne retake includedOne retake included
Membership/CPA prerequisitesAICPA membership and qualifying CPA license or certificateSame credential framework applies

The practical advice is to choose a pathway based on your actual experience record, then prepare strictly for that format. The Experienced Pathway's case-study structure rewards a different reading and reasoning rhythm than straightforward multiple-choice items, so do not use Standard Pathway mock exams to simulate it. Keeping the two preparation tracks separate prevents you from calibrating your pacing and expectations against the wrong test. Our difficulty guide discusses what makes the exam challenging for different backgrounds.

Fees, Registration, and Delivery

Official Standard Pathway registration is listed at USD $400-$500, with a member discount available after you sign in. The Experienced Pathway registration range is USD $165-$220. Both include one retake. Key rules to understand before you pay:

  • Registration is nonrefundable and nontransferable.
  • The product lists one-year availability, so plan your scheduling inside that window.
  • Delivery is through Kryterion testing centers or remotely proctored online delivery.
  • Scheduling is year-round, rather than restricted to fixed windows.
  • Results are immediate after you finish.

There is also an optional preparation product worth distinguishing from the exam itself: the 52-CPE CITP Learning Pathway Bundle, which includes an exam after completion of all three modules. Listed prices are USD $429 for AICPA or CIMA members, $540 for nonmembers, and $345 for existing CITP holders. These are bundle prices covering the learning content, not standalone exam fees, so do not add them to or confuse them with the registration figures above. For a complete cost picture, including maintenance, see our CITP certification cost breakdown, and for scheduling details see CITP exam dates and scheduling.

Budget tip: Because one retake is included, your downside risk on a first attempt is lower than with certifications that charge full price for every sitting. That said, the retake should be a safety net, not a plan. Use a timed practice exam before booking so you sit the real one with a realistic sense of readiness. You can try one at our CITP practice test site.

CITP vs. CISA: Where the Credentials Diverge

CPAs weighing technology credentials often compare CITP with CISA (Certified Information Systems Auditor). The two overlap in IT risk and control themes, but they serve different purposes, and the relationship between them is directly relevant: passing CISA waives the CITP exam requirement, though not the other CITP requirements.

DimensionCITPCISA
Who it is forCPAs specifically, via AICPA membership and CPA statusIS audit, control, and assurance professionals broadly
Scope emphasisTechnology as it intersects with accounting, assurance, data, and business advisoryInformation systems auditing and control
Cybersecurity reportingIncludes SOC for Cybersecurity and SOC reportingAudit-centered coverage of controls and security
Data and analytics contentA full domain on BI, data management, and analyticsLess central to the credential's identity
RelationshipCISA pass waives the CITP exam, not other requirementsIndependent credential from a separate body

If you already hold CISA, the waiver can save you an exam, but you still need to satisfy membership, licensure, and experience conditions. If you hold neither, the better question is which credential matches the work you actually do. CITP leans toward advisory and assurance roles that bridge finance and technology, while CISA leans toward dedicated IT audit. For a values-based decision, our ROI analysis walks through the trade-offs.

Where CITP Fits in a Career

The CITP is not a credential that gets you hired into a generic help-desk or network role. It signals to employers that a CPA can speak credibly about technology risk, data, and controls. The employers and roles that tend to value it share a common thread: they need someone fluent in both accounting and technology.

  • Public accounting and advisory firms with IT assurance, SOC reporting, cybersecurity advisory, or data analytics practices.
  • Internal audit and risk functions at organizations that need auditors who understand IT general controls and technology-enabled processes.
  • Finance and controllership teams undergoing systems implementations, automation, or analytics buildouts.
  • Consulting practices serving clients on governance, data management, and security programs.

Because compensation varies enormously by employer, region, and seniority, we avoid quoting figures here; our salary analysis and CITP jobs overview discuss earnings drivers and role types qualitatively.

Key Takeaway

The credential's value compounds when it matches your existing trajectory. A CPA already working on SOC engagements or IT audits gains the most because the designation formalizes and signals expertise they are using daily. A CPA in a purely compliance-focused tax role should think harder about whether the credential connects to their next move.

Sequencing Your Preparation

The right study order depends on your background, but a sensible principle is to start where you are weakest and finish where you are strongest, saving your best domain for final review when confidence matters. Here is one illustrative schedule for a CPA with an audit background but limited data-analytics exposure. Adjust it to your own gaps; our CITP study guide offers a fuller framework.

Weeks 1-2

Domain 2: Business Intelligence, Data Management and Analytics

  • Build vocabulary for data governance, data quality, and BI lifecycle concepts.
  • Practice interpreting scenarios about data reliability and reporting decisions.
Weeks 3-4

Domain 1: Information Security & Cyber Risks

  • Study security governance structures and cyber risk assessment logic.
  • Memorize the purpose and audience of SOC for Cybersecurity.
Weeks 5-6

Domain 3: IT Governance, Risks & Controls

  • Review IT governance and strategy alignment, plus IT control evaluation.
  • Separate SOC reporting concepts cleanly from SOC for Cybersecurity.
Week 7

Integrated practice

Work through realistic item styles in the practice test hub before scheduling. Review the logic behind wrong answers, since scenario-driven multiple-choice questions often hinge on picking the best response among several plausible ones. To understand how scoring works, see our note on the CITP passing score, and for outcome data see what the pass-rate data shows.

Maintaining the Credential After You Pass

Earning CITP is not a one-time event. Annual maintenance requires you to keep several conditions current:

  1. Maintain qualifying CPA status.
  2. Maintain AICPA membership.
  3. Complete 20 hours of CITP-related continuing professional development.
  4. Pay the annual fee.
  5. Attest to compliance.

The 20-hour CPD requirement is where many holders get caught, so build it into your annual learning plan. The 52-CPE Learning Pathway Bundle can double as both exam preparation and a source of qualifying hours, though you should confirm how particular hours apply to your maintenance cycle. If a CPA license or AICPA membership lapses, the credential is at risk, so treat those as ongoing obligations rather than one-time checkpoints. Training options are discussed at CITP training.

Frequently Asked Questions

Who issues the CITP certification?

The American Institute of Certified Public Accountants (AICPA), within AICPA & CIMA, issues the Certified Information Technology Professional credential. It is a CPA-focused designation, so it is distinct from other credentials that happen to share the CITP acronym.

Do I need to be a CPA to earn CITP?

Yes. Candidates need a valid and unrevoked qualifying CPA license or certificate, along with AICPA membership in good standing. Active or inactive CPA status can qualify, and an academic experience alternative exists for eligible full-time professors.

What does the Standard Pathway exam cost?

Official Standard Pathway registration is listed at USD $400-$500, with a member discount available after sign-in. One retake is included, and registration is nonrefundable and nontransferable. The Learning Pathway Bundle is a separate preparation product with its own pricing.

Does passing CISA exempt me from the CITP exam?

Passing the CISA examination waives the CITP examination requirement, but it does not waive the remaining credential requirements. You still need AICPA membership, a qualifying CPA license or certificate, and the required relevant experience.

What is the Experienced Pathway and who should take it?

The Experienced Pathway is an alternative route for professionals with at least 7,000 relevant experience hours and 7 years of relevant experience. It has 60 case-study-based and standalone multiple-choice questions in 2 hours, with a registration range of USD $165-$220 and one retake included. Prepare for it separately from the Standard Pathway.

Ready to pass your CITP exam?

Put this into practice with free CITP questions across every exam domain.