CITP logo
Focused certification exam prep
Start practice

CITP Cheat Sheet 2026: One-Page Review of Must-Know Facts

TL;DR
  • CITP is the AICPA credential for CPAs; the Standard Pathway is a multiple-choice exam delivered through Kryterion.
  • Eligibility requires AICPA membership, a valid CPA license or certificate, and 1,000 relevant business-experience hours within 5 years.
  • The exam covers three areas: security and cyber risks, BI/data/analytics, and IT governance, risks and controls.
  • Standard Pathway registration is listed at USD $400-$500, with one retake included and nonrefundable registration.

What This Cheat Sheet Covers

This is a compressed, fact-first review of the Certified Information Technology Professional credential offered by the American Institute of Certified Public Accountants (AICPA), within AICPA & CIMA. It is built for CPAs who already understand the credential's purpose and want a single reference page covering eligibility, fees, format, content areas, and maintenance. If you are still deciding whether to pursue it, start with What Is CITP Certification? and Is the CITP Certification Worth It? before returning here.

Everything below reflects the AICPA & CIMA pages checked in September 2026. Fees, availability, and policies can change, so confirm specifics on the official registration pages before you pay. Use this sheet to organize your thinking, then deepen each area with the CITP Study Guide and drill with the CITP practice tests.

Credential Snapshot: Who, What, and Where

ItemWhat to Know
Full nameCertified Information Technology Professional (CITP)
Governing bodyAICPA, within AICPA & CIMA
AudienceCPAs and qualifying certificate holders working at the intersection of finance, technology, and risk
Primary exam (this site's focus)Standard Pathway, multiple-choice
Testing vendorKryterion testing centers or remotely proctored online delivery
SchedulingYear-round; results are immediate
Retake policyOne retake included with registration
Registration termsNonrefundable and nontransferable; one-year availability listed

The credential signals that a CPA can speak credibly about technology risk, data, and controls, which is why it appeals to auditors, advisory professionals, and finance leaders who oversee systems. For the hiring side of the picture, see CITP Jobs and the CITP Salary Guide.

Eligibility Checklist

Run through these items before you register. A gap in any one of them stops the process, regardless of how well you score on practice questions.

  1. AICPA membership in good standing. Membership is a stated eligibility element, not an optional extra.
  2. A valid, unrevoked qualifying CPA license or certificate. Active or inactive CPA status can qualify.
  3. 1,000 relevant business-experience hours within the preceding 5 years. The hours must be relevant to the credential's subject area and fall inside the five-year window.
  4. Academic alternative. An academic experience alternative is available to eligible full-time professors.
Document your hours early: The 1,000-hour requirement is the item candidates most often underestimate. Keep a running log of engagements, systems involved, and your role so you are not reconstructing five years of work from memory. The full rules live in CITP Requirements: Eligibility, Prerequisites & How to Qualify.

Fees and Registration Mechanics

The official Standard Pathway registration is listed at USD $400-$500, with a member discount available after you sign in. The range reflects the way pricing is presented on the registration page, so check the figure you see when logged in rather than relying on any single number quoted elsewhere.

  • One retake is included in the registration, which changes how you should think about risk on your first sitting.
  • Registration is nonrefundable and nontransferable. You cannot pass the seat to a colleague or recover the fee if plans change.
  • One-year availability is listed for the product, so register when you are close to ready rather than months early.

There is also an optional preparation product: the 52-CPE CITP Learning Pathway Bundle, which includes an exam after you complete all three modules. Listed prices are USD $429 for AICPA or CIMA members, $540 for nonmembers, and $345 for existing CITP holders. These are bundle prices covering learning content, not standalone exam fees, so do not compare them directly with the registration range above. For a full budget view including membership and maintenance, read CITP Certification Cost: Complete Pricing Breakdown.

Delivery and Question Format

The Standard Pathway exam uses multiple-choice questions. You can sit it at a Kryterion testing center or take it remotely with online proctoring, and scheduling is available year-round rather than in fixed windows. Results are immediate. Details on timing and booking are covered in CITP Exam Dates: Testing Windows, Deadlines & Scheduling.

Because the format is multiple-choice, the skill being tested is applied judgment: reading a short scenario, identifying which control, framework, or reporting concept applies, and eliminating plausible-but-wrong options. That is a different muscle than recalling definitions, and it is why scenario-based CITP practice questions matter more than flashcards alone. For scoring details, see CITP Passing Score, and for realistic expectations about difficulty, see How Hard Is the CITP Exam? and CITP Pass Rate: What the Data Shows.

Remote vs. test center: Remote proctoring is convenient, but it adds environment requirements such as a clear workspace and stable connection. If your home setup is unpredictable, a testing center removes a variable you do not need on exam day.

Domain 1: Information Security & Cyber Risks

Information Security & Cyber Risks

This area draws on the underlying topics of information security governance, cybersecurity risk management, and SOC for Cybersecurity. Expect questions that ask you to reason about how an organization governs security and how a CPA evaluates and reports on cyber risk.

  • Security governance: who owns security decisions, how policies are set and enforced, and how oversight reaches the board and management.
  • Cybersecurity risk management: identifying assets and threats, assessing likelihood and impact, selecting responses, and monitoring residual risk.
  • SOC for Cybersecurity: the purpose of the reporting engagement, who uses it, and how it differs conceptually from other service-organization reporting.
  • Scenario skill: distinguishing a governance failure from a technical control failure when a question describes an incident.

The common trap here is answering with a technical fix when the question is really about governance or risk ownership. Read the scenario for who is accountable before you read the answer choices.

Domain 2: Business Intelligence, Data Management and Analytics

Business Intelligence, Data Management and Analytics

This area maps to data management, data analysis and reporting, and business intelligence management. It tests whether you understand how data is governed, prepared, analyzed, and turned into decisions.

  • Data management: data quality, lifecycle, ownership, and the controls that keep data reliable for reporting.
  • Data analysis and reporting: choosing appropriate analytical approaches and recognizing when outputs are misleading or built on weak inputs.
  • Business intelligence management: how BI environments are planned, governed, and aligned to business questions rather than built for their own sake.
  • Scenario skill: spotting the upstream data issue behind a downstream reporting problem.

CPAs often find this domain more approachable than expected because the instinct for completeness, accuracy, and reconciliation transfers directly. The newer vocabulary around analytics and BI is where extra review time pays off. The CITP Exam Domains Guide breaks each content area down further.

Domain 3: IT Governance, Risks & Controls

IT Governance, Risks & Controls

This area covers IT governance and strategy, IT risks and controls, and SOC reporting. It is the most audit-adjacent of the three and the one where an assurance background helps most.

  • IT governance and strategy: aligning technology investment to organizational objectives and ensuring accountability for IT decisions.
  • IT risks and controls: general and application controls, how control deficiencies arise, and what compensating controls can and cannot do.
  • SOC reporting: the purpose of SOC reports, who relies on them, and how a user entity should consider them.
  • Scenario skill: matching a described weakness to the control category that addresses it.

Key Takeaway

Two of the nine underlying topics involve SOC reporting in different forms: SOC for Cybersecurity under Domain 1 and SOC reporting under Domain 3. Build a clear side-by-side understanding of what each addresses so you do not blur them under time pressure.

Standard vs. Experienced Pathway

AICPA offers a second route, the Experienced Pathway, aimed at candidates with substantially more experience. Keep the two straight, because the preparation is not interchangeable.

FeatureStandard PathwayExperienced Pathway
Question styleMultiple-choiceCase-study-based and standalone multiple-choice
Question count and timeSee official registration page60 questions in 2 hours
Registration rangeUSD $400-$500USD $165-$220
RetakeOne includedOne included
Experience requirement1,000 relevant hours within the preceding 5 yearsAt least 7,000 relevant experience hours and 7 years of relevant experience

The Experienced Pathway's case-study component means preparing for longer, integrated scenarios rather than only standalone items. If you qualify for it, prepare specifically for that format and do not assume Standard Pathway mock exams reflect it. This site's primary focus is the Standard Pathway, so use our practice exams for that route and treat any Experienced Pathway prep as a separate track.

CITP vs. CISA: What the Waiver Does and Does Not Do

Candidates who hold or plan to earn CISA often ask how it interacts with CITP. The facts are narrow and worth memorizing: passing the CISA examination waives the CITP examination requirement, but not the remaining credential requirements. You would still need to satisfy the other conditions, including AICPA membership, a qualifying CPA license or certificate, and the experience-hour requirement.

  • Different purposes: CITP is a CPA-oriented credential from AICPA; CISA is a separate information systems audit credential from a different body.
  • Waiver, not equivalence: the waiver removes the exam step only. It does not make the two credentials interchangeable.
  • Planning implication: if you already hold CISA, confirm the waiver process on the official pages rather than assuming it applies automatically.

For the broader decision of which credential fits your career path, weigh it against your role and employer expectations, then see the ROI analysis.

Sequencing Your Review by Domain

One practical approach is to sequence review by how much each domain overlaps with what you already do. A CPA from audit usually sits comfortably in Domain 3 and needs the most ramp-up in Domain 2's analytics and BI vocabulary. A CPA from advisory or finance operations may find the reverse.

Weeks 1-2

Your weakest domain first

  • Start with the domain furthest from your daily work so you have the most repetition on it.
  • For many candidates this is Domain 2 (BI, data management, analytics).
Weeks 3-4

Security and governance foundations

  • Cover Domain 1 security governance and cyber risk management.
  • Pair SOC for Cybersecurity with SOC reporting from Domain 3 to keep them distinct.
Weeks 5-6

Controls and mixed practice

  • Finish Domain 3 controls, then switch to mixed-domain scenario sets.
  • Review every missed question for the reasoning, not just the right letter.

Adjust the timeline to your own schedule; the point is to front-load the unfamiliar material and finish with mixed practice that mimics the real exam. A deeper plan is in the CITP Study Guide, and structured courses are outlined under CITP Training.

After You Pass: Annual Maintenance

Earning the credential is not the end of the obligation. Annual maintenance requires:

  • Qualifying CPA status
  • AICPA membership
  • 20 hours of CITP-related continuing professional development
  • Annual payment
  • A compliance attestation

Plan the 20 CPD hours around topics that genuinely keep you current in security, data, and controls, since the same material that helped you pass is what employers expect you to keep sharpening. Missing any one element can jeopardize the credential, so calendar the annual cycle the day you pass.

Quick-reference recap: Eligibility is membership plus CPA status plus 1,000 hours in 5 years. The Standard Pathway is multiple-choice via Kryterion with one retake included. Three domains, nine underlying topics. CISA waives the exam only. Maintenance is 20 CPD hours a year plus membership, payment, and attestation.

Frequently Asked Questions

What does CITP stand for?

CITP stands for Certified Information Technology Professional, a credential offered by the AICPA within AICPA & CIMA for CPAs working in technology, data, and risk. See What Does CITP Stand For? for more.

How much does the Standard Pathway exam cost?

Official registration is listed at USD $400-$500, with a member discount available after sign-in. One retake is included, and registration is nonrefundable and nontransferable. The Learning Pathway Bundle is a separate product with its own pricing.

What experience do I need to sit the Standard Pathway?

You need AICPA membership in good standing, a valid and unrevoked qualifying CPA license or certificate, and 1,000 relevant business-experience hours within the preceding 5 years. An academic alternative exists for eligible full-time professors.

Does passing CISA mean I skip CITP entirely?

No. Passing the CISA examination waives the CITP examination requirement only. You must still meet the remaining credential requirements, such as membership, CPA status, and experience hours.

How do I maintain the credential each year?

Maintain qualifying CPA status and AICPA membership, complete 20 hours of CITP-related CPD, pay the annual fee, and submit a compliance attestation. Calendar these items as soon as you earn the credential.

Ready to pass your CITP exam?

Put this into practice with free CITP questions across every exam domain.