- What This Cheat Sheet Covers
- Credential Snapshot: Who, What, and Where
- Eligibility Checklist
- Fees and Registration Mechanics
- Delivery and Question Format
- Domain 1: Information Security & Cyber Risks
- Domain 2: Business Intelligence, Data Management and Analytics
- Domain 3: IT Governance, Risks & Controls
- Standard vs. Experienced Pathway
- CITP vs. CISA: What the Waiver Does and Does Not Do
- Sequencing Your Review by Domain
- After You Pass: Annual Maintenance
- Frequently Asked Questions
- CITP is the AICPA credential for CPAs; the Standard Pathway is a multiple-choice exam delivered through Kryterion.
- Eligibility requires AICPA membership, a valid CPA license or certificate, and 1,000 relevant business-experience hours within 5 years.
- The exam covers three areas: security and cyber risks, BI/data/analytics, and IT governance, risks and controls.
- Standard Pathway registration is listed at USD $400-$500, with one retake included and nonrefundable registration.
What This Cheat Sheet Covers
This is a compressed, fact-first review of the Certified Information Technology Professional credential offered by the American Institute of Certified Public Accountants (AICPA), within AICPA & CIMA. It is built for CPAs who already understand the credential's purpose and want a single reference page covering eligibility, fees, format, content areas, and maintenance. If you are still deciding whether to pursue it, start with What Is CITP Certification? and Is the CITP Certification Worth It? before returning here.
Everything below reflects the AICPA & CIMA pages checked in September 2026. Fees, availability, and policies can change, so confirm specifics on the official registration pages before you pay. Use this sheet to organize your thinking, then deepen each area with the CITP Study Guide and drill with the CITP practice tests.
Credential Snapshot: Who, What, and Where
| Item | What to Know |
|---|---|
| Full name | Certified Information Technology Professional (CITP) |
| Governing body | AICPA, within AICPA & CIMA |
| Audience | CPAs and qualifying certificate holders working at the intersection of finance, technology, and risk |
| Primary exam (this site's focus) | Standard Pathway, multiple-choice |
| Testing vendor | Kryterion testing centers or remotely proctored online delivery |
| Scheduling | Year-round; results are immediate |
| Retake policy | One retake included with registration |
| Registration terms | Nonrefundable and nontransferable; one-year availability listed |
The credential signals that a CPA can speak credibly about technology risk, data, and controls, which is why it appeals to auditors, advisory professionals, and finance leaders who oversee systems. For the hiring side of the picture, see CITP Jobs and the CITP Salary Guide.
Eligibility Checklist
Run through these items before you register. A gap in any one of them stops the process, regardless of how well you score on practice questions.
- AICPA membership in good standing. Membership is a stated eligibility element, not an optional extra.
- A valid, unrevoked qualifying CPA license or certificate. Active or inactive CPA status can qualify.
- 1,000 relevant business-experience hours within the preceding 5 years. The hours must be relevant to the credential's subject area and fall inside the five-year window.
- Academic alternative. An academic experience alternative is available to eligible full-time professors.
Fees and Registration Mechanics
The official Standard Pathway registration is listed at USD $400-$500, with a member discount available after you sign in. The range reflects the way pricing is presented on the registration page, so check the figure you see when logged in rather than relying on any single number quoted elsewhere.
- One retake is included in the registration, which changes how you should think about risk on your first sitting.
- Registration is nonrefundable and nontransferable. You cannot pass the seat to a colleague or recover the fee if plans change.
- One-year availability is listed for the product, so register when you are close to ready rather than months early.
There is also an optional preparation product: the 52-CPE CITP Learning Pathway Bundle, which includes an exam after you complete all three modules. Listed prices are USD $429 for AICPA or CIMA members, $540 for nonmembers, and $345 for existing CITP holders. These are bundle prices covering learning content, not standalone exam fees, so do not compare them directly with the registration range above. For a full budget view including membership and maintenance, read CITP Certification Cost: Complete Pricing Breakdown.
Delivery and Question Format
The Standard Pathway exam uses multiple-choice questions. You can sit it at a Kryterion testing center or take it remotely with online proctoring, and scheduling is available year-round rather than in fixed windows. Results are immediate. Details on timing and booking are covered in CITP Exam Dates: Testing Windows, Deadlines & Scheduling.
Because the format is multiple-choice, the skill being tested is applied judgment: reading a short scenario, identifying which control, framework, or reporting concept applies, and eliminating plausible-but-wrong options. That is a different muscle than recalling definitions, and it is why scenario-based CITP practice questions matter more than flashcards alone. For scoring details, see CITP Passing Score, and for realistic expectations about difficulty, see How Hard Is the CITP Exam? and CITP Pass Rate: What the Data Shows.
Domain 1: Information Security & Cyber Risks
Information Security & Cyber Risks
This area draws on the underlying topics of information security governance, cybersecurity risk management, and SOC for Cybersecurity. Expect questions that ask you to reason about how an organization governs security and how a CPA evaluates and reports on cyber risk.
- Security governance: who owns security decisions, how policies are set and enforced, and how oversight reaches the board and management.
- Cybersecurity risk management: identifying assets and threats, assessing likelihood and impact, selecting responses, and monitoring residual risk.
- SOC for Cybersecurity: the purpose of the reporting engagement, who uses it, and how it differs conceptually from other service-organization reporting.
- Scenario skill: distinguishing a governance failure from a technical control failure when a question describes an incident.
The common trap here is answering with a technical fix when the question is really about governance or risk ownership. Read the scenario for who is accountable before you read the answer choices.
Domain 2: Business Intelligence, Data Management and Analytics
Business Intelligence, Data Management and Analytics
This area maps to data management, data analysis and reporting, and business intelligence management. It tests whether you understand how data is governed, prepared, analyzed, and turned into decisions.
- Data management: data quality, lifecycle, ownership, and the controls that keep data reliable for reporting.
- Data analysis and reporting: choosing appropriate analytical approaches and recognizing when outputs are misleading or built on weak inputs.
- Business intelligence management: how BI environments are planned, governed, and aligned to business questions rather than built for their own sake.
- Scenario skill: spotting the upstream data issue behind a downstream reporting problem.
CPAs often find this domain more approachable than expected because the instinct for completeness, accuracy, and reconciliation transfers directly. The newer vocabulary around analytics and BI is where extra review time pays off. The CITP Exam Domains Guide breaks each content area down further.
Domain 3: IT Governance, Risks & Controls
IT Governance, Risks & Controls
This area covers IT governance and strategy, IT risks and controls, and SOC reporting. It is the most audit-adjacent of the three and the one where an assurance background helps most.
- IT governance and strategy: aligning technology investment to organizational objectives and ensuring accountability for IT decisions.
- IT risks and controls: general and application controls, how control deficiencies arise, and what compensating controls can and cannot do.
- SOC reporting: the purpose of SOC reports, who relies on them, and how a user entity should consider them.
- Scenario skill: matching a described weakness to the control category that addresses it.
Key Takeaway
Two of the nine underlying topics involve SOC reporting in different forms: SOC for Cybersecurity under Domain 1 and SOC reporting under Domain 3. Build a clear side-by-side understanding of what each addresses so you do not blur them under time pressure.
Standard vs. Experienced Pathway
AICPA offers a second route, the Experienced Pathway, aimed at candidates with substantially more experience. Keep the two straight, because the preparation is not interchangeable.
| Feature | Standard Pathway | Experienced Pathway |
|---|---|---|
| Question style | Multiple-choice | Case-study-based and standalone multiple-choice |
| Question count and time | See official registration page | 60 questions in 2 hours |
| Registration range | USD $400-$500 | USD $165-$220 |
| Retake | One included | One included |
| Experience requirement | 1,000 relevant hours within the preceding 5 years | At least 7,000 relevant experience hours and 7 years of relevant experience |
The Experienced Pathway's case-study component means preparing for longer, integrated scenarios rather than only standalone items. If you qualify for it, prepare specifically for that format and do not assume Standard Pathway mock exams reflect it. This site's primary focus is the Standard Pathway, so use our practice exams for that route and treat any Experienced Pathway prep as a separate track.
CITP vs. CISA: What the Waiver Does and Does Not Do
Candidates who hold or plan to earn CISA often ask how it interacts with CITP. The facts are narrow and worth memorizing: passing the CISA examination waives the CITP examination requirement, but not the remaining credential requirements. You would still need to satisfy the other conditions, including AICPA membership, a qualifying CPA license or certificate, and the experience-hour requirement.
- Different purposes: CITP is a CPA-oriented credential from AICPA; CISA is a separate information systems audit credential from a different body.
- Waiver, not equivalence: the waiver removes the exam step only. It does not make the two credentials interchangeable.
- Planning implication: if you already hold CISA, confirm the waiver process on the official pages rather than assuming it applies automatically.
For the broader decision of which credential fits your career path, weigh it against your role and employer expectations, then see the ROI analysis.
Sequencing Your Review by Domain
One practical approach is to sequence review by how much each domain overlaps with what you already do. A CPA from audit usually sits comfortably in Domain 3 and needs the most ramp-up in Domain 2's analytics and BI vocabulary. A CPA from advisory or finance operations may find the reverse.
Your weakest domain first
- Start with the domain furthest from your daily work so you have the most repetition on it.
- For many candidates this is Domain 2 (BI, data management, analytics).
Security and governance foundations
- Cover Domain 1 security governance and cyber risk management.
- Pair SOC for Cybersecurity with SOC reporting from Domain 3 to keep them distinct.
Controls and mixed practice
- Finish Domain 3 controls, then switch to mixed-domain scenario sets.
- Review every missed question for the reasoning, not just the right letter.
Adjust the timeline to your own schedule; the point is to front-load the unfamiliar material and finish with mixed practice that mimics the real exam. A deeper plan is in the CITP Study Guide, and structured courses are outlined under CITP Training.
After You Pass: Annual Maintenance
Earning the credential is not the end of the obligation. Annual maintenance requires:
- Qualifying CPA status
- AICPA membership
- 20 hours of CITP-related continuing professional development
- Annual payment
- A compliance attestation
Plan the 20 CPD hours around topics that genuinely keep you current in security, data, and controls, since the same material that helped you pass is what employers expect you to keep sharpening. Missing any one element can jeopardize the credential, so calendar the annual cycle the day you pass.
Frequently Asked Questions
CITP stands for Certified Information Technology Professional, a credential offered by the AICPA within AICPA & CIMA for CPAs working in technology, data, and risk. See What Does CITP Stand For? for more.
Official registration is listed at USD $400-$500, with a member discount available after sign-in. One retake is included, and registration is nonrefundable and nontransferable. The Learning Pathway Bundle is a separate product with its own pricing.
You need AICPA membership in good standing, a valid and unrevoked qualifying CPA license or certificate, and 1,000 relevant business-experience hours within the preceding 5 years. An academic alternative exists for eligible full-time professors.
No. Passing the CISA examination waives the CITP examination requirement only. You must still meet the remaining credential requirements, such as membership, CPA status, and experience hours.
Maintain qualifying CPA status and AICPA membership, complete 20 hours of CITP-related CPD, pay the annual fee, and submit a compliance attestation. Calendar these items as soon as you earn the credential.