- How the CITP Exam Is Organized
- Domain 1: Information Security & Cyber Risks
- Domain 2: Business Intelligence, Data Management and Analytics
- Domain 3: IT Governance, Risks & Controls
- The Nine Underlying Areas at a Glance
- What the Questions Feel Like
- Standard vs. Experienced Pathway Content
- Sequencing the Domains in Your Study Plan
- Where These Domains Show Up in Real Jobs
- Frequently Asked Questions
- The CITP Standard Pathway is organized into three content areas, which AICPA breaks into nine underlying topic areas.
- Domain 1 pairs information security governance and cybersecurity risk management with SOC for Cybersecurity.
- Domain 3 covers IT governance and strategy, IT risks and controls, and SOC reporting.
- The Standard Pathway uses multiple-choice questions; the Experienced Pathway adds case studies and has its own preparation needs.
How the CITP Exam Is Organized
The Certified Information Technology Professional credential is issued by the American Institute of Certified Public Accountants (AICPA), within AICPA & CIMA, and it is built for CPAs who work where technology, risk, and financial reporting meet. That audience shapes the exam. You are not being tested as a network engineer or a software developer. You are being tested as a licensed professional who has to assess, advise on, and report about technology environments.
AICPA's exam registration page presents the content under three headings, and this guide uses those exact names:
- Information Security & Cyber Risks
- Business Intelligence, Data Management and Analytics
- IT Governance, Risks & Controls
Beneath those headings sit nine underlying areas: information security governance, cybersecurity risk management, SOC for Cybersecurity, data management, data analysis and reporting, business intelligence management, IT governance and strategy, IT risks and controls, and SOC reporting. Knowing which area belongs to which domain makes your notes easier to organize and your weak spots easier to spot.
This guide is the content-area companion to the rest of our CITP library. If you are still deciding whether to pursue the credential, start with what CITP certification is and the CITP requirements and eligibility rules. If you already qualify and want a plan, pair this article with the CITP study guide.
Domain 1: Information Security & Cyber Risks
This domain is where many candidates feel the credential's identity most strongly. It combines three of the nine underlying areas: information security governance, cybersecurity risk management, and SOC for Cybersecurity. The common thread is that security is treated as a governance and assurance topic, not purely a technical one.
Information Security Governance
Governance questions ask who is accountable for security, how policy flows from leadership to operations, and how an organization shows that its security program is directed and overseen.
- Roles and responsibilities for security oversight, including board and management involvement
- How security policies, standards, and procedures relate to one another
- Aligning the security program with organizational objectives and risk appetite
- Measuring and reporting on security program performance
Cybersecurity Risk Management
This area tests whether you can reason through a risk from identification to treatment, using the vocabulary a CPA would use in a risk assessment or an advisory engagement.
- Identifying assets, threats, and vulnerabilities, and understanding how they combine into risk
- Distinguishing inherent risk from residual risk after controls are applied
- Risk response options: mitigate, transfer, accept, or avoid
- Incident response and recovery concepts as they relate to risk management
SOC for Cybersecurity
SOC for Cybersecurity is an AICPA reporting framework for communicating about an entity's cybersecurity risk management program. Expect to be tested on what it is, who uses it, and how it differs from other SOC reports.
- The purpose of a cybersecurity risk management examination and the report that results
- The intended audiences for these reports and what they are meant to convey
- How the reporting framework differs in focus from SOC reports on service organization controls
A useful way to study this domain is to ask, for every concept, "what would an auditor or advisor ask to see as evidence?" That framing matches how CITP questions tend to be written. For the broader sense of how demanding the content is, see how hard the CITP exam is.
Domain 2: Business Intelligence, Data Management and Analytics
Domain 2 reflects how much of a modern finance and assurance function depends on data. It spans three underlying areas: data management, data analysis and reporting, and business intelligence management. Candidates who work mostly in audit or tax sometimes underestimate this domain because it feels closer to analytics than to controls.
Data Management
Data management questions concern how an organization keeps its data reliable, available, and fit for use across systems.
- Data governance concepts, including ownership and stewardship of data
- Data quality dimensions such as accuracy, completeness, consistency, and timeliness
- Data lifecycle thinking: creation, storage, use, retention, and disposal
- How data moves between systems and where integrity can be compromised
Data Analysis and Reporting
This area is about turning data into conclusions that decision-makers can trust, and about the professional judgment involved in doing so.
- Choosing appropriate analytical approaches for a given business or audit question
- Validating the completeness and reliability of data before relying on results
- Presenting findings clearly, including visualization and reporting choices
- Recognizing limitations and avoiding misleading conclusions
Business Intelligence Management
Business intelligence management looks at the programs, tools, and processes that deliver analytics to the organization on an ongoing basis.
- How BI initiatives are planned, governed, and aligned with business needs
- The relationship between source systems, data repositories, and reporting layers
- Controls over BI outputs that management relies on for decisions
Domain 3: IT Governance, Risks & Controls
The third domain is the closest to the traditional IT audit and advisory skill set. It covers IT governance and strategy, IT risks and controls, and SOC reporting. Candidates with a background in IT general controls or application controls usually find it familiar, while those coming from other specialties should budget extra time here.
IT Governance and Strategy
This area looks at how technology decisions are directed, prioritized, and aligned with what the organization is trying to achieve.
- How IT strategy supports business strategy, and how that alignment is governed
- Oversight structures for technology investment and performance
- Managing technology-related change and its effect on the organization
IT Risks and Controls
Here you are expected to connect technology risks to the controls that address them and to reason about control design and effectiveness.
- Distinguishing general controls from application-level controls
- Preventive, detective, and corrective control types and when each fits
- Common control areas such as access management, change management, and operations
- Business continuity and disaster recovery as control considerations
SOC Reporting
SOC reporting is a distinct area from SOC for Cybersecurity, and keeping the two straight is one of the most valuable things you can do before exam day.
- The purpose of SOC reports on controls at a service organization
- How user entities and their auditors rely on these reports
- The difference between reports focused on financial reporting controls and those addressing broader criteria
- Understanding report structure, including management's description and the auditor's opinion
Key Takeaway
SOC for Cybersecurity sits in Domain 1 and SOC reporting sits in Domain 3. Build a one-page comparison of the two early in your studies, because questions will test whether you can tell which framework applies to a given scenario.
The Nine Underlying Areas at a Glance
The table below maps each of the nine underlying areas to its parent domain and describes the kind of thinking each one rewards. Use it as a checklist when you review your notes.
| Domain | Underlying Area | What It Rewards |
|---|---|---|
| 1. Information Security & Cyber Risks | Information security governance | Understanding accountability, policy, and oversight |
| 1. Information Security & Cyber Risks | Cybersecurity risk management | Reasoning from threat to risk to response |
| 1. Information Security & Cyber Risks | SOC for Cybersecurity | Knowing the framework, audience, and purpose |
| 2. Business Intelligence, Data Management and Analytics | Data management | Data quality, governance, and lifecycle thinking |
| 2. Business Intelligence, Data Management and Analytics | Data analysis and reporting | Sound analytical judgment and clear reporting |
| 2. Business Intelligence, Data Management and Analytics | Business intelligence management | Governing analytics programs and their outputs |
| 3. IT Governance, Risks & Controls | IT governance and strategy | Aligning technology direction with business goals |
| 3. IT Governance, Risks & Controls | IT risks and controls | Matching controls to risks and judging effectiveness |
| 3. IT Governance, Risks & Controls | SOC reporting | Interpreting and applying SOC reports |
What the Questions Feel Like
The Standard Pathway uses multiple-choice questions, delivered at Kryterion testing centers or through remotely proctored online delivery. Scheduling is available year-round, and results are returned immediately. If you want the logistics, our guides on CITP exam dates and scheduling and the CITP passing score go deeper.
Because the audience is practicing CPAs, expect scenario-driven items rather than pure recall. A typical question places you in a client or employer situation and asks what the most appropriate action, control, or conclusion would be. Several answer choices usually sound plausible. The difference tends to come down to professional judgment: which option best addresses the stated risk, fits the stated framework, or respects the stated limitation.
- Read the role. Are you the auditor, the advisor, or management? The best answer changes with the role.
- Name the domain. Decide in a few seconds whether the item is really about security, data, or governance and controls. That narrows which concepts apply.
- Watch for framework traps. Items touching SOC reports often hinge on whether the scenario calls for a cybersecurity examination or a controls report.
- Prefer the answer that addresses the root risk, not the one that merely sounds technical.
To rehearse this style, work through realistic items in the CITP practice test and review the reasoning behind each answer, not just whether you were right.
Standard vs. Experienced Pathway Content
AICPA offers two routes to the exam requirement, and they should not be blended in your preparation. The Standard Pathway is the primary examination covered on this site. The Experienced Pathway has 60 case-study-based and standalone multiple-choice questions in 2 hours, and it requires at least 7,000 relevant experience hours and 7 years of relevant experience. Its registration range is USD $165-$220 and includes one retake.
| Feature | Standard Pathway | Experienced Pathway |
|---|---|---|
| Question format | Multiple-choice | 60 case-study-based and standalone multiple-choice questions in 2 hours |
| Experience requirement | 1,000 relevant business-experience hours within the preceding 5 years | At least 7,000 relevant experience hours and 7 years of relevant experience |
| Registration range | USD $400-$500, with a member discount after sign-in | USD $165-$220 |
| Retake | One retake included | One retake included |
Both routes share the same credential, but if you are preparing for the Standard Pathway, practice with Standard Pathway-style items. For cost details across the whole credential, including the optional learning bundle, see the CITP certification cost breakdown.
Sequencing the Domains in Your Study Plan
You do not need a generic schedule, but the order in which you tackle the domains matters. A sensible sequence is driven by how the domains build on each other and by where your own background is thinnest.
Domain 3 foundations first
- Learn the control vocabulary: general versus application controls, preventive versus detective
- Study IT governance and strategy so later security topics have context
- Draft your SOC reporting versus SOC for Cybersecurity comparison sheet
Domain 1 on top of that base
- Work through security governance, then cybersecurity risk management
- Study SOC for Cybersecurity and revisit your comparison sheet
- Practice scenario questions that ask for the best response to a stated risk
Domain 2 and integration
- Cover data management, data analysis and reporting, and BI management
- Take mixed practice sets spanning all three domains
- Revisit whichever underlying area your results show as weakest
Starting with Domain 3 is a deliberate choice: controls and governance language underpins how security and data questions are framed. If your day job is already heavy in IT audit, you could reverse the order and spend the early weeks on Domain 2, which is often the least familiar. For a fuller plan, see the CITP study guide, and keep the CITP cheat sheet handy for last-week review.
Where These Domains Show Up in Real Jobs
The three content areas map closely to work that CPAs are asked to do. Domain 1 appears in cybersecurity risk assessments, security-focused advisory engagements, and SOC for Cybersecurity work. Domain 2 appears in data analytics for audit and finance, reporting and dashboard programs, and data governance initiatives. Domain 3 appears in IT audit, internal audit, SOC examinations, and technology risk advisory.
That breadth is why the credential is relevant to public accounting firms, internal audit and risk functions, and advisory practices. To explore what that looks like in practice, read about CITP jobs, the CITP salary guide, and the broader question of whether the CITP certification is worth it. Keeping the credential also carries ongoing obligations: annual maintenance requires qualifying CPA status, AICPA membership, 20 hours of CITP-related continuing professional development, annual payment, and a compliance attestation.
If you want structured preparation beyond self-study, AICPA offers a 52-CPE CITP Learning Pathway Bundle that includes an exam after you complete all three modules. Listed prices are USD $429 for AICPA or CIMA members, $540 for nonmembers, and $345 for existing CITP holders. These are bundle prices, not standalone exam fees, so do not confuse them with the registration cost. More on formal options is in our overview of CITP training.
Key Takeaway
Treat the three domains as three different lenses on the same professional question: can this organization's technology, data, and security be trusted, and how would you show it? Studying with that question in mind makes the nine underlying areas hang together.
Frequently Asked Questions
The Standard Pathway is organized into three content areas: Information Security & Cyber Risks; Business Intelligence, Data Management and Analytics; and IT Governance, Risks & Controls. AICPA breaks these into nine underlying areas.
SOC for Cybersecurity falls under Information Security & Cyber Risks, while SOC reporting falls under IT Governance, Risks & Controls. They are distinct topics, so learn how they differ before attempting practice questions.
The Standard Pathway uses multiple-choice questions, delivered at Kryterion testing centers or via remote proctoring, with year-round scheduling and immediate results. The Experienced Pathway is a separate exam with case-study-based and standalone multiple-choice questions.
Passing the CISA examination waives the CITP examination requirement, but it does not waive the remaining credential requirements such as AICPA membership, a qualifying CPA license or certificate, and the relevant experience hours. See CITP requirements for the full picture.
Our CITP practice test lets you work through exam-style multiple-choice items so you can identify which of the nine underlying areas needs the most attention before you register.