CITP logo
Focused certification exam prep
Start practice

CITP Exam Domains 2026: Complete Guide to All 3 Content Areas

TL;DR
  • The CITP Standard Pathway is organized into three content areas, which AICPA breaks into nine underlying topic areas.
  • Domain 1 pairs information security governance and cybersecurity risk management with SOC for Cybersecurity.
  • Domain 3 covers IT governance and strategy, IT risks and controls, and SOC reporting.
  • The Standard Pathway uses multiple-choice questions; the Experienced Pathway adds case studies and has its own preparation needs.

How the CITP Exam Is Organized

The Certified Information Technology Professional credential is issued by the American Institute of Certified Public Accountants (AICPA), within AICPA & CIMA, and it is built for CPAs who work where technology, risk, and financial reporting meet. That audience shapes the exam. You are not being tested as a network engineer or a software developer. You are being tested as a licensed professional who has to assess, advise on, and report about technology environments.

AICPA's exam registration page presents the content under three headings, and this guide uses those exact names:

  1. Information Security & Cyber Risks
  2. Business Intelligence, Data Management and Analytics
  3. IT Governance, Risks & Controls

Beneath those headings sit nine underlying areas: information security governance, cybersecurity risk management, SOC for Cybersecurity, data management, data analysis and reporting, business intelligence management, IT governance and strategy, IT risks and controls, and SOC reporting. Knowing which area belongs to which domain makes your notes easier to organize and your weak spots easier to spot.

This guide is the content-area companion to the rest of our CITP library. If you are still deciding whether to pursue the credential, start with what CITP certification is and the CITP requirements and eligibility rules. If you already qualify and want a plan, pair this article with the CITP study guide.

Scope note: This article covers the Standard Pathway content, which is the primary examination on this site. The Experienced Pathway is a different exam with a different format, so its preparation should be kept separate. We explain the distinction in a later section.

Domain 1: Information Security & Cyber Risks

This domain is where many candidates feel the credential's identity most strongly. It combines three of the nine underlying areas: information security governance, cybersecurity risk management, and SOC for Cybersecurity. The common thread is that security is treated as a governance and assurance topic, not purely a technical one.

Information Security Governance

Governance questions ask who is accountable for security, how policy flows from leadership to operations, and how an organization shows that its security program is directed and overseen.

  • Roles and responsibilities for security oversight, including board and management involvement
  • How security policies, standards, and procedures relate to one another
  • Aligning the security program with organizational objectives and risk appetite
  • Measuring and reporting on security program performance

Cybersecurity Risk Management

This area tests whether you can reason through a risk from identification to treatment, using the vocabulary a CPA would use in a risk assessment or an advisory engagement.

  • Identifying assets, threats, and vulnerabilities, and understanding how they combine into risk
  • Distinguishing inherent risk from residual risk after controls are applied
  • Risk response options: mitigate, transfer, accept, or avoid
  • Incident response and recovery concepts as they relate to risk management

SOC for Cybersecurity

SOC for Cybersecurity is an AICPA reporting framework for communicating about an entity's cybersecurity risk management program. Expect to be tested on what it is, who uses it, and how it differs from other SOC reports.

  • The purpose of a cybersecurity risk management examination and the report that results
  • The intended audiences for these reports and what they are meant to convey
  • How the reporting framework differs in focus from SOC reports on service organization controls

A useful way to study this domain is to ask, for every concept, "what would an auditor or advisor ask to see as evidence?" That framing matches how CITP questions tend to be written. For the broader sense of how demanding the content is, see how hard the CITP exam is.

Domain 2: Business Intelligence, Data Management and Analytics

Domain 2 reflects how much of a modern finance and assurance function depends on data. It spans three underlying areas: data management, data analysis and reporting, and business intelligence management. Candidates who work mostly in audit or tax sometimes underestimate this domain because it feels closer to analytics than to controls.

Data Management

Data management questions concern how an organization keeps its data reliable, available, and fit for use across systems.

  • Data governance concepts, including ownership and stewardship of data
  • Data quality dimensions such as accuracy, completeness, consistency, and timeliness
  • Data lifecycle thinking: creation, storage, use, retention, and disposal
  • How data moves between systems and where integrity can be compromised

Data Analysis and Reporting

This area is about turning data into conclusions that decision-makers can trust, and about the professional judgment involved in doing so.

  • Choosing appropriate analytical approaches for a given business or audit question
  • Validating the completeness and reliability of data before relying on results
  • Presenting findings clearly, including visualization and reporting choices
  • Recognizing limitations and avoiding misleading conclusions

Business Intelligence Management

Business intelligence management looks at the programs, tools, and processes that deliver analytics to the organization on an ongoing basis.

  • How BI initiatives are planned, governed, and aligned with business needs
  • The relationship between source systems, data repositories, and reporting layers
  • Controls over BI outputs that management relies on for decisions
Why this domain trips people up: The questions often blend a data scenario with an assurance question, such as whether a report can be relied on. If you only memorize definitions, those blended items feel unfamiliar. Practice reading a scenario and naming the data risk before you look at the answer choices.

Domain 3: IT Governance, Risks & Controls

The third domain is the closest to the traditional IT audit and advisory skill set. It covers IT governance and strategy, IT risks and controls, and SOC reporting. Candidates with a background in IT general controls or application controls usually find it familiar, while those coming from other specialties should budget extra time here.

IT Governance and Strategy

This area looks at how technology decisions are directed, prioritized, and aligned with what the organization is trying to achieve.

  • How IT strategy supports business strategy, and how that alignment is governed
  • Oversight structures for technology investment and performance
  • Managing technology-related change and its effect on the organization

IT Risks and Controls

Here you are expected to connect technology risks to the controls that address them and to reason about control design and effectiveness.

  • Distinguishing general controls from application-level controls
  • Preventive, detective, and corrective control types and when each fits
  • Common control areas such as access management, change management, and operations
  • Business continuity and disaster recovery as control considerations

SOC Reporting

SOC reporting is a distinct area from SOC for Cybersecurity, and keeping the two straight is one of the most valuable things you can do before exam day.

  • The purpose of SOC reports on controls at a service organization
  • How user entities and their auditors rely on these reports
  • The difference between reports focused on financial reporting controls and those addressing broader criteria
  • Understanding report structure, including management's description and the auditor's opinion

Key Takeaway

SOC for Cybersecurity sits in Domain 1 and SOC reporting sits in Domain 3. Build a one-page comparison of the two early in your studies, because questions will test whether you can tell which framework applies to a given scenario.

The Nine Underlying Areas at a Glance

The table below maps each of the nine underlying areas to its parent domain and describes the kind of thinking each one rewards. Use it as a checklist when you review your notes.

DomainUnderlying AreaWhat It Rewards
1. Information Security & Cyber RisksInformation security governanceUnderstanding accountability, policy, and oversight
1. Information Security & Cyber RisksCybersecurity risk managementReasoning from threat to risk to response
1. Information Security & Cyber RisksSOC for CybersecurityKnowing the framework, audience, and purpose
2. Business Intelligence, Data Management and AnalyticsData managementData quality, governance, and lifecycle thinking
2. Business Intelligence, Data Management and AnalyticsData analysis and reportingSound analytical judgment and clear reporting
2. Business Intelligence, Data Management and AnalyticsBusiness intelligence managementGoverning analytics programs and their outputs
3. IT Governance, Risks & ControlsIT governance and strategyAligning technology direction with business goals
3. IT Governance, Risks & ControlsIT risks and controlsMatching controls to risks and judging effectiveness
3. IT Governance, Risks & ControlsSOC reportingInterpreting and applying SOC reports

What the Questions Feel Like

The Standard Pathway uses multiple-choice questions, delivered at Kryterion testing centers or through remotely proctored online delivery. Scheduling is available year-round, and results are returned immediately. If you want the logistics, our guides on CITP exam dates and scheduling and the CITP passing score go deeper.

Because the audience is practicing CPAs, expect scenario-driven items rather than pure recall. A typical question places you in a client or employer situation and asks what the most appropriate action, control, or conclusion would be. Several answer choices usually sound plausible. The difference tends to come down to professional judgment: which option best addresses the stated risk, fits the stated framework, or respects the stated limitation.

  • Read the role. Are you the auditor, the advisor, or management? The best answer changes with the role.
  • Name the domain. Decide in a few seconds whether the item is really about security, data, or governance and controls. That narrows which concepts apply.
  • Watch for framework traps. Items touching SOC reports often hinge on whether the scenario calls for a cybersecurity examination or a controls report.
  • Prefer the answer that addresses the root risk, not the one that merely sounds technical.

To rehearse this style, work through realistic items in the CITP practice test and review the reasoning behind each answer, not just whether you were right.

Standard vs. Experienced Pathway Content

AICPA offers two routes to the exam requirement, and they should not be blended in your preparation. The Standard Pathway is the primary examination covered on this site. The Experienced Pathway has 60 case-study-based and standalone multiple-choice questions in 2 hours, and it requires at least 7,000 relevant experience hours and 7 years of relevant experience. Its registration range is USD $165-$220 and includes one retake.

FeatureStandard PathwayExperienced Pathway
Question formatMultiple-choice60 case-study-based and standalone multiple-choice questions in 2 hours
Experience requirement1,000 relevant business-experience hours within the preceding 5 yearsAt least 7,000 relevant experience hours and 7 years of relevant experience
Registration rangeUSD $400-$500, with a member discount after sign-inUSD $165-$220
RetakeOne retake includedOne retake included

Both routes share the same credential, but if you are preparing for the Standard Pathway, practice with Standard Pathway-style items. For cost details across the whole credential, including the optional learning bundle, see the CITP certification cost breakdown.

Eligibility reminder: Standard Pathway candidates need AICPA membership in good standing, a valid and unrevoked qualifying CPA license or certificate, and 1,000 relevant business-experience hours within the preceding 5 years. Active or inactive CPA status can qualify, and an academic experience alternative exists for eligible full-time professors. Passing the CISA examination waives the CITP examination requirement, not the remaining credential requirements.

Sequencing the Domains in Your Study Plan

You do not need a generic schedule, but the order in which you tackle the domains matters. A sensible sequence is driven by how the domains build on each other and by where your own background is thinnest.

Weeks 1-2

Domain 3 foundations first

  • Learn the control vocabulary: general versus application controls, preventive versus detective
  • Study IT governance and strategy so later security topics have context
  • Draft your SOC reporting versus SOC for Cybersecurity comparison sheet
Weeks 3-4

Domain 1 on top of that base

  • Work through security governance, then cybersecurity risk management
  • Study SOC for Cybersecurity and revisit your comparison sheet
  • Practice scenario questions that ask for the best response to a stated risk
Weeks 5-6

Domain 2 and integration

  • Cover data management, data analysis and reporting, and BI management
  • Take mixed practice sets spanning all three domains
  • Revisit whichever underlying area your results show as weakest

Starting with Domain 3 is a deliberate choice: controls and governance language underpins how security and data questions are framed. If your day job is already heavy in IT audit, you could reverse the order and spend the early weeks on Domain 2, which is often the least familiar. For a fuller plan, see the CITP study guide, and keep the CITP cheat sheet handy for last-week review.

Where These Domains Show Up in Real Jobs

The three content areas map closely to work that CPAs are asked to do. Domain 1 appears in cybersecurity risk assessments, security-focused advisory engagements, and SOC for Cybersecurity work. Domain 2 appears in data analytics for audit and finance, reporting and dashboard programs, and data governance initiatives. Domain 3 appears in IT audit, internal audit, SOC examinations, and technology risk advisory.

That breadth is why the credential is relevant to public accounting firms, internal audit and risk functions, and advisory practices. To explore what that looks like in practice, read about CITP jobs, the CITP salary guide, and the broader question of whether the CITP certification is worth it. Keeping the credential also carries ongoing obligations: annual maintenance requires qualifying CPA status, AICPA membership, 20 hours of CITP-related continuing professional development, annual payment, and a compliance attestation.

If you want structured preparation beyond self-study, AICPA offers a 52-CPE CITP Learning Pathway Bundle that includes an exam after you complete all three modules. Listed prices are USD $429 for AICPA or CIMA members, $540 for nonmembers, and $345 for existing CITP holders. These are bundle prices, not standalone exam fees, so do not confuse them with the registration cost. More on formal options is in our overview of CITP training.

Key Takeaway

Treat the three domains as three different lenses on the same professional question: can this organization's technology, data, and security be trusted, and how would you show it? Studying with that question in mind makes the nine underlying areas hang together.

Frequently Asked Questions

How many content areas does the CITP exam have?

The Standard Pathway is organized into three content areas: Information Security & Cyber Risks; Business Intelligence, Data Management and Analytics; and IT Governance, Risks & Controls. AICPA breaks these into nine underlying areas.

Which domain contains SOC for Cybersecurity, and which contains SOC reporting?

SOC for Cybersecurity falls under Information Security & Cyber Risks, while SOC reporting falls under IT Governance, Risks & Controls. They are distinct topics, so learn how they differ before attempting practice questions.

What question format does the Standard Pathway use?

The Standard Pathway uses multiple-choice questions, delivered at Kryterion testing centers or via remote proctoring, with year-round scheduling and immediate results. The Experienced Pathway is a separate exam with case-study-based and standalone multiple-choice questions.

Does passing the CISA exam replace the CITP exam?

Passing the CISA examination waives the CITP examination requirement, but it does not waive the remaining credential requirements such as AICPA membership, a qualifying CPA license or certificate, and the relevant experience hours. See CITP requirements for the full picture.

Where can I practice questions by domain?

Our CITP practice test lets you work through exam-style multiple-choice items so you can identify which of the nine underlying areas needs the most attention before you register.

Ready to pass your CITP exam?

Put this into practice with free CITP questions across every exam domain.