- What the Data Actually Shows (and Doesn't)
- Why There Is No Headline Pass Rate
- Who Sits the Exam: The Pre-Filtered Candidate Pool
- Standard Pathway vs. Experienced Pathway
- Where Candidates Lose Points, Domain by Domain
- Fees, the Included Retake, and Outcome Math
- Improving Your Odds: A CITP-Specific Plan
- Frequently Asked Questions
- Based on the sources checked, AICPA does not publish a headline CITP pass rate, so any precise figure you see is unverified.
- Candidates are pre-filtered: AICPA membership, a qualifying CPA license, and 1,000 relevant business-experience hours are required before registering.
- The Standard Pathway registration is listed at USD $400-$500 and includes one retake, which reshapes the real-world risk of a first fail.
- Passing CISA waives the CITP exam requirement, not the remaining credential requirements.
What the Data Actually Shows (and Doesn't)
Search for a CITP pass rate and you will find confident-sounding percentages on forums, prep vendor pages, and social posts. Treat them with suspicion. For the Certified Information Technology Professional credential from AICPA & CIMA, the sources checked for this article, including the main CITP page, the exam registration pages, and the content specification outline, do not state a published first-attempt pass rate. This article does not make one up.
That may sound unsatisfying, but it is the most useful thing a data-minded candidate can know. If a site quotes an exact number with no citation to AICPA, it is either borrowing a figure from a different credential that shares the "CITP" acronym or guessing. Neither helps you plan.
What we can do is reason from verifiable structural facts: who is allowed to sit the exam, how it is delivered, what it costs, how retakes work, and which content areas are tested. Those facts tell you far more about your real risk than a single percentage would. If you want the difficulty picture from a candidate's perspective, our companion piece on how hard the CITP exam is goes deeper on question style and cognitive load.
Why There Is No Headline Pass Rate
A single published pass rate would be misleading for CITP for several structural reasons, all grounded in how the program is built:
- Two pathways with different exams. The Standard Pathway uses multiple-choice questions. The Experienced Pathway has 60 case-study-based and standalone multiple-choice questions in 2 hours. Blending them into one rate would hide meaningful differences in candidate profile and format.
- Year-round scheduling. Testing is available year-round through Kryterion testing centers or remotely proctored online delivery. There is no single annual cohort sitting the same form on the same day, which makes period-based rates awkward to define.
- Immediate results. Candidates see results right away, so there is no batch-reporting cycle that naturally produces an annual statistic.
- A small, specialized population. CITP is a CPA-focused credential. The eligible pool is a narrow slice of the accounting profession, so rates computed from limited sample sizes would swing wildly.
For the scoring side of the question, see our breakdown of the CITP passing score, which separates what is confirmed from what is commonly assumed.
Who Sits the Exam: The Pre-Filtered Candidate Pool
Even without a published rate, the eligibility gate tells you something important: this is not an open-enrollment exam. Before you can register for the Standard Pathway, you need:
- AICPA membership in good standing.
- A valid and unrevoked qualifying CPA license or certificate. Active or inactive CPA status can qualify.
- 1,000 relevant business-experience hours within the preceding 5 years.
An academic experience alternative is available to eligible full-time professors. The full eligibility picture, including how hours are documented, is covered in our CITP requirements guide.
What does this mean for outcomes? Candidates are already licensed CPAs with real IT-related work history, typically in IT audit, assurance, advisory, internal audit, or finance roles with heavy systems exposure. They have survived a professional licensing regime and already think in terms of controls, risk, and evidence. That is a stronger baseline than a general-population certification exam, and it cuts both ways. Strong candidates tend to be comfortable with the question style, but they can also be overconfident about domains outside their daily work, such as analytics tooling or cybersecurity reporting frameworks.
Standard Pathway vs. Experienced Pathway
Because pass-rate chatter often mixes the two routes, it helps to see them side by side. This site's primary examination is the Standard Pathway; the Experienced Pathway should be prepared for separately.
| Feature | Standard Pathway | Experienced Pathway |
|---|---|---|
| Question format | Multiple-choice questions | 60 case-study-based and standalone multiple-choice questions in 2 hours |
| Registration fee range | USD $400-$500 (member discount after sign-in) | USD $165-$220 |
| Retake | One retake included | One retake included |
| Experience requirement | 1,000 relevant business-experience hours in the preceding 5 years | At least 7,000 relevant experience hours and 7 years of relevant experience |
| Delivery | Kryterion testing centers or remote proctoring; year-round; immediate results | Registered through its own AICPA & CIMA exam page |
| Typical candidate | CPA building toward the credential with a solid IT-related work record | Senior practitioner with extensive IT-related experience |
The practical takeaway: any aggregated "CITP pass rate" blends a candidate who is early in their IT-assurance career with one who has seven or more years of relevant experience. Their odds are not comparable. Keep your preparation pathway-specific, and do not use Experienced Pathway case-study practice as a stand-in for Standard Pathway mock exams. A focused CITP practice test built around the Standard Pathway format is the better rehearsal if that is your route.
Where Candidates Lose Points, Domain by Domain
Without a published rate or official domain-level statistics, we cannot say which domain has the worst fail rate, and anyone claiming that is guessing. What we can do is map the nine underlying content areas from the exam specification to the three headings, and flag where CPAs most often have thin coverage. Our complete domains guide expands on each area.
Domain 1: Information Security & Cyber Risks
This domain covers information security governance, cybersecurity risk management, and SOC for Cybersecurity.
- Distinguish governance responsibilities (policy, oversight, accountability) from operational security controls.
- Understand how cybersecurity risk management programs are described and evaluated.
- Know what a SOC for Cybersecurity engagement is meant to communicate and to whom, versus other reporting types.
- Expect scenario-style questions that test judgment about risk, not memorization of tool names.
Domain 2: Business Intelligence, Data Management and Analytics
This domain covers data management, data analysis and reporting, and business intelligence management.
- Data quality, lifecycle, and governance concepts matter as much as the analytics themselves.
- Be ready to reason about reporting integrity: where data comes from, how it is transformed, and what could go wrong.
- For many audit-trained CPAs, this is the domain with the least day-to-day exposure, so it often deserves extra preparation time.
Domain 3: IT Governance, Risks & Controls
This domain covers IT governance and strategy, IT risks and controls, and SOC reporting.
- Link IT strategy to business objectives and oversight structures.
- Apply control frameworks thinking: identify risks, map controls, evaluate design and operation.
- Know the purpose and audience of SOC reports, a topic that overlaps with Domain 1's SOC for Cybersecurity and invites confusion between report types.
The overlap between SOC for Cybersecurity (Domain 1) and SOC reporting (Domain 3) is a classic place to drop points. Study them side by side so you can tell which report type a scenario is pointing to.
Fees, the Included Retake, and Outcome Math
Since we cannot quote a pass rate, a more decision-useful lens is the financial and procedural structure of an attempt. Official Standard Pathway registration is listed at USD $400-$500, with a member discount available after sign-in. One retake is included. Registration is nonrefundable and nontransferable, and the product lists one-year availability.
Put those together and the real-world risk profile looks quite different from a one-shot exam:
- A first-attempt miss is not a second payment. The included retake means a failed first sitting does not automatically double your registration cost.
- The one-year availability window means your attempts have a clock. Plan your first sitting early enough that a retake still fits comfortably inside it.
- Nonrefundable, nontransferable registration means you should not register until you are genuinely close to ready. You cannot hand the seat to a colleague or recover the fee if plans change.
The optional 52-CPE CITP Learning Pathway Bundle is a separate preparation product, not an exam fee. It includes an exam after completion of all three modules, with listed prices of USD $429 for AICPA or CIMA members, $540 for nonmembers, and $345 for existing CITP holders. Do not confuse these bundle prices with the standalone registration fees above. A complete cost picture is in our CITP certification cost breakdown.
Key Takeaway
Treat the included retake as a safety net, not a strategy. Schedule your first attempt when your practice results are consistently solid across all three domains, and keep your one-year availability window in view so a retake, if needed, is not rushed.
Improving Your Odds: A CITP-Specific Plan
Rather than chasing a statistic, shift your effort to the variables you control. This is the one place we sketch a schedule, and it is tied directly to the domain structure. For a fuller methodology, see the CITP study guide.
Diagnose Before You Study
- Take a baseline CITP practice test to expose which of the three domains is weakest for you.
- Read the content specification outline and mark each of the nine underlying areas as strong, shaky, or unfamiliar.
Domain 2 First
- Start with Business Intelligence, Data Management and Analytics, since it is typically the least familiar to audit-trained CPAs.
- Cover data management, analysis and reporting, and BI management before moving on.
Domain 1, Then Domain 3
- Work through security governance, cyber risk management, and SOC for Cybersecurity.
- Follow with IT governance, IT risks and controls, and SOC reporting, deliberately contrasting the two SOC topics.
Mixed Practice and Review
- Take mixed-domain question sets under timed conditions in the same delivery mode you will use on exam day.
- Review misses by root cause: knowledge gap, misread question, or confusion between similar report types or concepts.
- Use the CITP cheat sheet for a final fact check.
Two additional levers are worth noting. First, if you are weighing the credential against other options, our comparison of the broader landscape in whether CITP is worth it helps you decide how much preparation investment is justified. Second, if you hold or are pursuing CISA, remember that passing the CISA examination waives the CITP examination requirement, though the remaining credential requirements still apply. For some candidates, that route changes the entire calculus of whether to sit the CITP exam at all.
Frequently Asked Questions
Based on the AICPA & CIMA sources checked, no official headline pass rate is published for the Certified Information Technology Professional exam. Be cautious of any specific percentage that does not cite AICPA, since figures from other credentials sharing the CITP acronym circulate widely.
Yes. Both the Standard Pathway and the Experienced Pathway registrations include one retake. Registration is nonrefundable and nontransferable, and the Standard Pathway product lists one-year availability, so plan your attempts within that window.
They are different exams for different candidates. The Experienced Pathway has 60 case-study-based and standalone multiple-choice questions in 2 hours and requires at least 7,000 relevant experience hours and 7 years of relevant experience. Its lower fee range reflects a different program design, not necessarily an easier test.
No. Passing the CISA examination waives the CITP examination requirement only. You must still meet the remaining credential requirements, including AICPA membership and a qualifying CPA license. See our requirements guide for details.
Look for consistent, solid results across all three domains on timed practice sets, not just one strong area. Because registration is nonrefundable, wait until Domain 1 (Information Security & Cyber Risks), Domain 2 (Business Intelligence, Data Management and Analytics), and Domain 3 (IT Governance, Risks & Controls) all feel dependable.