CITP logo
Focused certification exam prep
Start practice

CITP Requirements 2026: Eligibility, Prerequisites & How to Qualify

TL;DR
  • CITP eligibility requires AICPA membership in good standing, a valid CPA license or certificate, and 1,000 relevant business-experience hours.
  • The 1,000 hours must fall within the preceding 5 years, and active or inactive CPA status can qualify.
  • Passing the CISA exam waives only the CITP exam requirement, not membership, licensure, or experience requirements.
  • The Experienced Pathway needs at least 7,000 relevant hours and 7 years of experience, with a separate 60-question exam.

CITP Requirements at a Glance

The Certified Information Technology Professional credential is awarded by the American Institute of Certified Public Accountants (AICPA), operating within AICPA & CIMA. Unlike many technology certifications that anyone can sit for after paying a fee, CITP is a credential layered on top of the CPA profession. That single design choice shapes every requirement: you must already be a CPA (or hold a qualifying CPA certificate), you must belong to the AICPA, and you must demonstrate real business experience with information technology before the credential is granted.

If you are still orienting yourself to the credential, our overview pages on what CITP certification is and what CITP stands for cover the basics. This article focuses squarely on the gatekeeping question: who can qualify, what you must document, and how the pieces fit together.

RequirementStandard PathwayExperienced Pathway
AICPA membershipGood standing requiredRequired for the credential
CPA license or certificateValid and unrevoked; active or inactive can qualifyValid and unrevoked CPA status
Relevant experience1,000 hours within the preceding 5 yearsAt least 7,000 hours and 7 years of relevant experience
ExaminationMultiple-choice Standard Pathway exam60 case-study-based and standalone multiple-choice questions in 2 hours
Registration rangeUSD $400-$500, member discount after sign-inUSD $165-$220
RetakeOne retake includedOne retake included

The Three Eligibility Gates

Think of CITP qualification as three gates you must pass through in any order, but all of which must be open before the credential is conferred.

Gate 1: AICPA Membership in Good Standing

You must be an AICPA member, and your membership must be in good standing. This is a real prerequisite rather than a formality. A lapsed membership, unpaid dues, or an open disciplinary matter can stall your application. Because membership also unlocks a member discount on Standard Pathway registration, joining early often pays for itself when you reach the registration step.

Gate 2: A Valid, Unrevoked CPA License or Certificate

The second gate is a qualifying CPA license or certificate that is valid and has not been revoked. Two details trip people up here:

  • Active versus inactive status. Active or inactive CPA status can qualify. If you moved into an industry or consulting role and placed your license on inactive status, you are not automatically disqualified.
  • Revocation is disqualifying. A revoked license does not meet the standard, regardless of how much IT experience you have accumulated.

Gate 3: 1,000 Relevant Business-Experience Hours in the Past 5 Years

The third gate is experience. Standard Pathway candidates need 1,000 hours of relevant business experience within the preceding 5 years. The five-year window matters: experience from a decade ago, however substantial, does not count toward this threshold. We unpack how to tally and document those hours in the next section.

Academic alternative: The experience requirement has an academic experience alternative available to eligible full-time professors. If you teach full time and your scholarship or instruction centers on information technology topics relevant to the credential, confirm your eligibility directly with AICPA before assuming you must accumulate business hours.

Counting Your 1,000 Experience Hours

The 1,000-hour threshold sounds modest until you start documenting it. A full-time employee works roughly 2,000 hours a year, so reaching 1,000 relevant hours does not require a full year of exclusive IT work. It does require that the hours be genuinely relevant, which means they should map to the subject matter the credential covers.

What Counts as Relevant

The credential's content spans information security and cybersecurity risk, data management and analytics, business intelligence, IT governance, and IT risks and controls. Work that plausibly counts includes:

  • Assessing or testing IT general controls and application controls during audits or internal reviews
  • Performing or supporting SOC 1, SOC 2, or SOC for Cybersecurity engagements
  • Designing or evaluating cybersecurity risk management programs and governance structures
  • Building data analysis, reporting, or business intelligence solutions that support financial or operational decisions
  • Advising on IT strategy, IT governance frameworks, or technology risk

Documenting Hours Defensibly

Even though the credential is verified through an application process, the smart habit is to keep a running log from the day you decide to pursue it. Record the engagement or project, the dates, an approximate hour count, and a one-line description of the IT-related work performed. Reconstructing hours from memory two years later is painful and error-prone.

Watch the rolling window: Because the 1,000 hours must fall in the preceding 5 years, your oldest hours age out as time passes. If you are borderline, do not wait: early hours in your log may drop out of the window before you apply.

The CISA Waiver: What It Does and Does Not Do

One of the most commonly misunderstood CITP rules involves the Certified Information Systems Auditor (CISA) certification. Passing the CISA examination waives the CITP examination requirement. That is a meaningful shortcut for professionals who already hold CISA, because it removes the need to sit for the CITP exam itself.

But read the rule carefully: the waiver covers the exam only. You must still satisfy every remaining requirement: AICPA membership in good standing, a valid and unrevoked CPA license or certificate, and the required relevant experience. A CISA holder who is not a CPA cannot use the waiver to bypass the CPA gate. CISA is a separate credential with a different purpose, and the waiver is a recognition of overlapping exam content rather than a substitute for the CPA foundation.

If you are weighing the two credentials against each other, the key distinction is audience and scope. CISA is a stand-alone information systems audit credential, while CITP is a CPA-anchored designation that blends IT with accounting, assurance, and business advisory. Candidates who hold both often find the combination valuable, and the waiver rewards that overlap.

Key Takeaway

If you already passed CISA, do not skip the paperwork. The waiver removes the CITP exam, but you still need AICPA membership, valid CPA status, and the experience hours. Verify the current waiver process on the AICPA site before you plan around it.

Standard Pathway vs. Experienced Pathway

AICPA offers two routes to demonstrating competence, and choosing the wrong one wastes time and money. The Standard Pathway is the primary examination route for most candidates and the one this site's practice materials are built around. The Experienced Pathway is a distinct alternative for seasoned professionals.

The Standard Pathway

The Standard Pathway uses multiple-choice questions and pairs with the 1,000-hour experience requirement. It is designed for CPAs who have meaningful but not necessarily decades-long IT exposure. Because the experience threshold is lower, the examination carries more of the burden of proving competence. This is the pathway to target if you are early or mid-career and building toward the credential.

The Experienced Pathway

The Experienced Pathway demands considerably more history: at least 7,000 relevant experience hours and 7 years of relevant experience. In exchange, the exam is shorter and cheaper. It contains 60 case-study-based and standalone multiple-choice questions to be completed in 2 hours, with a registration range of USD $165-$220 that includes one retake.

Keep the preparation separate: The Experienced Pathway's case-study format differs from the Standard Pathway's multiple-choice-only structure. Do not use a Standard Pathway mock exam to simulate Experienced Pathway conditions, and do not assume skills practiced for one transfer cleanly to the other. If you qualify for both, pick the route that matches your profile and prepare specifically for it.

For a side-by-side view of how demanding each route feels in practice, see our breakdown in How Hard Is the CITP Exam?, and for the cost implications of choosing one route over the other, read the CITP certification cost breakdown.

Registration, Fees, and Retake Mechanics

Meeting the eligibility gates and registering for the exam are related but separate steps. Here is how the mechanics work for the Standard Pathway.

  • Registration fee: Official Standard Pathway registration is listed at USD $400-$500. A member discount is available after you sign in to your AICPA account.
  • Retake included: One retake is included with registration, which softens the downside of a first-attempt miss.
  • Non-refundable and non-transferable: Registration cannot be refunded or handed to another person, so confirm your readiness and eligibility before you pay.
  • One-year availability: The product lists one-year availability, meaning you have a defined window to use the registration, including the retake.
  • Delivery: Testing takes place at Kryterion testing centers or through remotely proctored online delivery, with year-round scheduling and immediate results.

Year-round scheduling is a genuine advantage. You are not bound to fixed testing windows, so you can sit the exam when your preparation peaks rather than when a calendar forces you. For scheduling specifics, see our guide to CITP exam dates and scheduling.

Do not confuse the bundle with the exam fee: The 52-CPE CITP Learning Pathway Bundle is optional preparation, not a requirement. It includes an exam after you complete all three modules, with listed prices of USD $429 for AICPA or CIMA members, $540 for nonmembers, and $345 for existing CITP holders. These are bundle prices, not standalone exam fees, so do not add them to or substitute them for the registration figures above.

What the Exam Actually Tests

Eligibility gets you to the starting line; the content determines whether you finish. AICPA organizes the Standard Pathway examination under three content headings, which draw on nine underlying areas: information security governance, cybersecurity risk management, SOC for Cybersecurity, data management, data analysis and reporting, business intelligence management, IT governance and strategy, IT risks and controls, and SOC reporting.

Domain 1: Information Security & Cyber Risks

This domain covers how organizations govern and protect information and how CPAs assess and report on cybersecurity.

  • Information security governance and accountability structures
  • Cybersecurity risk management processes
  • SOC for Cybersecurity reporting concepts

Domain 2: Business Intelligence, Data Management and Analytics

This domain addresses how data is stored, governed, analyzed, and turned into decision-ready reporting.

  • Data management practices and data quality
  • Data analysis and reporting techniques
  • Business intelligence management

Domain 3: IT Governance, Risks & Controls

This domain links technology strategy and control design to assurance engagements.

  • IT governance and strategy alignment
  • IT risks and controls, including general and application controls
  • SOC reporting for service organizations

For a deeper tour of each area, read our complete CITP exam domains guide. Understanding these domains also informs your experience-hour strategy: the work you log toward the 1,000 hours should ideally overlap with the domains you will be tested on, which makes preparation and qualification reinforce each other.

A Qualification Plan Built Around the Domains

Generic study calendars are everywhere; the useful move is sequencing your preparation around how the three CITP domains relate to your own background. Use the timeline below as a template and shift the order depending on where your experience is strongest.

Weeks 1-2

Confirm eligibility and map your gaps

  • Verify AICPA membership status and CPA license standing
  • Total your relevant hours in the past 5 years against the 1,000-hour threshold
  • Decide Standard versus Experienced Pathway based on hours and years of experience
Weeks 3-5

Start with your weakest domain

  • Audit-heavy CPAs: begin with Domain 2 (Business Intelligence, Data Management and Analytics)
  • Data and analytics professionals: begin with Domain 3 (IT Governance, Risks & Controls)
  • Take notes on SOC reporting vocabulary, which spans domains
Weeks 6-8

Cover the security domain and consolidate

  • Work Domain 1 (Information Security & Cyber Risks) with emphasis on SOC for Cybersecurity
  • Run timed question sets across all three domains
  • Review misses by domain, then register once scores are consistently strong

The logic is simple: spend your first heavy study weeks where your professional experience gives you the least advantage, because strong areas need only refreshing. For a fuller methodology, our CITP study guide walks through resources and pacing, and you can pressure-test your readiness on the CITP practice test site before paying for a registration you cannot refund.

Keeping the Credential After You Qualify

Qualifying is not a one-time event. CITP carries ongoing obligations, and failing to meet them can cost you the designation. Annual maintenance requires:

  • Qualifying CPA status
  • AICPA membership
  • 20 hours of CITP-related continuing professional development
  • Annual payment
  • A compliance attestation

The practical takeaway is that the same three gates you cleared to earn the credential must stay open every year. If your CPA license lapses or you let your AICPA membership expire, you lose the foundation the credential rests on. Plan your CPD hours around CITP-relevant topics throughout the year rather than scrambling at the deadline.

If you are evaluating whether the ongoing commitment is worth it, our ROI analysis of CITP weighs maintenance effort against career benefits, and the CITP salary guide and CITP jobs page cover the career side.

Key Takeaway

Treat eligibility as a checklist you re-verify annually, not once. CPA status, AICPA membership, 20 CITP-related CPD hours, payment, and attestation all recur. Build them into your yearly calendar from day one.

Frequently Asked Questions

Do I need to be a CPA to earn the CITP credential?

Yes. CITP requires a valid and unrevoked qualifying CPA license or certificate, along with AICPA membership in good standing. Active or inactive CPA status can qualify, but a revoked license does not.

How much experience do I need for the Standard Pathway?

You need 1,000 relevant business-experience hours within the preceding 5 years. An academic experience alternative is available to eligible full-time professors. The Experienced Pathway is separate and requires at least 7,000 hours and 7 years of relevant experience.

Does passing CISA mean I automatically get CITP?

No. Passing the CISA examination waives the CITP examination requirement only. You must still hold AICPA membership in good standing, a valid CPA license or certificate, and meet the experience requirement before the credential is granted.

What does the Standard Pathway exam registration cost, and is there a retake?

Official Standard Pathway registration is listed at USD $400-$500, with a member discount available after sign-in. One retake is included. Registration is nonrefundable and nontransferable, and the product lists one-year availability. See the full cost breakdown for planning details.

How do I stay certified once I qualify?

Annual maintenance requires qualifying CPA status, AICPA membership, 20 hours of CITP-related continuing professional development, annual payment, and a compliance attestation. Missing any of these can jeopardize the credential.

Ready to pass your CITP exam?

Put this into practice with free CITP questions across every exam domain.