CITP logo
Focused certification exam prep
Start practice

CITP Study Guide 2026: How to Pass on Your First Attempt

TL;DR
  • CITP is issued by AICPA & CIMA and requires a qualifying CPA license, AICPA membership and 1,000 relevant business-experience hours.
  • The Standard Pathway is multiple-choice, delivered at Kryterion centers or online, with immediate results and one included retake.
  • Prepare around three domains: security and cyber risk, data and analytics, and IT governance, risks and controls.
  • Passing the CISA exam waives the CITP exam requirement, but not the other credential requirements.

Before You Open a Book: Confirm You Can Sit the Exam

Most certification study guides begin with a study schedule. For the Certified Information Technology Professional credential, the smarter first step is an eligibility check, because CITP is a credential for CPAs and the exam is gated behind several prerequisites. Studying for months and then discovering you cannot register is the most avoidable mistake in this process.

The credential is governed by the American Institute of Certified Public Accountants (AICPA), within AICPA & CIMA. To register for the Standard Pathway, you need:

  • AICPA membership in good standing.
  • A valid, unrevoked qualifying CPA license or certificate. Active or inactive CPA status can qualify.
  • 1,000 relevant business-experience hours within the preceding 5 years.

An academic experience alternative exists for eligible full-time professors. If your background is in teaching rather than practice, that route is worth investigating before you assume the hours requirement blocks you. For a deeper walkthrough of every prerequisite and how to document your hours, see our guide to CITP requirements, eligibility and prerequisites.

Document your hours early: The 1,000-hour requirement is measured over a rolling 5-year window. Start a simple log now, noting the engagement, the IT-related work performed, and approximate hours, so you are not reconstructing your experience from memory when you register.

Standard Pathway vs. Experienced Pathway

CITP offers two examination routes, and choosing the wrong one wastes time. This guide focuses on the Standard Pathway, which is the primary examination for most CPAs entering the credential. The Experienced Pathway is built for seasoned practitioners and carries much heavier experience requirements.

FeatureStandard PathwayExperienced Pathway
Question styleMultiple-choice60 case-study-based and standalone multiple-choice questions
TimeSee AICPA's registration page for current details2 hours
Experience required1,000 relevant business-experience hours within the preceding 5 yearsAt least 7,000 relevant experience hours and 7 years of relevant experience
Registration rangeUSD $400-$500, member discount after sign-inUSD $165-$220
RetakeOne includedOne included

The lower registration price of the Experienced Pathway is not a shortcut. It reflects a different candidate: someone with seven years of relevant work already behind them. If you do not meet the 7,000-hour and 7-year thresholds, the Standard Pathway is your route. And if you qualify for both, keep your preparation separate. Case-study practice does not substitute for the Standard Pathway's question style, and vice versa.

What the Standard Pathway Exam Looks Like

The Standard Pathway uses multiple-choice questions, delivered either at a Kryterion testing center or through remote online proctoring. Scheduling is available year-round, so there is no fixed testing window to plan around, and results are provided immediately after you finish. If you want the specifics on scheduling mechanics, our CITP exam dates and scheduling guide covers the practical side.

Because the exam is multiple-choice rather than essay or performance-based, your preparation should emphasize two skills: recognizing the correct concept among plausible distractors, and applying professional judgment to short business scenarios. CITP questions typically sit at the intersection of IT and accounting practice, so expect scenarios where a CPA must reason about controls, risk, reporting or data, not just recall a definition.

For a realistic picture of the challenge, read How Hard Is the CITP Exam?, and for scoring details see our CITP passing score explainer. We deliberately avoid quoting pass-rate figures here; our CITP pass rate analysis discusses what can and cannot be said responsibly about the data.

Domain 1: Information Security & Cyber Risks

This domain draws on the exam's information security governance, cybersecurity risk management, and SOC for Cybersecurity areas. It rewards candidates who can think like both an IT risk practitioner and an assurance professional.

Information Security & Cyber Risks

You need to understand how organizations govern security, how they identify and respond to cyber risk, and how an independent practitioner reports on a cybersecurity risk management program.

  • Information security governance: roles and responsibilities, policy frameworks, and how security strategy aligns with business objectives.
  • Cybersecurity risk management: identifying threats and vulnerabilities, assessing likelihood and impact, selecting and evaluating mitigating controls, and incident response thinking.
  • SOC for Cybersecurity: the purpose of this reporting framework, who the intended users are, and how it differs from other attestation reports.

Where candidates lose points here

The common error is treating security as a purely technical subject. CITP questions are written for CPAs, so the correct answer often reflects governance, risk appraisal or reporting purpose rather than a configuration detail. When two options both sound technically sound, ask which one a risk-minded finance or assurance professional would defend.

Pay particular attention to the distinction between a management's cybersecurity risk management program and the examination of that program by a practitioner. Questions in this territory tend to test whether you understand who asserts what, and who provides assurance over it.

Domain 2: Business Intelligence, Data Management and Analytics

This domain maps to the data management, data analysis and reporting, and business intelligence management areas. It is the domain where a CPA's analytical instincts help most, but it also contains vocabulary that accountants do not always use daily.

Business Intelligence, Data Management and Analytics

Expect questions about how data is collected, stored, governed, analyzed and turned into decision-ready information.

  • Data management: data quality, data governance, lifecycle considerations, and the controls that protect integrity and availability.
  • Data analysis and reporting: selecting appropriate analytical approaches, interpreting results, and presenting findings accurately to stakeholders.
  • Business intelligence management: how BI tools and processes support decision-making, and how to evaluate whether a BI environment is reliable.

A practical way to study it

Work from the question "how would this data fail?" Poor source data, flawed transformations, misleading visualizations and weak governance each map to a different failure point. Candidates who can name the failure point usually select the right answer. This domain also overlaps with the controls material in Domain 3, because data integrity is ultimately a control objective, so notes you build here will pay off twice.

Domain 3: IT Governance, Risks & Controls

The third domain covers IT governance and strategy, IT risks and controls, and SOC reporting. For many CPAs this is the most familiar territory, since controls and attestation are core professional concepts, but it is also where over-confidence causes mistakes.

IT Governance, Risks & Controls

This domain tests how IT is directed, how its risks are identified and controlled, and how service organization and related reports are used.

  • IT governance and strategy: aligning IT with organizational goals, oversight structures, and evaluating whether IT investments support strategy.
  • IT risks and controls: general and application controls, change management, access management, and how control deficiencies are evaluated.
  • SOC reporting: the purpose and use of SOC reports, what they tell a user entity, and what they do not.

Keep SOC for Cybersecurity (Domain 1) and the broader SOC reporting material here mentally separate. Both involve reports issued by practitioners, but they serve different purposes and audiences. Building a two-column comparison of scope, users and subject matter is one of the highest-value study artifacts you can create. For a fuller treatment of all three content areas, see our complete guide to the CITP exam domains, and keep our CITP cheat sheet handy for last-week review.

Sequencing the Three Domains Across Your Prep

You do not need a generic study calendar; you need a sequence that respects how the domains reinforce one another. The order below front-loads the domain that supplies vocabulary for the other two. Adjust the number of weeks to your own schedule and experience.

Weeks 1-2

Domain 3 foundation: governance and controls

  • Review IT governance structures and control categories first, since this language recurs across the exam.
  • Build your SOC comparison table early.
Weeks 3-4

Domain 1: security and cyber risk

  • Layer cyber risk management and SOC for Cybersecurity onto your controls knowledge.
  • Practice scenario questions that ask who is responsible for what.
Weeks 5-6

Domain 2: data, BI and analytics

  • Study data governance, analysis approaches and BI reliability, linking each to a control objective.
Final week

Mixed practice and weak-spot repair

  • Take mixed-domain practice sets, then revisit only the topics you missed.

A fuller walk-through of building a plan around the credential is in our CITP training overview. If you are unsure whether the effort is justified, our ROI analysis of the CITP certification can help you decide before you commit.

Official Materials, Bundles and Practice Questions

AICPA & CIMA publishes an exam content specification outline, and it is the single most useful document for scoping your study. Read it before anything else, then map each of its areas to the three domains above so you know exactly where your weak spots are.

AICPA also offers an optional CITP Learning Pathway Bundle, worth 52 CPE, with an exam included after completion of all three modules. Listed bundle prices are USD $429 for AICPA or CIMA members, $540 for nonmembers, and $345 for existing CITP holders. These are bundle prices, not standalone exam fees, so do not confuse them with the Standard Pathway registration range of USD $400-$500. Our CITP certification cost breakdown lays out how the pieces fit together.

Treat the bundle as optional: The Learning Pathway Bundle is structured learning with CPE value, which suits candidates who want guided instruction. It is not a prerequisite for the Standard Pathway exam, so decide based on your learning style and how much of the content is new to you.

For question practice, you can work through realistic items on our CITP practice test site. Practice questions are most valuable when you review the reasoning behind every answer, including the ones you got right. If you guessed correctly, treat it as a miss and revisit the topic.

The CISA Waiver and How It Changes Your Plan

Passing the CISA examination waives the CITP examination requirement. It does not waive the remaining credential requirements, so you still need the qualifying CPA status, AICPA membership and the relevant experience hours. If you already hold or are close to earning CISA, you may be able to skip a separate CITP exam entirely.

The decision between the two credentials depends on your career direction, since they are issued by different bodies and carry different professional signals. We compare them in detail elsewhere, but the planning takeaway is simple: before you invest in CITP exam prep, confirm whether a CISA result changes your path. If you are a CPA considering your next credential, ask whether you want the exam or the waiver.

Registration Mechanics and Exam-Day Logistics

The official Standard Pathway registration is listed at USD $400-$500, with a member discount available after sign-in. A few rules matter for planning:

  • One retake is included with registration, which lowers the cost of a first-attempt miss but does not remove the value of preparing properly.
  • Registration is nonrefundable and nontransferable. Only register once you are ready to schedule.
  • The product lists one-year availability, so build your preparation timeline around that window rather than registering far in advance and letting it lapse.

Choose between a Kryterion testing center and remote proctoring based on your environment. Remote delivery is convenient, but it demands a quiet, compliant space and a reliable connection, so test your setup well before exam day. Because scheduling is year-round, there is no reason to rush into an unready attempt. Pick the date at which you are consistently performing well on mixed practice.

After You Pass: Maintaining the Credential

Earning the credential is not the end of the process. Annual maintenance requires qualifying CPA status, AICPA membership, 20 hours of CITP-related continuing professional development, annual payment and a compliance attestation. If any of those lapses, the credential is at risk, so factor these ongoing obligations into your decision.

The payoff is professional positioning. CITP holders typically work where finance, technology and assurance meet: public accounting firms with IT assurance or advisory practices, internal audit and risk functions, and finance or controllership roles in technology-heavy organizations. For the market view, see our CITP jobs overview and our salary analysis, and if you are still learning the basics, start with what CITP certification is. You can also revisit this CITP study guide as a checklist while you prepare.

Key Takeaway

Verify eligibility first, then study by domain in an order that builds vocabulary: governance and controls, then security and cyber risk, then data and analytics. Use the content specification outline as your map and finish with mixed-domain practice.

Frequently Asked Questions

Who can sit the CITP Standard Pathway exam?

You need AICPA membership in good standing, a valid and unrevoked qualifying CPA license or certificate (active or inactive status can qualify), and 1,000 relevant business-experience hours within the preceding 5 years. An academic experience alternative exists for eligible full-time professors.

How much does the Standard Pathway exam cost?

Official registration is listed at USD $400-$500, with a member discount available after sign-in. One retake is included, and registration is nonrefundable and nontransferable. The optional Learning Pathway Bundle is priced separately and is not a standalone exam fee.

What is the difference between the Standard and Experienced Pathways?

The Standard Pathway is multiple-choice and requires 1,000 relevant experience hours. The Experienced Pathway has 60 case-study-based and standalone multiple-choice questions in 2 hours, requires at least 7,000 hours and 7 years of relevant experience, and has a lower registration range of USD $165-$220.

Does passing CISA mean I skip the CITP exam?

Passing the CISA examination waives the CITP examination requirement, but not the other credential requirements such as CPA status, AICPA membership and experience hours.

What do I need to do to keep the credential after passing?

Annual maintenance requires qualifying CPA status, AICPA membership, 20 hours of CITP-related continuing professional development, annual payment and a compliance attestation.

Ready to pass your CITP exam?

Put this into practice with free CITP questions across every exam domain.