CITP logo
Focused certification exam prep
Start practice

CITP Training

TL;DR
  • CITP is issued through AICPA & CIMA and requires a qualifying CPA license or certificate plus AICPA membership.
  • Standard Pathway candidates need 1,000 relevant business-experience hours within the preceding 5 years.
  • Train across three domains: security and cyber risk, data and analytics, and IT governance, risks and controls.
  • The optional 52-CPE Learning Pathway Bundle is priced at $429 for members, $540 for nonmembers, and $345 for CITP holders.

What CITP Training Actually Covers

CITP training is different from preparing for a general IT certification. The Certified Information Technology Professional credential is built for CPAs who work where technology, controls, and assurance overlap. Training therefore has to do two jobs at once: it must sharpen your technical fluency in areas like cybersecurity risk management and data analytics, and it must keep you thinking like a CPA who evaluates risk, reports to stakeholders, and advises management.

That dual focus shapes everything about how you should prepare. A candidate who treats CITP as a pure technology exam will underinvest in governance, reporting frameworks, and control evaluation. A candidate who treats it as an accounting exam with some IT sprinkled in will be surprised by the depth expected in information security governance and data management. Good training sits in the middle.

If you are still orienting yourself, start with the basics in What Is CITP Certification? and then return here to build a plan. For a broader walkthrough of the preparation process, the CITP Study Guide 2026: How to Pass on Your First Attempt pairs well with this article.

Confirm Eligibility Before You Spend on Training

The most expensive training mistake is preparing for an exam you cannot yet register for. Before buying any course or bundle, verify that you meet the Standard Pathway requirements:

  • AICPA membership in good standing. This is a gate, not a formality.
  • A valid and unrevoked qualifying CPA license or certificate. Active or inactive CPA status can qualify.
  • 1,000 relevant business-experience hours within the preceding 5 years. The experience must be relevant to the domains the credential covers.

An academic experience alternative is available to eligible full-time professors, which matters if your IT-related work happens in a classroom rather than a client engagement. The full breakdown lives in CITP Requirements 2026: Eligibility, Prerequisites & How to Qualify, and it is worth reading before you commit money to training.

Document your hours early: Because the 1,000 hours must fall within the preceding five years, start logging engagements now. Note the client or project, the dates, and which domain the work touched (security, data analytics, or IT governance and controls). Reconstructing this later is far harder than recording it as you go.

Standard vs. Experienced Pathway: Train for the Right Exam

AICPA offers two routes to the exam, and they call for different preparation. The Standard Pathway is the primary examination most candidates take. The Experienced Pathway is designed for seasoned practitioners and has a distinct structure.

FeatureStandard PathwayExperienced Pathway
Experience required1,000 relevant hours within the preceding 5 yearsAt least 7,000 relevant hours and 7 years of relevant experience
Question formatMultiple-choice questions60 case-study-based and standalone multiple-choice questions in 2 hours
Registration rangeUSD $400-$500, member discount available after sign-inUSD $165-$220
RetakeOne retake includedOne retake included

Keep your preparation for the two pathways separate. The Experienced Pathway leans on case-study reasoning, so practicing with Standard Pathway mock questions will not fully prepare you for it, and the reverse is also true. Decide which pathway applies to you before you pick study materials. Details on scheduling both routes appear in CITP Exam Dates 2026: Testing Windows, Deadlines & Scheduling.

Domain-by-Domain Training Priorities

The exam content is organized into three headings, with nine underlying areas beneath them. Effective training maps your study time to those headings and to the specific subtopics inside each. For a full treatment, see CITP Exam Domains 2026: Complete Guide to All 3 Content Areas. The summary below focuses on what to train.

Domain 1: Information Security & Cyber Risks

This domain covers information security governance, cybersecurity risk management, and SOC for Cybersecurity. Expect to reason about how an organization governs security, identifies and responds to cyber risk, and how a CPA reports on a cybersecurity risk management program.

  • How security governance structures assign accountability and oversight
  • Cybersecurity risk assessment and the lifecycle of managing identified risks
  • The purpose, scope, and reporting structure of SOC for Cybersecurity engagements
  • Distinguishing management's responsibilities from the practitioner's responsibilities

Domain 2: Business Intelligence, Data Management and Analytics

This domain spans data management, data analysis and reporting, and business intelligence management. It rewards candidates who understand how data moves through an organization and how it becomes decision-ready information.

  • Data governance, quality, and lifecycle management concepts
  • Selecting appropriate analysis and reporting approaches for a business question
  • How business intelligence programs are managed and aligned to organizational goals
  • Risks that poor data management introduces into reporting and controls

Domain 3: IT Governance, Risks & Controls

This domain covers IT governance and strategy, IT risks and controls, and SOC reporting. It is where CPA assurance instincts meet technology, and candidates with audit backgrounds often find it the most natural.

  • How IT strategy aligns with business objectives and is overseen at the governance level
  • Identifying IT risks and evaluating the controls that address them
  • SOC reporting: what the reports are for, who relies on them, and how to interpret them
  • The relationship between general IT controls and the reliability of financial reporting

The 52-CPE Learning Pathway Bundle

AICPA offers an optional preparation product called the CITP Learning Pathway Bundle. It delivers 52 CPE credits across three modules and includes an exam that unlocks after you complete all three modules. Because the modules map to the credential's subject matter, many candidates use the bundle as structured instruction rather than assembling resources piecemeal.

Listed bundle prices are USD $429 for AICPA or CIMA members, $540 for nonmembers, and $345 for existing CITP holders. These are bundle prices, not standalone exam fees, so do not add them to or confuse them with the official registration cost when you budget. Our CITP Certification Cost 2026: Complete Pricing Breakdown lays out how the pieces fit together.

Is the bundle required? No. It is optional preparation. It tends to suit candidates who want guided, credit-bearing instruction, especially if their daily work touches only one or two of the three domains. Candidates who already work across security, data, and IT controls may prefer lighter-weight practice and targeted review instead.

Training for the Multiple-Choice Format

The Standard Pathway uses multiple-choice questions, which means your training should include realistic question practice rather than only reading. CITP questions typically present a business or technology scenario and ask you to identify the best response, the most significant risk, or the most appropriate control. The skill being tested is judgment, not recall of definitions alone.

When you work through practice items, train yourself to do three things:

  1. Identify the role. Is the question asking what management should do, what a practitioner should evaluate, or what a governance body should oversee?
  2. Locate the domain. Recognizing whether a scenario is about cyber risk, data management, or IT controls narrows which framework applies.
  3. Eliminate on principle. Wrong answers are often plausible actions that belong to a different role or address a different risk.

You can build this habit with a realistic AICPA CITP practice test and review every explanation, including for items you answered correctly. If you want a sense of how demanding the questions are before you start, read How Hard Is the CITP Exam? Complete Difficulty Guide 2026.

Sequencing Your Training Across the Domains

Generic scheduling advice is less useful than a sequence tied to how the domains build on each other. A sensible order starts with whichever domain is furthest from your daily work and finishes with an integrated review. Here is one example framework for a candidate whose background is audit-heavy and lighter on data analytics:

Weeks 1-2

Domain 2 first: the unfamiliar ground

  • Learn data management and business intelligence concepts while your energy is highest
  • Practice matching reporting and analysis approaches to business questions
Weeks 3-4

Domain 1: security and cyber risk

  • Cover security governance and cybersecurity risk management
  • Study SOC for Cybersecurity scope and reporting
Weeks 5-6

Domain 3: governance, risks, and controls

  • Reinforce IT governance and strategy and control evaluation
  • Review SOC reporting and how reports are interpreted
Week 7

Integrated practice and weak-area repair

  • Take mixed-domain practice sets under timed conditions
  • Revisit the two or three subtopics where you missed the most items

Reverse the order if your strengths run the other way. A security specialist might begin with Domain 3 to build the governance and assurance lens. The principle is to tackle your weakest area while you have the most time to recover from it. For a condensed reference as exam day approaches, the CITP Cheat Sheet 2026: One-Page Review of Must-Know Facts works as a final pass.

Where CISA Fits Into Your Training Plan

Many candidates ask about the relationship between CITP and CISA. The key fact for training purposes is this: passing the CISA examination waives the CITP examination requirement. It does not waive the remaining credential requirements, so you would still need to satisfy eligibility, membership, and other conditions.

That makes the choice a strategic one. If you already hold CISA, you may be able to skip the exam portion of CITP and focus your effort on meeting the other requirements. If you hold neither, you can weigh which exam better matches your career direction, since the two credentials emphasize different things. CITP is positioned for CPAs and their advisory and assurance roles, while CISA is a separate credential with its own scope. We compare the two in more depth in Is the CITP Certification Worth It? Complete ROI Analysis 2026.

Key Takeaway

Do not assume holding CISA means you automatically hold CITP. The waiver applies only to the exam requirement. Confirm the remaining requirements with AICPA before you plan around it.

Registration, Retakes, and Test-Day Logistics

Knowing the mechanics ahead of time removes avoidable stress. For the Standard Pathway, the official registration is listed at USD $400-$500, with a member discount available after you sign in. One retake is included. Registration is nonrefundable and nontransferable, and the product lists one-year availability, so plan your window carefully rather than registering and then letting months slip by.

Delivery is through Kryterion testing centers or remotely proctored online delivery, with year-round scheduling and immediate results. The flexibility is useful: you can pick a testing center if you prefer a controlled environment, or take the exam from home if your setup meets the proctoring requirements.

  • Choose your delivery mode early. If you go remote, test your equipment and room setup well before exam day.
  • Register when your training is mostly done. Because the registration clock runs for a year and fees are nonrefundable, avoid registering as a motivational gimmick unless you are genuinely ready to commit.
  • Understand the retake. One retake is included, which lowers the cost of a first-attempt miss but is no reason to take the first sitting casually.

If you want to understand how scoring works before you sit, read CITP Passing Score 2026: Exactly What You Need to Pass and, for a data-informed look at outcomes, CITP Pass Rate 2026: What the Data Shows.

Training Doesn't End at the Exam: Maintenance

Earning the credential starts a maintenance cycle, and your training habits should anticipate it. Annual maintenance requires qualifying CPA status, AICPA membership, 20 hours of CITP-related continuing professional development, annual payment, and a compliance attestation.

The 20 CITP-related CPD hours are the practical piece. Rather than scrambling at the end of a cycle, treat continuing education as an ongoing extension of your training. Topics that map to the three domains, such as evolving cyber risk practices, data analytics techniques, and IT control frameworks, keep both your skills and your credential current.

The credential also supports career direction. If you are weighing where CITP can take you, explore CITP Jobs for the kinds of roles where this expertise is valued, and CITP Salary Guide 2026: Complete Earnings Analysis for a qualitative look at compensation considerations.

Frequently Asked Questions

Do I need formal training to take the CITP exam?

No. The AICPA Learning Pathway Bundle is optional preparation, not a prerequisite. You must meet the eligibility requirements, including AICPA membership, a qualifying CPA license or certificate, and 1,000 relevant business-experience hours for the Standard Pathway, but how you prepare is up to you.

How much does the CITP Learning Pathway Bundle cost?

Listed prices are USD $429 for AICPA or CIMA members, $540 for nonmembers, and $345 for existing CITP holders. The bundle provides 52 CPE credits across three modules and includes an exam after you complete all of them. These are bundle prices, not the standalone exam registration fee.

Can I use the same study materials for the Standard and Experienced Pathways?

Not entirely. The Standard Pathway uses multiple-choice questions, while the Experienced Pathway has 60 case-study-based and standalone multiple-choice questions in 2 hours. Keep your practice separate so you build the right skills for the pathway you are taking.

If I pass CISA, do I still need to do anything for CITP?

Passing CISA waives the CITP examination requirement, but it does not waive the remaining credential requirements. You would still need to meet eligibility, membership, and the other conditions for the credential.

What do I need to keep my CITP credential active?

Annual maintenance requires qualifying CPA status, AICPA membership, 20 hours of CITP-related continuing professional development, annual payment, and a compliance attestation.

Ready to measure where your training stands? Work through realistic questions on the CITP Exam Prep practice site and use the results to focus your remaining study time on the domains that need it most.

Ready to pass your CITP exam?

Put this into practice with free CITP questions across every exam domain.