CITP logo
Focused certification exam prep
Start practice

What Does CITP Mean?

TL;DR
  • CITP stands for Certified Information Technology Professional, a credential issued by the AICPA within AICPA & CIMA.
  • Candidates need AICPA membership, a valid CPA license or certificate, and 1,000 relevant business-experience hours within 5 years.
  • The Standard Pathway covers three content areas: security and cyber risks, data and analytics, and IT governance and controls.
  • Passing the CISA exam waives the CITP exam requirement, but not the remaining credential requirements.

The Short Answer: What CITP Means

CITP stands for Certified Information Technology Professional. It is a specialty credential for CPAs who work where accounting, technology, and risk meet. The designation signals that a CPA has demonstrated knowledge of information security, data management and analytics, and IT governance and controls, rather than only traditional accounting and audit skills.

If you have seen the letters on a business card or LinkedIn profile and wondered what they represent, this is the meaning: a CPA who has gone beyond general accounting competence to show depth in technology-related assurance and advisory work. For other phrasings of the same question, see our explainers on what CITP stands for and the broader overview of CITP certification.

Who Issues It and Why It Exists

The credential is governed by the American Institute of Certified Public Accountants (AICPA), operating within AICPA & CIMA. That origin explains much about how the credential works. It is not a general IT certification open to anyone with a technology background. It is built for CPAs, and its structure assumes the holder already has professional accounting standing.

The reason it exists is straightforward. Modern financial reporting, audit, and advisory work depend on information systems. Auditors evaluate IT general controls, assurance providers examine cybersecurity risk management programs, and finance teams rely on data analytics and business intelligence. CITP gives CPAs a recognized way to show competence in those areas, and gives employers and clients a quick signal when they need someone who can bridge the finance and technology sides of an engagement.

Identity check: On this site, CITP always means the AICPA's Certified Information Technology Professional. Other credentials use the same four letters, but nothing on this page, including eligibility, fees, and exam content, applies to them. If you are researching a different certification, confirm the issuing body before relying on any details.

Why the Acronym Causes Confusion

"CITP" is a short acronym, and short acronyms get reused. Searching the letters can surface unrelated credentials from other organizations, which is a common source of mistaken assumptions about requirements and costs. The simplest safeguard is to anchor on the issuing body. The credential covered here is the one granted by the AICPA, and it is tied to CPA status. If a source does not mention the AICPA, CPAs, or the three content areas described below, it is probably describing something else.

For a plain-language walkthrough of the term itself, our guides to CITP meaning and what a CITP is approach the same question from different angles.

What the Credential Actually Covers

The Standard Pathway exam is organized into three content areas, each built from underlying subject areas. Understanding these tells you more about what CITP means in practice than the title alone does.

Domain 1: Information Security & Cyber Risks

This area addresses how organizations govern and manage security and cyber risk, and how assurance is provided over it.

  • Information security governance
  • Cybersecurity risk management
  • SOC for Cybersecurity

Domain 2: Business Intelligence, Data Management and Analytics

This area concerns how data is organized, analyzed, and turned into reporting that supports decisions.

  • Data management
  • Data analysis and reporting
  • Business intelligence management

Domain 3: IT Governance, Risks & Controls

This area covers how technology is directed, how its risks are identified, and how controls and service-organization reporting are evaluated.

  • IT governance and strategy
  • IT risks and controls
  • SOC reporting

The pattern is worth noticing. Domain 1 is about protecting information, Domain 2 is about using information, and Domain 3 is about governing the systems that hold it. A CPA who masters all three can speak credibly about technology risk to boards, audit committees, and clients. For a deeper breakdown of each area, read our complete guide to the CITP exam domains.

The Role of SOC Reporting Knowledge

Two of the nine underlying areas, SOC for Cybersecurity and SOC reporting, relate to System and Organization Controls engagements. This is a distinctive feature of an AICPA credential: the AICPA develops the frameworks behind these reports, so the exam treats them as core knowledge rather than peripheral topics. Candidates who have never worked on a SOC engagement should expect to invest extra time here.

Who Qualifies for CITP

The eligibility rules are what most clearly separate CITP from open-enrollment certifications. For the Standard Pathway, you need all of the following:

  • AICPA membership in good standing
  • A valid and unrevoked qualifying CPA license or certificate
  • 1,000 relevant business-experience hours within the preceding 5 years

Active or inactive CPA status can qualify, which matters for CPAs who have moved into roles where they no longer maintain an active license. An academic experience alternative exists for eligible full-time professors, recognizing that teaching in this field is a legitimate route to the experience requirement.

Eligibility before exam prep: Because the credential requires CPA status and AICPA membership, confirm both before you spend money on study materials. The experience-hours requirement is also easy to underestimate if your technology work has been spread across other duties. Our full breakdown of CITP requirements explains how to document and count qualifying hours.

Standard Pathway vs. Experienced Pathway

CITP offers two routes to the exam, and they are designed for different career stages. Keep the two separate in your preparation, since the formats differ.

FeatureStandard PathwayExperienced Pathway
Experience required1,000 relevant business-experience hours within the preceding 5 yearsAt least 7,000 relevant experience hours and 7 years of relevant experience
Question formatMultiple-choice questions60 case-study-based and standalone multiple-choice questions
TimeSet by the exam product2 hours
Registration rangeUSD $400-$500USD $165-$220
RetakeOne retake includedOne retake included

The Experienced Pathway rewards depth of career experience with a lower fee and a case-study-influenced format. The Standard Pathway is the primary route for CPAs earlier in their technology specialization, and it is the focus of this site's practice resources. If you are unsure which route fits you, start with the experience-hours thresholds above; they decide the question for most candidates.

Fees and Registration Mechanics

Official Standard Pathway registration is listed at USD $400-$500, and a member discount is available after sign-in. One retake is included. Registration is nonrefundable and nontransferable, and the product lists one-year availability, so you should register with a realistic plan to test within that window rather than as a placeholder.

Delivery is through Kryterion testing centers or remotely proctored online delivery, with year-round scheduling and immediate results. That flexibility removes the fixed testing-window constraint that many professional exams impose. For scheduling specifics, see CITP exam dates and scheduling.

Optional Learning Pathway Bundle

AICPA also offers a 52-CPE CITP Learning Pathway Bundle that includes an exam after completion of all three modules. Listed prices are USD $429 for AICPA or CIMA members, $540 for nonmembers, and $345 for existing CITP holders. These are bundle prices, not standalone exam fees, so do not compare them directly against the registration range above. The bundle can make sense if you want structured instruction plus CPE credit, but it is optional. For the complete financial picture, including renewal costs, see our CITP certification cost breakdown.

Key Takeaway

Budget in two layers: the exam registration (a range, with a member discount after sign-in) and any optional preparation. Treat the bundle as a training product with an exam attached, not as a cheaper way to register.

CITP vs. CISA: How They Relate

CPAs interested in technology assurance often weigh CITP against CISA, the Certified Information Systems Auditor credential. They are different credentials from different bodies, but they connect in one important way: passing the CISA examination waives the CITP examination requirement. It does not waive the remaining credential requirements, so you would still need AICPA membership, CPA standing, and the experience hours.

  • CITP is a CPA-focused credential from the AICPA with broad coverage of security, data analytics, and IT governance.
  • CISA is an IT audit credential from a separate body, and it is not limited to CPAs.
  • The overlap is the waiver: a CPA who already holds CISA credit has a shorter route to CITP.

Which is better depends on your career direction. A CPA whose clients expect an accounting-profession designation will often find CITP more recognizable in that context, while someone whose work is purely IT audit may value CISA for its audience. Many professionals eventually hold both. Our ROI analysis of CITP walks through the trade-offs in more depth.

Who Hires CITP Holders

CITP is relevant wherever CPAs are asked to evaluate or advise on technology. Typical employers and roles include:

  • Public accounting firms, particularly in IT audit, risk advisory, and SOC reporting practices
  • Corporate finance and internal audit teams responsible for controls over financial reporting systems
  • Consulting practices advising on cybersecurity risk, data governance, and analytics programs
  • Organizations building data and analytics capabilities that need finance-literate leadership

The credential tends to matter most in roles where a client or stakeholder wants proof that the CPA understands technology risk, not just accounting. Our CITP jobs overview and salary guide cover hiring patterns and earnings in more detail.

Keeping the Credential Active

Earning CITP is not a one-time event. Annual maintenance requires:

  1. Qualifying CPA status
  2. AICPA membership
  3. 20 hours of CITP-related continuing professional development
  4. Annual payment
  5. Compliance attestation

The 20-hour CPD requirement is specific to CITP-related topics, so general accounting CPE will not necessarily satisfy it. Plan your annual learning around the three domains so your maintenance hours also keep your technical knowledge current.

A Domain-Based Preparation Sequence

Rather than a generic study calendar, sequence your preparation around how the three domains build on each other. This is one reasonable ordering; adjust it to your background.

Start

Domain 3 first if you come from audit

  • IT governance, risks, and controls will feel familiar, giving you early momentum
  • Review SOC reporting concepts, since they bridge into Domain 1
Middle

Domain 1: security and cyber risk

  • Study governance, cyber risk management, and SOC for Cybersecurity together
  • Practice distinguishing control objectives from control activities
Later

Domain 2: data and analytics

  • Candidates from audit or tax backgrounds often need the most time here
  • Focus on data management, reporting, and business intelligence concepts
Final

Mixed practice

  • Take timed multiple-choice sets across all three domains
  • Review every miss against its domain

If your background is in data or analytics instead, reverse the order and give Domain 3 the extra time. For a complete plan, use our CITP study guide, and keep the CITP cheat sheet handy for last-week review. When you are ready to test yourself on question style and pacing, try the CITP practice tests on the main site.

To calibrate your expectations before you commit, read how hard the CITP exam is and the notes on the passing score.

Frequently Asked Questions

What does CITP stand for?

CITP stands for Certified Information Technology Professional. It is a credential offered by the AICPA, within AICPA & CIMA, for CPAs with expertise in technology, security, data, and IT governance.

Do I need to be a CPA to earn CITP?

Yes. The credential requires a valid and unrevoked qualifying CPA license or certificate, along with AICPA membership in good standing. Active or inactive CPA status can qualify, and an academic experience alternative exists for eligible full-time professors.

What subjects does the CITP exam cover?

The Standard Pathway covers three content areas: Information Security & Cyber Risks; Business Intelligence, Data Management and Analytics; and IT Governance, Risks & Controls. These draw on nine underlying subject areas, including SOC for Cybersecurity and SOC reporting.

How much does the CITP exam cost?

Official Standard Pathway registration is listed at USD $400-$500, with a member discount available after sign-in. One retake is included, and registration is nonrefundable and nontransferable. The Experienced Pathway is listed at USD $165-$220.

Can CISA replace the CITP exam?

Passing the CISA examination waives the CITP examination requirement, but it does not waive the other credential requirements. You still need AICPA membership, CPA standing, and the required experience hours.

Understanding what CITP means is the first step; deciding whether it fits your career is the second. For the full picture, continue with what CITP is, check what is known about pass rates, and review the available CITP training options.

Ready to pass your CITP exam?

Put this into practice with free CITP questions across every exam domain.