- The Short Answer: What CITP Means
- Who Issues It and Why It Exists
- Why the Acronym Causes Confusion
- What the Credential Actually Covers
- Who Qualifies for CITP
- Standard Pathway vs. Experienced Pathway
- Fees and Registration Mechanics
- CITP vs. CISA: How They Relate
- Who Hires CITP Holders
- Keeping the Credential Active
- A Domain-Based Preparation Sequence
- Frequently Asked Questions
- CITP stands for Certified Information Technology Professional, a credential issued by the AICPA within AICPA & CIMA.
- Candidates need AICPA membership, a valid CPA license or certificate, and 1,000 relevant business-experience hours within 5 years.
- The Standard Pathway covers three content areas: security and cyber risks, data and analytics, and IT governance and controls.
- Passing the CISA exam waives the CITP exam requirement, but not the remaining credential requirements.
The Short Answer: What CITP Means
CITP stands for Certified Information Technology Professional. It is a specialty credential for CPAs who work where accounting, technology, and risk meet. The designation signals that a CPA has demonstrated knowledge of information security, data management and analytics, and IT governance and controls, rather than only traditional accounting and audit skills.
If you have seen the letters on a business card or LinkedIn profile and wondered what they represent, this is the meaning: a CPA who has gone beyond general accounting competence to show depth in technology-related assurance and advisory work. For other phrasings of the same question, see our explainers on what CITP stands for and the broader overview of CITP certification.
Who Issues It and Why It Exists
The credential is governed by the American Institute of Certified Public Accountants (AICPA), operating within AICPA & CIMA. That origin explains much about how the credential works. It is not a general IT certification open to anyone with a technology background. It is built for CPAs, and its structure assumes the holder already has professional accounting standing.
The reason it exists is straightforward. Modern financial reporting, audit, and advisory work depend on information systems. Auditors evaluate IT general controls, assurance providers examine cybersecurity risk management programs, and finance teams rely on data analytics and business intelligence. CITP gives CPAs a recognized way to show competence in those areas, and gives employers and clients a quick signal when they need someone who can bridge the finance and technology sides of an engagement.
Why the Acronym Causes Confusion
"CITP" is a short acronym, and short acronyms get reused. Searching the letters can surface unrelated credentials from other organizations, which is a common source of mistaken assumptions about requirements and costs. The simplest safeguard is to anchor on the issuing body. The credential covered here is the one granted by the AICPA, and it is tied to CPA status. If a source does not mention the AICPA, CPAs, or the three content areas described below, it is probably describing something else.
For a plain-language walkthrough of the term itself, our guides to CITP meaning and what a CITP is approach the same question from different angles.
What the Credential Actually Covers
The Standard Pathway exam is organized into three content areas, each built from underlying subject areas. Understanding these tells you more about what CITP means in practice than the title alone does.
Domain 1: Information Security & Cyber Risks
This area addresses how organizations govern and manage security and cyber risk, and how assurance is provided over it.
- Information security governance
- Cybersecurity risk management
- SOC for Cybersecurity
Domain 2: Business Intelligence, Data Management and Analytics
This area concerns how data is organized, analyzed, and turned into reporting that supports decisions.
- Data management
- Data analysis and reporting
- Business intelligence management
Domain 3: IT Governance, Risks & Controls
This area covers how technology is directed, how its risks are identified, and how controls and service-organization reporting are evaluated.
- IT governance and strategy
- IT risks and controls
- SOC reporting
The pattern is worth noticing. Domain 1 is about protecting information, Domain 2 is about using information, and Domain 3 is about governing the systems that hold it. A CPA who masters all three can speak credibly about technology risk to boards, audit committees, and clients. For a deeper breakdown of each area, read our complete guide to the CITP exam domains.
The Role of SOC Reporting Knowledge
Two of the nine underlying areas, SOC for Cybersecurity and SOC reporting, relate to System and Organization Controls engagements. This is a distinctive feature of an AICPA credential: the AICPA develops the frameworks behind these reports, so the exam treats them as core knowledge rather than peripheral topics. Candidates who have never worked on a SOC engagement should expect to invest extra time here.
Who Qualifies for CITP
The eligibility rules are what most clearly separate CITP from open-enrollment certifications. For the Standard Pathway, you need all of the following:
- AICPA membership in good standing
- A valid and unrevoked qualifying CPA license or certificate
- 1,000 relevant business-experience hours within the preceding 5 years
Active or inactive CPA status can qualify, which matters for CPAs who have moved into roles where they no longer maintain an active license. An academic experience alternative exists for eligible full-time professors, recognizing that teaching in this field is a legitimate route to the experience requirement.
Standard Pathway vs. Experienced Pathway
CITP offers two routes to the exam, and they are designed for different career stages. Keep the two separate in your preparation, since the formats differ.
| Feature | Standard Pathway | Experienced Pathway |
|---|---|---|
| Experience required | 1,000 relevant business-experience hours within the preceding 5 years | At least 7,000 relevant experience hours and 7 years of relevant experience |
| Question format | Multiple-choice questions | 60 case-study-based and standalone multiple-choice questions |
| Time | Set by the exam product | 2 hours |
| Registration range | USD $400-$500 | USD $165-$220 |
| Retake | One retake included | One retake included |
The Experienced Pathway rewards depth of career experience with a lower fee and a case-study-influenced format. The Standard Pathway is the primary route for CPAs earlier in their technology specialization, and it is the focus of this site's practice resources. If you are unsure which route fits you, start with the experience-hours thresholds above; they decide the question for most candidates.
Fees and Registration Mechanics
Official Standard Pathway registration is listed at USD $400-$500, and a member discount is available after sign-in. One retake is included. Registration is nonrefundable and nontransferable, and the product lists one-year availability, so you should register with a realistic plan to test within that window rather than as a placeholder.
Delivery is through Kryterion testing centers or remotely proctored online delivery, with year-round scheduling and immediate results. That flexibility removes the fixed testing-window constraint that many professional exams impose. For scheduling specifics, see CITP exam dates and scheduling.
Optional Learning Pathway Bundle
AICPA also offers a 52-CPE CITP Learning Pathway Bundle that includes an exam after completion of all three modules. Listed prices are USD $429 for AICPA or CIMA members, $540 for nonmembers, and $345 for existing CITP holders. These are bundle prices, not standalone exam fees, so do not compare them directly against the registration range above. The bundle can make sense if you want structured instruction plus CPE credit, but it is optional. For the complete financial picture, including renewal costs, see our CITP certification cost breakdown.
Key Takeaway
Budget in two layers: the exam registration (a range, with a member discount after sign-in) and any optional preparation. Treat the bundle as a training product with an exam attached, not as a cheaper way to register.
CITP vs. CISA: How They Relate
CPAs interested in technology assurance often weigh CITP against CISA, the Certified Information Systems Auditor credential. They are different credentials from different bodies, but they connect in one important way: passing the CISA examination waives the CITP examination requirement. It does not waive the remaining credential requirements, so you would still need AICPA membership, CPA standing, and the experience hours.
- CITP is a CPA-focused credential from the AICPA with broad coverage of security, data analytics, and IT governance.
- CISA is an IT audit credential from a separate body, and it is not limited to CPAs.
- The overlap is the waiver: a CPA who already holds CISA credit has a shorter route to CITP.
Which is better depends on your career direction. A CPA whose clients expect an accounting-profession designation will often find CITP more recognizable in that context, while someone whose work is purely IT audit may value CISA for its audience. Many professionals eventually hold both. Our ROI analysis of CITP walks through the trade-offs in more depth.
Who Hires CITP Holders
CITP is relevant wherever CPAs are asked to evaluate or advise on technology. Typical employers and roles include:
- Public accounting firms, particularly in IT audit, risk advisory, and SOC reporting practices
- Corporate finance and internal audit teams responsible for controls over financial reporting systems
- Consulting practices advising on cybersecurity risk, data governance, and analytics programs
- Organizations building data and analytics capabilities that need finance-literate leadership
The credential tends to matter most in roles where a client or stakeholder wants proof that the CPA understands technology risk, not just accounting. Our CITP jobs overview and salary guide cover hiring patterns and earnings in more detail.
Keeping the Credential Active
Earning CITP is not a one-time event. Annual maintenance requires:
- Qualifying CPA status
- AICPA membership
- 20 hours of CITP-related continuing professional development
- Annual payment
- Compliance attestation
The 20-hour CPD requirement is specific to CITP-related topics, so general accounting CPE will not necessarily satisfy it. Plan your annual learning around the three domains so your maintenance hours also keep your technical knowledge current.
A Domain-Based Preparation Sequence
Rather than a generic study calendar, sequence your preparation around how the three domains build on each other. This is one reasonable ordering; adjust it to your background.
Domain 3 first if you come from audit
- IT governance, risks, and controls will feel familiar, giving you early momentum
- Review SOC reporting concepts, since they bridge into Domain 1
Domain 1: security and cyber risk
- Study governance, cyber risk management, and SOC for Cybersecurity together
- Practice distinguishing control objectives from control activities
Domain 2: data and analytics
- Candidates from audit or tax backgrounds often need the most time here
- Focus on data management, reporting, and business intelligence concepts
Mixed practice
- Take timed multiple-choice sets across all three domains
- Review every miss against its domain
If your background is in data or analytics instead, reverse the order and give Domain 3 the extra time. For a complete plan, use our CITP study guide, and keep the CITP cheat sheet handy for last-week review. When you are ready to test yourself on question style and pacing, try the CITP practice tests on the main site.
To calibrate your expectations before you commit, read how hard the CITP exam is and the notes on the passing score.
Frequently Asked Questions
CITP stands for Certified Information Technology Professional. It is a credential offered by the AICPA, within AICPA & CIMA, for CPAs with expertise in technology, security, data, and IT governance.
Yes. The credential requires a valid and unrevoked qualifying CPA license or certificate, along with AICPA membership in good standing. Active or inactive CPA status can qualify, and an academic experience alternative exists for eligible full-time professors.
The Standard Pathway covers three content areas: Information Security & Cyber Risks; Business Intelligence, Data Management and Analytics; and IT Governance, Risks & Controls. These draw on nine underlying subject areas, including SOC for Cybersecurity and SOC reporting.
Official Standard Pathway registration is listed at USD $400-$500, with a member discount available after sign-in. One retake is included, and registration is nonrefundable and nontransferable. The Experienced Pathway is listed at USD $165-$220.
Passing the CISA examination waives the CITP examination requirement, but it does not waive the other credential requirements. You still need AICPA membership, CPA standing, and the required experience hours.
Understanding what CITP means is the first step; deciding whether it fits your career is the second. For the full picture, continue with what CITP is, check what is known about pass rates, and review the available CITP training options.