- The Short Answer: What CITP Stands For
- Why the Acronym Causes Confusion
- Who Issues the Credential
- What the Designation Signals
- The Three Content Areas Behind the Name
- Who Can Hold the Credential
- Pathways, Exam Format, and Fees
- CITP vs. CISA
- Where CITP Holders Work
- Sequencing Your First Weeks of Preparation
- Keeping the Designation Active
- Frequently Asked Questions
- CITP stands for Certified Information Technology Professional, issued by the AICPA within AICPA & CIMA.
- It is a CPA-focused credential: you need a qualifying CPA license or certificate and AICPA membership.
- The Standard Pathway requires 1,000 relevant business-experience hours within the preceding 5 years.
- Exam content spans security and cyber risk, data and analytics, and IT governance, risks and controls.
The Short Answer: What CITP Stands For
CITP stands for Certified Information Technology Professional. It is a specialty designation awarded by the American Institute of Certified Public Accountants (AICPA), operating within AICPA & CIMA. Each word in the name carries meaning: "Certified" signals that a governing body has verified your qualifications, "Information Technology" defines the subject area, and "Professional" reflects the fact that the credential is built for working practitioners rather than students or entry-level candidates.
If you landed here searching for the meaning of the letters, that is the whole answer. The rest of this article explains what sits behind the name, because the expansion alone does not tell you who can earn it, what the exam covers, or why a CPA would want it. For a broader overview, see our explainers on what CITP is and CITP meaning.
Why the Acronym Causes Confusion
Several unrelated credentials, products, and organizations in the technology and business world share the same four letters. A web search for "CITP" can surface results that have nothing to do with one another, which is why so many people arrive at this question unsure which one they are looking at.
This site is about one specific credential: the Certified Information Technology Professional designation from the AICPA. If you are reading a salary figure, an exam fee, a pass rate, or a list of topics, check that the source clearly names the AICPA and the full title. Mixing facts across look-alike acronyms is the most common way candidates end up with the wrong preparation plan or the wrong expectations about cost and eligibility.
Who Issues the Credential
The CITP is governed by the AICPA, the professional body for certified public accountants in the United States, within AICPA & CIMA. That origin shapes everything about the credential. It was designed for accounting and finance professionals who work where business processes, data, and technology meet: assurance engagements, internal controls over systems, cybersecurity risk reporting, data analytics, and technology advisory work.
Because the AICPA owns the designation, the exam registration, content specification outline, and renewal rules all live on AICPA-CIMA properties. When details change, the official pages are the authority; this site tracks them, but you should always confirm current fees and policies with the source before you register. Our CITP certification overview covers the credential at a higher level.
What the Designation Signals
Holding the CITP tells employers and clients that a CPA has demonstrated depth in technology topics that traditional accounting training only touches lightly. Practically, it signals three things:
- Technology fluency within a trusted profession. The holder is still a CPA, bound by professional standards, but can speak credibly about system controls, data governance, and cyber risk.
- Experience, not just exam performance. Eligibility is gated by relevant business-experience hours, so the designation reflects applied work rather than classroom knowledge alone.
- Ongoing commitment. Annual maintenance with technology-focused CPD means the credential is not a one-time achievement.
Whether that signal translates into better pay or opportunities depends on your role and market. We analyze that in the CITP salary guide and weigh the investment in whether the CITP certification is worth it.
The Three Content Areas Behind the Name
The "Information Technology" in the title is defined concretely by the exam content. The AICPA organizes the Standard Pathway into three content headings, supported by nine underlying areas. Understanding these tells you what "IT professional" actually means in this context.
Domain 1: Information Security & Cyber Risks
This domain covers how organizations protect information and manage cyber exposure, including reporting on that posture.
- Information security governance
- Cybersecurity risk management
- SOC for Cybersecurity
Domain 2: Business Intelligence, Data Management and Analytics
This domain treats data as a business asset: how it is managed, analyzed, and turned into reporting that supports decisions.
- Data management
- Data analysis and reporting
- Business intelligence management
Domain 3: IT Governance, Risks & Controls
This domain connects technology strategy to oversight, controls, and assurance reporting.
- IT governance and strategy
- IT risks and controls
- SOC reporting
Notice the through-line: SOC reporting appears in two places, once on the cybersecurity side and once on the controls side. Candidates with an attestation background often find that overlap familiar, while those from tax or advisory roles may need to build that vocabulary from scratch. A detailed walk-through is in the CITP exam domains guide.
Who Can Hold the Credential
The expansion "Certified Information Technology Professional" might suggest anyone working in IT can earn it. They cannot. The CITP is a CPA-focused credential, and the standard requirements are:
- AICPA membership in good standing.
- A valid and unrevoked qualifying CPA license or certificate. Active or inactive CPA status can qualify.
- 1,000 relevant business-experience hours within the preceding 5 years.
An academic experience alternative is available to eligible full-time professors, so teaching-track CPAs are not shut out. There is also a notable shortcut on the exam side: passing the CISA examination waives the CITP examination requirement. It does not waive the remaining credential requirements, so you would still need to meet membership, licensure, and experience criteria.
For the full checklist and how to document your hours, read CITP requirements.
Pathways, Exam Format, and Fees
There are two routes to the exam, and they differ in experience thresholds, format, and price. Keep their preparation separate; materials for one are not a substitute for the other.
| Feature | Standard Pathway | Experienced Pathway |
|---|---|---|
| Experience required | 1,000 relevant business-experience hours within the preceding 5 years | At least 7,000 relevant experience hours and 7 years of relevant experience |
| Question format | Multiple-choice questions | 60 case-study-based and standalone multiple-choice questions in 2 hours |
| Registration fee range | USD $400-$500, with a member discount after sign-in | USD $165-$220 |
| Retake | One retake included | One retake included |
| Delivery | Kryterion testing centers or remotely proctored online, with year-round scheduling | |
Results are immediate, and because scheduling is year-round you are not tied to a fixed testing window. Details on timing are in CITP exam dates, and the full cost picture, including optional prep products, is in the CITP certification cost breakdown.
Optional Learning Pathway Bundle
The AICPA also sells a 52-CPE CITP Learning Pathway Bundle that includes an exam after you complete all three modules. Listed prices are USD $429 for AICPA or CIMA members, $540 for nonmembers, and $345 for existing CITP holders. Treat these as bundle prices, not standalone exam fees; comparing them directly against the Standard Pathway registration range will mislead you.
Key Takeaway
Decide your pathway first, then buy preparation. A candidate who qualifies for the Experienced Pathway should not be drilling Standard Pathway question banks, and vice versa. Pick the route, confirm the format, and then build your plan around it.
CITP vs. CISA
The most common comparison candidates make is between the CITP and the CISA. They overlap in subject matter (controls, governance, risk) but serve different professional identities.
- Audience. The CITP is built around CPAs and requires a qualifying CPA license or certificate plus AICPA membership. The CISA is oriented toward IT audit and assurance professionals generally.
- Emphasis. The CITP blends security, data analytics, and IT governance within a CPA context, including SOC reporting. That mix of business intelligence and cyber reporting is distinctive.
- Interaction. Passing the CISA waives the CITP examination requirement, though not the remaining credential requirements. For a CPA who already holds the CISA, that makes the CITP a comparatively short step.
If you are deciding between them, the question is less "which is better" and more "which identity do I want on my signature block." CPAs who want their technology expertise recognized by the same body that licenses their core profession tend to see the CITP as the natural fit.
Where CITP Holders Work
Because the designation sits at the intersection of accounting and technology, the roles that value it cluster around a few areas:
- Public accounting firms running IT assurance, SOC reporting, cybersecurity advisory, and data analytics service lines.
- Internal audit and risk functions in corporations that need auditors who understand system controls and data governance.
- Finance and controllership teams where reporting depends on business intelligence tools and data management practices.
- Consulting and advisory practices helping clients with IT governance and strategy.
Job titles vary widely, so search by function rather than by the credential name alone. Our CITP jobs page explores role types in more depth.
Sequencing Your First Weeks of Preparation
Rather than a generic schedule, sequence your study around where CPAs typically have gaps. Most candidates arrive strong on controls and reporting concepts and weaker on technical security and data tooling, so front-load the unfamiliar material while your motivation is highest.
Domain 1: Information Security & Cyber Risks
- Learn security governance structures and how cyber risk is assessed and managed
- Study the purpose and audience of SOC for Cybersecurity reporting
Domain 2: Business Intelligence, Data Management and Analytics
- Work through data management concepts, then analysis and reporting techniques
- Understand how business intelligence is governed and delivered to decision-makers
Domain 3: IT Governance, Risks & Controls
- Connect IT strategy to oversight, then to specific risks and controls
- Reconcile SOC reporting here with what you learned in Domain 1
Integration and Practice
- Take timed multiple-choice sets across all three domains
- Revisit whichever domain produced the most misses
Domain 3 comes last on purpose: it ties together concepts from the first two, and the SOC reporting overlap makes more sense once you have seen both contexts. For resources and a fuller plan, see the CITP study guide, and if you want to gauge how demanding the exam is before committing, read how hard the CITP exam is. When you are ready to test yourself, our CITP practice test offers exam-style multiple-choice questions.
Keeping the Designation Active
Earning the credential is not the end of the obligation. Annual maintenance requires:
- Qualifying CPA status
- AICPA membership
- 20 hours of CITP-related continuing professional development
- Annual payment
- A compliance attestation
The CPD requirement is worth planning around from day one. Because the hours must be CITP-related, choose training that genuinely reinforces the three content areas rather than generic accounting CPE. If you let your CPA status or AICPA membership lapse, the CITP cannot stand on its own, since both are prerequisites for maintaining it. Explore options on our CITP training page.
Frequently Asked Questions
CITP stands for Certified Information Technology Professional, a specialty credential offered by the AICPA within AICPA & CIMA for CPAs who work at the intersection of accounting and technology. See also what CITP stands for and what CITP means.
Yes. You need a valid and unrevoked qualifying CPA license or certificate, plus AICPA membership in good standing. Active or inactive CPA status can qualify, and an academic experience alternative exists for eligible full-time professors.
The Standard Pathway requires 1,000 relevant business-experience hours within the preceding 5 years. The Experienced Pathway requires at least 7,000 relevant experience hours and 7 years of relevant experience.
Standard Pathway registration is listed at USD $400-$500, with a member discount after sign-in, and includes one retake. The Experienced Pathway is listed at USD $165-$220, also with one retake. Registration is nonrefundable and nontransferable. See the full cost breakdown for details.
Passing the CISA examination waives the CITP examination requirement, but not the other credential requirements such as AICPA membership, CPA status, and experience hours.