CITP logo
Focused certification exam prep
Start practice

What Is A CITP?

TL;DR
  • CITP stands for Certified Information Technology Professional, issued by the AICPA within AICPA & CIMA, for CPAs.
  • The Standard Pathway requires AICPA membership, a qualifying CPA license, and 1,000 relevant experience hours within five years.
  • Exam content spans three areas: security and cyber risks, data and analytics, and IT governance, risks and controls.
  • Passing the CISA exam waives the CITP exam requirement, but not the credential's other requirements.

What a CITP Actually Is

CITP stands for Certified Information Technology Professional. It is a specialty credential for certified public accountants who work where technology, risk, data, and financial reporting intersect. It is not an entry-level IT certification, and it is not open to anyone who simply likes computers. The credential is built on a CPA foundation: the technology expertise it recognizes is layered on top of professional accounting standing.

Because several unrelated credentials share the same four letters, it is worth being precise. When this site says CITP, it means the AICPA credential for CPAs, and everything below describes only that credential. If you are weighing it against other options or still sorting out the terminology, our short explainers on what CITP stands for and CITP meaning cover the naming question, and the broader CITP certification overview ties it together.

In practical terms, a CITP signals that a CPA can speak credibly about information security, data governance, analytics, and IT controls, the topics that increasingly sit inside audits, advisory engagements, and finance transformation projects.

Who Issues the Credential

The credential is governed by the American Institute of Certified Public Accountants (AICPA), operating within AICPA & CIMA. That matters for two reasons. First, the credential's rules (eligibility, fees, renewal) are set by the same institution that serves the CPA profession, so the requirements assume you are already part of that ecosystem. Second, the exam content reflects accounting-profession concerns: how technology risk affects financial reporting, assurance, and management decision-making, rather than purely vendor-specific or engineering topics.

Exam registration, the content specification outline, and the optional learning bundle are all published on AICPA & CIMA's own pages, which is where you should verify any current detail before paying for anything.

Who Can Hold It: Eligibility

The eligibility gate is one of the defining features of CITP. For the Standard Pathway, candidates need all of the following:

  • AICPA membership in good standing.
  • A valid, unrevoked qualifying CPA license or certificate. Active or inactive CPA status can qualify.
  • 1,000 hours of relevant business experience within the preceding five years.

There is also an academic experience alternative for eligible full-time professors, which recognizes teaching and scholarship in place of business hours. The practical takeaway: you cannot "study your way in" without the CPA license and membership. If you are still figuring out whether you qualify, the detailed CITP requirements guide walks through the prerequisites step by step.

The CISA Waiver: Passing the CISA examination waives the CITP examination requirement. It does not waive the remaining credential requirements, so you would still need AICPA membership, a qualifying CPA license, and the experience hours. Think of it as a substitute for the exam only, never for the whole credential.

The Three Content Areas

AICPA's registration page presents the exam content under three headings. Underneath them sit nine finer-grained areas: information security governance, cybersecurity risk management, SOC for Cybersecurity, data management, data analysis and reporting, business intelligence management, IT governance and strategy, IT risks and controls, and SOC reporting. The full breakdown lives in our guide to all three CITP content areas; here is the overview.

Domain 1: Information Security & Cyber Risks

This area covers how organizations govern security and manage cyber risk, with a distinctly assurance-oriented lens.

  • Information security governance: policies, roles, and accountability structures
  • Cybersecurity risk management: identifying, assessing, and responding to cyber threats
  • SOC for Cybersecurity: the AICPA reporting framework for communicating about an entity's cybersecurity risk management program

Domain 2: Business Intelligence, Data Management and Analytics

This area tests how data is managed, analyzed, and turned into decision-ready information.

  • Data management: quality, structure, lifecycle, and governance of data
  • Data analysis and reporting: applying analytical techniques and presenting results
  • Business intelligence management: the processes and tools that deliver insight to decision-makers

Domain 3: IT Governance, Risks & Controls

This area centers on how technology is directed, how its risks are identified, and how controls are designed and evaluated.

  • IT governance and strategy: aligning technology with business objectives
  • IT risks and controls: general and application controls and how they support reliable reporting
  • SOC reporting: understanding and evaluating service-organization control reports

Notice the recurring SOC theme. SOC for Cybersecurity appears under Domain 1 and SOC reporting under Domain 3. Candidates from audit backgrounds often find this familiar territory; those from tax or advisory may need extra attention here.

How the Exam Works

The Standard Pathway exam uses multiple-choice questions. It is delivered through Kryterion testing centers or by remotely proctored online delivery, with year-round scheduling and immediate results. There are no fixed annual testing windows to chase, so you can pick a date once you feel ready. For specifics on scheduling mechanics, see CITP exam dates and scheduling.

Questions tend to be scenario-driven: a described control weakness, a data governance problem, a SOC report excerpt, and a choice among plausible responses. The skill being tested is professional judgment as much as recall. If you want a realistic feel for that style, the CITP practice tests are built around the same multiple-choice format.

Many candidates ask about the passing threshold and the exam's difficulty. We cover both in CITP passing score and how hard the CITP exam is, and we address pass-rate questions in what the data shows on CITP pass rates.

Standard Pathway vs. Experienced Pathway

CITP has two routes, and mixing up their preparation is a common mistake. The Standard Pathway is this site's primary focus; the Experienced Pathway is a separate exam for seasoned professionals.

FeatureStandard PathwayExperienced Pathway
Experience required1,000 relevant hours within the preceding 5 yearsAt least 7,000 relevant hours and 7 years of relevant experience
Question formatMultiple choice60 case-study-based and standalone multiple-choice questions
TimeSee AICPA's registration page2 hours
Registration rangeUSD $400-$500USD $165-$220
RetakeOne retake includedOne retake included
Basic prerequisitesAICPA membership, qualifying CPA licenseAICPA membership, qualifying CPA license

The Experienced Pathway costs less but demands far more experience, which is the trade AICPA is making: deeper career history substitutes for a larger testing fee. Keep your preparation separate for each route. A mock exam designed for the Standard Pathway does not mirror the Experienced Pathway's case-study structure, so do not treat them as interchangeable.

Fees and Registration Mechanics

Official Standard Pathway registration is listed at USD $400-$500, with a member discount available after sign-in. Several mechanics are worth knowing before you click purchase:

  • One retake is included with registration.
  • Registration is nonrefundable and nontransferable, so confirm your eligibility first.
  • The product lists one-year availability, meaning you should plan your timeline instead of registering and waiting indefinitely.

There is also an optional 52-CPE CITP Learning Pathway Bundle that includes an exam after you complete all three modules. Listed prices are USD $429 for AICPA or CIMA members, $540 for nonmembers, and $345 for existing CITP holders. These are bundle prices, not standalone exam fees, so do not compare them directly to the registration range above. The bundle is a bonus if you want structured coursework plus CPE credit; it is not required to qualify.

Budget Reality Check: Beyond the exam registration itself, remember that AICPA membership and your CPA license are prerequisites with their own costs, and the credential carries annual maintenance fees. Our CITP certification cost breakdown lays out the full picture, and is CITP worth it weighs those costs against career returns.

CITP vs. CISA

The most common comparison is between CITP and CISA, since both touch IT assurance. They are different credentials from different organizations with different audiences. CITP is an AICPA credential for CPAs, with a blended scope across security, data analytics, and governance. CISA is a separate, widely recognized information systems audit credential with its own body and its own requirements.

The two are connected by one rule: passing the CISA examination waives the CITP examination requirement. That makes CISA holders who are also CPAs a natural fit for CITP, because they can pursue the credential without sitting the CITP exam, though they must still satisfy membership, license, and experience requirements. For a CPA deciding which to pursue, CITP's advantage is its breadth across data and analytics and its fit within the accounting profession; CISA's advantage is its pure audit focus. We do not quote comparative figures here because they vary by source and shift over time.

Who Hires CITPs and What They Do

CITP holders are CPAs, so they work wherever accounting expertise meets technology exposure. Typical environments include:

  • Public accounting firms: IT audit, SOC examinations, cybersecurity advisory, and data analytics practices.
  • Internal audit and risk functions: assessing IT general controls, evaluating third-party SOC reports, and supporting technology risk programs.
  • Finance and controllership teams: overseeing systems that feed financial reporting, ERP implementations, and analytics initiatives.
  • Consulting and advisory practices: data governance, business intelligence strategy, and security governance work.

The credential tends to differentiate candidates for roles that bridge finance and technology rather than for purely technical engineering jobs. For role descriptions and market context, see CITP jobs and the CITP salary guide, which discuss earnings qualitatively rather than relying on unsourced figures.

Keeping the Credential Active

CITP is not a one-time achievement. Annual maintenance requires:

  1. Qualifying CPA status
  2. AICPA membership
  3. 20 hours of CITP-related continuing professional development
  4. Annual payment
  5. A compliance attestation

The 20-hour CPD requirement is deliberately topic-specific, so general CPE credits unrelated to technology, data, or risk will not necessarily count. Plan your annual learning around the same three content areas you studied for the exam, which keeps your knowledge current and your credential in good standing. The CITP training overview covers options for building that CPD.

A CITP-Specific Preparation Sequence

Rather than generic scheduling advice, sequence your preparation around how the content areas build on each other. Start with Domain 3 because IT governance and controls give you the vocabulary that Domains 1 and 2 reuse. Then tackle Domain 1, where the SOC for Cybersecurity material connects directly to the SOC reporting you will already have seen. Finish with Domain 2, which is the most tool- and technique-heavy.

Weeks 1-2

Domain 3: IT Governance, Risks & Controls

  • Learn governance structures and strategy alignment
  • Work through general and application controls
  • Read the structure of a SOC report
Weeks 3-4

Domain 1: Information Security & Cyber Risks

  • Study security governance and cyber risk management
  • Compare SOC for Cybersecurity with other SOC reporting
  • Practice scenario questions on risk response
Weeks 5-6

Domain 2: Business Intelligence, Data Management and Analytics

  • Cover data quality, lifecycle, and governance
  • Review analysis and reporting techniques
  • Understand how BI programs are managed

Adjust the timeline to your own background: audit professionals may compress Domain 3, while those newer to analytics may expand Domain 2. For a fuller plan, use the CITP study guide, reinforce key facts with the CITP cheat sheet, and test yourself with realistic CITP exam questions as you finish each domain.

Key Takeaway

Do not start by memorizing definitions. Start by confirming eligibility, because registration is nonrefundable and nontransferable. Then study the three content areas in the order that lets each one reinforce the next.

Frequently Asked Questions

What does CITP stand for?

CITP stands for Certified Information Technology Professional. It is an AICPA credential for CPAs who specialize in information technology, security, data analytics, and IT governance.

Do I need to be a CPA to earn the CITP?

Yes. You need a valid, unrevoked qualifying CPA license or certificate, plus AICPA membership in good standing. Active or inactive CPA status can qualify.

How much experience does the Standard Pathway require?

The Standard Pathway requires 1,000 relevant business-experience hours within the preceding five years. Eligible full-time professors may use an academic experience alternative.

Does passing CISA mean I skip the CITP?

Passing the CISA exam waives the CITP examination requirement only. You must still meet the remaining requirements, including AICPA membership, a qualifying CPA license, and experience hours.

What is the difference between the Standard and Experienced Pathways?

The Standard Pathway is a multiple-choice exam requiring 1,000 experience hours. The Experienced Pathway has 60 case-study and standalone questions in 2 hours but requires at least 7,000 hours and 7 years of relevant experience.

Ready to pass your CITP exam?

Put this into practice with free CITP questions across every exam domain.