CITP logo
Focused certification exam prep
Start practice

What Is CITP?

TL;DR
  • CITP stands for Certified Information Technology Professional, a credential issued through AICPA & CIMA for CPAs.
  • The Standard Pathway is a multiple-choice exam listed at USD $400-$500, with one retake included.
  • Eligibility needs AICPA membership, a qualifying CPA license, and 1,000 relevant business-experience hours within 5 years.
  • Exam content spans three domains: security and cyber risks, data and analytics, and IT governance and controls.

What CITP Actually Is

CITP stands for Certified Information Technology Professional. It is a specialty credential for CPAs who work where accounting, technology, risk, and data meet. It signals that a CPA can evaluate technology environments, understand how controls protect financial information, and advise on how data and systems support business decisions.

Many credentials share the "CITP" acronym, so precision matters. On this site, and in this article, CITP refers only to the Certified Information Technology Professional credential. If you want other framings of the same topic, our pages on what CITP stands for and the meaning of CITP cover the terminology, while the CITP certification overview goes broader.

The credential is a good fit for accounting professionals whose work has drifted toward technology: auditors reviewing system-heavy clients, advisors guiding finance teams through digital change, and controllers who own reporting platforms. It is not a general IT certification. It assumes an accounting foundation and layers technology judgment on top of it.

Who Issues It and Who Qualifies

The credential is governed by the American Institute of Certified Public Accountants (AICPA), operating within AICPA & CIMA. That origin explains its character: the exam leans toward assurance, governance, controls, and reporting rather than hands-on engineering.

For the Standard Pathway, candidates must meet three eligibility conditions:

  • AICPA membership in good standing. Membership is a prerequisite, not an optional extra.
  • A valid, unrevoked qualifying CPA license or certificate. Active or inactive CPA status can qualify.
  • 1,000 relevant business-experience hours within the preceding 5 years. The experience must be relevant to the credential's subject matter.

An academic experience alternative exists for eligible full-time professors. Our dedicated guide to CITP requirements and how to qualify walks through documentation and edge cases in more detail.

Check Eligibility Before You Pay: Registration is nonrefundable and nontransferable. Confirm your membership status, license standing, and experience-hour count before registering, because a mismatch discovered later can cost you the fee.

The Three Content Domains

The exam content is organized under three headings on AICPA's registration page. Beneath them sit nine underlying areas: information security governance, cybersecurity risk management, SOC for Cybersecurity, data management, data analysis and reporting, business intelligence management, IT governance and strategy, IT risks and controls, and SOC reporting. For a deeper walkthrough, see our complete guide to all three CITP content areas.

Domain 1: Information Security & Cyber Risks

This domain tests whether you can reason about protecting information and evaluating cybersecurity risk from an assurance perspective.

  • Information security governance: who owns security decisions, how policy flows to practice
  • Cybersecurity risk management: identifying, assessing, and responding to cyber risk
  • SOC for Cybersecurity: the purpose and structure of reporting on an entity's cybersecurity risk management program

Domain 2: Business Intelligence, Data Management and Analytics

Here the exam asks how data becomes reliable, usable information for decisions.

  • Data management: quality, lifecycle, and governance of data assets
  • Data analysis and reporting: choosing sound methods and presenting results accurately
  • Business intelligence management: how BI tools and processes are governed and kept trustworthy

Domain 3: IT Governance, Risks & Controls

This domain connects technology to the control environment CPAs already know well.

  • IT governance and strategy: aligning technology with business objectives and oversight
  • IT risks and controls: evaluating general and application controls and their effect on financial reporting
  • SOC reporting: understanding service organization reports and what they do and do not tell a user

What the Question Style Rewards

The Standard Pathway uses multiple-choice questions. Expect scenario-flavored items in which you must pick the best action, the most relevant control, or the most appropriate type of report, rather than recite a definition. Candidates with an audit background often find Domain 3 familiar and Domain 2 less so, while those from advisory or technology-adjacent roles frequently experience the reverse. For a candid read on where people struggle, see how hard the CITP exam is.

Standard Pathway vs. Experienced Pathway

AICPA offers two routes to the exam, and they are separate products with separate preparation needs. This site's primary focus is the Standard Pathway.

FeatureStandard PathwayExperienced Pathway
Question formatMultiple-choice60 questions combining case-study-based and standalone multiple-choice
TimeSee the official registration page2 hours
Registration rangeUSD $400-$500USD $165-$220
RetakeOne includedOne included
Experience requirement1,000 relevant hours within the preceding 5 yearsAt least 7,000 relevant hours and 7 years of relevant experience

The Experienced Pathway rewards long-tenured practitioners with a lower fee and a case-study element. Do not blend preparation for the two: case-study reasoning is a different skill from the straight multiple-choice recall and judgment the Standard Pathway demands. If you plan to use our CITP practice tests, treat them as Standard Pathway preparation.

Registration and Fee Mechanics

The official Standard Pathway registration is listed at USD $400-$500, and a member discount is available after you sign in. One retake is included, which softens the financial risk of a first-attempt miss. The registration is nonrefundable and nontransferable, and the product lists one-year availability, so you have a defined window to schedule and sit the exam rather than an open-ended one.

Delivery is through Kryterion testing centers or remotely proctored online delivery, with year-round scheduling and immediate results. That flexibility means you can choose a test date around your busy season instead of waiting for a narrow window. Our guide to CITP exam dates and scheduling covers the practical side, and the full CITP certification cost breakdown adds the surrounding expenses.

The Learning Pathway Bundle Is Not the Exam Fee

AICPA also sells a 52-CPE CITP Learning Pathway Bundle. It includes an exam after you complete all three modules. Listed prices are USD $429 for AICPA or CIMA members, $540 for nonmembers, and $345 for existing CITP holders. These are bundle prices, not standalone exam fees, so do not compare them directly against the USD $400-$500 registration range. The bundle is optional preparation that also earns CPE; it is useful if you want structured instruction, but it is not required to qualify.

Budget Honestly: Count the exam registration, any optional bundle, practice materials, and the ongoing annual maintenance cost. The sticker price of the exam is only the first line in the total.

CITP vs. CISA

The most common comparison is with the Certified Information Systems Auditor (CISA) credential. They overlap in subject matter but differ in purpose and prerequisites.

  • Audience. CITP is built for CPAs and requires AICPA membership and a qualifying CPA license. CISA is oriented around information systems audit, control, and assurance without that CPA framing.
  • Breadth. CITP spans security, data and analytics, and governance. The data and business intelligence domain gives it a wider advisory flavor than a pure audit credential.
  • The connection. Passing the CISA examination waives the CITP examination requirement. It does not waive the remaining credential requirements, so you still need membership, a qualifying CPA license, and the experience hours.

If you already hold CISA and are a CPA, the CITP path may be shorter than you expect. If you hold neither, the right choice depends on whether your career is anchored in the accounting profession or in broader IT audit. Our article on whether CITP is worth it helps frame that decision.

Who Values the Credential

CITP matters most in settings where a CPA must speak credibly about technology. That includes public accounting firms with IT assurance and advisory practices, internal audit and risk functions inside larger organizations, finance and controllership roles that own reporting systems, and consulting teams advising on data governance and analytics. The credential tends to help most when it supports a role that already blends accounting and technology, rather than acting as a standalone ticket to a new field.

Because this is a specialty designation layered on a CPA license, its value shows up as differentiation within accounting careers rather than entry into unrelated IT jobs. For roles and earning context, see our pages on CITP jobs and the CITP salary guide.

Sequencing Your Preparation by Domain

You do not need an elaborate system. What helps is sequencing study around your own background, since the three domains reward different prior experience. A practical order:

Weeks 1-2

Start With Your Weakest Domain

  • Audit-heavy candidates: begin with Domain 2 (data management, BI, analytics)
  • Advisory or data-heavy candidates: begin with Domain 3 (controls and SOC reporting)
  • Build vocabulary first so scenario questions stop feeling foreign
Weeks 3-4

Domain 1 and Its Reporting Links

  • Study security governance and cyber risk management together
  • Pair SOC for Cybersecurity with SOC reporting so you can distinguish them under pressure
Weeks 5-6

Integrate and Test

  • Take timed practice questions mixing all three domains
  • Review misses by underlying area, not just by score

The pairing of the two SOC topics is deliberate: SOC for Cybersecurity and SOC reporting sit in different domains but are easy to confuse, and exam writers know it. Our CITP study guide expands this into a fuller plan, and the CITP cheat sheet is useful for a final review. When you are ready to test yourself, start with the CITP practice test.

Key Takeaway

Do not study the nine underlying areas as nine isolated lists. Group them by the three exam domains, then drill the confusable pairs, especially the two SOC topics, so you can pick the right answer when two options look plausible.

Keeping the Credential Active

Earning CITP is not a one-time event. Annual maintenance requires:

  • Qualifying CPA status
  • AICPA membership
  • 20 hours of CITP-related continuing professional development
  • Annual payment
  • A compliance attestation

The 20-hour CPD expectation keeps holders current in a field where technology and risk change quickly. Plan for it from the start, because lapsing on membership or CPA status affects the credential too. For how scoring and results work at the point of testing, read about the CITP passing score and the pass rate discussion.

Frequently Asked Questions

What does CITP stand for?

CITP stands for Certified Information Technology Professional. It is a credential issued through AICPA & CIMA for CPAs who work at the intersection of accounting, technology, data, and risk.

Do I need to be a CPA to earn CITP?

Yes. Eligibility requires a valid, unrevoked qualifying CPA license or certificate, along with AICPA membership in good standing and 1,000 relevant business-experience hours within the preceding 5 years. Active or inactive CPA status can qualify.

How much does the Standard Pathway exam cost?

Official registration is listed at USD $400-$500, with a member discount available after sign-in. One retake is included. Registration is nonrefundable and nontransferable, and the product lists one-year availability.

Does passing CISA mean I automatically get CITP?

No. Passing the CISA examination waives the CITP examination requirement only. You must still satisfy the remaining credential requirements, including CPA licensure, AICPA membership, and the experience criteria.

How is the Experienced Pathway different?

It has 60 case-study-based and standalone multiple-choice questions in 2 hours, a registration range of USD $165-$220 with one retake, and requires at least 7,000 relevant experience hours and 7 years of relevant experience. Prepare for it separately from the Standard Pathway.

If you are deciding whether to commit, start with the overview of CITP certification, confirm your eligibility, and then build a domain-by-domain plan with the training options that fit your schedule.

Ready to pass your CITP exam?

Put this into practice with free CITP questions across every exam domain.