- What the CITP Credential Actually Is
- Who the Credential Is Built For
- Eligibility: What You Must Have Before You Sit
- Standard Pathway vs. Experienced Pathway
- The Three Content Areas and What They Cover
- Exam Delivery, Fees, and Registration Mechanics
- CITP vs. CISA: Where They Overlap
- Who Hires CITP Holders
- Sequencing Your Preparation Around the Domains
- Keeping the Credential Active
- Frequently Asked Questions
- CITP stands for Certified Information Technology Professional and is awarded by the AICPA, within AICPA & CIMA, to CPAs.
- The Standard Pathway requires AICPA membership, a valid CPA license or certificate, and 1,000 relevant experience hours in the past 5 years.
- The Experienced Pathway demands at least 7,000 hours and 7 years of experience, with 60 questions in 2 hours.
- Three content areas span security and cyber risk, data and analytics, and IT governance, risks and controls.
What the CITP Credential Actually Is
CITP stands for Certified Information Technology Professional. It is a specialty credential issued by the American Institute of Certified Public Accountants (AICPA), operating within AICPA & CIMA. It is not a general IT certification, and it is not open to anyone with a technology résumé. It is built for CPAs who work where accounting, risk, and technology meet.
That framing matters because a lot of candidates arrive expecting a vendor-style technical exam on networking or system administration. CITP is different. The credential signals that a CPA can evaluate information security posture, manage and analyze data, and assess IT governance and controls through the lens of financial and assurance work. If you want an even shorter orientation, the explainers on what CITP is and what CITP stands for cover the naming and basics, while this article goes deeper into how the credential works in practice.
Who the Credential Is Built For
The CITP is aimed at CPAs whose work is increasingly shaped by technology. Typical profiles include:
- Auditors who test IT general controls and rely on system-generated data in financial statement audits.
- Advisory professionals who help clients design security programs, evaluate cyber risk, or build data analytics capabilities.
- Finance and controllership leaders responsible for the systems and controls behind financial reporting.
- Internal auditors and risk professionals assessing technology governance across the enterprise.
- Professionals who prepare or examine SOC reports, whether for service organizations or cybersecurity risk management programs.
The common thread is that the CPA is the credential holder first. The CITP layers a technology-and-risk specialization on top of existing professional standing. For a closer look at career outcomes, see our guide to CITP jobs, and for the economic angle, the ROI analysis of the CITP certification.
Eligibility: What You Must Have Before You Sit
The Standard Pathway is the primary route and the one this site focuses on. Eligibility rests on three pillars:
- AICPA membership in good standing. Membership is a prerequisite, not an optional extra.
- A valid and unrevoked qualifying CPA license or certificate. Active or inactive CPA status can qualify.
- 1,000 hours of relevant business experience within the preceding 5 years. The experience must be relevant to the technology, security, data, or governance work the credential covers.
An academic experience alternative exists for eligible full-time professors, which recognizes teaching and scholarship in place of conventional business hours. If you are unsure whether your work counts, the dedicated page on CITP requirements and how to qualify walks through the prerequisites in more detail.
Standard Pathway vs. Experienced Pathway
The credential offers two routes to the exam, and they differ in who they serve, what they require, and how they are priced. Keep them separate in your mind, and in your preparation.
| Feature | Standard Pathway | Experienced Pathway |
|---|---|---|
| Experience required | 1,000 relevant hours within the preceding 5 years | At least 7,000 relevant hours and 7 years of experience |
| Question style | Multiple-choice questions | Case-study-based and standalone multiple-choice questions |
| Length | Multiple-choice exam on the Standard Pathway | 60 questions in 2 hours |
| Registration range | USD $400-$500, member discount after sign-in | USD $165-$220 |
| Retake | One retake included | One retake included |
| Best for | CPAs building toward the credential with moderate experience | Seasoned professionals with deep, long-running technology experience |
The Experienced Pathway's case-study component changes how you prepare. Case studies reward reading scenarios carefully and applying judgment across several facts at once, whereas straightforward multiple-choice items test recall and application of a single concept. If you are on the Standard Pathway, do not train with case-study-heavy material, and if you are on the Experienced Pathway, do not assume Standard Pathway practice questions represent your exam. Our CITP practice tests are aligned to the Standard Pathway.
The Three Content Areas and What They Cover
AICPA's exam registration page groups the content into three headings. Underneath them sit nine areas that together define the knowledge base. Below, each heading is mapped to the nine underlying areas. For a deeper treatment, see the complete guide to all three CITP content areas.
Domain 1: Information Security & Cyber Risks
This area is about protecting information and managing the risk that it is compromised. It draws on three underlying topics: information security governance, cybersecurity risk management, and SOC for Cybersecurity.
- How security governance is structured, who owns it, and how it connects to business objectives.
- Identifying, assessing, and responding to cybersecurity risk in a structured program.
- The SOC for Cybersecurity reporting framework, which lets management describe and auditors examine an entity's cybersecurity risk management program.
- Distinguishing governance responsibilities from operational security tasks, a frequent source of tricky answer choices.
Domain 2: Business Intelligence, Data Management and Analytics
This area treats data as an asset to be governed, analyzed, and turned into decisions. Its underlying topics are data management, data analysis and reporting, and business intelligence management.
- How data is collected, stored, structured, and kept reliable throughout its lifecycle.
- Analytical techniques and how results are communicated through reporting.
- Managing business intelligence capabilities so that insights are accurate, timely, and useful.
- Recognizing where poor data quality or weak management undermines analysis.
Domain 3: IT Governance, Risks & Controls
This area is the closest to traditional assurance work. It covers IT governance and strategy, IT risks and controls, and SOC reporting.
- Aligning IT strategy with organizational goals and overseeing it through governance structures.
- Identifying IT risks and evaluating the controls designed to mitigate them.
- SOC reporting, including how service organization reports are used and evaluated.
- Reasoning about control design versus operating effectiveness.
Exam Delivery, Fees, and Registration Mechanics
How the exam is delivered
The exam is delivered through Kryterion, either at a testing center or through remotely proctored online delivery. Scheduling is available year-round, so there is no single annual testing window to plan around, and results are provided immediately. If you are mapping out your timeline, see the overview of CITP exam dates and scheduling.
What registration costs
Official Standard Pathway registration is listed at USD $400-$500, with a member discount available after you sign in. One retake is included. Registration is nonrefundable and nontransferable, and the product lists one-year availability, meaning you should plan your attempt within that window rather than registering speculatively. A full breakdown of every line item lives in the CITP certification cost guide.
The optional learning bundle
AICPA also offers the 52-CPE CITP Learning Pathway Bundle, which includes an exam after completion of all three modules. Listed prices are USD $429 for AICPA or CIMA members, $540 for nonmembers, and $345 for existing CITP holders. These are bundle prices, not standalone exam fees, so do not compare them directly against the registration range above. The bundle is a preparation option, not a requirement.
Key Takeaway
Before paying, confirm which product you are buying. The exam registration, the Experienced Pathway registration, and the learning bundle are three different purchases with different prices and different purposes. Mixing them up is the most common budgeting error.
CITP vs. CISA: Where They Overlap
CISA, the Certified Information Systems Auditor credential, is the credential most often compared with CITP. They are distinct, and the relationship between them is specific:
- Different audiences. CITP is designed for CPAs and sits within the AICPA ecosystem. CISA is a broader information systems audit and control credential.
- Different emphasis. CITP combines security, data and analytics, and IT governance within a CPA context. CISA is centered on auditing and controlling information systems.
- A formal link. Passing the CISA examination waives the CITP examination requirement, though not the remaining credential requirements.
For a CPA who already holds CISA, the CITP can be a relatively efficient addition, since the exam requirement is waived. For a CPA who holds neither, the choice depends on career direction: CITP ties more directly to AICPA membership and CPA identity, while CISA is more widely recognized in dedicated IS audit roles outside accounting.
Who Hires CITP Holders
Demand for the credential concentrates where CPAs and technology risk intersect. You will most often encounter it at:
- Public accounting firms with IT assurance, SOC reporting, cybersecurity advisory, or data analytics practices.
- Corporate finance and internal audit functions that need CPAs who understand the systems behind financial reporting.
- Consulting and advisory firms helping organizations with governance, risk, and control design.
- Service organizations that undergo SOC examinations and need staff who can manage that process.
Because compensation varies enormously by region, firm size, and seniority, this article does not quote salary figures. For earnings context, the CITP salary guide addresses the topic qualitatively, and the guide to CITP jobs describes typical role types.
Sequencing Your Preparation Around the Domains
Rather than generic study advice, tie your calendar to the content. A sensible order puts the most foundational and most testable material first. The sample below assumes a Standard Pathway candidate working across several weeks; adjust the length to your experience and schedule.
Domain 3 foundations: IT governance, risks and controls
- Start here because governance and control concepts underpin the other two areas.
- Learn IT governance and strategy, then the logic of IT risks and controls.
- Study SOC reporting and note how it differs from SOC for Cybersecurity.
Domain 1: Information security and cyber risks
- Cover information security governance and cybersecurity risk management.
- Study SOC for Cybersecurity as a distinct reporting framework.
- Practice separating governance duties from operational duties.
Domain 2: Data, analytics, and business intelligence
- Work through data management, then data analysis and reporting.
- Finish with business intelligence management.
- Focus on data quality and how it affects conclusions.
Integrated practice and review
- Take timed multiple-choice sets that mix all three areas.
- Revisit the Domain 1 and Domain 3 SOC distinction.
- Review missed questions by topic, not by score.
For a fuller methodology, the CITP study guide lays out a complete plan, and the CITP cheat sheet condenses the must-know facts into a quick review. If you want to gauge your readiness before committing to a date, the CITP practice test is a practical checkpoint. Candidates sometimes ask how demanding all this is; the difficulty guide and the passing score explainer address that directly, and the pass rate discussion explains what can and cannot be reliably said about outcomes.
Keeping the Credential Active
Earning the CITP is not the end of the obligation. Annual maintenance requires:
- Qualifying CPA status.
- AICPA membership.
- 20 hours of CITP-related continuing professional development.
- Annual payment.
- A compliance attestation.
Plan your continuing education so the 20 hours are genuinely CITP-related rather than general CPE, since topic relevance is part of the requirement. Existing CITP holders also receive a lower bundle price on the learning pathway, which can be a convenient way to earn related hours.
Frequently Asked Questions
CITP stands for Certified Information Technology Professional. It is an AICPA credential for CPAs who specialize in the intersection of technology, security, data, and governance. More detail is available in our explainers on what CITP stands for and CITP meaning.
Yes. The credential requires a valid and unrevoked qualifying CPA license or certificate, along with AICPA membership in good standing. Active or inactive CPA status can qualify.
The Standard Pathway requires 1,000 relevant business-experience hours within the preceding 5 years. The Experienced Pathway requires at least 7,000 relevant hours and 7 years of relevant experience. An academic alternative exists for eligible full-time professors.
Passing CISA waives the CITP examination requirement, but you must still satisfy the remaining credential requirements, including membership, CPA standing, and experience.
Official Standard Pathway registration is listed at USD $400-$500, with a member discount after sign-in and one retake included. The Experienced Pathway is listed at USD $165-$220, also with one retake. The learning bundle is a separate, optional purchase. See the full cost breakdown for details.