- What the CCITP-A Credential Actually Covers
- Who Administers and Confers CCITP-A
- Eligibility and Prerequisites
- Exam Format, Fee, and Delivery
- The Six CCITP-A Exam Domains
- Passing Score and Pass Rate
- Who Hires CCITP-A Credential Holders
- Maintaining the Credential
- Mapping a Study Schedule to the Domains
- Frequently Asked Questions
- CCITP-A is jointly conferred by the Under Secretary of Defense for Intelligence and Security and the Director of NCSC, administered by DCSA/CDSE/SPeD.
- The exam is 86 questions (80 scored, 6 unscored) in 135 minutes, scenario-based multiple choice, delivered via Pearson VUE.
- Eligible candidates pay $0 for the assessment, but DAU approval must precede scheduling.
- Passing requires a scaled score of 650/800, not a fixed raw percentage.
What the CCITP-A Credential Actually Covers
CCITP-A stands for Certified Counter-Insider Threat Professional - Analysis, a credential built around the analytic work performed inside Insider Threat Programs - identifying behavioral indicators, researching anomalies, and synthesizing findings into actionable reporting. The legacy name "CCITP-A" is still widely searched, though the current CDSE-issued name is Certified Insider Threat Professional - Analysis (CITP-A); the exact effective date of that rename has not been verified, so candidates should treat both names as referring to the same credential track described on this site.
If you're still orienting yourself to the acronym itself, our companion pieces on What Is CCITP-A?, CCITP-A Meaning, and What Does CCITP-A Stand For? break down the terminology before you dive into exam mechanics.
Who Administers and Confers CCITP-A
CCITP-A is not issued by a private training vendor. The credential is jointly conferred by two federal authorities: the Under Secretary of Defense for Intelligence and Security, and the Director of the National Counterintelligence and Security Center (NCSC). Day-to-day administration - eligibility review, exam scheduling coordination, and credential tracking in DAU - falls to DCSA's Center for Development of Security Excellence (CDSE) through the SPeD Program Management Office.
This government-backed structure is part of why the credential functions differently from commercial certifications: there's no membership tier, no vendor "non-member" pricing, and no marketing-driven exam bundles. Everything routes through DAU approval and Pearson VUE scheduling.
Eligibility and Prerequisites
CCITP-A is not an entry-level exam. Before DAU approval is granted and a Pearson VUE seat can be scheduled, candidates must satisfy several prerequisites:
- Hold a current CITP-F (foundational) credential
- Be a current Insider Threat Program staff member
- Have at least 12 months of program experience
- Complete 40 hours of analysis-related training
- Complete 8 hours of User Activity Monitoring (UAM) policy/tool training
- Review 10 case studies
- Obtain program-manager approval with a signed eligibility memorandum
No verified degree requirement or reference-count minimum exists beyond what's listed above. Because eligibility gating is unusually document-heavy compared to many IT certifications, we cover each step in detail in CCITP-A Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Key Takeaway
Start your eligibility memorandum and training-hour documentation months before you plan to sit the exam - DAU approval must be finalized before you can even book a Pearson VUE slot.
Exam Format, Fee, and Delivery
The indexed official handbook and the CDSE July 1, 2026 tracker agree on the core structure: 86 total questions, made up of 80 scored items plus 6 unscored (pretest) items, delivered in a 135-minute scenario-based multiple-choice format. Questions are built around realistic Insider Threat casework rather than pure definitional recall, which is a meaningful difference from many certification exams.
On cost: the published, indexed official handbook lists the assessment fee at $0 for eligible candidates. There is no member/non-member fee split because there is no membership model - eligibility, not payment tier, is the gate. For a full breakdown of what "free" does and doesn't include (training hours, retake logistics, time investment), see CCITP-A Certification Cost 2026: Complete Pricing Breakdown.
Details on open-book status, calculator use, home proctoring availability, adaptive testing, and retake intervals remain unverified as of this writing - don't assume any of those without confirming against your current scheduling instructions. Exact testing windows and scheduling logistics are tracked separately in CCITP-A Exam Dates 2026: Testing Windows, Deadlines & Scheduling.
| Exam Attribute | Verified Detail |
|---|---|
| Total questions | 86 (80 scored, 6 unscored) |
| Time limit | 135 minutes |
| Question style | Scenario-based multiple choice |
| Delivery | Pearson VUE test center |
| Fee | $0 for eligible candidates |
| Passing score | Scaled 650/800 |
The Six CCITP-A Exam Domains
The current six-topic weighting is drawn from the 2024 AIRE material; no newly obtained 2026 blueprint has replaced it, so treat these as the best-verified weights available. Individual weights are not invented here for Domains 4 and 5 - only their combined share is published.
Domain 1: Policy and directives (20%)
Covers the governing directives and policy framework behind Insider Threat Programs - the "why" behind analytic procedures.
- Know which directives authorize program analytic activity and reporting chains
Domain 2: Social and behavior science (10%)
Tests understanding of behavioral indicators, motivations, and the human factors underlying insider risk.
- Be able to distinguish indicator categories from unrelated behavioral noise
Domain 3: Researching (20%)
Focuses on gathering, verifying, and contextualizing information relevant to a potential insider threat case.
- Practice scenario questions that require source triangulation, not single-source conclusions
Domain 4: Synthesis
Jointly weighted with Domain 5 at 35% - the heaviest combined block on the exam. Synthesis questions ask you to pull multiple data threads into a coherent analytic judgment.
- Expect multi-paragraph scenarios where the "correct" answer requires combining Domain 1 and Domain 3 inputs
Domain 5: Tools and methods
Also part of the 35% combined block with Domain 4. Covers the analytic tools, UAM platforms, and methodologies analysts apply day to day.
- Reinforce this with the 8-hour UAM policy/tool training required for eligibility
Domain 6: Vulnerabilities assessment and management (15%)
Covers identifying organizational and individual vulnerabilities and how programs manage them over time.
- Review case-study patterns tied to vulnerability escalation and mitigation
Because Domains 4 and 5 together make up more exam weight than any other pairing, candidates often underestimate how much study time belongs there. For a deeper walkthrough of each domain with example question framing, see CCITP-A Exam Domains 2026: Complete Guide to All 6 Content Areas.
Passing Score and Pass Rate
The indexed handbook specifies a scaled passing threshold of 650 out of 800 - this is not equivalent to a flat 81.25% raw-correct-answer requirement, since scaled scoring accounts for item difficulty across the 80 scored questions. A separately linked "combined handbook" that reportedly clarifies scaling in more detail was inaccessible at the time of research, so treat the 650/800 figure as the authoritative number until that document becomes available. Full mechanics are covered in CCITP-A Passing Score 2026: Exactly What You Need to Pass.
On outcomes: the official record shows 21 of 39 assessments passed in CY2025 (53.85%), and 1 of 2 in June 2026 (50%). Neither figure is identified as a first-attempt-only rate, and no full-year 2026 pass rate has been published yet. Avoid treating either number as a precise predictor of your personal odds - sample sizes, especially for June 2026, are small. A detailed look at what these numbers mean for your preparation is in CCITP-A Pass Rate 2026: What the Data Shows.
Who Hires CCITP-A Credential Holders
Because the credential is conferred jointly through DoD and NCSC channels and administered via DCSA/CDSE, demand concentrates in federal agencies, defense contractors, and cleared-industry employers that operate formal Insider Threat Programs. Analysts already working in those programs - the same population that must meet the 12-month program experience prerequisite - are the primary candidate pool, and employers often treat the credential as validation of analytic maturity rather than a door-opener for newcomers. If you're mapping out career paths, CCITP-A Jobs surveys the kinds of roles where the credential gets referenced, and Is the CCITP-A Certification Worth It? Complete ROI Analysis 2026 walks through the cost-free-but-time-intensive tradeoff in more depth. For compensation context tied specifically to this analytic track, see CCITP-A Salary Guide 2026: Complete Earnings Analysis.
Maintaining the Credential
Current maintenance-page text indexed by CDSE specifies 100 Professional Development Units (PDUs) per two-year cycle, with at least 50 of those tied specifically to Insider Threat-related content, recorded through DAU. Older official material referenced a three-year cycle instead, so if you hold a credential issued before the newer cycle language was published, confirm your individual expiry date and how the transition was treated for your cohort - don't assume the newer two-year/100-PDU rule retroactively applies without checking your DAU record.
As of the July 1, 2026 tracker, there were 223 active CITP-A credentials recorded in DAU. That figure reflects active credential holders tracked in the system - it is not a keyword-search or demand estimate, and shouldn't be used to infer hiring volume.
Mapping a Study Schedule to the Domains
Generic study techniques only matter here insofar as they map to the weighting above. Given that Domains 4 and 5 jointly carry 35% - more than any other pairing - and Domains 1 and 3 each carry 20%, a defensible allocation of limited study time looks roughly like this:
Policy and directives + Researching
- Build a directive-to-procedure map for Domain 1
- Practice source-triangulation scenarios for Domain 3
Synthesis + Tools and methods
- Work multi-paragraph scenario questions combining Domain 4 and 5 content
- Revisit UAM tool training notes from your 8-hour eligibility requirement
Social and behavior science + Vulnerabilities assessment and management
- Review behavioral indicator taxonomies for Domain 2
- Cycle through case-study patterns for Domain 6
Full review and scenario drilling
- Run timed practice sets under the 135-minute constraint
- Re-test weak domains identified in earlier weeks
For a more granular week-by-week plan with specific resource recommendations, see CCITP-A Study Guide 2026: How to Pass on Your First Attempt. If you'd rather jump straight to condensed review material, the CCITP-A Cheat Sheet 2026: One-Page Review of Must-Know Facts compiles the key figures referenced throughout this article in one place. You can also run scenario-style practice questions directly on our practice test platform to get comfortable with the scenario-based format before exam day.
Key Takeaway
Because Domain 4 and Domain 5 content jointly outweighs any single other domain, don't split study time evenly across all six - weight your review toward synthesis and tools/methods scenarios.
Frequently Asked Questions
CCITP-A is the legacy name for the credential; CDSE's current name is Certified Insider Threat Professional - Analysis (CITP-A). The exact date the rename took effect is unverified, but both names refer to the same credential and exam structure described here.
The published, indexed official handbook lists the assessment fee at $0 for eligible candidates. There is no member or non-member pricing tier since the credential isn't membership-based.
Per the CDSE July 1, 2026 tracker and the indexed handbook, the exam has 86 total questions (80 scored, 6 unscored) with a 135-minute time limit, delivered in scenario-based multiple-choice format via Pearson VUE.
The indexed handbook specifies a scaled passing score of 650 out of 800, not a flat raw-percentage requirement. See the dedicated passing-score breakdown for more detail on how scaling works.
You need a current CITP-F credential, current Insider Threat Program employment, 12 months of program experience, 40 hours of analysis-related training, 8 hours of UAM policy/tool training, review of 10 case studies, and a signed program-manager eligibility memorandum, followed by DAU approval before scheduling.