CCITP-A logo
Focused certification exam prep
Start practice

CCITP-A Cheat Sheet 2026: One-Page Review of Must-Know Facts

TL;DR
  • The exam has 86 questions (80 scored, 6 unscored) in 135 minutes, scenario-based multiple choice.
  • Passing is a scaled 650/800, not a flat 81.25% raw score - treat it as scaled.
  • Domains 4 and 5 (Synthesis; Tools and Methods) jointly carry 35% - the largest published weight group.
  • Eligible candidates pay no assessment fee per the indexed official handbook.

Cheat Sheet Overview: What This Page Covers

This page is a condensed, one-stop reference for the Certified Counter-Insider Threat Professional - Analysis credential - the credential currently administered by CDSE under the updated name Certified Insider Threat Professional - Analysis (CITP-A). The renaming's effective date is unverified in public material, so you may see both names circulating through 2026; they refer to the same credential track covered throughout this site. If you want the long-form breakdown behind any line item here, the CCITP-A Study Guide 2026 and CCITP-A Exam Domains 2026 guide go deeper than a cheat sheet reasonably can.

Everything below is sourced from the indexed official handbook, the CDSE July 1, 2026 tracker, and the 2024 AIRE weighting material - not from generic exam-prep assumptions. Where CERT facts are unverified (open-book status, adaptivity, retake intervals), this sheet says so instead of guessing.

Naming Note: Treat "CCITP-A" and "CITP-A" as the same program in current materials. The conferring authorities are the Under Secretary of Defense for Intelligence and Security and the Director of the National Counterintelligence and Security Center, with day-to-day administration by DCSA/CDSE's SPeD Program Management Office.

Exam Format at a Glance

Lock these numbers in before you walk into the Pearson VUE test center:

  • Question count: 86 total - 80 scored, 6 unscored (per the CDSE July 1, 2026 tracker).
  • Time limit: 135 minutes.
  • Question style: Scenario-based multiple choice - expect situational prompts built around insider threat analysis workflows, not simple definition recall.
  • Delivery: Pearson VUE test centers. DAU eligibility approval must be finalized before you can schedule a seat.
  • Fee: $0 for eligible candidates per the indexed official handbook - member/non-member tiers don't apply here.

Unscored items are mixed in with scored ones and you won't know which is which, so pace yourself as if all 86 count. For a deeper discussion of how difficulty plays out question-by-question, see How Hard Is the CCITP-A Exam?

Exam AttributeConfirmed Detail
Total questions86 (80 scored + 6 unscored)
Time allotted135 minutes
FormatScenario-based multiple choice
Delivery channelPearson VUE test centers
Assessment fee$0 for eligible candidates
Passing thresholdScaled 650/800
Open-book / calculator / home proctoring / adaptivityUnverified - confirm with CDSE before test day

The Six CCITP-A Domains, Fast

The current six-topic weighting below is verified only from the official 2024 AIRE material, not from a newly obtained 2026 blueprint. Treat individual percentages as the most recent confirmed figures rather than a locked-in 2026 blueprint, and never let a prep resource invent domain weights that aren't published.

Domain 1: Policy and Directives - 20%

Covers the governing policy framework insider threat analysts operate inside, including directive-driven reporting obligations and programmatic authorities.

  • Know which directives establish Insider Threat Program requirements and reporting chains.

Domain 2: Social and Behavior Science - 10%

Tests understanding of behavioral indicators and the social-science foundations analysts use to interpret anomalous conduct.

  • Focus on how behavioral indicators are contextualized, not memorized as a checklist.

Domain 3: Researching - 20%

Covers how analysts gather, validate, and correlate information from authorized sources during an investigation.

  • Expect scenarios testing source selection and research methodology under policy constraints.

Domain 4: Synthesis - part of a combined 35%

Synthesis is where raw research and behavioral signals get turned into an analytic judgment. Domains 4 and 5 together carry the largest published weight of any domain group.

  • Practice combining multiple weak indicators into one coherent analytic narrative.

Domain 5: Tools and Methods - part of a combined 35%

Covers the analytic tools, UAM platforms, and methodologies used in day-to-day insider threat analysis work.

  • Review UAM tool functionality - this ties directly to the 8-hour UAM policy/tool training prerequisite.

Domain 6: Vulnerabilities Assessment and Management - 15%

Covers identifying organizational and individual vulnerabilities and how they're tracked and mitigated over time.

  • Understand the lifecycle from vulnerability identification through mitigation and case closure.

Key Takeaway

Because Domains 4 and 5 jointly make up 35%, candidates who treat Synthesis and Tools/Methods as "minor" topics tend to underperform. Weight your review time accordingly, and read the full breakdown in the CCITP-A Exam Domains 2026 guide if any domain feels unfamiliar.

Eligibility Checklist

You cannot schedule the exam without meeting every one of these items, confirmed through DAU and program-manager sign-off:

  • Hold a current CITP-F credential.
  • Be a current Insider Threat Program (ITP) employee.
  • Have at least 12 months of program experience.
  • Complete 40 hours of analysis-related training.
  • Complete 8 hours of UAM policy/tool training.
  • Review 10 case studies.
  • Obtain program-manager approval with a signed eligibility memorandum.

No separate degree requirement or reference count is verified in current materials - don't let third-party sites invent one. For the full walk-through of how each prerequisite is documented, see CCITP-A Requirements 2026.

Registration and Fee Facts

Registration mechanics are simpler than most certifications in this space, but the sequencing matters:

  1. Secure DAU eligibility approval first - this precedes any scheduling step.
  2. Once approved, schedule your seat through Pearson VUE.
  3. Eligible candidates are not charged an assessment fee ($0), per the indexed official handbook.

Because the fee structure and approval workflow differ from other credentials sharing similar acronyms, verify every cost assumption against the CCITP-A Certification Cost 2026 breakdown rather than assuming non-member pricing applies - it doesn't here. For scheduling windows and deadlines tied to your DAU approval, check CCITP-A Exam Dates 2026.

Scheduling Reminder: Pearson VUE will not let you book a seat until DAU eligibility approval is finalized. Don't count study weeks toward a test date until that approval is confirmed in hand.

Scoring and Pass Rate Snapshot

Two numbers get confused constantly, so separate them clearly:

  • Passing threshold: A scaled 650/800. The indexed handbook explicitly rejects the idea of a flat 81.25% raw-correct requirement - the scaling model means not every question is weighted equally.
  • Pass rate: CY2025 showed 21 of 39 assessments passing, or 53.85%. June 2026 showed 1 of 2, or 50%. Neither figure is identified as first-attempt-only, and no full-year 2026 rate has been published yet.

With sample sizes this small (39 assessments for an entire calendar year, 2 in a single month), treat any percentage as directional rather than statistically definitive. For the full context behind these numbers, read CCITP-A Pass Rate 2026: What the Data Shows, and for exactly how the scaled score is calculated, see CCITP-A Passing Score 2026.

Key Takeaway

A scaled 650/800 does not translate cleanly to "answer 81.25% of questions correctly." Study toward mastery of the domains, not toward hitting a specific raw-answer target.

Maintenance and Renewal Facts

Once certified, don't let the maintenance cycle catch you off guard:

  • Current maintenance-page text specifies 100 PDUs per two-year cycle, with at least 50 of those PDUs tied directly to Insider Threat-related content.
  • PDUs must be recorded in DAU.
  • Older official material references a three-year cycle instead - confirm your individual expiry date and how any transition between cycle lengths is being treated for your specific certification date.

Given the discrepancy between older three-year language and current two-year PDU requirements, don't assume your renewal date based on a generic timeline - verify it directly against your DAU record.

Who Actually Hires CCITP-A Holders

This credential sits inside the federal Insider Threat Program ecosystem, not the broader commercial cybersecurity job market. Holders typically work as insider threat analysts within DoD components, intelligence community elements, or cleared defense contractor ITPs - roles that require the exact prerequisites listed above (active program membership, CITP-F, and UAM training) as a baseline, not a resume bonus.

The July 2026 DCSA/CDSE tracker lists only 223 active CITP-A credentials recorded in DAU - a small, specialized population compared to broad IT certifications. That number reflects active credential holders in a government tracking system, not a search-volume or demand estimate, so don't read it as a measure of job openings. For a closer look at the roles this credential opens up, see CCITP-A Jobs, and for compensation context drawn from available data, see the CCITP-A Salary Guide 2026.

Why the Population Is Small: Every path to this credential runs through an active Insider Threat Program role plus a signed program-manager eligibility memorandum. You can't self-study your way in from outside the government/cleared-contractor ecosystem - eligibility is gated at the door.

A One-Week Domain Review Pass

If you've already built out a full study plan and just need a final compressed review before test day, map your remaining days to domain weight rather than domain order:

Day 1-2

Domains 4 & 5 - Synthesis and Tools/Methods (35% combined)

  • Run through scenario questions requiring multi-source analytic judgments.
  • Review UAM tool functions tied to the 8-hour UAM training requirement.
Day 3

Domains 1 & 3 - Policy/Directives and Researching (20% each)

  • Drill directive citations and reporting-chain scenarios.
  • Review source validation steps used in research workflows.
Day 4

Domain 6 - Vulnerabilities Assessment and Management (15%)

  • Walk through the vulnerability-identification-to-mitigation lifecycle.
Day 5

Domain 2 - Social and Behavior Science (10%) + full review

Spaced, timed practice in the final days matters more than new content intake at this point - run a full 135-minute simulation at least once on the practice test site so the pacing feels familiar before you sit for the real 86-question exam. If you haven't yet built a longer-range plan, the CCITP-A Study Guide 2026 covers week-by-week sequencing from week one.

FAQ

Is CCITP-A the same as CITP-A?

Yes, in the context of this credential. CDSE's current name for the program is Certified Insider Threat Professional - Analysis (CITP-A); CCITP-A is the legacy name still referenced in older and some current materials. The renaming's effective date isn't publicly verified.

How many questions are on the CCITP-A exam, and how long do I get?

86 questions total - 80 scored and 6 unscored - delivered as scenario-based multiple choice, with a 135-minute time limit, per the indexed official handbook and the CDSE July 1, 2026 tracker.

What score do I need to pass?

A scaled 650 out of 800. The indexed handbook explicitly states this is not the same as requiring 81.25% raw correct answers, since the score is scaled rather than a direct percentage.

Do I have to pay an exam fee?

No. The indexed official handbook lists a $0 assessment fee for eligible candidates. Member/non-member fee tiers common to other certifications don't apply to this credential.

How do I maintain the certification after passing?

Current maintenance-page text requires 100 PDUs per two-year cycle, with at least 50 tied to Insider Threat-related content, recorded in DAU. Older material references a three-year cycle, so confirm your personal expiry date and cycle treatment directly with DAU.

Ready to pass your CCITP-A exam?

Put this into practice with free CCITP-A questions across every exam domain.