- What CCITP-A Actually Stands For
- Legacy Name vs. the Current CDSE Designation
- Who Confers and Administers the Credential
- Why "Analysis" Is the Operative Word
- What the Letters Mean on Exam Day
- How the Six Domains Define the Meaning
- What "Certified" Requires Before You Even Register
- Who Actually Earns This Credential
- Keeping the Credential Meaningful After You Pass
- Turning the Definition Into a Study Plan
- Frequently Asked Questions
- CCITP-A is the legacy name; CDSE's current designation is Certified Insider Threat Professional - Analysis (CITP-A).
- Conferral is joint: the Under Secretary of Defense for Intelligence and Security and the Director of the National Counterintelligence and Security Center.
- The exam is 86 scenario-based multiple-choice questions (80 scored, 6 unscored) in 135 minutes, delivered via Pearson VUE.
- Eligible candidates pay $0 for the assessment, but DAU eligibility approval must happen before scheduling.
What CCITP-A Actually Stands For
CCITP-A stands for Certified Counter-Insider Threat Professional - Analysis. It sits inside the broader Security Professional Education Development (SPeD) Certification Program and is specifically built for practitioners who perform the analytical work of an Insider Threat Program: gathering, correlating, and assessing information to identify potential insider risk indicators before they become incidents.
That last word - "Analysis" - is not decorative. It's the distinguishing feature that separates this credential from adjacent SPeD certifications focused on program foundations or operations. If you're trying to understand exactly what this title implies about the job it validates, our companion piece on What Is CCITP-A? breaks down the functional role in more detail, and What Does CCITP-A Stand For? walks through each word of the acronym individually.
Legacy Name vs. the Current CDSE Designation
Here's where the meaning gets a little nuanced: CDSE's currently published name for this credential is Certified Insider Threat Professional - Analysis (CITP-A). "CCITP-A" is the legacy key/name that many candidates, employers, and training materials still use and search for. The exact effective date of the renaming is not publicly verified, which is why you'll see both labels in circulation - job postings, older study guides, and internal agency documents may still reference CCITP-A, while CDSE's current indexed pages use CITP-A.
For search and practical purposes, treat the two labels as referring to the same underlying credential, program requirements, and exam. If you want the full context on how the identity and branding of this certification fit together, see CCITP-A Certification and What Is A CCITP-A?.
Key Takeaway
When researching this credential, search both "CCITP-A" and "CITP-A" - official CDSE material may use either depending on page age, and the requirements described apply to both labels.
Who Confers and Administers the Credential
Understanding the meaning of CCITP-A also means understanding its chain of authority. The credential is jointly conferred by two federal offices:
- The Under Secretary of Defense for Intelligence and Security
- The Director of the National Counterintelligence and Security Center
Day-to-day administration - eligibility processing, exam scheduling coordination, and credential record-keeping - runs through the DCSA/CDSE SPeD Program Management Office. This joint conferral structure is part of why the credential carries weight: it's not a vendor-created certificate but a government-recognized professional designation tied to national counterintelligence and security policy.
Why "Analysis" Is the Operative Word
The "-A" suffix separates this credential from other tracks within the Insider Threat certification family. Analysis-track professionals are the people who take raw reporting - behavioral observations, access logs, user activity monitoring (UAM) data, HR flags - and turn it into an assessed judgment about potential risk. That work requires fluency in:
- Applicable policy and legal authorities governing insider threat data collection
- Behavioral science concepts relevant to risk indicators
- Research techniques for building a complete picture from fragmented data
- Synthesis of multiple data streams into a coherent analytic product
- Tools and methods used across UAM platforms and case management systems
- Vulnerability assessment and management practices tied to program risk posture
Those six areas aren't arbitrary - they map directly onto the official exam content domains, which we unpack fully in CCITP-A Exam Domains 2026: Complete Guide to All 6 Content Areas.
What the Letters Mean on Exam Day
If the acronym represents a role, the exam is how CDSE verifies you can perform it. The assessment consists of 86 total questions - 80 scored and 6 unscored - delivered as scenario-based multiple choice over 135 minutes at a Pearson VUE test center. Current published material does not confirm whether the exam is open-book, whether a calculator is permitted, whether home proctoring is offered, or whether the exam is computer-adaptive - so don't plan your test-day strategy around assumptions in any of those areas until CDSE confirms them directly.
Passing isn't a simple raw percentage. The indexed handbook specifies a scaled passing score of 650 out of 800, which is a different calculation than a flat 81.25% correct-answer threshold sometimes assumed from the raw numbers. For a deeper breakdown of how scaled scoring actually works and what it means for how many questions you can miss, read CCITP-A Passing Score 2026: Exactly What You Need to Pass.
How the Six Domains Define the Meaning
The clearest way to understand what this certification actually certifies is to look at its content domains. Based on the most recently verified official weighting (2024 AIRE material - a newer 2026 blueprint has not been obtained), the structure is:
| Domain | Weight |
|---|---|
| Domain 1: Policy and directives | 20% |
| Domain 2: Social and behavior science | 10% |
| Domain 3: Researching | 20% |
| Domain 4: Synthesis | Part of 35% combined with Domain 5 |
| Domain 5: Tools and methods | Part of 35% combined with Domain 4 |
| Domain 6: Vulnerabilities assessment and management | 15% |
Domains 4 and 5 together carry the largest published share of the exam at 35% combined, though individual weights within that pair aren't separately specified in available official material. Practically, this means synthesis skills - turning scattered data into a defensible analytic conclusion - and familiarity with the tools and methods analysts actually use are the heaviest-tested capabilities on the exam.
Domain 3: Researching (20%)
Candidates must demonstrate the ability to locate, verify, and correlate information from multiple authorized sources relevant to an insider threat case.
- Open-source and internal data correlation
- Source credibility and verification
- Building a research trail that supports an analytic finding
For a domain-by-domain breakdown with study priorities for each content area, see CCITP-A Exam Domains 2026: Complete Guide to All 6 Content Areas, and for a broader read on how difficult the exam feels in practice given this structure, check How Hard Is the CCITP-A Exam? Complete Difficulty Guide 2026.
What "Certified" Requires Before You Even Register
Part of the meaning of this credential is baked into who is even allowed to sit for it. This isn't an open-enrollment exam - eligibility requires:
- Current CITP-F certification
- Current status as Insider Threat Program personnel
- At least 12 months of program experience
- 40 hours of analysis-related training
- 8 hours of UAM policy/tool training
- Review of 10 case studies
- Program-manager approval with a signed eligibility memorandum
DAU eligibility approval must be finalized before you can schedule your Pearson VUE session - there's no shortcut around this sequencing. A full walkthrough of each requirement and how to document it is available in CCITP-A Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Key Takeaway
The acronym "certified" means something specific here: you can't self-study your way to eligibility. Program experience, training hours, and a signed memorandum from your program manager are mandatory gates before scheduling.
Who Actually Earns This Credential
Because eligibility requires current Insider Threat Program personnel status, nearly everyone pursuing this credential already works inside a government or defense-industrial-base Insider Threat Program in an analytical capacity. That typically includes UAM analysts, counterintelligence analysts supporting insider threat missions, and security professionals transitioning from foundational (CITP-F) roles into analysis-focused responsibilities. As of the July 2026 DAU tracker, there were 223 active credentials recorded - a figure that reflects actual credential holders, not a keyword-search estimate.
If you're weighing whether pursuing this credential fits your career trajectory, CCITP-A Jobs looks at the kinds of roles that reference this certification, and Is the CCITP-A Certification Worth It? Complete ROI Analysis 2026 weighs the investment against the outcome qualitatively, without inventing salary figures that aren't verified for this specific credential.
Keeping the Credential Meaningful After You Pass
Passing the exam isn't the end of what the credential means - it also carries ongoing maintenance obligations. The current maintenance-page text specifies 100 Professional Development Units (PDUs) per two-year cycle, with at least 50 of those PDUs tied directly to insider-threat-related activity, all recorded in DAU. Older official material referenced a three-year cycle instead, so if you're already certified, confirm your individual expiry date and which cycle length applies to your transition period rather than assuming either figure universally.
Turning the Definition Into a Study Plan
Once you understand what CCITP-A actually certifies - analytical capability across six specific domains - your preparation should mirror that structure rather than relying on generic exam-prep habits. A useful approach is to sequence study blocks around the heaviest-weighted domains first.
Policy, Directives, and Researching
- Review governing authorities and documentation requirements (Domain 1)
- Practice correlating multi-source information (Domain 3)
Synthesis and Tools/Methods
- Work through scenario-based practice items combining data into analytic judgments (Domain 4)
- Build familiarity with common UAM and case-management tool workflows (Domain 5)
Vulnerabilities and Behavioral Science
- Study vulnerability assessment frameworks (Domain 6)
- Review behavioral indicator concepts (Domain 2)
Full-Length Review
- Run timed practice sessions matching the 135-minute, 86-question format
- Target your weakest domain pair based on practice results
For a structured, exam-specific prep plan built around this exact domain weighting, see CCITP-A Study Guide 2026: How to Pass on Your First Attempt. If you want a fast-reference summary of every fact covered here in one place, bookmark CCITP-A Cheat Sheet 2026: One-Page Review of Must-Know Facts. You can also sharpen your scenario-question instincts using full-length timed simulations on the main practice test platform before exam day.
Frequently Asked Questions
Yes - CCITP-A is the legacy key/name, while CITP-A (Certified Insider Threat Professional - Analysis) is the current CDSE designation. Both refer to the same underlying credential and requirements.
It is jointly conferred by the Under Secretary of Defense for Intelligence and Security and the Director of the National Counterintelligence and Security Center, with administration through DCSA/CDSE's SPeD Program Management Office.
According to the published indexed handbook, eligible candidates pay $0 for the assessment. There is no member/non-member fee distinction, since eligibility - not payment tier - is the primary requirement.
The exam contains 86 total questions (80 scored, 6 unscored), delivered as scenario-based multiple choice over 135 minutes. Passing requires a scaled score of 650 out of 800, not a flat percentage of correct answers.
No. Candidates must first hold current CITP-F certification, be current Insider Threat Program personnel, meet experience and training-hour requirements, and obtain a signed eligibility memorandum and DAU approval before scheduling through Pearson VUE.