CCITP-A logo
Focused certification exam prep
Start practice

CCITP-A Requirements 2026: Eligibility, Prerequisites & How to Qualify

TL;DR
  • You need current CITP-F status plus at least 12 months of Insider Threat Program experience to apply.
  • Candidates must log 40 hours of analysis training, 8 hours of UAM policy/tool training, and review 10 case studies.
  • A signed eligibility memorandum from your program manager is mandatory before DAU will clear you for Pearson VUE scheduling.
  • There is no assessment fee published for eligible candidates in the official handbook - $0 to sit the exam.

Who Is Eligible for CCITP-A in 2026

CCITP-A - Certified Counter-Insider Threat Professional - Analysis - is not an open-enrollment certification you can simply register for after buying a study guide. It is a role-based credential built around personnel who already work inside a federal or defense Insider Threat Program. If you want the plain-language rundown of what the credential represents before digging into eligibility mechanics, see What Is CCITP-A? and CCITP-A Meaning for background on the acronym and its scope.

One naming note worth flagging up front: CDSE's current program literature refers to this credential as the Certified Insider Threat Professional - Analysis (CITP-A), though the exact effective date of that rename is unverified in public materials. This site uses the legacy "CCITP-A" name that most practitioners and job postings still search for, but the underlying eligibility rules, domains, and administration described here apply to the same credential regardless of which label you encounter.

Bottom line: Eligibility for CCITP-A is gated by employment status, prior certification, documented training hours, and sign-off from your own Insider Threat Program leadership - not by a generic application form or open registration window.

The Core Prerequisites Before You Apply

Before DAU will clear you to schedule a Pearson VUE seat, you must satisfy a fixed set of prerequisites. These are documented, auditable items - not soft recommendations - and each one maps to something an assessor or program manager can verify in writing.

  • Current CITP-F status. The Foundation-level credential must be active; CCITP-A is explicitly a follow-on assessment, not a standalone entry point.
  • Active Insider Threat Program personnel status. You must currently be working within a recognized Insider Threat Program, not simply have past exposure to one.
  • At least 12 months of program experience. This is a minimum floor, not a guideline - document start dates carefully for your memorandum.
  • 40 hours of analysis-related training. This training should map closely to the analytic and synthesis work tested in the exam.
  • 8 hours of UAM (User Activity Monitoring) policy/tool training. Separate from the 40-hour requirement, and specific to UAM policy and tooling rather than general analysis.
  • Review of 10 case studies. These case reviews are a distinct, trackable requirement - keep a log of which cases you completed and when.

No verified degree requirement or outside reference count appears in current official material, so don't assume you need academic credentials on top of the above list. If any of these facts conflict with what you find in a newer combined handbook, treat the official DCSA/CDSE source as authoritative over secondary summaries, including this one.

Why These Prerequisites Exist

Each prerequisite corresponds directly to exam content. The 40 hours of analysis training supports the Synthesis and Researching domains; the 8 hours of UAM training supports Tools and Methods; and the 10 case studies reinforce Vulnerabilities Assessment and Management. Treat your prerequisite hours as your first study pass, not a separate checkbox.

  • Analysis training hours → Domains 3 and 4 content
  • UAM policy/tool training → Domain 5 content
  • Case study reviews → Domain 6 content

Program-Manager Approval and the Eligibility Memorandum

The single most distinctive requirement in the CCITP-A pathway is that your own Insider Threat Program manager must approve your candidacy and sign an eligibility memorandum. This is not a formality - it is the gatekeeping mechanism that keeps the credential tied to people who are actually doing the analytic work day-to-day, which is also why only 223 CITP-A credentials were showing as active in DAU as of the July 2026 tracker. This is a small, highly specific population compared to commercial IT certifications with six-figure holder counts.

Key Takeaway

Start the conversation with your program manager early. The signed memorandum, your 12-month experience documentation, and your training-hour logs all have to align before DAU approval - and that review happens before you're ever allowed to book a Pearson VUE appointment.

Who Confers and Administers the Credential

CCITP-A is jointly conferred by the Under Secretary of Defense for Intelligence and Security and the Director of the National Counterintelligence and Security Center. Day-to-day administration - eligibility processing, training records, and credential tracking - runs through DCSA's Center for Development of Security Excellence (CDSE) and the SPeD Program Management Office. For a deeper explainer of how this structure differs from the credentialing bodies behind similarly-named certifications in other industries, see What Does CCITP-A Stand For? and What Is A CCITP-A?.

Because the conferral authorities are government intelligence and security leadership rather than a private certifying vendor, the eligibility process is intentionally stricter and more document-heavy than typical IT certification registration. There's no self-attestation option - your program manager's signature is what makes you eligible, not your own claim of experience.

Registration, Scheduling, and Fee Mechanics

Once DAU approves your eligibility package, exam delivery happens through Pearson VUE test centers. A few mechanics worth knowing before you plan your timeline:

  • DAU approval comes first. You cannot schedule a Pearson VUE appointment until your eligibility is approved in the DAU system - there's no way to skip the queue by registering directly with Pearson VUE.
  • No assessment fee for eligible candidates. The indexed official handbook lists a $0 assessment fee; there is no member versus non-member fee distinction because this isn't a dues-based membership credential. For a full pricing breakdown including training-hour costs and opportunity cost, see CCITP-A Certification Cost 2026: Complete Pricing Breakdown.
  • Format and length. The exam is scenario-based multiple choice, 135 minutes, with 86 total questions - 80 scored and 6 unscored, per the CDSE July 1, 2026 tracker.
  • Scheduling windows. If you're mapping your prerequisite completion against test-center availability, review CCITP-A Exam Dates 2026: Testing Windows, Deadlines & Scheduling before you lock in your eligibility memorandum timeline.
Open-book status unconfirmed: Calculator use, home proctoring options, exam adaptivity, and retake intervals are not reliably verified in current public materials. Confirm these directly with your DAU point of contact rather than assuming standard testing-industry defaults apply.

What the Exam Actually Tests

CCITP-A's content is organized into six domains, and understanding their relative weight matters as much as understanding your prerequisites - it tells you where to invest limited study time once you're approved to sit the exam.

DomainPublished Weight
Policy and directives20%
Social and behavior science10%
Researching20%
SynthesisPart of 35% (Domains 4 & 5 combined)
Tools and methodsPart of 35% (Domains 4 & 5 combined)
Vulnerabilities assessment and management15%

These weights trace back to officially verified 2024 AIRE material rather than a confirmed newly issued 2026 blueprint, so treat Domains 4 and 5 as jointly accounting for the largest published share - 35% combined - without assuming an exact individual split between them. For a domain-by-domain breakdown of subtopics and sample question framing, read CCITP-A Exam Domains 2026: Complete Guide to All 6 Content Areas.

Domains 4 & 5: Synthesis and Tools and Methods

Because these two domains jointly carry the single largest weighting block on the exam, candidates who treat their 40-hour analysis training and 8-hour UAM training as throwaway compliance items - rather than real preparation - tend to feel the gap most acutely here.

  • Synthesis: pulling disparate indicators into a coherent analytic judgment
  • Tools and methods: applying UAM and analytic tooling correctly within policy bounds

Passing requires a scaled score of 650 out of 800 - not a flat percentage of correct answers - according to the indexed official handbook. A newly linked combined handbook was inaccessible at the time of review, so if you encounter a raw "81.25% correct" claim elsewhere, treat the scaled 650/800 threshold as the more reliable figure. Full scoring mechanics are broken down in CCITP-A Passing Score 2026: Exactly What You Need to Pass.

Turning Your Prerequisites Into Domain Readiness

Once your eligibility memorandum is signed and your Pearson VUE date is on the calendar, the real work is converting your prerequisite hours into exam-ready recall. A short, domain-aware schedule works better than generic cramming because your prerequisite training already overlaps heavily with tested content.

Week 1

Policy and Directives + Social/Behavior Science

  • Review governing directives and program policy documents you already handle at work
  • Revisit behavioral indicator frameworks from your 40-hour analysis training
Week 2

Researching

  • Practice structured open-source and case research workflows
  • Re-walk through several of your 10 required case studies with fresh notes
Week 3

Synthesis and Tools and Methods

  • Drill scenario questions that combine multiple indicators into one judgment
  • Review UAM tooling and policy material from your 8-hour requirement
Week 4

Vulnerabilities Assessment and Management + Full Review

  • Work through vulnerability assessment frameworks and mitigation reasoning
  • Take full-length scenario practice under the 135-minute time limit

If you want a more exhaustive walkthrough of pacing, question strategy, and common scenario traps, pair this timeline with CCITP-A Study Guide 2026: How to Pass on Your First Attempt. For a candid assessment of how difficult the exam feels relative to your existing analytic experience, see How Hard Is the CCITP-A Exam? Complete Difficulty Guide 2026. You can also run full scenario-style practice sets on our CCITP-A practice test platform to stress-test your timing before exam day.

Reality check on outcomes: Official figures show 21 of 39 assessments passed in CY2025 (53.85%) and 1 of 2 in June 2026 (50%), with neither figure identified as first-attempt-only and no full-year 2026 rate available yet. These numbers reflect a small, highly specialized test-taking population - not a mass-market exam. See CCITP-A Pass Rate 2026: What the Data Shows for the full context.

Staying Eligible After You Pass

Passing the exam isn't the end of the eligibility story. Current CDSE maintenance-page text specifies 100 Professional Development Units (PDUs) per two-year cycle, with at least 50 tied specifically to Insider Threat-related content, all recorded in DAU. Older official material referenced a three-year cycle instead, so if your certificate or onboarding paperwork states a different renewal period, confirm your individual expiration date and any transition treatment directly with your SPeD Program Management Office contact rather than assuming either cycle length applies by default.

This maintenance requirement reinforces the same theme as the initial prerequisites: CCITP-A is designed to track people who remain actively engaged in Insider Threat Program work, not a one-time credential you earn and shelve. If you're weighing whether the ongoing PDU commitment is worth it relative to career payoff, Is the CCITP-A Certification Worth It? Complete ROI Analysis 2026 and CCITP-A Salary Guide 2026: Complete Earnings Analysis cover that tradeoff in more depth, while CCITP-A Jobs outlines the types of roles and hiring organizations that typically require or prefer the credential.

For a condensed, printable reference of every fact covered in this requirements breakdown - prerequisites, domain weights, and maintenance cycle - bookmark CCITP-A Cheat Sheet 2026: One-Page Review of Must-Know Facts. And if your organization is still building out internal training to satisfy the 40-hour and 8-hour requirements, CCITP-A Training walks through what that training typically needs to cover.

Frequently Asked Questions

Can I apply for CCITP-A without holding CITP-F first?

No. Current CITP-F status is a documented prerequisite. CCITP-A is positioned as a follow-on assessment, not a standalone entry credential.

Does CCITP-A have a published assessment fee?

The indexed official handbook lists no assessment fee for eligible candidates - effectively $0. There is no member/non-member fee tier since this isn't a dues-based membership program.

How many questions are on the exam and how long do I get?

The CDSE July 1, 2026 tracker confirms 86 total questions (80 scored, 6 unscored), delivered as scenario-based multiple choice over 135 minutes per the indexed handbook.

What's the passing score?

A scaled 650 out of 800, according to the indexed official handbook - not a flat percentage of raw correct answers. See the dedicated passing score article for more detail.

How long does my certification last once I pass?

Current maintenance-page guidance specifies 100 PDUs per two-year cycle, with at least 50 Insider Threat-related and recorded in DAU. Older material referenced three years instead, so confirm your specific expiration date with your program office.

Ready to pass your CCITP-A exam?

Put this into practice with free CCITP-A questions across every exam domain.