CCITP-A logo
Focused certification exam prep
Start practice

What Does CCITP-A Mean?

TL;DR
  • CCITP-A stands for Certified Counter-Insider Threat Professional - Analysis, jointly conferred by USD(I&S) and NCSC.
  • The exam has 86 total questions (80 scored, 6 unscored) over 135 minutes, delivered via Pearson VUE.
  • Passing uses a scaled score of 650 out of 800, not a flat percentage of correct answers.
  • Eligible candidates pay $0 in assessment fees, but prerequisites like CITP-F and program experience come first.

What Does CCITP-A Actually Mean?

CCITP-A stands for Certified Counter-Insider Threat Professional - Analysis. It is a credential built specifically for people who work inside Insider Threat Programs and whose job is to analyze reporting, behavioral indicators, and case data to identify and mitigate insider risk. It is not a general cybersecurity badge, and it is not the same thing as other credentials that happen to share the same four-letter abbreviation. If you landed on this page comparing acronyms, it's worth pinning down: everything described here refers to the counter-insider threat analysis credential, not any similarly-named program from an unrelated industry.

The "A" at the end matters. CCITP-A is the analysis track within a small family of counter-insider threat certifications, distinguishing analysts from program management or other specialty tracks. If you're unclear on how this fits into the broader naming conventions, our companion piece on CCITP-A Meaning breaks down the terminology layer by layer, and What Does CCITP-A Stand For? covers the acronym expansion in more detail.

Quick Definition: CCITP-A certifies that a working insider threat program analyst can apply policy, behavioral science, research methods, synthesis, tools, and vulnerability assessment to real insider threat casework - not just recite definitions.

The Name Change You Should Know About

One detail trips up a lot of researchers: the requested legacy name "CCITP-A" is being retained in some materials even though the current naming used by CDSE is Certified Insider Threat Professional - Analysis (CITP-A). The exact effective date of this renaming has not been consistently verified across sources, which is why you'll see both labels floating around government and training documentation. Functionally, they describe the same analysis-track credential and the same body of knowledge.

If you're building a study plan or searching job postings, it's smart to search both terms. Employers and training vendors may still reference the older "CCITP-A" phrasing out of habit or because their internal documentation hasn't caught up with the rename. For a deeper dive into exactly what the credential covers under either name, see What Is CCITP-A? and What Is CCITP-A Certification?.

Who Administers and Confers CCITP-A

CCITP-A isn't a vendor-run certificate. It is jointly conferred by the Under Secretary of Defense for Intelligence and Security and the Director of the National Counterintelligence and Security Center. Day-to-day administration sits with DCSA's Center for Development of Security Excellence (CDSE) through the SPeD (Security Professional Education Development) Certification Program Management Office.

Practically, this means:

  • Testing is delivered through Pearson VUE test centers.
  • Before you can schedule an exam, you need current DAU eligibility approval - the Defense Acquisition University system is where your prerequisite completion and program-manager sign-off get tracked.
  • There is no separate "membership" structure like you'd see with commercial certifying bodies; everything routes through government training and personnel systems.

This government-administered structure is a big part of why CCITP-A looks and feels different from commercial IT certifications, and it's also why registration logistics deserve their own look - see CCITP-A Exam Dates 2026: Testing Windows, Deadlines & Scheduling for how the scheduling process plays out in practice.

The Six Domains Behind the Letters

Understanding what CCITP-A "means" in practice requires looking at what the exam actually tests. Based on the most recently verified 2024 AIRE material, the credential is organized around six domains. Domains 4 and 5 together carry the largest published weighting - 35% combined - though individual breakdowns between them haven't been separately confirmed.

DomainTopicWeight
Domain 1Policy and Directives20%
Domain 2Social and Behavior Science10%
Domain 3Researching20%
Domain 4SynthesisPart of 35% combined with Domain 5
Domain 5Tools and MethodsPart of 35% combined with Domain 4
Domain 6Vulnerabilities Assessment and Management15%

Domain 1: Policy and Directives

Candidates need working familiarity with the policy framework that governs insider threat programs - what authorizes program activity, what boundaries exist, and how directives translate into day-to-day analyst decisions.

  • Expect scenario questions tied to policy application, not memorized citation numbers.

Domain 3: Researching

This domain tests how analysts gather, verify, and contextualize information from multiple sources before drawing conclusions about potential insider risk.

  • Pairs heavily with Domain 4 (Synthesis) in scenario-based questions.

Domains 4 & 5: Synthesis and Tools and Methods

Together these make up the single largest weighted block on the exam. Synthesis asks you to pull disparate reporting into a coherent assessment; Tools and Methods tests familiarity with the analytic techniques and systems analysts actually use.

  • Because this pairing carries the most exam weight, under-preparing here has the biggest downside risk.

Domain 6: Vulnerabilities Assessment and Management

Covers identifying organizational and individual vulnerabilities that elevate insider risk, and how those vulnerabilities get tracked and managed over time.

For a domain-by-domain breakdown with more granular study guidance, the dedicated CCITP-A Exam Domains 2026: Complete Guide to All 6 Content Areas goes deeper than space allows here.

What the Exam Actually Looks Like

The CCITP-A exam uses scenario-based multiple choice questions - you're not just matching terms to definitions, you're reading a short situation and selecting the analytically sound response. According to the indexed official handbook and a July 1, 2026 CDSE tracker:

  • 86 total questions, broken into 80 scored and 6 unscored (unscored items are typically used for future question validation and aren't disclosed to candidates).
  • 135 minutes total time allotted.
  • Format is scenario-based multiple choice throughout - no separate essay or performance-based component has been confirmed.

Details like open-book status, calculator availability, home proctoring options, and whether the exam is adaptive remain unverified in current sources, so don't assume any of those conveniences apply until you confirm them through your official eligibility paperwork.

Fee Structure: The indexed official handbook lists the assessment fee as $0 for eligible candidates. There's no member/non-member pricing tier because eligibility - not membership - is the gate. For the full cost picture including training time and prerequisite hours, see CCITP-A Certification Cost 2026: Complete Pricing Breakdown.

How "Passing" Is Defined

This is one of the most misunderstood parts of the credential. The indexed handbook specifies a scaled passing threshold of 650 out of 800 - not a flat 81.25% raw correct-answer requirement, even though that math might look similar on the surface. Scaled scoring typically accounts for item difficulty, so two candidates answering the same number of questions correctly could receive different scaled results depending on which specific questions they got right.

A newly linked "combined handbook" referenced in some materials was inaccessible at the time of research, so if you see conflicting scoring claims elsewhere, treat the scaled 650/800 figure from the indexed handbook as the more reliable reference point. A full explanation of how scaled scoring affects your prep strategy lives in CCITP-A Passing Score 2026: Exactly What You Need to Pass.

Key Takeaway

Don't study to a percentage target. Study to competency across all six domains, since the scaled scoring model rewards consistent performance over lucky guesses on easier items.

Who Is Eligible to Even Sit for It

CCITP-A is not open to the general public or entry-level security staff. Eligibility requires:

  • Current CITP-F (the foundational-level credential) status.
  • Being a current Insider Threat Program staff member.
  • At least 12 months of program experience.
  • 40 hours of analysis-related training.
  • 8 hours of UAM (User Activity Monitoring) policy and tool training.
  • Review of 10 case studies.
  • Program-manager approval with a signed eligibility memorandum.

No verified source confirms a separate degree requirement or a specific reference-letter count, so don't let unofficial checklists convince you those are mandatory. For the complete eligibility walkthrough, including how the signed memorandum process works, read CCITP-A Requirements 2026: Eligibility, Prerequisites & How to Qualify.

Reality Check: You cannot casually decide to sit for CCITP-A. The prerequisite stack - CITP-F, 12 months of experience, 48 combined training hours, case study review, and manager sign-off - means the exam itself is the last step in a much longer qualification process, not the starting point.

Who Pursues CCITP-A and Why

Because eligibility is restricted to people already working inside Insider Threat Programs, CCITP-A functions less like a career-entry credential and more like a formal recognition of analytical competency for professionals already doing the work. Based on the DAU tracker, there were 223 active CITP-A credentials recorded as of the July 2026 reporting period - a modest, specialized population consistent with a credential gated by program membership and manager approval rather than open enrollment.

Typical holders work in roles tied to federal insider threat programs, counterintelligence support, or defense-sector security operations where UAM tools, case research, and behavioral analysis are part of the daily job. If you're assessing whether this credential fits your career trajectory, CCITP-A Jobs and Is the CCITP-A Certification Worth It? Complete ROI Analysis 2026 both dig into where this credential tends to matter on a resume, while CCITP-A Salary Guide 2026: Complete Earnings Analysis looks at compensation patterns using only verified figures.

Keeping the Credential Active

Earning CCITP-A isn't a one-time event. Current maintenance-page text specifies 100 PDUs per two-year cycle, with at least 50 of those PDUs tied specifically to Insider Threat-related content, recorded through DAU. Older official material referenced a three-year cycle instead, so if your original eligibility documentation predates the switch, confirm your individual expiration date and how the transition was applied to your cycle - don't assume the current two-year rule automatically overrides whatever cycle you were originally assigned.

Turning the Acronym Into a Study Plan

Once you understand what CCITP-A actually tests, the most efficient prep sequence follows the domain weighting rather than a generic study calendar. Since Domains 4 and 5 (Synthesis and Tools and Methods) jointly carry the largest published weight, they deserve the most dedicated review time, followed by the 20%-weighted Domains 1 and 3.

Weeks 1-2

Policy and Research Foundations

  • Review Domain 1 (Policy and Directives) source documents
  • Practice Domain 3 (Researching) scenario questions
Weeks 3-4

Synthesis and Tools Deep Dive

  • Spend the bulk of your time here given the combined 35% weighting
  • Work through case studies connecting research findings to synthesized assessments
Week 5

Behavior Science and Vulnerabilities

  • Cover Domain 2 and Domain 6 content
  • Run full-length scenario question sets under the 135-minute time limit

For a complete week-by-week plan rather than this abbreviated version, and for guidance on how difficult the scenario questions actually feel in practice, check out the CCITP-A Study Guide 2026: How to Pass on Your First Attempt and How Hard Is the CCITP-A Exam? Complete Difficulty Guide 2026. If you want condensed reference material to review during the final week, the CCITP-A Cheat Sheet 2026: One-Page Review of Must-Know Facts is built for quick review passes. You can also practice realistic scenario-style questions on our main practice test platform before scheduling your official Pearson VUE appointment.

Understanding pass rates can help calibrate expectations without inventing numbers that aren't verified. Official figures show CY2025 results of 21 out of 39 assessments passing (53.85%), and June 2026 results of 1 out of 2 (50%) - neither figure is identified as first-attempt-only, and no full-year 2026 rate has been published yet. For context on what these numbers do and don't tell you, see CCITP-A Pass Rate 2026: What the Data Shows.

Frequently Asked Questions

Is CCITP-A the same as CITP-A?

Functionally, yes. CCITP-A is a retained legacy name for what CDSE currently calls Certified Insider Threat Professional - Analysis (CITP-A). The exact date of the rename hasn't been consistently verified, so both terms appear in circulation.

How much does the CCITP-A exam cost?

The indexed official handbook lists the assessment fee as $0 for eligible candidates. There is no member versus non-member pricing because eligibility, not membership, determines access.

What score do I need to pass CCITP-A?

You need a scaled score of 650 out of 800, based on the indexed official handbook. This is not the same as needing 81.25% of raw questions correct, since scaled scoring accounts for item difficulty.

Can anyone register for the CCITP-A exam?

No. You must hold current CITP-F status, be a current Insider Threat Program staff member, have at least 12 months of program experience, complete 40 hours of analysis training and 8 hours of UAM training, review 10 case studies, and obtain program-manager approval with a signed eligibility memorandum.

How long is the CCITP-A exam and how many questions does it have?

The exam contains 86 total questions - 80 scored and 6 unscored - delivered over 135 minutes in a scenario-based multiple choice format through Pearson VUE test centers.

Ready to pass your CCITP-A exam?

Put this into practice with free CCITP-A questions across every exam domain.