- What Does CCITP-A Actually Mean?
- The Name Change You Should Know About
- Who Administers and Conferrs CCITP-A
- The Six Domains Behind the Letters
- What the Exam Actually Looks Like
- How "Passing" Is Defined
- Who Is Eligible to Even Sit for It
- Who Pursues CCITP-A and Why
- Keeping the Credential Active
- Turning the Acronym Into a Study Plan
- Frequently Asked Questions
- CCITP-A stands for Certified Counter-Insider Threat Professional - Analysis, jointly conferred by USD(I&S) and NCSC.
- The exam has 86 total questions (80 scored, 6 unscored) over 135 minutes, delivered via Pearson VUE.
- Passing uses a scaled score of 650 out of 800, not a flat percentage of correct answers.
- Eligible candidates pay $0 in assessment fees, but prerequisites like CITP-F and program experience come first.
What Does CCITP-A Actually Mean?
CCITP-A stands for Certified Counter-Insider Threat Professional - Analysis. It is a credential built specifically for people who work inside Insider Threat Programs and whose job is to analyze reporting, behavioral indicators, and case data to identify and mitigate insider risk. It is not a general cybersecurity badge, and it is not the same thing as other credentials that happen to share the same four-letter abbreviation. If you landed on this page comparing acronyms, it's worth pinning down: everything described here refers to the counter-insider threat analysis credential, not any similarly-named program from an unrelated industry.
The "A" at the end matters. CCITP-A is the analysis track within a small family of counter-insider threat certifications, distinguishing analysts from program management or other specialty tracks. If you're unclear on how this fits into the broader naming conventions, our companion piece on CCITP-A Meaning breaks down the terminology layer by layer, and What Does CCITP-A Stand For? covers the acronym expansion in more detail.
The Name Change You Should Know About
One detail trips up a lot of researchers: the requested legacy name "CCITP-A" is being retained in some materials even though the current naming used by CDSE is Certified Insider Threat Professional - Analysis (CITP-A). The exact effective date of this renaming has not been consistently verified across sources, which is why you'll see both labels floating around government and training documentation. Functionally, they describe the same analysis-track credential and the same body of knowledge.
If you're building a study plan or searching job postings, it's smart to search both terms. Employers and training vendors may still reference the older "CCITP-A" phrasing out of habit or because their internal documentation hasn't caught up with the rename. For a deeper dive into exactly what the credential covers under either name, see What Is CCITP-A? and What Is CCITP-A Certification?.
Who Administers and Confers CCITP-A
CCITP-A isn't a vendor-run certificate. It is jointly conferred by the Under Secretary of Defense for Intelligence and Security and the Director of the National Counterintelligence and Security Center. Day-to-day administration sits with DCSA's Center for Development of Security Excellence (CDSE) through the SPeD (Security Professional Education Development) Certification Program Management Office.
Practically, this means:
- Testing is delivered through Pearson VUE test centers.
- Before you can schedule an exam, you need current DAU eligibility approval - the Defense Acquisition University system is where your prerequisite completion and program-manager sign-off get tracked.
- There is no separate "membership" structure like you'd see with commercial certifying bodies; everything routes through government training and personnel systems.
This government-administered structure is a big part of why CCITP-A looks and feels different from commercial IT certifications, and it's also why registration logistics deserve their own look - see CCITP-A Exam Dates 2026: Testing Windows, Deadlines & Scheduling for how the scheduling process plays out in practice.
The Six Domains Behind the Letters
Understanding what CCITP-A "means" in practice requires looking at what the exam actually tests. Based on the most recently verified 2024 AIRE material, the credential is organized around six domains. Domains 4 and 5 together carry the largest published weighting - 35% combined - though individual breakdowns between them haven't been separately confirmed.
| Domain | Topic | Weight |
|---|---|---|
| Domain 1 | Policy and Directives | 20% |
| Domain 2 | Social and Behavior Science | 10% |
| Domain 3 | Researching | 20% |
| Domain 4 | Synthesis | Part of 35% combined with Domain 5 |
| Domain 5 | Tools and Methods | Part of 35% combined with Domain 4 |
| Domain 6 | Vulnerabilities Assessment and Management | 15% |
Domain 1: Policy and Directives
Candidates need working familiarity with the policy framework that governs insider threat programs - what authorizes program activity, what boundaries exist, and how directives translate into day-to-day analyst decisions.
- Expect scenario questions tied to policy application, not memorized citation numbers.
Domain 3: Researching
This domain tests how analysts gather, verify, and contextualize information from multiple sources before drawing conclusions about potential insider risk.
- Pairs heavily with Domain 4 (Synthesis) in scenario-based questions.
Domains 4 & 5: Synthesis and Tools and Methods
Together these make up the single largest weighted block on the exam. Synthesis asks you to pull disparate reporting into a coherent assessment; Tools and Methods tests familiarity with the analytic techniques and systems analysts actually use.
- Because this pairing carries the most exam weight, under-preparing here has the biggest downside risk.
Domain 6: Vulnerabilities Assessment and Management
Covers identifying organizational and individual vulnerabilities that elevate insider risk, and how those vulnerabilities get tracked and managed over time.
For a domain-by-domain breakdown with more granular study guidance, the dedicated CCITP-A Exam Domains 2026: Complete Guide to All 6 Content Areas goes deeper than space allows here.
What the Exam Actually Looks Like
The CCITP-A exam uses scenario-based multiple choice questions - you're not just matching terms to definitions, you're reading a short situation and selecting the analytically sound response. According to the indexed official handbook and a July 1, 2026 CDSE tracker:
- 86 total questions, broken into 80 scored and 6 unscored (unscored items are typically used for future question validation and aren't disclosed to candidates).
- 135 minutes total time allotted.
- Format is scenario-based multiple choice throughout - no separate essay or performance-based component has been confirmed.
Details like open-book status, calculator availability, home proctoring options, and whether the exam is adaptive remain unverified in current sources, so don't assume any of those conveniences apply until you confirm them through your official eligibility paperwork.
How "Passing" Is Defined
This is one of the most misunderstood parts of the credential. The indexed handbook specifies a scaled passing threshold of 650 out of 800 - not a flat 81.25% raw correct-answer requirement, even though that math might look similar on the surface. Scaled scoring typically accounts for item difficulty, so two candidates answering the same number of questions correctly could receive different scaled results depending on which specific questions they got right.
A newly linked "combined handbook" referenced in some materials was inaccessible at the time of research, so if you see conflicting scoring claims elsewhere, treat the scaled 650/800 figure from the indexed handbook as the more reliable reference point. A full explanation of how scaled scoring affects your prep strategy lives in CCITP-A Passing Score 2026: Exactly What You Need to Pass.
Key Takeaway
Don't study to a percentage target. Study to competency across all six domains, since the scaled scoring model rewards consistent performance over lucky guesses on easier items.
Who Is Eligible to Even Sit for It
CCITP-A is not open to the general public or entry-level security staff. Eligibility requires:
- Current CITP-F (the foundational-level credential) status.
- Being a current Insider Threat Program staff member.
- At least 12 months of program experience.
- 40 hours of analysis-related training.
- 8 hours of UAM (User Activity Monitoring) policy and tool training.
- Review of 10 case studies.
- Program-manager approval with a signed eligibility memorandum.
No verified source confirms a separate degree requirement or a specific reference-letter count, so don't let unofficial checklists convince you those are mandatory. For the complete eligibility walkthrough, including how the signed memorandum process works, read CCITP-A Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Who Pursues CCITP-A and Why
Because eligibility is restricted to people already working inside Insider Threat Programs, CCITP-A functions less like a career-entry credential and more like a formal recognition of analytical competency for professionals already doing the work. Based on the DAU tracker, there were 223 active CITP-A credentials recorded as of the July 2026 reporting period - a modest, specialized population consistent with a credential gated by program membership and manager approval rather than open enrollment.
Typical holders work in roles tied to federal insider threat programs, counterintelligence support, or defense-sector security operations where UAM tools, case research, and behavioral analysis are part of the daily job. If you're assessing whether this credential fits your career trajectory, CCITP-A Jobs and Is the CCITP-A Certification Worth It? Complete ROI Analysis 2026 both dig into where this credential tends to matter on a resume, while CCITP-A Salary Guide 2026: Complete Earnings Analysis looks at compensation patterns using only verified figures.
Keeping the Credential Active
Earning CCITP-A isn't a one-time event. Current maintenance-page text specifies 100 PDUs per two-year cycle, with at least 50 of those PDUs tied specifically to Insider Threat-related content, recorded through DAU. Older official material referenced a three-year cycle instead, so if your original eligibility documentation predates the switch, confirm your individual expiration date and how the transition was applied to your cycle - don't assume the current two-year rule automatically overrides whatever cycle you were originally assigned.
Turning the Acronym Into a Study Plan
Once you understand what CCITP-A actually tests, the most efficient prep sequence follows the domain weighting rather than a generic study calendar. Since Domains 4 and 5 (Synthesis and Tools and Methods) jointly carry the largest published weight, they deserve the most dedicated review time, followed by the 20%-weighted Domains 1 and 3.
Policy and Research Foundations
- Review Domain 1 (Policy and Directives) source documents
- Practice Domain 3 (Researching) scenario questions
Synthesis and Tools Deep Dive
- Spend the bulk of your time here given the combined 35% weighting
- Work through case studies connecting research findings to synthesized assessments
Behavior Science and Vulnerabilities
- Cover Domain 2 and Domain 6 content
- Run full-length scenario question sets under the 135-minute time limit
For a complete week-by-week plan rather than this abbreviated version, and for guidance on how difficult the scenario questions actually feel in practice, check out the CCITP-A Study Guide 2026: How to Pass on Your First Attempt and How Hard Is the CCITP-A Exam? Complete Difficulty Guide 2026. If you want condensed reference material to review during the final week, the CCITP-A Cheat Sheet 2026: One-Page Review of Must-Know Facts is built for quick review passes. You can also practice realistic scenario-style questions on our main practice test platform before scheduling your official Pearson VUE appointment.
Understanding pass rates can help calibrate expectations without inventing numbers that aren't verified. Official figures show CY2025 results of 21 out of 39 assessments passing (53.85%), and June 2026 results of 1 out of 2 (50%) - neither figure is identified as first-attempt-only, and no full-year 2026 rate has been published yet. For context on what these numbers do and don't tell you, see CCITP-A Pass Rate 2026: What the Data Shows.
Frequently Asked Questions
Functionally, yes. CCITP-A is a retained legacy name for what CDSE currently calls Certified Insider Threat Professional - Analysis (CITP-A). The exact date of the rename hasn't been consistently verified, so both terms appear in circulation.
The indexed official handbook lists the assessment fee as $0 for eligible candidates. There is no member versus non-member pricing because eligibility, not membership, determines access.
You need a scaled score of 650 out of 800, based on the indexed official handbook. This is not the same as needing 81.25% of raw questions correct, since scaled scoring accounts for item difficulty.
No. You must hold current CITP-F status, be a current Insider Threat Program staff member, have at least 12 months of program experience, complete 40 hours of analysis training and 8 hours of UAM training, review 10 case studies, and obtain program-manager approval with a signed eligibility memorandum.
The exam contains 86 total questions - 80 scored and 6 unscored - delivered over 135 minutes in a scenario-based multiple choice format through Pearson VUE test centers.