CCITP-A logo
Focused certification exam prep
Start practice

What Does CCITP-A Stand For?

TL;DR
  • CCITP-A stands for Certified Counter-Insider Threat Professional - Analysis, now rebranded by CDSE as CITP-A.
  • The exam has 86 total questions (80 scored, 6 unscored) in a 135-minute, scenario-based multiple-choice format.
  • Eligible candidates pay $0 - there is no assessment fee listed in the official handbook.
  • Passing requires a scaled score of 650/800, not a flat percentage of correct answers.

What the Letters Actually Mean

CCITP-A stands for Certified Counter-Insider Threat Professional - Analysis. It is one tier within a broader counter-insider threat credentialing track, specifically focused on the analytic work of identifying, researching, and assessing potential insider threat indicators inside an organization's program.

If you've seen this acronym attached to a different field entirely, you're not imagining things - several well-known credentials share similar-looking letters, but this site and this article are strictly about the counter-insider threat analysis credential described above. Every fact here traces back to that specific program.

One important nuance: the name you'll see on current CDSE materials is shifting. The requested legacy key, CCITP-A, is retained for search and reference purposes, but the current CDSE name is Certified Insider Threat Professional - Analysis (CITP-A). The exact effective date of that renaming has not been independently verified in the sources reviewed for this article, so candidates should treat "CCITP-A" and "CITP-A" as the same underlying credential during this transition period rather than as two separate programs.

Naming in Transition: Expect to see both "CCITP-A" and "CITP-A" used in official and unofficial materials for a while. They refer to the same analysis-track credential; the letters simply reflect an organizational rename in progress.

For a broader look at the identity and scope of this credential beyond just the acronym breakdown, see What Is CCITP-A? and CCITP-A Meaning.

Who Confers and Administers CCITP-A

The CCITP-A credential isn't issued by a private certification vendor. It carries joint conferral authority from the Under Secretary of Defense for Intelligence and Security and the Director of the National Counterintelligence and Security Center. Day-to-day administration - eligibility review, scheduling support, and recordkeeping - sits with DCSA, specifically the Center for Development of Security Excellence (CDSE) under the SPeD Certification Program Management Office.

This dual-authority structure is part of why the acronym matters so much: this is a government-recognized credential tied to defense and counterintelligence insider threat programs, not a generic industry certificate. Candidates typically come from within DAU-tracked Insider Threat Program roles rather than applying cold from the general public.

Exam Format: Questions, Timing, and Delivery

The CCITP-A exam is delivered through Pearson VUE test centers. Before you can schedule a seat, your eligibility must first be approved through DAU - scheduling simply isn't available until that approval step is complete.

According to the CDSE tracker and the indexed official handbook, the exam consists of:

  • 86 total questions - 80 scored and 6 unscored
  • 135 minutes of testing time
  • Scenario-based multiple-choice question format

The unscored questions are mixed in with scored ones, meaning you won't know which six are being field-tested for future exam versions - treat every question as if it counts. Details on calculator access, open-book provisions, home proctoring, and whether the exam adapts in difficulty are not currently verified, so don't plan your test-day logistics around assumptions in those areas until you've confirmed them directly through your eligibility paperwork.

For a deeper breakdown of what makes this format challenging in practice, How Hard Is the CCITP-A Exam? Complete Difficulty Guide 2026 walks through the pacing math and scenario-reading demands.

The Six Domains Behind the Acronym

The "Analysis" half of the acronym is reflected directly in the exam's content structure. Based on the most recently verified official blueprint (2024 AIRE material), the CCITP-A exam organizes its content into six domains. Individual weights below are published for four of the six; Domains 4 and 5 are reported jointly.

DomainTopicWeight
Domain 1Policy and directives20%
Domain 2Social and behavior science10%
Domain 3Researching20%
Domain 4 & 5Synthesis / Tools and methods35% (combined)
Domain 6Vulnerabilities assessment and management15%

Domain 1: Policy and Directives

Covers the governing frameworks insider threat analysts operate under - the authorities and directives that shape what analysis can and cannot be done.

  • Know which directive governs which program activity

Domain 2: Social and Behavior Science

Tests understanding of the behavioral indicators and human-factors context behind insider threat activity, distinct from pure technical detection.

  • Smallest weighted domain, but still tested with scenario questions

Domain 3: Researching

Focuses on gathering, verifying, and contextualizing information relevant to a potential insider threat case.

  • Tied closely to analytic tradecraft, not just raw data collection

Domains 4 & 5: Synthesis and Tools/Methods

Together the largest tested area. Synthesis covers pulling disparate research threads into a coherent analytic judgment; Tools and Methods covers the analytic and user-activity-monitoring tools analysts apply day to day.

  • Expect the heaviest question volume here

Domain 6: Vulnerabilities Assessment and Management

Covers identifying organizational vulnerabilities an insider could exploit, and how programs manage and mitigate those exposures over time.

  • Connects directly to case-study review work required before eligibility

A domain-by-domain walkthrough with more granular subtopics is available in CCITP-A Exam Domains 2026: Complete Guide to All 6 Content Areas.

Registration, Eligibility, and the Fee Question

One detail that surprises people researching this credential for the first time: the indexed official handbook lists no assessment fee - $0 for eligible candidates. There's no member/non-member pricing split because that distinction simply doesn't apply here the way it might for other professional exams.

That doesn't mean the exam is "free and open," though. Eligibility is the real gate, and it's substantial:

  • Current CITP-F credential
  • Current Insider Threat Program personnel status
  • At least 12 months of program experience
  • 40 hours of analysis-related training
  • 8 hours of UAM (user activity monitoring) policy/tool training
  • Review of 10 case studies
  • Program-manager approval with a signed eligibility memorandum

No separate degree requirement or minimum reference count has been verified. In other words, the path to sitting the exam runs through your program and your manager's sign-off, not through a generic application fee.

Cost Reality Check: With no listed assessment fee, the real "cost" of CCITP-A is time - the training hours, case-study review, and program tenure required before you're even eligible to schedule.

For the full breakdown of what budgeting for this credential actually looks like once training time and PDUs are factored in, see CCITP-A Certification Cost 2026: Complete Pricing Breakdown, and for the prerequisite checklist in full detail, see CCITP-A Requirements 2026: Eligibility, Prerequisites & How to Qualify.

What "Passing" the CCITP-A Actually Requires

The indexed handbook specifies a scaled passing threshold of 650 out of 800 - not a raw percentage of correct answers. A commonly repeated figure of 81.25% correct is a misreading of that scaled score and is not how the handbook defines passing. A newly linked "combined handbook" referenced in some materials was inaccessible at the time of review, so treat any claim beyond the scaled 650/800 figure with caution until you can confirm it against your own eligibility documentation.

This scaled scoring approach matters for how you study: you can't simply count how many questions you think you need right out of 80 scored items and call it done, because the scaling adjusts for question difficulty across the pool. For a full explanation of how scaled scoring works in practice, read CCITP-A Passing Score 2026: Exactly What You Need to Pass.

Key Takeaway

Don't study to a percentage target. Study to master each domain's content, since the 650/800 scaled score weighs difficulty, not just raw answer count.

On pass-rate expectations, the official figures available are CY2025 at 21 of 39 assessments (53.85%) and June 2026 at 1 of 2 (50%). Neither figure is identified as first-attempt-only, and no full-year 2026 rate has been published yet. A closer look at what these numbers do and don't tell you is in CCITP-A Pass Rate 2026: What the Data Shows.

Who Pursues CCITP-A and Why

Because eligibility requires being current Insider Threat Program personnel already, CCITP-A isn't a credential people pick up speculatively to break into the field - it's typically pursued by analysts already embedded in a program who want formal, government-recognized recognition of their analytic competency. The joint conferral from Under Secretary of Defense for Intelligence and Security and the Director of NCSC signals to hiring managers and program leadership that the holder has met a defense-community-recognized bar for insider threat analysis work, not just a vendor-issued badge.

As of the July tracker referenced in CDSE materials, there were 223 active CITP-A credentials recorded in DAU - a figure describing the current population of credential holders, not a search-volume or demand estimate. That relatively small, specialized population reflects how tightly scoped the eligibility pipeline is.

If you're weighing whether to pursue it at all given your career stage, Is the CCITP-A Certification Worth It? Complete ROI Analysis 2026 and CCITP-A Salary Guide 2026: Complete Earnings Analysis go into the career-impact side in more depth, and CCITP-A Jobs looks at where this credential tends to show up in role requirements.

Mapping a Study Plan to the Acronym's Domains

Once you understand that CCITP-A's "Analysis" focus is split across six weighted domains, your prep schedule should mirror that weighting rather than treating every topic equally. Since Domains 4 and 5 (Synthesis and Tools/Methods) jointly carry 35% - the largest published share - they deserve the most calendar time, followed by Domain 1 (Policy and Directives) and Domain 3 (Researching) at 20% each, then Domain 6 (Vulnerabilities Assessment and Management) at 15%, and finally Domain 2 (Social and Behavior Science) at 10%.

Weeks 1-2

Policy and Directives + Researching

  • Review governing directives and program authorities
  • Practice research/verification scenario questions
Weeks 3-5

Synthesis and Tools/Methods

  • Work through UAM tool scenarios tied to your 8-hour training
  • Practice combining research threads into analytic judgments
Week 6

Vulnerabilities Assessment and Social/Behavior Science

  • Revisit your required 10 case studies
  • Review behavioral-indicator scenario patterns
Week 7

Timed Practice

  • Full-length runs under the 135-minute limit
  • Pace for 86 questions including unscored items

This domain-weighted sequencing, rather than a generic flashcard-and-review-cycle approach, is what a credential-specific study plan should look like. For a complete week-by-week guide built entirely around these domains, see CCITP-A Study Guide 2026: How to Pass on Your First Attempt, and for repeatable scenario drills, the practice platform at our main practice test site mirrors the scenario-based multiple-choice style you'll see on exam day.

Keeping the Credential After You Earn It

Earning CCITP-A isn't a one-time event. The current maintenance-page text indexed for this credential specifies 100 PDUs per two-year cycle, with at least 50 of those tied to Insider Threat-related content, recorded in DAU. Older official material referenced a three-year cycle instead, so if you're already holding the credential, confirm your individual expiry date and how any transition between the two cycle lengths was treated for your specific cohort rather than assuming the newer figure applies retroactively.

For a one-page reference you can keep handy while tracking both exam-day facts and maintenance requirements, see CCITP-A Cheat Sheet 2026: One-Page Review of Must-Know Facts. You can also run scheduling scenarios and scored practice sets at our practice exam platform to keep your domain knowledge current between recertification cycles.

Frequently Asked Questions

What does CCITP-A stand for, exactly?

Certified Counter-Insider Threat Professional - Analysis. The current CDSE name is Certified Insider Threat Professional - Analysis (CITP-A); both refer to the same analysis-track credential.

Is CCITP-A the same as CITP-A?

Yes, for practical purposes. CITP-A is the current CDSE name; CCITP-A is the legacy/longer key retained for reference. The exact date the rename took full effect is unverified.

How much does the CCITP-A exam cost?

The indexed official handbook lists no assessment fee - $0 for eligible candidates. There is no member versus non-member pricing distinction.

How many questions are on the exam and how long do I get?

86 total questions (80 scored, 6 unscored) delivered in a scenario-based multiple-choice format, within a 135-minute testing window.

What score do I need to pass?

A scaled score of 650 out of 800, per the indexed official handbook - not a flat 81.25% raw-correct-answer requirement.

Ready to pass your CCITP-A exam?

Put this into practice with free CCITP-A questions across every exam domain.