CCITP-A logo
Focused certification exam prep
Start practice

What Is A CCITP-A?

TL;DR
  • CCITP-A is jointly conferred by the Under Secretary of Defense for Intelligence and Security and the Director of NCSC, administered by DCSA/CDSE/SPeD.
  • The exam has 86 total questions (80 scored, 6 unscored) and a 135-minute scenario-based multiple-choice format.
  • Passing requires a scaled score of 650/800, not a simple 81.25% raw correct-answer count.
  • Eligible candidates pay $0 for the assessment, but approval through DAU must precede scheduling.

What Is a CCITP-A?

CCITP-A stands for Certified Counter-Insider Threat Professional - Analysis. It is the legacy name for what CDSE now refers to as the Certified Insider Threat Professional - Analysis (CITP-A), though the exact effective date of that rename has not been independently verified. For candidates researching the credential today, both names point to the same assessment, the same prerequisites, and the same body of knowledge focused on identifying, analyzing, and mitigating insider threat behavior inside government and cleared-industry environments.

The credential is jointly conferred by the Under Secretary of Defense for Intelligence and Security and the Director of the National Counterintelligence and Security Center, with day-to-day administration handled by the Defense Counterintelligence and Security Agency through CDSE and the SPeD Certification Program Management Office. This dual-authority structure is worth remembering because it explains why the credential carries weight specifically within DoD and federal insider threat programs rather than functioning as a general private-sector security certification.

If you landed here after searching variations like "what does CCITP-A stand for" or "CCITP-A meaning," the short answer is that it is a practitioner-level analysis credential for people already working inside an Insider Threat Program - not an entry-level or vendor-neutral security certificate.

Naming Note: Because "CCITP-A" is used by more than one credential family across the industry, always confirm you're reading material tied to the DCSA/CDSE/SPeD version before applying any fact, fee, or domain weight to your study plan.

Who Administers the Credential

Three organizations touch the CCITP-A lifecycle in different ways:

  • Conferral authorities - the Under Secretary of Defense for Intelligence and Security and the Director of NCSC jointly confer the credential.
  • Program administration - DCSA, through CDSE and the SPeD PMO, manages eligibility review, content, and maintenance tracking.
  • Delivery - the exam itself is delivered at Pearson VUE test centers, but candidates cannot simply register on their own; current DAU eligibility approval must precede scheduling.

This separation of conferral, administration, and delivery is a common feature of federal certification programs, but it surprises candidates coming from commercial IT certifications where self-registration is the norm. Before you can even book a seat, your eligibility file has to clear through DAU.

The Six Exam Domains

The current six-topic structure - verified against official 2024 AIRE material rather than a newly obtained 2026 blueprint - breaks the content into the following areas:

Domain 1: Policy and Directives (20%)

Covers the regulatory and directive-level foundation an analyst must know to operate inside a compliant Insider Threat Program.

  • Governing policy frameworks that shape program authority and scope

Domain 2: Social and Behavior Science (10%)

Focuses on behavioral indicators and the human factors that inform risk assessment of potential insider threat activity.

  • Recognizing behavioral patterns relevant to analytic judgments

Domain 3: Researching (20%)

Tests the ability to gather, verify, and contextualize information from multiple sources during an investigation or inquiry.

  • Source evaluation and research methodology applied to case work

Domain 4: Synthesis

Part of the largest published weighting group (jointly 35% with Domain 5). Synthesis questions ask candidates to pull together disparate data points into a coherent analytic conclusion.

  • Combining multiple data streams into a single risk narrative

Domain 5: Tools and Methods

Also part of the 35% combined weighting with Domain 4. Covers the analytic tools and methodological approaches used in day-to-day insider threat analysis work, including user activity monitoring concepts.

  • Practical application of analytic tools and techniques

Domain 6: Vulnerabilities Assessment and Management (15%)

Addresses how analysts identify organizational and individual vulnerabilities and how those findings feed into risk mitigation decisions.

  • Translating identified vulnerabilities into actionable management steps

For a deeper breakdown of each domain with sample question patterns, see the CCITP-A Exam Domains 2026: Complete Guide to All 6 Content Areas. Because Domains 4 and 5 jointly account for 35% of the exam - the largest published group - they deserve disproportionate study time relative to the smaller domains like Social and Behavior Science.

Key Takeaway

Do not split your prep time evenly across six domains. Domains 4 and 5 together outweigh any single other domain, so prioritize synthesis and tools/methods material first.

Exam Format, Length, and Scoring

According to the CDSE tracker dated July 1, 2026, the CCITP-A exam contains 86 total questions: 80 scored and 6 unscored. The indexed official handbook specifies a 135-minute time limit and describes the question style as scenario-based multiple choice - meaning most items present a short situational narrative followed by a decision or analytic judgment rather than a simple recall question.

Passing is defined on a scaled 650/800 basis in the indexed handbook, not as a raw percentage of correct answers. That distinction matters: a scaled score means the specific number of questions you need right can shift between forms, so treating it as "you need roughly 81.25% correct" is a misreading of how the scoring actually works. A newly linked combined handbook describing this in more detail was inaccessible at the time of research, so candidates should treat the scaled-score model as the authoritative version until that document becomes available again.

Unverified at this time: whether the exam is open-book, whether a calculator is permitted, whether home proctoring is offered as an alternative to Pearson VUE centers, whether the exam is adaptive, and what the current retake interval is. Candidates should confirm these logistics directly with CDSE/SPeD before exam day rather than assuming policies from other certifications apply here.

For a full walkthrough of exactly how the scaled score works and what it means for your target correct-answer count, see CCITP-A Passing Score 2026: Exactly What You Need to Pass.

Exam AttributePublished Detail
Total questions86 (80 scored, 6 unscored)
Time limit135 minutes
Question styleScenario-based multiple choice
Passing thresholdScaled 650/800
DeliveryPearson VUE test centers
Assessment fee$0 for eligible candidates

Fees and Registration Mechanics

The published indexed official handbook states there is no assessment fee - $0 for eligible candidates, with member/non-member pricing tiers not applicable since this is not a dues-based membership certification. That makes the financial barrier to the exam itself effectively nonexistent; the real cost is the time investment required to meet prerequisites and prepare for scenario-based questions across six domains.

Registration isn't a simple self-service process, though. Current DAU eligibility approval must precede scheduling at a Pearson VUE center. In practice, this means your Insider Threat Program leadership and the eligibility review process both have to clear before you can pick a test date. For a full breakdown of what this costs in time and documentation even without a dollar fee, read CCITP-A Certification Cost 2026: Complete Pricing Breakdown.

Eligibility and Prerequisites

CCITP-A is not an open-enrollment exam. To be approved, candidates generally need:

  • A current CITP-F credential
  • Current status as Insider Threat Program personnel
  • At least 12 months of program experience
  • 40 hours of analysis-related training
  • 8 hours of UAM (user activity monitoring) policy and tool training
  • Completed review of 10 case studies
  • Program-manager approval with a signed eligibility memorandum

No separate degree requirement or reference count has been verified in current source material, so don't assume a four-year degree is mandatory unless your program manager tells you otherwise. The full eligibility checklist, including how to document each requirement for your memorandum, is covered in CCITP-A Requirements 2026: Eligibility, Prerequisites & How to Qualify.

Sequencing Matters: Because the CITP-F credential and program-manager memorandum are prerequisites rather than formalities, candidates should start that paperwork months before they plan to sit the CCITP-A exam - not the week they intend to register.

Who Hires CCITP-A Holders

CCITP-A sits specifically inside the DoD and federal Insider Threat Program ecosystem. Holders are typically already working as insider threat analysts, counterintelligence support staff, or UAM/behavioral analysis personnel inside a cleared program before they ever sit the exam - the prerequisite structure essentially guarantees this. The credential functions less as a door-opener into the field and more as a formal validation of analytic competence for people already doing the work, which is an important distinction from commercial certifications that target career-changers.

If you're trying to understand how this credential translates into job titles, responsibilities, and compensation discussions, see CCITP-A Jobs and CCITP-A Salary Guide 2026: Complete Earnings Analysis. And if you're still weighing whether pursuing it is worth the prerequisite burden given your career stage, Is the CCITP-A Certification Worth It? Complete ROI Analysis 2026 walks through that decision in more depth.

What the Published Pass Rate Data Shows

Official figures show CY2025 results of 21 out of 39 assessments passing, or 53.85%, and June 2026 results of 1 out of 2, or 50%. Neither figure is identified as a first-attempt pass rate, and no full-year 2026 rate has been published yet. The July 2026 CDSE tracker also lists 223 active CITP-A credentials recorded in DAU - a measure of active credential holders, not a search-volume or popularity metric.

These numbers are small sample sizes (39 and 2 assessments respectively), so treat them as directional rather than statistically robust. A deeper look at what these figures do and don't tell you about your own odds is available in CCITP-A Pass Rate 2026: What the Data Shows, and for a broader sense of how challenging the scenario-based format feels in practice, see How Hard Is the CCITP-A Exam? Complete Difficulty Guide 2026.

Maintaining the Credential

Current maintenance-page text indexed for CCITP-A specifies 100 PDUs per two-year cycle, with at least 50 of those PDUs tied specifically to Insider Threat-related content, all recorded in DAU. Older official material references a three-year cycle instead, so candidates should confirm their individual expiration date and how any transition between the two cycle lengths was handled for their specific credentialing year rather than assuming one timeline universally applies.

Because PDU tracking happens in DAU and ties back to the same system used for eligibility approval, it's worth getting familiar with that platform well before your first renewal deadline approaches.

Scheduling Your Prep Around the Domains

Rather than a generic week-by-week template, CCITP-A prep should be sequenced around the published domain weights. Since Domains 4 and 5 jointly carry the largest share of the exam at 35%, they warrant the first and longest study blocks, followed by the 20% domains (Policy and Directives, Researching), then Vulnerabilities Assessment and Management at 15%, with Social and Behavior Science at 10% reviewed last as a lighter-weight domain.

Weeks 1-2

Synthesis and Tools and Methods

  • Work through case-study style scenarios that require combining multiple data points into one judgment
  • Review UAM tool concepts tied to the 8-hour policy training prerequisite
Weeks 3-4

Policy and Directives, Researching

  • Map governing directives to program authority questions
  • Practice source-evaluation scenarios drawn from investigative research tasks
Week 5

Vulnerabilities Assessment and Management

  • Practice translating identified vulnerabilities into mitigation recommendations
Week 6

Social and Behavior Science and full-length review

  • Review behavioral indicator scenarios
  • Run a full 135-minute timed practice session on the practice test site to build pacing for 86 questions

A complete week-by-week plan with specific resource recommendations is available in the CCITP-A Study Guide 2026: How to Pass on Your First Attempt. If you'd rather drill the content in short bursts, the CCITP-A Cheat Sheet 2026: One-Page Review of Must-Know Facts condenses the domain weights and format details into a single quick-reference page.

Key Takeaway

Practicing full 135-minute, scenario-based sessions on a realistic practice test platform before exam day matters more for CCITP-A than memorizing raw facts, since the format rewards applied judgment over recall.

FAQ

Is CCITP-A the same as CITP-A?

CCITP-A is the legacy name; CDSE's current name for the same credential is Certified Insider Threat Professional - Analysis (CITP-A). The exact effective date of the rename is unverified, but both names refer to the same DCSA/CDSE/SPeD-administered credential.

How much does the CCITP-A exam cost?

The published indexed handbook lists no assessment fee - $0 for eligible candidates. Member and non-member pricing tiers don't apply since this isn't a membership-based certification.

How many questions are on the CCITP-A exam and how long do I get?

The exam has 86 total questions - 80 scored and 6 unscored - delivered as scenario-based multiple choice within a 135-minute time limit.

What score do I need to pass CCITP-A?

The indexed handbook specifies a scaled passing score of 650 out of 800, not a flat percentage of raw correct answers.

Do I need prior certifications before attempting CCITP-A?

Yes. Published prerequisites include a current CITP-F credential, current Insider Threat Program personnel status, at least 12 months of program experience, 40 hours of analysis training, 8 hours of UAM training, review of 10 case studies, and a signed program-manager eligibility memorandum.

Ready to pass your CCITP-A exam?

Put this into practice with free CCITP-A questions across every exam domain.