- CCITP-A is a DoD/NCSC-conferred analysis credential; CDSE's current naming is CITP-A, though the legacy label still circulates.
- The exam is 86 questions (80 scored, 6 unscored) in 135 minutes, delivered via Pearson VUE.
- Passing requires a scaled score of 650/800 - not a simple percentage of correct answers.
- The indexed official handbook lists a $0 assessment fee for eligible candidates once DAU eligibility is approved.
What CCITP-A Actually Means
CCITP-A stands for Certified Counter-Insider Threat Professional - Analysis - a credential built specifically for personnel who analyze insider threat data, behavioral indicators, and case information inside a formal Insider Threat Program. It is worth pinning this down because the same four letters are used by unrelated certifications in other industries. On this site, and in every article linked below, CCITP-A refers only to the insider-threat analysis credential governed by U.S. defense and counterintelligence authorities.
It is also worth noting that the issuing body's current published name for this credential is Certified Insider Threat Professional - Analysis (CITP-A). The "CCITP-A" label is a legacy name that many candidates, employers, and job postings still use, and the exact effective date of the rename has not been independently verified. If you see both names in official or unofficial material, you are likely looking at the same credential at different points in its naming history. Our companion piece on the CCITP-A meaning walks through this naming history in more detail, and the breakdown of what CCITP-A stands for covers the acronym expansion itself.
Who Confers and Administers It
CCITP-A is not issued by a private certifying body. It is jointly conferred under the authority of the Under Secretary of Defense for Intelligence and Security and the Director of the National Counterintelligence and Security Center (NCSC). Day-to-day administration - eligibility review, scheduling coordination, and credential records - sits with the Defense Counterintelligence and Security Agency (DCSA) through the Center for Development of Security Excellence (CDSE) and the Security Professional Education Development (SPeD) Program Management Office.
This government-program structure is a meaningful difference from most commercial IT or security certifications. There's no membership tier, no vendor marketing push, and no "non-member fee" category - because eligibility runs through program-manager approval and a formal eligibility memorandum rather than an open marketplace registration.
Who Pursues CCITP-A and Why
CCITP-A is built for people already working inside an Insider Threat Program - not for career-changers looking for an entry point. Typical candidates are insider threat analysts, counterintelligence support staff, and program personnel responsible for researching, synthesizing, and reporting on potential insider threat indicators using approved tools and methods. Because eligibility requires current Insider Threat Program personnel status and a signed approval memorandum, this credential functions more as a formal proficiency marker within an existing role than as a door-opener into the field.
If you're trying to figure out whether pursuing it lines up with your career goals - including how hiring managers in this space treat it - see our dedicated look at CCITP-A jobs and the broader ROI analysis of whether CCITP-A is worth it.
Exam Format, Delivery, and Fee
The CCITP-A assessment is delivered at Pearson VUE test centers, and scheduling only happens after your DAU eligibility status has been approved - you cannot book a seat first and sort out eligibility later. The indexed official handbook describes the assessment as scenario-based multiple choice, administered in 135 minutes.
A CDSE tracker dated July 1, 2026 confirms the exam contains 86 total questions - 80 scored and 6 unscored (the unscored items are used for item analysis and aren't counted toward your result, though you won't know which ones they are during the test).
Key Takeaway
Treat all 86 questions as scored while testing. You have no way to identify the 6 unscored items, so pacing across the full 135 minutes matters for every question.
On cost: the indexed official handbook lists the assessment fee as $0 for eligible candidates. There is no member/non-member fee distinction because eligibility is gated by program approval rather than purchased access. For a full breakdown of what "free assessment" does and doesn't cover (training hours, case study time, administrative requirements), see the CCITP-A certification cost breakdown.
Passing is based on a scaled score of 650 out of a possible 800 - the indexed handbook is explicit that this is not the same as needing 81.25% of raw questions correct. Scaled scoring typically weights certain domains or question difficulties differently, so a candidate's passing threshold isn't a simple fraction of 86. For the full explanation of how scaled scoring works for this exam, read the CCITP-A passing score guide.
The Six CCITP-A Domains
The current domain structure - verified from official 2024 AIRE material rather than a newly obtained 2026 blueprint - organizes CCITP-A content into six topic areas. Four domains carry a disclosed weight; Domains 4 and 5 are grouped together in official material and jointly represent the largest published share of the exam, at 35% combined. No individual split between Domain 4 and Domain 5 has been verified, so don't assume an even 17.5/17.5 split.
| Domain | Topic Area | Published Weight |
|---|---|---|
| Domain 1 | Policy and Directives | 20% |
| Domain 2 | Social and Behavior Science | 10% |
| Domain 3 | Researching | 20% |
| Domain 4 | Synthesis | Part of 35% (combined with Domain 5) |
| Domain 5 | Tools and Methods | Part of 35% (combined with Domain 4) |
| Domain 6 | Vulnerabilities Assessment and Management | 15% |
Domain 1: Policy and Directives
Covers the regulatory and directive framework that governs Insider Threat Programs - the "why" behind what analysts are authorized to collect, review, and report.
- Know which directives authorize program activity, not just their titles
Domain 3: Researching
Tests the candidate's ability to gather, verify, and organize information relevant to a potential insider threat case from authorized sources.
- Focus on source reliability and research sequencing, not just tool names
Domains 4 & 5: Synthesis, and Tools and Methods
Together these make up the largest scored portion of the exam. Synthesis tests how well you can pull disparate research into a coherent assessment; Tools and Methods tests practical familiarity with analytic techniques and platforms used in insider threat work.
- Allocate the most review time here given the combined 35% weight
For a domain-by-domain breakdown with study priorities for each, see the full CCITP-A exam domains guide. If you're still assessing how demanding the exam is relative to your current analyst experience, the CCITP-A difficulty guide breaks that down using the same scoring and format facts above.
Eligibility Snapshot
CCITP-A eligibility is built around existing program experience rather than open enrollment. Candidates generally need:
- A current CITP-F credential
- Current status as Insider Threat Program personnel
- At least 12 months of program experience
- 40 hours of analysis-related training
- 8 hours of User Activity Monitoring (UAM) policy/tool training
- Review of 10 case studies
- Program-manager approval with a signed eligibility memorandum
No independently verified degree requirement or reference count exists in current material - be cautious of any prep source that states a specific degree mandate. For the complete eligibility walkthrough, including how the memorandum process typically works, see CCITP-A requirements and eligibility.
Keeping the Credential Active
Current indexed maintenance-page text specifies 100 Professional Development Units (PDUs) per two-year cycle, with at least 50 of those tied specifically to Insider Threat-related activity, recorded in DAU. Older official material references a three-year cycle instead, so if you're already holding or renewing CCITP-A, confirm your individual expiry date and how any cycle-length transition applies to you rather than assuming the newer figure automatically overrides your personal timeline.
As of the July 2026 DCSA tracker, there were 223 active CITP-A credentials recorded in DAU. That figure reflects active credential holders in the system - it is not a measure of search interest or job-market demand, so don't read it as a popularity metric.
Mapping Study Time to the Weighting
Generic study techniques only help if they're pointed at the right material. Given that Domains 4 and 5 jointly account for 35% of the published weighting - more than any other pairing - your review schedule should weight accordingly rather than spreading effort evenly across all six domains.
Policy, Research, and Behavior Foundations
- Build fluency in Domain 1 (Policy and Directives) and Domain 3 (Researching) since each carries 20%
- Layer in Domain 2 (Social and Behavior Science) at 10%, since it's lighter-weighted but conceptually distinct
Synthesis and Tools and Methods
- Spend the largest single block of review time on Domains 4 and 5 combined, reflecting their 35% share
- Practice turning research outputs into a synthesized analytic judgment - this is the core skill both domains test
Vulnerabilities and Scenario Practice
- Close with Domain 6 (Vulnerabilities Assessment and Management) at 15%
- Run full scenario-based practice sets timed to the 135-minute window
For a structured, week-by-week plan built entirely around these domain weights, see the CCITP-A study guide for passing on the first attempt. You can also pair that plan with timed scenario practice on our CCITP-A practice test platform to get comfortable with the scenario-based multiple-choice format before test day.
Frequently Asked Questions
They appear to refer to the same analysis-track credential at different points in its naming history. CDSE's current published name is Certified Insider Threat Professional - Analysis (CITP-A), while CCITP-A is the legacy name still widely used. The exact date the rename took effect is unverified.
A CDSE tracker dated July 1, 2026 confirms 86 total questions: 80 scored and 6 unscored, delivered over 135 minutes in a scenario-based multiple-choice format.
The indexed official handbook lists a $0 assessment fee for eligible candidates. There is no member versus non-member fee structure, since eligibility runs through program-manager approval rather than open purchase.
A scaled score of 650 out of 800, per the indexed handbook. This is explicitly not the same as a flat 81.25% raw correct-answer requirement, since scaled scoring weights items differently.
Candidates generally need a current CITP-F credential, current Insider Threat Program personnel status, at least 12 months of program experience, specified training hours, case study review, and a signed program-manager eligibility memorandum. Full details are covered in the CCITP-A requirements guide.