CCITP-A logo
Focused certification exam prep
Start practice

What Is CCITP-A Certification?

TL;DR
  • CCITP-A is jointly conferred by USD(I&S) and the NCSC director, administered via DCSA/CDSE/SPeD PMO.
  • The exam has 86 questions (80 scored, 6 unscored) in 135 minutes, delivered at Pearson VUE.
  • Passing requires a scaled score of 650/800, not a fixed percent-correct cutoff.
  • There is no assessment fee for eligible candidates - $0 to sit the exam.

What CCITP-A Actually Is

CCITP-A stands for Certified Counter-Insider Threat Professional - Analysis, a credential built for personnel who perform analytic work inside formal Insider Threat Programs. If you've seen the name "CITP-A" referenced elsewhere, that's not a different program - it's the renaming trajectory this same credential has been on, with CDSE materials increasingly referring to it as Certified Insider Threat Professional - Analysis. This article covers the CCITP-A certification specifically as administered under the counter-insider threat community, not any unrelated credential that happens to share the same four letters.

For readers who landed here after searching broader questions like what is CCITP-A, CCITP-A meaning, or what does CCITP-A stand for, the short version is: it's a government-recognized analysis-track credential sitting alongside a foundational tier, intended to validate that you can research, synthesize, and assess insider threat indicators using approved tools and methods.

Identity Check: This article discusses only the Insider Threat Program analysis credential described above. Fee amounts, pass rates, and question counts below come from official CDSE/DCSA tracking and handbook material - not from any other certification that uses similar initials.

Who Administers and Confers the Credential

CCITP-A is not issued by a private certifying body. It is jointly conferred by the Under Secretary of Defense for Intelligence and Security and the Director of the National Counterintelligence and Security Center. Day-to-day administration - handbooks, eligibility review, exam logistics - runs through the Defense Counterintelligence and Security Agency (DCSA), specifically the Center for Development of Security Excellence (CDSE) and the SPeD Program Management Office.

That structure matters for candidates: approval isn't a matter of paying a vendor and scheduling a test. Eligibility has to be reviewed and approved through DAU channels before you can even book a seat at a Pearson VUE test center. If you're unclear on how that approval chain works, the CCITP-A Requirements breakdown walks through the eligibility memorandum process in detail.

Exam Format, Delivery, and Question Style

The exam is delivered in person at Pearson VUE test centers. Per the CDSE tracker dated July 1, 2026, the exam contains 86 total questions - 80 scored plus 6 unscored pretest items that don't count toward your result but help validate future exam versions. The indexed official handbook specifies a 135-minute time limit and describes the question style as scenario-based multiple choice.

That scenario framing is the key difference from a typical recall-based certification exam. Questions tend to present a short situation - an anomalous access pattern, a behavioral observation, a policy conflict - and ask you to identify the correct analytic or procedural response rather than define a term in isolation. Details on whether the exam is open-book, uses a calculator, allows home proctoring, is adaptive, or what retake intervals apply are currently unverified in official sources, so don't assume any of those conditions without confirming through your program's eligibility channel.

Key Takeaway

Budget the full 135 minutes assuming every scored question requires reading a short scenario first - this is not a exam you can speed-read through definitions.

The Six CCITP-A Exam Domains

CCITP-A content is organized into six domains. The weighting below reflects the most recently verified official breakdown (2024 AIRE material); a newer 2026 blueprint document was not independently obtainable, so treat the percentages as the best-confirmed figures rather than a freshly re-issued split.

Domain 1: Policy and Directives (20%)

Covers the governing directives and policy framework that define Insider Threat Program authority, scope, and reporting obligations.

  • Know which policy instruments establish program requirements

Domain 2: Social and Behavior Science (10%)

Focuses on behavioral indicators and the psychological/social frameworks analysts use to contextualize anomalies.

  • Understand how behavioral science informs - but doesn't replace - technical indicators

Domain 3: Researching (20%)

Tests the ability to gather, verify, and correlate information from multiple authorized sources during an analytic inquiry.

  • Practice structuring a research question before pulling data

Domain 4: Synthesis

Together with Domain 5, this is the largest weighted group at 35% combined. Synthesis covers turning disparate research threads into a coherent analytic judgment.

  • Be ready to connect multiple weak signals into one defensible conclusion

Domain 5: Tools and Methods

Also part of the 35% combined weighting with Domain 4. Covers the analytic tools and methodologies used in day-to-day insider threat work, including UAM platforms.

  • Know the purpose and limitations of User Activity Monitoring tools

Domain 6: Vulnerabilities Assessment and Management (15%)

Covers identifying, assessing, and managing vulnerabilities that could be exploited by a potential insider threat.

  • Focus on the full lifecycle: identify, assess, mitigate, monitor

Because the individual split between Domains 4 and 5 isn't published separately, don't try to memorize an exact percentage for either one alone - study them as a combined block. For a deeper walk-through of each domain with example topic lists, see the CCITP-A Exam Domains 2026 guide.

Eligibility and Prerequisites

CCITP-A isn't an open-enrollment exam. Candidates must satisfy a specific prerequisite stack before DAU approval is granted:

  • Current CITP-F (the foundational tier) credential
  • Current status as Insider Threat Program personnel
  • At least 12 months of program experience
  • 40 hours of analysis-related training
  • 8 hours of UAM policy/tool training
  • Review of 10 case studies
  • Program-manager approval with a signed eligibility memorandum

No verified separate degree requirement or reference count exists beyond this list. Because this prerequisite chain is unusually procedural compared to most commercial certifications, it's worth reading the full CCITP-A Requirements article before you assume you qualify - missing one training hour requirement or case-study review can delay your eligibility memorandum.

Cost and Registration Mechanics

Here's a detail that surprises a lot of candidates researching this exam: the published, indexed official handbook lists no assessment fee - $0 for eligible candidates. There's no member/non-member pricing tier because membership isn't part of this credential's model at all. Your actual "cost" is the time investment in the prerequisite training and case-study review, plus whatever your organization requires administratively.

Registration itself runs through Pearson VUE, but only after your DAU eligibility approval is in place - you can't shop around for a seat before that approval precedes scheduling. For the full breakdown of what does and doesn't cost money around this certification, see CCITP-A Certification Cost 2026.

Passing Score and Pass Rate Data

The indexed handbook sets the passing threshold as a scaled score of 650 out of 800 - this is explicitly not the same as a raw 81.25% correct-answer requirement, since scaled scoring can weight items differently. A newly linked "combined handbook" that might clarify this further was inaccessible at time of research, so treat 650/800 as the confirmed standard. A full explanation of how scaled scoring works for this exam is available in CCITP-A Passing Score 2026.

On pass rates, the only verified official figures are: CY2025 - 21 of 39 assessments passed (53.85%), and June 2026 - 1 of 2 (50%). Neither figure is labeled as a first-attempt-only rate, and no full-year 2026 rate has been published yet. Treat these as small, assessment-count-based snapshots rather than a stable long-term benchmark - a deeper look at what these numbers do and don't tell you is in the CCITP-A Pass Rate 2026 article, and for context on perceived difficulty, see How Hard Is the CCITP-A Exam?.

MetricValue
Scored questions80
Unscored (pretest) questions6
Total questions86
Time limit135 minutes
Passing score650/800 (scaled)
Assessment fee$0 for eligible candidates
CY2025 pass rate53.85% (21/39)
June 2026 pass rate50% (1/2)
Active credentials in DAU (per July tracker)223

Maintaining the Credential

Once earned, CCITP-A requires ongoing professional development to stay active. The current maintenance-page indexed text specifies 100 PDUs per two-year cycle, with at least 50 of those PDUs tied directly to Insider Threat-related content, all recorded through DAU. Older official material referenced a three-year cycle instead, so if you're already certified, confirm your individual expiry date and how the transition between the two cycle lengths was handled for your specific credential record - don't assume the newer two-year figure automatically overwrote an older three-year cycle without a formal notice.

223 Active Holders: The July tracker lists 223 active CITP-A credentials recorded in DAU. That's a small, specialized population - this is not a general-market keyword-volume estimate, and it underscores how niche and role-specific this certification remains.

Who Hires CCITP-A Holders

CCITP-A holders work inside formal Insider Threat Programs across federal agencies, DoD components, and cleared contractor organizations that operate under program-manager-approved structures. Because eligibility itself requires you to already be Insider Threat Program personnel with at least 12 months of program experience, this isn't typically an entry-point credential - it's a validation layer for analysts already embedded in the discipline, signaling that their research, synthesis, and tools proficiency has been formally assessed. If you're mapping out what roles value this credential and how it affects career trajectory, the CCITP-A Jobs page and the CCITP-A Salary Guide 2026 go into more detail, and the broader Is the CCITP-A Certification Worth It? analysis weighs the time investment against career benefit.

Mapping a Study Plan to the Blueprint

Rather than applying a generic study template, your prep time should mirror domain weight. Domains 4 and 5 jointly account for 35% of content - the largest published group - so they deserve the most sustained attention, while Domain 2 at only 10% should get comparatively lighter review.

Week 1

Policy and Directives + Researching

  • Build a reference map of governing directives (Domain 1)
  • Practice structured research workflows against scenario prompts (Domain 3)
Week 2

Tools and Methods + Synthesis

  • Drill UAM policy and tool scenarios (Domain 5)
  • Practice combining multiple weak indicators into one judgment (Domain 4)
Week 3

Vulnerabilities + Behavioral Science

  • Work through the vulnerability lifecycle: identify, assess, mitigate (Domain 6)
  • Review behavioral indicator frameworks (Domain 2)
Week 4

Full Scenario Review

  • Run full-length scenario-based practice sets under the 135-minute limit
  • Revisit case studies required for your eligibility memorandum

For a complete week-by-week plan with recommended practice volume, read the CCITP-A Study Guide 2026. And since the exam leans heavily on scenario-based multiple choice rather than definition recall, running realistic practice questions on our CCITP-A practice test platform is one of the most direct ways to get comfortable with that question style before test day. If you want a condensed reference you can review in the final days before your exam, the CCITP-A Cheat Sheet 2026 consolidates the must-know facts covered here. Scheduling logistics, including how far in advance you can book at Pearson VUE once approved, are covered in CCITP-A Exam Dates 2026.

Key Takeaway

Weight your study time 35% toward Synthesis and Tools and Methods combined, then layer in the remaining domains proportionally - don't study all six equally.

Finally, if you arrived here from a related search like what is a CCITP-A, what does CCITP-A mean, or you're building out general familiarity before committing to the prerequisite path, spending time on practice questions modeled on the real domain weighting is a faster way to gauge readiness than reading alone. Formal preparation resources, including CDSE-aligned coursework, are summarized in CCITP-A Training.

Frequently Asked Questions

Is CCITP-A the same thing as CITP-A?

Yes - CITP-A (Certified Insider Threat Professional - Analysis) is the current CDSE naming direction for the credential historically referenced as CCITP-A. The renaming effective date is unverified, but both names describe the same analysis-track credential discussed in this article.

How many questions are on the CCITP-A exam, and how long do I get?

The exam contains 86 total questions - 80 scored and 6 unscored - delivered as scenario-based multiple choice. The indexed handbook specifies a 135-minute time limit.

What does the CCITP-A exam cost?

The published official handbook lists no assessment fee - $0 for eligible candidates. There is no member versus non-member pricing because membership isn't part of this credential's structure.

What score do I need to pass?

You need a scaled score of 650 out of 800, which is not the same as a fixed 81.25% raw-correct requirement since scaled scoring weights items differently.

Can I take the CCITP-A exam without insider threat program experience?

No. Eligibility requires current CITP-F status, being current Insider Threat Program personnel, at least 12 months of program experience, specific training hours, case-study review, and a program-manager-approved eligibility memorandum before DAU approval and Pearson VUE scheduling.

Ready to pass your CCITP-A exam?

Put this into practice with free CCITP-A questions across every exam domain.