- CCITP-F has 110 multiple-choice questions: 100 scored, 10 unscored pilot items.
- Exam duration is 130 minutes; passing requires 650 of 800 scaled points, not a percentage.
- Four weighted domain groups: Policy and Directives (25%), Social and Behavioral Science (10%), Researching (30%), and Synthesis & Tools and Methods (35%).
- Eligibility requires active C-InT program affiliation, six months of experience, ten training hours, and Program Manager approval.
What Is CCITP-F Certification?
The Certified Counter-Insider Threat Professional - Fundamentals (CCITP-F) credential is the entry-tier certification in the CCITP program line, designed to validate baseline competency for personnel working in or with counter-insider threat (C-InT) programs. It is not a general-purpose cybersecurity or risk-management credential - it is built specifically around the policy, behavioral science, research, and analytic synthesis skills that insider threat program staff use day to day. If you landed here searching for background on what CCITP-F actually is or what the CCITP-F designation means in practice, this article consolidates the structural facts: exam format, domain weighting, eligibility gates, and governance.
Because several unrelated credentials also use the acronym "CCITP-F," it's worth anchoring on this: the version covered here is conferred jointly through defense and counterintelligence channels, not by a commercial IT certification vendor. Keep that distinction in mind if you cross-reference other sources while studying.
Who Governs and Confers the Credential
CCITP-F sits under the authority of the CCITP Governance Council (CCITP GC), which sets program standards across the CCITP certification family. Final conferral is a joint action between the Under Secretary of Defense for Intelligence and Security (USD(I&S)) and the Director of the National Counterintelligence and Security Center (NCSC). This dual-authority structure reflects the hybrid defense/counterintelligence nature of insider threat work.
Exam Format: Questions, Timing, and Scoring
Per the current official CCITP Program Candidate Handbook (March 2025, page 6), the CCITP-F exam consists of 110 multiple-choice questions total - 100 scored questions and 10 unscored pilot questions mixed in without being identified to the candidate. Each question has exactly one correct answer; there is no partial credit or weighted scoring at the item level.
- Total questions: 110 (100 scored + 10 unscored pilot)
- Question type: Single-answer multiple choice
- Duration: 130 minutes (two hours, ten minutes - listed as 2.1667 exam hours)
- Passing standard: 650 out of 800 scaled points
That passing threshold is a scaled score, not a raw percentage of questions answered correctly - scaled scoring accounts for the pilot questions and item difficulty, so don't try to reverse-engineer a "percent correct" target. For a deeper breakdown of how the scaled scoring model works and what 650/800 actually implies for your preparation, see the dedicated CCITP-F passing score guide.
Key Takeaway
Budget your 130 minutes across roughly 110 items - that's a little over a minute per question on average, including the unscored pilot items you won't be able to identify during the exam.
For a candidate-level walkthrough of what the testing experience feels like, including pacing and question phrasing patterns, the CCITP-F difficulty guide and the pass rate analysis are useful companion reads before you book a seat.
The Four Weighted Domain Groups
The issuer publishes five topic areas organized into four weighted groups, with Synthesis and Tools and Methods combined into a single 35% block. No official split is published between Synthesis and Tools and Methods individually - treat that 35% as one combined domain for study-planning purposes rather than inventing a sub-percentage.
Domain 1: Policy and Directives (25%)
Covers the regulatory and directive framework governing C-InT programs - the policy backbone that shapes how insider threat programs are authorized, structured, and audited.
- Familiarity with governing directives and program authorities
- Understanding how policy translates into program-level requirements
Domain 2: Social and Behavioral Science (10%)
The smallest-weighted domain, focused on behavioral indicators and the social science underpinnings of insider threat risk assessment.
- Behavioral indicator recognition
- Foundational psychology and social-science concepts applied to risk
Domain 3: Researching (30%)
A heavily weighted domain testing how candidates gather, vet, and apply information relevant to insider threat casework and program development.
- Research methods and source evaluation
- Applying research findings to program or case context
Domain 4: Synthesis & Tools and Methods (35%)
The largest single weighted block, combining analytic synthesis skills with the tools and methods used in C-InT practice. Because it's the heaviest-weighted area, it deserves the largest share of your study time.
- Synthesizing disparate information into actionable assessments
- Applying standard tools and methods used in insider threat analysis
| Domain | Weight |
|---|---|
| Policy and Directives | 25% |
| Social and Behavioral Science | 10% |
| Researching | 30% |
| Synthesis & Tools and Methods | 35% |
For a full breakdown of each domain's subtopics and sample question phrasing, see the complete CCITP-F exam domains guide.
Eligibility Requirements
CCITP-F is not an open-entry exam. To sit for it, a candidate must currently be working in or affiliated with a counter-insider-threat program and meet all of the following:
- At least six months of experience working in or with a C-InT program
- At least ten hours of related training
- Approval from a Program Manager
This gatekeeping means CCITP-F functions more as a validation of existing on-the-job C-InT involvement than as a general entry credential for outsiders. If you're unsure whether your current role or training record qualifies, the full CCITP-F requirements breakdown walks through documentation and approval mechanics in detail.
Who Hires CCITP-F Holders
Because eligibility is restricted to people already working in or with counter-insider threat programs, CCITP-F tends to function as a formal credentialing step for personnel already embedded in C-InT roles - insider threat analysts, program support staff, and related security/counterintelligence functions within organizations that operate formal insider threat programs. It's less a door-opener for career switchers and more a standardized competency marker for people already inside the discipline. For a broader look at the roles and functions associated with this credential, see CCITP-F jobs and the qualitative discussion in whether CCITP-F certification is worth pursuing.
Mapping a Study Schedule to the Domains
Generic study techniques only matter here insofar as they map to CCITP-F's specific weighting. Because Synthesis & Tools and Methods (35%) and Researching (30%) together account for the majority of scored points, your schedule should weight those domains heavily rather than splitting time evenly across all four.
Policy and Directives
- Build a reference map of governing directives and authorities
- Light review given the 25% weight - don't over-invest here
Social and Behavioral Science
- Focus narrowly - it's the lowest-weighted domain at 10%
- Prioritize indicator recognition over theory depth
Researching
- Practice source vetting and research-application scenarios
- This domain carries 30% of the exam - treat it as high priority
Synthesis & Tools and Methods
- Spend the most total hours here - it's the single heaviest block at 35%
- Run timed practice sets to build pacing for the 130-minute window
A more detailed week-by-week breakdown, including recommended review order and self-check milestones, is available in the CCITP-F study guide for 2026. For quick-reference review in the final days before your test date, the CCITP-F cheat sheet condenses the must-know facts covered in this article.
Once you've mapped out domain priorities, running scored practice questions on our practice test platform is the fastest way to find out which domain is actually your weak point rather than guessing from the weighting alone.
Avoiding Handbook Version Confusion
One source of candidate confusion is outdated handbook data circulating online. The older Spring 2024 V1_8 handbook listed 115 total questions, including 15 pilot items. That figure is superseded for this component by the current March 2025 handbook, which specifies 110 total questions - 100 scored and 10 pilot. If you see a study resource citing 115 questions or a different pilot count, it's referencing the retired version.
Key Takeaway
Always confirm you're studying against the current March 2025 handbook figures (110 questions, 100 scored, 10 pilot) rather than the retired Spring 2024 V1_8 numbers.
It's also worth being explicit that CCITP-F statistics should never be blended with those of other CCITP tier credentials - domain names, weights, and question counts differ by component, and importing figures from a different tier (or from an unrelated credential that happens to share the same acronym) will leave you studying the wrong material entirely.
For the authoritative source, the current official handbook is published by CDSE and should be your primary reference alongside structured practice; cross-check anything you read on third-party sites against it, including the figures summarized on this practice test resource.
Frequently Asked Questions
The current handbook (March 2025) specifies 110 multiple-choice questions total: 100 scored and 10 unscored pilot questions, each with a single correct answer.
The exam duration is 130 minutes, listed in the handbook as two hours and ten minutes (2.1667 exam hours).
You need 650 out of 800 scaled points. This is a scaled score, not a raw percentage of correct answers, so it shouldn't be interpreted as a simple percent-correct target.
No. Eligibility is restricted to current counter-insider-threat program or affiliated personnel with at least six months of relevant experience, at least ten hours of related training, and Program Manager approval.
Synthesis & Tools and Methods, combined, carries the largest weight at 35%, followed by Researching at 30%, Policy and Directives at 25%, and Social and Behavioral Science at 10%.