- CCITP-F stands for Certified Counter-Insider Threat Professional - Fundamentals, governed by the CCITP Governance Council.
- Conferral is joint between USD(I&S) and the Director of the NCSC - not a single private certifying body.
- The current March 2025 handbook specifies 110 questions (100 scored, 10 pilot) in 130 minutes.
- Passing requires 650 of 800 scaled points - a scaled score, not a raw percentage.
Breaking Down the Acronym
CCITP-F stands for Certified Counter-Insider Threat Professional - Fundamentals. Each piece of that name matters more than it looks:
- Certified - the credential is awarded through a formal conferral process, not simply issued after a test score.
- Counter-Insider Threat - the discipline this credential validates: detecting, assessing, and mitigating risks posed by trusted insiders, as opposed to external cyber or physical threats.
- Professional - the credential is built for people already working in or around insider threat programs, not casual learners.
- Fundamentals - this is the foundational tier of the CCITP credential track, focused on the baseline knowledge, policy framework, and research skills every counter-insider threat practitioner needs before moving into more specialized work.
If you're searching for a plain-language definition, our companion piece What Is CCITP-F? covers the same ground from a different angle, and CCITP-F Meaning walks through the terminology practitioners use day to day. This article focuses specifically on what the acronym represents structurally - who governs it, what the exam actually tests, and why the "Fundamentals" label is doing real work in the name.
Who Governs and Confers CCITP-F
The name "Certified Counter-Insider Threat Professional - Fundamentals" is attached to a specific governance structure, not a generic industry test. The credential is overseen by the CCITP Governance Council (CCITP GC), which sets the standards, maintains the handbook, and defines what "certified" means for this discipline.
Conferral itself is joint. Two authorities sign off on the credential:
- The Under Secretary of Defense for Intelligence and Security (USD(I&S))
- The Director of the National Counterintelligence and Security Center (NCSC)
This dual-authority structure is a big part of why the "C" in CCITP-F carries weight: passing the exam produces a score report, but that score report "does not itself constitute the final certification conferral decision." The governance process behind the name is deliberately separate from the testing process. For a deeper look at what this credential involves end-to-end, see CCITP-F Certification and What Is CCITP-F Certification?.
What the Name Means on Exam Day
Understanding what CCITP-F stands for also means understanding how that definition translates into the actual test. Per the current official CCITP Program Candidate Handbook (March 2025, page 6):
- 110 total multiple-choice questions - 100 scored and 10 unscored pilot items, each with a single correct answer
- 130-minute duration (two hours and ten minutes; listed as 2.1667 exam hours)
- Passing standard: 650 out of 800 scaled points - not a percentage score
Note that an older Spring 2024 (V1_8) handbook listed 115 total questions with 15 pilots. That version is superseded for this component by the current March 2025 handbook's 110-question, 10-pilot structure. If you find older study material referencing 115 questions, treat the current handbook as authoritative. For the full breakdown of how the scaled score works, read CCITP-F Passing Score 2026: Exactly What You Need to Pass.
Key Takeaway
Because pilot questions are unscored but indistinguishable from scored ones during the exam, candidates should treat every one of the 110 questions as if it counts - there's no reliable way to identify which 10 are pilots.
The Four Domains Behind the Letters
The "Counter-Insider Threat" portion of the name is operationalized through five topic areas grouped into four weighted domains. These weights define how the exam is actually built:
Domain 1: Policy and Directives (25%)
Covers the regulatory and directive foundation that governs insider threat programs - the "why" behind program structure.
- Know the governing directives that establish program authority and scope
Domain 2: Social and Behavioral Science (10%)
The smallest weighted domain, focused on the behavioral indicators and human factors relevant to insider risk.
- Understand behavioral indicators without over-relying on anecdote
Domain 3: Researching (30%)
The single largest domain, testing a candidate's ability to gather, verify, and apply information relevant to insider threat casework.
- Master research methodology and source evaluation, not just terminology
Domain 4: Synthesis & Tools and Methods (35%)
A combined domain covering how findings are synthesized and which tools and methods support that process. No separate official percentage exists for Synthesis versus Tools and Methods individually - the 35% is published as one joint weight.
- Practice combining research outputs into a coherent analytic product
| Domain | Weight | What It Demands |
|---|---|---|
| Policy and Directives | 25% | Regulatory/directive knowledge |
| Social and Behavioral Science | 10% | Behavioral indicator literacy |
| Researching | 30% | Research methodology, sourcing |
| Synthesis & Tools and Methods | 35% | Combining analysis with applied tools |
For a domain-by-domain study strategy, see CCITP-F Exam Domains 2026: Complete Guide to All 4 Content Areas. Note that these weighted groups are specific to CCITP-F - a related but distinct CCITP-Analysis credential uses different statistics and an additional Vulnerabilities Assessment topic that does not apply here.
Who Actually Pursues This Credential
Because the name includes "Professional," the credential is built around people already embedded in counter-insider threat work - program analysts, researchers, and practitioners supporting designated C-InT programs. It is not marketed as a general-audience security certification. Organizations building out insider threat functions use CCITP-F as a baseline qualifier when staffing roles, and candidates often pursue it alongside other program-specific training. If you're exploring career paths tied to this credential, CCITP-F Jobs outlines the kinds of roles where this fundamentals-level designation is relevant, and Is the CCITP-F Certification Worth It? Complete ROI Analysis 2026 weighs the credential against career goals without resorting to invented salary figures.
Why "Fundamentals" Doesn't Mean Entry-Level
It's tempting to read "Fundamentals" as "beginner," but the eligibility criteria say otherwise. To sit for CCITP-F, a candidate must be:
- Current counter-insider-threat program or affiliated personnel
- In possession of at least six months of experience working in or with a C-InT program
- Holding at least ten hours of related training
- Approved by their Program Manager
This is not an open-entry exam anyone can register for online. The "Fundamentals" designation refers to the content tier within the broader CCITP credential structure, not the bar for who may attempt it. Full detail on meeting these criteria is in CCITP-F Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Mapping the Name to a Study Plan
Once you understand what each part of CCITP-F stands for, a study plan can follow the domain weights directly rather than guessing at emphasis. A simple way to sequence preparation:
Policy and Directives (25%)
- Build a reference outline of governing directives before moving on - this domain is foundational to everything else
Researching (30%)
- Practice source evaluation and research methodology questions, since this is the single heaviest domain
Synthesis & Tools and Methods (35%)
- Work through scenario-style items that require combining research findings into a usable conclusion
Social and Behavioral Science (10%) + Full Review
- Finish the smallest domain, then run full-length timed practice sets matching the 130-minute format
This sequencing isn't arbitrary - it mirrors the published weights so your time investment matches how the exam is actually scored. For a more detailed walkthrough of pacing, review techniques, and how to handle the 110-question format under time pressure, see CCITP-F Study Guide 2026: How to Pass on Your First Attempt. If you want a sense of how challenging candidates generally find the exam relative to its domain weighting, How Hard Is the CCITP-F Exam? Complete Difficulty Guide 2026 and CCITP-F Pass Rate 2026: What the Data Shows are useful next reads. When you're ready to test your readiness against realistic scoring conditions, the practice exams at our main practice test platform simulate the 650/800 scaled passing standard directly.
Key Takeaway
Treat the domain weights as your study time allocation: Researching and Synthesis & Tools and Methods together account for 65% of the exam, so they deserve the majority of your prep hours.
Frequently Asked Questions
CCITP-F stands for Certified Counter-Insider Threat Professional - Fundamentals, the foundational-tier credential governed by the CCITP Governance Council and jointly conferred by USD(I&S) and the NCSC Director.
"Fundamentals" refers to the content tier within the CCITP program structure, distinct from other tiers like CCITP-Analysis. It still requires prior program experience and approval - it is not an open-entry beginner exam.
Per the current March 2025 handbook, the exam has 110 multiple-choice questions (100 scored, 10 unscored pilot) administered in 130 minutes.
650 out of 800 scaled points. This is a scaled score, not a raw percentage of questions answered correctly, and a score report alone does not finalize certification conferral.
No. Eligibility requires being current counter-insider-threat program or affiliated personnel with at least six months of C-InT program experience, at least ten hours of related training, and Program Manager approval.