CCITP-F logo
Focused certification exam prep
Start practice

What Is CCITP-F?

TL;DR
  • CCITP-F is conferred jointly by USD(I&S) and the NCSC under CCITP Governance Council oversight.
  • The current exam has 110 multiple-choice questions: 100 scored, 10 unscored pilot items.
  • Candidates get 130 minutes and must reach 650 of 800 scaled points to pass.
  • Researching (30%) and the joint Synthesis & Tools and Methods group (35%) carry the most weight.

What Is CCITP-F?

CCITP-F stands for Certified Counter-Insider Threat Professional - Fundamentals. It is the entry-level credential in the broader CCITP certification track, built specifically for personnel who work inside, or in direct support of, a counter-insider threat (C-InT) program. This article covers only that version of the acronym - several other industries use "CCITP-F" for unrelated credentials, and none of their facts apply here. Everything below comes from the official program documentation governing this specific certification.

Unlike generic security certifications that anyone can register for, CCITP-F is purpose-built around the practical work of identifying, researching, and reporting on insider threat indicators within an established program structure. If you're trying to understand exactly what the exam covers, how it's scored, and who qualifies to sit for it, this page is the foundational overview - pair it with the detailed CCITP-F Exam Domains 2026: Complete Guide to All 4 Content Areas once you're ready to go deeper into content.

Not Open-Entry: CCITP-F is restricted to current counter-insider-threat program or affiliated personnel. You cannot simply register as an outside candidate the way you might for many commercial IT certifications.

Who Governs and Confers CCITP-F

CCITP-F sits under the authority of the CCITP Governance Council (CCITP GC), which oversees the program's standards, content, and policy. Final certification is a joint conferral between two authorities:

  • The Under Secretary of Defense for Intelligence and Security (USD(I&S))
  • The Director of the National Counterintelligence and Security Center (NCSC)

This dual-authority structure matters for candidates because it means a passing exam score is not, by itself, the final word. According to the current official CCITP Program Candidate Handbook, a score report does not itself constitute the final certification conferral decision - the credential is issued through the governance process after the scoring threshold is met. This distinction is worth understanding before exam day so you aren't surprised by the sequence of events after you finish testing.

Exam Format, Timing, and Scoring

The current official CCITP Program Candidate Handbook (March 2025, printed page 6) specifies the exam structure that candidates should rely on today:

  • 110 total multiple-choice questions - 100 scored, 10 unscored pilot questions, each with a single correct answer
  • 130-minute time limit (two hours and ten minutes; listed as 2.1667 exam hours in the handbook's hours field)
  • Passing standard: 650 out of 800 scaled points - this is a scaled score, not a raw percentage

Because the 10 pilot questions are unscored and indistinguishable from scored items during the test, candidates should treat every question on the screen as if it counts. There's no way to identify which ten are pilot items, so skipping or rushing through sections based on a guess about "which ones don't matter" is not a viable strategy.

Handbook Version Matters: An older Spring 2024 (V1_8) handbook listed 115 total questions including 15 pilot items. That version is superseded for CCITP-F - the current March 2025 handbook's 110-question, 100-scored/10-pilot structure is the one that governs the exam today. If you find older study material referencing 115 questions, it's outdated.

For a full breakdown of what the scaled scoring actually means in practice and how far 650 points really goes, see CCITP-F Passing Score 2026: Exactly What You Need to Pass. If you're weighing whether the exam's structure makes it a tough test overall, How Hard Is the CCITP-F Exam? Complete Difficulty Guide 2026 digs into that question directly.

h2 id="domains">The Four Weighted Domains

The issuer publishes five named topic areas organized into four weighted groups. Two of those named areas - Synthesis, and Tools and Methods - are combined into a single published weight. No separate percentage breakdown exists for Synthesis versus Tools and Methods individually, so don't rely on any source that tries to split that 35% into sub-percentages; that information isn't officially published.

Domain 1: Policy and Directives - 25%

Candidates need working knowledge of the policy framework that governs counter-insider threat programs, including the directives that establish program authority, reporting obligations, and operational boundaries.

  • Understand how policy constrains what a C-InT program can collect, analyze, and act on

Domain 2: Social and Behavioral Science - 10%

This domain is the smallest weight but covers the human-factors side of insider threat work: behavioral indicators, risk factors, and the science behind why insiders act.

  • Focus on how behavioral science informs - but does not replace - policy-driven decision-making

Domain 3: Researching - 30%

One of the two heaviest-weighted areas. This domain tests the practical skill of gathering, verifying, and organizing information relevant to a potential insider threat case.

  • Expect scenario-based questions on research methodology and source evaluation

Domain 4: Synthesis & Tools and Methods - 35%

The largest single weighted group, combining the ability to synthesize findings into usable conclusions with knowledge of the tools and methods used in day-to-day C-InT work.

  • Treat this as the domain requiring the most practice time given its combined weight

A detailed, item-by-item walkthrough of each domain - including the kinds of question stems you're likely to see - is covered in CCITP-F Exam Domains 2026: Complete Guide to All 4 Content Areas. If you want a condensed, quick-reference version of the same material, bookmark the CCITP-F Cheat Sheet 2026: One-Page Review of Must-Know Facts.

Eligibility: Who Can Sit for CCITP-F

CCITP-F is not an open-registration exam. The handbook restricts eligibility to candidates who meet all of the following:

  • Currently work in, or are affiliated with, a counter-insider-threat program
  • Have at least six months of experience working in or with a C-InT program
  • Have completed at least ten hours of related training
  • Have obtained Program Manager approval to sit for the exam

In other words, this isn't a credential you can simply decide to pursue on your own initiative without institutional backing. Your eligibility is tied directly to your current role and your Program Manager's sign-off. If you're unsure whether you currently qualify, the full breakdown of each requirement - including how the six months and ten hours are typically documented - is laid out in CCITP-F Requirements 2026: Eligibility, Prerequisites & How to Qualify.

Key Takeaway

Before you spend time studying domain content, confirm your eligibility status with your Program Manager. The six-month experience window and ten-hour training requirement are prerequisites, not formalities.

Who Hires CCITP-F Holders

Because eligibility is restricted to people already working in or alongside C-InT programs, CCITP-F functions less as a door-opener for outsiders and more as a standardized validation of skills for people already embedded in this work. Organizations that run or support insider threat programs use the credential to confirm that program personnel share a common baseline understanding of policy, research methods, and analytical synthesis - regardless of which office or component they came from.

If you're trying to figure out how this credential fits into a broader career trajectory inside the counter-insider threat field, two resources go further than this overview:

CCITP-F at a Glance

AttributeCurrent CCITP-F Specification
Governing bodyCCITP Governance Council (CCITP GC)
Conferral authoritiesUSD(I&S) and Director, NCSC (joint)
Total questions110 (100 scored, 10 unscored pilot)
Time allotted130 minutes (2.1667 exam hours)
Passing standard650 of 800 scaled points
Weighted domain groups4 groups across 5 named topic areas
Top-weighted domainSynthesis & Tools and Methods (35%)
EligibilityC-InT program affiliation, 6 months experience, 10 hrs training, PM approval
Handbook referenceMarch 2025 edition (supersedes Spring 2024 V1_8)

For context on how this specification translates into real-world difficulty, and what current candidates report about the test experience, see CCITP-F Pass Rate 2026: What the Data Shows. And if budget planning for your Program Manager is part of your next step, CCITP-F Certification Cost 2026: Complete Pricing Breakdown covers the fee mechanics in detail.

Mapping a Study Plan to the Domain Weights

Given that Researching (30%) and Synthesis & Tools and Methods (35%) together account for 65% of the exam, the most efficient study sequence front-loads those two domains rather than spreading time evenly across all four. A weighted approach - spending roughly proportional time per domain - tends to outperform a flat "equal time for everything" schedule, simply because the exam itself isn't weighted equally.

Week 1

Policy and Directives + Social and Behavioral Science

  • Build the foundational policy framework first, since later domains reference it
  • Cover behavioral science concepts in the same week since it's the lowest-weighted domain
Weeks 2-3

Researching

  • Dedicate two full weeks to research methodology given its 30% weight
  • Practice scenario questions that mirror source evaluation and verification tasks
Weeks 4-5

Synthesis & Tools and Methods

  • Since this is the single largest weighted group at 35%, give it the most practice-question volume
  • Work through combined synthesis-and-tools scenarios rather than studying the two concepts separately
Week 6

Full review and timed practice

  • Run full-length timed sessions against the 130-minute limit
  • Revisit weaker domains identified during practice

A full, step-by-step version of this approach - including how many practice questions to target per domain - is available in the CCITP-F Study Guide 2026: How to Pass on Your First Attempt. You can also run timed practice exams built around the official domain weighting to get comfortable with the 130-minute pace before your scheduled date.

Avoid Flat Study Plans: Spending equal time on all four domains ignores that Social and Behavioral Science is weighted at only 10% while Synthesis & Tools and Methods is weighted at 35%. Match your study hours to the published weights, not to how interesting or unfamiliar a topic feels.

Frequently Asked Questions

What does CCITP-F stand for?

CCITP-F stands for Certified Counter-Insider Threat Professional - Fundamentals, the entry-level credential in the CCITP program track governed by the CCITP Governance Council. See a direct breakdown at What Does CCITP-F Stand For?.

Can anyone register for the CCITP-F exam?

No. Eligibility is restricted to current counter-insider-threat program or affiliated personnel with at least six months of relevant experience, ten hours of related training, and Program Manager approval.

How many questions are on the CCITP-F exam, and how long do I get?

The current March 2025 handbook specifies 110 total questions (100 scored, 10 unscored pilot items) with a 130-minute time limit.

Is passing score a percentage?

No. CCITP-F uses a scaled score, and candidates must reach 650 out of 800 scaled points to pass - this is not expressed as a percentage correct.

Does a passing score automatically mean I'm certified?

Not immediately. A score report does not itself constitute the final certification conferral decision; conferral involves the joint authorities overseeing the program. For more on the broader credential structure, see CCITP-F Certification or the quick overview at What Is CCITP-F Certification?.

Ready to pass your CCITP-F exam?

Put this into practice with free CCITP-F questions across every exam domain.