- What CCITP-F Actually Is
- Who Governs and Confers the Credential
- Who Can Sit for CCITP-F
- Exam Format: Questions, Timing, and Scoring
- The Four Domains of CCITP-F
- What You Actually Need to Know
- Why the Handbook Version Matters
- Who Hires CCITP-F Holders
- Mapping a Study Plan to the Domain Weights
- Frequently Asked Questions
- CCITP-F is jointly conferred under USD(I&S) and the NCSC, governed by the CCITP Governance Council.
- The current exam has 110 multiple-choice questions (100 scored, 10 unscored pilot) in 130 minutes.
- Passing requires 650 of 800 scaled points - not a raw percentage.
- Four weighted domains: Policy and Directives (25%), Social and Behavioral Science (10%), Researching (30%), and Synthesis & Tools and Methods (35%).
What CCITP-F Actually Is
CCITP-F stands for Certified Counter-Insider Threat Professional - Fundamentals. It is the entry-level credential in the broader CCITP certification program, designed to validate that a practitioner understands the foundational policy, behavioral science, research, and analytic-synthesis skills that underpin counter-insider threat (C-InT) work across government and cleared-industry environments.
Unlike open-enrollment IT or security certifications, CCITP-F is purpose-built for people already working inside or alongside a counter-insider threat program. It is not a generic "insider threat awareness" badge - it is a formal, governance-backed credential tied to a specific body of C-InT doctrine, policy, and practice. If you're still trying to pin down the acronym itself, our companion pieces on What Is CCITP-F? and CCITP-F Meaning cover the terminology in more depth.
Who Governs and Confers the Credential
CCITP-F sits under the authority of the CCITP Governance Council (CCITP GC), which sets the program's standards and handbook content. Conferral of the certification itself is a joint action between the Under Secretary of Defense for Intelligence and Security (USD(I&S)) and the Director of the National Counterintelligence and Security Center (NCSC).
That dual-authority structure matters practically: passing the exam is necessary but not sufficient. A score report is a milestone, not the certificate. The program's governance process reviews eligibility, training hours, and program approval before the credential is formally conferred - which is one reason the CCITP-F Requirements page is worth reading before you even schedule a seat.
Who Can Sit for CCITP-F
CCITP-F is restricted-entry. You cannot simply register and test. To be eligible, a candidate generally must:
- Be current counter-insider-threat program personnel, or affiliated personnel working directly with a C-InT program.
- Have at least six months of experience working in or with a C-InT program.
- Complete at least ten hours of related training.
- Obtain Program Manager approval before registering.
This gatekeeping is intentional. The exam assumes you already have operational context - you're not learning what an insider threat is for the first time; you're demonstrating you can apply policy, behavioral indicators, and research methods in a real program setting. For the full breakdown of documentation and approval steps, see CCITP-F Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Key Takeaway
If you don't currently work in or with a C-InT program, CCITP-F is not yet the right certification to pursue - eligibility is the first hurdle, not the exam itself.
Exam Format: Questions, Timing, and Scoring
Per the current official CCITP Program Candidate Handbook (March 2025, page 6), the CCITP-F exam consists of 110 multiple-choice questions: 100 scored items plus 10 unscored pilot questions used to evaluate future exam content. Every question has exactly one correct answer - there are no multi-select or fill-in-the-blank formats.
Candidates have 130 minutes (two hours and ten minutes) to complete the exam. That works out to roughly 1 minute and 11 seconds per question if you treat all 110 evenly, though since you can't distinguish scored from pilot items during the test, pacing should be planned against the full question count, not just the 100 that count toward your score.
Passing is defined as a scaled score of 650 out of 800 points - not a percentage of correct answers. This distinction trips up candidates who assume "70% correct" or similar simple math applies. For a detailed explanation of how scaled scoring works and why it isn't a straight percentage, read CCITP-F Passing Score 2026: Exactly What You Need to Pass.
| Exam Detail | Current Standard (March 2025 Handbook) |
|---|---|
| Total questions | 110 (100 scored + 10 pilot) |
| Question format | Multiple choice, one correct answer each |
| Time allowed | 130 minutes (2.1667 exam hours) |
| Passing standard | 650 of 800 scaled points |
| Result delivery | Score report; final conferral is a separate governance decision |
It's also worth knowing that scheduling windows and testing cadence are managed separately from the scoring rules above. If you're planning around a specific deadline, check CCITP-F Exam Dates 2026: Testing Windows, Deadlines & Scheduling before locking in a study timeline.
The Four Domains of CCITP-F
The issuer organizes the exam content into five named topic areas, but reports them in four weighted domain groups because Synthesis and Tools and Methods are combined into a single published weight. No official breakdown splits that 35% further, so any source claiming an exact split between the two is guessing, not reporting fact.
Domain 1: Policy and Directives (25%)
Covers the governing policy framework behind counter-insider threat programs - the directives, authorities, and compliance obligations that shape how a C-InT program must operate.
- Knowing which policies authorize specific program activities
- Understanding the roles and responsibilities embedded in governing directives
Domain 2: Social and Behavioral Science (10%)
The smallest weighted domain, but conceptually dense. It focuses on the behavioral science underpinning insider threat risk - motivations, stressors, and behavioral indicators relevant to risk assessment.
- Behavioral indicator categories and their relevance to risk
- How behavioral science informs program decision-making, not just detection
Domain 3: Researching (30%)
The largest single-weighted domain. It tests a candidate's ability to gather, validate, and apply information relevant to a C-InT case or program decision.
- Research methods and source evaluation appropriate to C-InT work
- Translating raw information into usable program input
Domain 4: Synthesis & Tools and Methods (35%)
The heaviest-weighted combined domain. It covers how practitioners pull together disparate information (synthesis) and the specific tools and methods used to do so within a C-InT program.
- Applying synthesis techniques to multi-source information
- Familiarity with the categories of tools and methods used in program analysis, without a separately published internal weight
For a question-by-question breakdown of how each domain tends to be tested, see CCITP-F Exam Domains 2026: Complete Guide to All 4 Content Areas.
What You Actually Need to Know
Because CCITP-F assumes existing program experience, the exam isn't testing whether you've memorized a textbook definition of "insider threat." It's testing whether you can connect policy, behavior, research, and synthesis into defensible program judgments. Concretely, that means being comfortable with:
- Identifying which governing directive or policy applies to a given program scenario
- Distinguishing behavioral indicators that merit further review from those that don't rise to a reportable threshold
- Selecting appropriate research approaches to validate or disprove a potential insider threat concern
- Synthesizing multiple data points (policy, behavioral, and research findings) into a coherent analytic product
- Applying standard tools and methods used within C-InT programs to support synthesis work
Because the scored and pilot questions are indistinguishable during the test, every one of the 110 questions deserves full attention - treat the exam as a 110-question test even though only 100 count.
Why the Handbook Version Matters
If you find older study material referencing 115 total questions with 15 pilot items, you're looking at the Spring 2024 V1_8 handbook, which has been superseded. The current official CCITP Program Candidate Handbook (March 2025) governs today's exam: 110 total questions, with 100 scored and 10 pilot. Always verify which handbook version a study resource is citing before trusting its numbers - and when in doubt, check the official CCITP Handbook PDF directly.
Who Hires CCITP-F Holders
Because eligibility already requires current or affiliated C-InT program experience, CCITP-F tends to function less as a door-opener into the field and more as a formal validation for people already doing the work - program analysts, researchers, and personnel supporting insider threat hubs within defense, intelligence, and cleared-industry environments. It signals that your judgment across policy, behavioral science, research, and synthesis has been independently assessed against a governance-backed standard rather than simply vouched for by a supervisor.
If you're evaluating whether the credential is worth pursuing given your current role and trajectory, read Is the CCITP-F Certification Worth It? Complete ROI Analysis 2026 and CCITP-F Salary Guide 2026: Complete Earnings Analysis. For a sense of where the credential shows up in job postings and role descriptions, see CCITP-F Jobs.
Mapping a Study Plan to the Domain Weights
Generic study techniques only help if they're pointed at the right material. Because Researching (30%) and the combined Synthesis & Tools and Methods domain (35%) together make up 65% of the exam, your study time should be weighted accordingly rather than split evenly across all five topic areas.
Policy and Directives (25%)
- Build a reference map of governing directives and authorities
- Practice matching scenarios to the correct policy citation
Social and Behavioral Science (10%)
- Review behavioral indicator categories
- Focus on threshold judgment - what warrants escalation versus monitoring
Researching (30%)
- Drill source evaluation and research-method scenarios
- Practice turning raw findings into program-usable conclusions
Synthesis & Tools and Methods (35%)
- Practice combining multi-domain information into a single judgment
- Review common tool/method categories used in C-InT analysis
In the final stretch, shift from learning new material to timed practice under the real 130-minute constraint so pacing across all 110 questions feels automatic. A structured walkthrough of this approach is in CCITP-F Study Guide 2026: How to Pass on Your First Attempt, and a condensed reference for last-minute review is available in the CCITP-F Cheat Sheet 2026: One-Page Review of Must-Know Facts.
Running full-length, timed practice sessions on our practice test platform is one of the most direct ways to get comfortable with the 110-question, 130-minute format before test day, since reading about the exam and actually pacing yourself through it are very different experiences. If you're still weighing how difficult the exam feels relative to your current experience level, How Hard Is the CCITP-F Exam? Complete Difficulty Guide 2026 walks through that in detail, and CCITP-F Pass Rate 2026: What the Data Shows covers what's publicly known about outcomes.
Frequently Asked Questions
CCITP-F stands for Certified Counter-Insider Threat Professional - Fundamentals, the entry-level component of the CCITP certification program. See What Does CCITP-F Stand For? for more detail.
No. Eligibility requires current or affiliated C-InT program personnel status, at least six months of relevant experience, at least ten hours of related training, and Program Manager approval before registration.
Per the current March 2025 handbook, the exam has 110 multiple-choice questions (100 scored, 10 unscored pilot) with a time limit of 130 minutes.
You need 650 out of 800 scaled points. This is a scaled score, not a raw percentage of correct answers, so it doesn't translate directly to "percent correct."
Not immediately. A score report is not itself the final conferral decision. Conferral involves the CCITP Governance Council process alongside the joint USD(I&S) and NCSC authorities.