By Compyl Research · Last reviewed September 2026
There is no list price for HITRUST certification, and any published range should be treated with suspicion, because the cost is generated by your own scope rather than set by a vendor. What you can do — and what actually protects a budget — is understand the five components that make up the total, know which of them you control, and put a specific set of questions to an assessor before you sign anything.
Key takeaways
- Scope generates cost. HITRUST tailors your requirement set from scope factors — systems, data volumes, geography, regulatory exposure. Requirement count is the closest thing to a cost driver, and you control it.
- The assessment type changes the order of magnitude. An e1 assesses 44 requirements; an i1, 182 in the current CSF release; an r2 uses a tailored set that is typically several hundred and examines five maturity levels instead of one.
- Most of the spend is usually internal. External assessor fees and platform subscription are the visible line items. Remediation and staff time are usually larger and are almost never in the quote.
- Readiness is the cheapest phase and the one people skip. Gaps found internally cost less than gaps found by an assessor during a validated assessment.
- Budget the cycle, not the certificate. e1 and i1 expire annually; r2 runs two years with an interim assessment in between. Year two is not free.
Why is there no published price for HITRUST?
Because there is no single product being priced. Three separate parties are involved and each charges differently.
HITRUST itself charges for use of the MyCSF assessment platform and for the quality assurance and report issuance associated with a validated assessment. The external assessor — an independent firm approved by HITRUST — charges for the validated assessment, and often separately for readiness work. Your own organization absorbs the remediation and the staff time, which is the component nobody invoices and almost everybody underestimates.
On top of that, the requirement set is generated per organization. Two companies of similar size running the same assessment type can face materially different requirement counts because their scope factors differ. A published “average” is therefore an average across incomparable engagements.
What are the components of HITRUST cost?
| Component | Paid to | What drives it | How much you control it |
|---|---|---|---|
| MyCSF platform and report | HITRUST | Assessment type, subscription tier, number of assessments | Low — set by the type you need |
| Readiness assessment | External assessor or advisor (or internal) | Requirement count, how much documentation already exists | High — can be done internally if you have the capability |
| Validated assessment | External assessor | Requirement count, number of systems and locations, evidence quality | Medium — scope and preparation both move it |
| Remediation | Internal, plus tooling and consultants | The gap between current state and the requirement set | High — and unknown until readiness is complete |
| Internal staff time | Internal | Evidence collection, interviews, policy and procedure writing, project management | High — the largest hidden component |
| Maintenance | All of the above | Annual recertification (e1, i1) or interim assessment (r2) | Medium — predictable once the first cycle is done |
The pattern worth internalising: the two components you can most influence — readiness and remediation — are the two that are hardest to estimate before you start, which is precisely why readiness comes first.
Which assessment type are you actually paying for?
Effort scales with requirement count and with the number of maturity levels examined, and the three assessment types differ on both.
- e1 assesses 44 foundational requirements against implementation only, and the certification is valid for one year.
- i1 assesses a fixed baseline — 182 requirements in the current CSF release — again on implementation only, valid for one year.
- r2 assesses a requirement set tailored to your scope factors, and scores every requirement across all five maturity levels: Policy, Procedure, Implemented, Measured and Managed. Valid for two years with an interim assessment in between.
The r2 is not simply a longer i1. Because it examines whether controls are measured and actively managed, organizations that have implemented controls but never measured them find that two of the five maturity levels score badly, and closing that gap is program-building work rather than documentation work. That is the difference that most affects the total.
Buying the wrong type is the expensive mistake in both directions: an e1 when the customer specified i1 buys a report nobody accepts; an r2 when i1 would satisfy the requirement buys assurance nobody asked for.
How does scope change the number?
Scope factors — the questions HITRUST asks about your organization to generate the requirement set — cover things like the number of records held, the systems and facilities in scope, whether you operate internationally, and which regulatory regimes apply. More scope means more requirements, more evidence, more testing and more remediation surface.
Practical levers:
- Assess the environment your customers care about, not the whole company. A well-defined production environment with clear boundaries is cheaper to assess and easier to defend than a vague one.
- Segment before you scope. Network and data segmentation that genuinely isolates out-of-scope systems removes them from the assessment. Segmentation asserted but not enforced does not.
- Use inheritance where it applies. Controls inherited from a certified cloud provider or a certified parent entity reduce what you have to evidence yourself.
- Do not scope so narrowly that the report fails its purpose. Confirm with the customer who asked for HITRUST what they expect to be covered, before scoping — not after.
What is not usually in the quote?
Assessor proposals typically cover the validated assessment. The items that most often arrive later:
- Readiness. Sometimes bundled, often a separate engagement, occasionally assumed to be your job.
- Remediation. Almost never included, and an assessor performing the validated assessment usually cannot remediate for you.
- Penetration testing and vulnerability scanning where the requirement set calls for them.
- Tooling you have to acquire to satisfy requirements — logging, monitoring, endpoint controls, evidence management.
- Internal time across security, engineering, IT, HR and legal for evidence, interviews and policy approval.
- Corrective action plan work if a domain or control falls short.
- Year two. Recertification or interim assessment, plus the maintenance effort in between.
What questions should you ask an assessor?
These separate a comparable proposal from a headline number:
- Given our scope factors, what requirement count does this generate?
- What exactly is included in this engagement, and what is billed separately?
- Is readiness included? If not, what do you charge for it, and can we do it ourselves?
- What are your assumptions about the quality and availability of our evidence, and what happens to the fee if those assumptions are wrong?
- What happens if a domain scores below the certification threshold — what is the remediation and re-testing process, and what does it cost?
- Which CSF version will we be assessed against, and when does it close for new assessments?
- What does year two look like — interim assessment or recertification, and at what effort?
- How much of our control set can be inherited, and from where?
- Who at your firm performs the fieldwork, and what is their healthcare or sector experience?
Getting written answers to questions 1, 2 and 5 before signing removes most of the variance from a HITRUST budget.
How do you reduce the total?
- Start with readiness, internally if you can. It is the cheapest place to find gaps and it converts remediation from an unknown into a plan.
- Scope deliberately. The requirement count is the cost, and scope is the requirement count.
- Fix documentation before fieldwork. Policy and Procedure carry weight in r2 scoring and are the cheapest maturity levels to raise — they cost writing time, not engineering time.
- Collect evidence continuously. Evidence assembled retrospectively costs staff weeks and still only describes the period it was collected in.
- Map once across frameworks. If you are also doing SOC 2 or ISO 27001, evidence a control once and use it everywhere rather than running parallel programs.
- Pick the assessment type your customers actually require. Confirm it in writing before scoping.
How Compyl helps you control HITRUST cost
The components you control — readiness, remediation and internal time — are all made larger by the same thing: evidence and policy scattered across systems, with no single view of which controls exist, who owns them and when they were last reviewed. Compyl maps one control set across HITRUST, SOC 2, ISO 27001 and HIPAA so a control is evidenced once, keeps policies, owners and review cycles in one place so the documentation-based maturity levels are demonstrable rather than reconstructed, and collects evidence continuously so fieldwork is a review rather than a scramble.
Book a demo to see how Compyl supports a HITRUST program. For the full picture of what certification involves, see our guide to HITRUST compliance.
HITRUST cost FAQs
How much does HITRUST certification cost?
There is no list price, and published ranges are unreliable because the requirement set is generated from each organization’s own scope factors. The total is made up of HITRUST platform and report fees, external assessor fees, readiness, remediation, internal staff time and the ongoing cycle. Requirement count and starting maturity drive it more than company size does.
Is an e1 or i1 cheaper than an r2?
Substantially, yes. e1 covers 44 requirements and i1 a fixed baseline of 182 in the current CSF release, both assessed on implementation only. An r2 uses a tailored requirement set and scores five maturity levels per requirement, which multiplies both assessor effort and internal preparation.
What is the biggest hidden cost?
Internal staff time and remediation. Neither appears in an assessor’s proposal, and together they usually exceed the fees that do. Remediation in particular is unknown until a readiness assessment is complete.
Can we do the readiness assessment ourselves?
Yes. Readiness is an unvalidated self-assessment against your generated requirement set, and organizations with an established security function frequently run it internally. The validated assessment itself must be performed by a HITRUST-approved external assessor.
Does HITRUST cost less the second time?
Usually, provided the program is maintained. Most of the first-cycle cost is remediation and building documentation; if evidence collection continues and policies stay current, the interim assessment or annual recertification is a smaller exercise. Programs that go dormant between cycles pay much of the first-cycle cost again.
Does using a compliance platform reduce the cost?
It reduces the components you control — evidence collection, documentation maintenance and duplicated work across frameworks. It does not change assessor fees or HITRUST’s own fees, and no platform performs the validated assessment.
How long does HITRUST certification take?
The timeline is driven by remediation rather than by assessment fieldwork. An organization with mature, documented, evidenced controls can move through readiness and validation comparatively quickly; one building the program during the project is limited by how fast it can write, approve and operate new controls — and by the requirement that controls be shown to operate, which cannot be compressed.
