A HITRUST readiness assessment is the gap check done before the validated assessment. It is not the certification itself. It tells you where your controls, policies and evidence stand against the HITRUST requirements you plan to be assessed on, so you can fix gaps before an assessor tests them.
This guide explains what a readiness assessment covers, when to do it, what you receive, and how it differs across the e1, i1 and r2 assessments.
What a HITRUST readiness assessment is
A readiness assessment compares how your organisation operates today with the requirements of your chosen HITRUST assessment. Its purpose is preparation. No certification is issued at the end of it.
Validated assessments are performed by our partner Huduku AI, a HITRUST Authorized External Assessor. CyberWave GRC provides readiness, implementation and certification support. CyberWave GRC is not an assessor.
When to do a readiness assessment
Do it before the validated assessment begins — ideally before you commit to an assessment date. Doing it first means gaps are found and fixed while there is still time, rather than during the validated assessment.
What is reviewed
A readiness assessment looks at four areas:
- Scope — which systems, locations and data are in the assessment, and whether the scope is wider than it needs to be.
- Policies — whether the required policies exist, are approved and are reviewed.
- Implemented controls — whether the controls described in your policies are actually in place.
- Evidence — whether you can show that each control is operating.
What you receive
At the end you receive two things:
- A gap list — each requirement that is not yet met, and why.
- A remediation plan — the actions needed to close each gap before the validated assessment.
How readiness differs for e1, i1 and r2
The approach is the same for every level; what changes is the number of requirements reviewed. The e1 assessment has the fewest requirements, i1 has more, and r2 has the most, with requirements tailored to your organisation's risk factors. Our guide to HITRUST e1 vs i1 vs r2 explains how to choose the right level before readiness starts.
How readiness is priced
We do not price readiness separately. It is part of the full engagement, which covers implementation and assessment:
| Assessment | CyberWave GRC engagement (implementation and assessment) |
|---|---|
| e1 | About $15,000 |
| i1 | About $40,000 |
| r2 | $150,000 to $200,000 |
HITRUST's own licence and report fees are paid to HITRUST directly and are not included in these figures. See our HITRUST certification cost guide for more detail.
Common gaps we see
In our engagements, the gaps that come up most often are:
- Policies that exist but are not approved or reviewed.
- Missing evidence that a control is operating — the control may be in place, but nothing proves it.
- Scope that is wider than it needs to be, which adds requirements and effort.
- Cloud provider controls that are not inherited, so work your cloud provider already does is assessed again.
Next step
If you are planning a HITRUST e1, i1 or r2 assessment, start with readiness. Learn how we support the full journey on our HITRUST consulting page, or book a 30-minute call to discuss your scope.
