HITRUST

    HITRUST Readiness Assessment: What It Covers and How to Prepare

    By Santhosh K, Chief Operating Officer, CyberWave GRC
    Published
    Last updated
    HITRUST

    Reviewed by Santhosh K, Chief Operating Officer, CyberWave GRC · CISA, CISM, CCISO, HITRUST CCSFP, CHQP, ISO/IEC 27001 Lead Auditor

    A HITRUST readiness assessment is the gap check done before the validated assessment. It is not the certification itself. It tells you where your controls, policies and evidence stand against the HITRUST requirements you plan to be assessed on, so you can fix gaps before an assessor tests them.

    This guide explains what a readiness assessment covers, when to do it, what you receive, and how it differs across the e1, i1 and r2 assessments.

    What a HITRUST readiness assessment is

    A readiness assessment compares how your organisation operates today with the requirements of your chosen HITRUST assessment. Its purpose is preparation. No certification is issued at the end of it.

    Validated assessments are performed by our partner Huduku AI, a HITRUST Authorized External Assessor. CyberWave GRC provides readiness, implementation and certification support. CyberWave GRC is not an assessor.

    When to do a readiness assessment

    Do it before the validated assessment begins — ideally before you commit to an assessment date. Doing it first means gaps are found and fixed while there is still time, rather than during the validated assessment.

    What is reviewed

    A readiness assessment looks at four areas:

    • Scope — which systems, locations and data are in the assessment, and whether the scope is wider than it needs to be.
    • Policies — whether the required policies exist, are approved and are reviewed.
    • Implemented controls — whether the controls described in your policies are actually in place.
    • Evidence — whether you can show that each control is operating.

    What you receive

    At the end you receive two things:

    • A gap list — each requirement that is not yet met, and why.
    • A remediation plan — the actions needed to close each gap before the validated assessment.

    How readiness differs for e1, i1 and r2

    The approach is the same for every level; what changes is the number of requirements reviewed. The e1 assessment has the fewest requirements, i1 has more, and r2 has the most, with requirements tailored to your organisation's risk factors. Our guide to HITRUST e1 vs i1 vs r2 explains how to choose the right level before readiness starts.

    How readiness is priced

    We do not price readiness separately. It is part of the full engagement, which covers implementation and assessment:

    AssessmentCyberWave GRC engagement (implementation and assessment)
    e1About $15,000
    i1About $40,000
    r2$150,000 to $200,000

    HITRUST's own licence and report fees are paid to HITRUST directly and are not included in these figures. See our HITRUST certification cost guide for more detail.

    Common gaps we see

    In our engagements, the gaps that come up most often are:

    • Policies that exist but are not approved or reviewed.
    • Missing evidence that a control is operating — the control may be in place, but nothing proves it.
    • Scope that is wider than it needs to be, which adds requirements and effort.
    • Cloud provider controls that are not inherited, so work your cloud provider already does is assessed again.

    Next step

    If you are planning a HITRUST e1, i1 or r2 assessment, start with readiness. Learn how we support the full journey on our HITRUST consulting page, or book a 30-minute call to discuss your scope.

    Frequently asked questions

    No. It is the gap check done before the validated assessment. It is not the certification itself.

    No. Readiness is part of the full engagement: e1 about $15,000, i1 about $40,000 and r2 $150,000 to $200,000, each covering implementation and assessment. HITRUST's own licence and report fees are paid to HITRUST directly and are not included.

    Our partner Huduku AI, a HITRUST Authorized External Assessor. CyberWave GRC is not an assessor.

    Policies that exist but are not approved or reviewed, missing evidence that a control is operating, scope wider than it needs to be, and cloud provider controls that are not inherited.
    Hi! I'm your AI Assistant 💬