What Does HITRUST Certification Cost?
HITRUST certification is three separate bills, and any single figure that does not say which of the three it includes is not a price. The first bill goes to HITRUST itself: a MyCSF subscription or bundle, and the report credit that every validated assessment consumes. The second goes to a HITRUST Authorized External Assessor for fieldwork. The third is your own readiness and remediation effort, and it is the one that varies most. HITRUST publishes the structure of the first bill in detail, and, on every page we could fetch as of August 25, 2026, no price for any of it: its own pricing page returned a 404, and its MyCSF page carries no dollar figure. Our budget planner prices HITRUST by row rather than by bill, with the gap analysis at $45,000 to $75,000, remediation at $55,000 to $110,000, audit fees at $40,000 to $80,000, and ongoing maintenance at $25,000 to $50,000 a year, as mid-market planning estimates for a 51 to 200 person company; those are our own figures and not a quote. The contrarian part is that the assessor is rarely the number to negotiate. The bill you control is the third one, and it is decided by scope and readiness months before anyone is invoiced.
This article walks the three bills in turn, sets out what HITRUST does and does not publish about the first, explains where our own planning rows come from and what they do not cover, and closes with the four decisions that move the total. Which tier you need is answered in HITRUST e1 vs i1 vs r2, which also carries the two published third-party all-in ranges per tier; how long each tier takes is answered in how long HITRUST takes. Neither is restated here.
Key takeaways
- HITRUST certification is three bills: the MyCSF subscription and report credit paid to HITRUST, the authorised external assessor's fee, and your own readiness and remediation effort. A figure that does not say which bills it includes cannot be compared with anything.
- HITRUST publishes the structure of its own bill in detail: four subscription levels, three bundles, report credits that expire in 12 months, and a subscription agreement under which fees are set per order form, are non-refundable and may rise annually. It publishes no list price on any page we could fetch.
- Our budget planner's HITRUST rows, gap analysis at $45,000 to $75,000, remediation at $55,000 to $110,000, audit fees at $40,000 to $80,000 and ongoing maintenance at $25,000 to $50,000 a year, are the site's own mid-market estimates and are pinned to the planner so this page cannot drift from it.
- Inheritance is the largest single lever on the assessor bill. HITRUST's MyCSF overview says organisations inherit "up to 60% of the controls" from cloud providers, a lower figure than the one on its inheritance marketing page.
- Top Floor is a readiness firm. We are not a HITRUST Authorized External Assessor, and the assessor fee is a separate line from anything we charge.
Bill one: what you pay HITRUST
This is the bill HITRUST documents most completely and prices least publicly.
HITRUST's MyCSF overview (document v.HT-501-12) describes four subscription levels: Report Only Access, which covers r2 only for 90 days with three users and one assessment object; Professional, Corporate and Premier, each running 12 months and each covering all three assessment types, with five, ten and unlimited users respectively. It then describes three bundles: an r2 Report Only Bundle with 90 days of assessment access, an e1 Lite Bundle with 30 days for the assessment and 12 months of read-only access afterwards, and an i1 Lite Bundle with 12 months of access. Every bundle includes exactly one report credit, and the overview states that report credits "expire in 12 months".
The report credit is the part that surprises first-time buyers. Under the Assessment Handbook, "a validated assessment report credit is required to make a reservation" for the QA block that every validated assessment must pass through, and failure to submit by the reserved date results in "cancellation of the reservation and a change fee being billed to the Assessed Entity." HITRUST's advisory HAA 2023-004 notes that the three assessment types "require different types of report credits", and that if HITRUST misses its own e1 post-submission service level, "the customer's next e1 Validated Assessment Report credit is complementary." So the credit is a priced unit with a shelf life and a penalty structure, even though the price itself is not on the page.
The subscription levels also gate features that affect the other two bills. Per the same overview, the CAP management module arrives at Corporate; internal inheritance and publishing for external inheritance arrive at Corporate; the interim or bridge assessment for r2 requires at least Professional; and the Report Only level includes no HITRUST CSF access in MyCSF and no assessment data retention. A subscription chosen for its price can therefore add work in the next assessment cycle, which is the pattern to avoid.
What HITRUST does not publish is any number. The MyCSF Subscription Agreement, version 3, effective August 1, 2025, says that the customer "agrees to pay all fees specified in an Order Form", that "payment obligations are non-cancelable and Fees paid are non-refundable", that quantities "cannot be decreased during the relevant Term", and that HITRUST "reserves the right to annually increase its Fees" with notice not less than sixty days before the term ends. The price lives in the order form. Third-party sites quote MyCSF list prices; we have not repeated them, because we could not verify a single one against a HITRUST page, and a price for a named company that its own site does not publish is exactly the kind of figure this site declines to print.
Bill two: what you pay the assessor
A HITRUST certification issues after a validated assessment performed by a HITRUST Authorized External Assessor and reviewed by HITRUST's quality assurance team. The assessor's fee is set by the assessor, not by HITRUST, and it scales with three things you can read off the tier and the scope before you ask for a quote.
The requirement count. HITRUST's framework page describes e1 as 43 core controls and i1 as 182 control requirements; its r2 data sheet gives the r2 count as "2000+ based on Tailoring (360 average)". Assessor fieldwork is testing, and testing is priced per requirement statement, so the tier decides the order of magnitude of this bill before any negotiation.
The fieldwork window. The handbook caps validated assessment fieldwork at 90 days for all three tiers and requires every control to have operated for 90 days before it can be tested. A control remediated during fieldwork can push the assessment into a second fieldwork period, which is a second block of assessor time. The clocks are set out in how long HITRUST takes.
Inheritance. The MyCSF overview states that "many save significant time, effort, and cost on their HITRUST assessments by inheriting up to 60% of the controls from their cloud service providers", with the footnote that the provider "must have an appropriate MyCSF subscription and current HITRUST Validated or Certified Assessment." That is a lower ceiling than the one HITRUST's inheritance marketing page quotes, and HITRUST inheritance explained takes both apart. For the assessor bill, every inherited requirement is one the assessor does not test, and that is the largest single lever on this line.
The published third-party all-in figures per tier, from two sources that disagree with each other, are in the tier comparison with their biases stated. We cite them there and do not restate them here, because a figure that appears in two places on one site eventually appears in two versions.
Bill three: what you pay in your own effort
This is the bill that no directory publishes and that decides whether the other two are paid once or twice.
It has three parts. The gap analysis, which is the structured comparison of your current controls against the requirement set of your tier and scope, and which for r2 cannot even begin until scoping has generated the requirement set. Remediation, which is the work of building or fixing the controls the gap analysis found wanting, and which carries the 90-day incubation clock in front of every one of them. And the ongoing programme, which for e1 and i1 is an annual reassessment, and for r2 is an interim assessment in the 90-day window before the first anniversary and a full recertification at two years.
Two structural facts keep this bill from being estimated by the tier alone. Remediation is dominated by the handful of requirements you do not already have, not by the total count; a company with a working access review and a formal secure development lifecycle has a very different bill from one without them, at the same tier. And the scope you choose for a first assessment decides how much of it is inheritable into the second, which is the internal inheritance the MyCSF overview describes and which nobody prices at the start.
Our own planning figures, and what they do not cover
Our budget planner publishes HITRUST as four rows, and we quote them here as the site's own estimates rather than as a market figure: the gap analysis at $45,000 to $75,000, remediation at $55,000 to $110,000, audit fees at $40,000 to $80,000, and ongoing maintenance at $25,000 to $50,000 a year, as mid-market planning estimates for a 51 to 200 person company. The planner's own disclaimer says these are our estimates and not a quote, and the figures on this page are pinned to the planner in our test suite so the two cannot drift apart.
Read them against the three bills, because the rows and the bills do not line up one to one. The gap analysis and remediation rows are bill three. The audit fees row is our estimate for bill two, the assessor's fieldwork and report. The ongoing maintenance row is the annual programme cost, and it is where a two-year r2 with an interim assessment differs materially from an annual e1 or i1. Bill one, the MyCSF subscription and report credit, is not a separate row in the planner, and we do not publish a figure for it, for the reason given above: HITRUST does not, and we will not invent one.
The rows are also mid-market. The planner applies a size multiplier for smaller and larger companies, and a small health tech vendor buying an e1 to satisfy a single customer will sit well under the base band on every row, while an organisation with several in-scope platforms and a tailored r2 set will sit above it. Use the planner for the multiplier, and use the tier comparison for the published market ranges, and expect the two to describe different things.
The four decisions that move the total
The tier. Chosen by the contract in front of you, not by ambition, which is the whole argument of the tier comparison. The requirement count sets the order of magnitude of the assessor bill and of the remediation bill together.
The scope. Fewer in-scope systems mean fewer requirement statements tested and fewer controls to remediate, but a scope drawn too tightly around one product produces less inheritable material for the second assessment and leaves the customer's actual data flows outside the certificate. Scope is decided once and paid for twice.
Readiness before fieldwork. A control found during fieldwork costs the remediation plus a second fieldwork period plus, often, a second QA reservation. A control found in readiness costs the remediation. This is the difference the third bill exists to buy.
Inheritance and subscription level together. Inheritance reduces the assessor bill; the subscription level decides whether you can use it. Choosing the cheapest MyCSF option and then discovering that internal inheritance or the r2 interim requires a higher one is a common way for bill one to be paid twice.
Where Top Floor fits
We do HITRUST readiness under our HITRUST practice: scoping, the gap analysis, the remediation plan, evidence preparation in MyCSF, and coordination with the assessor. The Security Rule work underneath usually runs under our HIPAA practice, and the continuing programme under Compliance as a Service.
We are not a HITRUST Authorized External Assessor and we do not issue certifications. The assessor's fee is a separate bill from anything we charge, and a firm that offers to both close your gaps and certify the result has a conflict worth asking about directly. Against our own interest: if a customer has named e1 and your 43 controls are already operating, the readiness bill should be small, and buying a large one is the overspend we see most often in health tech.
How to decide this week
Ask HITRUST or an assessor for the order form that names the subscription level and the report credit for your tier, because that is the only place the first bill is priced. Then get two assessor quotes for the same scope, and ask each what it assumes about inheritance, because that assumption is most of the difference between them.
Finally, before budgeting the third bill, list the requirements you know you do not have. If the list is short, the planner's bands are conservative for you; if it is long, the tier conversation with the customer is cheaper than the remediation programme, and that conversation is the one to have first.
Frequently asked questions
How much does HITRUST certification cost in total?
There is no honest single figure, because HITRUST certification is three separate bills: the MyCSF subscription and report credit paid to HITRUST, the authorised external assessor's fee, and your own readiness and remediation effort. HITRUST publishes the structure of its own bill and no price on any page we could fetch as of August 2026. Our budget planner's HITRUST rows are the site's own mid-market planning estimates and are quoted in the article above; the two published third-party all-in ranges per tier are in our tier comparison, and they disagree with each other.
Does HITRUST publish its prices?
Not on any page we could fetch. HITRUST's MyCSF overview publishes the subscription levels, the bundles and the fact that report credits expire in 12 months, and its subscription agreement states that fees are specified in an order form, are non-refundable and may be increased annually. Its pricing blog page returned a 404 when we checked on August 25, 2026, and its MyCSF page carries no figure. Third-party sites quote MyCSF list prices; we have not repeated them because none could be verified against a HITRUST page.
What is the HITRUST report credit?
A report credit is the priced unit HITRUST consumes for each validated assessment report, and it is required before you can reserve a quality assurance block. HITRUST's MyCSF overview states that report credits expire in 12 months, its e1 advisory notes that e1, i1 and r2 require different types of credit, and the Assessment Handbook states that missing a reserved submission date cancels the reservation and bills a change fee. If HITRUST misses its published e1 post-submission service level, the next e1 report credit is complementary.
Which part of HITRUST cost can we actually reduce?
Your own readiness effort and the assessor's fee, in that order. Readiness before fieldwork avoids the second fieldwork period and the second QA reservation that a control found during testing tends to cause. Inheritance from a certified cloud provider, which HITRUST's MyCSF overview puts at up to 60 percent of controls, removes requirements from the assessor's test plan, provided your subscription level supports it. The tier and the scope decide the order of magnitude of both bills before either lever is pulled, and the tier is a procurement question answered by the contract that started the process.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.