Frequently asked questions
Straight answers — including the certification myth, costs, and what CISA gives away free.
Is there such a thing as “NIST CSF certification”?
No. NIST publishes the Cybersecurity Framework as voluntary guidance — it does not certify companies, and no certificate is issued by NIST. Firms offering “CSF certification” mean their own attestation or readiness program; ask exactly what is being attested and by whom.
What does HITRUST certification cost?
Our labeled estimates: readiness $25,000–$60,000; i1 validated $40,000–$100,000; r2 validated $75,000–$200,000+. See the cost guide for the full breakdown and what buyers forget to budget.
Do I need an authorized assessor for HITRUST?
For a validated (r2) assessment, yes — HITRUST requires an authorized external assessor. Firms in our directory described as authorized assessors appear on HITRUST’s published external assessor list (checked September 2026).
CSF or HITRUST — which first?
Start with CSF 2.0 unless a customer or contract demands the HITRUST certificate. Healthcare organizations handling PHI usually need HITRUST (often r2); everyone else should let buyer demand decide.
How is this directory different from a Google search?
Every firm is verified real (website checked), assessor claims are cross-checked against HITRUST’s own list, costs are labeled estimates with provenance — and ranking can’t be bought.
How much does it cost?
Published sources and our labeled estimates put a CSF 2.0 gap assessment at $15,000–$40,000, a HITRUST readiness assessment at $25,000–$60,000, and a HITRUST r2 validated assessment at $75,000–$200,000+. Use the estimator for a planning band, then get 2–3 scoped quotes. See the cost guide.
How long does implementation take?
A realistic end-to-end range for a first CSF 2.0 program: 4–9 months. A HITRUST r2 journey (readiness → remediation → validated assessment): 9–18 months. Timelines below assume a mid-market organization with basic IT hygiene already in place. See the timeline.
How do you make money?
When you request quotes, matched firms may pay us a lead or referral fee. That never affects which firms we list or what our guides say — firms can't pay to change a profile or buy a recommendation.
Are the firms on this site endorsed by CISA?
No. CISA does not endorse private firms. Our listings are independent, alphabetical, and never sold.
Still have questions?
Ask us — or get matched with firms who answer for a living.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.