{ Free HITRUST Readiness Assessment }

Your customer asked for HITRUST certification. Find out which one you actually need.

One 30-minute call with a HITRUST consultant. You get a written readiness assessment that names your tier — e1, i1 or r2 — scoped against your inherent risk factors, every gap risk-rated, with a week-by-week plan to certification. Yours to keep, whether or not you work with us.

SOC 2 compliance badge
5 star rating on g2 for our soc 2 compliance services

5.0 on G2

Compliance consulting

Get your free readiness assessment
{ The deliverable }

What lands in your inbox three days later

Not a summary email. A written report your team can work from and a HITRUST External Assessor would recognise.

1

Your tier, and the reasoning behind it

e1, i1 or r2 — named, with the logic shown. We map what your customer actually asked for against your inherent risk factors, so you're not certifying to a level nobody required or discovering mid-assessment that you scoped too low.

2

Your scoped requirement count

An r2 can carry anywhere from 198 to over 2,000 requirement statements depending on your risk factors — the average in-scope assessment is around 360. You get your number, not a range.

3

Requirement-by-requirement gap analysis

Every requirement statement in scope for your tier, marked met, partial, or gap — with the evidence a HITRUST External Assessor will expect to see for each one.

4

Maturity scoring readiness

HITRUST doesn't score pass/fail — it scores maturity, domain by domain. Most teams have controls implemented but no measurement or management around them, and that's where scores fall short. We show you where you'd land today.

+

Platform and MyCSF configuration review

If you're on one

On Vanta, Drata, Secureframe or Thoropass? We audit the configuration too — disabled tests, partial integrations, controls showing green on evidence that wouldn't survive validation. If you've already opened a MyCSF object, we check whether it's scoped correctly before you spend another month against it.

SOC2 consultant talking with their client and laughing
Excerpt from a live client engagement, redacted. Every finding carries an ID, an owner-ready action, and a risk score.
{ How this fits }

The assessment is the first two phases. Yours free.

HITRUST certification is a seven-phase process. We give away the first two because they're the two that tell you whether the other five are worth doing — and because whoever scopes your assessment is usually who you want running the rest.
phase 1

Scope and tier determination

Which entities, systems and data flows are in scope, what your customer's contract actually requires, and which of e1, i1 or r2 that lands you on. This single decision sets your cost, your timeline, and your requirement count.

free
phase 2

Readiness gap assessment

The full requirement-by-requirement analysis against your tier, with every gap risk-rated and a prioritised remediation roadmap.

free
phase 3

Control implementation and remediation

Closing the gaps — policies, procedures, and the operating evidence behind them, built to score at the maturity levels HITRUST actually measures.

Engagement
phase 4

MyCSF setup and requirement tailoring

Creating and scoping the assessment object correctly, confirming inherent risk factors, and tailoring requirement statements before the clock starts.

Engagement
phase 5

Evidence collection and internal validation

We assemble and score the evidence internally first, so weak requirements surface while they're still cheap to fix rather than during validation.

Engagement
phase 6

External Assessor selection and coordination

We help you pick an authorised External Assessor firm that fits your size and stage, and manage the relationship so you're not translating between assessor and engineering.

Engagement
phase 7

Validated assessment and QA support

We sit with you through fieldwork, HITRUST's QA review, and any corrective action plans, through to your certification letter.

Engagement
If you want us to run phases 3 through 7, that's a fixed monthly fee — no hourly billing, no scope-creep invoices. And you can cancel anytime if you're not saving at least 100+ hours a year. If you'd rather take the assessment and do the remediation in-house, that's a perfectly good outcome too. The report is yours either way.
{ The obvious question }

Why would you give this away?

Because we've scoped enough HITRUST assessments that 30 minutes of the right questions gets us most of the way there. The marginal cost to us is low. The cost to you of getting the tier wrong is not — HITRUST's own platform fees start around $18,100 for MyCSF, before an External Assessor or a consultant invoices anything.

And we'd rather you decide whether to work with us after seeing how we think — with a document in your hands — than after a sales call where we tell you how good we are.
{ The 30 minutes }

What actually happens on the call

Nothing to prepare. No documents to gather. If you have the security questionnaire or contract clause your customer sent, bring it — that's the only useful artefact.
00-05

The ask

What your customer, payer or health system actually requested — in their words — and what's riding on it.

05-12

Inherent risk factors

The structured questions that determine your tier and your requirement count: data volume, internet-facing systems, number of records, wireless, third parties. This is the part nobody else does for free.

12-25

Controls and evidence

A walkthrough of access management, risk management, endpoint and network protection, incident response, business continuity, third-party assurance and configuration management — where you stand and what's already documented.

25-28

Tooling and MyCSF

If you're on a compliance platform, we look at how it's actually configured. If you've already opened a MyCSF object, we check the scope. If you're on neither, we tell you whether you need either.

28-30

What happens next

We confirm what the report covers and when it lands. No pitch — if there's a fit, we'll talk about it after you've read it.

{ Who we've done this for }

Teams who had to prove it to a customer, not just claim it

What I valued most working with Kevin was that he never operated like a vendor. From the first engagement, he and his team behaved as an embedded partner, sitting inside our pocesses, owning the work alongside us, and treating our certification as their own deliverables.

Tim Clark
CTO

"Jai's clear communication and detailed readiness assessment for SOC2 ensured that we had a clear compliance roadmap. Their professional conduct and thorough understanding of SOC2 principles have not only prepared us for the audit but alo instilled greater confidence in our team regarding security measures."

Penumatcha Vijaya Rama Raju
Head of cloud platform

"Cycore's assistance was highly valuable and appreciated. The deciding factor was their personalized approach to supporting our needs."

Wouter de Bie
Co-Founder and CTO

We chose Cycore because of their perfect balance of cost and expertise. Cycore operated with integrity and as a partner.

Brandon Day
CEO at Cocoon

Having worked with a number of companies in the cybersecurity consulting space, working with Cycore was by far the easiest. Their client communication, transparency, and dedication to deadlines were excellent.

Head of Global Investigations

The role we play now is more of a supervisory position — it’s 1,000 times easier than when we were doing it ourselves. As founders, we wear a lot of hats. To be able to put that one down is just… chef’s kiss.

Latoya Scott-Brown
Co-Founder and CEO at HackHer

Being in the healthcare space, we take security and privacy seriously. Cycore's services allowed us to have the security expertise at hand when it mattered the most.

Tahseen Omar
Chief Operating Officer

It easy to see why the team at Cycore is highly praised. They understood our company needs and executed well.

Sherin Davis
Chief Product Officer

Cycore provided exemplary service in managing our compliance needs. Their team's experience is evident with how quickly they were able to solve our challenges.

David Kim
Co-Founder

All it took was 20 days for my team to have a strategy and playbook to execute SOC 2. All thanks to Cycore.

Rob Ratterman
CEO & Co-Founder

With Cycore, there's no need for my team and I to worry about security and privacy. Cycore keeps us up to date on our compliance program and notifies us ahead of time if they need something from us.

Nils Schneider
CEO & Co-Founder

Security questionnaires were a hassle for our team to turn over quickly in our sales cyles. Cycore has managed to make this process more efficient.

Phoebe Miller
Head of Business Operations

The Cycore team has been nothing short of great in helping us reach SOC 2 attestation. Highly recommend.

Charlie Ramirez
Managing Partner

Our team was short staffed and needed security expertise to continue building our security program. Cycore has been instrumental in our security posture success.

Richard Edwards
VP of Enterprise IT

We were looking for an in-house CISO but once we heard about Cycore's vCISO services, we knew this is what we needed. Thank you Cycore!

Kristian Nedyalkov
Product Manager
{ fit }

Who this is for

We'd rather tell you now than 20 minutes into a call.

A good fit if

  • A health system, payer or enterprise customer has HITRUST in a contract or security review, and the deal is waiting on it
  • You handle PHI or other regulated data — healthtech, digital health, SaaS, BPO or a healthcare service provider, roughly 20–500 people
  • You need to be certified in the next 3–9 months
  • You don't yet know whether you need e1, i1 or r2 — or you've been quoted for one and want a second opinion
  • You have someone senior who owns this, even part-time

Probably not if

  • You need a certification letter in under four weeks — that isn't achievable honestly, by anyone
  • You're looking for a policy template pack rather than a certifiable control environment
  • Nobody internally owns security and nobody's willing to
  • You want the certificate without the controls behind it
{ case studies }

The Work Behind the Trust

A look at how companies reached compliance and reduced risk with Cycore.
Cocoon logo
Compliance Service

How Cocoon Ensured 100% SOC 2 Compliance

learn more
Confida logo
Compliance Service

How Confida.ai Got SOC 2-Ready to Compete for Enterprise Deals

learn more
{ questions }

Before you book

Is this a sales call in disguise?

No. The call is a structured interview so we can build the report — we ask questions, you answer them. We don't pitch during it. Afterwards you get the assessment whether or not you want to talk about working together. If you do want to talk, we'll have that conversation once you've read it and can judge us on the work rather than the pitch.

Which assessment do we actually need — e1, i1 or r2?

That's the question the assessment exists to answer, and it's genuinely not guessable from the outside. e1 is the foundational tier, valid one year. i1 sits in the middle at 182 requirement statements, also valid one year. r2 is the risk-based tier, valid two years, and its requirement count is tailored to your inherent risk factors — in practice anywhere from just under 200 to over 2,000, averaging around 360. What your customer asked for and what they'll actually accept are often two different things, and we'll tell you which one you're looking at.

How thorough can a report from a 30-minute call really be?

Fair question. This is a directional assessment based on a structured interview — it tells you which tier you're on, where your gaps are, how serious they are, and what order to fix them in. It is not the same as a full validated readiness assessment where we review your actual evidence and configuration requirement by requirement. What it will do is give you an accurate map. Teams routinely find out they're five months from certification rather than five weeks, or that they've been scoped for an r2 when an i1 would have satisfied the customer.

What if we're not on a compliance platform yet?

Completely fine, and it doesn't change the assessment. We'll tell you honestly whether you need one — plenty of organisations certify without one, and for some the tooling adds cost without adding much.If you are on Vanta, Drata, Secureframe or Thoropass, we'll review your configuration as part of the assessment. That's usually where the surprises are.

How long does HITRUST certification actually take?

It depends entirely on tier. An e1 typically runs four to six weeks, an i1 eight to twelve, and an r2 four to six months from a standing start — depending on scope, existing maturity, and how much of the work your team absorbs versus hands over. e1 and i1 certifications are valid for one year; an r2 is valid for two, with an interim assessment in between. The assessment will give you a realistic date rather than an optimistic one.

What does HITRUST cost — including the parts you don't control?

Three separate line items, and it's worth seeing them separately. HITRUST charges for the MyCSF platform — subscriptions typically start around $18,100, and a readiness assessment report starts around $3,625. Your External Assessor firm prices its own fieldwork based on tier and scope. Our work is a fixed monthly fee over the length of the engagement — not hourly billing, so the number doesn't move when the work does. We'll give you the actual number alongside the assessment, so you're comparing a real price against a real scope rather than a range against a guess.

Can we just take the report and do it ourselves?

Yes, and some teams do. The report is written to be actionable by your own people — that's why the remediation plan is sequenced and assigned rather than a list of findings. Most teams who read it decide they'd rather not spend the next four months on it. But that's a decision you get to make with the document in front of you.

We already have SOC 2 and HIPAA. Doesn't that count for something?

It counts for a lot — HITRUST harmonises requirements from 40+ authoritative sources including HIPAA, NIST, ISO 27001 and PCI DSS, so work you've already done maps across rather than starting over. What it doesn't do is substitute. HIPAA tells you what to protect; HITRUST tells you how, and certifies that you've done it. That's precisely why health systems and payers are asking for it instead of accepting a self-attestation. Part of what the assessment does is show you how much of your existing evidence carries over.

Don’t Let HITRUST Hold
Up Your Next Contract.

Cancel anytime. If you’re not saving 100+ hours, you don’t pay.

Fill Out The Form Below For More Details
{ Free HITRUST Readiness Assessment }

Every month you wait pushes your certification date

An r2 takes four to six months. This call takes thirty minutes and costs nothing — and it's the difference between planning against a real timeline and hoping your customer will wait.

Get your free readiness assessment