HITRUST
- Company typePrivate
- Founded2007
- HeadquartersFrisco, United States
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
HITRUST firmographics
Firmographics- Name
- HITRUST
- Legal name
- HITRUST Services LLC
- Website
- https://hitrustalliance.net/
- Company type
- Private
- Founded year
- 2007
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Ownership category
- akta.pro rank
HITRUST industry classification
Industry- Product category
- Cybersecurity Compliance & Risk Assurance Software
- NAICS
- Other Computer Related Services (541519), Testing Laboratories and Services (54138)
- SIC
- Services-Computer Processing & Data Preparation (7374)
- akta.pro primary industry
- Governance, Risk & Compliance (GRC) Advisory & Assessments (BPAKAHAH)
- akta.pro secondary industries
- Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC), Security Awareness, Training & Compliance Attestation (HDADAIAJ)
Keywords
Where HITRUST is headquartered
LocationHeadquarters
- HQ city
- Frisco
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
HITRUST business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Certification and Assessment Services: HITRUST generates revenue through certification fees for e1, i1, r2, and AI security assessments. Organizations pay for third-party assessment and certification processes that validate security controls against HITRUST frameworks. Valid for 1-2 years depending on assessment type.
- MyCSF SaaS Platform Subscription: Subscription-based access to the MyCSF assessment SaaS platform, sold directly or through resellers. Subscriptions are purchased for use during defined terms, with pricing based on users and/or assessments.
- HITRUST Academy Training: Revenue from training programs including Certified HITRUST Quality Professional (CHQP) and Certified CSF Practitioner (CCSFP) courses, plus new customer orientation.
- HITRUST TPRM Services: Third-Party Risk Management assessment services for organizations managing vendor cybersecurity risk.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | e1 - Foundational cybersecurity assurance |
| Subscription | Annual | i1 - Threat-adaptive assurance |
| Subscription | Multi-year contract | r2 - Tailored assurance with highest level of control requirements |
| Subscription | Annual | AI Security Assessment |
| Subscription | Annual | AI Risk Management Assessment |
Go-to-market motion1 record
Distribution channels4 records
Marketing channels8 records
HITRUST product offering
Product offeringCore offering
HITRUST provides a comprehensive cybersecurity assurance platform built on the HITRUST CSF framework, a threat-adaptive control library harmonizing 60+ standards including NIST, ISO, HIPAA, and OWASP. Customers subscribe to the MyCSF SaaS platform to perform self-assessments and obtain tiered certifications (e1 foundational, i1 threat-adaptive, r2 highest assurance, plus AI Security and AI Risk Management assessments) validated by HITRUST Authorized External Assessors. Supporting offerings include the Results Distribution System (RDS) API for sharing certification results with stakeholders, TPRM services for vendor risk management, Insights Reports mapping results to multiple regulatory frameworks, the Products and Services Directory, the XChange Portal, and the HITRUST Academy training and certification programs.
Product overview
HITRUST offers a comprehensive cybersecurity assurance platform built around its HITRUST CSF framework — a threat-adaptive control library harmonizing 60+ standards including NIST, ISO, OWASP, and HIPAA. The core platform consists of MyCSF, a SaaS-based assessment and certification management tool, complemented by the Results Distribution System (RDS) API for sharing certified results with stakeholders. HITRUST's traversable assessment portfolio spans three tiers: e1 (foundational, 43 controls), i1 (threat-adaptive, 182 controls), and r2 (highest assurance, fully tailored) — all built on the shared HITRUST CSF framework, enabling organizations to reuse controls and progressively deepen their certification. The portfolio is augmented by two AI-specific assessments (AI Security Assessment and AI Risk Management Assessment), Insights Reports that translate results into HIPAA/NIST/GovRAMP mappings, TPRM Services for vendor risk management, a Products and Services Directory (PSD), and the XChange Portal for third-party risk coordination. Training is delivered through the HITRUST Academy (CHQP, CCSFP).
Differentiator
Problem solved
Functional benefit
Brands
- MyCSF: Assessment SaaS platform for HITRUST CSF assessments and certifications.
- RDS (Results Distribution System)
- HITRUST TPRM Services
- HITRUST AI Security Assessment
- HITRUST AI Risk Management Assessment
- HITRUST CSF
- HITRUST Cyber Threat Adaptive
Products and services
- HITRUST MyCSF HITRUST's flagship cloud-based SaaS platform for performing self-assessments against the HITRUST CSF framework, allowing organizations to assess, track, and report on their security and privacy controls, manage remediation, and submit for HITRUST certification through a centralized, guided workflow.
- HITRUST Results Distribution System (RDS) A secure, API-enabled system that allows organizations to electronically share HITRUST Assessment results with customers, partners, and stakeholders in a standardized, structured format, streamlining third-party risk management and vendor oversight.
- HITRUST CSF Framework The HITRUST Common Security Framework (CSF) is a comprehensive, threat-adaptive control library harmonizing 60+ frameworks and standards, providing 14 control categories, 49 objectives, and 156+ specifications that enable tailored, risk-based assessments and consistent cybersecurity and compliance across varied industry needs.
- HITRUST e1 Assessment & Certification Foundational HITRUST cybersecurity assurance certification with 43 core controls, aligned with NIST, ISO, and OWASP frameworks, valid for 1 year and independently tested and validated.
- HITRUST i1 Assessment & Certification Threat-adaptive HITRUST assurance certification with 182 control requirements, valid for 1 year, providing mid-tier organizations with validated security controls aligned to the current threat landscape and regulatory frameworks through independent third-party testing.
- HITRUST r2 Assessment & Certification Tailored HITRUST assurance certification with the highest level of control requirements, valid for 2 years, integrating healthcare, financial, and SOC 2 requirements into a single validated framework with ongoing monitoring and maturity scoring requirements.
- HITRUST AI Security Assessment Comprehensive HITRUST controls to secure and certify deployed AI systems, providing AI-specific security validation that can be added to any core HITRUST certification and covers adversarial AI techniques and AI model protection controls.
- HITRUST AI Risk Management Assessment HITRUST assessment with 51 controls aligned with ISO/IEC 23894:2023 and the NIST AI Risk Management Framework, helping organizations evaluate and continuously improve AI risk management programs and address algorithmic bias, data privacy, and model integrity risks.
- HITRUST Insights Reports Reporting product that translates and maps HITRUST assessment results into multiple regulatory frameworks including HIPAA, HICP, NIST SP 800-171, and GovRAMP, enabling organizations to demonstrate compliance across multiple standards from a single HITRUST assessment.
- HITRUST NIST CSF 2.0 Assessment HITRUST Assessment and certification to the NIST Cybersecurity Framework 2.0 specification, enabling organizations to obtain HITRUST-aligned certification against the latest NIST requirements.
- HITRUST TPRM Services Third-Party Risk Management (TPRM) assessment services that leverage HITRUST's standardized framework to assess vendors consistently, automate vendor cybersecurity and AI assessments, and provide organizations with reliable, data-backed vendor risk visibility.
- HITRUST Products and Services Directory (PSD) Searchable directory of products and services that have been assessed and certified under the HITRUST framework, enabling organizations to discover and evaluate certified third-party solutions.
- HITRUST XChange Portal Portal enabling organizations to manage third-party risk assessments, share HITRUST certifications with vendors, and facilitate the IRQ (Inherent Risk Questionnaire) process for vendor risk evaluation.
- HITRUST Academy Training and certification programs including Certified HITRUST Quality Professional (CHQP) and Certified CSF Practitioner (CCSFP), designed for security and compliance professionals seeking to build expertise in HITRUST assessments and the CSF framework.
- HITRUST CSF v11.2.0 with AI Security Controls HITRUST CSF version 11.2.0, released October 2023, introduced 51 specialized AI security controls to address vulnerabilities in healthcare cloud environments, consolidating 14 control categories, 49 objectives, and 156+ specifications to help organizations manage AI-specific risks including algorithmic bias, data privacy, and model integrity.
Quantifiable outcome
- 99.62% breach-free rate for HITRUST-certified environments
- +5 more outcomes
Companies that use HITRUST
Customer profileNamed customers5 records
Segments4 records
Ideal customer profiles3 records
HITRUST technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
AI capability1 record
Feature5 records
HITRUST partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core.
- Crowe LLPcoreExpanded collaboration integrating HITRUST's security and AI certification platform into Crowe's TPRM offerings. Automates vendor cybersecurity and AI assessments, shortens assessment timelines, increases consistency across vendor landscapes, and reduces repetitive manual work for both Crowe clients and assessed companies.
- Rapid7coreStrategic partnership integrating Rapid7's Surface Command attack surface visibility platform with HITRUST's assurance framework to automate compliance validation. Enables organizations to shift from periodic manual audits to continuous, evidence-based security posture assessment. Reduces audit scope and costs while improving cyber resilience.
- Lloyd's of LondoncoreLaunched first-of-its-kind cyber insurance consortium backed by AA-rated insurers and built around HITRUST certification. The initiative offers organizations with HITRUST certifications improved coverage, lower rates, and streamlined underwriting processes.
Scale indicators10 records
Recent moves6 records
Expansion highlights6 records
HITRUST competitors and assessment
Company assessmentBroad incumbents
- KPMG (Cyber Security Services): KPMG's cybersecurity practice delivers HITRUST, ISO, SOC 2, and broader GRC advisory and assessment services. As a Big 4 firm, it competes both as an authorized external assessor and as a broader enterprise GRC incumbent.
- OneTrust: OneTrust is a broad GRC, privacy, and trust intelligence platform. It competes with HITRUST for compliance and TPRM budget and integrates with HITRUST MyCSF as both a partner and a partial substitute in enterprise stacks.
- Deloitte (Cyber & Strategic Risk): Deloitte provides enterprise-wide cyber risk, regulatory, and HITRUST assessment services. As a broad incumbent with global reach, it overlaps with HITRUST across healthcare, financial services, and regulated industries.
Emerging players
- Secureframe: Secureframe provides automated compliance for SOC 2, ISO 27001, HIPAA, PCI, and other frameworks. It competes with HITRUST for compliance budget in mid-market and overlaps with HITRUST's healthcare SaaS customer base.
- Drata: Drata automates SOC 2, ISO 27001, HIPAA, and other compliance audits with continuous monitoring. As a fast-growing GRC automation platform, it represents an emerging threat that could compress HITRUST's manual assessment value proposition.
- Vanta: Vanta automates security compliance for SOC 2, ISO 27001, HIPAA, and more than a dozen frameworks. It is an emerging GRC automation competitor and a complementary integration partner for HITRUST MyCSF.
Direct peers
- Coalfire: Coalfire is a cybersecurity advisory and assessment firm with deep HITRUST, FedRAMP, PCI, and SOC 2 practices. It directly competes as both a HITRUST external assessor and a broader GRC advisory peer.
- A-LIGN: A-LIGN is a cybersecurity compliance auditing and certification firm offering SOC 2, ISO 27001, HITRUST, PCI, and FedRAMP assessments. It directly competes with HITRUST's authorized external assessor ecosystem and overlaps on HITRUST r2 delivery.
- Schellman: Schellman is a top-tier security and privacy compliance assessor delivering SOC 2, ISO 27001, HITRUST, PCI, and FedRAMP audits. It is a direct competitor in HITRUST assessment delivery and parallel GRC assurance services.
Others
- Censinet: Censinet's RiskOps platform automates HITRUST and AI security assessments for healthcare vendor risk. It is a channel and technology partner to HITRUST and an adjacent TPRM peer for the same healthcare buyer.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks7 records
Key highlights7 records
Customer concentration
HITRUST social profiles
Digital presenceHITRUST compliance and trust
Trust signalCompliance6 records
HITRUST financial estimates
Financial estimateRevenue estimate
Valuation estimate
HITRUST leadership team
Management profileNumber of profiles
Profiles5 records
HITRUST funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
HITRUST M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about HITRUST
What does HITRUST do?
HITRUST provides a comprehensive cybersecurity assurance platform built on the HITRUST CSF framework, a threat-adaptive control library harmonizing 60+ standards including NIST, ISO, HIPAA, and OWASP. Customers subscribe to the MyCSF SaaS platform to perform self-assessments and obtain tiered certifications (e1 foundational, i1 threat-adaptive, r2 highest assurance, plus AI Security and AI Risk Management assessments) validated by HITRUST Authorized External Assessors. Supporting offerings include the Results Distribution System (RDS) API for sharing certification results with stakeholders, TPRM services for vendor risk management, Insights Reports mapping results to multiple regulatory frameworks, the Products and Services Directory, the XChange Portal, and the HITRUST Academy training and certification programs.
Is HITRUST a public or private company?
HITRUST is a private company. It is classified as venture growth investor backed and is currently operating.
When was HITRUST founded?
HITRUST was founded in 2007. It employs 101 to 250 people.
Where is HITRUST based?
HITRUST is headquartered in Frisco, United States, in the North America region.
How does HITRUST make money?
Four revenue lines are on record. Certification and Assessment Services are the primary driver. The others are myCSF SaaS Platform Subscription, HITRUST Academy Training and HITRUST TPRM Services.
Who are HITRUST's main competitors?
Broad incumbents on record are KPMG (Cyber Security Services), OneTrust and Deloitte (Cyber & Strategic Risk). Emerging players are Secureframe, Drata and Vanta. Direct peers are Coalfire, A-LIGN and Schellman. Censinet is listed as an others.
Does HITRUST have an API?
Yes. HITRUST offers the Results Distribution System (RDS) API, which allows organizations to electronically share HITRUST Assessment results with customers, partners, and stakeholders in a standardized, structured format. This is a secure, API-enabled system for results distribution. Developer documentation is at hitrustalliance.net/rds-terms.
What industry is HITRUST in?
HITRUST's product category is Cybersecurity Compliance & Risk Assurance Software. Its primary akta.pro industry code is BPAKAHAH, Governance, Risk & Compliance (GRC) Advisory & Assessments, with a secondary code of BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX). Its NAICS code is 541519 and its SIC code is 7374.