Pricing report
CSF & HITRUST costs 2026: every figure, cited
A meta-analysis of cost data for CISA-guidance consulting work. One provenance label per row — published source or clearly-labeled directory estimate. No invented averages.
| Cost item | Range | Source | Source date | Scope |
|---|---|---|---|---|
| NIST CSF 2.0 — the framework itself | $0 | NIST | 2026 | Free download from nist.gov; no certification fee exists |
| CSF 2.0 gap assessment (consultant) | $15,000–$40,000 | Directory estimate | September 2026 | Current-state assessment against CSF 2.0 subcategories; mid-market scope |
| CSF 2.0 program implementation (mid-market) | $50,000–$150,000 | Directory estimate | September 2026 | Roadmap plus control build-out; excludes tooling and staff |
| HITRUST readiness assessment | $25,000–$60,000 | Directory estimate | September 2026 | Pre-assessment dry run against the HITRUST CSF requirement statements |
| HITRUST i1 validated assessment | $40,000–$100,000 | Directory estimate | September 2026 | Assessor-led; 1-year certification on leading-practice requirements |
| HITRUST r2 validated assessment | $75,000–$200,000+ | Directory estimate | September 2026 | Comprehensive assessor-led assessment; 2-year certification |
| vCISO for program build | $8,000–$20,000 / month | Directory estimate | September 2026 | Part-time security leadership through implementation |
| Incident-response retainer | $50,000–$200,000 / year | Directory estimate | September 2026 | Prepaid IR hours plus tabletop and readiness reviews |
How to read this table
- CISA (2026) rows are CISA's own published services and guidance — free where noted.
- Directory estimate (September 2026) rows are our labeled estimates synthesized from published consulting-rate data — useful for budgeting, not quotes.
- Published planning ranges (2025–2026) rows come from widely published third-party ranges.
Sources
- NIST — Cybersecurity Framework 2.0 (nist.gov)
The framework itself is free: six Functions (Govern, Identify, Protect, Detect, Respond, Recover), 22 Categories, 106 Subcategories. No certification, no fee. - HITRUST — assessment types e1, i1, r2 (hitrustalliance.net)
HITRUST defines three assurance options: e1 (foundational hygiene), i1 (leading practice), r2 (comprehensive, 2-year certification). Validated r2 assessments require an authorized external assessor. - HITRUST — find an external assessor (hitrustalliance.net)
HITRUST's published directory of authorized external assessor organizations — our assessor-status cross-check source, September 2026. - Directory estimates (September 2026)
Advisory and assessment engagement bands synthesized from published consulting-rate data and firm planning ranges; labeled estimates, not quotes.
Turn ranges into quotes
Estimates plan budgets. Scoped quotes set them — get 2–3, free.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.